Turok
Topic Starter
I did all the steps self help told me to i scanned with malwarebytes' anti-malware and provided you with the log
also used thed ERUNT program to back up my registry files
also used HighjackThis to provide you with a log which i will type out
i cant use the registry every time i try start>run>regedit it says "Registry Editing Has been disabled by your administrator". Yet i am the administrator it still says this, and i have no access to the Task Manager. Someone please help me
-Regards,
Turok
P.S: everytime i do the scan and then restart PC the regedit gets locked again and again it seems those programs arent solving the direct problem only the smaller ones.
___________________________________________________
"Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:58:15 AM, on 5/27/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\idt\intelel_v104\wdm\STacSV.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Razer\Tarantula\razerhid.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\EVGA Precision\Bundle\OSDServer\RTSS.exe
C:\Program Files\EVGA Precision\EVGAPrecision.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Razer\Tarantula\razertra.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\user\Desktop\PC things links etc\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe, explorer.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LXCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Tarantula] C:\Program Files\Razer\Tarantula\razerhid.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" -start
O4 - HKLM\..\Run: [RivaTunerStatisticsServer] "C:\Program Files\EVGA Precision\Bundle\OSDServer\RTSS.exe" /s
O4 - HKLM\..\Run: [EVGAPrecision] "C:\Program Files\EVGA Precision\EVGAPrecision.exe" /s
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: Tournament Shark.lnk = C:\Program Files\Poker Pro Labs\Tournament Shark\TournamentShark.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Download; All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download; with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\user\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\user\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: Web-Based Email Tools - http://email.secureserver.net/Download.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{F61F8A23-0D5D-4DEB-B191-54C280EA55D3}: NameServer = 192.168.1.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcc_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcccoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - c:\program files\idt\intelel_v104\wdm\STacSV.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe (file missing)
–
End of file - 8713 bytes
"
I also provided you guys with the COMBO FIX LOG
__________________________________________________
ComboFix 09-05-26.02 - Lord Heave 05/27/2009 2:26.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2558.2025 [GMT 3:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\user\LOCALS~1\Temp\ivfjb.exe
c:\documents and settings\user\Local Settings\temp\ivfjb.exe
c:\windows\system32\drivers\fetpz.sys
c:\windows\system32\drivers\gxgzwwy.sys
D:\2u.com
D:\68.exe
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-04-26 to 2009-05-26 )))))))))))))))))))))))))))))))
.
2009-05-26 22:35 . 2009-05-26 22:35 ——– d—–w c:\program files\ERUNT
2009-05-26 21:20 . 2009-05-26 21:20 ——– d—–w c:\documents and settings\user\Application Data\Malwarebytes
2009-05-26 21:19 . 2009-05-26 10:20 40160 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 21:19 . 2009-05-26 21:20 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-26 21:19 . 2009-05-26 21:19 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-26 21:19 . 2009-05-26 10:19 19096 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-26 21:10 . 2009-05-26 21:12 ——– d—–w C:\CCleaner
2009-05-26 19:59 . 2009-05-26 19:59 167376 —-a-w c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\j2lm3ea1.default\FlashGot.exe
2009-05-26 19:49 . 2009-05-26 22:01 ——– d–h–w C:\$AVG8.VAULT$
2009-05-26 19:44 . 2009-05-26 19:44 ——– d—–w c:\program files\AVG
2009-05-26 18:07 . 2009-05-26 19:08 ——– d–h–w c:\windows\system32\GroupPolicy
2009-05-22 20:04 . 2009-05-26 19:51 ——– d—–w c:\windows\slog
2009-05-22 20:04 . 2001-03-28 14:38 69632 —-a-w c:\windows\system32\GkSui18.EXE
2009-04-29 21:19 . 2009-04-29 21:19 41808 —-a-w c:\windows\system32\xfcodec.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-26 23:31 . 2009-03-29 14:20 117760 —-a-w c:\documents and settings\user\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-05-26 22:39 . 2009-05-26 22:39 292 —-a-w c:\program files\mshbo.txt
2009-05-26 21:52 . 2008-07-02 02:46 34 —-a-w c:\documents and settings\user\jagex_runescape_preferences.dat
2009-05-26 21:51 . 2007-06-29 14:44 ——– d—–w c:\program files\PokerStars
2009-05-26 20:37 . 2006-12-26 07:37 ——– d—–w c:\program files\Common Files\Autodesk Shared
2009-05-26 20:34 . 2007-08-22 17:27 ——– d—–w c:\program files\Azureus
2009-05-26 20:34 . 2006-12-26 07:37 ——– d—–w c:\program files\AutoCAD 2005
2009-05-26 20:30 . 2008-11-03 01:08 ——– d—–w c:\program files\AIM6
2009-05-26 20:27 . 2008-09-23 10:33 ——– d—–w c:\program files\Acoustica MP3 To Wave Converter PLUS
2009-05-26 20:27 . 2009-04-01 22:25 ——– d—–w c:\program files\Absolute Poker
2009-05-26 20:26 . 2006-12-26 08:11 ——– d—–w c:\program files\Abbyy FineReader 6.0 Sprint
2009-05-26 19:59 . 2008-01-06 19:00 ——– d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-05-26 19:56 . 2007-09-19 20:38 ——– d—–w c:\documents and settings\All Users\Application Data\SwiftSwitch
2009-05-26 18:16 . 2007-10-17 14:44 ——– d—–w c:\program files\NoAdware5.0
2009-05-26 15:41 . 2008-11-11 23:36 ——– d—–w c:\program files\Diablo II
2009-05-26 13:18 . 2008-05-11 18:07 ——– d—–w c:\program files\SwiftKit
2009-05-21 22:52 . 2009-04-23 21:10 ——– d—–w c:\documents and settings\All Users\Application Data\DriverScanner
2009-05-19 11:56 . 2006-12-26 08:09 ——– d—–w c:\program files\Lx_cats
2009-05-17 20:21 . 2006-12-28 15:56 ——– d—–w c:\documents and settings\user\Application Data\LimeWire
2009-05-16 23:50 . 2007-02-01 21:17 ——– d—–w c:\program files\FlashGet
2009-05-11 23:43 . 2009-03-10 16:34 ——– d—–w c:\program files\Full Tilt Poker
2009-05-10 17:06 . 2009-02-25 00:58 ——– d—–w c:\documents and settings\user\Application Data\Xfire
2009-05-10 16:42 . 2009-02-25 00:58 ——– d—–w c:\program files\Xfire
2009-05-06 18:51 . 2008-10-20 18:15 ——– d—–w c:\program files\EVGA Precision
2009-04-30 10:10 . 2008-07-21 12:35 ——– d—–w c:\program files\SUPERAntiSpyware
2009-04-23 21:35 . 2009-04-23 21:34 ——– d—–w c:\program files\IDT
2009-04-23 21:34 . 2006-12-26 11:29 ——– d–h–w c:\program files\InstallShield Installation Information
2009-04-23 21:10 . 2009-04-23 21:06 ——– dc-h–w c:\documents and settings\All Users\Application Data\{148D8B8A-8F96-4822-81EC-D510B626B7D5}
2009-04-23 21:10 . 2009-04-23 21:10 ——– d—–w c:\program files\Uniblue
2009-04-23 21:10 . 2009-04-23 21:10 ——– d—–w c:\documents and settings\user\Application Data\Uniblue
2009-04-22 22:59 . 2007-09-08 20:18 ——– d—–w c:\program files\Warcraft III
2009-04-20 22:52 . 2009-04-20 22:47 ——– d—–w c:\program files\Poker Skins
2009-04-18 18:45 . 2007-04-22 11:59 77554 —-a-w c:\windows\War3Unin.dat
2009-04-01 22:25 . 2009-04-01 22:25 ——– d—–w c:\program files\_uninstallation_info
2009-03-28 13:20 . 2007-09-10 16:43 ——– d—–w c:\program files\PartyGaming
2006-11-25 10:11 . 2009-02-04 01:34 2560 –sh–r c:\windows\system32\fooool.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-04-30 1830128]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-25 13529088]
"LXCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll" [2005-01-10 69632]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-25 86016]
"Tarantula"="c:\program files\Razer\Tarantula\razerhid.exe" [2007-05-07 159744]
"ISUSScheduler"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" [2004-06-16 81920]
"RivaTunerStatisticsServer"="c:\program files\EVGA Precision\Bundle\OSDServer\RTSS.exe" [2008-07-11 64528]
"EVGAPrecision"="c:\program files\EVGA Precision\EVGAPrecision.exe" [2008-07-11 236560]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-05-22 442467]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2004-08-03 53760]
c:\documents and settings\user\Desktop\Documents for d2 etc\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 112640]
Tournament Shark.lnk - c:\program files\Poker Pro Labs\Tournament Shark\TournamentShark.exe [2009-2-27 278528]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-01-01 12:26 356352 —-a-w c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"NoAdware5"="c:\program files\NoAdware5.0\NoAdware5.exe" :Scan:
"SUPERAntiSpyware"=c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" /s
"FlashGet"=c:\program files\FlashGet\FlashGet.exe /min
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start
"ISUSPM Startup"=c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe"
"lxccmon.exe"="c:\program files\Lexmark 3300 Series\lxccmon.exe"
"nwiz"=nwiz.exe /install
"Lachesis"=c:\program files\Razer\Lachesis\razerhid.exe
"Tarantula"=c:\program files\Razer\Tarantula\razerhid.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Data 20-12-06\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"d:\\Data 20-12-06\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\SCC-TDS\\Command & Conquer 3 - Tiberium Wars\\RetailExe\\1.4\\cnc3game.dat"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Ocean Technology\\GG E-Sports Platform\\GGclient.exe"=
"c:\\kav\\kav7.0\\english\\setup.exe"=
"c:\\Program Files\\WaaaghTV\\wtvClient0.95.00\\wtvClient.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\english\\setup.exe"=
"d:\\Data 20-12-06\\mIRC\\mirc.exe"=
"c:\\Program Files\\Ocean Technology\\GG E-Sports Platform\\Garena.exe"=
"c:\\Program Files\\Warcraft III\\Frozen Throne.exe"=
"c:\\Program Files\\Guild Wars\\Gw.exe"=
"c:\\kkndextreme\\Kknd.exe"=
"c:\\Soldat\\Soldat.exe"=
"c:\\World Of Warcraft\\Wow.exe"=
"c:\\World Of Warcraft\\BNUpdate.exe"=
"d:\\Data 20-12-06\\mIRC2\\mirc.exe"=
"c:\\Old games\\DOSBox-0.72\\dosbox.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\IDT\\WDM\\sttray.exe"=
"c:\\WINDOWS\\system32\\dwwin.exe"=
"c:\\Program Files\\Razer\\Tarantula\\razerhid.exe"=
"c:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"=
"c:\\WINDOWS\\system32\\netsh.exe"=
"c:\\Program Files\\PokerStars\\PokerStars.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\PokerStars\\PokerStarsUpdate.exe"=
"c:\\Program Files\\ERUNT\\ERUNT.EXE"=
"c:\\Documents and Settings\\user\\Desktop\\PC things links etc\\HiJackThis.exe"=
"c:\\Program Files\\EVGA Precision\\EVGAPrecision.exe"=
"c:\\ComboFix\\Nircmd.com"=
"c:\\DOCUME~1\\user\\LOCALS~1\\Temp\\rfyg.exe"=
"c:\\DOCUME~1\\user\\LOCALS~1\\Temp\\cayj.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5000:TCP"= 5000:TCP:RedVex
"6112:TCP"= 6112:TCP:Warcraft III
"6112:UDP"= 6112:UDP:Port 6112
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6881:TCP"= 6881:TCP:Blizzard2
"6999:TCP"= 6999:TCP:Blizzard3
"6882:TCP"= 6882:TCP:blizzard4
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [5/28/2008 10:33 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/28/2008 10:33 AM 55024]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [11/3/2008 4:09 AM 24652]
R3 abp470n5;abp470n5;\??\c:\windows\system32\drivers\uosn.sys –> c:\windows\system32\drivers\uosn.sys [?]
R3 LachesisFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [1/1/2008 7:05 PM 12032]
R3 RTCore32;RTCore32;c:\program files\EVGA Precision\RTCore32.sys [5/25/2005 9:39 PM 4608]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/28/2008 10:33 AM 7408]
R3 TarFltr;Razer Tarantula USB Keyboard;c:\windows\system32\drivers\UsbFltr.sys [8/14/2007 6:14 PM 45440]
S3 AVPsys;AVPsys;c:\windows\system32\drivers\cdaudio.sys [8/17/2001 4:52 PM 18688]
S3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [7/13/2007 4:14 AM 10880]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2009-05-26 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-02-29 11:24]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
——- Supplementary Scan ——-
.
uLocal Page = \blank.htm
mStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
IE: &Download; All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download; with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: {F61F8A23-0D5D-4DEB-B191-54C280EA55D3} = 192.168.1.1
DPF: Web-Based Email Tools - hxxp://email.secureserver.net/Download.CAB
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-27 02:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-1935655697-2077806209-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:6c,84,d7,bf,89,8b,4f,00,00,76,e0,69,f5,96,cc,e0,c2,bf,ee,06,df,25,c0,
84,7c,7a,f1,6c,da,da,8a,38,f8,7d,e2,21,19,da,4a,66,54,2b,fb,ca,1a,af,22,c8,\
"??"=hex:0c,07,e0,68,4d,15,85,4f,50,1e,73,a7,29,36,84,ab
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\run\OptionalComponents]
@DACL=(02 0000)
@=""
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1056)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
- - - - - - - > 'explorer.exe'(3220)
c:\program files\EVGA Precision\Bundle\OSDServer\RTSSHooks.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\IDT\IntelEL_v104\WDM\stacsv.exe
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
c:\program files\Razer\Tarantula\razertra.exe
c:\docume~1\user\LOCALS~1\temp\rfyg.exe
c:\docume~1\user\LOCALS~1\temp\cayj.exe
c:\docume~1\user\LOCALS~1\temp\w54ef2.exe
.
**************************************************************************
.
Completion time: 2009-05-26 2:37 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-26 23:37
ComboFix2.txt 2008-07-21 11:14
Pre-Run: 36,694,310,912 bytes free
Post-Run: 36,421,890,048 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
273 — E O F — 2008-06-12 00:07
also used thed ERUNT program to back up my registry files
also used HighjackThis to provide you with a log which i will type out
i cant use the registry every time i try start>run>regedit it says "Registry Editing Has been disabled by your administrator". Yet i am the administrator it still says this, and i have no access to the Task Manager. Someone please help me
-Regards,
Turok
P.S: everytime i do the scan and then restart PC the regedit gets locked again and again it seems those programs arent solving the direct problem only the smaller ones.
___________________________________________________
"Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:58:15 AM, on 5/27/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\idt\intelel_v104\wdm\STacSV.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Razer\Tarantula\razerhid.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\EVGA Precision\Bundle\OSDServer\RTSS.exe
C:\Program Files\EVGA Precision\EVGAPrecision.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Razer\Tarantula\razertra.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\user\Desktop\PC things links etc\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe, explorer.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LXCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Tarantula] C:\Program Files\Razer\Tarantula\razerhid.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" -start
O4 - HKLM\..\Run: [RivaTunerStatisticsServer] "C:\Program Files\EVGA Precision\Bundle\OSDServer\RTSS.exe" /s
O4 - HKLM\..\Run: [EVGAPrecision] "C:\Program Files\EVGA Precision\EVGAPrecision.exe" /s
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: Tournament Shark.lnk = C:\Program Files\Poker Pro Labs\Tournament Shark\TournamentShark.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Download; All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download; with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe (file missing)
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\user\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\user\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: Web-Based Email Tools - http://email.secureserver.net/Download.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{F61F8A23-0D5D-4DEB-B191-54C280EA55D3}: NameServer = 192.168.1.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: lxcc_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcccoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - c:\program files\idt\intelel_v104\wdm\STacSV.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe (file missing)
–
End of file - 8713 bytes
"
I also provided you guys with the COMBO FIX LOG
__________________________________________________
ComboFix 09-05-26.02 - Lord Heave 05/27/2009 2:26.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2558.2025 [GMT 3:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\user\LOCALS~1\Temp\ivfjb.exe
c:\documents and settings\user\Local Settings\temp\ivfjb.exe
c:\windows\system32\drivers\fetpz.sys
c:\windows\system32\drivers\gxgzwwy.sys
D:\2u.com
D:\68.exe
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-04-26 to 2009-05-26 )))))))))))))))))))))))))))))))
.
2009-05-26 22:35 . 2009-05-26 22:35 ——– d—–w c:\program files\ERUNT
2009-05-26 21:20 . 2009-05-26 21:20 ——– d—–w c:\documents and settings\user\Application Data\Malwarebytes
2009-05-26 21:19 . 2009-05-26 10:20 40160 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 21:19 . 2009-05-26 21:20 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-26 21:19 . 2009-05-26 21:19 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-26 21:19 . 2009-05-26 10:19 19096 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-26 21:10 . 2009-05-26 21:12 ——– d—–w C:\CCleaner
2009-05-26 19:59 . 2009-05-26 19:59 167376 —-a-w c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\j2lm3ea1.default\FlashGot.exe
2009-05-26 19:49 . 2009-05-26 22:01 ——– d–h–w C:\$AVG8.VAULT$
2009-05-26 19:44 . 2009-05-26 19:44 ——– d—–w c:\program files\AVG
2009-05-26 18:07 . 2009-05-26 19:08 ——– d–h–w c:\windows\system32\GroupPolicy
2009-05-22 20:04 . 2009-05-26 19:51 ——– d—–w c:\windows\slog
2009-05-22 20:04 . 2001-03-28 14:38 69632 —-a-w c:\windows\system32\GkSui18.EXE
2009-04-29 21:19 . 2009-04-29 21:19 41808 —-a-w c:\windows\system32\xfcodec.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-26 23:31 . 2009-03-29 14:20 117760 —-a-w c:\documents and settings\user\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-05-26 22:39 . 2009-05-26 22:39 292 —-a-w c:\program files\mshbo.txt
2009-05-26 21:52 . 2008-07-02 02:46 34 —-a-w c:\documents and settings\user\jagex_runescape_preferences.dat
2009-05-26 21:51 . 2007-06-29 14:44 ——– d—–w c:\program files\PokerStars
2009-05-26 20:37 . 2006-12-26 07:37 ——– d—–w c:\program files\Common Files\Autodesk Shared
2009-05-26 20:34 . 2007-08-22 17:27 ——– d—–w c:\program files\Azureus
2009-05-26 20:34 . 2006-12-26 07:37 ——– d—–w c:\program files\AutoCAD 2005
2009-05-26 20:30 . 2008-11-03 01:08 ——– d—–w c:\program files\AIM6
2009-05-26 20:27 . 2008-09-23 10:33 ——– d—–w c:\program files\Acoustica MP3 To Wave Converter PLUS
2009-05-26 20:27 . 2009-04-01 22:25 ——– d—–w c:\program files\Absolute Poker
2009-05-26 20:26 . 2006-12-26 08:11 ——– d—–w c:\program files\Abbyy FineReader 6.0 Sprint
2009-05-26 19:59 . 2008-01-06 19:00 ——– d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-05-26 19:56 . 2007-09-19 20:38 ——– d—–w c:\documents and settings\All Users\Application Data\SwiftSwitch
2009-05-26 18:16 . 2007-10-17 14:44 ——– d—–w c:\program files\NoAdware5.0
2009-05-26 15:41 . 2008-11-11 23:36 ——– d—–w c:\program files\Diablo II
2009-05-26 13:18 . 2008-05-11 18:07 ——– d—–w c:\program files\SwiftKit
2009-05-21 22:52 . 2009-04-23 21:10 ——– d—–w c:\documents and settings\All Users\Application Data\DriverScanner
2009-05-19 11:56 . 2006-12-26 08:09 ——– d—–w c:\program files\Lx_cats
2009-05-17 20:21 . 2006-12-28 15:56 ——– d—–w c:\documents and settings\user\Application Data\LimeWire
2009-05-16 23:50 . 2007-02-01 21:17 ——– d—–w c:\program files\FlashGet
2009-05-11 23:43 . 2009-03-10 16:34 ——– d—–w c:\program files\Full Tilt Poker
2009-05-10 17:06 . 2009-02-25 00:58 ——– d—–w c:\documents and settings\user\Application Data\Xfire
2009-05-10 16:42 . 2009-02-25 00:58 ——– d—–w c:\program files\Xfire
2009-05-06 18:51 . 2008-10-20 18:15 ——– d—–w c:\program files\EVGA Precision
2009-04-30 10:10 . 2008-07-21 12:35 ——– d—–w c:\program files\SUPERAntiSpyware
2009-04-23 21:35 . 2009-04-23 21:34 ——– d—–w c:\program files\IDT
2009-04-23 21:34 . 2006-12-26 11:29 ——– d–h–w c:\program files\InstallShield Installation Information
2009-04-23 21:10 . 2009-04-23 21:06 ——– dc-h–w c:\documents and settings\All Users\Application Data\{148D8B8A-8F96-4822-81EC-D510B626B7D5}
2009-04-23 21:10 . 2009-04-23 21:10 ——– d—–w c:\program files\Uniblue
2009-04-23 21:10 . 2009-04-23 21:10 ——– d—–w c:\documents and settings\user\Application Data\Uniblue
2009-04-22 22:59 . 2007-09-08 20:18 ——– d—–w c:\program files\Warcraft III
2009-04-20 22:52 . 2009-04-20 22:47 ——– d—–w c:\program files\Poker Skins
2009-04-18 18:45 . 2007-04-22 11:59 77554 —-a-w c:\windows\War3Unin.dat
2009-04-01 22:25 . 2009-04-01 22:25 ——– d—–w c:\program files\_uninstallation_info
2009-03-28 13:20 . 2007-09-10 16:43 ——– d—–w c:\program files\PartyGaming
2006-11-25 10:11 . 2009-02-04 01:34 2560 –sh–r c:\windows\system32\fooool.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-04-30 1830128]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-25 13529088]
"LXCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll" [2005-01-10 69632]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-25 86016]
"Tarantula"="c:\program files\Razer\Tarantula\razerhid.exe" [2007-05-07 159744]
"ISUSScheduler"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" [2004-06-16 81920]
"RivaTunerStatisticsServer"="c:\program files\EVGA Precision\Bundle\OSDServer\RTSS.exe" [2008-07-11 64528]
"EVGAPrecision"="c:\program files\EVGA Precision\EVGAPrecision.exe" [2008-07-11 236560]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-05-22 442467]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2004-08-03 53760]
c:\documents and settings\user\Desktop\Documents for d2 etc\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 112640]
Tournament Shark.lnk - c:\program files\Poker Pro Labs\Tournament Shark\TournamentShark.exe [2009-2-27 278528]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-01-01 12:26 356352 —-a-w c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"NoAdware5"="c:\program files\NoAdware5.0\NoAdware5.exe" :Scan:
"SUPERAntiSpyware"=c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" /s
"FlashGet"=c:\program files\FlashGet\FlashGet.exe /min
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start
"ISUSPM Startup"=c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe"
"lxccmon.exe"="c:\program files\Lexmark 3300 Series\lxccmon.exe"
"nwiz"=nwiz.exe /install
"Lachesis"=c:\program files\Razer\Lachesis\razerhid.exe
"Tarantula"=c:\program files\Razer\Tarantula\razerhid.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Data 20-12-06\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"d:\\Data 20-12-06\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\SCC-TDS\\Command & Conquer 3 - Tiberium Wars\\RetailExe\\1.4\\cnc3game.dat"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Ocean Technology\\GG E-Sports Platform\\GGclient.exe"=
"c:\\kav\\kav7.0\\english\\setup.exe"=
"c:\\Program Files\\WaaaghTV\\wtvClient0.95.00\\wtvClient.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\english\\setup.exe"=
"d:\\Data 20-12-06\\mIRC\\mirc.exe"=
"c:\\Program Files\\Ocean Technology\\GG E-Sports Platform\\Garena.exe"=
"c:\\Program Files\\Warcraft III\\Frozen Throne.exe"=
"c:\\Program Files\\Guild Wars\\Gw.exe"=
"c:\\kkndextreme\\Kknd.exe"=
"c:\\Soldat\\Soldat.exe"=
"c:\\World Of Warcraft\\Wow.exe"=
"c:\\World Of Warcraft\\BNUpdate.exe"=
"d:\\Data 20-12-06\\mIRC2\\mirc.exe"=
"c:\\Old games\\DOSBox-0.72\\dosbox.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\IDT\\WDM\\sttray.exe"=
"c:\\WINDOWS\\system32\\dwwin.exe"=
"c:\\Program Files\\Razer\\Tarantula\\razerhid.exe"=
"c:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"=
"c:\\WINDOWS\\system32\\netsh.exe"=
"c:\\Program Files\\PokerStars\\PokerStars.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\PokerStars\\PokerStarsUpdate.exe"=
"c:\\Program Files\\ERUNT\\ERUNT.EXE"=
"c:\\Documents and Settings\\user\\Desktop\\PC things links etc\\HiJackThis.exe"=
"c:\\Program Files\\EVGA Precision\\EVGAPrecision.exe"=
"c:\\ComboFix\\Nircmd.com"=
"c:\\DOCUME~1\\user\\LOCALS~1\\Temp\\rfyg.exe"=
"c:\\DOCUME~1\\user\\LOCALS~1\\Temp\\cayj.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5000:TCP"= 5000:TCP:RedVex
"6112:TCP"= 6112:TCP:Warcraft III
"6112:UDP"= 6112:UDP:Port 6112
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6881:TCP"= 6881:TCP:Blizzard2
"6999:TCP"= 6999:TCP:Blizzard3
"6882:TCP"= 6882:TCP:blizzard4
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [5/28/2008 10:33 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/28/2008 10:33 AM 55024]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [11/3/2008 4:09 AM 24652]
R3 abp470n5;abp470n5;\??\c:\windows\system32\drivers\uosn.sys –> c:\windows\system32\drivers\uosn.sys [?]
R3 LachesisFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [1/1/2008 7:05 PM 12032]
R3 RTCore32;RTCore32;c:\program files\EVGA Precision\RTCore32.sys [5/25/2005 9:39 PM 4608]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/28/2008 10:33 AM 7408]
R3 TarFltr;Razer Tarantula USB Keyboard;c:\windows\system32\drivers\UsbFltr.sys [8/14/2007 6:14 PM 45440]
S3 AVPsys;AVPsys;c:\windows\system32\drivers\cdaudio.sys [8/17/2001 4:52 PM 18688]
S3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [7/13/2007 4:14 AM 10880]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2009-05-26 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-02-29 11:24]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
——- Supplementary Scan ——-
.
uLocal Page = \blank.htm
mStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
IE: &Download; All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download; with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: {F61F8A23-0D5D-4DEB-B191-54C280EA55D3} = 192.168.1.1
DPF: Web-Based Email Tools - hxxp://email.secureserver.net/Download.CAB
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-27 02:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-1935655697-2077806209-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:6c,84,d7,bf,89,8b,4f,00,00,76,e0,69,f5,96,cc,e0,c2,bf,ee,06,df,25,c0,
84,7c,7a,f1,6c,da,da,8a,38,f8,7d,e2,21,19,da,4a,66,54,2b,fb,ca,1a,af,22,c8,\
"??"=hex:0c,07,e0,68,4d,15,85,4f,50,1e,73,a7,29,36,84,ab
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\run\OptionalComponents]
@DACL=(02 0000)
@=""
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1056)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
- - - - - - - > 'explorer.exe'(3220)
c:\program files\EVGA Precision\Bundle\OSDServer\RTSSHooks.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\IDT\IntelEL_v104\WDM\stacsv.exe
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
c:\program files\Razer\Tarantula\razertra.exe
c:\docume~1\user\LOCALS~1\temp\rfyg.exe
c:\docume~1\user\LOCALS~1\temp\cayj.exe
c:\docume~1\user\LOCALS~1\temp\w54ef2.exe
.
**************************************************************************
.
Completion time: 2009-05-26 2:37 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-26 23:37
ComboFix2.txt 2008-07-21 11:14
Pre-Run: 36,694,310,912 bytes free
Post-Run: 36,421,890,048 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
273 — E O F — 2008-06-12 00:07