Spyware / Malware / Virus Removal
[Resolved] Can't even run HijackThis
18 min read
tase2
Topic Starter
Hi
I am not sure if this post belongs here as I am not even able to run HijackThis-thus there is no log to post. Admins feel free to move if need be.
Here is my situation.
I am using an Acer Aspire 7720 laptop running Vista Home premium Svpk1.
Everything worked fantastic until Saturday night. The only thing I can think of is visiting a questionable torrent search site. But whatever the culprit the following is what I have been experiencing since Saturday night (6/13/09). I spent all day yesterday trying to fix it on my own.
The first problem is that Personal Antivirus (PAV) got onto my laptop and I can't remove it. It seems to have taken over the laptop, with trojan notifications and (not positive this is PAV) but almost every site I try to visit now may load and if so I receive this red box stating
Warning! Visiting this site may harm your computer!
This web site probably contains malicious software program, which can cause damage to your computer or perform actions without your permission. Your computer may be infected after visiting such web site.
We recommend you to install (or activate) antivirus security software
I do realize that visiting this site can cause harm to my computer.
and from that point on the page is blocked. I have tried uninstall-no good.
Also since Saturday-Every google link redirects me to some shopping site of one kind or another. I discovered that if I copy/paste the actual URL into the address bar I can get to the page I wanted to go to. It is about 50/50 whether the site will be blocked or not.
I am at work so I am going on memory here, but these are the programs I've loaded or tried to load:
Spybot Search and Destroy
Malwarebytes' Anti-Malware
Hijackthis
adaware
pcdoctor
pc pitstop
Kaspersky
spyhunter security suite
There are problems with each and everyone of them.
HijackThis took forever to even allow the software to load-saved to desktop-It gets to install to ……….and then get the Hijackthis icon-I click it -absolutely nothing happens
Others are blocked, others say bad connection when trying to load
others say "blank" has stopped working-windows will try and find how to resolve it.
This "blank" has stopped working error also comes up constantly
I have AVG as my default antivirus. It runs fine-has detected a trojan or 2, but never seems to fix the problem.
spyhunter security suite seem to be the only program that will run a full scan. It shows like 18 or so infected files, registry, but won't allow a fix until you pay and register. I was ready to do that by this point, I was blocked everytime I tried to go to register. Now I think I read that spyhunter is a bogus program anyway.
I failed to mention I was able to download and run EUS??? registry cleaner and fixer, but all the same problems remained.
I also want to mention that just about everything I tried in regular mode, I also used in safe mode-with networking. It did seem to help a lot, but obviosly didn't fix anything.
The only other thing I'll mention is that I was unable to even load most of the programs from their sites, but was able to from CNET or Downloads.com
Sorry for the lengthy post, but as you all know it can be very frustrating.
I am willing to try anything, so any help would be greatly appreciated
Mark
CatByte
Hi,
We need to be able to get you to download and run some programs,
so lets see if we can eliminate one of the problems stopping you:
First show hidden files and folders:
Next
Navigate to this folder and delete it:
c:\documents and settings\All Users\Start Menu\PAV
If you cannot locate it at that location (that's it;s usual installation place on most machines, but no guarantee that's where it will be on yours)
use windows explorer (windows key +E) to search for the PAV folder and delete it.
Then do the following:
Please download DDS and save it to your desktop.
Please include the contents of the following in your next reply:
DDS.txt
Attach.txt.
STEP #2
Download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any "<— ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
Post the contents of GMER.txt in your next reply.
We need to be able to get you to download and run some programs,
so lets see if we can eliminate one of the problems stopping you:
First show hidden files and folders:
- Close all programs so that you are at your desktop.
- Open the Control Panel menu and click Folder Options.
- After the new window appears select the View tab.
- Put a checkmark in the checkbox labeled Display the contents of system folders.
- Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
- Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
- Remove the checkmark from the checkbox labeled Hide protected operating system files.
- Press the Apply button and then the OK button and exit My Computer.
- Now your computer is configured to show all hidden files.
Next
Navigate to this folder and delete it:
c:\documents and settings\All Users\Start Menu\PAV
If you cannot locate it at that location (that's it;s usual installation place on most machines, but no guarantee that's where it will be on yours)
use windows explorer (windows key +E) to search for the PAV folder and delete it.
Then do the following:
Please download DDS and save it to your desktop.
- Disable any script blocking protection
- Double click dds.pif to run the tool.
- When done, two DDS.txt's will open.
- Save both reports to your desktop.
Please include the contents of the following in your next reply:
DDS.txt
Attach.txt.
STEP #2
Download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any "<— ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
- Click NO
- In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
- Now click the Scan button.
Once the scan is complete, you may receive another notice about rootkit activity. - Click OK.
- GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
- Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.
tase2
Here yoou go.
DDS.txt
DDS (Ver_09-05-14.01) - NTFSx86
Run by [removed] at 17:17:09.30 on 15/06/2009
Internet Explorer: 8.0.6001.18783
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.2.1033.18.2037.1109 [GMT -4:00]
SP: Lavasoft Ad-Watch Live! *enabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NCH Software\BroadCam\broadCam.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
C:\Acer\Empowering Technology\eNet\eNet Service.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\lxczcoms.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\PSIService.exe
C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter3.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
C:\Windows\system32\taskeng.exe
C:\Users\Mark\Desktop\dds.pif
C:\Windows\system32\rundll32.exe
C:\Windows\system32\conime.exe
============== Pseudo HJT Report ===============
uStart Page = www.google.com/
uWindow Title = Windows Internet Explorer provided by Yahoo!
uDefault_Page_URL = hxxp://ca.yahoo.com/?fr=fp-yie8
mStart Page = hxxp://en.ca.acer.yahoo.com
mDefault_Page_URL = hxxp://en.ca.acer.yahoo.com
BHO: {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: &Helper: {2e59498d-7e44-4452-9044-0973b080b9e8} - c:\windows\system32\winexplorer.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\windows\system32\eDStoolbar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~1.0_0\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {2D337EB0-3BFB-42A3-B314-A24BBA8C085B} - hxxp://download.yahoo.com/dl/mail/yautoiol1.cab
DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} - hxxp://apps.corel.com/nos_dl_manager_dev/plugin/IEGetPlugin.ocx
DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} - hxxp://utilities.pcpitstop.com/Exterminate2/pcpitstopAntiVirus.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?e=1217524564667&h=a7bb39296449244c01aa6065c9783ad0/&filename=jinstall-6u7-windows-i586-jc.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://plugin.driveragent.com/files/driveragent.cab
DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
TCP: NameServer = 85.255.112.104,85.255.112.155
TCP: {8501B573-C9B5-4E69-9CB0-0B6A2F963A00} = 85.255.112.104,85.255.112.155
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: avgrsstx.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-14 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-5-24 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-5-24 108552]
R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\elrawdsk.sys [2008-2-9 12800]
R3 enecir;ENE CIR Receiver;c:\windows\system32\drivers\enecir.sys [2007-8-31 32256]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2007-8-31 179712]
============== File Associations ===============
regfile=NOTEPAD.EXE %1
scrfile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
=============== Created Last 30 ================
2009-06-15 00:41 335 a——- C:\spyhunter.fix
2009-06-15 00:41 –d—– c:\program files\Enigma Software Group
2009-06-14 23:56 40,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-14 23:56 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-06-14 23:56 –d—– c:\programdata\Malwarebytes
2009-06-14 23:56 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-06-14 23:56 –d—– c:\progra~2\Malwarebytes
2009-06-14 23:24 –d—– c:\program files\Eusing Free Registry Cleaner
2009-06-14 21:47 15,688 a——- c:\windows\system32\lsdelete.exe
2009-06-14 21:40 64,160 a——- c:\windows\system32\drivers\Lbd.sys
2009-06-14 21:39 -cd-h— c:\programdata\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-14 21:39 -cd-h— c:\progra~2\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-14 21:39 –d—– c:\program files\Lavasoft
2009-06-14 20:49 –d—– c:\users\mark\appdata\roaming\SUPERAntiSpyware.com
2009-06-14 20:49 –d—– c:\program files\SUPERAntiSpyware
2009-06-14 19:47 199,829,553 a——- c:\windows\MEMORY.DMP
2009-06-14 16:55 –d—– c:\program files\common files\Wise Installation Wizard
2009-06-14 04:34 376,320 a——- c:\windows\system32\winexplorer.dll
2009-06-14 04:33 –d—– c:\program files\common files\Uninstall
2009-06-14 04:32 –d—– c:\program files\PAV
2009-06-14 03:34 –d—– c:\program files\Trend Micro
2009-06-14 01:20 –d—– c:\programdata\PCPitstop
2009-06-14 01:20 –d—– c:\progra~2\PCPitstop
2009-06-14 01:19 –d—– c:\program files\PCPitstop
2009-06-14 01:01 –d—– c:\programdata\Lavasoft
2009-06-13 18:14 –d—– c:\program files\BHVideo
2009-06-13 17:13 –d—– c:\program files\uTorrent
2009-06-13 17:11 –d—– c:\users\mark\appdata\roaming\uTorrent
2009-06-10 02:13 2,033,152 a——- c:\windows\system32\win32k.sys
2009-06-10 02:01 784,896 a——- c:\windows\system32\rpcrt4.dll
2009-05-27 21:59 –d—– c:\users\mark\appdata\roaming\Camfrog
2009-05-25 19:20 –d—– c:\programdata\NCH Software
2009-05-25 19:19 –d—– c:\users\mark\appdata\roaming\NCH Software
2009-05-25 19:19 –d—– c:\program files\NCH Software
2009-05-24 22:21 –d-h— C:\$AVG8.VAULT$
2009-05-24 21:25 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-05-24 21:25 108,552 a——- c:\windows\system32\drivers\avgtdix.sys
2009-05-24 21:25 325,896 a——- c:\windows\system32\drivers\avgldx86.sys
2009-05-24 21:25 –d—– c:\windows\system32\drivers\Avg
2009-05-24 21:25 –d—– c:\programdata\avg8
2009-05-24 21:25 –d—– c:\program files\AVG
2009-05-24 21:25 –d—– c:\progra~2\avg8
2009-05-22 16:37 –d—– c:\users\mark\appdata\roaming\ooVoo Details
2009-05-22 02:27 –d—– c:\users\mark\appdata\roaming\Acer
2009-05-18 15:07 –d—– c:\users\Mark
2009-05-16 20:11 –d—– c:\program files\Paradise8
==================== Find3M ====================
2009-05-23 22:18 5,850 a–sh— c:\windows\system32\KGyGaAvL.sys
2009-05-09 01:50 915,456 a——- c:\windows\system32\wininet.dll
2009-05-09 01:34 71,680 a——- c:\windows\system32\iesetup.dll
2009-04-23 08:42 636,928 a——- c:\windows\system32\localspl.dll
2009-03-12 21:17 143,360 a——- c:\windows\inf\infstrng.dat
2009-03-12 21:17 143,360 a——- c:\windows\inf\infstor.dat
2009-03-12 21:17 86,016 a——- c:\windows\inf\infpub.dat
2008-07-07 11:32 174 a–sh— c:\program files\desktop.ini
2008-07-02 14:32 665,600 a——- c:\windows\inf\drvindex.dat
2007-12-22 15:19 476,752 a——- c:\programdata\pswi_preloaded.exe
2007-12-22 15:19 476,752 a——- c:\progra~2\pswi_preloaded.exe
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2007-12-30 19:17 8 —shr– c:\windows\system32\58FCD56796.sys
2007-12-22 15:20 88 —shr– c:\windows\system32\6C1FC0BF72.sys
============= FINISH: 17:18:06.04 ===============
Attatch.txt
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-05-14.01)
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 02/12/2007 3:18:03 AM
System Uptime: 15/06/2009 5:14:42 PM (0 hours ago)
Motherboard: Acer | | Poyang
Processor: Intel® Core™2 Duo CPU T5250 @ 1.50GHz | uPGA-478 | 1500/166mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 112 GiB total, 60.432 GiB free.
D: is FIXED (NTFS) - 111 GiB total, 111.343 GiB free.
E: is CDROM ()
==== Disabled Device Manager Items =============
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft Tun Miniport Adapter
Device ID: ROOT\*TUNMP\0001
Manufacturer: Microsoft
Name: Teredo Tunneling Pseudo-Interface
PNP Device ID: ROOT\*TUNMP\0001
Service: tunmp
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Broadcom NetLink ™ Gigabit Ethernet
Device ID: PCI\VEN_14E4&DEV_1693&SUBSYS_011E1025&REV_02\4&185174AE&0&00E2
Manufacturer: Broadcom
Name: Broadcom NetLink ™ Gigabit Ethernet
PNP Device ID: PCI\VEN_14E4&DEV_1693&SUBSYS_011E1025&REV_02\4&185174AE&0&00E2
Service: b57nd60x
==== System Restore Points ===================
==== Installed Programs ======================
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office system
Acer Assist
Acer Crystal Eye
Acer Crystal Eye webcam
Acer eAudio Management
Acer eDataSecurity Management
Acer eLock Management
Acer Empowering Technology
Acer eNet Management
Acer ePower Management
Acer ePresentation Management
Acer eSettings Management
Acer Mobility Center Plug-In
Acer Registration
Acer ScreenSaver
Ad-Aware
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Photoshop Elements 6.0
Adobe Reader 8.1.2
ALPS Touch Pad Driver
Apple Mobile Device Support
Apple Software Update
ArcSoft MediaConverter 2
µTorrent
Authentium AntiVirus SDK - 2
AutoUpdate
AVG Free 8.5
BHVideo
Bonjour
BroadCam
CDDRV_Installer
Corel Paint Shop Pro Photo XI
CorelDRAW Graphics Suite X3
Debut Video Capture Software
DirectXInstallService
DivX Codec
DivX Converter
DivX Player
DivX Web Player
EMC 10 Content
eMusic Download Manager
EN
Eusing Free Registry Cleaner
FlashLynx Video Download Software
FontNav
Google Earth
Google Toolbar for Internet Explorer
HDAUDIO Soft Data Fax Modem with SmartCP
helptut
helpug
Intel® Graphics Media Accelerator Driver
Intel® Matrix Storage Manager
iTunes
Java™ 6 Update 7
KhalInstallWrapper
LightScribe 1.4.142.1
Luxor 2
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB929729)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Hybrid 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft WorldWide Telescope
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
NCH Toolbox
NTI Backup NOW! 4.7
NTI CD & DVD-Maker
ooVoo
Paradise 8
PC Pitstop Exterminate2 2.0
Photilla Photo Album Software
PowerProducer 3.72
Prism Video Converter
QuickTime
Realtek High Definition Audio Driver
Roxio Activation Module
Roxio BackOnTrack
Roxio Central Audio
Roxio Central Copy
Roxio Central Core
Roxio Central Data
Roxio Central Tools
Roxio CinePlayer
Roxio CinePlayer Decoder Pack
Roxio Disc Gallery
Roxio Easy Media Creator 10 Suite
Roxio File Backup
Roxio MediaShare
Roxio Update Manager
Safari
Security Update for 2007 Microsoft Office System (KB951550)
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB969679)
Security Update for Microsoft Office Excel 2007 (KB969682)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office Publisher 2007 (KB950114)
Security Update for Microsoft Office system 2007 (KB954326)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office Word 2007 (KB969604)
Security Update for Visio 2007 (KB947590)
SmartSound Quicktracks Plugin
Spelling Dictionaries Support For Adobe Reader 8
SpyHunter
SUPERAntiSpyware Free Edition
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Outlook 2007 (KB952142)
Update for Microsoft Office Outlook 2007 Help (KB957246)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (kb970012)
Update Manager
VBA
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Windows Live Mail
Windows Live Messenger
WinRAR archiver
XVID Codec Installation
Zuma Deluxe
Zuma Deluxe 1.0
==== End Of File ===========================
GMER.txt
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-06-15 20:18:09
Windows 6.0.6001 Service Pack 1
—- System - GMER 1.0.15 —-
Code 98397E78 ZwCreateSection
Code 983969B8 ZwDuplicateObject
Code 8DE1DAD8 ZwEnumerateKey
Code 8DCFA0E0 ZwFlushInstructionCache
Code 9838B4B8 ZwSetInformationFile
Code 9838B018 ZwSetSystemInformation
Code 9838B620 ZwWriteFile
Code 8DCF7DDD IofCallDriver
Code 8DE23996 IofCompleteRequest
Code 98397E77 NtCreateSection
Code 983969B7 NtDuplicateObject
Code 9838B4B7 NtSetInformationFile
Code 9838B61F NtWriteFile
—- Kernel code sections - GMER 1.0.15 —-
.text ntoskrnl.exe!IofCallDriver 82492169 5 Bytes JMP 8DCF7DE2
.text ntoskrnl.exe!IofCompleteRequest 824921D6 5 Bytes JMP 8DE2399B
PAGE ntoskrnl.exe!ZwFlushInstructionCache 825F41C2 5 Bytes JMP 8DCFA0E4
PAGE ntoskrnl.exe!ZwSetSystemInformation 8260013E 5 Bytes JMP 9838B01C
PAGE ntoskrnl.exe!ZwEnumerateKey 8261F58C 5 Bytes JMP 8DE1DADC
PAGE ntoskrnl.exe!SeCreateAccessState + 1BA2 8263D51B 7 Bytes JMP 9838BC2C
PAGE ntoskrnl.exe!NtWriteFile 82648A22 7 Bytes JMP 9838B624
PAGE ntoskrnl.exe!NtCreateSection 82655B1F 7 Bytes JMP 98397E7C
PAGE ntoskrnl.exe!FsRtlGetFileSize + 194 82660041 7 Bytes JMP 98397A74
PAGE ntoskrnl.exe!NtDuplicateObject 82667AE3 7 Bytes JMP 983969BC
PAGE ntoskrnl.exe!RtlUpcaseUnicodeChar + 58 8266D703 7 Bytes JMP 983978E4
PAGE ntoskrnl.exe!NtSetInformationFile 82674C09 5 Bytes JMP 9838B4BC
PAGE ntoskrnl.exe!FsRtlIsNameInExpression + 439 82676763 7 Bytes JMP 9838BEB4
—- User IAT/EAT - GMER 1.0.15 —-
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [74907BA4] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [749498C5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7490D3C8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [748FF527] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [74907599] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [748FE43D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [7493B33D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [7490D68A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [7490012E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [74900095] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [748F71F3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [7498D802] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [749275E1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [748FDAE1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [748F668F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [748F66BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74901E45] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
—- Devices - GMER 1.0.15 —-
Device \FileSystem\fastfat \FatCdrom Code 9838B2A8
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \FileSystem\fastfat \Fat Code 9838B2A8
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
—- Services - GMER 1.0.15 —-
Service C:\Windows\system32\drivers\MSIVXqkpafndmvxgwwietautbpprvympfvotv.sys (*** hidden *** ) [SYSTEM] MSIVXserv.sys <– ROOTKIT !!!
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001583b7e356
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys@imagepath \systemroot\system32\drivers\MSIVXqkpafndmvxgwwietautbpprvympfvotv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys\modules@MSIVXserv \\?\globalroot\systemroot\system32\drivers\MSIVXqkpafndmvxgwwietautbpprvympfvotv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys\modules@MSIVXl \\?\globalroot\systemroot\system32\MSIVXchnivexrrctwvmvevsfqjjutxwxbppou.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys\modules@MSIVXclk \\?\globalroot\systemroot\system32\MSIVXejcpmyqnxmutdsxfwvofooisrdireiph.dll
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001583b7e356
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys@imagepath \systemroot\system32\drivers\MSIVXqkpafndmvxgwwietautbpprvympfvotv.sys
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys\modules
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys\modules@MSIVXserv \\?\globalroot\systemroot\system32\drivers\MSIVXqkpafndmvxgwwietautbpprvympfvotv.sys
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys\modules@MSIVXl \\?\globalroot\systemroot\system32\MSIVXchnivexrrctwvmvevsfqjjutxwxbppou.dll
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys\modules@MSIVXclk \\?\globalroot\systemroot\system32\MSIVXejcpmyqnxmutdsxfwvofooisrdireiph.dll
—- Files - GMER 1.0.15 —-
File C:\Windows\System32\drivers\MSIVXqkpafndmvxgwwietautbpprvympfvotv.sys 79872 bytes executable <– ROOTKIT !!!
File C:\Windows\System32\MSIVXchnivexrrctwvmvevsfqjjutxwxbppou.dll 26624 bytes executable
File C:\Windows\System32\MSIVXcount 4 bytes
File C:\Windows\System32\MSIVXejcpmyqnxmutdsxfwvofooisrdireiph.dll 52224 bytes executable
—- EOF - GMER 1.0.15 —-
Thanks
Mark
DDS.txt
DDS (Ver_09-05-14.01) - NTFSx86
Run by [removed] at 17:17:09.30 on 15/06/2009
Internet Explorer: 8.0.6001.18783
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.2.1033.18.2037.1109 [GMT -4:00]
SP: Lavasoft Ad-Watch Live! *enabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NCH Software\BroadCam\broadCam.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
C:\Acer\Empowering Technology\eNet\eNet Service.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\lxczcoms.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\PSIService.exe
C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter3.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
C:\Windows\system32\taskeng.exe
C:\Users\Mark\Desktop\dds.pif
C:\Windows\system32\rundll32.exe
C:\Windows\system32\conime.exe
============== Pseudo HJT Report ===============
uStart Page = www.google.com/
uWindow Title = Windows Internet Explorer provided by Yahoo!
uDefault_Page_URL = hxxp://ca.yahoo.com/?fr=fp-yie8
mStart Page = hxxp://en.ca.acer.yahoo.com
mDefault_Page_URL = hxxp://en.ca.acer.yahoo.com
BHO: {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: &Helper: {2e59498d-7e44-4452-9044-0973b080b9e8} - c:\windows\system32\winexplorer.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\windows\system32\eDStoolbar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~1.0_0\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {2D337EB0-3BFB-42A3-B314-A24BBA8C085B} - hxxp://download.yahoo.com/dl/mail/yautoiol1.cab
DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} - hxxp://apps.corel.com/nos_dl_manager_dev/plugin/IEGetPlugin.ocx
DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} - hxxp://utilities.pcpitstop.com/Exterminate2/pcpitstopAntiVirus.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?e=1217524564667&h=a7bb39296449244c01aa6065c9783ad0/&filename=jinstall-6u7-windows-i586-jc.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://plugin.driveragent.com/files/driveragent.cab
DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
TCP: NameServer = 85.255.112.104,85.255.112.155
TCP: {8501B573-C9B5-4E69-9CB0-0B6A2F963A00} = 85.255.112.104,85.255.112.155
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: avgrsstx.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-14 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-5-24 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-5-24 108552]
R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\elrawdsk.sys [2008-2-9 12800]
R3 enecir;ENE CIR Receiver;c:\windows\system32\drivers\enecir.sys [2007-8-31 32256]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2007-8-31 179712]
============== File Associations ===============
regfile=NOTEPAD.EXE %1
scrfile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
=============== Created Last 30 ================
2009-06-15 00:41 335 a——- C:\spyhunter.fix
2009-06-15 00:41 –d—– c:\program files\Enigma Software Group
2009-06-14 23:56 40,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-14 23:56 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-06-14 23:56 –d—– c:\programdata\Malwarebytes
2009-06-14 23:56 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-06-14 23:56 –d—– c:\progra~2\Malwarebytes
2009-06-14 23:24 –d—– c:\program files\Eusing Free Registry Cleaner
2009-06-14 21:47 15,688 a——- c:\windows\system32\lsdelete.exe
2009-06-14 21:40 64,160 a——- c:\windows\system32\drivers\Lbd.sys
2009-06-14 21:39 -cd-h— c:\programdata\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-14 21:39 -cd-h— c:\progra~2\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-14 21:39 –d—– c:\program files\Lavasoft
2009-06-14 20:49 –d—– c:\users\mark\appdata\roaming\SUPERAntiSpyware.com
2009-06-14 20:49 –d—– c:\program files\SUPERAntiSpyware
2009-06-14 19:47 199,829,553 a——- c:\windows\MEMORY.DMP
2009-06-14 16:55 –d—– c:\program files\common files\Wise Installation Wizard
2009-06-14 04:34 376,320 a——- c:\windows\system32\winexplorer.dll
2009-06-14 04:33 –d—– c:\program files\common files\Uninstall
2009-06-14 04:32 –d—– c:\program files\PAV
2009-06-14 03:34 –d—– c:\program files\Trend Micro
2009-06-14 01:20 –d—– c:\programdata\PCPitstop
2009-06-14 01:20 –d—– c:\progra~2\PCPitstop
2009-06-14 01:19 –d—– c:\program files\PCPitstop
2009-06-14 01:01 –d—– c:\programdata\Lavasoft
2009-06-13 18:14 –d—– c:\program files\BHVideo
2009-06-13 17:13 –d—– c:\program files\uTorrent
2009-06-13 17:11 –d—– c:\users\mark\appdata\roaming\uTorrent
2009-06-10 02:13 2,033,152 a——- c:\windows\system32\win32k.sys
2009-06-10 02:01 784,896 a——- c:\windows\system32\rpcrt4.dll
2009-05-27 21:59 –d—– c:\users\mark\appdata\roaming\Camfrog
2009-05-25 19:20 –d—– c:\programdata\NCH Software
2009-05-25 19:19 –d—– c:\users\mark\appdata\roaming\NCH Software
2009-05-25 19:19 –d—– c:\program files\NCH Software
2009-05-24 22:21 –d-h— C:\$AVG8.VAULT$
2009-05-24 21:25 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-05-24 21:25 108,552 a——- c:\windows\system32\drivers\avgtdix.sys
2009-05-24 21:25 325,896 a——- c:\windows\system32\drivers\avgldx86.sys
2009-05-24 21:25 –d—– c:\windows\system32\drivers\Avg
2009-05-24 21:25 –d—– c:\programdata\avg8
2009-05-24 21:25 –d—– c:\program files\AVG
2009-05-24 21:25 –d—– c:\progra~2\avg8
2009-05-22 16:37 –d—– c:\users\mark\appdata\roaming\ooVoo Details
2009-05-22 02:27 –d—– c:\users\mark\appdata\roaming\Acer
2009-05-18 15:07 –d—– c:\users\Mark
2009-05-16 20:11 –d—– c:\program files\Paradise8
==================== Find3M ====================
2009-05-23 22:18 5,850 a–sh— c:\windows\system32\KGyGaAvL.sys
2009-05-09 01:50 915,456 a——- c:\windows\system32\wininet.dll
2009-05-09 01:34 71,680 a——- c:\windows\system32\iesetup.dll
2009-04-23 08:42 636,928 a——- c:\windows\system32\localspl.dll
2009-03-12 21:17 143,360 a——- c:\windows\inf\infstrng.dat
2009-03-12 21:17 143,360 a——- c:\windows\inf\infstor.dat
2009-03-12 21:17 86,016 a——- c:\windows\inf\infpub.dat
2008-07-07 11:32 174 a–sh— c:\program files\desktop.ini
2008-07-02 14:32 665,600 a——- c:\windows\inf\drvindex.dat
2007-12-22 15:19 476,752 a——- c:\programdata\pswi_preloaded.exe
2007-12-22 15:19 476,752 a——- c:\progra~2\pswi_preloaded.exe
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2007-12-30 19:17 8 —shr– c:\windows\system32\58FCD56796.sys
2007-12-22 15:20 88 —shr– c:\windows\system32\6C1FC0BF72.sys
============= FINISH: 17:18:06.04 ===============
Attatch.txt
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-05-14.01)
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 02/12/2007 3:18:03 AM
System Uptime: 15/06/2009 5:14:42 PM (0 hours ago)
Motherboard: Acer | | Poyang
Processor: Intel® Core™2 Duo CPU T5250 @ 1.50GHz | uPGA-478 | 1500/166mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 112 GiB total, 60.432 GiB free.
D: is FIXED (NTFS) - 111 GiB total, 111.343 GiB free.
E: is CDROM ()
==== Disabled Device Manager Items =============
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft Tun Miniport Adapter
Device ID: ROOT\*TUNMP\0001
Manufacturer: Microsoft
Name: Teredo Tunneling Pseudo-Interface
PNP Device ID: ROOT\*TUNMP\0001
Service: tunmp
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Broadcom NetLink ™ Gigabit Ethernet
Device ID: PCI\VEN_14E4&DEV_1693&SUBSYS_011E1025&REV_02\4&185174AE&0&00E2
Manufacturer: Broadcom
Name: Broadcom NetLink ™ Gigabit Ethernet
PNP Device ID: PCI\VEN_14E4&DEV_1693&SUBSYS_011E1025&REV_02\4&185174AE&0&00E2
Service: b57nd60x
==== System Restore Points ===================
==== Installed Programs ======================
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office system
Acer Assist
Acer Crystal Eye
Acer Crystal Eye webcam
Acer eAudio Management
Acer eDataSecurity Management
Acer eLock Management
Acer Empowering Technology
Acer eNet Management
Acer ePower Management
Acer ePresentation Management
Acer eSettings Management
Acer Mobility Center Plug-In
Acer Registration
Acer ScreenSaver
Ad-Aware
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Photoshop Elements 6.0
Adobe Reader 8.1.2
ALPS Touch Pad Driver
Apple Mobile Device Support
Apple Software Update
ArcSoft MediaConverter 2
µTorrent
Authentium AntiVirus SDK - 2
AutoUpdate
AVG Free 8.5
BHVideo
Bonjour
BroadCam
CDDRV_Installer
Corel Paint Shop Pro Photo XI
CorelDRAW Graphics Suite X3
Debut Video Capture Software
DirectXInstallService
DivX Codec
DivX Converter
DivX Player
DivX Web Player
EMC 10 Content
eMusic Download Manager
EN
Eusing Free Registry Cleaner
FlashLynx Video Download Software
FontNav
Google Earth
Google Toolbar for Internet Explorer
HDAUDIO Soft Data Fax Modem with SmartCP
helptut
helpug
Intel® Graphics Media Accelerator Driver
Intel® Matrix Storage Manager
iTunes
Java™ 6 Update 7
KhalInstallWrapper
LightScribe 1.4.142.1
Luxor 2
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB929729)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Hybrid 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft WorldWide Telescope
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
NCH Toolbox
NTI Backup NOW! 4.7
NTI CD & DVD-Maker
ooVoo
Paradise 8
PC Pitstop Exterminate2 2.0
Photilla Photo Album Software
PowerProducer 3.72
Prism Video Converter
QuickTime
Realtek High Definition Audio Driver
Roxio Activation Module
Roxio BackOnTrack
Roxio Central Audio
Roxio Central Copy
Roxio Central Core
Roxio Central Data
Roxio Central Tools
Roxio CinePlayer
Roxio CinePlayer Decoder Pack
Roxio Disc Gallery
Roxio Easy Media Creator 10 Suite
Roxio File Backup
Roxio MediaShare
Roxio Update Manager
Safari
Security Update for 2007 Microsoft Office System (KB951550)
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB969679)
Security Update for Microsoft Office Excel 2007 (KB969682)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office Publisher 2007 (KB950114)
Security Update for Microsoft Office system 2007 (KB954326)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office Word 2007 (KB969604)
Security Update for Visio 2007 (KB947590)
SmartSound Quicktracks Plugin
Spelling Dictionaries Support For Adobe Reader 8
SpyHunter
SUPERAntiSpyware Free Edition
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Outlook 2007 (KB952142)
Update for Microsoft Office Outlook 2007 Help (KB957246)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (kb970012)
Update Manager
VBA
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Windows Live Mail
Windows Live Messenger
WinRAR archiver
XVID Codec Installation
Zuma Deluxe
Zuma Deluxe 1.0
==== End Of File ===========================
GMER.txt
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-06-15 20:18:09
Windows 6.0.6001 Service Pack 1
—- System - GMER 1.0.15 —-
Code 98397E78 ZwCreateSection
Code 983969B8 ZwDuplicateObject
Code 8DE1DAD8 ZwEnumerateKey
Code 8DCFA0E0 ZwFlushInstructionCache
Code 9838B4B8 ZwSetInformationFile
Code 9838B018 ZwSetSystemInformation
Code 9838B620 ZwWriteFile
Code 8DCF7DDD IofCallDriver
Code 8DE23996 IofCompleteRequest
Code 98397E77 NtCreateSection
Code 983969B7 NtDuplicateObject
Code 9838B4B7 NtSetInformationFile
Code 9838B61F NtWriteFile
—- Kernel code sections - GMER 1.0.15 —-
.text ntoskrnl.exe!IofCallDriver 82492169 5 Bytes JMP 8DCF7DE2
.text ntoskrnl.exe!IofCompleteRequest 824921D6 5 Bytes JMP 8DE2399B
PAGE ntoskrnl.exe!ZwFlushInstructionCache 825F41C2 5 Bytes JMP 8DCFA0E4
PAGE ntoskrnl.exe!ZwSetSystemInformation 8260013E 5 Bytes JMP 9838B01C
PAGE ntoskrnl.exe!ZwEnumerateKey 8261F58C 5 Bytes JMP 8DE1DADC
PAGE ntoskrnl.exe!SeCreateAccessState + 1BA2 8263D51B 7 Bytes JMP 9838BC2C
PAGE ntoskrnl.exe!NtWriteFile 82648A22 7 Bytes JMP 9838B624
PAGE ntoskrnl.exe!NtCreateSection 82655B1F 7 Bytes JMP 98397E7C
PAGE ntoskrnl.exe!FsRtlGetFileSize + 194 82660041 7 Bytes JMP 98397A74
PAGE ntoskrnl.exe!NtDuplicateObject 82667AE3 7 Bytes JMP 983969BC
PAGE ntoskrnl.exe!RtlUpcaseUnicodeChar + 58 8266D703 7 Bytes JMP 983978E4
PAGE ntoskrnl.exe!NtSetInformationFile 82674C09 5 Bytes JMP 9838B4BC
PAGE ntoskrnl.exe!FsRtlIsNameInExpression + 439 82676763 7 Bytes JMP 9838BEB4
—- User IAT/EAT - GMER 1.0.15 —-
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [74907BA4] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [749498C5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7490D3C8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [748FF527] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [74907599] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [748FE43D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [7493B33D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [7490D68A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [7490012E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [74900095] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [748F71F3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [7498D802] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [749275E1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [748FDAE1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [748F668F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [748F66BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2284] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74901E45] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18065_none_9e7abe2e
c9c13222\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
—- Devices - GMER 1.0.15 —-
Device \FileSystem\fastfat \FatCdrom Code 9838B2A8
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \FileSystem\fastfat \Fat Code 9838B2A8
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
—- Services - GMER 1.0.15 —-
Service C:\Windows\system32\drivers\MSIVXqkpafndmvxgwwietautbpprvympfvotv.sys (*** hidden *** ) [SYSTEM] MSIVXserv.sys <– ROOTKIT !!!
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001583b7e356
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys@imagepath \systemroot\system32\drivers\MSIVXqkpafndmvxgwwietautbpprvympfvotv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys\modules@MSIVXserv \\?\globalroot\systemroot\system32\drivers\MSIVXqkpafndmvxgwwietautbpprvympfvotv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys\modules@MSIVXl \\?\globalroot\systemroot\system32\MSIVXchnivexrrctwvmvevsfqjjutxwxbppou.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\MSIVXserv.sys\modules@MSIVXclk \\?\globalroot\systemroot\system32\MSIVXejcpmyqnxmutdsxfwvofooisrdireiph.dll
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001583b7e356
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys@imagepath \systemroot\system32\drivers\MSIVXqkpafndmvxgwwietautbpprvympfvotv.sys
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys\modules
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys\modules@MSIVXserv \\?\globalroot\systemroot\system32\drivers\MSIVXqkpafndmvxgwwietautbpprvympfvotv.sys
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys\modules@MSIVXl \\?\globalroot\systemroot\system32\MSIVXchnivexrrctwvmvevsfqjjutxwxbppou.dll
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys\modules@MSIVXclk \\?\globalroot\systemroot\system32\MSIVXejcpmyqnxmutdsxfwvofooisrdireiph.dll
—- Files - GMER 1.0.15 —-
File C:\Windows\System32\drivers\MSIVXqkpafndmvxgwwietautbpprvympfvotv.sys 79872 bytes executable <– ROOTKIT !!!
File C:\Windows\System32\MSIVXchnivexrrctwvmvevsfqjjutxwxbppou.dll 26624 bytes executable
File C:\Windows\System32\MSIVXcount 4 bytes
File C:\Windows\System32\MSIVXejcpmyqnxmutdsxfwvofooisrdireiph.dll 52224 bytes executable
—- EOF - GMER 1.0.15 —-
Thanks
Mark
CatByte
Hi,
Please do the following:
Please download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
Please do the following:
Please download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
- If you are using Firefox, make sure that your download settings are as follows:
- Tools->Options->Main tab
- Set to "Always ask me where to Save the files".
- During the download, rename Combofix to Combo-Fix as follows:
[external image: Posted Image]
[external image: Posted Image]
- It is important you rename Combofix during the download, but not after.
- Please do not rename Combofix to other names, but only to the one indicated.
- Close any open browsers.
- Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
———————————————————–
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
- Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
———————————————————–
- Close any open browsers.
- If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
———————————————————–
- Double click on combo-Fix.exe & follow the prompts.
- When finished, it will produce a report for you.
- Please post the "C:\Combo-Fix.txt" for further review.
tase2
Here you go
ComboFix 09-06-15.05 - Mark 16/06/2009 0:09.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.2.1033.18.2037.586 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\drv\Tuner\Yuan\Resources\_desktop.ini
c:\program files\PAV
c:\users\Mark\AppData\Local\Temp\install_flash_player.exe
c:\windows\system32\drivers\MSIVXqkpafndmvxgwwietautbpprvympfvotv.sys
c:\windows\system32\MSIVXchnivexrrctwvmvevsfqjjutxwxbppou.dll
c:\windows\system32\MSIVXcount
c:\windows\system32\MSIVXejcpmyqnxmutdsxfwvofooisrdireiph.dll
c:\windows\system32\winexplorer.dll
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_MSIVXserv.sys
((((((((((((((((((((((((( Files Created from 2009-05-16 to 2009-06-16 )))))))))))))))))))))))))))))))
.
2009-06-16 04:29 . 2009-06-16 04:29 ——– d—–w- c:\users\Mark\AppData\Local\temp
2009-06-16 04:29 . 2009-06-16 04:29 ——– d—–w- c:\users\Tamara\AppData\Local\temp
2009-06-16 04:29 . 2009-06-16 04:29 ——– d—–w- c:\users\Guest\AppData\Local\temp
2009-06-15 04:41 . 2009-06-15 22:25 ——– d—–w- c:\program files\Enigma Software Group
2009-06-15 03:56 . 2009-05-26 17:20 40160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-15 03:56 . 2009-06-15 05:27 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-15 03:56 . 2009-06-15 03:56 ——– d—–w- c:\programdata\Malwarebytes
2009-06-15 03:56 . 2009-05-26 17:19 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-15 03:24 . 2009-06-15 03:24 ——– d—–w- c:\program files\Eusing Free Registry Cleaner
2009-06-15 01:47 . 2009-03-09 19:06 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-06-15 01:47 . 2009-06-15 01:47 121348 —-a-w- c:\programdata\Lavasoft\Ad-Aware\ThreatWork\Submit\psdutil.dll
2009-06-15 01:40 . 2009-03-09 19:06 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-15 01:40 . 2009-03-12 08:17 2902048 -c–a-w- c:\programdata\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-06-15 01:39 . 2009-06-15 01:40 ——– dc-h–w- c:\programdata\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-15 01:39 . 2009-06-15 01:39 ——– d—–w- c:\program files\Lavasoft
2009-06-15 00:49 . 2009-06-15 03:44 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-06-15 00:49 . 2009-06-15 00:49 ——– d—–w- c:\users\Mark\AppData\Roaming\SUPERAntiSpyware.com
2009-06-14 20:55 . 2009-06-14 20:55 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-06-14 08:33 . 2009-06-14 08:33 ——– d—–w- c:\program files\Common Files\Uninstall
2009-06-14 07:34 . 2009-06-14 07:34 ——– d—–w- c:\program files\Trend Micro
2009-06-14 05:20 . 2009-06-15 05:52 ——– d—–w- c:\programdata\PCPitstop
2009-06-14 05:19 . 2009-06-15 05:51 ——– d—–w- c:\program files\PCPitstop
2009-06-14 05:01 . 2009-06-15 01:39 ——– d—–w- c:\programdata\Lavasoft
2009-06-13 22:14 . 2009-06-13 22:14 ——– d—–w- c:\program files\BHVideo
2009-06-13 21:13 . 2009-06-13 21:13 ——– d—–w- c:\program files\uTorrent
2009-06-13 21:11 . 2009-06-14 00:11 ——– d—–w- c:\users\Mark\AppData\Roaming\uTorrent
2009-06-13 15:44 . 2009-06-13 15:44 ——– d—–w- c:\users\Guest\AppData\Roaming\NCH Software
2009-06-13 15:04 . 2009-06-13 15:04 ——– d—–w- c:\users\Guest\AppData\Local\Google
2009-06-12 21:02 . 2009-06-12 21:02 456304 —-a-w- c:\programdata\Google\Google Toolbar\Update\gtb7F1F.tmp.exe
2009-06-10 06:13 . 2009-04-21 11:55 2033152 —-a-w- c:\windows\system32\win32k.sys
2009-06-10 06:03 . 2009-04-23 12:42 636928 —-a-w- c:\windows\system32\localspl.dll
2009-06-10 06:03 . 2009-05-09 05:50 915456 —-a-w- c:\windows\system32\wininet.dll
2009-06-10 06:03 . 2009-05-09 05:34 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-06-10 06:01 . 2009-04-23 12:43 784896 —-a-w- c:\windows\system32\rpcrt4.dll
2009-06-06 01:10 . 2009-06-14 22:01 1356 —-a-w- c:\users\Mark\AppData\Local\d3d9caps.dat
2009-06-05 17:35 . 2009-06-05 17:35 ——– d—–w- c:\users\Mark\AppData\Roaming\Roxio
2009-06-01 04:44 . 2009-06-01 04:44 ——– d—–w- c:\users\Mark\AppData\Local\Microsoft Games
2009-05-28 01:59 . 2009-06-13 18:56 ——– d—–w- c:\users\Mark\AppData\Roaming\Camfrog
2009-05-27 04:45 . 2009-05-28 01:22 ——– d—–w- c:\users\Mark\AppData\Local\Yahoo
2009-05-25 23:20 . 2009-06-12 21:28 ——– d—–w- c:\programdata\NCH Software
2009-05-25 23:19 . 2009-06-12 21:27 ——– d—–w- c:\program files\NCH Software
2009-05-25 23:19 . 2009-06-05 17:01 ——– d—–w- c:\users\Mark\AppData\Roaming\NCH Software
2009-05-25 17:50 . 2009-05-25 17:50 ——– d—–w- c:\users\Mark\AppData\Local\Deployment
2009-05-25 17:50 . 2009-05-25 17:50 ——– d—–w- c:\users\Mark\AppData\Local\Apps
2009-05-25 02:21 . 2009-06-15 02:34 ——– d–h–w- C:\$AVG8.VAULT$
2009-05-25 01:25 . 2009-05-25 01:25 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-05-25 01:25 . 2009-05-25 01:25 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-25 01:25 . 2009-05-25 01:25 325896 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-05-25 01:25 . 2009-06-15 21:49 ——– d—–w- c:\windows\system32\drivers\Avg
2009-05-25 01:25 . 2009-05-25 01:25 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-05-25 01:25 . 2009-06-14 17:53 ——– d—–w- c:\programdata\avg8
2009-05-25 01:25 . 2009-05-25 01:25 ——– d—–w- c:\program files\AVG
2009-05-24 02:18 . 2009-05-24 02:19 ——– d—–w- c:\users\Mark\AppData\Roaming\Corel
2009-05-22 20:37 . 2009-05-22 20:37 ——– d—–w- c:\users\Mark\AppData\Roaming\ooVoo Details
2009-05-22 06:27 . 2009-05-22 06:27 ——– d—–w- c:\users\Mark\AppData\Roaming\Acer
2009-05-22 05:36 . 2009-05-22 05:36 93248 —-a-w- c:\users\Mark\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-21 03:32 . 2009-06-15 20:57 ——– d—–w- c:\users\Mark\AppData\Local\Adobe
2009-05-20 03:13 . 2009-05-20 03:13 ——– d—–w- c:\users\Mark\AppData\Local\Apple
2009-05-18 19:09 . 2009-05-18 19:09 ——– d—–w- c:\users\Mark\AppData\Roaming\Yahoo!
2009-05-18 19:09 . 2009-06-13 17:05 ——– d—–w- c:\users\Mark\AppData\Local\Google
2009-05-17 05:51 . 2009-05-17 05:51 ——– d—–w- c:\users\Tamara\AppData\Roaming\ooVoo Details
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-16 04:06 . 2008-05-31 17:29 12 —-a-w- c:\windows\bthservsdp.dat
2009-06-10 07:05 . 2007-12-29 22:34 ——– d—–w- c:\programdata\Microsoft Help
2009-06-05 17:50 . 2008-06-16 20:27 ——– d—–w- c:\program files\Roxio
2009-06-05 16:31 . 2008-05-10 20:31 ——– d—–w- c:\programdata\NCH Swift Sound
2009-06-05 16:31 . 2008-05-10 20:30 ——– d—–w- c:\program files\NCH Swift Sound
2009-05-28 01:26 . 2007-12-02 17:47 ——– d—–w- c:\program files\Yahoo!
2009-05-28 01:24 . 2009-03-06 18:19 ——– d—–w- c:\programdata\Yahoo!
2009-05-24 02:18 . 2007-12-22 19:20 5850 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-05-17 00:22 . 2009-05-17 00:11 ——– d—–w- c:\program files\Paradise8
2009-05-15 21:43 . 2009-05-09 21:17 680 —-a-w- c:\users\Tamara\AppData\Local\d3d9caps.dat
2009-05-15 21:41 . 2009-05-03 22:15 93248 —-a-w- c:\users\Tamara\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-15 13:26 . 2007-12-02 16:33 ——– d—–w- c:\program files\Windows Live
2009-05-15 13:14 . 2007-12-02 16:40 ——– d—–w- c:\program files\Windows Live Toolbar
2009-05-15 13:10 . 2007-08-31 05:59 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-05-14 13:13 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-05-13 16:43 . 2009-05-13 16:43 ——– d—–w- c:\program files\Common Files\Windows Live
2009-05-10 23:13 . 2008-02-09 16:37 ——– d—–w- c:\programdata\iolo
2009-05-06 23:20 . 2009-05-03 22:58 ——– d—–w- c:\program files\Planet7 Casino
2009-05-06 23:20 . 2009-05-03 23:23 ——– d—–w- c:\program files\Silver Oak Casino
2009-05-06 23:17 . 2009-05-06 23:17 ——– d—–w- c:\users\Tamara\AppData\Roaming\DivX
2009-05-03 22:59 . 2009-05-03 22:15 ——– d—–w- c:\users\Tamara\AppData\Roaming\iolo
2009-05-03 22:20 . 2009-05-03 22:20 ——– d—–w- c:\users\Tamara\AppData\Roaming\Yahoo!
2009-05-03 22:15 . 2009-05-03 22:15 ——– d—–w- c:\users\Tamara\AppData\Roaming\Leadertech
2009-05-03 22:15 . 2009-05-03 22:15 ——– d—–w- c:\users\Tamara\AppData\Roaming\Roxio
2007-12-30 23:17 . 2007-12-30 23:17 8 –sh–r- c:\windows\System32\58FCD56796.sys
2007-12-22 19:20 . 2007-12-22 19:20 88 –sh–r- c:\windows\System32\6C1FC0BF72.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-04 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Empowering Technology Launcher.lnk]
backup=c:\windows\pss\Empowering Technology Launcher.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{5F51E54C-1883-4E02-8952-66B3F119A062}"= UDP:c:\windows\System32\lxczcoms.exe:Lexmark Communications System
"{22018E50-F1AC-4262-B5DA-8D3A721A5A5A}"= TCP:c:\windows\System32\lxczcoms.exe:Lexmark Communications System
"{6B10E6D6-ECC9-4881-BFCC-E8B9E9448C82}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxczpswx.exe:Printer Status Window
"{638E84D0-5F23-4AC4-AFA4-D38FD8462BEF}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxczpswx.exe:Printer Status Window
"{FC8C58D3-7AFD-456A-AA57-C10B494EC600}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{A341D81B-4574-4841-9FA4-5DC8D7FA3DA4}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{5E0BD40D-C918-4DFE-913C-CA2D27F72F59}"= UDP:c:\program files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe:iolo Firewall®
"{C4CA3A20-EB69-4789-8B5C-40904F97AADE}"= TCP:c:\program files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe:iolo Firewall®
"{39D2F4A6-2483-43F1-B517-09F4519F418A}"= UDP:c:\program files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe:iolo AntiVirus®
"{72EA8900-5A0C-4EB0-B45B-2CC805431804}"= TCP:c:\program files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe:iolo AntiVirus®
"{BDDA12AD-3C55-4105-8CF0-DF68FFA32B30}"= UDP:c:\program files\iolo\System Mechanic Professional 7\AntiVirus\iAVEmailScanner.exe:iolo AntiVirus® Email Protection
"{A576B66D-C2DE-46E6-9713-226934565BA2}"= TCP:c:\program files\iolo\System Mechanic Professional 7\AntiVirus\iAVEmailScanner.exe:iolo AntiVirus® Email Protection
"{1587DF41-847B-4B0D-B94D-13CC5A9AA97A}"= Disabled:UDP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{C391511B-7C8A-4B03-9360-FB9E6E9A43D5}"= Disabled:TCP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"TCP Query User{8C7262D4-96DE-4EA7-872E-3889C3F80081}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{53E6180E-A55E-49DE-8C3D-2114C0F61705}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{BD48FC19-009E-4343-9B40-0258423D584C}"= TCP:2799:Altova License Metering Port (UDP)
"{FD3A5CD1-07E9-4B92-ABDF-BE28656953F5}"= UDP:2799:Altova License Metering Port (TCP)
"{A3EA3C91-088C-4730-9ACF-C54470AD7CC6}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{FCF40573-826A-40CB-AD38-B2A60AF1EBD7}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{8B19B348-B662-49AA-BA58-74DE76C69912}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{9012AEF3-0363-46B7-A596-D38F73CC8A39}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{7B3029E2-32FC-4170-836C-62FB9524AC0F}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{AC81E57B-534C-4A1F-BA3E-FBF89C3AAF2A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{7F9FDA0F-0FF2-4109-A331-F4461401E9A6}c:\\program files\\oovoo\\oovoo.exe"= UDP:c:\program files\oovoo\oovoo.exe:ooVoo
"UDP Query User{ACB06F30-44FA-4500-A752-077B5816623A}c:\\program files\\oovoo\\oovoo.exe"= TCP:c:\program files\oovoo\oovoo.exe:ooVoo
"{B82A096E-A5A3-4463-98F6-9C44ED1893A7}"= Disabled:UDP:443:ooVoo TCP port 443
"{A35FE2BF-1B8B-4114-92D8-CB8A73F5CF1C}"= Disabled:TCP:443:ooVoo UDP port 443
"{F4DE7FBA-7F54-49DE-B71B-3343A7308FB4}"= Disabled:UDP:37674:ooVoo TCP port 37674
"{EF73B2EF-101E-499C-8BC2-DF38819BB8CC}"= Disabled:TCP:37674:ooVoo UDP port 37674
"{F7AFE01C-D1AD-47BC-8D54-8102158C513C}"= Disabled:TCP:37675:ooVoo UDP port 37675
"TCP Query User{4F534D5A-C7D6-4750-9AE2-710505B220F5}c:\\program files\\oovoo\\oovoo.exe"= UDP:c:\program files\oovoo\oovoo.exe:ooVoo
"UDP Query User{0D218826-5A75-44F5-BFDE-626D62764C4A}c:\\program files\\oovoo\\oovoo.exe"= TCP:c:\program files\oovoo\oovoo.exe:ooVoo
"{BCED55B6-2975-4EA6-8971-35DAE2953A28}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{1C6AAB50-ADB7-4F12-884D-631328010F45}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{373EB1B1-952C-4E42-B595-8000E9C2A01C}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{D606E421-D8CE-4450-8ECB-3D48FE65E1FA}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{D3EF95AA-CCF2-477F-BE57-9C1F42C931AF}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{F7A4D666-A976-4C51-A6C3-465EF79B9475}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe
"{69BEB895-8B5D-46ED-8A46-C94A5AA505C3}"= UDP:86:BroadCam Web Server
"{A962B5B6-6B92-4635-9511-95591D79805C}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{18810E61-73D1-4D6F-8D13-DC82DA6B1D38}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{C38A14C4-6E0E-4443-BDA7-65B36C5BEEC4}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{728CDABC-5F8E-42B6-84D6-A8D2D0B1114C}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Acer\\Empowering Technology\\eDataSecurity\\eDSfsu.exe"= c:\acer\Empowering Technology\eDataSecurity\eDSfsu.exe:*:Enabled:eDSfsu
"c:\\Acer\\Empowering Technology\\eDataSecurity\\encryption.exe"= c:\acer\Empowering Technology\eDataSecurity\encryption.exe:*:Enabled:encryption
"c:\\Acer\\Empowering Technology\\eDataSecurity\\decryption.exe"= c:\acer\Empowering Technology\eDataSecurity\decryption.exe:*:Enabled:decryption
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [14/06/2009 9:40 PM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [24/05/2009 9:25 PM 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [24/05/2009 9:25 PM 108552]
R1 ElRawDisk;ElRawDisk;c:\windows\System32\drivers\elrawdsk.sys [09/02/2008 12:49 PM 12800]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [02/10/2007 3:46 PM 124832]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [24/05/2009 9:25 PM 298776]
R2 BroadCamService;BroadCam Service;c:\program files\NCH Software\BroadCam\broadCam.exe [25/05/2009 7:20 PM 368644]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [09/03/2009 3:06 PM 951632]
R2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [24/08/2007 4:52 PM 166384]
R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [31/08/2007 1:11 AM 32256]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [24/08/2007 4:52 PM 1083888]
S2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\Roxio\Digital Home 10\RoxioUpnpService10.exe [24/08/2007 4:53 PM 362992]
S2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [24/08/2007 4:52 PM 309744]
S2 SessionLauncher;SessionLauncher; [x]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [31/08/2007 1:11 AM 179712]
S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [24/08/2007 4:53 PM 72176]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\PCPitstop\PCPitstopScheduleService.exe [15/06/2009 1:51 AM 77312]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
Contents of the 'Scheduled Tasks' folder
2009-06-16 c:\windows\Tasks\User_Feed_Synchronization-{2F813C91-EA31-42E0-8FCE-06CD7310A732}.job
- c:\windows\system32\msfeedssync.exe [2009-04-04 11:31]
2009-06-16 c:\windows\Tasks\User_Feed_Synchronization-{539DC73A-5177-4DF4-8A08-C6FCCCA86A3E}.job
- c:\windows\system32\msfeedssync.exe [2009-04-04 11:31]
2009-06-16 c:\windows\Tasks\User_Feed_Synchronization-{F52471F2-32F4-49AB-B265-602BD793045F}.job
- c:\windows\system32\msfeedssync.exe [2009-04-04 11:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = www.google.com/
mStart Page = hxxp://en.ca.acer.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} - hxxp://utilities.pcpitstop.com/Exterminate2/pcpitstopAntiVirus.dll
.
.
——- File Associations ——-
.
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-16 00:29
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-06-16 0:30
ComboFix-quarantined-files.txt 2009-06-16 04:30
Pre-Run: 64,783,515,648 bytes free
Post-Run: 71,225,159,680 bytes free
282 — E O F — 2009-06-13 05:50
ComboFix 09-06-15.05 - Mark 16/06/2009 0:09.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.2.1033.18.2037.586 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\drv\Tuner\Yuan\Resources\_desktop.ini
c:\program files\PAV
c:\users\Mark\AppData\Local\Temp\install_flash_player.exe
c:\windows\system32\drivers\MSIVXqkpafndmvxgwwietautbpprvympfvotv.sys
c:\windows\system32\MSIVXchnivexrrctwvmvevsfqjjutxwxbppou.dll
c:\windows\system32\MSIVXcount
c:\windows\system32\MSIVXejcpmyqnxmutdsxfwvofooisrdireiph.dll
c:\windows\system32\winexplorer.dll
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_MSIVXserv.sys
((((((((((((((((((((((((( Files Created from 2009-05-16 to 2009-06-16 )))))))))))))))))))))))))))))))
.
2009-06-16 04:29 . 2009-06-16 04:29 ——– d—–w- c:\users\Mark\AppData\Local\temp
2009-06-16 04:29 . 2009-06-16 04:29 ——– d—–w- c:\users\Tamara\AppData\Local\temp
2009-06-16 04:29 . 2009-06-16 04:29 ——– d—–w- c:\users\Guest\AppData\Local\temp
2009-06-15 04:41 . 2009-06-15 22:25 ——– d—–w- c:\program files\Enigma Software Group
2009-06-15 03:56 . 2009-05-26 17:20 40160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-15 03:56 . 2009-06-15 05:27 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-15 03:56 . 2009-06-15 03:56 ——– d—–w- c:\programdata\Malwarebytes
2009-06-15 03:56 . 2009-05-26 17:19 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-15 03:24 . 2009-06-15 03:24 ——– d—–w- c:\program files\Eusing Free Registry Cleaner
2009-06-15 01:47 . 2009-03-09 19:06 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-06-15 01:47 . 2009-06-15 01:47 121348 —-a-w- c:\programdata\Lavasoft\Ad-Aware\ThreatWork\Submit\psdutil.dll
2009-06-15 01:40 . 2009-03-09 19:06 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-15 01:40 . 2009-03-12 08:17 2902048 -c–a-w- c:\programdata\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-06-15 01:39 . 2009-06-15 01:40 ——– dc-h–w- c:\programdata\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-15 01:39 . 2009-06-15 01:39 ——– d—–w- c:\program files\Lavasoft
2009-06-15 00:49 . 2009-06-15 03:44 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-06-15 00:49 . 2009-06-15 00:49 ——– d—–w- c:\users\Mark\AppData\Roaming\SUPERAntiSpyware.com
2009-06-14 20:55 . 2009-06-14 20:55 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-06-14 08:33 . 2009-06-14 08:33 ——– d—–w- c:\program files\Common Files\Uninstall
2009-06-14 07:34 . 2009-06-14 07:34 ——– d—–w- c:\program files\Trend Micro
2009-06-14 05:20 . 2009-06-15 05:52 ——– d—–w- c:\programdata\PCPitstop
2009-06-14 05:19 . 2009-06-15 05:51 ——– d—–w- c:\program files\PCPitstop
2009-06-14 05:01 . 2009-06-15 01:39 ——– d—–w- c:\programdata\Lavasoft
2009-06-13 22:14 . 2009-06-13 22:14 ——– d—–w- c:\program files\BHVideo
2009-06-13 21:13 . 2009-06-13 21:13 ——– d—–w- c:\program files\uTorrent
2009-06-13 21:11 . 2009-06-14 00:11 ——– d—–w- c:\users\Mark\AppData\Roaming\uTorrent
2009-06-13 15:44 . 2009-06-13 15:44 ——– d—–w- c:\users\Guest\AppData\Roaming\NCH Software
2009-06-13 15:04 . 2009-06-13 15:04 ——– d—–w- c:\users\Guest\AppData\Local\Google
2009-06-12 21:02 . 2009-06-12 21:02 456304 —-a-w- c:\programdata\Google\Google Toolbar\Update\gtb7F1F.tmp.exe
2009-06-10 06:13 . 2009-04-21 11:55 2033152 —-a-w- c:\windows\system32\win32k.sys
2009-06-10 06:03 . 2009-04-23 12:42 636928 —-a-w- c:\windows\system32\localspl.dll
2009-06-10 06:03 . 2009-05-09 05:50 915456 —-a-w- c:\windows\system32\wininet.dll
2009-06-10 06:03 . 2009-05-09 05:34 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-06-10 06:01 . 2009-04-23 12:43 784896 —-a-w- c:\windows\system32\rpcrt4.dll
2009-06-06 01:10 . 2009-06-14 22:01 1356 —-a-w- c:\users\Mark\AppData\Local\d3d9caps.dat
2009-06-05 17:35 . 2009-06-05 17:35 ——– d—–w- c:\users\Mark\AppData\Roaming\Roxio
2009-06-01 04:44 . 2009-06-01 04:44 ——– d—–w- c:\users\Mark\AppData\Local\Microsoft Games
2009-05-28 01:59 . 2009-06-13 18:56 ——– d—–w- c:\users\Mark\AppData\Roaming\Camfrog
2009-05-27 04:45 . 2009-05-28 01:22 ——– d—–w- c:\users\Mark\AppData\Local\Yahoo
2009-05-25 23:20 . 2009-06-12 21:28 ——– d—–w- c:\programdata\NCH Software
2009-05-25 23:19 . 2009-06-12 21:27 ——– d—–w- c:\program files\NCH Software
2009-05-25 23:19 . 2009-06-05 17:01 ——– d—–w- c:\users\Mark\AppData\Roaming\NCH Software
2009-05-25 17:50 . 2009-05-25 17:50 ——– d—–w- c:\users\Mark\AppData\Local\Deployment
2009-05-25 17:50 . 2009-05-25 17:50 ——– d—–w- c:\users\Mark\AppData\Local\Apps
2009-05-25 02:21 . 2009-06-15 02:34 ——– d–h–w- C:\$AVG8.VAULT$
2009-05-25 01:25 . 2009-05-25 01:25 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-05-25 01:25 . 2009-05-25 01:25 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-25 01:25 . 2009-05-25 01:25 325896 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-05-25 01:25 . 2009-06-15 21:49 ——– d—–w- c:\windows\system32\drivers\Avg
2009-05-25 01:25 . 2009-05-25 01:25 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-05-25 01:25 . 2009-06-14 17:53 ——– d—–w- c:\programdata\avg8
2009-05-25 01:25 . 2009-05-25 01:25 ——– d—–w- c:\program files\AVG
2009-05-24 02:18 . 2009-05-24 02:19 ——– d—–w- c:\users\Mark\AppData\Roaming\Corel
2009-05-22 20:37 . 2009-05-22 20:37 ——– d—–w- c:\users\Mark\AppData\Roaming\ooVoo Details
2009-05-22 06:27 . 2009-05-22 06:27 ——– d—–w- c:\users\Mark\AppData\Roaming\Acer
2009-05-22 05:36 . 2009-05-22 05:36 93248 —-a-w- c:\users\Mark\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-21 03:32 . 2009-06-15 20:57 ——– d—–w- c:\users\Mark\AppData\Local\Adobe
2009-05-20 03:13 . 2009-05-20 03:13 ——– d—–w- c:\users\Mark\AppData\Local\Apple
2009-05-18 19:09 . 2009-05-18 19:09 ——– d—–w- c:\users\Mark\AppData\Roaming\Yahoo!
2009-05-18 19:09 . 2009-06-13 17:05 ——– d—–w- c:\users\Mark\AppData\Local\Google
2009-05-17 05:51 . 2009-05-17 05:51 ——– d—–w- c:\users\Tamara\AppData\Roaming\ooVoo Details
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-16 04:06 . 2008-05-31 17:29 12 —-a-w- c:\windows\bthservsdp.dat
2009-06-10 07:05 . 2007-12-29 22:34 ——– d—–w- c:\programdata\Microsoft Help
2009-06-05 17:50 . 2008-06-16 20:27 ——– d—–w- c:\program files\Roxio
2009-06-05 16:31 . 2008-05-10 20:31 ——– d—–w- c:\programdata\NCH Swift Sound
2009-06-05 16:31 . 2008-05-10 20:30 ——– d—–w- c:\program files\NCH Swift Sound
2009-05-28 01:26 . 2007-12-02 17:47 ——– d—–w- c:\program files\Yahoo!
2009-05-28 01:24 . 2009-03-06 18:19 ——– d—–w- c:\programdata\Yahoo!
2009-05-24 02:18 . 2007-12-22 19:20 5850 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-05-17 00:22 . 2009-05-17 00:11 ——– d—–w- c:\program files\Paradise8
2009-05-15 21:43 . 2009-05-09 21:17 680 —-a-w- c:\users\Tamara\AppData\Local\d3d9caps.dat
2009-05-15 21:41 . 2009-05-03 22:15 93248 —-a-w- c:\users\Tamara\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-15 13:26 . 2007-12-02 16:33 ——– d—–w- c:\program files\Windows Live
2009-05-15 13:14 . 2007-12-02 16:40 ——– d—–w- c:\program files\Windows Live Toolbar
2009-05-15 13:10 . 2007-08-31 05:59 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-05-14 13:13 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-05-13 16:43 . 2009-05-13 16:43 ——– d—–w- c:\program files\Common Files\Windows Live
2009-05-10 23:13 . 2008-02-09 16:37 ——– d—–w- c:\programdata\iolo
2009-05-06 23:20 . 2009-05-03 22:58 ——– d—–w- c:\program files\Planet7 Casino
2009-05-06 23:20 . 2009-05-03 23:23 ——– d—–w- c:\program files\Silver Oak Casino
2009-05-06 23:17 . 2009-05-06 23:17 ——– d—–w- c:\users\Tamara\AppData\Roaming\DivX
2009-05-03 22:59 . 2009-05-03 22:15 ——– d—–w- c:\users\Tamara\AppData\Roaming\iolo
2009-05-03 22:20 . 2009-05-03 22:20 ——– d—–w- c:\users\Tamara\AppData\Roaming\Yahoo!
2009-05-03 22:15 . 2009-05-03 22:15 ——– d—–w- c:\users\Tamara\AppData\Roaming\Leadertech
2009-05-03 22:15 . 2009-05-03 22:15 ——– d—–w- c:\users\Tamara\AppData\Roaming\Roxio
2007-12-30 23:17 . 2007-12-30 23:17 8 –sh–r- c:\windows\System32\58FCD56796.sys
2007-12-22 19:20 . 2007-12-22 19:20 88 –sh–r- c:\windows\System32\6C1FC0BF72.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-04 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Empowering Technology Launcher.lnk]
backup=c:\windows\pss\Empowering Technology Launcher.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{5F51E54C-1883-4E02-8952-66B3F119A062}"= UDP:c:\windows\System32\lxczcoms.exe:Lexmark Communications System
"{22018E50-F1AC-4262-B5DA-8D3A721A5A5A}"= TCP:c:\windows\System32\lxczcoms.exe:Lexmark Communications System
"{6B10E6D6-ECC9-4881-BFCC-E8B9E9448C82}"= UDP:c:\windows\System32\spool\drivers\w32x86\3\lxczpswx.exe:Printer Status Window
"{638E84D0-5F23-4AC4-AFA4-D38FD8462BEF}"= TCP:c:\windows\System32\spool\drivers\w32x86\3\lxczpswx.exe:Printer Status Window
"{FC8C58D3-7AFD-456A-AA57-C10B494EC600}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{A341D81B-4574-4841-9FA4-5DC8D7FA3DA4}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{5E0BD40D-C918-4DFE-913C-CA2D27F72F59}"= UDP:c:\program files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe:iolo Firewall®
"{C4CA3A20-EB69-4789-8B5C-40904F97AADE}"= TCP:c:\program files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe:iolo Firewall®
"{39D2F4A6-2483-43F1-B517-09F4519F418A}"= UDP:c:\program files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe:iolo AntiVirus®
"{72EA8900-5A0C-4EB0-B45B-2CC805431804}"= TCP:c:\program files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe:iolo AntiVirus®
"{BDDA12AD-3C55-4105-8CF0-DF68FFA32B30}"= UDP:c:\program files\iolo\System Mechanic Professional 7\AntiVirus\iAVEmailScanner.exe:iolo AntiVirus® Email Protection
"{A576B66D-C2DE-46E6-9713-226934565BA2}"= TCP:c:\program files\iolo\System Mechanic Professional 7\AntiVirus\iAVEmailScanner.exe:iolo AntiVirus® Email Protection
"{1587DF41-847B-4B0D-B94D-13CC5A9AA97A}"= Disabled:UDP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{C391511B-7C8A-4B03-9360-FB9E6E9A43D5}"= Disabled:TCP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"TCP Query User{8C7262D4-96DE-4EA7-872E-3889C3F80081}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{53E6180E-A55E-49DE-8C3D-2114C0F61705}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{BD48FC19-009E-4343-9B40-0258423D584C}"= TCP:2799:Altova License Metering Port (UDP)
"{FD3A5CD1-07E9-4B92-ABDF-BE28656953F5}"= UDP:2799:Altova License Metering Port (TCP)
"{A3EA3C91-088C-4730-9ACF-C54470AD7CC6}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{FCF40573-826A-40CB-AD38-B2A60AF1EBD7}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{8B19B348-B662-49AA-BA58-74DE76C69912}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{9012AEF3-0363-46B7-A596-D38F73CC8A39}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{7B3029E2-32FC-4170-836C-62FB9524AC0F}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{AC81E57B-534C-4A1F-BA3E-FBF89C3AAF2A}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{7F9FDA0F-0FF2-4109-A331-F4461401E9A6}c:\\program files\\oovoo\\oovoo.exe"= UDP:c:\program files\oovoo\oovoo.exe:ooVoo
"UDP Query User{ACB06F30-44FA-4500-A752-077B5816623A}c:\\program files\\oovoo\\oovoo.exe"= TCP:c:\program files\oovoo\oovoo.exe:ooVoo
"{B82A096E-A5A3-4463-98F6-9C44ED1893A7}"= Disabled:UDP:443:ooVoo TCP port 443
"{A35FE2BF-1B8B-4114-92D8-CB8A73F5CF1C}"= Disabled:TCP:443:ooVoo UDP port 443
"{F4DE7FBA-7F54-49DE-B71B-3343A7308FB4}"= Disabled:UDP:37674:ooVoo TCP port 37674
"{EF73B2EF-101E-499C-8BC2-DF38819BB8CC}"= Disabled:TCP:37674:ooVoo UDP port 37674
"{F7AFE01C-D1AD-47BC-8D54-8102158C513C}"= Disabled:TCP:37675:ooVoo UDP port 37675
"TCP Query User{4F534D5A-C7D6-4750-9AE2-710505B220F5}c:\\program files\\oovoo\\oovoo.exe"= UDP:c:\program files\oovoo\oovoo.exe:ooVoo
"UDP Query User{0D218826-5A75-44F5-BFDE-626D62764C4A}c:\\program files\\oovoo\\oovoo.exe"= TCP:c:\program files\oovoo\oovoo.exe:ooVoo
"{BCED55B6-2975-4EA6-8971-35DAE2953A28}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{1C6AAB50-ADB7-4F12-884D-631328010F45}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"TCP Query User{373EB1B1-952C-4E42-B595-8000E9C2A01C}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{D606E421-D8CE-4450-8ECB-3D48FE65E1FA}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{D3EF95AA-CCF2-477F-BE57-9C1F42C931AF}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{F7A4D666-A976-4C51-A6C3-465EF79B9475}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe
"{69BEB895-8B5D-46ED-8A46-C94A5AA505C3}"= UDP:86:BroadCam Web Server
"{A962B5B6-6B92-4635-9511-95591D79805C}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{18810E61-73D1-4D6F-8D13-DC82DA6B1D38}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{C38A14C4-6E0E-4443-BDA7-65B36C5BEEC4}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{728CDABC-5F8E-42B6-84D6-A8D2D0B1114C}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Acer\\Empowering Technology\\eDataSecurity\\eDSfsu.exe"= c:\acer\Empowering Technology\eDataSecurity\eDSfsu.exe:*:Enabled:eDSfsu
"c:\\Acer\\Empowering Technology\\eDataSecurity\\encryption.exe"= c:\acer\Empowering Technology\eDataSecurity\encryption.exe:*:Enabled:encryption
"c:\\Acer\\Empowering Technology\\eDataSecurity\\decryption.exe"= c:\acer\Empowering Technology\eDataSecurity\decryption.exe:*:Enabled:decryption
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [14/06/2009 9:40 PM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [24/05/2009 9:25 PM 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [24/05/2009 9:25 PM 108552]
R1 ElRawDisk;ElRawDisk;c:\windows\System32\drivers\elrawdsk.sys [09/02/2008 12:49 PM 12800]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [02/10/2007 3:46 PM 124832]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [24/05/2009 9:25 PM 298776]
R2 BroadCamService;BroadCam Service;c:\program files\NCH Software\BroadCam\broadCam.exe [25/05/2009 7:20 PM 368644]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [09/03/2009 3:06 PM 951632]
R2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [24/08/2007 4:52 PM 166384]
R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [31/08/2007 1:11 AM 32256]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [24/08/2007 4:52 PM 1083888]
S2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\Roxio\Digital Home 10\RoxioUpnpService10.exe [24/08/2007 4:53 PM 362992]
S2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [24/08/2007 4:52 PM 309744]
S2 SessionLauncher;SessionLauncher; [x]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\b57nd60x.sys [31/08/2007 1:11 AM 179712]
S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [24/08/2007 4:53 PM 72176]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\PCPitstop\PCPitstopScheduleService.exe [15/06/2009 1:51 AM 77312]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
Contents of the 'Scheduled Tasks' folder
2009-06-16 c:\windows\Tasks\User_Feed_Synchronization-{2F813C91-EA31-42E0-8FCE-06CD7310A732}.job
- c:\windows\system32\msfeedssync.exe [2009-04-04 11:31]
2009-06-16 c:\windows\Tasks\User_Feed_Synchronization-{539DC73A-5177-4DF4-8A08-C6FCCCA86A3E}.job
- c:\windows\system32\msfeedssync.exe [2009-04-04 11:31]
2009-06-16 c:\windows\Tasks\User_Feed_Synchronization-{F52471F2-32F4-49AB-B265-602BD793045F}.job
- c:\windows\system32\msfeedssync.exe [2009-04-04 11:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = www.google.com/
mStart Page = hxxp://en.ca.acer.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} - hxxp://utilities.pcpitstop.com/Exterminate2/pcpitstopAntiVirus.dll
.
.
——- File Associations ——-
.
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-16 00:29
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-06-16 0:30
ComboFix-quarantined-files.txt 2009-06-16 04:30
Pre-Run: 64,783,515,648 bytes free
Post-Run: 71,225,159,680 bytes free
282 — E O F — 2009-06-13 05:50
CatByte
Hi,
You are showing you have AVG on your system as well as Iolo AV, please advise the status of both these AV's..did you attempt to uninstall AVG?
Please do the following
It's important to run this online scan to search for any remnants. It can take some time, so please be patient and allow it to run it's full course:
Using Internet Explorer or Firefox, visit Kaspersky Online Scanner:
1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
You are showing you have AVG on your system as well as Iolo AV, please advise the status of both these AV's..did you attempt to uninstall AVG?
Please do the following
- Open your Malware Bytes AntiMalware programe
- Select the updates tab, and allow the program to update
- run a quick scan on your system
- Allow the program to remove any detected items
- post the resulting log.
It's important to run this online scan to search for any remnants. It can take some time, so please be patient and allow it to run it's full course:
Using Internet Explorer or Firefox, visit Kaspersky Online Scanner:
1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
- Close any open programs
- Turn off the real time scanner of any existing antivirus program while performing the online scan
- Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
- Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
- Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
- Click View scan report at the bottom.
[external image: Posted Image] - Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
tase2
Hi CatByte
On your 1st question - I'm not even sure what a lolo-AV is, so I don't think I ever downloaded it. I couldn't find it on search.
I do have AVG. I donn't think I've tried to uninstall it. I did fiddle with it a bit when you asked that I not have 2 virus apllications running at the same time.
I hope that helps.
I am posting 2 Maleware bytes logs-one before deleting the 6 infections and one after.
Malwarebytes' Anti-Malware 1.37
Database version: 2290
Windows 6.0.6001 Service Pack 1
16/06/2009 7:35:08 PM
mbam-log-2009-06-16 (19-34-57).txt
Scan type: Quick Scan
Objects scanned: 100877
Time elapsed: 4 minute(s), 7 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BHVideo (Trojan.DNSChanger) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\BHVideo (Trojan.DNSChanger) -> No action taken.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
c:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BHVideo (Trojan.DNSChanger) -> No action taken.
C:\Program Files\BHVideo (Trojan.DNSChanger) -> No action taken.
Files Infected:
c:\Users\Mark\AppData\Roaming\microsoft\Windows\start menu\Programs\BHVideo\Uninstall.lnk (Trojan.DNSChanger) -> No action taken.
c:\program files\BHVideo\Uninstall.exe (Trojan.DNSChanger) -> No action taken.
Malwarebytes' Anti-Malware 1.37
Database version: 2290
Windows 6.0.6001 Service Pack 1
16/06/2009 7:35:14 PM
mbam-log-2009-06-16 (19-35-14).txt
Scan type: Quick Scan
Objects scanned: 100877
Time elapsed: 4 minute(s), 7 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BHVideo (Trojan.DNSChanger) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\BHVideo (Trojan.DNSChanger) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
c:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BHVideo (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\Program Files\BHVideo (Trojan.DNSChanger) -> Quarantined and deleted successfully.
Files Infected:
c:\Users\Mark\AppData\Roaming\microsoft\Windows\start menu\Programs\BHVideo\Uninstall.lnk (Trojan.DNSChanger) -> Quarantined and deleted successfully.
c:\program files\BHVideo\Uninstall.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
I can't believe it-I know I save the Kasper log to my desktop-but I can't find it anywhere. carp**-that took a long time-I guess I will do it again tonight.
Thanks
Mark
tase2
Hi CatByte
I'll try this again
On your 1st question - I'm not even sure what a lolo-AV is, so I don't think I ever downloaded it. I couldn't find it on search.
I do have AVG. I donn't think I've tried to uninstall it. I did fiddle with it a bit when you asked that I not have 2 virus apllications running at the same time.
I hope that helps.
I am posting 2 Maleware bytes logs-one before deleting the 6 infections and one after.
Malwarebytes' Anti-Malware 1.37
Database version: 2290
Windows 6.0.6001 Service Pack 1
16/06/2009 7:35:08 PM
mbam-log-2009-06-16 (19-34-57).txt
Scan type: Quick Scan
Objects scanned: 100877
Time elapsed: 4 minute(s), 7 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BHVideo (Trojan.DNSChanger) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\BHVideo (Trojan.DNSChanger) -> No action taken.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
c:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BHVideo (Trojan.DNSChanger) -> No action taken.
C:\Program Files\BHVideo (Trojan.DNSChanger) -> No action taken.
Files Infected:
c:\Users\Mark\AppData\Roaming\microsoft\Windows\start menu\Programs\BHVideo\Uninstall.lnk (Trojan.DNSChanger) -> No action taken.
c:\program files\BHVideo\Uninstall.exe (Trojan.DNSChanger) -> No action taken.
Malwarebytes' Anti-Malware 1.37
Database version: 2290
Windows 6.0.6001 Service Pack 1
16/06/2009 7:35:14 PM
mbam-log-2009-06-16 (19-35-14).txt
Scan type: Quick Scan
Objects scanned: 100877
Time elapsed: 4 minute(s), 7 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BHVideo (Trojan.DNSChanger) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\BHVideo (Trojan.DNSChanger) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
c:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BHVideo (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\Program Files\BHVideo (Trojan.DNSChanger) -> Quarantined and deleted successfully.
Files Infected:
c:\Users\Mark\AppData\Roaming\microsoft\Windows\start menu\Programs\BHVideo\Uninstall.lnk (Trojan.DNSChanger) -> Quarantined and deleted successfully.
c:\program files\BHVideo\Uninstall.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully.
Kaspersky log
——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
Wednesday, June 17, 2009
Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Thursday, June 18, 2009 02:37:50
Records in database: 2359259
——————————————————————————–
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
Scan statistics:
Files scanned: 127588
Threat name: 2
Infected objects: 2
Suspicious objects: 0
Duration of the scan: 02:01:38
File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\Windows\System32\drivers\_MSIVXqkpafndmvxgwwietautbpprvympfvotv_.sys.zip Infected: Trojan.Win32.Tdss.ahpu 1
C:\Qoobox\Quarantine\C\Windows\System32\MSIVXchnivexrrctwvmvevsfqjjutxwxbppou.dll.vir Infected: Trojan.Win32.Agent.clxm 1
The selected area was scanned.
CatByte
Hi,
This was the program I was referring to:
Anyway,
The file found by Kaspersky is already in quarantine, so cannot harm the computer.
NEXT
Please download JavaRa to your desktop and unzip it to its own folder.
NEXT
Visit ADOBEand download the latest version of Acrobat Reader (version 9.1)
Having the latest updates ensures there are no security vulnerabilities in your system.
NEXT
Please run a fresh DDS log so I can make sure you are clean, then we can begin our final clean up.
Also please asbise how your computer is running now and if there are any outstanding issues.
This was the program I was referring to:
c:\program files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe:iolo Firewall®
c:\program files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe:iolo AntiVirus®
Anyway,
The file found by Kaspersky is already in quarantine, so cannot harm the computer.
NEXT
Please download JavaRa to your desktop and unzip it to its own folder.
- Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
- Accept any prompts.
- Open JavaRa.exe again and select Search For Updates.
- Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
- Download and install the latest Java Runtime Environment (JRE) version for your computer.(version 6, update 14)
NEXT
Visit ADOBEand download the latest version of Acrobat Reader (version 9.1)
Having the latest updates ensures there are no security vulnerabilities in your system.
NEXT
Please run a fresh DDS log so I can make sure you are clean, then we can begin our final clean up.
Also please asbise how your computer is running now and if there are any outstanding issues.
tase2
Hi
Is there any arm in having both
QUOTE
c:\program files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe:iolo Firewall®
c:\program files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe:iolo AntiVirus® ? or do I need to delete one?
I updated Java & Adobe
Here are my DDS logs
DDS (Ver_09-05-14.01) - NTFSx86
Run by [removed] at 15:43:40.16 on 18/06/2009
Internet Explorer: 8.0.6001.18783
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.2.1033.18.2037.859 [GMT -4:00]
SP: Lavasoft Ad-Watch Live! *enabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NCH Software\BroadCam\broadCam.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
C:\Acer\Empowering Technology\eNet\eNet Service.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\lxczcoms.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\PSIService.exe
C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\system32\conime.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\msiexec.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Mark\Desktop\dds.pif
============== Pseudo HJT Report ===============
uStart Page = www.google.com/
mStart Page = hxxp://en.ca.acer.yahoo.com
BHO: {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572
\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google
toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\windows\system32\eDStoolbar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
DPF: {2D337EB0-3BFB-42A3-B314-A24BBA8C085B} - hxxp://download.yahoo.com/dl/mail/yautoiol1.cab
DPF: {459E93B6-150E-45D5-8D4B-45C66FC035FE} - hxxp://apps.corel.com/nos_dl_manager_dev/plugin/IEGetPlugin.ocx
DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} - hxxp://utilities.pcpitstop.com/Exterminate2/pcpitstopAntiVirus.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://plugin.driveragent.com/files/driveragent.cab
DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\windows\system32\avgrsstx.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-17 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-5-24 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-5-24 108552]
R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\elrawdsk.sys [2008-2-9 12800]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\adobe\photoshop elements 6.0\PhotoshopElementsFileAgent.exe [2007
-10-2 124832]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-5-24 298776]
R2 BroadCamService;BroadCam Service;c:\program files\nch software\broadcam\broadCam.exe [2009-5-25 368644]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 1003344]
R2 lxcz_device;lxcz_device;c:\windows\system32\lxczcoms.exe -service –> c:\windows\system32\lxczcoms.exe -service [?]
R2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxWatch10.exe [2007-8-24 166384]
R3 enecir;ENE CIR Receiver;c:\windows\system32\drivers\enecir.sys [2007-8-31 32256]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxMediaDB10.exe [2007-8-24 1083888]
S2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\roxio\digital home 10\RoxioUpnpService10.exe [2007-8-24 362992]
S2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\common files\roxio shared\10.0\sharedcom\RoxLiveShare10.exe [2007-8-24 309744]
S2 SessionLauncher;SessionLauncher; [x]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2007-8-31 179712]
S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\roxio\digital home 10\RoxioUPnPRenderer10.exe [2007-8-24 72176]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\pcpitstop\PCPitstopScheduleService.exe [2009-6-15 77312]
============== File Associations ===============
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
=============== Created Last 30 ================
2009-06-18 14:36 410,984 a——- c:\windows\system32\deploytk.dll
2009-06-18 13:42 –d—– c:\users\mark\JavaRa
2009-06-18 13:41 –d—– c:\users\mark\New Folder
2009-06-18 01:20 –d—– c:\program files\Camfrog
2009-06-17 23:56 64,160 a——- c:\windows\system32\drivers\Lbd.sys
2009-06-16 01:15 428,544 a——- c:\windows\system32\EncDec.dll
2009-06-16 01:15 293,376 a——- c:\windows\system32\psisdecd.dll
2009-06-16 01:15 217,088 a——- c:\windows\system32\psisrndr.ax
2009-06-16 01:15 177,664 a——- c:\windows\system32\mpg2splt.ax
2009-06-16 01:15 80,896 a——- c:\windows\system32\MSNP.ax
2009-06-16 00:58 –d—– c:\users\mark\appdata\roaming\Malwarebytes
2009-06-16 00:30 –dsh— C:\$RECYCLE.BIN
2009-06-15 23:50 161,792 a——- c:\windows\SWREG.exe
2009-06-15 23:50 155,136 a——- c:\windows\PEV.exe
2009-06-15 23:50 98,816 a——- c:\windows\sed.exe
2009-06-15 23:50 –ds—- C:\Combo-Fix
2009-06-15 00:41 335 a——- C:\spyhunter.fix
2009-06-15 00:41 –d—– c:\program files\Enigma Software Group
2009-06-14 23:56 40,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-14 23:56 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-06-14 23:56 –d—– c:\programdata\Malwarebytes
2009-06-14 23:56 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-06-14 23:56 –d—– c:\progra~2\Malwarebytes
2009-06-14 23:24 –d—– c:\program files\Eusing Free Registry Cleaner
2009-06-14 21:47 15,688 a——- c:\windows\system32\lsdelete.exe
2009-06-14 21:39 -cd-h— c:\programdata\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-14 21:39 -cd-h— c:\progra~2\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-14 21:39 –d—– c:\program files\Lavasoft
2009-06-14 20:49 –d—– c:\users\mark\appdata\roaming\SUPERAntiSpyware.com
2009-06-14 20:49 –d—– c:\program files\SUPERAntiSpyware
2009-06-14 19:47 199,829,553 a——- c:\windows\MEMORY.DMP
2009-06-14 16:55 –d—– c:\program files\common files\Wise Installation Wizard
2009-06-14 04:33 –d—– c:\program files\common files\Uninstall
2009-06-14 03:34 –d—– c:\program files\Trend Micro
2009-06-14 01:20 –d—– c:\programdata\PCPitstop
2009-06-14 01:20 –d—– c:\progra~2\PCPitstop
2009-06-14 01:19 –d—– c:\program files\PCPitstop
2009-06-14 01:01 –d—– c:\programdata\Lavasoft
2009-06-13 17:13 –d—– c:\program files\uTorrent
2009-06-13 17:11 –d—– c:\users\mark\appdata\roaming\uTorrent
2009-06-10 02:13 2,033,152 a——- c:\windows\system32\win32k.sys
2009-06-10 02:01 784,896 a——- c:\windows\system32\rpcrt4.dll
2009-05-27 21:59 –d—– c:\users\mark\appdata\roaming\Camfrog
2009-05-25 19:20 –d—– c:\programdata\NCH Software
2009-05-25 19:19 –d—– c:\users\mark\appdata\roaming\NCH Software
2009-05-25 19:19 –d—– c:\program files\NCH Software
2009-05-24 22:21 –d-h— C:\$AVG8.VAULT$
2009-05-24 21:25 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-05-24 21:25 108,552 a——- c:\windows\system32\drivers\avgtdix.sys
2009-05-24 21:25 325,896 a——- c:\windows\system32\drivers\avgldx86.sys
2009-05-24 21:25 –d—– c:\windows\system32\drivers\Avg
2009-05-24 21:25 –d—– c:\programdata\avg8
2009-05-24 21:25 –d—– c:\program files\AVG
2009-05-24 21:25 –d—– c:\progra~2\avg8
2009-05-22 16:37 –d—– c:\users\mark\appdata\roaming\ooVoo Details
2009-05-22 02:27 –d—– c:\users\mark\appdata\roaming\Acer
==================== Find3M ====================
2009-05-23 22:18 5,850 a–sh— c:\windows\system32\KGyGaAvL.sys
2009-05-09 01:50 915,456 a——- c:\windows\system32\wininet.dll
2009-05-09 01:34 71,680 a——- c:\windows\system32\iesetup.dll
2009-04-23 08:42 636,928 a——- c:\windows\system32\localspl.dll
2009-03-12 21:17 143,360 a——- c:\windows\inf\infstrng.dat
2009-03-12 21:17 143,360 a——- c:\windows\inf\infstor.dat
2009-03-12 21:17 86,016 a——- c:\windows\inf\infpub.dat
2008-07-07 11:32 174 a–sh— c:\program files\desktop.ini
2008-07-02 14:32 665,600 a——- c:\windows\inf\drvindex.dat
2007-12-22 15:19 476,752 a——- c:\programdata\pswi_preloaded.exe
2007-12-22 15:19 476,752 a——- c:\progra~2\pswi_preloaded.exe
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2007-12-30 19:17 8 —shr– c:\windows\system32\58FCD56796.sys
2007-12-22 15:20 88 —shr– c:\windows\system32\6C1FC0BF72.sys
============= FINISH: 15:44:21.25 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-05-14.01)
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 02/12/2007 3:18:03 AM
System Uptime: 18/06/2009 1:18:38 PM (2 hours ago)
Motherboard: Acer | | Poyang
Processor: Intel® Core™2 Duo CPU T5250 @ 1.50GHz | uPGA-478 | 1500/166mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 112 GiB total, 65.334 GiB free.
D: is FIXED (NTFS) - 111 GiB total, 111.343 GiB free.
E: is CDROM ()
==== Disabled Device Manager Items =============
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft Tun Miniport Adapter
Device ID: ROOT\*TUNMP\0001
Manufacturer: Microsoft
Name: Teredo Tunneling Pseudo-Interface
PNP Device ID: ROOT\*TUNMP\0001
Service: tunmp
Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Broadcom NetLink ™ Gigabit Ethernet
Device ID: PCI\VEN_14E4&DEV_1693&SUBSYS_011E1025&REV_02\4&185174AE&0&00E2
Manufacturer: Broadcom
Name: Broadcom NetLink ™ Gigabit Ethernet
PNP Device ID: PCI\VEN_14E4&DEV_1693&SUBSYS_011E1025&REV_02\4&185174AE&0&00E2
Service: b57nd60x
Class GUID:
Description:
Device ID: ROOT\LEGACY_BEEP\XX_LONNYRJONES_XX
Manufacturer:
Name:
PNP Device ID: ROOT\LEGACY_BEEP\XX_LONNYRJONES_XX
Service: MSIVXserv.sys
==== System Restore Points ===================
RP618: 10/06/2009 3:00:17 AM - Windows Update
RP619: 13/06/2009 1:50:05 AM - Windows Update
RP620: 14/06/2009 3:00:34 AM - Restore Operation
RP621: 14/06/2009 3:06:15 AM - Restore Operation
RP622: 14/06/2009 9:52:17 AM - Restore Operation
RP630: 16/06/2009 1:32:46 AM - Windows Update
RP631: 16/06/2009 7:24:21 PM - Windows Update
RP632: 17/06/2009 3:00:12 AM - Windows Update
RP633: 18/06/2009 2:19:38 PM - Scheduled Checkpoint
RP634: 18/06/2009 2:35:39 PM - Installed Java™ 6 Update 14
RP635: 18/06/2009 2:56:14 PM - Windows Update
RP636: 18/06/2009 2:57:19 PM - Installed Adobe Reader 9.1.
==== Installed Programs ======================
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office system
Acer Assist
Acer Crystal Eye
Acer Crystal Eye webcam
Acer eAudio Management
Acer eDataSecurity Management
Acer eLock Management
Acer Empowering Technology
Acer eNet Management
Acer ePower Management
Acer ePresentation Management
Acer eSettings Management
Acer Mobility Center Plug-In
Acer Registration
Acer ScreenSaver
Ad-Aware
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Photoshop Elements 6.0
Adobe Reader 9.1.2
ALPS Touch Pad Driver
Apple Mobile Device Support
Apple Software Update
ArcSoft MediaConverter 2
µTorrent
Authentium AntiVirus SDK - 2
AutoUpdate
AVG Free 8.5
Bonjour
BroadCam
Camfrog Video Chat 5.3
CDDRV_Installer
Corel Paint Shop Pro Photo XI
CorelDRAW Graphics Suite X3
Debut Video Capture Software
DirectXInstallService
DivX Codec
DivX Converter
DivX Player
DivX Web Player
EMC 10 Content
eMusic Download Manager
EN
Eusing Free Registry Cleaner
FlashLynx Video Download Software
FontNav
Google Earth
Google Toolbar for Internet Explorer
HDAUDIO Soft Data Fax Modem with SmartCP
helptut
helpug
Intel® Graphics Media Accelerator Driver
Intel® Matrix Storage Manager
iTunes
Java™ 6 Update 14
Java™ 6 Update 7
KhalInstallWrapper
LightScribe 1.4.142.1
Luxor 2
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB929729)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Hybrid 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft WorldWide Telescope
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
NCH Toolbox
NTI Backup NOW! 4.7
NTI CD & DVD-Maker
ooVoo
Paradise 8
PC Pitstop Exterminate2 2.0
Photilla Photo Album Software
PowerProducer 3.72
Prism Video Converter
QuickTime
Realtek High Definition Audio Driver
Roxio Activation Module
Roxio BackOnTrack
Roxio Central Audio
Roxio Central Copy
Roxio Central Core
Roxio Central Data
Roxio Central Tools
Roxio CinePlayer
Roxio CinePlayer Decoder Pack
Roxio Disc Gallery
Roxio Easy Media Creator 10 Suite
Roxio File Backup
Roxio MediaShare
Roxio Update Manager
Safari
Security Update for 2007 Microsoft Office System (KB951550)
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB969679)
Security Update for Microsoft Office Excel 2007 (KB969682)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office Publisher 2007 (KB950114)
Security Update for Microsoft Office system 2007 (KB954326)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office Word 2007 (KB969604)
Security Update for Visio 2007 (KB947590)
SmartSound Quicktracks Plugin
Spelling Dictionaries Support For Adobe Reader 8
SUPERAntiSpyware Free Edition
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Outlook 2007 (KB969907)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (kb970012)
Update Manager
VBA
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Windows Live Mail
Windows Live Messenger
WinRAR archiver
XVID Codec Installation
Zuma Deluxe
Zuma Deluxe 1.0
==== Event Viewer Messages From Past Week ========
18/06/2009 2:58:19 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
18/06/2009 2:58:19 PM, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
18/06/2009 2:58:19 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
17/06/2009 11:56:49 PM, Error: Service Control Manager [7000] - The Lbd service failed to start due to the following error: The system cannot find the file specified.
16/06/2009 1:19:01 AM, Error: Service Control Manager [7030] - The Local System Utility service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
15/06/2009 5:16:12 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD
15/06/2009 2:34:07 AM, Error: EventLog [6008] - The previous system shutdown at 2:32:30 AM on 15/06/2009 was unexpected.
15/06/2009 11:50:57 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the PEVSystemStart service to connect.
15/06/2009 11:50:56 PM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
14/06/2009 9:53:15 PM, Error: EventLog [6008] - The previous system shutdown at 9:51:29 PM on 14/06/2009 was unexpected.
14/06/2009 9:01:17 PM, Error: EventLog [6008] - The previous system shutdown at 8:59:28 PM on 14/06/2009 was unexpected.
14/06/2009 8:58:28 PM, Error: EventLog [6008] - The previous system shutdown at 8:56:47 PM on 14/06/2009 was unexpected.
14/06/2009 8:53:47 PM, Error: EventLog [6008] - The previous system shutdown at 8:52:02 PM on 14/06/2009 was unexpected.
14/06/2009 8:51:02 PM, Error: EventLog [6008] - The previous system shutdown at 8:49:15 PM on 14/06/2009 was unexpected.
14/06/2009 7:47:56 PM, Error: EventLog [6008] - The previous system shutdown at 7:45:21 PM on 14/06/2009 was unexpected.
14/06/2009 5:40:17 PM, Error: EventLog [6008] - The previous system shutdown at 5:38:35 PM on 14/06/2009 was unexpected.
14/06/2009 5:39:56 PM, Error: ACPI [13] - : The embedded controller (EC) did not respond within the specified timeout period. This may indicate that there is an error in the EC hardware or firmware or that the BIOS is accessing the EC incorrectly. You should check with your computer manufacturer for an upgraded BIOS. In some situations, this error may cause the computer to function incorrectly.
14/06/2009 4:55:18 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
14/06/2009 4:10:58 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AvgTdiX
14/06/2009 3:01:51 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service RoxMediaDB10 with arguments "" in order to run the server: {14EFC14B-A5E8-4CC7-8E8F-2E46FA6A3878}
14/06/2009 2:51:02 PM, Error: EventLog [6008] - The previous system shutdown at 2:49:12 PM on 14/06/2009 was unexpected.
14/06/2009 2:21:19 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AvgLdx86 AvgMfx86 ElRawDisk spldr Wanarpv6
14/06/2009 2:21:19 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
14/06/2009 2:20:30 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
14/06/2009 2:20:27 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
14/06/2009 2:20:25 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
14/06/2009 2:20:18 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
14/06/2009 11:47:25 PM, Error: EventLog [6008] - The previous system shutdown at 11:46:08 PM on 14/06/2009 was unexpected.
14/06/2009 11:39:46 PM, Error: Service Control Manager [7031] - The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
14/06/2009 11:39:46 PM, Error: Service Control Manager [7024] - The Windows Search service terminated with service-specific error 2147749155 (0x80040D23).
14/06/2009 11:39:08 PM, Error: EventLog [6008] - The previous system shutdown at 11:37:19 PM on 14/06/2009 was unexpected.
14/06/2009 1:36:16 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D3DCB472-7261-43CE-924B-0704BD730D5F} to the user CAMPO-LAPTOP\Mark SID (S-1-5-21-3021740154-2341606432-4124999485-1008) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
14/06/2009 1:36:16 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {A47979D2-C419-11D9-A5B4-001185AD2B89} to the user CAMPO-LAPTOP\Mark SID (S-1-5-21-3021740154-2341606432-4124999485-1008) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
14/06/2009 1:36:16 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {375FF000-DD27-11D9-8F9C-0002B3988E81} to the user CAMPO-LAPTOP\Mark SID (S-1-5-21-3021740154-2341606432-4124999485-1008) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
14/06/2009 1:36:16 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {145B4335-FE2A-4927-A040-7C35AD3180EF} to the user CAMPO-LAPTOP\Mark SID (S-1-5-21-3021740154-2341606432-4124999485-1008) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
14/06/2009 1:03:44 AM, Error: Service Control Manager [7023] - The Secure Socket Tunneling Protocol Service service terminated with the following error: The RPC server is unavailable.
14/06/2009 1:03:44 AM, Error: Service Control Manager [7001] - The Remote Access Connection Manager service depends on the Secure Socket Tunneling Protocol Service service which failed to start because of the following error: The RPC server is unavailable.
14/06/2009 1:01:52 AM, Error: Service Control Manager [7030] - The Lavasoft Ad-Aware Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
13/06/2009 12:04:28 PM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.
11/06/2009 6:52:59 AM, Error: Service Control Manager [7000] - The SessionLauncher service failed to start due to the following error: The system cannot find the path specified.
11/06/2009 5:01:37 PM, Error: EventLog [6008] - The previous system shutdown at 7:08:44 AM on 11/06/2009 was unexpected.
==== End Of File ===========================
The laptop seems to be running OK. Alll major issues seem pretty much cleared up.
I so appreciate all you have done so far.
I will await my next instructions.
Thanks
Mark
CatByte
Hi,
no, you need both an antivirus and a firewall but now I don't see System Mechanic Professional 7 installed anymore - did you uninstall it?
I can recommend a free antivirus and a free firewall if you wish.
Three excellent free AntiVirus products are:
Avira AntiVir
Avast
AVG
set the one you choose to receive automatic updates so you are always as fully protected as possible from the newest virus threats.
If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.
NOTE: DO NOT install more than one anti-virus program as they will conflict, and provide less protection, not more.
Three excellent free firewalls are:
Comodo
Sunbelt Kerio
Sygate
NOTE: DO NOT install more than one firewall.
Note: If you choose Comodo - Please be careful with the installation of the Comodo program, it comes bundled with an adware toolbar which you need to de-select when you are going through the installation process. It's not a malicious program, but it may be a privacy risk and I don't think you want it on your system.
NEXT
P2P - I see you have P2P software utorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It may be contributing to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.
NEXT
While you are in Add / Remove programs locate Java™ 6 Update 7 and remove it. as its still showing as installed. (leave java 6 update 14 - that is the up to date version)
NEXT
Follow these steps to uninstall Combofix
[external image: Posted Image]
NEXT
Now to remove the rest of the tools that we have used in fixing your machine:
NEXT
Below I have included a number of recommendations for how to protect your computer against malware infections.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.
Thank you for your patience, and performing all of the procedures requested.
Please respond one last time so we can consider the thread resolved and close it, thank-you.
c:\program files\iolo\System Mechanic Professional 7\Personal Firewall\ioloFW.exe:iolo Firewall®
c:\program files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe:iolo AntiVirus® ? or do I need to delete one?
no, you need both an antivirus and a firewall but now I don't see System Mechanic Professional 7 installed anymore - did you uninstall it?
I can recommend a free antivirus and a free firewall if you wish.
Three excellent free AntiVirus products are:
Avira AntiVir
Avast
AVG
set the one you choose to receive automatic updates so you are always as fully protected as possible from the newest virus threats.
If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.
NOTE: DO NOT install more than one anti-virus program as they will conflict, and provide less protection, not more.
Three excellent free firewalls are:
Comodo
Sunbelt Kerio
Sygate
NOTE: DO NOT install more than one firewall.
Note: If you choose Comodo - Please be careful with the installation of the Comodo program, it comes bundled with an adware toolbar which you need to de-select when you are going through the installation process. It's not a malicious program, but it may be a privacy risk and I don't think you want it on your system.
NEXT
P2P - I see you have P2P software utorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It may be contributing to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.
NEXT
While you are in Add / Remove programs locate Java™ 6 Update 7 and remove it. as its still showing as installed. (leave java 6 update 14 - that is the up to date version)
NEXT
Follow these steps to uninstall Combofix
- Click START then RUN
- Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.
[external image: Posted Image]
NEXT
Now to remove the rest of the tools that we have used in fixing your machine:
- Make sure you have an Internet Connection.
- Download OTC to your desktop and run it
- A list of tool components used in the Cleanup of malware will be downloaded.
- If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
- Click Yes to begin the Cleanup process and remove these components, including this application.
- You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.
NEXT
Below I have included a number of recommendations for how to protect your computer against malware infections.
- Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.
- SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.
- SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.
- Make Internet Explorer more secure
- Click Start > Run
- Type Inetcpl.cpl & click OK
- Click on the Security tab
- Click Reset all zones to default level
- Make sure the Internet Zone is selected & Click Custom level
- In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
- Next Click OK, then Apply button and then OK to exit the Internet Properties page.
- ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
- MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.
WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:- Green to go
- Yellow for caution
- Red to stop
- Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
Here
If you choose to use Firefox, I highly recommend this add-on to keep your PC even more secure.
- NoScript - for blocking ads and other potential website attacks
- Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
- ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
- In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
Think Prevention.
PC Safety and Security–What Do I Need?.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.
Thank you for your patience, and performing all of the procedures requested.
Please respond one last time so we can consider the thread resolved and close it, thank-you.
tase2
Hi
I ran the OTC as directed but no
"•A list of tool components used in the Cleanup of malware will be downloaded" never showed up.
It went directly to the •Click Yes to begin the Cleanup process command.
So my desktop still looks like
[external image: Posted Image]
What do you think we should do?
Thanks
Mark
I ran the OTC as directed but no
"•A list of tool components used in the Cleanup of malware will be downloaded" never showed up.
It went directly to the •Click Yes to begin the Cleanup process command.
So my desktop still looks like
[external image: Posted Image]
What do you think we should do?
Thanks
Mark
CatByte
Use this tool instead:
Download ToolsCleaner2 to your desktop and run it ( by de A.Rothstein & Dj Quiou )
Download ToolsCleaner2 to your desktop and run it ( by de A.Rothstein & Dj Quiou )
- Click the Pt. Restauration button and press OK to the prompts.
- Click the Corbeille button and press OK to the prompt.
- Click the Fichiers temp button and press OK to the prompt.
- Click the Recherche button and let it run ( it may look like it freezes but let it continue )
- Once it is done click the Suppression button and let it remove anything it finds.
- Close the program
CatByte
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI