This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] wowfx.dll and ssqPgDtq.dll Part Two

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Old thread:

http://forums.whatthetech.com/wowfx_dll_ss…ll_t102420.html

(I do have legit Windows, not sure what muBlinder is, I'll ask my bro)


OK.

ComboFix seemed to fix it, but then two days later AVG found the viruses again and it kept restarting my computer and AVG went mental with the same virus dll names and another random one.
So I ran it again, and AVG is quiet again.

I am worried it will reappear…


Please help, I will be eternally grateful!

HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:40:46, on 30/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe
D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
D:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
D:\PROGRA~1\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
D:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Documents and Settings\mike\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
E:\Program Files\utorrent.exe
D:\Program Files\Kontiki\KHost.exe
D:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe
D:\Program Files\Logitech\SetPoint\SetPoint.exe
D:\Program Files\OpenOffice.org 3\program\soffice.exe
D:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe
D:\Program Files\OpenOffice.org 3\program\soffice.bin
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
D:\PROGRA~1\AVG\AVG8\avgrsx.exe
D:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
D:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
D:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\mike\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\notepad.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {15C2DE55-9796-4657-AAA5-EB605D6C5F9A} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file)
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [BtTray] "D:\Program Files\IVT Corporation\BlueSoleil\BtTray.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [StartCCC] "D:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Google Desktop Search] "D:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "D:\PROGRA~1\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [NokiaMServer] C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles
O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [muBlinder] C:\Documents and Settings\mike\Desktop\muBlinder\muBlinder.exe -startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\mike\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [uTorrent] "E:\Program Files\utorrent.exe"
O4 - HKCU\..\Run: [kdx] D:\Program Files\Kontiki\KHost.exe -all
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] D:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.0.lnk = D:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Logitech SetPoint.lnk = D:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\Microsoft Office\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - (no file)
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\DLink\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (Egg Money Manager Digital Safe) - https://moneymanager.egg.com/Pinsafe/accounttracking.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1228927274578
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1228927252500
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: BlueSoleilCS - Unknown owner - D:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe
O23 - Service: BsHelpCS - Unknown owner - D:\Program Files\IVT Corporation\BlueSoleil\BsHelpCS.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - D:\Program Files\DLink\Bluetooth Software\bin\btwdins.exe
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - D:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - D:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: ServiceLayer - Nokia. - D:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - D:\Program Files\Spyware Terminator\sp_rsser.exe

–
End of file - 11469 bytes


Next post will contain a ComboFix log (after running)
ComboFix 09-04-29.01 - mike 30/04/2009 1:29.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2047.1440 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
AV: BitDefender Antivirus *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\mike\Start Menu\Programs\Startup\userinit.exe
c:\documents and settings\mike\svchost.exe
c:\windows\system32\drivers\services.exe
c:\windows\system32\jkkJdDVL.dll
c:\windows\system32\LVDdJkkj.ini
c:\windows\system32\LVDdJkkj.ini2
c:\windows\system32\wowfx.dll
d:\program files\altcmd
d:\program files\altcmd\altcmd.inf
d:\program files\altcmd\altcmd32.dll
d:\program files\altcmd\uninstall.bat

—– BITS: Possible infected sites —–

hxxp://ccp.vo.llnwd.net
.
((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-4-30 )))))))))))))))))))))))))))))))
.

2009-04-29 23:52 . 2009-04-29 23:52 ——– d—–w c:\windows\system32\append.dll
2009-04-29 23:52 . 2009-04-29 23:52 ——– d—–w c:\windows\system32\xlib254.dll
2009-04-29 23:52 . 2006-08-28 05:57 57344 —-a-w c:\windows\system32\digest32.dll
2009-04-29 18:56 . 2009-04-29 18:56 ——– d—–w d:\program files\Veetle
2009-04-28 14:10 . 2009-04-28 14:10 ——– d—–w C:\_OTScanIt
2009-04-27 15:39 . 2009-04-27 15:39 ——– d—–w d:\program files\MeadCo Neptune
2009-04-27 12:32 . 2009-04-27 12:32 ——– d—–w d:\program files\GSpot
2009-04-24 16:05 . 2009-04-24 16:05 ——– d—–w c:\documents and settings\mike\Local Settings\Application Data\CCP
2009-04-24 15:25 . 2009-04-24 15:25 ——– d—–w c:\documents and settings\All Users\Application Data\CCP
2009-04-24 15:25 . 2009-04-24 15:25 ——– d—–w d:\program files\CCP
2009-04-24 09:17 . 2009-04-24 09:17 ——– d-sh–w c:\documents and settings\mike\03BDB09EB178B718
2009-04-19 11:58 . 2009-04-19 11:58 10520 —-a-w c:\windows\system32\avgrsstx.dll
2009-04-19 11:58 . 2009-04-19 11:58 108552 —-a-w c:\windows\system32\drivers\avgtdix.sys
2009-04-19 11:58 . 2009-04-19 11:58 325640 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-04-19 11:58 . 2009-04-29 09:14 ——– d—–w c:\windows\system32\drivers\Avg
2009-04-19 11:57 . 2009-04-19 11:57 ——– d—–w c:\windows\system32\Migration
2009-04-19 11:55 . 2009-04-19 11:55 ——– d—–w c:\documents and settings\mike\Application Data\Bitdefender
2009-04-18 11:25 . 2009-04-19 11:52 81984 —-a-w c:\windows\system32\bdod.bin
2009-04-18 11:18 . 2009-04-19 11:56 ——– d—–w c:\program files\Common Files\BitDefender
2009-04-18 11:18 . 2009-04-18 11:20 ——– d—–w c:\documents and settings\All Users\Application Data\BitDefender
2009-04-18 11:18 . 2009-04-18 11:18 ——– d—–w d:\program files\BitDefender
2009-04-17 20:40 . 2009-04-17 20:40 ——– d—–w c:\documents and settings\NetworkService\Application Data\Trusteer
2009-04-17 17:46 . 2009-04-17 17:46 ——– d—–w d:\program files\DIFX
2009-04-17 17:46 . 2008-08-26 08:26 18816 —-a-w c:\windows\system32\drivers\pccsmcfd.sys
2009-04-17 12:40 . 2009-04-17 12:40 ——– d—–w c:\documents and settings\mike\Application Data\Trusteer
2009-04-17 12:39 . 2009-04-17 12:39 ——– d—–w d:\program files\Trusteer
2009-04-15 19:43 . 2009-04-15 19:43 ——– d—–w c:\documents and settings\mike\Application Data\PPLiveVA
2009-04-15 19:43 . 2009-04-15 19:43 ——– d—–w c:\documents and settings\mike\Local Settings\Application Data\VirtualStore
2009-04-15 19:43 . 2009-04-16 20:48 ——– d—–w d:\program files\PPLiveVA
2009-04-15 19:42 . 2009-04-16 20:48 ——– d—–w c:\documents and settings\All Users\Application Data\PPLiveVA
2009-04-15 12:03 . 2009-03-06 14:22 284160 -c—-w c:\windows\system32\dllcache\pdh.dll
2009-04-15 12:03 . 2009-02-09 12:10 401408 -c—-w c:\windows\system32\dllcache\rpcss.dll
2009-04-15 12:03 . 2009-02-06 11:11 110592 -c—-w c:\windows\system32\dllcache\services.exe
2009-04-15 12:03 . 2009-02-09 12:10 473600 -c—-w c:\windows\system32\dllcache\fastprox.dll
2009-04-15 12:03 . 2009-02-06 10:10 227840 -c—-w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-15 12:03 . 2009-02-09 12:10 453120 -c—-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-15 12:03 . 2009-02-09 12:10 729088 -c—-w c:\windows\system32\dllcache\lsasrv.dll
2009-04-15 12:03 . 2009-02-09 12:10 617472 -c—-w c:\windows\system32\dllcache\advapi32.dll
2009-04-15 12:03 . 2009-02-09 12:10 714752 -c—-w c:\windows\system32\dllcache\ntdll.dll
2009-04-15 12:03 . 2008-05-03 11:55 2560 —-a-w c:\windows\system32\xpsp4res.dll
2009-04-15 12:03 . 2008-04-21 12:08 215552 -c—-w c:\windows\system32\dllcache\wordpad.exe
2009-04-14 14:12 . 2009-04-06 14:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-04-14 14:12 . 2009-04-06 14:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-14 14:12 . 2009-04-14 14:12 ——– d—–w d:\program files\Malwarebytes' Anti-Malware
2009-04-06 15:16 . 2009-04-06 15:16 ——– d—–w c:\documents and settings\mike\Application Data\Malwarebytes
2009-04-06 15:16 . 2009-04-06 15:16 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-06 14:27 . 2009-04-06 14:27 ——– d-sh–w c:\windows\system32\config\systemprofile\IETldCache
2009-04-06 14:27 . 2009-04-06 14:27 ——– d-sh–w c:\documents and settings\NetworkService\IETldCache
2009-04-06 14:13 . 2009-02-20 18:09 78336 —-a-w c:\windows\system32\ieencode.dll
2009-04-06 13:42 . 2009-04-06 13:42 ——– d—–w d:\program files\Trend Micro
2009-04-06 12:58 . 2009-04-06 12:58 ——– d—–w c:\documents and settings\mike\Local Settings\Application Data\{264D4B86-1F8E-40E4-941B-E11ED7D7C769}
2009-04-06 10:22 . 2009-04-06 10:21 142592 —-a-w c:\windows\system32\drivers\sp_rsdrv2.sys
2009-04-06 10:21 . 2009-04-28 11:35 ——– d—–w c:\documents and settings\mike\Application Data\Spyware Terminator
2009-04-06 10:21 . 2009-04-29 09:51 ——– d—–w c:\documents and settings\All Users\Application Data\Spyware Terminator
2009-04-06 10:21 . 2009-04-27 19:03 ——– d—–w d:\program files\Spyware Terminator
2009-04-04 17:06 . 2009-04-14 10:50 16 —-a-w c:\windows\Emimog.bin
2009-04-04 17:06 . 2009-04-14 14:03 1420 —-a-w c:\windows\Dpeyewahatewis.dat
2009-04-02 12:13 . 2002-12-10 01:20 102439 —-a-w c:\windows\system32\sipr3260.dll
2009-04-02 12:13 . 2006-09-29 11:24 217127 —-a-w c:\windows\system32\drv43260.dll
2009-04-02 12:13 . 2006-09-29 11:25 208935 —-a-w c:\windows\system32\drv33260.dll
2009-04-02 12:13 . 2006-09-29 11:26 176165 —-a-w c:\windows\system32\drv23260.dll
2009-04-02 12:13 . 2007-03-18 19:37 65602 —-a-w c:\windows\system32\cook3260.dll
2009-04-02 12:13 . 2006-05-11 18:21 626688 —-a-w c:\windows\system32\vp7vfw.dll
2009-04-02 12:13 . 2006-05-20 15:16 1184984 —-a-w c:\windows\system32\wvc1dmod.dll
2009-04-02 11:53 . 2009-04-02 11:53 ——– d—–w d:\program files\XviD
2009-04-02 11:40 . 2009-04-02 11:40 ——– d—–w d:\program files\AviSynth 2.5

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-29 16:13 . 2007-11-26 16:57 ——– d—–w d:\program files\Mozilla Firefox 3 Beta 1
2009-04-29 10:15 . 2006-03-12 02:45 ——– d—–w d:\program files\Mozilla Thunderbird
2009-04-28 23:12 . 2008-11-20 13:39 ——– d—–w d:\program files\Foobar2000
2009-04-27 15:42 . 2007-09-11 19:01 ——– d—–w d:\program files\Opera 9
2009-04-24 16:10 . 2009-02-12 19:22 598808 —-a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-04-24 12:18 . 2006-03-12 02:52 ——– d—–w d:\program files\Steam
2009-04-18 14:17 . 2007-09-11 23:58 ——– d—–w d:\program files\Nokia
2009-04-18 12:43 . 2007-09-11 23:58 ——– d—–w c:\program files\Common Files\Nokia
2009-04-08 17:20 . 2008-09-02 17:14 ——– d—–w d:\program files\Unlocker
2009-04-06 16:04 . 2008-06-16 20:59 ——– d—–w d:\program files\Digsby
2009-04-02 12:13 . 2008-08-12 11:42 47360 —-a-w c:\windows\system32\drivers\pcouffin.sys
2009-04-02 12:13 . 2008-08-12 11:42 47360 —-a-w c:\documents and settings\mike\Application Data\pcouffin.sys
2009-04-02 12:13 . 2008-08-12 11:42 ——– d—–w d:\program files\VSO
2009-04-02 11:40 . 2008-08-08 10:44 ——– d—–w d:\program files\Avi2Dvd
2009-04-02 09:56 . 2007-09-13 11:44 ——– d—–w d:\program files\Spybot - Search & Destroy
2009-04-01 10:23 . 2007-09-11 21:00 ——– d—–w d:\program files\Java
2009-03-23 16:43 . 2008-05-29 23:29 ——– d—–w d:\program files\MSECACHE
2009-03-20 11:00 . 2009-03-19 15:03 ——– d—–w d:\program files\Windows Desktop Search
2009-03-20 10:59 . 2008-02-03 22:10 ——– d—–w d:\program files\Microsoft Silverlight
2009-03-19 14:06 . 2008-02-06 15:07 ——– d—–w c:\program files\Common Files\Adobe
2009-03-17 18:06 . 2008-04-01 17:38 ——– d—–w d:\program files\Soulseek
2009-03-12 10:28 . 2009-03-11 20:35 ——– d—–w d:\program files\TVAnts
2009-03-09 04:19 . 2008-09-03 13:09 410984 —-a-w c:\windows\system32\deploytk.dll
2009-03-08 18:41 . 2008-04-17 09:58 ——– d—–w d:\program files\NZBPlayer
2009-03-06 14:22 . 2004-08-04 04:56 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2004-08-04 04:56 826368 —-a-w c:\windows\system32\wininet.dll
2009-02-17 23:49 . 2007-09-11 18:50 89608 —-a-w c:\documents and settings\mike\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-02-16 21:43 . 2007-09-11 18:50 1488688 —-a-w c:\windows\system32\muBlinder_ValBackup.dll
2009-02-10 20:05 . 2007-12-04 03:14 73880 —ha-w c:\windows\system32\mlfcache.dat
2009-02-09 12:10 . 2004-08-04 04:56 729088 —-a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2004-08-04 04:56 401408 —-a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2004-08-04 04:56 617472 —-a-w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2004-08-04 04:56 714752 —-a-w c:\windows\system32\ntdll.dll
2009-02-09 11:13 . 2004-08-04 03:17 1846784 —-a-w c:\windows\system32\win32k.sys
2009-02-07 18:02 . 2004-08-03 22:59 2066048 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-02-06 11:11 . 2004-08-04 04:56 110592 —-a-w c:\windows\system32\services.exe
2009-02-06 11:08 . 2004-08-04 03:20 2189056 —-a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2004-08-07 00:17 35328 —-a-w c:\windows\system32\sc.exe
2009-02-03 19:59 . 2004-08-04 04:56 56832 —-a-w c:\windows\system32\secur32.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-04-24_10.20.25 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-30 00:33 . 2009-04-30 00:33 16384 c:\windows\Temp\Perflib_Perfdata_86c.dat
- 2007-09-11 17:55 . 2009-04-24 09:14 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-09-11 17:55 . 2009-04-30 00:32 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-09-11 17:55 . 2009-04-24 09:14 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-09-11 17:55 . 2009-04-30 00:32 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-09-11 17:55 . 2009-04-24 09:14 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2007-09-11 17:55 . 2009-04-30 00:32 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2004-08-04 04:56 . 2008-04-14 00:12 578560 c:\windows\system32\user32.dll
- 2004-08-04 04:56 . 2005-10-01 19:42 578560 c:\windows\system32\user32.dll
- 2004-08-04 04:56 . 2005-10-01 19:42 578560 c:\windows\system32\dllcache\user32.dll
+ 2004-08-04 04:56 . 2005-10-07 09:24 578560 c:\windows\system32\dllcache\user32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="d:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-12 68856]
"Google Update"="c:\documents and settings\mike\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-02 133104]
"uTorrent"="e:\program files\utorrent.exe" [2009-04-28 282416]
"kdx"="d:\program files\Kontiki\KHost.exe" [2008-02-27 1032376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"BtTray"="d:\program files\IVT Corporation\BlueSoleil\BtTray.exe" [2008-05-12 258134]
"GrooveMonitor"="d:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"StartCCC"="d:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-07-07 185896]
"Google Desktop Search"="d:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-02-12 30192]
"QuickTime Task"="d:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"SpywareTerminator"="d:\progra~1\Spyware Terminator\SpywareTerminatorShield.exe" [2009-04-06 2176000]
"AVG8_TRAY"="d:\progra~1\AVG\AVG8\avgtray.exe" [2009-04-19 1932568]
"muBlinder"="c:\documents and settings\mike\Desktop\muBlinder\muBlinder.exe" [2009-04-02 1464320]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-10-10 69632]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="d:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 1241088]

c:\documents and settings\mike\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - d:\program files\OpenOffice.org 3\program\quickstart.exe [2008-12-15 384000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - d:\program files\Logitech\SetPoint\SetPoint.exe [2008-12-21 809488]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-11-07 16:41 72208 —-a-w c:\program files\common files\logishrd\bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-19 11:58 10520 —-a-w c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, snapapi32.dll, digest32.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BTTray.lnk]
backup=c:\windows\pss\BTTray.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NETGEAR WG311v3 Smart Wizard.lnk]
backup=c:\windows\pss\NETGEAR WG311v3 Smart Wizard.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Nokia Nseries PC Suite.lnk]
backup=c:\windows\pss\Nokia Nseries PC Suite.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Nokia PC Phone Tray Application.lnk]
backup=c:\windows\pss\Nokia PC Phone Tray Application.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^mike^Start Menu^Programs^Startup^OpenOffice.org 2.4.lnk]
backup=c:\windows\pss\OpenOffice.org 2.4.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^mike^Start Menu^Programs^Startup^PowerMenu.lnk]
backup=c:\windows\pss\PowerMenu.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^mike^Start Menu^Programs^Startup^Sins of a Solar Empire Launcher.lnk]
backup=c:\windows\pss\Sins of a Solar Empire Launcher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"KService"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\Steam\\SteamApps\\[removed]\\counter-strike\\hl.exe"=
"d:\\Program Files\\xchat\\xchat.exe"=
"d:\\Program Files\\Steam\\steam.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"e:\\Program Files\\utorrent.exe"=
"d:\\Program Files\\Kontiki\\KService.exe"=
"d:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleilCS.exe"=
"d:\\Program Files\\iTunes\\iTunes.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\System32\\svchost.exe"= c:\\WINDOWS\\system32\\svchost.exe
"c:\\WINDOWS\\system32\\wbem\\wmiprvse.exe"=
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"d:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"d:\\Program Files\\Steam\\SteamApps\\common\\red orchestra\\System\\RedOrchestra.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4719:TCP"= 4719:TCP:4719

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;d:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2009-02-12 30192]
R3 hitmanpro3;Hitman Pro 3 Support Driver; [x]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-04-19 325640]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-04-19 108552]
S1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2009-04-06 142592]
S2 avg8wd;AVG Free8 WatchDog;d:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-04-19 298264]
S2 LBeepKE;LBeepKE;c:\windows\system32\Drivers\LBeepKE.sys [2008-09-26 10384]


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5aa214f2-6fff-11dc-a20c-000c41270de2}]
\Shell\AutoRun\command - J:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder

2009-04-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- d:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2009-04-30 c:\windows\Tasks\GlaryInitialize.job
- d:\program files\Glary Utilities\initialize.exe [2008-07-22 10:08]

2009-04-30 c:\windows\Tasks\Google Software Updater.job
- d:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-09-11 15:01]

2009-04-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-682003330-261903793-725345543-1003.job
- c:\documents and settings\mike\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-02 23:09]
.
- - - - ORPHANS REMOVED - - - -

BHO-{5FEFE3F4-6828-4E43-B223-9D9C293FE3B8} - c:\windows\system32\jkkJdDVL.dll
Notify-qoMgfCtt - qoMgfCtt.dll


.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} - hxxps://moneymanager.egg.com/Pinsafe/accounttracking.cab
FF - ProfilePath - c:\documents and settings\mike\Application Data\Mozilla\Firefox\Profiles\aa2wu6md.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://news.bbc.co.uk/|http://news.google.com/
FF - component: d:\program files\Mozilla Firefox 3 Beta 1\components\GoogleDesktopMozilla.dll
FF - plugin: c:\documents and settings\mike\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: d:\progra~1\MEADCO~1\npmeadax.dll
FF - plugin: d:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: d:\program files\Mozilla Firefox 3 Beta 1\plugins\np-mswmp.dll
FF - plugin: d:\program files\Opera 9\program\plugins\npdivx32.dll
FF - plugin: d:\program files\Opera 9\program\plugins\NPOFF12.DLL
FF - plugin: d:\program files\Opera 9\program\plugins\npqtplugin.dll
FF - plugin: d:\program files\Opera 9\program\plugins\npqtplugin2.dll
FF - plugin: d:\program files\Opera 9\program\plugins\npqtplugin3.dll
FF - plugin: d:\program files\Opera 9\program\plugins\npqtplugin4.dll
FF - plugin: d:\program files\Opera 9\program\plugins\npqtplugin5.dll
FF - plugin: d:\program files\Opera 9\program\plugins\npqtplugin6.dll
FF - plugin: d:\program files\Opera 9\program\plugins\npqtplugin7.dll
FF - plugin: d:\program files\Opera 9\program\plugins\NPSWF32.dll

—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.notify.interval - 600000
FF - user.js: content.switch.threshold - 1000000
FF - user.js: nglayout.initialpaint.delay - 600
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-30 01:33
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-682003330-261903793-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{21F0C5B7-25DB-4D81-5AFD-74098EE37085}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"gafdgjgnndpdcl"=hex:63,61,66,70,63,6c,00,00

[HKEY_USERS\S-1-5-21-682003330-261903793-725345543-1003\Software\SecuROM\License information*]
"datasecu"=hex:a5,fd,27,74,e7,ce,a5,6f,74,9b,ee,6d,a1,8f,e9,e7,9a,cc,77,15,1e,
69,12,9a,30,87,24,bd,2c,60,54,13,11,89,7d,6d,c8,15,0d,91,f9,6d,09,2f,35,a9,\
"rkeysecu"=hex:48,1d,d2,48,97,43,63,c8,bb,32,cb,31,da,01,13,78
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(728)
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll

- - - - - - - > 'lsass.exe'(784)
c:\windows\system32\wininet.dll

- - - - - - - > 'explorer.exe'(1960)
d:\program files\Logitech\SetPoint\GameHook.dll
d:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\BsLangInDepRes.dll
c:\windows\system32\Bs2Res.dll
c:\windows\system32\btncopy.dll
d:\program files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
d:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
d:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_eng.nlr
d:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\rundll32.exe
d:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
d:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Common Files\Nokia\MPlatform\NokiaMServer.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
d:\program files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe
d:\program files\OpenOffice.org 3\program\soffice.exe
d:\program files\DLink\Bluetooth Software\bin\btwdins.exe
d:\program files\OpenOffice.org 3\program\soffice.bin
d:\program files\Java\jre6\bin\jqs.exe
d:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
d:\program files\AVG\AVG8\avgrsx.exe
d:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
d:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
d:\program files\Spyware Terminator\sp_rsser.exe
d:\program files\IVT Corporation\BlueSoleil\BsHelpCS.exe
c:\documents and settings\mike\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
c:\documents and settings\mike\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
c:\documents and settings\mike\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
c:\documents and settings\mike\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
c:\documents and settings\mike\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
c:\documents and settings\mike\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
c:\documents and settings\mike\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
.
**************************************************************************
.
Completion time: 2009-04-30 1:37 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-30 00:37
ComboFix2.txt 2009-04-24 10:22

Pre-Run: 11,872,178,176 bytes free
Post-Run: 12,166,205,440 bytes free

381
Hi there my apologies for the delay but you appear to have dropped of my radar :blush:

There are still malware files there but one is tied in to your lsa system so I will need a different tool to remove it

To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link.

Download OTScanit2 to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt on your desktop.
  • Close ALL OTHER PROGRAMS.
  • Open the OTScanit folder and double-click on OTScanit.exe to start the program.
  • Check the box that says Scan All Users
  • Check the Radio button for Rootkit check YES
  • Under Additional Scans check the following:
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EventViewer Errors/Warnings (last 10)
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
During the scan AVG picked up two .dll files which I removed. I couldn't check the all users box for some reason, when I did a pink box appeared round it but it didn't seem to stay that way after I pressed Scan. 📎OTScanIt.Txt
OK lets give this a run and on completion let me know how your computer is running

Start OTScanit. Copy/Paste the information in the quotebox below into the pane where it says "Paste fix here" and then click the Run Fix button.

[Unregister Dlls]
[Registry - Safe List]
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {FE063DB1-4EC0-403e-8DD8-394C54984B2C} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
YN -> WebBrowser\\"{FE063DB9-4EC0-403E-8DD8-394C54984B2C}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls
YY -> C:\WINDOWS\system32\wowfx.dll -> %SystemRoot%\system32\wowfx.dll
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders
*SecurityProviders* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders
YY -> snapapi32.dll -> %SystemRoot%\system32\snapapi32.dll
YY -> digest32.dll -> %SystemRoot%\system32\digest32.dll
< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders
[Files/Folders - Created Within 30 Days]
NY -> nopscdf.exe -> %SystemDrive%\nopscdf.exe
NY -> xrnvhqk.exe -> %SystemDrive%\xrnvhqk.exe
NY -> jbmiye.exe -> %SystemDrive%\jbmiye.exe
NY -> mjdgyuwj.exe -> %SystemDrive%\mjdgyuwj.exe
[Empty Temp Folders]

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here along with a new OTScanit log.

I will review the information when it comes back in.

Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.
During the scan AVG a Trojan Horse Generic9.ACFR found a .dll in temp found "on open", so a moved it to a vault [Registry - Safe List] Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{FE063DB9-4EC0-403E-8DD8-394C54984B2C} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE063DB9-4EC0-403E-8DD8-394C54984B2C}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\WINDOWS\system32\wowfx.dll deleted successfully. File C:\WINDOWS\system32\wowfx.dll not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders:snapapi32.dll deleted successfully. LoadLibrary failed for C:\WINDOWS\system32\snapapi32.dll C:\WINDOWS\system32\snapapi32.dll NOT unregistered. C:\WINDOWS\system32\snapapi32.dll moved successfully. Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders:digest32.dll scheduled to be deleted on reboot. File C:\WINDOWS\system32\digest32.dll not found. [Files/Folders - Created Within 30 Days] File C:\nopscdf.exe not found! File C:\xrnvhqk.exe not found! File C:\jbmiye.exe not found! File C:\mjdgyuwj.exe not found! [Empty Temp Folders] File delete failed. C:\Documents and Settings\mike\Local Settings\Temp\Temporary Internet Files\Content.IE5\D6SE18DQ\client[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\mike\Local Settings\Temp\Temporary Internet Files\Content.IE5\D5SCZ2UY\adv0001[1].htm scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\mike\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\mike\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\mike\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\mike\Local Settings\Temp\etilqs_bexv4vuv8cVapfLTK7Fr scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\mike\Local Settings\Temp\etilqs_YW1G67wfvIevUUZhAGEE scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\mike\Local Settings\Temp\~DF2D98.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\mike\Local Settings\Temp\~DF31B3.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\mike\Local Settings\Temp\~DF7753.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\mike\Local Settings\Temp\~DF7ACD.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Documents and Settings\mike\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. User's Temporary Internet Files folder emptied. Local Service Temp folder emptied. Local Service Temporary Internet Files folder emptied. Network Service Temp folder emptied. File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Network Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_390.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. FireFox cache emptied. RecycleBin -> emptied. < End of fix log > OTScanIt2 by OldTimer - Version 1.0.14.0 fix logfile created on 05062009_210529 Files moved on Reboot… C:\Documents and Settings\mike\Local Settings\Temp\Temporary Internet Files\Content.IE5\D6SE18DQ\client[1].htm moved successfully. File C:\Documents and Settings\mike\Local Settings\Temp\Temporary Internet Files\Content.IE5\D5SCZ2UY\adv0001[1].htm not found! File C:\Documents and Settings\mike\Local Settings\Temp\etilqs_bexv4vuv8cVapfLTK7Fr not found! File C:\Documents and Settings\mike\Local Settings\Temp\etilqs_YW1G67wfvIevUUZhAGEE not found! File C:\Documents and Settings\mike\Local Settings\Temp\~DF2D98.tmp not found! C:\Documents and Settings\mike\Local Settings\Temp\~DF31B3.tmp moved successfully. C:\Documents and Settings\mike\Local Settings\Temp\~DF7753.tmp moved successfully. File C:\Documents and Settings\mike\Local Settings\Temp\~DF7ACD.tmp not found! File C:\WINDOWS\temp\Perflib_Perfdata_390.dat not found! Registry entries deleted on Reboot… Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders:digest32.dll scheduled to be deleted on reboot. 📎OTScanIt.Txt
Looks much better now a final few to remove and then a scan for orphans

Start OTScanit. Copy/Paste the information in the quotebox below into the pane where it says "Paste fix here" and then click the Run Fix button.

[Unregister Dlls]
[Registry - Safe List]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YY -> "muBlinder" -> %UserProfile%\Desktop\muBlinder\muBlinder.exe [C:\Documents and Settings\mike\Desktop\muBlinder\muBlinder.exe -startup]
[Custom Items]
:reg
[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{21F0C5B7-25DB-4D81-5AFD-74098EE37085}]
:end
[Empty Temp Folders]

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here.

I will review the information when it comes back in.

THEN

[external image: Posted Image] Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.


Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.
Think AVG found something again randomly, but it might have been in system restore, should I disable/enable? [Registry - Safe List] Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\muBlinder not found. File C:\Documents and Settings\mike\Desktop\muBlinder\muBlinder.exe not found. [Custom Items] ========== REGISTRY ========== Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{21F0C5B7-25DB-4D81-5AFD-74098EE37085}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21F0C5B7-25DB-4D81-5AFD-74098EE37085}\ not found. [Empty Temp Folders] File delete failed. C:\Documents and Settings\mike\Local Settings\Temp\svfhp.tmp\svg13.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\mike\Local Settings\Temp\svfhp.tmp\svg2p.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\mike\Local Settings\Temp\svfhp.tmp\svg33.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\mike\Local Settings\Temp\svfhp.tmp\svg39.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\mike\Local Settings\Temp\etilqs_1v4HPCCJxu5ncf2clk7W scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\mike\Local Settings\Temp\etilqs_eNvWaezDkHRo7hCiIder scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\mike\Local Settings\Temp\etilqs_w6LVdfJKj0GulttO9PPj scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\mike\Local Settings\Temp\~DFC591.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\mike\Local Settings\Temp\~DFCF36.tmp scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\mike\Local Settings\Temp\~DFD2F9.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Documents and Settings\mike\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. User's Temporary Internet Files folder emptied. Local Service Temp folder emptied. Local Service Temporary Internet Files folder emptied. Network Service Temp folder emptied. File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Network Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_214.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. FireFox cache emptied. RecycleBin -> emptied. < End of fix log > OTScanIt2 by OldTimer - Version 1.0.14.0 fix logfile created on 05072009_204930 Files moved on Reboot… File C:\Documents and Settings\mike\Local Settings\Temp\svfhp.tmp\svg13.tmp not found! C:\Documents and Settings\mike\Local Settings\Temp\svfhp.tmp\svg2p.tmp moved successfully. File C:\Documents and Settings\mike\Local Settings\Temp\svfhp.tmp\svg33.tmp not found! File C:\Documents and Settings\mike\Local Settings\Temp\svfhp.tmp\svg39.tmp not found! File C:\Documents and Settings\mike\Local Settings\Temp\etilqs_1v4HPCCJxu5ncf2clk7W not found! File C:\Documents and Settings\mike\Local Settings\Temp\etilqs_eNvWaezDkHRo7hCiIder not found! File C:\Documents and Settings\mike\Local Settings\Temp\etilqs_w6LVdfJKj0GulttO9PPj not found! C:\Documents and Settings\mike\Local Settings\Temp\~DFC591.tmp moved successfully. File C:\Documents and Settings\mike\Local Settings\Temp\~DFCF36.tmp not found! C:\Documents and Settings\mike\Local Settings\Temp\~DFD2F9.tmp moved successfully. File C:\WINDOWS\temp\Perflib_Perfdata_214.dat not found! Registry entries deleted on Reboot… MBAM: Malwarebytes' Anti-Malware 1.36 Database version: 2000 Windows 5.1.2600 Service Pack 3 08/05/2009 10:48:53 mbam-log-2009-05-08 (10-48-53).txt Scan type: Quick Scan Objects scanned: 81839 Time elapsed: 4 minute(s), 31 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Not selected for removal. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) I didn't want to remove the disabled security. I think everything has fixed, except AVG finds things in System Restore, shall I disable/enable? Thank you very much for your help!
Subject to no further problems lets kill the restore points and send you on your way

Now the best part of the day —– Your log now appears clean :thumbup:

A good workman always cleans up after himself so..Run OTListit and hit the cleanup button. It will remove all the programmes we have used plus itself. MBAM can be uninstalled via control panel add/remove along with ERUNT. But they may be useful tools to keep

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.

[external image: Posted Image] Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. Beware it is NOT supported for use in 9x or ME and probably will not install in those systems

Upgrading Java:
  • Download the latest version of Java SE Runtime Environment (JRE)JRE 6 Update 13.
  • Click the "Download" button to the right.
  • Select your Platform and check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement.".
  • Click on Continue.
  • Click on the link to download Windows Offline Installation (jre-6u13-windows-i586-p.exe) and save it to your desktop. Do NOT use the Sun Download Manager..
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the jre-6u13-windows-i586-p.exe and select "Run as an Administrator.")

XP
Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:
  • Select Start > All Programs > Accessories > System tools > System Restore.
  • On the dialogue box that appears select Create a Restore Point
  • Click NEXT
  • Enter a name e.g. Clean
  • Click CREATE
You now have a clean restore point, to get rid of the bad ones:
  • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
  • In the Drop down box that appears select your main drive e.g. C
  • Click OK
  • The System will do some calculation and the display a dialogue box with TABS
  • Select the More Options Tab.
  • At the bottom will be a system restore box with a CLEANUP button click this
  • Accept the Warning and select OK again, the program will close and you are done

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
  • SpywareBlaster to help prevent spyware from installing in the first place.
  • SuperAntispyware Run weekly to keep your system clean
It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit

To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?
Keep safe :wavey:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI