This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Antivirus xp 2009 issues

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
I recently had a problem with this virus and I think I've made some progress getting rid of it. I've got rid of the pop-ups and I've gotten my desktop back. However I still only have partial access to my task manager, (I'm missing the buttons on the top), and any program I start shuts down 30 seconds later. This is only a problem on my account. If I log on with another username there is no problem. Any ideas?




Malwarebytes' Anti-Malware 1.35
Database version: 1904
Windows 5.1.2600 Service Pack 3

3/27/2009 9:16:16 AM
mbam-log-2009-03-27 (09-16-16).txt

Scan type: Quick Scan
Objects scanned: 98029
Time elapsed: 5 minute(s), 39 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:09:11 AM, on 3/27/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\WINDOWS\system32\lxcecoms.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {4137c42f-b388-455e-90d5-3882a3a84db7} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [amd_dc_opt] "C:\Program Files\AMD\amd_dc_opt\amd_dc_opt.exe"
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QUICKCARE] C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe /P QUICKCARE
O4 - HKLM\..\Run: [LXCECATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools\daemon.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe -silent
O4 - HKCU\..\Run: [Universal Installer] "C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe" /fromrun /starthidden
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O8 - Extra context menu item: &Search - ?p=ZRfox000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.2.2.89.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service (lavasoft ad-aware service) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: PC Tools Auxiliary Service (sdauxservice) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdcoreservice) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\

–
End of file - 7521 bytes
Hi meanween, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

When using this tool, please hold the shift key down while connecting the USB device. This will prevent it from autorunning.

Please run the program enough times to ensure All your USB devices have been connected to the computer.

Do not use any USB devices until we have cleaned the computer. We will clean the USB devices last.

Download Flash_Disinfector.exe by sUBs and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
Reboot your computer when done.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder…it will help protect your drives from future infection.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

For your TaskManager, try this. Open taskmanager, double click on it anywhere outside the window. Let me know if the tabs are back.

Please post back with
  • combofix log
  • new HJT log
  • how many USB devices you have

Thanks
Hi,
The task manager fix worked. Thanks.

I have 2 mp3 players (flash drives).

Logs below, Thanks.



ComboFix 09-03-27.02 - Dan 2009-03-28 1:17:17.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1482 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
c:\windows\update1i.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_ICF
——-\Service_PCIDump


((((((((((((((((((((((((( Files Created from 2009-02-28 to 2009-03-28 )))))))))))))))))))))))))))))))
.

2009-03-28 00:47 . 2009-03-28 00:47 d——– c:\documents and settings\All Users\Application Data\Electronic Arts
2009-03-27 10:01 . 2009-03-27 10:01 d——– c:\program files\Trend Micro
2009-03-27 08:24 . 2009-03-27 08:24 d——– c:\documents and settings\Carmen\Application Data\Malwarebytes
2009-03-27 03:04 . 2009-03-09 13:06 15,688 –a—— c:\windows\system32\lsdelete.exe
2009-03-27 02:47 . 2009-03-09 13:06 64,160 –a—— c:\windows\system32\drivers\Lbd.sys
2009-03-27 02:38 . 2009-03-27 02:46 d–h-c— c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-03-27 00:42 . 2009-03-27 00:42 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2009-03-26 22:19 . 2009-03-27 01:29 d——– c:\program files\Malwarebytes' Anti-Malware
2009-03-26 22:19 . 2009-03-26 22:19 d——– c:\documents and settings\Dan\Application Data\Malwarebytes
2009-03-26 22:19 . 2009-03-26 22:19 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-26 22:19 . 2009-03-26 16:49 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-26 22:19 . 2009-03-26 16:49 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-03-26 17:59 . 2008-12-11 08:38 159,600 –a—— c:\windows\system32\drivers\pctgntdi.sys
2009-03-26 17:58 . 2009-03-27 00:42 d——– c:\program files\Common Files\PC Tools
2009-03-26 17:58 . 2009-03-06 16:45 130,424 –a—— c:\windows\system32\drivers\PCTCore.sys
2009-03-26 17:58 . 2008-12-18 12:16 73,840 –a—— c:\windows\system32\drivers\PCTAppEvent.sys
2009-03-26 17:58 . 2008-12-10 12:36 64,392 –a—— c:\windows\system32\drivers\pctplsg.sys
2009-03-26 16:45 . 2009-03-26 16:45 d——– c:\documents and settings\Administrator
2009-03-26 16:17 . 2009-03-27 00:42 d——– c:\program files\Spyware Doctor
2009-03-26 16:17 . 2009-03-26 16:17 d——– c:\documents and settings\Dan\Application Data\PC Tools
2009-03-26 16:17 . 2009-03-26 16:17 d——– c:\documents and settings\All Users\Application Data\PC Tools
2009-03-26 16:09 . 2009-03-26 16:09 74,240 –a—— c:\windows\system32\zlib.dll
2009-03-26 15:47 . 2009-03-26 15:47 280,079 ——— c:\windows\system32\0375ea37675ad8f762dae5f7b9f6dc1c.TMP
2009-03-26 15:47 . 2009-03-26 15:47 94,208 –ahs—- c:\windows\ADF6B.exe
2009-03-26 15:47 . 2009-03-28 01:25 88,428 –a—— c:\windows\system32\drivers\332e0944.sys
2009-03-26 15:47 . 2009-03-26 15:47 31,744 –a—— C:\meki.exe
2009-03-26 15:47 . 2009-03-26 15:47 296 –ahs—- c:\windows\system\sdtr.sys
2009-03-26 15:47 . 2009-03-26 15:47 2 –a—— C:\-327958491
2009-03-24 13:22 . 2009-03-24 13:21 410,984 –a—— c:\windows\system32\deploytk.dll
2009-03-24 13:22 . 2009-03-24 13:21 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-03-21 17:15 . 2009-03-21 17:15 94,208 –a—— c:\windows\DIIUnin.exe
2009-03-21 17:15 . 2009-03-21 17:22 35,119 –a—— c:\windows\DIIUnin.dat
2009-03-21 17:15 . 2009-03-21 17:15 2,829 –a—— c:\windows\DIIUnin.pif
2009-03-12 22:34 . 2009-03-24 13:32 54,156 –ah—– c:\windows\QTFont.qfn
2009-03-12 22:34 . 2009-03-12 22:34 1,409 –a—— c:\windows\QTFont.for
2009-03-07 23:05 . 2009-03-07 23:05 d——– c:\program files\KingsIsle Entertainment
2009-03-04 16:00 . 2008-08-14 04:11 2,189,184 —–c— c:\windows\system32\dllcache\ntoskrnl.exe
2009-03-04 16:00 . 2008-08-14 04:09 2,145,280 —–c— c:\windows\system32\dllcache\ntkrnlmp.exe
2009-03-04 15:59 . 2008-08-14 03:33 2,066,048 —–c— c:\windows\system32\dllcache\ntkrnlpa.exe
2009-03-04 15:59 . 2008-08-14 03:33 2,023,936 —–c— c:\windows\system32\dllcache\ntkrpamp.exe
2009-03-04 15:59 . 2008-10-24 05:21 455,296 —–c— c:\windows\system32\dllcache\mrxsmb.sys
2009-03-04 15:59 . 2008-10-15 10:34 337,408 —–c— c:\windows\system32\dllcache\netapi32.dll
2009-03-04 15:59 . 2008-12-11 04:57 333,952 —–c— c:\windows\system32\dllcache\srv.sys
2009-03-04 15:47 . 2009-03-04 15:47 d——– c:\windows\system32\scripting
2009-03-04 15:47 . 2009-03-04 15:47 d——– c:\windows\system32\en
2009-03-04 15:47 . 2009-03-04 15:47 d——– c:\windows\system32\bits
2009-03-04 15:47 . 2009-03-04 15:47 d——– c:\windows\l2schemas
2009-03-04 15:44 . 2009-03-04 15:44 d——– c:\windows\ServicePackFiles
2009-03-04 15:36 . 2009-03-04 15:36 d——– c:\windows\EHome

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-27 08:46 ——— d—–w c:\program files\Lavasoft
2009-03-27 08:44 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2009-03-27 07:24 ——— d—–w c:\program files\Diablo II
2009-03-27 06:42 ——— d—–w c:\program files\MSN Messenger
2009-03-26 22:25 ——— d—–w c:\program files\Spybot - Search & Destroy
2009-03-26 21:50 ——— d—–w c:\documents and settings\Dan\Application Data\uTorrent
2009-03-24 19:59 ——— d—–w c:\documents and settings\Carmen\Application Data\LimeWire
2009-03-24 19:22 ——— d—–w c:\program files\LimeWire
2009-03-24 19:21 ——— d—–w c:\program files\Java
2009-03-24 04:10 ——— d—–w c:\program files\Lx_cats
2009-03-21 21:59 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-25 14:45 ——— d—–w c:\program files\Microsoft Games
2009-02-25 14:41 ——— d—–w c:\documents and settings\All Users\Application Data\2Wire
2009-02-21 18:37 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-02-21 18:37 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-02-21 18:28 ——— d—–w c:\program files\Qwest
2009-02-21 18:16 ——— d—–w c:\documents and settings\Dan\Application Data\2Wire
2009-02-21 05:52 ——— d—–w c:\program files\Phun
2009-02-20 23:56 ——— d—–w c:\program files\Microsoft Games for Windows - LIVE
2009-02-19 00:10 ——— d—–w c:\program files\Ubisoft
2008-11-08 00:06 75,512 —-a-w c:\documents and settings\Carmen\Application Data\GDIPFONTCACHEV1.DAT
2008-04-28 13:44 21 —-a-w c:\program files\Common Files\appop.log
2008-01-03 04:45 22,328 —-a-w c:\documents and settings\Dan\Application Data\PnkBstrK.sys
2007-03-10 01:47 22,040 —-a-w c:\documents and settings\Collin J\Application Data\GDIPFONTCACHEV1.DAT
2006-10-05 00:47 22,040 —-a-w c:\documents and settings\Dan\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools\daemon.exe" [2007-12-15 482760]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-03-18 3325952]
"Universal Installer"="c:\program files\ComcastUI\Universal Installer\uinstaller.exe" [2008-03-18 984616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"amd_dc_opt"="c:\program files\AMD\amd_dc_opt\amd_dc_opt.exe" [2006-06-28 106496]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-21 1601304]
"QUICKCARE"="c:\program files\Qwest\QuickCare\bin\sprtcmd.exe" [2007-05-09 198800]
"LXCECATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll" [2005-07-20 73728]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-24 136600]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]

c:\documents and settings\Carmen\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2008-02-25 3450608]

c:\documents and settings\Collin J\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2008-01-19 225280]

c:\documents and settings\M to the Y\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-03-10 139776]

c:\documents and settings\Dan\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2008-02-25 3450608]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-21 12:37 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.X264"= x264vfw.dll
"VIDC.3iv2"= 3ivxVfWCodec.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lavasoft ad-aware service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
–a—— 2006-01-02 17:41 45056 c:\program files\ATI Technologies\ATI.ACE\CLI.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
——— 2004-12-02 18:23 102400 c:\program files\Creative\MediaSource\Detector\CTDetect.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzPrint]
–a—— 2005-07-26 06:17 94208 c:\program files\Lexmark 4300 Series\ezprint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer]
–a—— 2005-07-12 03:36 299008 c:\program files\Lexmark Fax Solutions\fm3032.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2006-06-14 16:24 278528 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxcemon.exe]
–a—— 2005-08-02 11:45 192512 c:\program files\Lexmark 4300 Series\lxcemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2008-04-13 18:12 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-06-08 02:27 282624 c:\program files\K-Lite Codec Pack\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
–a—— 2009-02-21 12:35 1410296 c:\program files\Valve\Steam\steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2005-11-10 13:03 36975 c:\program files\Java\jre1.5.0_06\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
——— 2000-05-11 01:00 90112 c:\windows\Updreg.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WINCINEMAMGR]
–a—— 2005-01-21 02:47 270336 c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
–a—— 2005-08-07 16:10 16384 c:\windows\CTHELPER.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTxfiHlp]
–a—— 2005-08-07 16:10 18944 c:\windows\system32\CTXFIHLP.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\LucasArts\\Star Wars Empire at War\\GameData\\fpupdate.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\meanween\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\LucasArts\\SWKotOR2\\swupdate.exe"=
"c:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"=
"c:\\Program Files\\THQ\\Dawn of War\\W40k.exe"=
"c:\\Program Files\\THQ\\Dawn of War\\W40kWA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Stardock Games\\Sins of a Solar Empire\\Sins of a Solar Empire.exe"=
"c:\\Program Files\\THQ\\Dawn of War - Soulstorm\\Soulstorm.exe"=
"c:\\Program Files\\Sony\\EverQuest II\\LaunchPad.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\dawn of war 2\\DOW2.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard1
"6112:TCP"= 6112:TCP:blizzard2

R0 lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-03-27 64160]
R0 pctcore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-03-26 130424]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-06-23 325128]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-21 298264]
R3 AmdTools;AMD Special Tools Driver;c:\windows\system32\drivers\AmdTools.sys [2006-10-09 31744]
S3 lavasoft ad-aware service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-09 951632]
S3 mbamswissarmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-03-26 38496]
S3 sdauxservice;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-03-26 348752]

— Other Services/Drivers In Memory —

*Deregistered* - sfc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
\Shell\AutoRun\command - autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\autorun.exe
.
Contents of the 'Scheduled Tasks' folder

2009-03-27 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 13:06]
.
- - - - ORPHANS REMOVED - - - -

BHO-{4137c42f-b388-455e-90d5-3882a3a84db7} - (no file)
HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKLM-Run-SpyHunter Security Suite - c:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe
Notify-dimsntfy - (no file)
Notify-wgalogon - (no file)
MSConfigStartUp-tgcmd - c:\program files\Support.com\bin\tgcmd.exe


.
——- Supplementary Scan ——-
.
uStart Page =
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &Search - ?p=ZRfox000
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Dan\Application Data\Mozilla\Firefox\Profiles\vls5eq4y.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net?cid=NET_mmhpset
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - plugin: c:\program files\IGN\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-28 01:25:14
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCECATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\332e0944]
"ImagePath"="\SystemRoot\System32\drivers\332e0944.sys"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\s-1-5-21-1202660629-362288127-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:d7,2e,d5,09,43,6b,8a,2f,f7,84,3e,2d,54,82,bf,d0,e1,3f,cc,17,07,
a2,0c,ce,8c,91,9b,ea,c2,5f,39,f2,75,79,54,b7,89,b7,71,03,e6,af,b7,02,6b,b4,\
"rkeysecu"=hex:0c,01,85,43,d9,94,1a,d5,71,29,87,48,26,17,d9,45
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(916)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\UAService7.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\lxcecoms.exe
.
**************************************************************************
.
Completion time: 2009-03-28 1:31:08 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-28 07:31:05

Pre-Run: 6,841,335,808 bytes free
Post-Run: 6,802,702,336 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
304 — E O F — 2009-03-15 09:03:45






Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:34:13 AM, on 3/28/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Electronic Arts\EADM\Core.exe
C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\WINDOWS\system32\lxcecoms.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [amd_dc_opt] "C:\Program Files\AMD\amd_dc_opt\amd_dc_opt.exe"
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QUICKCARE] C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe /P QUICKCARE
O4 - HKLM\..\Run: [LXCECATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools\daemon.exe"
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [Universal Installer] "C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe" /fromrun /starthidden
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O8 - Extra context menu item: &Search - ?p=ZRfox000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.2.2.89.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service (lavasoft ad-aware service) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: PC Tools Auxiliary Service (sdauxservice) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdcoreservice) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\

–
End of file - 7085 bytes
Hi meanween,

Limewire
You have Limewire, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554

I would recommend that you uninstall Limewire, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.




Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE
Do Not copy the word CODE

File::
c:\windows\system32\0375ea37675ad8f762dae5f7b9f6dc1c.TMP
c:\windows\ADF6B.exe
c:\windows\system32\drivers\332e0944.sys
C:\meki.exe
c:\windows\system\sdtr.sys
C:\-327958491

Registry::

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]





Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :regfind
    wuauserv
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Please post back with
  • combofix log
  • SystemLook log
  • new HJT log obtained last.

How's the computer?

Thanks
Hi,
Limewire has been removed.

Update on the computer:
Any program I start, (web browser, game, ect) closes after about 30 seconds, very frustrating.
The desktop disappears then reappears on its own, (this is without me doing anything). Same
with the start bar. It has spread to all users now, not just my logon.

Here's the logs.

Thanks for your help.




SystemLook v1.0 by jpshortstuff (02.03.09)
Log created at 12:40 on 28/03/2009 by Dan (Administrator - Elevation successful)

========== regfind ==========

Searching for "wuauserv"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\wuauserv]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WUAUSERV]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WUAUSERV\0000]
""Service""=="wuauserv"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WUAUSERV\0000]
""Service""=="wuauserv"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WUAUSERV\0000]
""Service""=="wuauserv"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WUAUSERV\0000]
""Service""=="wuauserv"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wuauserv]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wuauserv\Parameters]
""ServiceDll""=="C:\WINDOWS\system32\wuauserv.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wuauserv\Enum]
""0""=="Root\LEGACY_WUAUSERV\0000"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\wuauserv]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\wuauserv\Parameters]
""ServiceDll""=="C:\WINDOWS\system32\wuauserv.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_WUAUSERV]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_WUAUSERV\0000]
""Service""=="wuauserv"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_WUAUSERV\0000]
""Service""=="wuauserv"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_WUAUSERV\0000]
""Service""=="wuauserv"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_WUAUSERV\0000]
""Service""=="wuauserv"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\wuauserv]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\wuauserv\Parameters]
""ServiceDll""=="C:\WINDOWS\system32\wuauserv.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WUAUSERV]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WUAUSERV\0000]
""Service""=="wuauserv"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WUAUSERV\0000]
""Service""=="wuauserv"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WUAUSERV\0000]
""Service""=="wuauserv"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WUAUSERV\0000]
""Service""=="wuauserv"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters]
""ServiceDll""=="C:\WINDOWS\system32\wuauserv.dll"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum]
""0""=="Root\LEGACY_WUAUSERV\0000"

-=End Of File=-







ComboFix 09-03-27.02 - Dan 2009-03-28 12:24:02.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1537 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Dan\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point

FILE ::
C:\-327958491
C:\meki.exe
c:\windows\ADF6B.exe
c:\windows\system\sdtr.sys
c:\windows\system32\0375ea37675ad8f762dae5f7b9f6dc1c.TMP
c:\windows\system32\drivers\332e0944.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\-327958491
C:\meki.exe
c:\windows\ADF6B.exe
c:\windows\system\sdtr.sys
c:\windows\system32\0375ea37675ad8f762dae5f7b9f6dc1c.TMP
c:\windows\system32\drivers\332e0944.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_332e0944


((((((((((((((((((((((((( Files Created from 2009-02-28 to 2009-03-28 )))))))))))))))))))))))))))))))
.

2009-03-28 00:47 . 2009-03-28 00:47 d——– c:\documents and settings\All Users\Application Data\Electronic Arts
2009-03-27 10:01 . 2009-03-27 10:01 d——– c:\program files\Trend Micro
2009-03-27 08:24 . 2009-03-27 08:24 d——– c:\documents and settings\Carmen\Application Data\Malwarebytes
2009-03-27 03:04 . 2009-03-09 13:06 15,688 –a—— c:\windows\system32\lsdelete.exe
2009-03-27 02:47 . 2009-03-09 13:06 64,160 –a—— c:\windows\system32\drivers\Lbd.sys
2009-03-27 02:38 . 2009-03-27 02:46 d–h-c— c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-03-27 00:42 . 2009-03-27 00:42 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2009-03-26 22:19 . 2009-03-27 01:29 d——– c:\program files\Malwarebytes' Anti-Malware
2009-03-26 22:19 . 2009-03-26 22:19 d——– c:\documents and settings\Dan\Application Data\Malwarebytes
2009-03-26 22:19 . 2009-03-26 22:19 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-26 22:19 . 2009-03-26 16:49 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-26 22:19 . 2009-03-26 16:49 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-03-26 17:59 . 2008-12-11 08:38 159,600 –a—— c:\windows\system32\drivers\pctgntdi.sys
2009-03-26 17:58 . 2009-03-27 00:42 d——– c:\program files\Common Files\PC Tools
2009-03-26 17:58 . 2009-03-06 16:45 130,424 –a—— c:\windows\system32\drivers\PCTCore.sys
2009-03-26 17:58 . 2008-12-18 12:16 73,840 –a—— c:\windows\system32\drivers\PCTAppEvent.sys
2009-03-26 17:58 . 2008-12-10 12:36 64,392 –a—— c:\windows\system32\drivers\pctplsg.sys
2009-03-26 16:45 . 2009-03-26 16:45 d——– c:\documents and settings\Administrator
2009-03-26 16:17 . 2009-03-27 00:42 d——– c:\program files\Spyware Doctor
2009-03-26 16:17 . 2009-03-26 16:17 d——– c:\documents and settings\Dan\Application Data\PC Tools
2009-03-26 16:17 . 2009-03-26 16:17 d——– c:\documents and settings\All Users\Application Data\PC Tools
2009-03-26 16:09 . 2009-03-26 16:09 74,240 –a—— c:\windows\system32\zlib.dll
2009-03-24 13:22 . 2009-03-24 13:21 410,984 –a—— c:\windows\system32\deploytk.dll
2009-03-24 13:22 . 2009-03-24 13:21 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-03-21 17:15 . 2009-03-21 17:15 94,208 –a—— c:\windows\DIIUnin.exe
2009-03-21 17:15 . 2009-03-21 17:22 35,119 –a—— c:\windows\DIIUnin.dat
2009-03-21 17:15 . 2009-03-21 17:15 2,829 –a—— c:\windows\DIIUnin.pif
2009-03-12 22:34 . 2009-03-24 13:32 54,156 –ah—– c:\windows\QTFont.qfn
2009-03-12 22:34 . 2009-03-12 22:34 1,409 –a—— c:\windows\QTFont.for
2009-03-07 23:05 . 2009-03-07 23:05 d——– c:\program files\KingsIsle Entertainment
2009-03-04 16:00 . 2008-08-14 04:11 2,189,184 —–c— c:\windows\system32\dllcache\ntoskrnl.exe
2009-03-04 16:00 . 2008-08-14 04:09 2,145,280 —–c— c:\windows\system32\dllcache\ntkrnlmp.exe
2009-03-04 15:59 . 2008-08-14 03:33 2,066,048 —–c— c:\windows\system32\dllcache\ntkrnlpa.exe
2009-03-04 15:59 . 2008-08-14 03:33 2,023,936 —–c— c:\windows\system32\dllcache\ntkrpamp.exe
2009-03-04 15:59 . 2008-10-24 05:21 455,296 —–c— c:\windows\system32\dllcache\mrxsmb.sys
2009-03-04 15:59 . 2008-10-15 10:34 337,408 —–c— c:\windows\system32\dllcache\netapi32.dll
2009-03-04 15:59 . 2008-12-11 04:57 333,952 —–c— c:\windows\system32\dllcache\srv.sys
2009-03-04 15:47 . 2009-03-04 15:47 d——– c:\windows\system32\scripting
2009-03-04 15:47 . 2009-03-04 15:47 d——– c:\windows\system32\en
2009-03-04 15:47 . 2009-03-04 15:47 d——– c:\windows\system32\bits
2009-03-04 15:47 . 2009-03-04 15:47 d——– c:\windows\l2schemas
2009-03-04 15:44 . 2009-03-04 15:44 d——– c:\windows\ServicePackFiles
2009-03-04 15:36 . 2009-03-04 15:36 d——– c:\windows\EHome

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-28 18:19 ——— d—–w c:\program files\LimeWire
2009-03-27 08:46 ——— d—–w c:\program files\Lavasoft
2009-03-27 08:44 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2009-03-27 07:24 ——— d—–w c:\program files\Diablo II
2009-03-27 06:42 ——— d—–w c:\program files\MSN Messenger
2009-03-26 22:25 ——— d—–w c:\program files\Spybot - Search & Destroy
2009-03-26 21:50 ——— d—–w c:\documents and settings\Dan\Application Data\uTorrent
2009-03-24 19:59 ——— d—–w c:\documents and settings\Carmen\Application Data\LimeWire
2009-03-24 19:21 ——— d—–w c:\program files\Java
2009-03-24 04:10 ——— d—–w c:\program files\Lx_cats
2009-03-21 21:59 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-25 14:45 ——— d—–w c:\program files\Microsoft Games
2009-02-25 14:41 ——— d—–w c:\documents and settings\All Users\Application Data\2Wire
2009-02-21 18:37 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-02-21 18:37 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-02-21 18:28 ——— d—–w c:\program files\Qwest
2009-02-21 18:16 ——— d—–w c:\documents and settings\Dan\Application Data\2Wire
2009-02-21 05:52 ——— d—–w c:\program files\Phun
2009-02-20 23:56 ——— d—–w c:\program files\Microsoft Games for Windows - LIVE
2009-02-19 00:10 ——— d—–w c:\program files\Ubisoft
2008-11-08 00:06 75,512 —-a-w c:\documents and settings\Carmen\Application Data\GDIPFONTCACHEV1.DAT
2008-04-28 13:44 21 —-a-w c:\program files\Common Files\appop.log
2008-01-03 04:45 22,328 —-a-w c:\documents and settings\Dan\Application Data\PnkBstrK.sys
2007-03-10 01:47 22,040 —-a-w c:\documents and settings\Collin J\Application Data\GDIPFONTCACHEV1.DAT
2006-10-05 00:47 22,040 —-a-w c:\documents and settings\Dan\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((( SnapShot@2009-03-28_ 1.30.09.23 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-28 18:31:47 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_730.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools\daemon.exe" [2007-12-15 482760]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-03-18 3325952]
"Universal Installer"="c:\program files\ComcastUI\Universal Installer\uinstaller.exe" [2008-03-18 984616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"amd_dc_opt"="c:\program files\AMD\amd_dc_opt\amd_dc_opt.exe" [2006-06-28 106496]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-21 1601304]
"QUICKCARE"="c:\program files\Qwest\QuickCare\bin\sprtcmd.exe" [2007-05-09 198800]
"LXCECATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll" [2005-07-20 73728]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-24 136600]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]

c:\documents and settings\Carmen\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2008-02-25 3450608]

c:\documents and settings\Collin J\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2008-01-19 225280]

c:\documents and settings\Dan\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2008-02-25 3450608]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-21 12:37 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.X264"= x264vfw.dll
"VIDC.3iv2"= 3ivxVfWCodec.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lavasoft ad-aware service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
–a—— 2006-01-02 17:41 45056 c:\program files\ATI Technologies\ATI.ACE\CLI.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
——— 2004-12-02 18:23 102400 c:\program files\Creative\MediaSource\Detector\CTDetect.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzPrint]
–a—— 2005-07-26 06:17 94208 c:\program files\Lexmark 4300 Series\ezprint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer]
–a—— 2005-07-12 03:36 299008 c:\program files\Lexmark Fax Solutions\fm3032.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2006-06-14 16:24 278528 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxcemon.exe]
–a—— 2005-08-02 11:45 192512 c:\program files\Lexmark 4300 Series\lxcemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2008-04-13 18:12 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-06-08 02:27 282624 c:\program files\K-Lite Codec Pack\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
–a—— 2009-02-21 12:35 1410296 c:\program files\Valve\Steam\steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2005-11-10 13:03 36975 c:\program files\Java\jre1.5.0_06\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
——— 2000-05-11 01:00 90112 c:\windows\Updreg.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WINCINEMAMGR]
–a—— 2005-01-21 02:47 270336 c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
–a—— 2005-08-07 16:10 16384 c:\windows\CTHELPER.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTxfiHlp]
–a—— 2005-08-07 16:10 18944 c:\windows\system32\CTXFIHLP.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LucasArts\\Star Wars Empire at War\\GameData\\fpupdate.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\meanween\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\LucasArts\\SWKotOR2\\swupdate.exe"=
"c:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"=
"c:\\Program Files\\THQ\\Dawn of War\\W40k.exe"=
"c:\\Program Files\\THQ\\Dawn of War\\W40kWA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Stardock Games\\Sins of a Solar Empire\\Sins of a Solar Empire.exe"=
"c:\\Program Files\\THQ\\Dawn of War - Soulstorm\\Soulstorm.exe"=
"c:\\Program Files\\Sony\\EverQuest II\\LaunchPad.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\dawn of war 2\\DOW2.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard1
"6112:TCP"= 6112:TCP:blizzard2

R0 lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-03-27 64160]
R0 pctcore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-03-26 130424]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-06-23 325128]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-21 298264]
R3 AmdTools;AMD Special Tools Driver;c:\windows\system32\drivers\AmdTools.sys [2006-10-09 31744]
S3 lavasoft ad-aware service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-09 951632]
S3 mbamswissarmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-03-26 38496]
S3 sdauxservice;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-03-26 348752]

— Other Services/Drivers In Memory —

*Deregistered* - sfc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\autorun.exe
.
Contents of the 'Scheduled Tasks' folder

2009-03-27 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 13:06]
.
.
——- Supplementary Scan ——-
.
uStart Page =
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &Search - ?p=ZRfox000
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Dan\Application Data\Mozilla\Firefox\Profiles\vls5eq4y.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net?cid=NET_mmhpset
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - plugin: c:\program files\IGN\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-28 12:32:13
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCECATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1202660629-362288127-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:d7,2e,d5,09,43,6b,8a,2f,f7,84,3e,2d,54,82,bf,d0,e1,3f,cc,17,07,
a2,0c,ce,8c,91,9b,ea,c2,5f,39,f2,75,79,54,b7,89,b7,71,03,e6,af,b7,02,6b,b4,\
"rkeysecu"=hex:0c,01,85,43,d9,94,1a,d5,71,29,87,48,26,17,d9,45
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(892)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\UAService7.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\lxcecoms.exe
.
**************************************************************************
.
Completion time: 2009-03-28 12:38:19 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-28 18:38:15
ComboFix2.txt 2009-03-28 07:31:10

Pre-Run: 6,819,807,232 bytes free
Post-Run: 6,823,280,640 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
294 — E O F — 2009-03-15 09:03:45







Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:50:28 PM, on 3/28/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Electronic Arts\EADM\Core.exe
C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\WINDOWS\system32\lxcecoms.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\imapi.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [amd_dc_opt] "C:\Program Files\AMD\amd_dc_opt\amd_dc_opt.exe"
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QUICKCARE] C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe /P QUICKCARE
O4 - HKLM\..\Run: [LXCECATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools\daemon.exe"
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [Universal Installer] "C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe" /fromrun /starthidden
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O8 - Extra context menu item: &Search - ?p=ZRfox000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.2.2.89.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service (lavasoft ad-aware service) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: PC Tools Auxiliary Service (sdauxservice) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdcoreservice) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\

–
End of file - 7117 bytes
Hi

Open hijackthis, do a system scan only and checkmark these lines, if present

O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\


Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.

This is not the legitamte Window update.

Reboot. Is the computer any better?

Re run HJT. Is the line still gone?

Thanks
Hi, I did as instructed and upon reboot the computer still has same problems and After running HJT the line is still there. Thanks
Hi, Also every time my desktop or taskbar disappears the process "imapi.exe" pops up in my task manager and the disappears. Thanks
Hi meanween,

Either HJT was unable to disable the service or something restarted it.

We'll remove this reg key

REGISTRY FIX

REGEDIT4

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]

Next you will need to create the repair registry fix to do that copy and paste ALL of the above in the quote box to a notepad file. Ensure there is no space above the REGEDIT4.
Then in notepad go to FILE > SAVE AS and in the dropdown box, set the top box SAVE IN to DESKTOP
Then in the FILE NAME box type (including the " " marks), "fix.reg"

Click save.

This will create a fix.reg file on your desktop with this icon [external image: Posted Image]


To use this file you will need to right click the icon and select merge, accept the warning if it appears and you are done.




Let's do this in safe mode.

First download this program, get the free one. This program has been able to deal with symptoms like yours.

Download superantispyware

Double click to install it. Just update it for now. After the updates are installed, close the program.

Please print out or copy and save these instructions into a notepad and save it to your desktop for reference while in safe mode.

Please then reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, a menu with options should appear;
Select the first option, to run Windows in Safe Mode, then press "Enter".
Choose your usual account.

once in safe mode


  • Click the Start button, then click Run.
  • In the run box, copy and paste services.msc and click OK.
  • In the window that opens locate Automatic Updates right click it and select Properties
  • On the General Tab find the section titled Startup Type. Use the dropdown menu and select Disabled.
  • Click Apply, Click OK
  • Close the sevices window

Next
SAS up like this.

Under Configuration and Preferences, click the Preferences button.
Then click the Scanning Control tab.

Under Scanner Options make sure the following are checked
- CHECK ALL BOXES

-Return to the main page by clicking close on that screen.
-On the main screen, under Scan for Harmful Software click Scan your computer. On the left check C:\Fixed Drive.(and other fixed drives)
-Under Complete Scan, choose Perform Complete Scan.
- Click Next to start the scan.

When the scan is done, quarentine everything found . Reboot if asked.

Please post back with
  • SaS log
  • new HJT log

Thanks
Hi,
I did everything as directed however when I tried to change automatic updates to disabled it said Access Denied
and wouldn't let me change it. I continued with the rest of the steps.

Thanks



SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 03/28/2009 at 09:39 PM

Application Version : 4.26.1000

Core Rules Database Version : 3816
Trace Rules Database Version: 1770

Scan type : Complete Scan
Total Scan Time : 00:53:47

Memory items scanned : 218
Memory threats detected : 0
Registry items scanned : 5478
Registry threats detected : 0
File items scanned : 22393
File threats detected : 111

Adware.Tracking Cookie
C:\Documents and Settings\Dan\Cookies\dan@msnportal.112.2o7[1].txt
C:\Documents and Settings\Carmen\Cookies\[removed][1].txt
C:\Documents and Settings\Carmen\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@optimost[1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@clicksor[2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@adinterax[1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@adinterax[2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@superstats[1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@atwola[1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@interclick[2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@mediawebmonster[1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@atwola[2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@interclick[4].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@interclick[1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@crackle[2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@chitika[2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][3].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@exittracking[1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@teen[1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@bluestreak[2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@onetruemedia[2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@precisionclick[2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@clickaider[2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@qnsr[1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@partner2profit[1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@imrworldwide[3].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@imrworldwide[2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@smileycentral[2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@mywebsearch[3].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@mywebsearch[1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@ticketsnow[1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@windowsmedia[2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@collective-media[2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@media6degrees[1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@revsci[1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][3].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@1.tracking4rev[2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@media6degrees[2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@spamblockerutility[2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@findology[1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@teennews[1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][3].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@adecn[1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@azjmp[1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@consumergain[2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\tacy_kelly@login.tracking101[2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed]-go[2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][2].txt
C:\Documents and Settings\Tacy Kelly\Cookies\[removed][1].txt
.interclick.com [ C:\Program Files\Sony\EverQuest II\mozilla\cookies.txt ]
.interclick.com [ C:\Program Files\Sony\EverQuest II\mozilla\cookies.txt ]
.interclick.com [ C:\Program Files\Sony\EverQuest II\mozilla\cookies.txt ]
.interclick.com [ C:\Program Files\Sony\EverQuest II\mozilla\cookies.txt ]
.interclick.com [ C:\Program Files\Sony\EverQuest II\mozilla\cookies.txt ]
.interclick.com [ C:\Program Files\Sony\EverQuest II\mozilla\cookies.txt ]
go.globaladsales.com [ C:\Program Files\Sony\EverQuest II\mozilla\cookies.txt ]
.ads.pointroll.com [ C:\Program Files\Sony\EverQuest II\mozilla\cookies.txt ]
.ads.pointroll.com [ C:\Program Files\Sony\EverQuest II\mozilla\cookies.txt ]
.ads.pointroll.com [ C:\Program Files\Sony\EverQuest II\mozilla\cookies.txt ]
.ads.pointroll.com [ C:\Program Files\Sony\EverQuest II\mozilla\cookies.txt ]
.ads.pointroll.com [ C:\Program Files\Sony\EverQuest II\mozilla\cookies.txt ]
.ads.pointroll.com [ C:\Program Files\Sony\EverQuest II\mozilla\cookies.txt ]
.ads.pointroll.com [ C:\Program Files\Sony\EverQuest II\mozilla\cookies.txt ]
.chitika.net [ C:\Program Files\Sony\EverQuest II\mozilla\cookies.txt ]
.apmebf.com [ C:\Program Files\Sony\EverQuest II\mozilla\cookies.txt ]

Application.PowerReg Scheduler
C:\DOCUMENTS AND SETTINGS\COLLIN J\START MENU\PROGRAMS\STARTUP\POWERREG SCHEDULER V3.EXE
C:\WINDOWS\Prefetch\POWERREG SCHEDULER V3.EXE-22D2B749.pf

Adware.MyWebSearch-Installer
C:\DOCUMENTS AND SETTINGS\TACY KELLY\DESKTOP\POPULARSCREENSAVERSSETUP2.2.60.11-2.ZRFOX000.EXE
C:\DOCUMENTS AND SETTINGS\TACY KELLY\MY DOCUMENTS\WWWWW.EXE
C:\DOCUMENTS AND SETTINGS\TACY KELLY\MY DOCUMENTS\ZZZZZZ.EXE

Adware.Vundo/Variant
C:\WINDOWS\SYSTEM32\FFDCBAEDFEDFDC.DLL








Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:48:56 PM, on 3/28/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Electronic Arts\EADM\Core.exe
C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\WINDOWS\system32\lxcecoms.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [amd_dc_opt] "C:\Program Files\AMD\amd_dc_opt\amd_dc_opt.exe"
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QUICKCARE] C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe /P QUICKCARE
O4 - HKLM\..\Run: [LXCECATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools\daemon.exe"
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [Universal Installer] "C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe" /fromrun /starthidden
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O8 - Extra context menu item: &Search - ?p=ZRfox000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.2.2.89.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service (lavasoft ad-aware service) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: PC Tools Auxiliary Service (sdauxservice) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdcoreservice) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\

–
End of file - 7343 bytes
Hi meanween,

We got one more piece of vundo. Any improvement?

I'm going to get some advice on that service. It has to go, but I need to be able to keep the legit one.


SysyemLook again. This time it will be a lot faster, seconds even . :)

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :reg
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wuauserv
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\wuauserv
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\wuauserv
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\wuauserv

    Please post back with the SystemLook results.

    Thanks
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Hi, The computer is acting the same. Thanks SystemLook v1.0 by jpshortstuff (02.03.09) Log created at 22:45 on 28/03/2009 by Dan (Administrator - Elevation successful) ========== reg ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv] "Description"="Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site." "DisplayName"="Automatic Updates" "ErrorControl"= 0x00000001 (1) "ImagePath"="%fystemroot%\system32\svchost.exe -k netsvcs" "ObjectName"="LocalSystem" "Start"= 0x00000002 (2) "Type"= 0x00000020 (32) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Enum] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv\Security] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wuauserv] "Description"="Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site." "DisplayName"="Automatic Updates" "ErrorControl"= 0x00000001 (1) "ImagePath"="%fystemroot%\system32\svchost.exe -k netsvcs" "ObjectName"="LocalSystem" "Start"= 0x00000002 (2) "Type"= 0x00000020 (32) [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wuauserv\Enum] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wuauserv\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wuauserv\Security] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\wuauserv] "Description"="Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site." "DisplayName"="Automatic Updates" "ErrorControl"= 0x00000001 (1) "ImagePath"="%systemroot%\system32\svchost.exe -k netsvcs" "ObjectName"="LocalSystem" "Start"= 0x00000002 (2) "Type"= 0x00000020 (32) [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\wuauserv\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\wuauserv\Security] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\wuauserv] (Unable to open key) [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\wuauserv] "Description"="Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site." "DisplayName"="Automatic Updates" "ErrorControl"= 0x00000001 (1) "ImagePath"="%fystemroot%\system32\svchost.exe -k netsvcs" "ObjectName"="LocalSystem" "Start"= 0x00000002 (2) "Type"= 0x00000020 (32) [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\wuauserv\Parameters] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\wuauserv\Security] -=End Of File=-
Hi meanween,

Let's see if we can find it.


Please download RootRepeal to your desktop
  • Physically disconnect your machine from the internet as your system will be unprotected.
  • Unzip it to it's own folder, close all other programs especially your security programs (anti-spyware, anti-virus, and firewall) and run RootRepeal.exe
  • Click the Report tab at the bottom and then the Scan button.
  • A box will pop up, check the boxes beside Drivers, Files, Processes SSDT and click OK.
  • Another box will open, check the boxes beside all the drives, eg : C:\, then click OK.
  • The scan will take a little while to run, so let it go unhindered.
  • Once it is done, click the Save Report button, call it RepealScan and save the log to your desktop.
  • Reconnect to the internet.
  • Post the log here in your reply.

Thanks
Hi, here's the report. Thanks ROOTREPEAL © AD, 2007-2008 ================================================== Scan Time: 2009/03/29 13:31 Program Version: Version 1.2.3.0 Windows Version: Windows XP SP3 ================================================== Drivers ——————- Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xA8438000 Size: 98304 File Visible: No Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xBA66E000 Size: 8192 File Visible: No Status: - Name: PCI_PNP2588 Image Path: \Driver\PCI_PNP2588 Address: 0x00000000 Size: 0 File Visible: No Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xA55FD000 Size: 45056 File Visible: No Status: - Name: sfc.SYS Image Path: C:\WINDOWS\System32\Drivers\sfc.SYS Address: 0xA523C000 Size: 8768 File Visible: No Status: - Name: spln.sys Image Path: spln.sys Address: 0xB9EA9000 Size: 1040384 File Visible: No Status: - Name: sptd Image Path: \Driver\sptd Address: 0x00000000 Size: 0 File Visible: No Status: - SSDT ——————- #: 041 Function Name: NtCreateKey Status: Hooked by "PCTCore.sys" at address 0xb9daa506 #: 047 Function Name: NtCreateProcess Status: Hooked by "PCTCore.sys" at address 0xb9d99240 #: 048 Function Name: NtCreateProcessEx Status: Hooked by "PCTCore.sys" at address 0xb9d99432 #: 063 Function Name: NtDeleteKey Status: Hooked by "PCTCore.sys" at address 0xb9daacc8 #: 065 Function Name: NtDeleteValueKey Status: Hooked by "PCTCore.sys" at address 0xb9daaf88 #: 071 Function Name: NtEnumerateKey Status: Hooked by "spln.sys" at address 0xb9ec7ca2 #: 073 Function Name: NtEnumerateValueKey Status: Hooked by "spln.sys" at address 0xb9ec8030 #: 119 Function Name: NtOpenKey Status: Hooked by "PCTCore.sys" at address 0xb9da93ec #: 160 Function Name: NtQueryKey Status: Hooked by "spln.sys" at address 0xb9ec8108 #: 177 Function Name: NtQueryValueKey Status: Hooked by "spln.sys" at address 0xb9ec7f88 #: 192 Function Name: NtRenameKey Status: Hooked by "PCTCore.sys" at address 0xb9dab3ec #: 247 Function Name: NtSetValueKey Status: Hooked by "PCTCore.sys" at address 0xb9daa7b8 #: 257 Function Name: NtTerminateProcess Status: Hooked by "C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys" at address 0xa85b9df0

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI