This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Antivirus xp 2009 issues

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

The computer was doing fine until I disabled the anti virus program and ran combofix, then it started acting up again.
Here's the logs.
Thanks






ComboFix 09-03-29.02 - Dan 2009-03-30 2:23:29.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1428 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-02-28 to 2009-03-30 )))))))))))))))))))))))))))))))
.

2009-03-29 21:16 . 2009-03-29 21:17 d——– c:\program files\ERUNT
2009-03-28 20:32 . 2009-03-28 20:32 d——– c:\program files\SUPERAntiSpyware
2009-03-28 20:32 . 2009-03-28 20:32 d——– c:\documents and settings\Dan\Application Data\SUPERAntiSpyware.com
2009-03-28 20:32 . 2009-03-28 20:32 d——– c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-03-28 00:47 . 2009-03-28 00:47 d——– c:\documents and settings\All Users\Application Data\Electronic Arts
2009-03-27 10:01 . 2009-03-27 10:01 d——– c:\program files\Trend Micro
2009-03-27 08:24 . 2009-03-27 08:24 d——– c:\documents and settings\Carmen\Application Data\Malwarebytes
2009-03-27 03:04 . 2009-03-09 13:06 15,688 –a—— c:\windows\system32\lsdelete.exe
2009-03-27 02:47 . 2009-03-09 13:06 64,160 –a—— c:\windows\system32\drivers\Lbd.sys
2009-03-27 02:38 . 2009-03-27 02:46 d–h-c— c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-03-27 00:42 . 2009-03-30 02:00 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2009-03-26 22:19 . 2009-03-27 01:29 d——– c:\program files\Malwarebytes' Anti-Malware
2009-03-26 22:19 . 2009-03-26 22:19 d——– c:\documents and settings\Dan\Application Data\Malwarebytes
2009-03-26 22:19 . 2009-03-26 22:19 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-26 22:19 . 2009-03-26 16:49 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-26 22:19 . 2009-03-26 16:49 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-03-26 17:59 . 2008-12-11 08:38 159,600 –a—— c:\windows\system32\drivers\pctgntdi.sys
2009-03-26 17:58 . 2009-03-27 00:42 d——– c:\program files\Common Files\PC Tools
2009-03-26 17:58 . 2009-03-06 16:45 130,424 –a—— c:\windows\system32\drivers\PCTCore.sys
2009-03-26 17:58 . 2008-12-18 12:16 73,840 –a—— c:\windows\system32\drivers\PCTAppEvent.sys
2009-03-26 17:58 . 2008-12-10 12:36 64,392 –a—— c:\windows\system32\drivers\pctplsg.sys
2009-03-26 16:45 . 2009-03-26 16:45 d——– c:\documents and settings\Administrator
2009-03-26 16:17 . 2009-03-27 00:42 d——– c:\program files\Spyware Doctor
2009-03-26 16:17 . 2009-03-26 16:17 d——– c:\documents and settings\Dan\Application Data\PC Tools
2009-03-26 16:17 . 2009-03-26 16:17 d——– c:\documents and settings\All Users\Application Data\PC Tools
2009-03-26 16:09 . 2009-03-26 16:09 74,240 –a—— c:\windows\system32\zlib.dll
2009-03-24 13:22 . 2009-03-24 13:21 410,984 –a—— c:\windows\system32\deploytk.dll
2009-03-24 13:22 . 2009-03-24 13:21 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-03-21 17:15 . 2009-03-21 17:15 94,208 –a—— c:\windows\DIIUnin.exe
2009-03-21 17:15 . 2009-03-21 17:22 35,119 –a—— c:\windows\DIIUnin.dat
2009-03-21 17:15 . 2009-03-21 17:15 2,829 –a—— c:\windows\DIIUnin.pif
2009-03-12 22:34 . 2009-03-24 13:32 54,156 –ah—– c:\windows\QTFont.qfn
2009-03-12 22:34 . 2009-03-12 22:34 1,409 –a—— c:\windows\QTFont.for
2009-03-07 23:05 . 2009-03-07 23:05 d——– c:\program files\KingsIsle Entertainment
2009-03-04 16:00 . 2008-08-14 04:11 2,189,184 —–c— c:\windows\system32\dllcache\ntoskrnl.exe
2009-03-04 16:00 . 2008-08-14 04:09 2,145,280 —–c— c:\windows\system32\dllcache\ntkrnlmp.exe
2009-03-04 15:59 . 2008-08-14 03:33 2,066,048 —–c— c:\windows\system32\dllcache\ntkrnlpa.exe
2009-03-04 15:59 . 2008-08-14 03:33 2,023,936 —–c— c:\windows\system32\dllcache\ntkrpamp.exe
2009-03-04 15:59 . 2008-10-24 05:21 455,296 —–c— c:\windows\system32\dllcache\mrxsmb.sys
2009-03-04 15:59 . 2008-10-15 10:34 337,408 —–c— c:\windows\system32\dllcache\netapi32.dll
2009-03-04 15:59 . 2008-12-11 04:57 333,952 —–c— c:\windows\system32\dllcache\srv.sys
2009-03-04 15:47 . 2009-03-04 15:47 d——– c:\windows\system32\scripting
2009-03-04 15:47 . 2009-03-04 15:47 d——– c:\windows\system32\en
2009-03-04 15:47 . 2009-03-04 15:47 d——– c:\windows\system32\bits
2009-03-04 15:47 . 2009-03-04 15:47 d——– c:\windows\l2schemas
2009-03-04 15:44 . 2009-03-04 15:44 d——– c:\windows\ServicePackFiles
2009-03-04 15:36 . 2009-03-04 15:36 d——– c:\windows\EHome
2009-02-25 08:41 . 2009-02-25 08:41 d——– c:\documents and settings\All Users\Application Data\2Wire
2009-02-21 22:58 . 2009-02-21 22:58 d——– C:\344446ece1753df836f1ae1005
2009-02-21 12:16 . 2009-02-21 12:16 d——– c:\documents and settings\Dan\Application Data\2Wire
2009-02-20 17:55 . 2009-02-20 17:56 d——– c:\program files\Microsoft Games for Windows - LIVE
2009-02-20 17:54 . 2008-07-12 09:18 3,851,784 –a—— c:\windows\system32\D3DX9_39.dll
2009-02-20 17:54 . 2008-07-12 09:18 1,493,528 –a—— c:\windows\system32\D3DCompiler_39.dll
2009-02-20 17:54 . 2008-07-31 11:40 509,448 –a—— c:\windows\system32\XAudio2_2.dll
2009-02-20 17:54 . 2008-07-12 09:18 467,984 –a—— c:\windows\system32\d3dx10_39.dll
2009-02-20 17:54 . 2008-07-31 11:41 238,088 –a—— c:\windows\system32\xactengine3_2.dll
2009-02-20 17:54 . 2008-07-31 11:41 68,616 –a—— c:\windows\system32\XAPOFX1_1.dll
2009-02-18 18:10 . 2009-02-18 18:10 d——– c:\program files\Ubisoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-29 02:32 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2009-03-28 18:19 ——— d—–w c:\program files\LimeWire
2009-03-27 08:46 ——— d—–w c:\program files\Lavasoft
2009-03-27 07:24 ——— d—–w c:\program files\Diablo II
2009-03-27 06:42 ——— d—–w c:\program files\MSN Messenger
2009-03-26 22:25 ——— d—–w c:\program files\Spybot - Search & Destroy
2009-03-26 21:50 ——— d—–w c:\documents and settings\Dan\Application Data\uTorrent
2009-03-24 19:59 ——— d—–w c:\documents and settings\Carmen\Application Data\LimeWire
2009-03-24 19:21 ——— d—–w c:\program files\Java
2009-03-24 04:10 ——— d—–w c:\program files\Lx_cats
2009-03-21 21:59 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-25 14:45 ——— d—–w c:\program files\Microsoft Games
2009-02-21 18:37 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-02-21 18:37 10,520 —-a-w c:\windows\system32\avgrsstx.dll
2009-02-21 18:37 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-02-21 18:28 ——— d—–w c:\program files\Qwest
2009-02-21 05:52 ——— d—–w c:\program files\Phun
2009-02-09 11:13 1,846,784 —-a-w c:\windows\system32\win32k.sys
2008-12-20 23:15 826,368 —-a-w c:\windows\system32\wininet.dll
2008-12-05 06:54 144,896 —-a-w c:\windows\system32\schannel.dll
2008-11-08 00:06 75,512 —-a-w c:\documents and settings\Carmen\Application Data\GDIPFONTCACHEV1.DAT
2008-04-28 13:44 21 —-a-w c:\program files\Common Files\appop.log
2008-01-03 04:45 22,328 —-a-w c:\documents and settings\Dan\Application Data\PnkBstrK.sys
2007-03-10 01:47 22,040 —-a-w c:\documents and settings\Collin J\Application Data\GDIPFONTCACHEV1.DAT
2006-10-05 00:47 22,040 —-a-w c:\documents and settings\Dan\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((( SnapShot@2009-03-28_ 1.30.09.23 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 18:02:28 163,328 —-a-w c:\windows\ERDNT\3-29-2009\ERDNT.EXE
+ 2009-03-30 03:17:37 1,470,464 —-a-w c:\windows\ERDNT\3-29-2009\Users\00000001\NTUSER.DAT
+ 2009-03-30 03:17:37 8,192 —-a-w c:\windows\ERDNT\3-29-2009\Users\00000002\UsrClass.dat
+ 2009-03-30 03:17:37 1,470,464 —-a-w c:\windows\ERDNT\3-29-2009\Users\00000003\NTUSER.DAT
+ 2009-03-30 03:17:38 8,192 —-a-w c:\windows\ERDNT\3-29-2009\Users\00000004\UsrClass.dat
+ 2009-03-30 03:17:38 8,732,672 —-a-w c:\windows\ERDNT\3-29-2009\Users\00000005\NTUSER.DAT
+ 2009-03-30 03:17:38 155,648 —-a-w c:\windows\ERDNT\3-29-2009\Users\00000006\UsrClass.dat
+ 2009-03-29 02:32:47 18,944 —-a-r c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2009-03-29 02:32:47 65,024 —-a-r c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
- 2009-03-27 21:31:46 16,384 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-03-30 05:25:07 16,384 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-03-27 21:31:46 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-03-30 05:25:07 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-03-30 07:45:04 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_2a4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools\daemon.exe" [2007-12-15 482760]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-03-18 3325952]
"Universal Installer"="c:\program files\ComcastUI\Universal Installer\uinstaller.exe" [2008-03-18 984616]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-03-23 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"amd_dc_opt"="c:\program files\AMD\amd_dc_opt\amd_dc_opt.exe" [2006-06-28 106496]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-21 1601304]
"QUICKCARE"="c:\program files\Qwest\QuickCare\bin\sprtcmd.exe" [2007-05-09 198800]
"LXCECATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll" [2005-07-20 73728]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-24 136600]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]

c:\documents and settings\Carmen\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2008-02-25 3450608]

c:\documents and settings\Dan\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2008-02-25 3450608]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 12:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-21 12:37 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.X264"= x264vfw.dll
"VIDC.3iv2"= 3ivxVfWCodec.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\lavasoft ad-aware service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
–a—— 2006-01-02 17:41 45056 c:\program files\ATI Technologies\ATI.ACE\CLI.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
——— 2004-12-02 18:23 102400 c:\program files\Creative\MediaSource\Detector\CTDetect.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzPrint]
–a—— 2005-07-26 06:17 94208 c:\program files\Lexmark 4300 Series\ezprint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer]
–a—— 2005-07-12 03:36 299008 c:\program files\Lexmark Fax Solutions\fm3032.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2006-06-14 16:24 278528 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxcemon.exe]
–a—— 2005-08-02 11:45 192512 c:\program files\Lexmark 4300 Series\lxcemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2008-04-13 18:12 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-06-08 02:27 282624 c:\program files\K-Lite Codec Pack\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
–a—— 2009-02-21 12:35 1410296 c:\program files\Valve\Steam\steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2005-11-10 13:03 36975 c:\program files\Java\jre1.5.0_06\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
——— 2000-05-11 01:00 90112 c:\windows\Updreg.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WINCINEMAMGR]
–a—— 2005-01-21 02:47 270336 c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
–a—— 2005-08-07 16:10 16384 c:\windows\CTHELPER.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTxfiHlp]
–a—— 2005-08-07 16:10 18944 c:\windows\system32\CTXFIHLP.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LucasArts\\Star Wars Empire at War\\GameData\\fpupdate.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\meanween\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\LucasArts\\SWKotOR2\\swupdate.exe"=
"c:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"=
"c:\\Program Files\\THQ\\Dawn of War\\W40k.exe"=
"c:\\Program Files\\THQ\\Dawn of War\\W40kWA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Stardock Games\\Sins of a Solar Empire\\Sins of a Solar Empire.exe"=
"c:\\Program Files\\THQ\\Dawn of War - Soulstorm\\Soulstorm.exe"=
"c:\\Program Files\\Sony\\EverQuest II\\LaunchPad.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Valve\\Steam\\SteamApps\\common\\dawn of war 2\\DOW2.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard1
"6112:TCP"= 6112:TCP:blizzard2

R0 lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-03-27 64160]
R0 pctcore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-03-26 130424]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-06-23 325128]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-03-23 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-03-23 72944]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-02-21 298264]
R3 AmdTools;AMD Special Tools Driver;c:\windows\system32\drivers\AmdTools.sys [2006-10-09 31744]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-03-23 7408]
S3 lavasoft ad-aware service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-03-09 951632]
S3 mbamswissarmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-03-26 38496]
S3 sdauxservice;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-03-26 348752]

— Other Services/Drivers In Memory —

*Deregistered* - sfc
.
Contents of the 'Scheduled Tasks' folder

2009-03-27 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 13:06]
.
.
——- Supplementary Scan ——-
.
uStart Page =
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &Search - ?p=ZRfox000
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Dan\Application Data\Mozilla\Firefox\Profiles\vls5eq4y.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.comcast.net?cid=NET_mmhpset
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - plugin: c:\program files\IGN\Download Manager\npfpdlm.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-30 02:28:39
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCECATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1202660629-362288127-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:d7,2e,d5,09,43,6b,8a,2f,f7,84,3e,2d,54,82,bf,d0,e1,3f,cc,17,07,
a2,0c,ce,8c,91,9b,ea,c2,5f,39,f2,75,79,54,b7,89,b7,71,03,e6,af,b7,02,6b,b4,\
"rkeysecu"=hex:0c,01,85,43,d9,94,1a,d5,71,29,87,48,26,17,d9,45
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(888)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-03-30 2:34:53
ComboFix-quarantined-files.txt 2009-03-30 08:34:50
ComboFix2.txt 2009-03-28 18:38:20
ComboFix3.txt 2009-03-28 07:31:10

Pre-Run: 6,446,940,160 bytes free
Post-Run: 6,456,102,912 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
291 — E O F — 2009-03-15 09:03:45







ROOTREPEAL © AD, 2007-2008
==================================================
Scan Time: 2009/03/30 02:21
Program Version: Version 1.2.3.0
Windows Version: Windows XP SP3
==================================================

Drivers
——————-
Name: 1394BUS.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\1394BUS.SYS
Address: 0xBA0B8000 Size: 57344 File Visible: -
Status: -

Name: ACPI.sys
Image Path: ACPI.sys
Address: 0xB9E63000 Size: 187776 File Visible: -
Status: -

Name: ACPI_HAL
Image Path: \Driver\ACPI_HAL
Address: 0x804D7000 Size: 2150400 File Visible: -
Status: -

Name: afd.sys
Image Path: C:\WINDOWS\System32\drivers\afd.sys
Address: 0xA84E1000 Size: 138496 File Visible: -
Status: -

Name: AmdTools.sys
Image Path: C:\WINDOWS\system32\DRIVERS\AmdTools.sys
Address: 0xBA1C8000 Size: 61440 File Visible: -
Status: -

Name: aorwkhxh.SYS
Image Path: C:\WINDOWS\System32\Drivers\aorwkhxh.SYS
Address: 0xB947E000 Size: 413696 File Visible: -
Status: -

Name: arp1394.sys
Image Path: C:\WINDOWS\system32\DRIVERS\arp1394.sys
Address: 0xBA298000 Size: 60800 File Visible: -
Status: -

Name: ASACPI.sys
Image Path: C:\WINDOWS\system32\DRIVERS\ASACPI.sys
Address: 0xBA5F2000 Size: 5152 File Visible: -
Status: -

Name: atapi.sys
Image Path: atapi.sys
Address: 0xB9E1B000 Size: 98304 File Visible: -
Status: -

Name: atapi.sys
Image Path: atapi.sys
Address: 0x00000000 Size: 0 File Visible: -
Status: -

Name: ati2cqag.dll
Image Path: C:\WINDOWS\System32\ati2cqag.dll
Address: 0xBF057000 Size: 499712 File Visible: -
Status: -

Name: ati2dvag.dll
Image Path: C:\WINDOWS\System32\ati2dvag.dll
Address: 0xBF012000 Size: 282624 File Visible: -
Status: -

Name: ati2mtag.sys
Image Path: C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
Address: 0xB94F7000 Size: 2662400 File Visible: -
Status: -

Name: ati3duag.dll
Image Path: C:\WINDOWS\System32\ati3duag.dll
Address: 0xBF16B000 Size: 3133440 File Visible: -
Status: -

Name: atikvmag.dll
Image Path: C:\WINDOWS\System32\atikvmag.dll
Address: 0xBF0D1000 Size: 442368 File Visible: -
Status: -

Name: atinavt2.sys
Image Path: C:\WINDOWS\system32\DRIVERS\atinavt2.sys
Address: 0xA827A000 Size: 163968 File Visible: -
Status: -

Name: atiok3x2.dll
Image Path: C:\WINDOWS\System32\atiok3x2.dll
Address: 0xBF13D000 Size: 188416 File Visible: -
Status: -

Name: ativvaxx.dll
Image Path: C:\WINDOWS\System32\ativvaxx.dll
Address: 0xBF468000 Size: 1597440 File Visible: -
Status: -

Name: ATMFD.DLL
Image Path: C:\WINDOWS\System32\ATMFD.DLL
Address: 0xBFFA0000 Size: 286720 File Visible: -
Status: -

Name: audstub.sys
Image Path: C:\WINDOWS\system32\DRIVERS\audstub.sys
Address: 0xBA78C000 Size: 3072 File Visible: -
Status: -

Name: avgldx86.sys
Image Path: C:\WINDOWS\System32\Drivers\avgldx86.sys
Address: 0xA83D3000 Size: 318464 File Visible: -
Status: -

Name: avgmfx86.sys
Image Path: C:\WINDOWS\System32\Drivers\avgmfx86.sys
Address: 0xBA438000 Size: 20992 File Visible: -
Status: -

Name: BdaSup.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\BdaSup.SYS
Address: 0xB92F4000 Size: 12288 File Visible: -
Status: -

Name: Beep.SYS
Image Path: C:\WINDOWS\System32\Drivers\Beep.SYS
Address: 0xBA60A000 Size: 4224 File Visible: -
Status: -

Name: BOOTVID.dll
Image Path: C:\WINDOWS\system32\BOOTVID.dll
Address: 0xBA4B8000 Size: 12288 File Visible: -
Status: -

Name: Cdfs.SYS
Image Path: C:\WINDOWS\System32\Drivers\Cdfs.SYS
Address: 0xB9433000 Size: 63744 File Visible: -
Status: -

Name: cdrom.sys
Image Path: C:\WINDOWS\system32\DRIVERS\cdrom.sys
Address: 0xBA2F8000 Size: 62976 File Visible: -
Status: -

Name: CLASSPNP.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS
Address: 0xBA108000 Size: 53248 File Visible: -
Status: -

Name: ctac32k.sys
Image Path: C:\WINDOWS\system32\drivers\ctac32k.sys
Address: 0xB4627000 Size: 638976 File Visible: -
Status: -

Name: ctaud2k.sys
Image Path: C:\WINDOWS\system32\drivers\ctaud2k.sys
Address: 0xB9879000 Size: 439424 File Visible: -
Status: -

Name: ctoss2k.sys
Image Path: C:\WINDOWS\system32\drivers\ctoss2k.sys
Address: 0xB9823000 Size: 204800 File Visible: -
Status: -

Name: ctprxy2k.sys
Image Path: C:\WINDOWS\system32\drivers\ctprxy2k.sys
Address: 0xBA490000 Size: 32768 File Visible: -
Status: -

Name: ctsfm2k.sys
Image Path: C:\WINDOWS\system32\drivers\ctsfm2k.sys
Address: 0xB46C3000 Size: 159744 File Visible: -
Status: -

Name: disk.sys
Image Path: disk.sys
Address: 0xBA0F8000 Size: 36352 File Visible: -
Status: -

Name: drmk.sys
Image Path: C:\WINDOWS\system32\drivers\drmk.sys
Address: 0xBA318000 Size: 61440 File Visible: -
Status: -

Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xA8343000 Size: 98304 File Visible: No
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xBA612000 Size: 8192 File Visible: No
Status: -

Name: Dxapi.sys
Image Path: C:\WINDOWS\System32\drivers\Dxapi.sys
Address: 0xB92FC000 Size: 12288 File Visible: -
Status: -

Name: dxg.sys
Image Path: C:\WINDOWS\System32\drivers\dxg.sys
Address: 0xBF000000 Size: 73728 File Visible: -
Status: -

Name: dxgthk.sys
Image Path: C:\WINDOWS\System32\drivers\dxgthk.sys
Address: 0xBA79E000 Size: 4096 File Visible: -
Status: -

Name: emupia2k.sys
Image Path: C:\WINDOWS\system32\drivers\emupia2k.sys
Address: 0xB46EA000 Size: 184320 File Visible: -
Status: -

Name: fdc.sys
Image Path: C:\WINDOWS\system32\DRIVERS\fdc.sys
Address: 0xBA3B0000 Size: 27392 File Visible: -
Status: -

Name: Fips.SYS
Image Path: C:\WINDOWS\System32\Drivers\Fips.SYS
Address: 0xBA2A8000 Size: 44544 File Visible: -
Status: -

Name: flpydisk.sys
Image Path: C:\WINDOWS\system32\DRIVERS\flpydisk.sys
Address: 0xBA400000 Size: 20480 File Visible: -
Status: -

Name: fltmgr.sys
Image Path: fltmgr.sys
Address: 0xB9DC7000 Size: 129792 File Visible: -
Status: -

Name: Fs_Rec.SYS
Image Path: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS
Address: 0xBA608000 Size: 7936 File Visible: -
Status: -

Name: ftdisk.sys
Image Path: ftdisk.sys
Address: 0xB9E33000 Size: 125056 File Visible: -
Status: -

Name: gameenum.sys
Image Path: C:\WINDOWS\system32\DRIVERS\gameenum.sys
Address: 0xB9938000 Size: 10624 File Visible: -
Status: -

Name: ha20x2k.sys
Image Path: C:\WINDOWS\system32\drivers\ha20x2k.sys
Address: 0xB4717000 Size: 1114112 File Visible: -
Status: -

Name: hal.dll
Image Path: C:\WINDOWS\system32\hal.dll
Address: 0x806E4000 Size: 134400 File Visible: -
Status: -

Name: HIDCLASS.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS
Address: 0xBA2B8000 Size: 36864 File Visible: -
Status: -

Name: HIDPARSE.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS
Address: 0xBA410000 Size: 28672 File Visible: -
Status: -

Name: hidusb.sys
Image Path: C:\WINDOWS\system32\DRIVERS\hidusb.sys
Address: 0xB9C73000 Size: 10368 File Visible: -
Status: -

Name: HTTP.sys
Image Path: C:\WINDOWS\System32\Drivers\HTTP.sys
Address: 0xA51DF000 Size: 264832 File Visible: -
Status: -

Name: i8042prt.sys
Image Path: C:\WINDOWS\system32\DRIVERS\i8042prt.sys
Address: 0xBA168000 Size: 52480 File Visible: -
Status: -

Name: imapi.sys
Image Path: C:\WINDOWS\system32\DRIVERS\imapi.sys
Address: 0xBA2E8000 Size: 42112 File Visible: -
Status: -

Name: ipnat.sys
Image Path: C:\WINDOWS\system32\DRIVERS\ipnat.sys
Address: 0xA8503000 Size: 152832 File Visible: -
Status: -

Name: ipsec.sys
Image Path: C:\WINDOWS\system32\DRIVERS\ipsec.sys
Address: 0xA85D2000 Size: 75264 File Visible: -
Status: -

Name: isapnp.sys
Image Path: isapnp.sys
Address: 0xBA0C8000 Size: 37248 File Visible: -
Status: -

Name: kbdclass.sys
Image Path: C:\WINDOWS\system32\DRIVERS\kbdclass.sys
Address: 0xBA3D8000 Size: 24576 File Visible: -
Status: -

Name: kbdhid.sys
Image Path: C:\WINDOWS\system32\DRIVERS\kbdhid.sys
Address: 0xB9C6B000 Size: 14592 File Visible: -
Status: -

Name: KDCOM.DLL
Image Path: C:\WINDOWS\system32\KDCOM.DLL
Address: 0xBA5A8000 Size: 8192 File Visible: -
Status: -

Name: ks.sys
Image Path: C:\WINDOWS\system32\DRIVERS\ks.sys
Address: 0xB98E5000 Size: 143360 File Visible: -
Status: -

Name: KSecDD.sys
Image Path: KSecDD.sys
Address: 0xB9D7B000 Size: 92288 File Visible: -
Status: -

Name: Lbd.sys
Image Path: Lbd.sys
Address: 0xBA118000 Size: 57472 File Visible: -
Status: -

Name: mnmdd.SYS
Image Path: C:\WINDOWS\System32\Drivers\mnmdd.SYS
Address: 0xBA60C000 Size: 4224 File Visible: -
Status: -

Name: mouclass.sys
Image Path: C:\WINDOWS\system32\DRIVERS\mouclass.sys
Address: 0xBA3B8000 Size: 23040 File Visible: -
Status: -

Name: MountMgr.sys
Image Path: MountMgr.sys
Address: 0xBA0D8000 Size: 42368 File Visible: -
Status: -

Name: mrxdav.sys
Image Path: C:\WINDOWS\system32\DRIVERS\mrxdav.sys
Address: 0xA58DA000 Size: 180608 File Visible: -
Status: -

Name: mrxsmb.sys
Image Path: C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
Address: 0xA8421000 Size: 455296 File Visible: -
Status: -

Name: Msfs.SYS
Image Path: C:\WINDOWS\System32\Drivers\Msfs.SYS
Address: 0xBA420000 Size: 19072 File Visible: -
Status: -

Name: msgpc.sys
Image Path: C:\WINDOWS\system32\DRIVERS\msgpc.sys
Address: 0xBA1A8000 Size: 35072 File Visible: -
Status: -

Name: msmpu401.sys
Image Path: C:\WINDOWS\system32\drivers\msmpu401.sys
Address: 0xBA78B000 Size: 2944 File Visible: -
Status: -

Name: mssmbios.sys
Image Path: C:\WINDOWS\system32\DRIVERS\mssmbios.sys
Address: 0xBA55C000 Size: 15488 File Visible: -
Status: -

Name: Mup.sys
Image Path: Mup.sys
Address: 0xB9CA7000 Size: 105344 File Visible: -
Status: -

Name: NDIS.sys
Image Path: NDIS.sys
Address: 0xB9CC1000 Size: 182656 File Visible: -
Status: -

Name: ndistapi.sys
Image Path: C:\WINDOWS\system32\DRIVERS\ndistapi.sys
Address: 0xB9934000 Size: 10112 File Visible: -
Status: -

Name: ndisuio.sys
Image Path: C:\WINDOWS\system32\DRIVERS\ndisuio.sys
Address: 0xA5FEA000 Size: 14592 File Visible: -
Status: -

Name: ndiswan.sys
Image Path: C:\WINDOWS\system32\DRIVERS\ndiswan.sys
Address: 0xB9453000 Size: 91520 File Visible: -
Status: -

Name: NDProxy.SYS
Image Path: C:\WINDOWS\System32\Drivers\NDProxy.SYS
Address: 0xBA1E8000 Size: 40576 File Visible: -
Status: -

Name: netbios.sys
Image Path: C:\WINDOWS\system32\DRIVERS\netbios.sys
Address: 0xBA278000 Size: 34688 File Visible: -
Status: -

Name: netbt.sys
Image Path: C:\WINDOWS\system32\DRIVERS\netbt.sys
Address: 0xA8529000 Size: 162816 File Visible: -
Status: -

Name: nic1394.sys
Image Path: C:\WINDOWS\system32\DRIVERS\nic1394.sys
Address: 0xBA148000 Size: 61824 File Visible: -
Status: -

Name: Npfs.SYS
Image Path: C:\WINDOWS\System32\Drivers\Npfs.SYS
Address: 0xBA428000 Size: 30848 File Visible: -
Status: -

Name: Ntfs.sys
Image Path: Ntfs.sys
Address: 0xB9CEE000 Size: 574976 File Visible: -
Status: -

Name: ntkrnlpa.exe
Image Path: C:\WINDOWS\system32\ntkrnlpa.exe
Address: 0x804D7000 Size: 2150400 File Visible: -
Status: -

Name: Null.SYS
Image Path: C:\WINDOWS\System32\Drivers\Null.SYS
Address: 0xBA73C000 Size: 2944 File Visible: -
Status: -

Name: nvapu.sys
Image Path: C:\WINDOWS\system32\drivers\nvapu.sys
Address: 0xB8BD2000 Size: 415360 File Visible: -
Status: -

Name: nvarm.sys
Image Path: C:\WINDOWS\system32\drivers\nvarm.sys
Address: 0xB8ADF000 Size: 69632 File Visible: -
Status: -

Name: nvax.sys
Image Path: C:\WINDOWS\system32\drivers\nvax.sys
Address: 0xBA2D8000 Size: 53376 File Visible: -
Status: -

Name: NVENETFD.sys
Image Path: C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
Address: 0xBA238000 Size: 33536 File Visible: -
Status: -

Name: nvmcp.sys
Image Path: C:\WINDOWS\system32\drivers\nvmcp.sys
Address: 0xB8AF0000 Size: 925696 File Visible: -
Status: -

Name: nvnetbus.sys
Image Path: C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
Address: 0xB9C83000 Size: 12928 File Visible: -
Status: -

Name: NVNRM.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\NVNRM.SYS
Address: 0xB97B4000 Size: 262144 File Visible: -
Status: -

Name: NVSNPU.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\NVSNPU.SYS
Address: 0xB9781000 Size: 208896 File Visible: -
Status: -

Name: ohci1394.sys
Image Path: ohci1394.sys
Address: 0xBA0A8000 Size: 61696 File Visible: -
Status: -

Name: parport.sys
Image Path: C:\WINDOWS\system32\DRIVERS\parport.sys
Address: 0xB946A000 Size: 80128 File Visible: -
Status: -

Name: PartMgr.sys
Image Path: PartMgr.sys
Address: 0xBA330000 Size: 19712 File Visible: -
Status: -

Name: ParVdm.SYS
Image Path: C:\WINDOWS\System32\Drivers\ParVdm.SYS
Address: 0xBA5C8000 Size: 6784 File Visible: -
Status: -

Name: pci.sys
Image Path: pci.sys
Address: 0xB9E52000 Size: 68224 File Visible: -
Status: -

Name: PCI_PNP1100
Image Path: \Driver\PCI_PNP1100
Address: 0x00000000 Size: 0 File Visible: No
Status: -

Name: pciide.sys
Image Path: pciide.sys
Address: 0xBA670000 Size: 3328 File Visible: -
Status: -

Name: PCIIDEX.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS
Address: 0xBA328000 Size: 28672 File Visible: -
Status: -

Name: PCTCore.sys
Image Path: PCTCore.sys
Address: 0xB9D92000 Size: 143360 File Visible: -
Status: -

Name: PnpManager
Image Path: \Driver\PnpManager
Address: 0x804D7000 Size: 2150400 File Visible: -
Status: -

Name: portcls.sys
Image Path: C:\WINDOWS\system32\drivers\portcls.sys
Address: 0xB9855000 Size: 147456 File Visible: -
Status: -

Name: processr.sys
Image Path: C:\WINDOWS\system32\DRIVERS\processr.sys
Address: 0xBA2C8000 Size: 35840 File Visible: -
Status: -

Name: psched.sys
Image Path: C:\WINDOWS\system32\DRIVERS\psched.sys
Address: 0xB93A2000 Size: 69120 File Visible: -
Status: -

Name: ptilink.sys
Image Path: C:\WINDOWS\system32\DRIVERS\ptilink.sys
Address: 0xBA3C8000 Size: 17792 File Visible: -
Status: -

Name: PxHelp20.sys
Image Path: PxHelp20.sys
Address: 0xBA338000 Size: 16512 File Visible: -
Status: -

Name: rasacd.sys
Image Path: C:\WINDOWS\system32\DRIVERS\rasacd.sys
Address: 0xBA590000 Size: 8832 File Visible: -
Status: -

Name: rasl2tp.sys
Image Path: C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
Address: 0xBA178000 Size: 51328 File Visible: -
Status: -

Name: raspppoe.sys
Image Path: C:\WINDOWS\system32\DRIVERS\raspppoe.sys
Address: 0xBA188000 Size: 41472 File Visible: -
Status: -

Name: raspptp.sys
Image Path: C:\WINDOWS\system32\DRIVERS\raspptp.sys
Address: 0xBA198000 Size: 48384 File Visible: -
Status: -

Name: raspti.sys
Image Path: C:\WINDOWS\system32\DRIVERS\raspti.sys
Address: 0xBA3D0000 Size: 16512 File Visible: -
Status: -

Name: RAW
Image Path: \FileSystem\RAW
Address: 0x804D7000 Size: 2150400 File Visible: -
Status: -

Name: rdbss.sys
Image Path: C:\WINDOWS\system32\DRIVERS\rdbss.sys
Address: 0xA8491000 Size: 175744 File Visible: -
Status: -

Name: RDPCDD.sys
Image Path: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
Address: 0xBA60E000 Size: 4224 File Visible: -
Status: -

Name: redbook.sys
Image Path: C:\WINDOWS\system32\DRIVERS\redbook.sys
Address: 0xBA308000 Size: 57600 File Visible: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA54F0000 Size: 45056 File Visible: No
Status: -

Name: SASDIFSV.SYS
Image Path: C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
Address: 0xBA430000 Size: 24576 File Visible: -
Status: -

Name: SASENUM.SYS
Image Path: C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
Address: 0xA83CB000 Size: 20480 File Visible: -
Status: -

Name: SASKUTIL.sys
Image Path: C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
Address: 0xA84BC000 Size: 151552 File Visible: -
Status: -

Name: SCSIPORT.SYS
Image Path: C:\WINDOWS\System32\Drivers\SCSIPORT.SYS
Address: 0xB9E91000 Size: 98304 File Visible: -
Status: -

Name: secdrv.sys
Image Path: C:\WINDOWS\system32\DRIVERS\secdrv.sys
Address: 0xA5892000 Size: 40960 File Visible: -
Status: -

Name: serenum.sys
Image Path: C:\WINDOWS\system32\DRIVERS\serenum.sys
Address: 0xB993C000 Size: 15744 File Visible: -
Status: -

Name: serial.sys
Image Path: C:\WINDOWS\system32\DRIVERS\serial.sys
Address: 0xBA158000 Size: 64512 File Visible: -
Status: -

Name: sfc.SYS
Image Path: C:\WINDOWS\System32\Drivers\sfc.SYS
Address: 0xA50A7000 Size: 8768 File Visible: No
Status: -

Name: Si3114r5.sys
Image Path: Si3114r5.sys
Address: 0xB9DE7000 Size: 212992 File Visible: -
Status: -

Name: SiWinAcc.sys
Image Path: SiWinAcc.sys
Address: 0xBA4BC000 Size: 10368 File Visible: -
Status: -

Name: spjx.sys
Image Path: spjx.sys
Address: 0xB9EA9000 Size: 1040384 File Visible: No
Status: -

Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No
Status: -

Name: sr.sys
Image Path: sr.sys
Address: 0xB9DB5000 Size: 73472 File Visible: -
Status: -

Name: srv.sys
Image Path: C:\WINDOWS\system32\DRIVERS\srv.sys
Address: 0xA56D0000 Size: 333952 File Visible: -
Status: -

Name: swenum.sys
Image Path: C:\WINDOWS\system32\DRIVERS\swenum.sys
Address: 0xBA5F4000 Size: 4352 File Visible: -
Status: -

Name: sysaudio.sys
Image Path: C:\WINDOWS\system32\drivers\sysaudio.sys
Address: 0xA5CE2000 Size: 60800 File Visible: -
Status: -

Name: tcpip.sys
Image Path: C:\WINDOWS\system32\DRIVERS\tcpip.sys
Address: 0xA8579000 Size: 361600 File Visible: -
Status: -

Name: TDI.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\TDI.SYS
Address: 0xBA3C0000 Size: 20480 File Visible: -
Status: -

Name: termdd.sys
Image Path: C:\WINDOWS\system32\DRIVERS\termdd.sys
Address: 0xBA1B8000 Size: 40704 File Visible: -
Status: -

Name: update.sys
Image Path: C:\WINDOWS\system32\DRIVERS\update.sys
Address: 0xB9300000 Size: 384768 File Visible: -
Status: -

Name: usbccgp.sys
Image Path: C:\WINDOWS\system32\DRIVERS\usbccgp.sys
Address: 0xBA440000 Size: 32128 File Visible: -
Status: -

Name: USBD.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\USBD.SYS
Address: 0xBA5F6000 Size: 8192 File Visible: -
Status: -

Name: usbehci.sys
Image Path: C:\WINDOWS\system32\DRIVERS\usbehci.sys
Address: 0xBA488000 Size: 30208 File Visible: -
Status: -

Name: usbhub.sys
Image Path: C:\WINDOWS\system32\DRIVERS\usbhub.sys
Address: 0xBA1D8000 Size: 59520 File Visible: -
Status: -

Name: usbohci.sys
Image Path: C:\WINDOWS\system32\DRIVERS\usbohci.sys
Address: 0xBA480000 Size: 17152 File Visible: -
Status: -

Name: USBPORT.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\USBPORT.SYS
Address: 0xB9908000 Size: 147456 File Visible: -
Status: -

Name: vga.sys
Image Path: C:\WINDOWS\System32\drivers\vga.sys
Address: 0xBA418000 Size: 20992 File Visible: -
Status: -

Name: VIDEOPRT.SYS
Image Path: C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS
Address: 0xB94E3000 Size: 81920 File Visible: -
Status: -

Name: VolSnap.sys
Image Path: VolSnap.sys
Address: 0xBA0E8000 Size: 52352 File Visible: -
Status: -

Name: wanarp.sys
Image Path: C:\WINDOWS\system32\DRIVERS\wanarp.sys
Address: 0xBA268000 Size: 34560 File Visible: -
Status: -

Name: watchdog.sys
Image Path: C:\WINDOWS\System32\watchdog.sys
Address: 0xBA450000 Size: 20480 File Visible: -
Status: -

Name: wdmaud.sys
Image Path: C:\WINDOWS\system32\drivers\wdmaud.sys
Address: 0xA5BB5000 Size: 83072 File Visible: -
Status: -

Name: Win32k
Image Path: \Driver\Win32k
Address: 0xBF800000 Size: 1847296 File Visible: -
Status: -

Name: win32k.sys
Image Path: C:\WINDOWS\System32\win32k.sys
Address: 0xBF800000 Size: 1847296 File Visible: -
Status: -

Name: WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\WMILIB.SYS
Address: 0xBA5AA000 Size: 8192 File Visible: -
Status: -

Name: WMIxWDM
Image Path: \Driver\WMIxWDM
Address: 0x804D7000 Size: 2150400 File Visible: -
Status: -

Name: yk51x86.sys
Image Path: C:\WINDOWS\system32\DRIVERS\yk51x86.sys
Address: 0xB97F4000 Size: 189568 File Visible: -
Status: -
Hi

Thatwas quite a list.

That file shows up in RootRepeal and the service may have restarted. This search shouldn't take long.

In SystemLook use this

:filefind
spjx.sys

Thanks
Hi, Here's the log. Thanks SystemLook v1.0 by jpshortstuff (02.03.09) Log created at 14:40 on 30/03/2009 by Dan (Administrator - Elevation successful) ========== filefind ========== Searching for "spjx.sys" No files found. -=End Of File=-
Hi, My AVG Resident shield has caught this twice today.I moved it to the vault both times. Thanks Process name: C:\WINDOWS\system32\svchost.exe Process ID: 2000 File Name: C:\System Volume Information\_restore{27A62C88-6E94-46F0-A50A-60EDA426EBF6}\RP1119\A0260941.exe
Hi Meanween,

sorry for the delay, under the weather and slept most of the day.

There is definately something very strange going. I'm getting two different stories from these logs. The AVG detection is in a restore point. Those are harmless unless you revert back to that point.

Let's use Avenger again and see if that driver did come back


2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):
Note: make sure you copy ALL the text. Do not copy the word Code

Drivers to delete:
sfc

Files to delete:
C:\WINDOWS\System32\Drivers\sfc.SYS

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, open the avenger folder and start The Avenger program by clicking on its icon.
  • Right click on the window under Input script here:, and select Paste.
  • You can also Paste the text copied to the clipboard into this window by pressing (Ctrl+V), or click on the third button under the menu to paste it from the clipboard.
  • Click on Execute
  • Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete" or "Drivers to Disable", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply


After you finish with Avenger, Please run AVZ again with the same set up. I'd like to see if the what both tools have to say when run close together.

  • Double click on AVZ.exe to run it.
  • Run an update by clicking the Auto Update button on the Right of the Log window: [external image: Posted Image]
  • Click Start to begin the update
Note: If you recieve an error message, chose a different source, then click Start again
  • After the update, from the "File" menu, choose "Standard Scripts"
  • Put a check next to item 2: Advanced System Investigation
  • Click Execute selected scripts
  • At the next prompt, click the OK button
  • Let the scan run and click "OK" when the completion prompt pops up
  • Now Close out of the Standard Scripts window, and exit AVZ
  • Navigate to the avz4 folder and locate the folder LOG
  • Inside the LOG folder you will find virusinfo_syscheck.htm and virusinfo_syscheck.zip
  • Attach virusinfo_syscheck.zip to your next reply



Thanks
Hi,
Hope you're feeling better. Here's the logs.
Thanks



Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

Driver "sfc" deleted successfully.

Error: file "C:\WINDOWS\System32\Drivers\sfc.SYS" not found!
Deletion of file "C:\WINDOWS\System32\Drivers\sfc.SYS" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
–> the object does not exist


Completed script processing.

*******************

Finished! Terminate.
[attachment removed]
Hi Meanween,

That file shows in AVZ.

Use SystemLook to find the path to wbex.sys and appmgmts.dll. After you get the full path to files, please submit them to Virus Scan using the instructions below.

For SytemLook

:filefind
wbex.sys 
appmgmts.dll



Virus Scan
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the full file path as indicated in the SystemLook log, one at a time, into the "Suspicious files to scan" box on the top of the page:
  • Please ensure the scan is completed and you have saved the results before submitting the next.

    Example full file paths
    C:\Windows\system32\badfile.exe
    C:\Windows\system32\drivers\badfile.sys

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.

Please post the Virus Scan results and the SystemLook log.

Thanks
Hi, It seems that Systemlook can't find either of them. SystemLook v1.0 by jpshortstuff (02.03.09) Log created at 00:43 on 31/03/2009 by Dan (Administrator - Elevation successful) ========== filefind ========== Searching for "wbex.sys" No files found. Searching for "appmgmts.dll" No files found. -=End Of File=-
Hi Meanween,

Okay. We seem to be hitting walls at each turn. None of these tools can agree on anything. :pullhair:

Download Dr.Web CureIt to the desktop:
  • Doubleclick the drweb-cureit icon to start the program.
  • press start
  • Allow the program to run the initial express scan
  • This will scan the files currently running in memory. If something is found, click the YES button when it asks you if you want to cure it. This is only a short scan.
    Note: A pop up may appear during this phase suggesting you purchase their program - click the X at the top right corner of this pop-up to close it.
  • Once the short scan has finished, check the Complete scan box on the left side, even if nothing was found on the initial scan.
  • Then click the small green arrow button on the right under the Dr.Web Antivirus picture to start the complete scan. (This scan will take several hours)
  • During this complete scan - if Dr.Web finds an infection a window will pop up requesting your attention. Select the Cure button.
    • Note:(If the file cannot be cured, Dr.Web will automatically delete the file)
  • Once the scan is complete, on the menu bar, click file and choose report list.
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Note:this report will need to be renamed to Dr.Web.txt in order to post it on the forum.
  • Close Dr.Web Cureit.
  • Please post the Dr.Web.txt report in your next reply

Grab a coffee or something, it may take awhile.

Thanks
Hi, Here is the log. Thanks sprtsync.dll;c:\program files\qwest\quickcare\bin;Probably DLOADER.Trojan;Incurable.Deleted.; (full version) handsome awkward the used 10.wma;C:\Documents and Settings\Carmen\My Documents\Carmen's Stuff\Music;Trojan.Isbar.389;Deleted.; 02 - the distillers acoustic 22.wma;C:\Documents and Settings\Carmen\My Documents\Carmen's Stuff\Music;Trojan.Isbar.389;Deleted.; mother earth martin gore.mp3;C:\Documents and Settings\Carmen\My Documents\Carmen's Stuff\Music\Cleanup CD;Trojan.WMALoader;Cured.; MovePlayerUpgrade.exe;C:\Documents and Settings\Tacy Kelly\Application Data\Move Networks\ie_bin;Trojan.Swizzor.10846;Deleted.; modem_common.js;C:\Program Files\Qwest\QuickCare\agentcommon\inc;Probably SCRIPT.Virus;Incurable.Deleted.; sma_common.js;C:\Program Files\Qwest\QuickCare\agentui\snapins\preferences;Probably SCRIPT.Virus;Incurable.Deleted.; 0375ea37675ad8f762dae5f7b9f6dc1c.TMP.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Probably DLOADER.Trojan;Incurable.Deleted.;

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI