This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] need help

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hia..seems like i have a hi jacker..all the typical redirecting..etc..only thing is it also wont let me update anything..tried to do spybot..nothing..ad aware..nothing..nortons..sunbelt..vipre..same thing..i cant even do microsoft updates..i've tried every scan i could..panda..bit defender eset etc….cant use any of them because it cant update its files (thats in the rare instance that i actually make to one of those pages,usually i just get a white page that says continue..oh..btw while its suppose to be going to lets say bitdefender.com the browser address changes to www.statuspower or something like that)..same for a number of other scans..i've tried going into safety on msn premium for the anti virus and anti spyware and i just get a blank page..the only one that i can reach is trend micro that found of a couple of trojan downloaders but still my problems persist..i also have trend micros RUbotted running and every couple of minutes it pops up with a window saying i have a bot do i want to open house call to clean it..i do that but it hasnt found anything except what i mentioned..this is the same problem i had a while ago..the difference is that this time i know where i got it..i had downloaded a movie and when i tries to open it it said that i needed to download DRM license..that installed herocodec and here i am..hope you here from someone soon..PS.. i was just reading another members post and realized that i should also mention that these redirections are mostly for any attempt i make at going to an antivirus site..and my malwarebytes anti malware program is being prevented from starting up also..man we'd all be in trouble if the makers also somehow started to prevent from going to sites such as this one..thanks everyone

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:07:36 AM, on 4/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\PROGRA~1\SPEEDB~2\VideoAcceleratorService.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\PROGRA~1\SPEEDB~2\VideoAcceleratorEngine.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\WINDOWS\explorer.exe
C:\Program Files\RapidSolution\Tunebite\TBPlayer.exe
C:\Program Files\RapidSolution\Tunebite\TBPlayer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: SpeedBitPlus Toolbar - {60270dc7-9ea0-472f-9b77-66652c06246e} - C:\Program Files\SpeedBitPlus\tbSpe1.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SpeedBitPlus Toolbar - {60270dc7-9ea0-472f-9b77-66652c06246e} - C:\Program Files\SpeedBitPlus\tbSpe1.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\DAP\DAPIEL~1.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: SpeedBitPlus Toolbar - {60270dc7-9ea0-472f-9b77-66652c06246e} - C:\Program Files\SpeedBitPlus\tbSpe1.dll
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Recguard] "C:\WINDOWS\SMINST\RECGUARD.EXE"
O4 - HKLM\..\Run: [RTHDCPL] "C:\WINDOWS\RTHDCPL.EXE"
O4 - HKLM\..\Run: [nTrayFw] "C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe"
O4 - HKLM\..\Run: [TMRUBottedTray] "C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe"
O4 - HKLM\..\Run: [Synchronization Agent] "C:\Program Files\Sync Manager\agent\syncagent.exe" -reportwithlogfile
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [SpeedBitVideoAccelerator] C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [SpeedBitVideoAccelerator] C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe (User 'Default user')
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~2\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~2\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~2\sblsp.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…20Installer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5727FF4C-EF4E-4d96-A96C-03AD91910448} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_ind.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D7DAF974-B1AC-433A-9BB7-B9E8EC3A3B7E}: NameServer = 85.255.112.80,85.255.112.168
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.80,85.255.112.168
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.80,85.255.112.168
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Google Update Service (gupdate1c9ac1250fbe3e6) (gupdate1c9ac1250fbe3e6) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe (file missing)
O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Shield 3\IoloSGCtrl.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
O23 - Service: Security Activity Dashboard Service - Unknown owner - C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe (file missing)
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~2\VideoAcceleratorService.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

–
End of file - 12063 bytes
Hi,

please do the following:

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
ok i did that..my machine shut down and then restarted and combofix then continued..after it ran evrything went back to how it usually appears..but now i dont have an internet connection. i have tried restarting my pc and still nothing..i tried everything that i know how to do for my connection and still nothing..i ran my msn messenger trouble shooter and theres a DNS problem..i'm typing this on another computer so you could know whats going on because if verizon cnt help me get my connection going again i dont know how i'll be able to communicate here and fix my machine..i even did a system restore thinking that it would replace whatever is needed for my connection to work again..nothing.. OH!! i also recieved a number of error messages for dll's..its hours later now and i dont remember what they were for..i'm including the combofix log, but please keep in mind that i did a system restore after running combofix.. could you leave some instructions as to how i should continue? hopefully i'll be able to get my connection going again..alright i just checked my usb stickand it turns out that i didnt properly copy and paste, so theres no log to post..
Hi.

The infection that you have is a Zlob DNS attacker - removing the infection should not have corrupted your ability to connect, but that sometimes happens given the type of infection it was

There's a couple of things to try to reset your DNS.

Please do the following:

reset your DNS server and flush your DNS cache.
I suggest you print out these instructions for easy reference:
  • Go to Start > Control Panel, and choose Network Connections.
  • Right click on your default connection, usually Local Area Connection for cable and DSL or Dial-up Connection if you are using Dial-up, and choose Properties.
  • Click the Networking tab
  • Double-click on the Internet Protocol (TCP/IP) item.
  • Write down the settings in case you should need to change them back.
  • Select the radio button that says "Obtain DNS servers automatically".
  • Click OK twice to get out of the properties screen and restart your computer.
  • If not prompted to reboot go ahead and reboot manually.
CAUTION: It's possible that your ISP (Internet Service Provider) requires specific DNS settings here. Make sure you know if you need these settings or not BEFORE you make any changes or you may lose your Internet connection. If you're sure you do not need a specific DNS address, then you may proceed.
  • Now go to Start > Run > type: cmd
  • Press OK or Hit Enter.
  • At the command prompt, type or copy/paste: ipconfig /flushdns (note the space between “..g /f…” it needs to be there)
  • Hit Enter.
  • You will get a confirmation that the flush was successful.
  • Close the command box.


Next you must reset the router to its default configuration. This can be done by inserting something tiny like a paper clip end or pencil tip into a small hole labeled "reset" located on the back of the router. Press and hold down the small button inside until the lights on the front of the router blink off and then on again (usually about 10 seconds). If you don’t know the router's default password, you can look it up HERE
ok i finally have my internet back :lol: ..but i'm still experiencing the same problems..cant update antivirus programs..cant run malwarebytes..and i'm still getting redirected..also trendmicro RUbotted keep popping up telling me i have a bot..i'm including a hijack this log..thank you..

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:42:55 PM, on 4/13/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\PROGRA~1\SPEEDB~2\VideoAcceleratorService.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\PROGRA~1\SPEEDB~2\VideoAcceleratorEngine.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\VSO\ConvertX\3\ConvertXtoDvd.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN\MSNCoreFiles\msn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: SpeedBitPlus Toolbar - {60270dc7-9ea0-472f-9b77-66652c06246e} - C:\Program Files\SpeedBitPlus\tbSpe1.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SpeedBitPlus Toolbar - {60270dc7-9ea0-472f-9b77-66652c06246e} - C:\Program Files\SpeedBitPlus\tbSpe1.dll
O2 - BHO: (no name) - {6c7b0eb4-9bc5-4ac5-b192-94fba2872d5e} - C:\WINDOWS\system32\cewmd.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {809BC980-5AFA-411B-BCD3-BB8B3816FCB5} - C:\WINDOWS\system32\cewmd.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: DAPIELoader Class - {FF6C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRA~1\DAP\DAPIEL~1.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: SpeedBitPlus Toolbar - {60270dc7-9ea0-472f-9b77-66652c06246e} - C:\Program Files\SpeedBitPlus\tbSpe1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Recguard] "C:\WINDOWS\SMINST\RECGUARD.EXE"
O4 - HKLM\..\Run: [RTHDCPL] "C:\WINDOWS\RTHDCPL.EXE"
O4 - HKLM\..\Run: [nTrayFw] "C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe"
O4 - HKLM\..\Run: [TMRUBottedTray] "C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe"
O4 - HKLM\..\Run: [Synchronization Agent] "C:\Program Files\Sync Manager\agent\syncagent.exe" -reportwithlogfile
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\.DEFAULT\..\Run: [SpeedBitVideoAccelerator] C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe (User 'Default user')
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~2\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~2\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~2\sblsp.dll
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemydsl.verizon.net/sdcCommon…20Installer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab3.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5727FF4C-EF4E-4d96-A96C-03AD91910448} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_ind.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D7DAF974-B1AC-433A-9BB7-B9E8EC3A3B7E}: NameServer = 85.255.112.80,85.255.112.168
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\
O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Google Update Service (gupdate1c9ac1250fbe3e6) (gupdate1c9ac1250fbe3e6) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe (file missing)
O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Shield 3\IoloSGCtrl.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
O23 - Service: Security Activity Dashboard Service - Unknown owner - C:\Program Files\Trend Micro\TrendSecure\SecurityActivityDashboard\tmarsvc.exe (file missing)
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~2\VideoAcceleratorService.exe
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

–
End of file - 12123 bytes
Hi,

Please do the following:

  • Open HiJackThis
  • Click on Do a system scan only
  • Check the boxes next to ONLY the entries listed below (if still present):


O2 - BHO: (no name) - {6c7b0eb4-9bc5-4ac5-b192-94fba2872d5e} - C:\WINDOWS\system32\cewmd.dll
O2 - BHO: (no name) - {809BC980-5AFA-411B-BCD3-BB8B3816FCB5} - C:\WINDOWS\system32\cewmd.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{D7DAF974-B1AC-433A-9BB7-B9E8EC3A3B7E}: NameServer = 85.255.112.80,85.255.112.168


  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.

NEXT

Please try and run Malware Bytes in Safemode

To Enter Safemode
  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY repeatedly,
  • this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Safemode
  • Then press the Enter Key on your Keyboard
  • go into your usual account


Did combofix complete a run and can you find the log it produced. It should be located in the same folder as Combo fix C:\ComboFix - if you can locate the log and post it along with the MBAM log
[attachment removed]ok..i did all that..when combfix ran i recieved this message..
a root kit was found & had to reboot..copy these entries down should they be needed later..
C:\WINDOWS\system32\drivers\gxvxcqtqojudhdyfobsymqodsdjcbkquhrcjy.sys

and this one..

C:\WINDOWS\system32\gxvxcotusviylkeihwftyufhvebrxdfhitwkx.dll

it hen had to reboot and continue to run..also while it was running i keep getting a window that says..
C:\PROGRA (right here theres suppose to be a sqiggly line..like a tilde in spanish..but i dont have that on my keyboard) 1\SPEEDB (sqiggly line)2\sblsp.dll is not a valid windows image.please check the installation diskette.

the image that i'm including is the RUbotted window that has popped up at least 10 times, so i shut it down..malwarebytes ran in safe mode and will start in regular mode but it wont update..heres the mbam log..

Malwarebytes' Anti-Malware 1.36
Database version: 1945
Windows 5.1.2600 Service Pack 2

4/13/2009 2:00:00 PM
mbam-log-2009-04-13 (14-00-00).txt

Scan type: Quick Scan
Objects scanned: 80684
Time elapsed: 6 minute(s), 52 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

and the combo fix log..

ComboFix 09-04-13.A2 - Owner 2009-04-13 13:42.7 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2943.2558 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: BitDefender Antivirus *On-access scanning disabled* (Updated)
FW: BitDefender Firewall *disabled*
FW: NVIDIA Firewall *disabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Owner\Application Data\inst.exe
c:\windows\system32\drivers\gxvxcqtqojudhdyfobsymqodsdjcbkquhrcjy.sys
c:\windows\system32\gxvxccounter
c:\windows\system32\gxvxcotusviylkeihwftyufhvebrxdfhitwkx.dll
c:\windows\system32\ovfsthfrydkjhdwrngnnvoweegckhiqbrcojlg.dll
c:\windows\system32\ovfsthujqnenrdrtytorcnfonujsrbanaumpoq.dll
c:\windows\system32\ovfsthxcaxgsxfybwgwtrddspqdutmgstlxuqw.dat
c:\windows\system32\ovfsthydgxtbspobldxekglvryddwobfkrifya.dat
c:\windows\system32\Pncrt.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_gxvxcserv.sys


((((((((((((((((((((((((( Files Created from 2009-03-13 to 2009-04-13 )))))))))))))))))))))))))))))))
.

8208-10-29 17:48 . 8208-10-29 17:48 ——– d—–w c:\documents and settings\All Users\Application Data\Applications
8208-10-29 16:58 . 8208-10-29 16:58 331805736 —-a-w C:\WindowsXP-KB936929-SP3-x86-ENU.exe
8208-10-29 16:28 . 8208-10-29 16:28 ——– d—–w c:\documents and settings\Administrator\Local Settings\Application Data\Ahead
8208-10-29 16:27 . 8208-10-29 16:27 72568 -c–a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
8208-10-29 16:27 . 8208-10-29 16:27 ——– d—–w c:\documents and settings\Administrator\Application Data\Corel
8208-10-29 16:21 . 8208-10-29 16:21 ——– d—–w c:\documents and settings\Owner\Local Settings\Application Data\DNA
8208-10-29 16:21 . 2009-04-03 04:07 ——– d—–w c:\documents and settings\Owner\Application Data\DNA
8208-10-29 16:21 . 2009-04-03 01:55 ——– d—–w c:\program files\DNA
2009-04-13 01:58 . 2007-03-19 01:37 65602 —-a-w c:\windows\system32\cook3260.dll
2009-04-13 01:58 . 2006-09-29 17:26 176165 —-a-w c:\windows\system32\drv23260.dll
2009-04-13 01:58 . 2006-09-29 17:25 208935 —-a-w c:\windows\system32\drv33260.dll
2009-04-13 01:58 . 2006-09-29 17:24 217127 —-a-w c:\windows\system32\drv43260.dll
2009-04-13 01:58 . 2006-05-20 21:16 1184984 —-a-w c:\windows\system32\wvc1dmod.dll
2009-04-13 01:58 . 2006-05-12 00:21 626688 —-a-w c:\windows\system32\vp7vfw.dll
2009-04-13 01:58 . 2004-05-04 16:53 1645320 —-a-w c:\windows\gdiplus.dll
2009-04-11 18:08 . 2009-04-11 18:08 155 —-a-w c:\windows\system32\SelfDel.bat
2009-04-11 18:08 . 2009-04-11 18:08 84045 —-a-w c:\windows\system32\ftp_non_crp.exe
2009-04-11 17:53 . 2009-04-13 17:46 109010 —-a-w c:\windows\system32\drivers\e3d7dc26.sys
2009-04-11 17:29 . 2009-04-11 17:29 552 —-a-w c:\windows\system32\d3d8caps.dat
2009-04-11 17:03 . 2009-04-11 17:03 125440 —-a-w c:\documents and settings\Owner\Local Settings\Application Data\CheckForUpdates.exe
2009-04-11 17:03 . 2009-04-11 17:03 24576 —-a-w c:\documents and settings\Owner\Local Settings\Application Data\codecsetup3956.exe
2009-04-11 06:09 . 2007-08-02 03:47 102664 —-a-w c:\windows\system32\drivers\tmcomm.sys
2009-04-10 16:41 . 2009-04-11 17:31 664 —-a-w c:\windows\system32\d3d9caps.dat
2009-04-09 21:58 . 2009-04-09 21:58 ——– d—–w c:\documents and settings\All Users\Application Data\CyberLink
2009-04-09 21:58 . 2009-04-09 21:58 ——– d—–w c:\documents and settings\Owner\Application Data\CyberLink
2009-04-06 19:39 . 2009-04-06 19:39 ——– d—–w c:\documents and settings\Owner\Application Data\MOVAVI
2009-04-06 19:38 . 2009-04-06 19:38 ——– d—–w c:\program files\Movavi Video Editor 4
2009-04-06 19:37 . 2009-04-06 19:37 ——– d—–w c:\documents and settings\Owner\Local Settings\Application Data\Downloaded Installations
2009-04-06 19:15 . 2009-04-06 19:38 ——– d—–w c:\documents and settings\Owner\Application Data\GetRightToGo
2009-04-06 19:03 . 2009-04-12 06:52 ——– d—–w c:\program files\Video Enhancer
2009-04-05 05:49 . 2009-04-05 05:49 ——– d—–w c:\program files\PixiePack Codec Pack
2009-04-05 05:48 . 2007-12-11 13:52 26784 —-a-w c:\windows\system32\drivers\tbhsd.sys
2009-04-05 05:48 . 2009-04-10 16:41 ——– d—–w c:\documents and settings\Owner\Application Data\Tunebite
2009-04-05 05:47 . 2009-04-05 05:51 ——– d—–w c:\documents and settings\All Users\Application Data\RapidSolution
2009-04-05 05:47 . 2009-04-05 05:47 ——– d—–w c:\program files\RapidSolution
2009-03-29 07:50 . 2009-03-29 07:50 ——– d—–w c:\documents and settings\All Users\Application Data\vsosdk
2009-03-27 14:03 . 2009-03-27 14:03 801312 —-a-w c:\windows\system32\nvcplui.exe
2009-03-27 14:03 . 2009-03-27 14:03 4710400 —-a-w c:\windows\system32\nvdisps.dll
2009-03-27 14:03 . 2009-03-27 14:03 420384 —-a-w c:\windows\system32\nvcpl.cpl
2009-03-27 14:03 . 2009-03-27 14:03 401408 —-a-w c:\windows\system32\nvcuvid.dll
2009-03-27 14:03 . 2009-03-27 14:03 3796992 —-a-w c:\windows\system32\nvvitvs.dll
2009-03-27 14:03 . 2009-03-27 14:03 3489792 —-a-w c:\windows\system32\nvgames.dll
2009-03-27 14:03 . 2009-03-27 14:03 2744320 —-a-w c:\windows\system32\nvwss.dll
2009-03-27 14:03 . 2009-03-27 14:03 188416 —-a-w c:\windows\system32\nvmccss.dll
2009-03-27 14:03 . 2009-03-27 14:03 1560576 —-a-w c:\windows\system32\nvcuda.dll
2009-03-27 14:03 . 2009-03-27 14:03 1273856 —-a-w c:\windows\system32\nvmobls.dll
2009-03-27 14:03 . 2009-03-27 14:03 1253376 —-a-w c:\windows\system32\NvPVEnc.ax
2009-03-24 00:29 . 2009-03-24 00:29 ——– d—–w c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-03-23 23:44 . 2009-04-13 04:37 ——– d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-03-23 23:08 . 2009-03-23 23:08 ——– d—–w c:\documents and settings\Owner\Local Settings\Application Data\LogMeIn
2009-03-23 23:08 . 2009-03-23 23:08 ——– d—–w c:\documents and settings\All Users\Application Data\LogMeIn
2009-03-23 23:08 . 2008-10-17 00:35 28984 —-a-w c:\windows\system32\LMIport.dll
2009-03-23 23:08 . 2008-10-17 00:35 83288 —-a-w c:\windows\system32\LMIRfsClientNP.dll
2009-03-23 23:08 . 2008-07-24 22:46 47640 —-a-w c:\windows\system32\drivers\LMIRfsDriver.sys
2009-03-23 23:07 . 2008-10-17 00:35 87352 —-a-w c:\windows\system32\LMIinit.dll
2009-03-23 23:07 . 2009-03-23 23:07 1024 —-a-w C:\.rnd
2009-03-23 23:07 . 2009-04-13 04:06 ——– d—–w c:\program files\LogMeIn
2009-03-23 16:23 . 2009-03-23 16:23 ——– d—–w c:\program files\TomTom International B.V
2009-03-16 16:14 . 2009-03-16 16:14 27 —-a-w c:\windows\system32\mcheck.mhf
2009-03-16 16:13 . 2008-05-27 23:18 36288 —-a-w c:\windows\system32\drivers\maploml.sys
2009-03-16 16:13 . 2008-05-27 22:03 37312 —-a-w c:\windows\system32\drivers\maplom.sys
2009-03-15 23:17 . 2009-04-10 16:00 0 —-a-w c:\windows\system32\msxver64.sqr
2009-03-15 23:16 . 2009-04-11 06:05 ——– d—–w c:\program files\Sync Manager

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
8208-10-29 16:44 . 2004-08-26 16:12 250032 –sha-r C:\ntldr
8208-10-29 16:42 . 2004-08-26 18:03 76487 -c–a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
8208-10-29 13:14 . 2008-10-24 04:06 72568 -c–a-w c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-13 17:27 . 2008-10-22 01:39 ——– d—–w c:\documents and settings\Owner\Application Data\uTorrent
2009-04-13 16:40 . 2008-10-22 01:06 ——– d—–w c:\documents and settings\Owner\Application Data\MSN6
2009-04-13 01:59 . 2009-03-08 17:42 ——– d—–w c:\documents and settings\Owner\Application Data\Vso
2009-04-13 01:58 . 2009-03-08 17:42 47360 —-a-w c:\windows\system32\drivers\pcouffin.sys
2009-04-13 01:58 . 2009-03-08 17:42 47360 —-a-w c:\documents and settings\Owner\Application Data\pcouffin.sys
2009-04-13 01:58 . 2009-03-08 17:42 ——– d—–w c:\program files\VSO
2009-04-11 19:46 . 2008-10-22 02:09 ——– d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-11 17:28 . 2008-11-26 18:45 ——– d—–w c:\program files\SystemRequirementsLab
2009-04-11 03:48 . 2009-02-05 03:30 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-08 00:37 . 2008-10-22 13:15 71357 —-a-w C:\MP4debug.log
2009-04-06 19:32 . 2009-02-05 03:30 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 19:32 . 2009-02-05 03:30 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-03-27 12:14 . 2008-10-22 02:44 453152 -c–a-w c:\windows\system32\NVUNINST.EXE
2009-03-23 23:52 . 2008-10-22 02:47 ——– d—–w c:\program files\Google
2009-03-23 16:22 . 2008-12-26 05:19 ——– d—–w c:\program files\TomTom HOME 2
2009-03-20 05:32 . 2008-11-12 00:41 ——– d—–w c:\program files\Lavasoft
2009-03-20 05:32 . 2008-10-23 01:50 ——– d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2009-03-19 05:18 . 2009-03-01 22:16 ——– d—–w c:\program files\TuneUp Utilities 2009
2009-03-18 16:53 . 2009-02-18 04:11 9024 —-a-w C:\aaw7boot.log
2009-03-16 16:13 . 2008-10-23 13:10 ——– d—–w c:\program files\SlySoft
2009-03-14 22:03 . 2009-03-02 04:23 ——– d—–w c:\program files\XMicro Internet Security
2009-03-14 02:28 . 2008-10-24 04:06 ——– d—–w c:\documents and settings\Owner\Application Data\Corel
2009-03-14 01:57 . 2008-10-24 00:54 3350 -csha-w c:\windows\system32\KGyGaAvL.sys
2009-03-14 01:57 . 2008-10-24 00:54 3350 -csha-w c:\windows\system32\KGyGaAvL.sys
2009-03-12 04:48 . 2008-10-25 23:57 ——– d—–w c:\program files\WarRock
2009-03-12 04:48 . 2008-10-31 15:42 ——– d—–w c:\program files\Windows Media Connect 2
2009-03-12 04:48 . 2008-10-22 02:57 ——– d—–w c:\program files\Microsoft Works
2009-03-12 04:47 . 2009-03-02 17:48 ——– d—–w c:\program files\SpeedBit Video Accelerator
2009-03-12 04:47 . 2009-03-02 17:41 ——– d—–w c:\program files\DAP
2009-03-12 04:47 . 2008-10-08 03:25 ——– d—–w c:\program files\AnyDVD
2009-03-12 04:45 . 2008-08-24 20:43 ——– d—–w c:\program files\OpenOffice.org 2.4
2009-03-12 04:45 . 2009-02-20 04:20 ——– d—–w c:\program files\Mozilla ActiveX Control v1.7.12
2009-03-12 04:45 . 2008-12-22 19:12 ——– d—–w c:\program files\bfgclient
2009-03-12 04:45 . 2008-10-22 02:54 ——– d—–w c:\program files\Microsoft Digital Image 2006
2009-03-12 04:45 . 2008-10-22 13:15 ——– d—–w c:\program files\WinAVI MP4 Converter
2009-03-12 04:43 . 2008-10-24 03:17 ——– d—–w c:\program files\DivX
2009-03-12 04:43 . 2008-10-22 02:57 ——– d—–w c:\program files\MSN Encarta Plus
2009-03-11 05:53 . 2008-10-22 04:09 ——– d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-03-08 04:20 . 2009-03-08 04:20 ——– d—–w c:\program files\GamersFirst
2009-03-08 04:20 . 2008-10-22 02:47 ——– d–h–w c:\program files\InstallShield Installation Information
2009-03-04 17:34 . 2009-03-04 00:59 ——– d—–w c:\program files\Windows Live Safety Center
2009-03-04 04:56 . 2009-03-04 04:56 244 —ha-w C:\sqmnoopt03.sqm
2009-03-04 04:56 . 2009-03-04 04:56 232 —ha-w C:\sqmdata03.sqm
2009-03-04 04:53 . 2009-03-04 04:53 256 —ha-w C:\sqmdata02.sqm
2009-03-04 04:53 . 2009-03-04 04:53 244 —ha-w C:\sqmnoopt02.sqm
2009-03-04 04:51 . 2009-03-04 04:51 244 —ha-w C:\sqmnoopt01.sqm
2009-03-04 04:51 . 2009-03-04 04:51 232 —ha-w C:\sqmdata01.sqm
2009-03-04 04:48 . 2008-10-22 04:01 ——– d—–w c:\documents and settings\Owner\Application Data\MSNInstaller
2009-03-04 04:11 . 2009-03-04 04:11 ——– d—–w c:\documents and settings\NetworkService\Application Data\Webroot
2009-03-04 03:46 . 2009-03-04 03:46 ——– d—–w c:\program files\Eidos Interactive
2009-03-04 00:00 . 2009-03-04 00:00 ——– d—–w c:\documents and settings\NetworkService\Application Data\TuneUp Software
2009-03-02 18:30 . 2008-10-23 01:19 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-03-02 18:30 . 2008-10-23 01:19 ——– d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-02 18:29 . 2009-03-02 18:29 ——– d—–w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-03-02 17:48 . 2009-03-02 17:41 ——– d—–w c:\documents and settings\All Users\Application Data\SpeedBit
2009-03-02 17:41 . 2009-03-02 17:41 ——– d—–w c:\program files\SpeedBitPlus
2009-03-02 17:41 . 2009-03-02 17:41 ——– d—–w c:\program files\Conduit
2009-03-02 17:41 . 2009-03-02 17:41 50688 —-a-w c:\windows\system32\wbhelp2.dll
2009-03-02 04:04 . 2009-03-02 04:01 67645 —-a-w c:\windows\system32\drivers\pshook11.sys
2009-03-02 01:59 . 2009-02-23 15:59 ——– d—–w c:\program files\a-squared Free
2009-03-02 01:59 . 2009-02-23 18:50 ——– d—–w c:\program files\a-squared Anti-Malware
2009-03-01 22:16 . 2009-03-01 22:16 603904 —-a-w c:\windows\system32\TUProgSt.exe
2009-03-01 22:16 . 2009-03-01 22:16 362240 —-a-w c:\windows\system32\TuneUpDefragService.exe
2009-03-01 22:16 . 2009-03-01 22:16 ——– d—–w c:\documents and settings\Owner\Application Data\TuneUp Software
2009-03-01 22:16 . 2009-03-01 22:16 ——– d—–w c:\documents and settings\All Users\Application Data\TuneUp Software
2009-03-01 22:15 . 2009-03-01 22:15 ——– d-sh–w c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-03-01 17:48 . 2009-03-01 17:48 ——– d—–w c:\program files\NVIDIA Corporation
2009-03-01 16:28 . 2009-03-01 16:28 ——– d—–w c:\program files\Nvidia Omega Drivers
2009-02-27 03:59 . 2009-02-25 17:29 ——– d—–w c:\program files\Softwaremile.com
2009-02-27 00:18 . 2009-02-18 02:19 48 –sh–w c:\windows\S1A0C4467.tmp
2009-02-25 18:42 . 2008-10-30 02:21 ——– d—–w c:\program files\Common Files\Agnitum Shared
2009-02-25 18:30 . 2009-02-25 18:30 ——– d—–w c:\program files\Agnitum
2009-02-23 04:48 . 2009-02-23 03:48 30670 —-a-w C:\CybDefInstallInfo.log
2009-02-22 22:16 . 2009-02-22 22:16 ——– d—–w c:\program files\Graugon
2009-02-22 22:16 . 2009-02-22 22:16 ——– d—–w c:\documents and settings\Owner\Application Data\Graugon
2009-02-22 19:48 . 2009-02-22 19:48 1234 —-a-w C:\ipconfig.txt
2009-02-22 18:54 . 2009-01-27 03:58 9480 —-a-w C:\debug.log
2009-02-22 01:30 . 2009-02-05 02:57 ——– d—–w c:\program files\Trend Micro
2009-02-22 00:35 . 2009-02-20 04:20 ——– d—–w c:\program files\VideoLAN
2009-02-21 01:16 . 2009-02-20 04:28 ——– d—–w c:\documents and settings\Owner\Application Data\vlc
2009-02-20 19:59 . 2009-02-20 19:59 4096 —-a-w c:\windows\d3dx.dat
2009-02-20 04:28 . 2009-02-20 04:28 ——– d—–w c:\documents and settings\All Users\Application Data\Graboid Inc
2009-02-20 04:27 . 2009-02-20 04:27 ——– d—–w c:\documents and settings\Owner\Application Data\MozillaControl
2009-02-20 04:20 . 2009-02-20 04:19 ——– d—–w c:\program files\Graboid
2009-02-19 21:26 . 2009-02-19 21:26 ——– d—–w c:\program files\BurnWorld
2009-02-18 01:03 . 2009-02-18 01:03 ——– d—–w c:\documents and settings\Administrator\Application Data\Sunbelt
2009-02-13 20:02 . 2009-02-13 20:02 ——– d—–w c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-02-09 10:19 . 2008-10-28 21:49 1846272 —-a-w c:\windows\system32\win32k.sys
2009-02-05 01:21 . 2008-10-23 01:15 410984 -c–a-w c:\windows\system32\deploytk.dll
2009-02-04 05:43 . 2009-02-04 05:43 107 —-a-w c:\documents and settings\Owner\Application Data\netstat.bat
2009-02-04 02:44 . 2009-02-04 02:44 3584 —-a-w c:\windows\system32\DisspyUninstall.exe
2009-02-04 02:44 . 2009-02-04 02:44 32768 —-a-w c:\windows\system32\REGTOOL5.DLL
2009-02-04 02:44 . 2009-02-04 02:44 147456 —-a-w c:\windows\system32\VBZIP11.DLL
2009-02-04 02:44 . 2009-02-04 02:44 143360 —-a-w c:\windows\system32\vbuzip10.dll
2009-01-31 04:47 . 2009-01-31 04:47 987896 —-a-w C:\coreuninstall.log
2009-01-31 03:41 . 2008-11-12 21:19 81984 -c–a-w c:\windows\system32\bdod.bin
2008-11-12 00:13 . 2008-11-12 00:13 700 -c–a-w c:\program files\ownvrxto.txt
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{60270dc7-9ea0-472f-9b77-66652c06246e}"= "c:\program files\SpeedBitPlus\tbSpe1.dll" [2009-03-02 1883672]

[HKEY_CLASSES_ROOT\clsid\{60270dc7-9ea0-472f-9b77-66652c06246e}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{60270dc7-9ea0-472f-9b77-66652c06246e}]
2009-03-02 14:02 1883672 –a—— c:\program files\SpeedBitPlus\tbSpe1.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FF6C3CF0-4B15-11D1-ABED-709549C10000}]
2009-03-02 13:41 140880 –a—— c:\progra~1\DAP\DAPIEL~1.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{60270dc7-9ea0-472f-9b77-66652c06246e}"= "c:\program files\SpeedBitPlus\tbSpe1.dll" [2009-03-02 1883672]

[HKEY_CLASSES_ROOT\clsid\{60270dc7-9ea0-472f-9b77-66652c06246e}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{60270DC7-9EA0-472F-9B77-66652C06246E}"= "c:\program files\SpeedBitPlus\tbSpe1.dll" [2009-03-02 1883672]

[HKEY_CLASSES_ROOT\clsid\{60270dc7-9ea0-472f-9b77-66652c06246e}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"RTHDCPL"="c:\windows\RTHDCPL.EXE" [2005-09-22 14854144]
"nTrayFw"="c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" [2005-07-29 270336]
"TMRUBottedTray"="c:\program files\Trend Micro\RUBotted\TMRUBottedTray.exe" [2008-11-06 288088]
"Synchronization Agent"="c:\program files\Sync Manager\agent\syncagent.exe" [BU]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-27 86016]
"nwiz"="nwiz.exe" [2009-03-27 c:\windows\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"SpeedBitVideoAccelerator"="c:\program files\SpeedBit Video Accelerator\VideoAccelerator.exe" [2009-03-02 2823784]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-16 20:35 87352 c:\windows\system32\LMIinit.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ZDSV"= scrvid.dll
"VIDC.XFR1"= xfcodec.dll
"vidc.dvsd"= pdvcodec.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe"
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
"Google Update"="c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe"
"SpeedBitVideoAccelerator"=c:\program files\SpeedBit Video Accelerator\VideoAccelerator.exe
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" /startup

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe"
"High Definition Audio Property Page Shortcut"="c:\windows\system32\HDAShCut.exe"
"TotalSecurityUpdate"="c:\program files\XMicro Internet Security\TSAtUdt.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\Nexon\\Combat Arms\\NMService.exe"=

R0 Lbd;Lbd; [x]
R1 pwipf6;pwipf6; [x]
R1 Start1Driver;Start1Driver; [x]
R2 gupdate1c9ac1250fbe3e6;Google Update Service (gupdate1c9ac1250fbe3e6);c:\program files\Google\Update\GoogleUpdate.exe [2009-03-23 133104]
R2 Security Activity Dashboard Service;Security Activity Dashboard Service; [x]
R2 Start2Driver;Start2Driver; [x]
R3 ioloSystemService;iolo System Service; [x]
R3 KernlProD;KernlProD; [x]
R3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\NPF.sys [2007-11-14 34448]
R3 SBRE;SBRE; [x]
R3 TMPassthru;Trend Micro Passthru Ndis Service;c:\windows\system32\DRIVERS\TMPassthru.sys [2008-03-02 206608]
R3 vidcap;vidcap; [x]
R4 LMIRfsClientNP;LMIRfsClientNP; [x]
S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-06-19 28544]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\RaInfo.sys [2008-07-24 12856]
S2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2008-07-24 47640]
S2 RUBotted;Trend Micro RUBotted Service;c:\program files\Trend Micro\RUBotted\TMRUBotted.exe [2008-11-06 582992]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2009-03-17 92008]
S2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\System32\TUProgSt.exe [2009-03-01 603904]
S2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~2\VideoAcceleratorService.exe [2009-03-02 288368]
S2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [2007-11-26 598856]
S3 MaplomL;MaplomL; [x]
S3 scrcap;scrcap;c:\windows\system32\DRIVERS\scrcap.sys [2006-12-27 9006]
S3 TMPassthruMP;TMPassthruMP;c:\windows\system32\DRIVERS\TMPassthru.sys [2008-03-02 206608]


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{621FCD24-4498-4324-A81E-07D331376EDF}]
c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Contents of the 'Scheduled Tasks' folder

2009-04-13 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-20 17:28]

2009-04-13 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-09-27 17:39]

2009-04-13 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-23 19:44]

2009-04-13 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-23 19:51]

2009-04-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-80318808-1749694936-3363987519-1003.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-07 17:34]

2008-10-31 c:\windows\Tasks\ISP signup reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-04 15:00]

2008-11-06 c:\windows\Tasks\ISP signup reminder 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-04 15:00]
.
.
——- Supplementary Scan ——-
.
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\progra~1\SPEEDB~2\sblsp.dll
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\82i9g6hb.default\
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1529850&SearchSource=2&q=
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\82i9g6hb.default\extensions\{1a71246c-3eb0-4d6c-af77-3ab756017c3a}\components\FFAlert.dll
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\82i9g6hb.default\extensions\{60270dc7-9ea0-472f-9b77-66652c06246e}\components\FFAlert.dll
FF - component: c:\program files\DAP\DAPFireFox\components\DAPFireFox.dll
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll

—- FIREFOX POLICIES —-
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
.
——- File Associations ——-
.
JSEFile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-13 13:46
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\e3d7dc26]
"ImagePath"="\SystemRoot\System32\drivers\e3d7dc26.sys"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\s-1-5-21-80318808-1749694936-3363987519-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{58F33A7D-0382-8B5C-BB44-F7DEEF6DA3E4}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"jalkjibdolpogmamnghk"=hex:62,61,68,65,00,00
"jalkjibdolpogmamngdk"=hex:62,61,6c,65,00,00
"ialjoddbpiilpopfma"=hex:6b,61,65,65,64,6d,62,65,61,6b,61,68,68,64,63,6b,62,68,
65,69,6b,6b,00,00
"habnljeagelcgpdi"=hex:6b,61,65,65,64,6d,62,65,6e,6a,63,65,6e,68,62,62,6d,6d,
6a,61,70,6e,00,01
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1740)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2009-04-13 13:48
ComboFix-quarantined-files.txt 2009-04-13 17:48
ComboFix2.txt 2009-04-12 05:15
ComboFix3.txt 2009-04-11 19:56
ComboFix4.txt 2009-02-08 15:47

Pre-Run: 80,808,243,200 bytes free
Post-Run: 80,822,534,144 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,4,5
380 — E O F — 2009-04-11 17:18
oh..and all webpages..links etc take forever to load..like even now when i went use a smiley.. :( it took like 30 seconds..try to get o this topic takes even longer..but this is with all webpages..which isnt typical behavior
Hi,

Please do the following:

Download Rooter.exe to your desktop

  • Doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt (Where %systemdrive% is usually C: or the drive that you have installed Windows).
  • Post that in your next reply.

NEXT

Please download SDFix and save it to your Desktop.
  • You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.
Double click on SDFix.exe. It should automatically extract a folder called SDFix to your system drive (usually C:\).
Please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key repeatedly;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual user account.
  • Open the SDFix folder and double click on RunThis.bat to start the script.
  • Type Y and press Enter to begin the script.
  • It will start cleaning your PC and then prompt you to press any key to Reboot.
  • Press any key to restart the PC.
  • Your system will take longer than normal to restart as the fixtool will be removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished.
  • Press any key to end the script and to load your desktop icons.
  • A text file should automatically open, so please copy the contents and post them here.
hi,

Are you doing it in safe mode?

Delete the copy you have and download a fresh copy….


if it won't run…just run the rooter tool, then try this tool:

Download Dr.Web CureIt to the desktop:
  • Doubleclick the drweb-cureit icon to start the program.
  • press start
  • Allow the program to run the initial express scan
  • This will scan the files currently running in memory. If something is found, click the YES button when it asks you if you want to cure it. This is only a short scan.
    Note: A pop up may appear during this phase suggesting you purchase their program - click the X at the top right corner of this pop-up to close it.
  • Once the short scan has finished, check the Complete scan box on the left side, even if nothing was found on the initial scan.
  • Then click the small green arrow button on the right under the Dr.Web Antivirus picture to start the complete scan. (This scan will take several hours)
  • During this complete scan - if Dr.Web finds an infection a window will pop up requesting your attention. Select the Cure button.
    • Note:(If the file cannot be cured, Dr.Web will automatically delete the file)
  • Once the scan is complete, on the menu bar, click file and choose report list.
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Note:this report will need to be renamed to Dr.Web.txt in order to post it on the forum.
  • Close Dr.Web Cureit.
  • Please post the Dr.Web.txt report in your next reply
hi i had to use the Dr.Web CureIt..i did the short scan and it didnt find anything..when i tried to continue i got a message saying something like the program and applications encountered an error and needs to close..that made my system reboot.. i experienced other errors as well in the middle of the scan..so icouldnt do the full scan and i'm having the same problems..i'm not on my computer and i plogize for not being able to tellyou exactly what the errors were..i have at least 1 screen shot of the 1st error..but not so sure about the 2nd because it was done in the midlle of a forced shut down (i forgot to mention that& it also had a timertill shut down)
Hi,

well that's not good news

were you able to get Rooter to run?

If so can you post the log.

Lets try a diagnostic tool to see if we can see what is going on to cause all these crashes

Please do the following:

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt.
    Note:These logs can be located in the OTListIt2. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
yes rooter ran..i cant post a log right now because i'm no home..but i will when i get there which will probably be sometime late tonight. when i had done the sdfix it wouldnt work in safe mode either..rooter i did in regular mode..am i suppose to do the dr program in safe mode?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI