This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] TR/Crypt.XPACK.Gen Removal

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, For the last few days my AV protection has been giving me a warning that I have TR/Crypt.XPACK.Gen Trojan found on my laptop although when I run a full sys scan it isn't found. Can anybody help please???? Thanks in advance.
Hello & Welcome to What the Tech
Please Subscribe to this Thread to get immediate notification of replies as soon as they are posted. To do this click Options, then click Track this Topic. Make sure it is set to Immediate Email Notification, then click Proceed.

In the meantime please note the following:
  • Any recommendations made are for your computer problems only and should NOT be used on any other computer.
  • Please DO NOT run any scans/tools or other fixes unless I ask you to. This is very important for several reasons. Here are just two of them:
    1. The tools that we use are very powerful and can cause >>irreparable damage<< to your computer if not used correctly.
    2. Commercial scanners, for the most part can not completely remove some of the more "resistant" infections. This makes it much more difficult to get rid of completely.
  • If you get stuck or are unsure of something please ask for a further explanation, do not guess.
  • It will require more than one round to properly clean your system. Continue to respond to this thread until I give you the All Clean! even if symptoms seemingly abate.
Please note that the forum is very busy and if I don't hear from you within five days this thread will be closed.
If for any reason you cannot complete instructions within that time, that's fine, just put a post here so that I know you're still here. We get a lot of people who simply leave & if there is no contact for that amount of time I will have to assume you have abandoned your topic.

Thanks

DDS
Download DDS.scr by sUBs from one of the following links & save it to your desktop.
http://www.techsupportforum.com/sectools/sUBs/dds
http://download.bleepingcomputer.com/sUBs/dds.scr
http://www.forospyware.com/sUBs/dds

  • Double-Click on dds.scr and a command window will appear. This is normal
  • Shortly after a log will appear
  • Click Yes at the next prompt, another log named attach.txt will appear
  • A window will open instructing you to post both logs. Copy the contents of both logs & post in your next reply
Gmer
Download gmer.zip from Gmer here & save it to your desktop.
  • Right click on gmer.zip, select Extract All… & extract the contents to your desktop
  • Double click the Gmer.exe file. If asked to allow gmer.sys driver to load, please consent
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file
  • Save it where you can easily find it, such as your desktop, and post the contents in your next reply
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

Note: Do not run any programs while Gmer is running.

To post in next reply:
DDS log
Contents of Attach.txt
Gmer log
Thanks for the response. I am at work at the moment and will follow the steps posted above tonight when I get home. Still here and in need of help. :(
No worries coldpost :thumbup:

I just noticed your OS is Vista Home Basic. If this is the problem machine you will need to run each of the tools by right-clicking on them & choosing Run as Administrator.
I am also now getting a TR Xpack dss warning. Am i right to assume this will show up in the fixes you have outlined above? Just about to DL programs and then run will post back relevant files shortly.
Shortly after discovering the last virus from my previous post and during the Gmer scan my laptop went to the Blue Screen of death and rebooted. PLEASE ADVISE???????!!!!!!!!
Having real problems here!! The scan on 2nd attempt gets to sector 63 and says 'has detected rootkit Gmer changes' or something to that effect and then just stops. Please help :(
Here are the dds files anyway for now. DDS (Ver_09-03-16.01) - NTFSx86 Run by [removed] at 18:03:03.09 on 27/03/2009 Internet Explorer: 7.0.6001.18000 Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.44.1033.18.2039.982 [GMT 0:00] ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\Windows\system32\WLANExt.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\SMINST\scheduler.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Windows\System32\spoolsv.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\AEADISRV.EXE C:\Windows\system32\agrsmsvc.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Program Files\Kontiki\KService.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe C:\Program Files\PDF Complete\pdfsvc.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\CyberLink\Shared files\RichVideo.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Media Player\wmpnetwk.exe c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Users\James\Desktop\iexplore.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Users\James\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.co.uk/ mStart Page = about:blank mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\iftuyszv.exe, BHO: {52d76078-ff07-47d6-91b9-1964591fd6d4} - c:\windows\vovefgts.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: D: {801ecc10-aec2-3cec-adcb-d73ef73d3df4} - c:\windows\system32\xwr33588.dll BHO: {98dbbf16-ca43-4c33-be80-99e6694468a4} - No File BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll BHO: {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - No File TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll uRun: [MsnMsgr] "c:\program files\msn messenger\MsnMsgr.Exe" /background uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [avgnt] "c:\program files\avira\antivir personaledition classic\avgnt.exe" /min mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe" mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe" mRun: [DAEMON Tools] "c:\program files\daemon tools\daemon.exe" -lang 1033 mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe mRunOnce: [ST Recovery Launcher] %WINDIR%\SMINST\launcher.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Download all with Free Download Manager IE: Download selected with Free Download Manager IE: Download video with Free Download Manager IE: Download with Free Download Manager IE: Send image to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUplden-us.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Notify: igfxcui - igfxdev.dll ============= SERVICES / DRIVERS =============== R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};c:\program files\cyberlink\powerdvd\000.fcl [2007-9-19 41456] R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2006-4-14 28933976] R2 pdfcDispatcher;PDF Document Manager;c:\program files\pdf complete\pdfsvc.exe [2007-12-11 540448] R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2008-6-17 810320] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2006-11-2 167936] S3 DAMDrv;DAMDrv;c:\windows\system32\drivers\DAMDrv.sys [2007-12-11 30008] S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\system32\flcdlock.exe [2007-6-8 172131] =============== Created Last 30 ================ 2009-03-23 19:17 300 —shr– C:\autorun.inf 2009-03-11 14:59 80,936 a——- c:\windows\system32\drivers\btwavdt.sys 2009-03-11 14:59 80,424 a——- c:\windows\system32\drivers\btwaudio.sys 2009-03-11 14:59 16,168 a——- c:\windows\system32\drivers\btwrchid.sys 2009-03-11 14:59 233,472 a——- c:\windows\system32\BtwRSupport.dll 2009-03-11 14:58 –d—– c:\windows\system32\es-MX 2009-03-11 14:58 –d—– c:\windows\system32\es-AR 2009-03-11 14:38 54,824 ——– c:\windows\system32\agrsmdel.exe 2009-03-11 14:37 –d—– c:\windows\Options 2009-03-11 14:34 –d—– c:\windows\system32\no-NO 2009-03-11 14:26 –d—– C:\Intel 2009-03-11 14:04 1,904 ——– c:\windows\system32\SetupBD.din 2009-03-11 14:03 12,800 a——- c:\windows\HPNICVersion.dll 2009-03-11 11:48 8,147,456 a——- c:\windows\system32\wmploc.DLL 2009-03-11 11:48 7,680 a——- c:\windows\system32\spwmp.dll 2009-03-11 11:48 4,096 a——- c:\windows\system32\msdxm.ocx 2009-03-11 11:48 4,096 a——- c:\windows\system32\dxmasf.dll 2009-03-11 11:48 268,288 a——- c:\windows\system32\schannel.dll 2009-03-11 11:48 2,033,152 a——- c:\windows\system32\win32k.sys ==================== Find3M ==================== 2009-03-26 22:07 2,484 a——- c:\windows\bthservsdp.dat 2009-03-11 15:00 143,360 a——- c:\windows\inf\infstrng.dat 2009-03-11 15:00 51,200 a——- c:\windows\inf\infpub.dat 2009-03-11 15:00 86,016 a——- c:\windows\inf\infstor.dat 2009-03-05 11:29 16,648 a——- c:\windows\help\oem\scripts\HC_ProtectSmartPatch.exe 2009-01-30 17:24 14,600 a——- c:\windows\help\oem\scripts\HC_InstallHPHC.exe 2009-01-15 06:11 827,392 a——- c:\windows\system32\wininet.dll 2008-10-04 10:26 174 a–sh— c:\program files\desktop.ini 2008-10-04 10:12 665,600 a——- c:\windows\inf\drvindex.dat 2008-06-23 16:07 87,608 a——- c:\users\james\appdata\roaming\inst.exe 2008-06-23 16:07 47,360 a——- c:\users\james\appdata\roaming\pcouffin.sys 2006-11-02 12:39 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 12:39 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 12:39 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 12:39 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 09:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 09:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 09:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 09:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat 2008-06-14 00:07 16,384 a–sh— c:\windows\system32\config\systemprofile\appdata\local\microsoft\feeds cache\index.dat 2008-06-14 00:07 32,768 a–sh— c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008061420080615\index.dat 2007-12-11 11:36 8,192 a–sh— c:\windows\users\default\NTUSER.DAT ============= FINISH: 18:03:53.43 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-03-16.01) Microsoft® Windows Vista™ Home Basic Boot Device: \Device\HarddiskVolume1 Install Date: 12/06/2008 04:59:06 System Uptime: 27/03/2009 07:38:14 (11 hours ago) Motherboard: Hewlett-Packard | | 30D8 Processor: Intel® Celeron® CPU 550 @ 2.00GHz | U10 | 1997/133mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 140 GiB total, 38.326 GiB free. D: is CDROM () E: is FIXED (NTFS) - 2 GiB total, 1.316 GiB free. F: is FIXED (NTFS) - 7 GiB total, 6.161 GiB free. H: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP445: 20/03/2009 08:12:16 - Windows Update RP446: 21/03/2009 10:20:17 - Scheduled Checkpoint RP447: 22/03/2009 15:23:19 - Scheduled Checkpoint RP448: 24/03/2009 11:07:50 - Scheduled Checkpoint RP449: 25/03/2009 09:59:55 - Scheduled Checkpoint RP450: 25/03/2009 17:23:56 - Installed HP Active Support Library RP451: 26/03/2009 18:59:22 - Windows Update RP452: 27/03/2009 09:05:23 - Scheduled Checkpoint ==== Installed Programs ====================== 2007 Microsoft Office system 4oD Activation Assistant for the 2007 Microsoft Office suites ActiveCheck component for HP Active Support Library Activision® Ad-Aware Adobe Flash Player 10 ActiveX Adobe Shockwave Player 11 Agere Systems HDA Modem Application Installer 4.00.B14 µTorrent Avira AntiVir Personal - Free Antivirus BIOS Configuration for HP ProtectTools Business Contact Manager for Outlook 2007 ConvertXtoDVD [removed] Curse Client Device Access Manager for HP ProtectTools Driver Genius Porfessional Edition 2004 3.1.621 Drum Controller Standard Tuning Kit ESU for Microsoft Vista Football Manager 2008 Google Toolbar for Internet Explorer Google Updater Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) HP Active Support Library HP Active Support Library 32 bit components HP Backup & Recovery Manager Installer HP Customer Experience Enhancements HP Doc Viewer HP Easy Setup - Frontend HP Help and Support HP Integrated Module with Bluetooth wireless technology 6.0.1.6000 HP MULTIPLE MODEM INSTALLER for VISTA HP Notebook Accessories Product Tour HP ProtectTools Security Manager HP Quick Launch Buttons 6.40 B2 HP Total Care Advisor HP Update HP User Guides 0084 HP Wireless Assistant HPAsset component for HP Active Support Library HPNetworkAssistant Intel® Graphics Media Accelerator Driver Intel® PRO Network Connections Drivers InterVideo DVD Check InterVideo Register Manager InterVideo WinDVD Java™ SE Runtime Environment 6 Update 1 K-Lite Codec Pack 3.5.7 Full Karaoke CD+G Creator Pro LightScribe 1.6.43.1 LimeWire PRO 4.17.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB929729) Microsoft .NET Framework 3.5 SP1 Microsoft Office 2003 Web Components Microsoft Office 2007 Primary Interop Assemblies Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Professional Hybrid 2007 Microsoft Office Professional Plus 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Small Business Connectivity Components Microsoft Office Word MUI (English) 2007 Microsoft Save as PDF Add-in for 2007 Microsoft Office programs Microsoft SQL Server 2005 Microsoft SQL Server 2005 Express Edition (MSSMLBIZ) Microsoft SQL Server Native Client Microsoft SQL Server Setup Support Files (English) Microsoft SQL Server VSS Writer Microsoft Visual C++ 2005 Redistributable Microsoft Visual J# .NET Redistributable Package 1.1 MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB941833) MSXML 4.0 SP2 (KB954430) PDF Complete PowerDVD PowerDVD Ultra PowerISO Roxio Activation Module Roxio Creator Audio Roxio Creator Basic v9 Roxio Creator Copy Roxio Creator Data Roxio Creator Tools Roxio Express Labeler 3 Roxio MyDVD Basic v9 Roxio Update Manager Samsung Master Samsung USB Driver ShadowExplorer 0.2 Sonic CinePlayer Decoder Pack SopCast 3.0.3 SoundMAX Spybot - Search & Destroy Synaptics Pointing Device Driver TVUPlayer [removed] Vista Default Settings VLC media player 0.9.4 Windows Live Messenger WinRAR archiver World of Warcraft Your Uninstaller! 2008 Version 6.0 ==== Event Viewer Messages From Past Week ======== 20/03/2009 08:37:29, Error: Microsoft-Windows-DistributedCOM [10000] - Unable to start a DCOM Server: {0002DF01-0000-0000-C000-000000000046}. The error: "3" Happened while starting this command: "C:\Program Files\Internet Explorer\iexplore.exe" -Embedding 21/03/2009 23:03:45, Error: BTHUSB [17] - The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded. 25/03/2009 13:23:21, Error: iaStor [9] - The device, \Device\Ide\iaStor0, did not respond within the timeout period. ==== End Of File ===========================
Hi
We'll leave Gmer & come back to it later if we need to.

P2P Warning!
IMPORTANT I notice there are signs of one or more P2P (Person to Person) File Sharing Programs on your computer.

µTorrent | LimeWire PRO 4.17.1

Please note that as long as you are using any form of Peer-to-Peer networking and downloading files from non-documented sources, you can expect infestations of malware to occur.
P2P file sharing used to be fairly safe. That is no longer true. I'd like you to read the Perils of P2P File Sharing where we explain why it's not a good idea to have them.
References for the risk of these programs can be found in these links: http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm
See Clean/Infected P2P Programs here

I would recommend you go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red) & any other P2P programs.

Disable Spybot's TeaTimer 1.5 & 1.6
  • If you have version 1.5, right click the Spybot Icon in the system tray near the clock (looks like a blue/white calendar with a padlock symbol)
  • Click once on Resident Protection, then right click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless
  • Go to Start > All Programs > Spybot - Search & Destroy > Spybot Search & Destroy
  • Click on Mode > Advanced Mode. When it prompts you, click Yes
  • On the left hand side, click on Tools
  • Check this box if it is not yet ticked: Resident
  • You will notice that Resident is now added under Tools. Click on Resident
  • Uncheck this box: Resident "TeaTimer" (Protection of over-all system settings) active
  • Exit Spybot Search & Destroy
  • Restart your computer for the changes to take effect
Leave TeatTimer disabled until your machine is clean.

ATF Cleaner
Download ATF Cleaner here by Atribune.
Right-click on ATF-Cleaner.exe then choose Run as Administrator to run the program
Under Main choose: Select All
Click the Empty Selected button
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button
NOTE: If you would like to keep your saved passwords, please click No at the prompt
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button
NOTE: If you would like to keep your saved passwords, please click No at the prompt
Click Exit on the Main menu to close the program.

Combofix
Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

**IMPORTANT !!! Save ComboFix.exe to your Desktop**

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
    A guide to do this can be found here
  • Right click on ComboFix.exe then choose Run as Administrator & follow the prompts
  • When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply along with a new HijackThis log.
A word of warning: Neither I nor sUBs are responsible for any damage you may cause to your machine by running ComboFix on your own. This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


To post in next reply:
Combofix log
New HijackThis log
Here is the combofix log but you havent told me to DL Hijack this???

ComboFix 09-03-28.06 - James 2009-03-29 10:20:45.1 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.2039.1178 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
c:\programdata\Microsoft\Windows\Start Menu\Programs\PlayMe
c:\programdata\Microsoft\Windows\Start Menu\Programs\PlayMe\Uninstall.lnk
c:\recycler\S-1-3-43-100012441-100020970-100031095-4789.com
c:\temp\1cb
c:\temp\1cb\syscheck.log
c:\users\James\AppData\Roaming\inst.exe
c:\users\James\AppData\Roaming\Microsoft\dtsc
c:\users\James\AppData\Roaming\Microsoft\dtsc\s
c:\users\James\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PlayMe
c:\windows\astctl32.ocx
c:\windows\cpan.dll
c:\windows\ctfmon32.exe
c:\windows\ctrlpan.dll
c:\windows\directx32.exe
c:\windows\dnsrelay.dll
c:\windows\editpad.exe
c:\windows\explore.exe
c:\windows\explorer32.exe
c:\windows\funniest.exe
c:\windows\funny.exe
c:\windows\gfmnaaa.dll
c:\windows\helpcvs.exe
c:\windows\inetinf.exe
c:\windows\internet.exe
c:\windows\mainms.vpi
c:\windows\megavid.cdt
c:\windows\msconfd.dll
c:\windows\msspi.dll
c:\windows\mswsc10.dll
c:\windows\mswsc20.dll
c:\windows\muotr.so
c:\windows\qttasks.exe
c:\windows\quicken.exe
c:\windows\rundll16.exe
c:\windows\rundll32.vbe
c:\windows\searchword.dll
c:\windows\sistem.exe
c:\windows\svchost32.exe
c:\windows\svcinit.exe
c:\windows\system32\gaopdxcounter
c:\windows\system32\hljwugsf.bin
c:\windows\system32\x64
c:\windows\time.exe
c:\windows\waol.exe
E:\Autorun.inf
e:\recycler\S-1-3-43-100012441-100020970-100031095-4789.com
F:\Autorun.inf
f:\recycler\S-1-3-43-100012441-100020970-100031095-4789.com

.
((((((((((((((((((((((((( Files Created from 2009-02-28 to 2009-03-29 )))))))))))))))))))))))))))))))
.

2009-03-27 19:24 . 2009-03-27 19:24 264,870,366 –a—— c:\windows\MEMORY.DMP
2009-03-23 20:16 . 2009-03-23 20:16 d——– c:\users\James\AppData\Roaming\vlc
2009-03-11 15:59 . 2007-12-12 14:12 233,472 –a—— c:\windows\System32\BtwRSupport.dll
2009-03-11 15:59 . 2007-12-12 14:12 80,936 –a—— c:\windows\System32\drivers\btwavdt.sys
2009-03-11 15:59 . 2007-12-12 14:12 80,424 –a—— c:\windows\System32\drivers\btwaudio.sys
2009-03-11 15:59 . 2007-12-12 14:12 16,168 –a—— c:\windows\System32\drivers\btwrchid.sys
2009-03-11 15:58 . 2009-03-11 15:58 d——– c:\windows\System32\es-MX
2009-03-11 15:58 . 2009-03-11 15:58 d——– c:\windows\System32\es-AR
2009-03-11 15:38 . 2008-02-29 17:07 54,824 ——— c:\windows\System32\agrsmdel.exe
2009-03-11 15:37 . 2009-03-11 15:37 d——– c:\windows\Options
2009-03-11 15:34 . 2009-03-11 15:34 d——– c:\windows\System32\no-NO
2009-03-11 15:26 . 2009-03-11 15:26 d——– C:\Intel
2009-03-11 15:04 . 2006-01-12 15:52 1,904 ——— c:\windows\System32\SetupBD.din
2009-03-11 15:03 . 2007-09-27 18:28 12,800 –a—— c:\windows\HPNICVersion.dll
2009-03-11 12:48 . 2008-12-16 04:29 8,147,456 –a—— c:\windows\System32\wmploc.DLL
2009-03-11 12:48 . 2009-02-09 04:10 2,033,152 –a—— c:\windows\System32\win32k.sys
2009-03-11 12:48 . 2008-11-27 05:43 268,288 –a—— c:\windows\System32\schannel.dll
2009-03-11 12:48 . 2008-12-16 06:31 7,680 –a—— c:\windows\System32\spwmp.dll
2009-03-11 12:48 . 2008-12-16 06:31 4,096 –a—— c:\windows\System32\msdxm.ocx
2009-03-11 12:48 . 2008-12-16 06:31 4,096 –a—— c:\windows\System32\dxmasf.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-29 09:24 ——— d—–w c:\programdata\Kontiki
2009-03-29 08:41 ——— d—–w c:\programdata\Google Updater
2009-03-28 19:23 ——— d—–w c:\users\James\AppData\Roaming\uTorrent
2009-03-25 17:25 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-25 17:25 ——— d—–w c:\program files\Hewlett-Packard
2009-03-18 07:59 ——— d—–w c:\users\James\AppData\Roaming\Vso
2009-03-15 13:11 ——— d—–w c:\programdata\Roxio
2009-03-11 15:05 ——— d—–w c:\program files\Windows Mail
2009-03-11 15:02 ——— d—–w c:\users\James\AppData\Roaming\Hewlett-Packard
2009-03-11 14:37 ——— d—–w c:\users\James\AppData\Roaming\Hewlett Packard
2009-03-11 14:20 ——— d—–w c:\program files\Analog Devices
2009-03-11 14:06 ——— d—–w c:\programdata\Hewlett-Packard
2009-03-10 19:41 ——— d—–w c:\program files\Sports Interactive
2009-03-05 11:29 16,648 —-a-w c:\windows\Help\OEM\scripts\HC_ProtectSmartPatch.exe
2009-02-28 17:38 ——— d—–w c:\users\James\AppData\Roaming\BraCa_Soft
2009-02-28 17:27 ——— d—–w c:\program files\Free Download Manager
2009-02-28 17:25 ——— d—a-w c:\programdata\TEMP
2009-02-28 15:55 ——— d—–w c:\users\James\AppData\Roaming\LimeWire
2009-02-10 20:19 ——— d—–w c:\program files\Kontiki
2009-02-10 20:19 ——— d—–w c:\program files\Channel4
2009-02-10 20:18 ——— d—–w c:\programdata\Channel4
2009-01-30 17:24 14,600 —-a-w c:\windows\Help\OEM\scripts\HC_InstallHPHC.exe
2009-01-29 19:23 ——— d—–w c:\program files\Activision
2009-01-15 06:11 827,392 —-a-w c:\windows\System32\wininet.dll
2008-10-04 10:26 174 –sha-w c:\program files\desktop.ini
2008-06-23 16:07 47,360 —-a-w c:\users\James\AppData\Roaming\pcouffin.sys
2008-06-14 00:07 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Feeds Cache\index.dat
2008-06-14 00:07 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008061420080615\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-06-19 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-20 266497]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-03-14 54832]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2006-11-12 157592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-07 833072]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-10-03 480560]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-02-21 1183744]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-04-04 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-04-04 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-04-04 133656]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"ST Recovery Launcher"="c:\windows\SMINST\launcher.exe" [2007-06-06 44168]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-12-04 727592]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\iexplore.exe]
"Debugger"=c:\windows\system32\ropfnqz.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
–a—— 2007-02-21 15:14 1183744 c:\program files\Analog Devices\Core\smax4pnp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-03-14 12:43 83608 c:\program files\Java\jre1.6.0_01\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
–a—— 2008-06-19 19:49 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WatchDog]
–a—— 2007-05-23 11:00 192512 c:\program files\InterVideo\DVD Check\DVDCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1408827420-3023802417-3614498867-1006]
"EnableNotificationsRef"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{DE3F1BC4-50BB-4C6F-93EB-A5783DF3426F}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{1288F1AD-2AF2-41E8-8581-85E5C9AA7898}c:\\program files\\bitlord\\bitlord.exe"= UDP:c:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{B3EA6666-D1E3-4BE6-A96E-CAC412AE3F11}c:\\program files\\bitlord\\bitlord.exe"= TCP:c:\program files\bitlord\bitlord.exe:BitLord
"TCP Query User{81FBD5EA-20D7-4A7B-84DB-199C0A6F486C}c:\\program files\\bitlord\\bitlord.exe"= UDP:c:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{BD1A509A-4378-4663-87D3-E0CAD361D777}c:\\program files\\bitlord\\bitlord.exe"= TCP:c:\program files\bitlord\bitlord.exe:BitLord
"{A03D27F0-9EFD-4E49-979E-33AD9A6B8756}"= UDP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{B1DC532B-4BE3-49D3-AD3B-6B33469D9149}"= TCP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{879E0625-7B87-4706-8A3D-752B578DE69E}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{3C7855D2-404E-4AA4-876E-21374994D369}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{26A402A8-E076-4B5F-A0FD-4432F8BC98C4}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{812A05BB-039E-40B1-B892-36C478E1D61E}"= c:\program files\Cyberlink\PowerDVD\PowerDVD.EXE:CyberLink PowerDVD
"{F3B3668D-344E-4041-856E-1DE18F04132F}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{11D95C54-86F2-4C3B-8256-779549A2C5C5}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"TCP Query User{C7CACFA6-3D1C-4CB8-B6CB-B4126AFC14AB}c:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"UDP Query User{904EAE78-54AB-43CD-B8CA-AD4BCF568F01}c:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"TCP Query User{94619F90-0098-4FA4-8034-901563BF7C92}c:\\program files\\sopcast\\sopcast.exe"= UDP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"UDP Query User{8DE963EC-F76F-4C8E-8983-F1367EB17938}c:\\program files\\sopcast\\sopcast.exe"= TCP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"{D3E845FC-8226-4CE9-B2A3-2D8BEDCF144E}"= UDP:c:\program files\LucasArts\Star Wars Empire at War\GameData\sweaw.exe:Star Wars: Empire at War
"{3FDD37D8-8BBE-4EC1-86E2-27B42251C428}"= TCP:c:\program files\LucasArts\Star Wars Empire at War\GameData\sweaw.exe:Star Wars: Empire at War
"TCP Query User{CA1BE92A-DF6B-40A1-A07A-5987E1257488}c:\\program files\\tvuplayer\\tvuplayer.exe"= UDP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"UDP Query User{F9E6C729-0CCB-40B7-BBFA-C751035347D2}c:\\program files\\tvuplayer\\tvuplayer.exe"= TCP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"TCP Query User{70D7C39C-EC2E-4F2E-A867-69F41714A14F}c:\\program files\\uusee\\uuseeplayer.exe"= UDP:c:\program files\uusee\uuseeplayer.exe:UUPlayer
"UDP Query User{4128B5A2-BE18-45C4-A9FC-1CE4643636B4}c:\\program files\\uusee\\uuseeplayer.exe"= TCP:c:\program files\uusee\uuseeplayer.exe:UUPlayer
"{01030978-2F5B-4FD4-B1E7-F605F054C36A}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{0B15CCD5-4E6D-4E33-A9C0-BA8E1BBB2308}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{22C3B6E7-2F72-4525-A26F-F9CF0697B6B6}"= UDP:c:\program files\World of Warcraft\BackgroundDownloader.exe:Blizzard Downloader
"{674AAFDB-BFA2-474B-BD71-506CAC65F59D}"= TCP:c:\program files\World of Warcraft\BackgroundDownloader.exe:Blizzard Downloader
"{56D61AB5-1C3A-47F7-86DC-339584B40329}"= UDP:3724:Blizzard Downloader: 3724
"TCP Query User{B3CA796F-1889-48AC-8B09-3B16E359D8B1}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{8E14172A-23E1-4CDD-9607-924663ACD682}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{B2280B7F-CD33-4D79-A138-7403DF85C8ED}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{C9FB674F-19C6-4E01-B5C6-67BD2119FCF7}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{EA5CA11A-D30B-4BB8-9B85-7AF311514B55}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{EB2E103F-66A1-48CF-AA9F-0EF749CA15B4}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{FA322D19-1A2F-4ED3-997D-2EEF8980953F}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{5CDCE150-87EF-4307-BF17-E00FB6CBE0D1}"= UDP:c:\program files\Curse\CurseClient.exe:Curse Client
"{8A1767AF-8468-4366-9C0D-CE026FF376CF}"= TCP:c:\program files\Curse\CurseClient.exe:Curse Client
"{22610662-2A78-4A0C-A079-6E610C64029A}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{222BFFF0-542C-4D0F-B531-B1D8A09DA3A0}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{3FD2E66A-B65B-4A3C-BB67-2B6BC7FC0290}"= Disabled:UDP:c:\program files\Sports Interactive\Football Manager 2009 Demo\fm.exe:Football Manager 2009 Demo
"{EE2B182E-23DA-4F69-8474-C71BA7207C1C}"= Disabled:TCP:c:\program files\Sports Interactive\Football Manager 2009 Demo\fm.exe:Football Manager 2009 Demo
"{6891F999-401A-495B-B088-9947CA8747D6}"= UDP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009
"{5A83D648-5D55-4552-B09B-EA20B6B96F5B}"= TCP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009
"TCP Query User{8232B7EE-6D77-4E88-AA7C-3841F68221E8}c:\\users\\james\\desktop\\iexplore.exe"= UDP:c:\users\james\desktop\iexplore.exe:iexplore.exe
"UDP Query User{C00B7F16-F19B-4ABA-99B2-CDEE8F98B55B}c:\\users\\james\\desktop\\iexplore.exe"= TCP:c:\users\james\desktop\iexplore.exe:iexplore.exe
"{1B250390-287D-494F-9AD1-C4F93F463E29}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{F7C82CE3-1F57-4504-839C-ECD60CE261CC}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"TCP Query User{7771161D-4066-4266-BC73-E66076B5AB7E}c:\\program files\\kontiki\\khost.exe"= UDP:c:\program files\kontiki\khost.exe:Delivery Manager
"UDP Query User{627E00CA-46A3-4414-9524-B53C04383024}c:\\program files\\kontiki\\khost.exe"= TCP:c:\program files\kontiki\khost.exe:Delivery Manager
"{6BF78CB7-EFC6-4D5C-A0D9-1533429EFBBB}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{9BC99080-189F-4D50-A001-19265CF71C19}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{E4026D65-2359-4C0E-86CE-EEFD0F3C57F0}"= Disabled:UDP:c:\program files\Sports Interactive\Football Manager 2009 Beta\fm.exe:Football Manager 2009 Demo
"{2FDE9B55-66EC-43D2-B3FF-A3B1CE0E6C69}"= Disabled:TCP:c:\program files\Sports Interactive\Football Manager 2009 Beta\fm.exe:Football Manager 2009 Demo

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
"DoNotAllowExceptions"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\uusee\\UUSeePlayer.exe"= c:\program files\uusee\UUSeePlayer.exe:*:Enabled:UUPlayer

R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};c:\program files\CyberLink\PowerDVD\000.fcl [2007-09-19 21:37:48 41456]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2006-04-14 28933976]
R2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [2007-12-11 540448]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2008-06-17 810320]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [2006-11-02 167936]
S3 DAMDrv;DAMDrv;c:\windows\System32\drivers\DAMDrv.sys [2007-12-11 30008]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\System32\flcdlock.exe [2007-06-08 172131]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
\shell\AutoRun\command - I:\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2f94c601-38a3-11dd-bddb-001e37b4ca0e}]
\shell\AutoRun\command - H:\autorun.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder

2009-03-29 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 19:02]
.
- - - - ORPHANS REMOVED - - - -

BHO-{52d76078-ff07-47d6-91b9-1964591fd6d4} - c:\windows\vovefgts.dll
BHO-{801ECC10-AEC2-3CEC-ADCB-D73EF73D3DF4} - c:\windows\system32\xwr33588.dll


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
mStart Page = about:blank
IE: Download all with Free Download Manager
IE: Download selected with Free Download Manager
IE: Download video with Free Download Manager
IE: Download with Free Download Manager
IE: Send image to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-29 10:24:08
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-03-29 10:26:46
ComboFix-quarantined-files.txt 2009-03-29 09:26:44

Pre-Run: 41,196,834,816 bytes free
Post-Run: 41,212,301,312 bytes free

276 — E O F — 2009-03-26 19:00:13

Let me know about hijack this……….
Hi
Sorry… forgot you didn't have HijackThis. Don't worry about it, we wont need it.

I thought I saw Spybot's Search & Destroy's TeaTimer in one of your logs. If you have TeaTimer enabled we will need to disable it until your machine is clean as it may interfere with fixes:

Disable Spybot's TeaTimer 1.5 & 1.6
  • If you have version 1.5, right click the Spybot Icon in the system tray near the clock (looks like a blue/white calendar with a padlock symbol)
  • Click once on Resident Protection, then right click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless
  • Go to Start > All Programs > Spybot - Search & Destroy > Spybot Search & Destroy
  • Click on Mode > Advanced Mode. When it prompts you, click Yes
  • On the left hand side, click on Tools
  • Check this box if it is not yet ticked: Resident
  • You will notice that Resident is now added under Tools. Click on Resident
  • Uncheck this box: Resident "TeaTimer" (Protection of over-all system settings) active
  • Exit Spybot Search & Destroy
  • Restart your computer for the changes to take effect

CFScript
Close any open browsers.
Open notepad and copy/paste the text in the code box below into it:

Driver::
gaopdxserv
File::
c:\windows\system32\ropfnqz.exe
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\iexplore.exe]
"Debugger"=-
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"InternetSettingsDisableNotify"=dword:00000000
"AutoUpdateDisableNotify"=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000000
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2f94c601-38a3-11dd-bddb-001e37b4ca0e}]
Save this as CFScript.txt, in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at "C:\ComboFix.txt"
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
A word of warning: Neither I nor sUBs are responsible for any damage you may cause to your machine by running ComboFix on your own. This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


See if you can run Gmer again. Make sure you have your AV program temporarily disabled before starting the sacn & don't run any other programs during the scan. If you still have problems with Gmer then try this one:
RootRepeal
Download RootRepeal.zip from here & unzip it to your Desktop.
  • Double click RootRepeal.exe to start the program
  • Click the Report tab at the bottom of the program window
  • Click the Scan button
  • In the Select Scan dialog, check:
    • Drivers
      Files
      Processes
      SSDT
      Stealth Objects
      Hidden Services
  • Click the OK button
  • In the next dialog, select all drives showing
  • Click OK to start the scan
Note: The scan can take some time. DO NOT run any other programs while the scan is running
  • When the scan is complete, the Save Report button will become available
  • Click this and save the report to your Desktop as RootRepeal.txt
  • Go to File then Exit to close the program
To post in next reply:
Combofix log
Gmer log if possible otherwise RootRepeal log
Let me know how the computer is running / problems
ComboFix 09-03-28.06 - James 2009-03-29 15:31:57.2 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.2039.1285 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\James\Desktop\CFScript.txt.txt
* Created a new restore point

FILE ::
c:\windows\system32\ropfnqz.exe
.

((((((((((((((((((((((((( Files Created from 2009-02-28 to 2009-03-29 )))))))))))))))))))))))))))))))
.

2009-03-27 19:24 . 2009-03-27 19:24 264,870,366 –a—— c:\windows\MEMORY.DMP
2009-03-23 20:16 . 2009-03-23 20:16 d——– c:\users\James\AppData\Roaming\vlc
2009-03-11 15:59 . 2007-12-12 14:12 233,472 –a—— c:\windows\System32\BtwRSupport.dll
2009-03-11 15:59 . 2007-12-12 14:12 80,936 –a—— c:\windows\System32\drivers\btwavdt.sys
2009-03-11 15:59 . 2007-12-12 14:12 80,424 –a—— c:\windows\System32\drivers\btwaudio.sys
2009-03-11 15:59 . 2007-12-12 14:12 16,168 –a—— c:\windows\System32\drivers\btwrchid.sys
2009-03-11 15:58 . 2009-03-11 15:58 d——– c:\windows\System32\es-MX
2009-03-11 15:58 . 2009-03-11 15:58 d——– c:\windows\System32\es-AR
2009-03-11 15:38 . 2008-02-29 17:07 54,824 ——— c:\windows\System32\agrsmdel.exe
2009-03-11 15:37 . 2009-03-11 15:37 d——– c:\windows\Options
2009-03-11 15:34 . 2009-03-11 15:34 d——– c:\windows\System32\no-NO
2009-03-11 15:26 . 2009-03-11 15:26 d——– C:\Intel
2009-03-11 15:04 . 2006-01-12 15:52 1,904 ——— c:\windows\System32\SetupBD.din
2009-03-11 15:03 . 2007-09-27 18:28 12,800 –a—— c:\windows\HPNICVersion.dll
2009-03-11 12:48 . 2008-12-16 04:29 8,147,456 –a—— c:\windows\System32\wmploc.DLL
2009-03-11 12:48 . 2009-02-09 04:10 2,033,152 –a—— c:\windows\System32\win32k.sys
2009-03-11 12:48 . 2008-11-27 05:43 268,288 –a—— c:\windows\System32\schannel.dll
2009-03-11 12:48 . 2008-12-16 06:31 7,680 –a—— c:\windows\System32\spwmp.dll
2009-03-11 12:48 . 2008-12-16 06:31 4,096 –a—— c:\windows\System32\msdxm.ocx
2009-03-11 12:48 . 2008-12-16 06:31 4,096 –a—— c:\windows\System32\dxmasf.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-29 14:34 ——— d—–w c:\programdata\Kontiki
2009-03-29 08:41 ——— d—–w c:\programdata\Google Updater
2009-03-28 19:23 ——— d—–w c:\users\James\AppData\Roaming\uTorrent
2009-03-25 17:25 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-25 17:25 ——— d—–w c:\program files\Hewlett-Packard
2009-03-18 07:59 ——— d—–w c:\users\James\AppData\Roaming\Vso
2009-03-15 13:11 ——— d—–w c:\programdata\Roxio
2009-03-11 15:05 ——— d—–w c:\program files\Windows Mail
2009-03-11 15:02 ——— d—–w c:\users\James\AppData\Roaming\Hewlett-Packard
2009-03-11 14:37 ——— d—–w c:\users\James\AppData\Roaming\Hewlett Packard
2009-03-11 14:20 ——— d—–w c:\program files\Analog Devices
2009-03-11 14:06 ——— d—–w c:\programdata\Hewlett-Packard
2009-03-10 19:41 ——— d—–w c:\program files\Sports Interactive
2009-03-05 11:29 16,648 —-a-w c:\windows\Help\OEM\scripts\HC_ProtectSmartPatch.exe
2009-02-28 17:38 ——— d—–w c:\users\James\AppData\Roaming\BraCa_Soft
2009-02-28 17:27 ——— d—–w c:\program files\Free Download Manager
2009-02-28 17:25 ——— d—a-w c:\programdata\TEMP
2009-02-28 15:55 ——— d—–w c:\users\James\AppData\Roaming\LimeWire
2009-02-10 20:19 ——— d—–w c:\program files\Kontiki
2009-02-10 20:19 ——— d—–w c:\program files\Channel4
2009-02-10 20:18 ——— d—–w c:\programdata\Channel4
2009-01-30 17:24 14,600 —-a-w c:\windows\Help\OEM\scripts\HC_InstallHPHC.exe
2009-01-29 19:23 ——— d—–w c:\program files\Activision
2009-01-15 06:11 827,392 —-a-w c:\windows\System32\wininet.dll
2008-10-04 10:26 174 –sha-w c:\program files\desktop.ini
2008-06-23 16:07 47,360 —-a-w c:\users\James\AppData\Roaming\pcouffin.sys
2008-06-14 00:07 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Feeds Cache\index.dat
2008-06-14 00:07 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008061420080615\index.dat
.

((((((((((((((((((((((((((((( SnapShot@2009-03-29_10.24.49.33 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-03-29 08:40:44 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-03-29 09:24:25 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-03-29 09:24:25 262,144 —ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2009-03-29 08:40:39 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-03-29 09:24:20 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
- 2009-03-29 09:19:36 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-03-29 14:22:46 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-03-29 09:19:36 65,536 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-03-29 14:22:46 65,536 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-03-29 09:19:36 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-03-29 14:22:46 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-06-19 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-20 266497]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-03-14 54832]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2006-11-12 157592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-07 833072]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-10-03 480560]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-02-21 1183744]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-04-04 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-04-04 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-04-04 133656]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"ST Recovery Launcher"="c:\windows\SMINST\launcher.exe" [2007-06-06 44168]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-12-04 727592]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
–a—— 2007-02-21 15:14 1183744 c:\program files\Analog Devices\Core\smax4pnp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-03-14 12:43 83608 c:\program files\Java\jre1.6.0_01\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
–a—— 2008-06-19 19:49 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WatchDog]
–a—— 2007-05-23 11:00 192512 c:\program files\InterVideo\DVD Check\DVDCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1408827420-3023802417-3614498867-1006]
"EnableNotificationsRef"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{DE3F1BC4-50BB-4C6F-93EB-A5783DF3426F}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{1288F1AD-2AF2-41E8-8581-85E5C9AA7898}c:\\program files\\bitlord\\bitlord.exe"= UDP:c:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{B3EA6666-D1E3-4BE6-A96E-CAC412AE3F11}c:\\program files\\bitlord\\bitlord.exe"= TCP:c:\program files\bitlord\bitlord.exe:BitLord
"TCP Query User{81FBD5EA-20D7-4A7B-84DB-199C0A6F486C}c:\\program files\\bitlord\\bitlord.exe"= UDP:c:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{BD1A509A-4378-4663-87D3-E0CAD361D777}c:\\program files\\bitlord\\bitlord.exe"= TCP:c:\program files\bitlord\bitlord.exe:BitLord
"{A03D27F0-9EFD-4E49-979E-33AD9A6B8756}"= UDP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{B1DC532B-4BE3-49D3-AD3B-6B33469D9149}"= TCP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{879E0625-7B87-4706-8A3D-752B578DE69E}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{3C7855D2-404E-4AA4-876E-21374994D369}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{26A402A8-E076-4B5F-A0FD-4432F8BC98C4}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{812A05BB-039E-40B1-B892-36C478E1D61E}"= c:\program files\Cyberlink\PowerDVD\PowerDVD.EXE:CyberLink PowerDVD
"{F3B3668D-344E-4041-856E-1DE18F04132F}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{11D95C54-86F2-4C3B-8256-779549A2C5C5}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"TCP Query User{C7CACFA6-3D1C-4CB8-B6CB-B4126AFC14AB}c:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"UDP Query User{904EAE78-54AB-43CD-B8CA-AD4BCF568F01}c:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"TCP Query User{94619F90-0098-4FA4-8034-901563BF7C92}c:\\program files\\sopcast\\sopcast.exe"= UDP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"UDP Query User{8DE963EC-F76F-4C8E-8983-F1367EB17938}c:\\program files\\sopcast\\sopcast.exe"= TCP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"{D3E845FC-8226-4CE9-B2A3-2D8BEDCF144E}"= UDP:c:\program files\LucasArts\Star Wars Empire at War\GameData\sweaw.exe:Star Wars: Empire at War
"{3FDD37D8-8BBE-4EC1-86E2-27B42251C428}"= TCP:c:\program files\LucasArts\Star Wars Empire at War\GameData\sweaw.exe:Star Wars: Empire at War
"TCP Query User{CA1BE92A-DF6B-40A1-A07A-5987E1257488}c:\\program files\\tvuplayer\\tvuplayer.exe"= UDP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"UDP Query User{F9E6C729-0CCB-40B7-BBFA-C751035347D2}c:\\program files\\tvuplayer\\tvuplayer.exe"= TCP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"TCP Query User{70D7C39C-EC2E-4F2E-A867-69F41714A14F}c:\\program files\\uusee\\uuseeplayer.exe"= UDP:c:\program files\uusee\uuseeplayer.exe:UUPlayer
"UDP Query User{4128B5A2-BE18-45C4-A9FC-1CE4643636B4}c:\\program files\\uusee\\uuseeplayer.exe"= TCP:c:\program files\uusee\uuseeplayer.exe:UUPlayer
"{01030978-2F5B-4FD4-B1E7-F605F054C36A}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{0B15CCD5-4E6D-4E33-A9C0-BA8E1BBB2308}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{22C3B6E7-2F72-4525-A26F-F9CF0697B6B6}"= UDP:c:\program files\World of Warcraft\BackgroundDownloader.exe:Blizzard Downloader
"{674AAFDB-BFA2-474B-BD71-506CAC65F59D}"= TCP:c:\program files\World of Warcraft\BackgroundDownloader.exe:Blizzard Downloader
"{56D61AB5-1C3A-47F7-86DC-339584B40329}"= UDP:3724:Blizzard Downloader: 3724
"TCP Query User{B3CA796F-1889-48AC-8B09-3B16E359D8B1}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{8E14172A-23E1-4CDD-9607-924663ACD682}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{B2280B7F-CD33-4D79-A138-7403DF85C8ED}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{C9FB674F-19C6-4E01-B5C6-67BD2119FCF7}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{EA5CA11A-D30B-4BB8-9B85-7AF311514B55}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{EB2E103F-66A1-48CF-AA9F-0EF749CA15B4}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{FA322D19-1A2F-4ED3-997D-2EEF8980953F}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{5CDCE150-87EF-4307-BF17-E00FB6CBE0D1}"= UDP:c:\program files\Curse\CurseClient.exe:Curse Client
"{8A1767AF-8468-4366-9C0D-CE026FF376CF}"= TCP:c:\program files\Curse\CurseClient.exe:Curse Client
"{22610662-2A78-4A0C-A079-6E610C64029A}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{222BFFF0-542C-4D0F-B531-B1D8A09DA3A0}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{3FD2E66A-B65B-4A3C-BB67-2B6BC7FC0290}"= Disabled:UDP:c:\program files\Sports Interactive\Football Manager 2009 Demo\fm.exe:Football Manager 2009 Demo
"{EE2B182E-23DA-4F69-8474-C71BA7207C1C}"= Disabled:TCP:c:\program files\Sports Interactive\Football Manager 2009 Demo\fm.exe:Football Manager 2009 Demo
"{6891F999-401A-495B-B088-9947CA8747D6}"= UDP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009
"{5A83D648-5D55-4552-B09B-EA20B6B96F5B}"= TCP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009
"TCP Query User{8232B7EE-6D77-4E88-AA7C-3841F68221E8}c:\\users\\james\\desktop\\iexplore.exe"= UDP:c:\users\james\desktop\iexplore.exe:iexplore.exe
"UDP Query User{C00B7F16-F19B-4ABA-99B2-CDEE8F98B55B}c:\\users\\james\\desktop\\iexplore.exe"= TCP:c:\users\james\desktop\iexplore.exe:iexplore.exe
"{1B250390-287D-494F-9AD1-C4F93F463E29}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{F7C82CE3-1F57-4504-839C-ECD60CE261CC}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"TCP Query User{7771161D-4066-4266-BC73-E66076B5AB7E}c:\\program files\\kontiki\\khost.exe"= UDP:c:\program files\kontiki\khost.exe:Delivery Manager
"UDP Query User{627E00CA-46A3-4414-9524-B53C04383024}c:\\program files\\kontiki\\khost.exe"= TCP:c:\program files\kontiki\khost.exe:Delivery Manager
"{6BF78CB7-EFC6-4D5C-A0D9-1533429EFBBB}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{9BC99080-189F-4D50-A001-19265CF71C19}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{E4026D65-2359-4C0E-86CE-EEFD0F3C57F0}"= Disabled:UDP:c:\program files\Sports Interactive\Football Manager 2009 Beta\fm.exe:Football Manager 2009 Demo
"{2FDE9B55-66EC-43D2-B3FF-A3B1CE0E6C69}"= Disabled:TCP:c:\program files\Sports Interactive\Football Manager 2009 Beta\fm.exe:Football Manager 2009 Demo

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
"DoNotAllowExceptions"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\uusee\\UUSeePlayer.exe"= c:\program files\uusee\UUSeePlayer.exe:*:Enabled:UUPlayer

R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};c:\program files\CyberLink\PowerDVD\000.fcl [2007-09-19 21:37:48 41456]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2006-04-14 28933976]
R2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [2007-12-11 540448]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2008-06-17 810320]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [2006-11-02 167936]
S3 DAMDrv;DAMDrv;c:\windows\System32\drivers\DAMDrv.sys [2007-12-11 30008]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\System32\flcdlock.exe [2007-06-08 172131]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder

2009-03-29 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 19:02]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
mStart Page = about:blank
IE: Download all with Free Download Manager
IE: Download selected with Free Download Manager
IE: Download video with Free Download Manager
IE: Download with Free Download Manager
IE: Send image to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-29 15:34:57
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(1104)
c:\windows\system32\btmmhook.dll
.
Completion time: 2009-03-29 15:37:31
ComboFix-quarantined-files.txt 2009-03-29 14:37:25
ComboFix2.txt 2009-03-29 09:26:50

Pre-Run: 41,559,138,304 bytes free
Post-Run: 41,540,943,872 bytes free

233 — E O F — 2009-03-26 19:00:13

GMER 1.0.15.14966 - http://www.gmer.net
Rootkit scan 2009-03-29 15:48:38
Windows 6.0.6001 Service Pack 1


—- System - GMER 1.0.15 —-

SSDT A72D911C ZwCreateThread
SSDT A72D9108 ZwOpenProcess
SSDT A72D910D ZwOpenThread
SSDT A72D9117 ZwTerminateProcess
SSDT A72D9112 ZwWriteVirtualMemory

INT 0x51 ? 86442BF8
INT 0x51 ? 86442BF8
INT 0x62 ? 86442BF8
INT 0x72 ? 86442BF8
INT 0x82 ? 86442BF8
INT 0x92 ? 849C3BF8
INT 0xA2 ? 849C3BF8
INT 0xB2 ? 849C7BF8

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 849C91F8

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

Device \Driver\volmgr \Device\VolMgrControl 849C51F8
Device \Driver\usbuhci \Device\USBPDO-0 8625B1F8

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0016411f4ab6
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e37624c68
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e37b4ca0e
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e37b4ca0e@0018135f0d55 0x62 0x74 0xA3 0xB9 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e37b4ca0e@001d25f92e33 0xEE 0x8A 0x5D 0x80 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e37b4ca0e@001fccf7732e 0x21 0x9A 0x18 0x99 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xDA 0xC9 0x0F 0xB0 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x45 0xBE 0xC9 0x24 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x4E 0x41 0x58 0x29 …
Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\0016411f4ab6
Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\001e37624c68
Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\001e37b4ca0e
Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\001e37b4ca0e@0018135f0d55 0x62 0x74 0xA3 0xB9 …
Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\001e37b4ca0e@001d25f92e33 0xEE 0x8A 0x5D 0x80 …
Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\001e37b4ca0e@001fccf7732e 0x21 0x9A 0x18 0x99 …
Reg HKLM\SYSTEM\ControlSet004\Services\gaopdxserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet004\Services\gaopdxserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet004\Services\gaopdxserv.sys@imagepath \systemroot\system32\drivers\gaopdxvfwxgtbhtjmxppsxsrbojveopjmemixf.sys
Reg HKLM\SYSTEM\ControlSet004\Services\gaopdxserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet004\Services\gaopdxserv.sys\modules
Reg HKLM\SYSTEM\ControlSet004\Services\gaopdxserv.sys\modules@gaopdxserv \\?\globalroot\systemroot\system32\drivers\gaopdxvfwxgtbhtjmxppsxsrbojveopjmemixf.sys
Reg HKLM\SYSTEM\ControlSet004\Services\gaopdxserv.sys\modules@gaopdxl \\?\globalroot\systemroot\system32\gaopdxxiimmltxxqxbvxfcrypquspkbnonispe.dll
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xDA 0xC9 0x0F 0xB0 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x45 0xBE 0xC9 0x24 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x4E 0x41 0x58 0x29 …

—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 sector 01: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR

—- EOF - GMER 1.0.15 —-

Dont know if it worked or not to be honest.

Comp is running ok but is slightly slow.
CFScript
Close any open browsers.
Open notepad and copy/paste the text in the code box below into it:

Rootkit::
c:\windows\system32\drivers\gaopdxvfwxgtbhtjmxppsxsrbojveopjmemixf.sys
c:\windows\system32\gaopdxxiimmltxxqxbvxfcrypquspkbnonispe.dll
Driver::
gaopdxvfwxgtbhtjmxppsxsrbojveopjmemixf
RegLockDel::
[HKLM\SYSTEM\ControlSet004\Services\gaopdxserv.sys]
Save this as CFScript.txt, in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at "C:\ComboFix.txt"
Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
A word of warning: Neither I nor sUBs are responsible for any damage you may cause to your machine by running ComboFix on your own. This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


MBR.exe
Download mbr.exe from here & save to your desktop.
  • Right-click the file, choose Run as Administrator to run the scan (a window will open briefly, then close)
  • The scan will create a mbr.log on your desktop - copy/paste those contents in your next reply
Run Gmer again & post the contents of the log.

Update Java Runtime
You are using an old version of Java. Sun's Java is sometimes updated in order to eliminate the exploitation of vulnerabilities in an existing version. For this reason, it's extremely important that you keep the program up to date, & also remove the older more vulnerable versions from your system. The most current version of Sun Java is: Java Runtime Environment Version 6 Update 13.
  • Download the latest version of Java Runtime Environment (JRE) 6 Here
  • Scroll down to where it says "Java SE Runtime Environment (JRE) 6 Update 13. The Java SE Runtime Environment (JRE) allows end-users to run Java applications."
  • Click the Download button to the right
  • Select the Windows platform from the dropdown menu
  • Read the License Agreement and then check the box that says: "I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue.The page will refresh
  • Click on the link to download Windows Offline Installation & save the file to your desktop
  • Close any programs you may have running - especially your web browser
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs & remove all older versions of Java
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions
  • Reboot your computer once all Java components are removed
  • Then from your desktop double-click on jre-6u13-windows-i586-p.exe to install the newest version
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel
Run ATF-Cleaner again.

Kaspersky Online Scan
Close your Internet browser then right-click & select Run As Administrator to re-open & run it
Go to Kaspersky website and perform an online antivirus scan
  • Read through the requirements and privacy statement and click on Accept button
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run
  • When the downloads have finished, click on Settings
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan
  • Once the scan is complete, it will display the results. Click on View Scan Report
  • You will see a list of infected items there. Click on Save Report As…
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply
To post in next reply:
Combofix log
MBR log
Gmer log
Kaspersky Scan log
ComboFix 09-03-28.06 - James 2009-03-30 17:41:24.3 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.2039.1166 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\James\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-02-28 to 2009-03-30 )))))))))))))))))))))))))))))))
.

2009-03-27 19:24 . 2009-03-27 19:24 264,870,366 –a—— c:\windows\MEMORY.DMP
2009-03-23 20:16 . 2009-03-23 20:16 d——– c:\users\James\AppData\Roaming\vlc
2009-03-11 15:59 . 2007-12-12 14:12 233,472 –a—— c:\windows\System32\BtwRSupport.dll
2009-03-11 15:59 . 2007-12-12 14:12 80,936 –a—— c:\windows\System32\drivers\btwavdt.sys
2009-03-11 15:59 . 2007-12-12 14:12 80,424 –a—— c:\windows\System32\drivers\btwaudio.sys
2009-03-11 15:59 . 2007-12-12 14:12 16,168 –a—— c:\windows\System32\drivers\btwrchid.sys
2009-03-11 15:58 . 2009-03-11 15:58 d——– c:\windows\System32\es-MX
2009-03-11 15:58 . 2009-03-11 15:58 d——– c:\windows\System32\es-AR
2009-03-11 15:38 . 2008-02-29 17:07 54,824 ——— c:\windows\System32\agrsmdel.exe
2009-03-11 15:37 . 2009-03-11 15:37 d——– c:\windows\Options
2009-03-11 15:34 . 2009-03-11 15:34 d——– c:\windows\System32\no-NO
2009-03-11 15:26 . 2009-03-11 15:26 d——– C:\Intel
2009-03-11 15:04 . 2006-01-12 15:52 1,904 ——— c:\windows\System32\SetupBD.din
2009-03-11 15:03 . 2007-09-27 18:28 12,800 –a—— c:\windows\HPNICVersion.dll
2009-03-11 12:48 . 2008-12-16 04:29 8,147,456 –a—— c:\windows\System32\wmploc.DLL
2009-03-11 12:48 . 2009-02-09 04:10 2,033,152 –a—— c:\windows\System32\win32k.sys
2009-03-11 12:48 . 2008-11-27 05:43 268,288 –a—— c:\windows\System32\schannel.dll
2009-03-11 12:48 . 2008-12-16 06:31 7,680 –a—— c:\windows\System32\spwmp.dll
2009-03-11 12:48 . 2008-12-16 06:31 4,096 –a—— c:\windows\System32\msdxm.ocx
2009-03-11 12:48 . 2008-12-16 06:31 4,096 –a—— c:\windows\System32\dxmasf.dll
2009-02-11 19:33 . 2009-01-15 04:36 1,383,424 –a—— c:\windows\System32\mshtml.tlb
2009-02-11 19:33 . 2009-01-15 07:11 827,392 –a—— c:\windows\System32\wininet.dll
2009-02-11 17:20 . 2009-02-24 23:33 d——– C:\Downloads
2009-02-10 21:19 . 2009-03-30 17:44 d——– c:\users\All Users\Kontiki
2009-02-10 21:19 . 2009-03-30 17:44 d——– c:\programdata\Kontiki
2009-02-10 21:19 . 2009-02-10 21:19 d——– c:\program files\Kontiki
2009-02-10 21:19 . 2009-02-10 21:19 d——– c:\program files\Channel4
2009-02-10 21:18 . 2009-02-10 21:18 d——– c:\users\All Users\Channel4
2009-02-10 21:18 . 2009-02-10 21:18 d——– c:\programdata\Channel4

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-30 16:34 ——— d—–w c:\programdata\Google Updater
2009-03-28 19:23 ——— d—–w c:\users\James\AppData\Roaming\uTorrent
2009-03-25 17:25 ——— d–h–w c:\program files\InstallShield Installation Information
2009-03-25 17:25 ——— d—–w c:\program files\Hewlett-Packard
2009-03-18 07:59 ——— d—–w c:\users\James\AppData\Roaming\Vso
2009-03-15 13:11 ——— d—–w c:\programdata\Roxio
2009-03-11 15:05 ——— d—–w c:\program files\Windows Mail
2009-03-11 15:02 ——— d—–w c:\users\James\AppData\Roaming\Hewlett-Packard
2009-03-11 14:37 ——— d—–w c:\users\James\AppData\Roaming\Hewlett Packard
2009-03-11 14:20 ——— d—–w c:\program files\Analog Devices
2009-03-11 14:06 ——— d—–w c:\programdata\Hewlett-Packard
2009-03-10 19:41 ——— d—–w c:\program files\Sports Interactive
2009-03-05 11:29 16,648 —-a-w c:\windows\Help\OEM\scripts\HC_ProtectSmartPatch.exe
2009-02-28 17:38 ——— d—–w c:\users\James\AppData\Roaming\BraCa_Soft
2009-02-28 17:27 ——— d—–w c:\program files\Free Download Manager
2009-02-28 17:25 ——— d—a-w c:\programdata\TEMP
2009-02-28 15:55 ——— d—–w c:\users\James\AppData\Roaming\LimeWire
2009-01-30 17:24 14,600 —-a-w c:\windows\Help\OEM\scripts\HC_InstallHPHC.exe
2009-01-29 19:23 ——— d—–w c:\program files\Activision
2008-10-04 10:26 174 –sha-w c:\program files\desktop.ini
2008-06-23 16:07 47,360 —-a-w c:\users\James\AppData\Roaming\pcouffin.sys
2008-06-14 00:07 16,384 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Feeds Cache\index.dat
2008-06-14 00:07 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008061420080615\index.dat
.

((((((((((((((((((((((((((((( SnapShot@2009-03-29_10.24.49.33 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-03-28 21:31:56 2,484 —-a-w c:\windows\bthservsdp.dat
+ 2009-03-30 16:44:15 2,484 —-a-w c:\windows\bthservsdp.dat
- 2009-03-29 08:40:44 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-03-30 16:45:31 262,144 –sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-03-30 16:45:31 262,144 —ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2009-03-29 08:40:39 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-03-30 16:45:31 262,144 –sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-03-30 16:45:31 262,144 —ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2009-03-29 09:19:36 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-03-30 16:45:46 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-03-29 09:19:36 65,536 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-03-30 16:45:46 65,536 –sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-03-29 09:19:36 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-03-30 16:45:46 32,768 –sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-03-29 08:43:39 126,468 —-a-w c:\windows\System32\perfc009.dat
+ 2009-03-30 16:38:23 127,908 —-a-w c:\windows\System32\perfc009.dat
- 2009-03-29 08:43:39 656,878 —-a-w c:\windows\System32\perfh009.dat
+ 2009-03-30 16:38:23 658,318 —-a-w c:\windows\System32\perfh009.dat
- 2009-03-29 08:41:19 9,514 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1408827420-3023802417-3614498867-1006_UserData.bin
+ 2009-03-30 16:34:02 9,514 —-a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1408827420-3023802417-3614498867-1006_UserData.bin
- 2009-03-29 08:41:19 112,872 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-03-30 16:34:02 113,098 —-a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-03-29 08:41:17 47,964 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-03-30 16:33:56 47,964 —-a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-06-19 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-20 266497]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-03-14 54832]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2006-11-12 157592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-06-07 833072]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-10-03 480560]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-02-21 1183744]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-04-04 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-04-04 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-04-04 133656]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"ST Recovery Launcher"="c:\windows\SMINST\launcher.exe" [2007-06-06 44168]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-12-04 727592]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
–a—— 2007-02-21 15:14 1183744 c:\program files\Analog Devices\Core\smax4pnp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-03-14 12:43 83608 c:\program files\Java\jre1.6.0_01\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
–a—— 2008-06-19 19:49 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WatchDog]
–a—— 2007-05-23 11:00 192512 c:\program files\InterVideo\DVD Check\DVDCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1408827420-3023802417-3614498867-1006]
"EnableNotificationsRef"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{DE3F1BC4-50BB-4C6F-93EB-A5783DF3426F}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{1288F1AD-2AF2-41E8-8581-85E5C9AA7898}c:\\program files\\bitlord\\bitlord.exe"= UDP:c:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{B3EA6666-D1E3-4BE6-A96E-CAC412AE3F11}c:\\program files\\bitlord\\bitlord.exe"= TCP:c:\program files\bitlord\bitlord.exe:BitLord
"TCP Query User{81FBD5EA-20D7-4A7B-84DB-199C0A6F486C}c:\\program files\\bitlord\\bitlord.exe"= UDP:c:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{BD1A509A-4378-4663-87D3-E0CAD361D777}c:\\program files\\bitlord\\bitlord.exe"= TCP:c:\program files\bitlord\bitlord.exe:BitLord
"{A03D27F0-9EFD-4E49-979E-33AD9A6B8756}"= UDP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{B1DC532B-4BE3-49D3-AD3B-6B33469D9149}"= TCP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{879E0625-7B87-4706-8A3D-752B578DE69E}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{3C7855D2-404E-4AA4-876E-21374994D369}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{26A402A8-E076-4B5F-A0FD-4432F8BC98C4}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{812A05BB-039E-40B1-B892-36C478E1D61E}"= c:\program files\Cyberlink\PowerDVD\PowerDVD.EXE:CyberLink PowerDVD
"{F3B3668D-344E-4041-856E-1DE18F04132F}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{11D95C54-86F2-4C3B-8256-779549A2C5C5}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"TCP Query User{C7CACFA6-3D1C-4CB8-B6CB-B4126AFC14AB}c:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"UDP Query User{904EAE78-54AB-43CD-B8CA-AD4BCF568F01}c:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"TCP Query User{94619F90-0098-4FA4-8034-901563BF7C92}c:\\program files\\sopcast\\sopcast.exe"= UDP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"UDP Query User{8DE963EC-F76F-4C8E-8983-F1367EB17938}c:\\program files\\sopcast\\sopcast.exe"= TCP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"{D3E845FC-8226-4CE9-B2A3-2D8BEDCF144E}"= UDP:c:\program files\LucasArts\Star Wars Empire at War\GameData\sweaw.exe:Star Wars: Empire at War
"{3FDD37D8-8BBE-4EC1-86E2-27B42251C428}"= TCP:c:\program files\LucasArts\Star Wars Empire at War\GameData\sweaw.exe:Star Wars: Empire at War
"TCP Query User{CA1BE92A-DF6B-40A1-A07A-5987E1257488}c:\\program files\\tvuplayer\\tvuplayer.exe"= UDP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"UDP Query User{F9E6C729-0CCB-40B7-BBFA-C751035347D2}c:\\program files\\tvuplayer\\tvuplayer.exe"= TCP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"TCP Query User{70D7C39C-EC2E-4F2E-A867-69F41714A14F}c:\\program files\\uusee\\uuseeplayer.exe"= UDP:c:\program files\uusee\uuseeplayer.exe:UUPlayer
"UDP Query User{4128B5A2-BE18-45C4-A9FC-1CE4643636B4}c:\\program files\\uusee\\uuseeplayer.exe"= TCP:c:\program files\uusee\uuseeplayer.exe:UUPlayer
"{01030978-2F5B-4FD4-B1E7-F605F054C36A}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{0B15CCD5-4E6D-4E33-A9C0-BA8E1BBB2308}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{22C3B6E7-2F72-4525-A26F-F9CF0697B6B6}"= UDP:c:\program files\World of Warcraft\BackgroundDownloader.exe:Blizzard Downloader
"{674AAFDB-BFA2-474B-BD71-506CAC65F59D}"= TCP:c:\program files\World of Warcraft\BackgroundDownloader.exe:Blizzard Downloader
"{56D61AB5-1C3A-47F7-86DC-339584B40329}"= UDP:3724:Blizzard Downloader: 3724
"TCP Query User{B3CA796F-1889-48AC-8B09-3B16E359D8B1}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{8E14172A-23E1-4CDD-9607-924663ACD682}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{B2280B7F-CD33-4D79-A138-7403DF85C8ED}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{C9FB674F-19C6-4E01-B5C6-67BD2119FCF7}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{EA5CA11A-D30B-4BB8-9B85-7AF311514B55}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{EB2E103F-66A1-48CF-AA9F-0EF749CA15B4}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{FA322D19-1A2F-4ED3-997D-2EEF8980953F}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{5CDCE150-87EF-4307-BF17-E00FB6CBE0D1}"= UDP:c:\program files\Curse\CurseClient.exe:Curse Client
"{8A1767AF-8468-4366-9C0D-CE026FF376CF}"= TCP:c:\program files\Curse\CurseClient.exe:Curse Client
"{22610662-2A78-4A0C-A079-6E610C64029A}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{222BFFF0-542C-4D0F-B531-B1D8A09DA3A0}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{3FD2E66A-B65B-4A3C-BB67-2B6BC7FC0290}"= Disabled:UDP:c:\program files\Sports Interactive\Football Manager 2009 Demo\fm.exe:Football Manager 2009 Demo
"{EE2B182E-23DA-4F69-8474-C71BA7207C1C}"= Disabled:TCP:c:\program files\Sports Interactive\Football Manager 2009 Demo\fm.exe:Football Manager 2009 Demo
"{6891F999-401A-495B-B088-9947CA8747D6}"= UDP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009
"{5A83D648-5D55-4552-B09B-EA20B6B96F5B}"= TCP:c:\program files\Sports Interactive\Football Manager 2009\fm.exe:Football Manager 2009
"TCP Query User{8232B7EE-6D77-4E88-AA7C-3841F68221E8}c:\\users\\james\\desktop\\iexplore.exe"= UDP:c:\users\james\desktop\iexplore.exe:iexplore.exe
"UDP Query User{C00B7F16-F19B-4ABA-99B2-CDEE8F98B55B}c:\\users\\james\\desktop\\iexplore.exe"= TCP:c:\users\james\desktop\iexplore.exe:iexplore.exe
"{1B250390-287D-494F-9AD1-C4F93F463E29}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{F7C82CE3-1F57-4504-839C-ECD60CE261CC}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"TCP Query User{7771161D-4066-4266-BC73-E66076B5AB7E}c:\\program files\\kontiki\\khost.exe"= UDP:c:\program files\kontiki\khost.exe:Delivery Manager
"UDP Query User{627E00CA-46A3-4414-9524-B53C04383024}c:\\program files\\kontiki\\khost.exe"= TCP:c:\program files\kontiki\khost.exe:Delivery Manager
"{6BF78CB7-EFC6-4D5C-A0D9-1533429EFBBB}"= UDP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{9BC99080-189F-4D50-A001-19265CF71C19}"= TCP:c:\program files\Kontiki\KService.exe:Delivery Manager Service
"{E4026D65-2359-4C0E-86CE-EEFD0F3C57F0}"= Disabled:UDP:c:\program files\Sports Interactive\Football Manager 2009 Beta\fm.exe:Football Manager 2009 Demo
"{2FDE9B55-66EC-43D2-B3FF-A3B1CE0E6C69}"= Disabled:TCP:c:\program files\Sports Interactive\Football Manager 2009 Beta\fm.exe:Football Manager 2009 Demo

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
"DoNotAllowExceptions"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\uusee\\UUSeePlayer.exe"= c:\program files\uusee\UUSeePlayer.exe:*:Enabled:UUPlayer

R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};c:\program files\CyberLink\PowerDVD\000.fcl [2007-09-19 21:37:48 41456]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2006-04-14 28933976]
R2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [2007-12-11 540448]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2008-06-17 810320]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [2006-11-02 167936]
S3 DAMDrv;DAMDrv;c:\windows\System32\drivers\DAMDrv.sys [2007-12-11 30008]
S3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\System32\flcdlock.exe [2007-06-08 172131]

— Other Services/Drivers In Memory —

*Deregistered* - sptd

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder

2009-03-30 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 19:02]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
mStart Page = about:blank
IE: Download all with Free Download Manager
IE: Download selected with Free Download Manager
IE: Download video with Free Download Manager
IE: Download with Free Download Manager
IE: Send image to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-30 17:46:02
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(1952)
c:\windows\system32\btmmhook.dll
c:\windows\system32\btncopy.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\audiodg.exe
c:\windows\System32\wlanext.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\windows\SMINST\Scheduler.exe
c:\windows\System32\igfxsrvc.exe
c:\windows\System32\AEADISRV.EXE
c:\windows\System32\agrsmsvc.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\WIDCOMM\Bluetooth Software\BTStackServer.exe
c:\program files\Kontiki\KService.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\System32\wbem\unsecapp.exe
c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
c:\windows\System32\wbem\WMIADAP.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2009-03-30 17:52:16 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-30 16:51:49
ComboFix2.txt 2009-03-29 14:37:32
ComboFix3.txt 2009-03-29 09:26:50

Pre-Run: 40,700,719,104 bytes free
Post-Run: 40,665,792,512 bytes free

279 — E O F — 2009-03-30 16:37:03

Stealth MBR rootkit detector 0.2.4 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK

GMER 1.0.15.14966 - http://www.gmer.net
Rootkit scan 2009-03-30 18:57:34
Windows 6.0.6001 Service Pack 1


—- System - GMER 1.0.15 —-

SSDT A674EE7C ZwCreateThread
SSDT A674EE68 ZwOpenProcess
SSDT A674EE6D ZwOpenThread
SSDT A674EE77 ZwTerminateProcess
SSDT A674EE72 ZwWriteVirtualMemory

INT 0x51 ? 861F9BF8
INT 0x51 ? 861F9BF8
INT 0x62 ? 861F9BF8
INT 0x72 ? 861F9BF8
INT 0x82 ? 861F9BF8
INT 0x92 ? 849BFBF8
INT 0xA2 ? 849BFBF8
INT 0xB2 ? 849C3BF8

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 849C51F8

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)

Device \Driver\volmgr \Device\VolMgrControl 849C11F8
Device \Driver\usbuhci \Device\USBPDO-0 862241F8
Device \FileSystem\cdfs \Cdfs 86BC9500

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0016411f4ab6
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e37624c68
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e37b4ca0e
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e37b4ca0e@0018135f0d55 0x62 0x74 0xA3 0xB9 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e37b4ca0e@001d25f92e33 0xEE 0x8A 0x5D 0x80 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001e37b4ca0e@001fccf7732e 0x21 0x9A 0x18 0x99 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xDA 0xC9 0x0F 0xB0 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x45 0xBE 0xC9 0x24 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x4E 0x41 0x58 0x29 …
Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\0016411f4ab6
Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\001e37624c68
Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\001e37b4ca0e
Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\001e37b4ca0e@0018135f0d55 0x62 0x74 0xA3 0xB9 …
Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\001e37b4ca0e@001d25f92e33 0xEE 0x8A 0x5D 0x80 …
Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\001e37b4ca0e@001fccf7732e 0x21 0x9A 0x18 0x99 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xDA 0xC9 0x0F 0xB0 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x45 0xBE 0xC9 0x24 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x4E 0x41 0x58 0x29 …

—- Files - GMER 1.0.15 —-

File C:\Windows\System32\LogFiles\HTTPERR\httperr1.log (size mismatch) 25755/25429 bytes
File C:\Windows\System32\WDI\LogFiles\WdiContextLog.etl.001 (size mismatch) 425984/393216 bytes

—- EOF - GMER 1.0.15 —-


——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Tuesday, March 31, 2009
Operating System: Microsoft Windows Vista Home Basic Edition, 32-bit Service Pack 1 (build 6001)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, March 30, 2009 22:36:40
Records in database: 1987911
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\

Scan statistics:
Files scanned: 210792
Threat name: 1
Infected objects: 3
Suspicious objects: 0
Duration of the scan: 01:56:58


File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\RECYCLER\S-1-3-43-100012441-100020970-100031095-4789.com.vir Infected: Trojan.Win32.Tdss.uyx 1
C:\Qoobox\Quarantine\E\RECYCLER\S-1-3-43-100012441-100020970-100031095-4789.com.vir Infected: Trojan.Win32.Tdss.uyx 1
C:\Qoobox\Quarantine\F\RECYCLER\S-1-3-43-100012441-100020970-100031095-4789.com.vir Infected: Trojan.Win32.Tdss.uyx 1

The selected area was scanned.

Ill wait to hear from you……….

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI