This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Browser redirected, can't open some programs, can&

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
i am new and i needed help with a problem i have. I have problems with my browser especially when i search in google and click a link and it gets redirected to other sites, this happens a lot. Another thing is that some of my programs like Ashampoo Winoptimizer doesn't open when i did work fine a while ago and i also have problems with my Windows Live Messenger when i try to log in i get in and see my contacts for a few seconds then it goes back to the log in screen this happens a few times before i finally get in and it stays. Also when i try to defragment i keep getting the error "Disk Defragmenter could not start".

Here is my HijackThis log file help would really be appreciated because this is a new computer i got a few weeks ago.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:55:02 PM, on 6/23/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\FlashGet\FlashGet.exe
C:\Program Files\Rainlendar2\Rainlendar2.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\foobar2000\foobar2000.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\WINDOWS\system32\dvmurl.dll
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MI1933~1\Office12\GRA8E1~1.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O4 - HKLM\..\Run: [StartupFaster] "C:\Program Files\Startup Faster\startuploader.exe" -run SFAURUN SFCURUN SFAUSTARTUP SFCUSTARTUP
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: StartupFaster
O4 - Global Startup: StartupFaster
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1238740728171
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MI1933~1\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd.dll,C:\PROGRA~1\Kaspersky Lab\Kaspersky Internet Security 2009\mzvkbd3.dll,C:\PROGRA~1\Kaspersky Lab\Kaspersky Internet Security 2009\adialhk.dll,C:\PROGRA~1\Kaspersky Lab\Kaspersky Internet Security 2009\kloehk.dll
O23 - Service: 1238303460 (.1238303460) - Unknown owner - C:\Documents and Settings\All Users\Application Data\Daniel Francis1238303460.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: Defragmentation-Service (DfSdkS) - mst software GmbH, Germany - C:\Program Files\Ashampoo\Ashampoo WinOptimizer 6\Dfsdks.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe

–
End of file - 6947 bytes

BTW i used the site "http://www.hijackthis.de" to analyze my log file before i posted and this file came up as being bad:
R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\WINDOWS\system32\dvmurl.dll
Does anyone know if this file should be deleted?
Hi, and :welcome:

BTW i used the site "http://www.hijackthis.de" to analyze my log file before i posted and this file came up as being bad:
R3 - URLSearchHook: DeviceVM Url Search Hook - {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\WINDOWS\system32\dvmurl.dll
Does anyone know if this file should be deleted?


One good reason not to use online scanners - that file is legit > http://en.wikipedia.org/wiki/DeviceVM and http://www.systemlookup.com/viewitem.php?l…&item=56906

Please do the following:


Please download DDS from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.


NEXT

Download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.
Thanks for the help and quick reply here is the DDS Log File - DDS (Ver_09-05-14.01) - NTFSx86 Run by [removed] at 19:57:32.84 on Wed 06/24/2009 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2475 [GMT 10:00] AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0} FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\FlashGet\FlashGet.exe svchost.exe C:\Program Files\Rainlendar2\Rainlendar2.exe C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\foobar2000\foobar2000.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\wscntfy.exe C:\Documents and Settings\Owner\Desktop\dds.scr ============== Pseudo HJT Report =============== uURLSearchHooks: DeviceVM Url Search Hook: {0063bf63-bfff-4b8f-9d26-4267df7f17dd} - c:\windows\system32\dvmurl.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: FGCatchUrl: {2f364306-aa45-47b5-9f9d-39a8b94e7ef7} - c:\program files\flashget\jccatch.dll BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2009\ievkbd.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\mi1933~1\office12\GRA8E1~1.DLL BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: FlashGet GetFlash Class: {f156768e-81ef-470c-9057-481ba8380dba} - c:\program files\flashget\getflash.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [StartupFaster] "c:\program files\startup faster\startuploader.exe" -run SFAURUN SFCURUN SFAUSTARTUP SFCUSTARTUP mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe" mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mPolicies-explorer: NoResolveTrack = 1 (0x1) IE: &Download All with FlashGet - c:\program files\flashget\jc_all.htm IE: &Download with FlashGet - c:\program files\flashget\jc_link.htm IE: Add to Banner Ad Blocker - c:\program files\kaspersky lab\kaspersky internet security 2009\ie_banner_deny.htm IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office12\EXCEL.EXE/3000 IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - c:\program files\flashget\FlashGet.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - {85E0B171-04FA-11D1-B7DA-00A0C90348D6} - c:\program files\kaspersky lab\kaspersky internet security 2009\SCIEPlgn.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mi1933~1\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1238740728171 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\mi1933~1\office12\GR99D3~1.DLL Notify: klogon - c:\windows\system32\klogon.dll AppInit_DLLs: c:\progra~1\kaspersky lab\kaspersky internet security 2009\mzvkbd.dll,c:\progra~1\kaspersky lab\kaspersky internet security 2009\mzvkbd3.dll,c:\progra~1\kaspersky lab\kaspersky internet security 2009\adialhk.dll,c:\progra~1\kaspersky lab\kaspersky internet security 2009\kloehk.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\mi1933~1\office12\GRA8E1~1.DLL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\8riyz6h1.default\ FF - prefs.js: browser.startup.homepage - www.google.com ============= SERVICES / DRIVERS =============== R0 kl1;Kl1;c:\windows\system32\drivers\kl1.sys [2008-7-21 121872] R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-1-29 33808] R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2009-6-18 226832] R2 AVP;Kaspersky Internet Security;c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe [2008-11-11 206088] R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\common files\nero\nero backitup 4\NBService.exe [2008-11-25 935208] R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [2008-3-13 26640] R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-4-30 24592] R3 UsbFltr;Razer Copperhead Driver;c:\windows\system32\drivers\copperhd.sys [2009-3-30 11596] S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys –> c:\windows\system32\drivers\Lbd.sys [?] S2 .1238303460;1238303460;c:\documents and settings\all users\application data\Daniel Francis1238303460.exe [2009-4-6 1232598] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-4-4 1684736] S3 DfSdkS;Defragmentation-Service;c:\program files\ashampoo\ashampoo winoptimizer 6\DfSdkS.exe [2009-6-11 410976] S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\owner\locals~1\temp\iyw9.tmp –> c:\docume~1\owner\locals~1\temp\IYW9.tmp [?] =============== Created Last 30 ================ 2009-06-23 20:10 –d—– c:\program files\Trend Micro 2009-06-18 16:47 105,395 a——- c:\windows\system32\drivers\klin.dat 2009-06-18 16:47 94,643 a——- c:\windows\system32\drivers\klick.dat 2009-06-18 16:47 –d—– c:\program files\Kaspersky Lab 2009-06-18 16:47 –d—– c:\docume~1\alluse~1\applic~1\Kaspersky Lab 2009-06-18 16:43 –d—– c:\docume~1\alluse~1\applic~1\Kaspersky Lab Setup Files 2009-06-18 16:39 –d—– C:\CLT 2009-06-18 16:39 –d—– C:\00000082 2009-06-11 17:59 33,632 a——- c:\windows\system32\DfSdkBt.exe 2009-06-08 17:32 –d—– c:\documents and settings\owner\.rainlendar2 2009-06-08 17:32 –d—– c:\program files\Rainlendar2 2009-06-04 16:11 –d—– c:\docume~1\owner\applic~1\Malwarebytes 2009-06-04 16:11 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-06-04 15:37 39,776 a——- c:\windows\system32\DfSdkBt64.exe 2009-06-04 15:37 –d—– c:\program files\Ashampoo ==================== Find3M ==================== 2009-06-18 17:01 33,808 a——- c:\windows\system32\drivers\klbg.sys 2009-05-21 16:44 16,608 a——- c:\windows\gdrv.sys 2009-05-08 01:32 345,600 a——- c:\windows\system32\localspl.dll 2009-04-29 14:56 827,392 a——- c:\windows\system32\wininet.dll 2009-04-29 14:55 78,336 a——- c:\windows\system32\ieencode.dll 2009-04-24 13:23 189,072 a——- c:\windows\system32\PnkBstrB.exe 2009-04-24 12:48 75,064 a——- c:\windows\system32\PnkBstrA.exe 2009-04-21 09:19 22,328 a——- c:\docume~1\owner\applic~1\PnkBstrK.sys 2009-04-17 22:26 1,847,168 a——- c:\windows\system32\win32k.sys 2009-04-16 01:12 1,232,598 a–shr– c:\docume~1\alluse~1\applic~1\Daniel Francis1238303460.exe 2009-04-16 00:51 585,216 a——- c:\windows\system32\rpcrt4.dll 2009-04-05 22:01 410,984 a——- c:\windows\system32\deploytk.dll 2009-04-03 16:58 76,487 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2009-03-29 15:08 21,640 a——- c:\windows\system32\emptyregdb.dat 2009-03-27 10:22 17,567,744 a——- c:\windows\RTHDCPL.EXE 2009-03-27 08:14 453,152 a——- c:\windows\system32\NVUNINST.EXE ============= FINISH: 19:59:17.59 ===============

Attachments:

Hi, Any luck with the GMER program? if you are having difficulty running it, please try it in safe mode. please make sure all other windows are closed and all your security programs are temporarily disabled
GMER Log File -

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-06-24 21:14:47
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

INT 0x62 ? 8AD9CBF8
INT 0x63 ? 8ABF4BF8
INT 0x82 ? 8AD9CBF8
INT 0x83 ? 8ABF4BF8
INT 0xB4 ? 8ABF4BF8

Code 8AA39560 ZwEnumerateKey
Code 8AA3A340 ZwFlushInstructionCache
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) FsRtlCheckLockForReadAccess
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab) IoIsOperationSynchronous
Code 8AA39306 IofCallDriver
Code 8AA3916E IofCompleteRequest

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!FsRtlCheckLockForReadAccess 804EAF84 5 Bytes JMP B6741626 \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab)
.text ntkrnlpa.exe!IofCallDriver 804EF1A6 5 Bytes JMP 8AA3930B
.text ntkrnlpa.exe!IofCompleteRequest 804EF236 5 Bytes JMP 8AA39173
.text ntkrnlpa.exe!IoIsOperationSynchronous 804EF912 5 Bytes JMP B67419E0 \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter fre_wnet_x86/Kaspersky Lab)
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 805B6812 5 Bytes JMP 8AA3A344
PAGE ntkrnlpa.exe!ZwEnumerateKey 80623FF0 4 Bytes JMP 8AA39564
? sphg.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload B8FB78AC 5 Bytes JMP 8ABF41D8

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\svchost.exe[120] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0066000A
.text C:\WINDOWS\Explorer.EXE[228] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00B7000A
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 010B000A
? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] C:\WINDOWS\system32\kernel32.dll time/date stamp mismatch;
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] USER32.dll!AlignRects + FFFA5598 7E412A78 4 Bytes [70, 11, 41, 6D] {JO 0x13; INC ECX; INSD }
.text C:\WINDOWS\system32\ctfmon.exe[352] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0100000A
.text C:\WINDOWS\system32\winlogon.exe[972] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0067000A
.text C:\WINDOWS\system32\services.exe[1020] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 003B000A
.text C:\Program Files\Rainlendar2\Rainlendar2.exe[1180] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00F3000A
? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] C:\WINDOWS\system32\kernel32.dll time/date stamp mismatch;
.text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] USER32.dll!AlignRects + FFFA5598 7E412A78 4 Bytes [70, 11, 41, 6D] {JO 0x13; INC ECX; INSD }
.text C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe[1764] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 008C000A
.text C:\WINDOWS\RTHDCPL.EXE[1924] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 01AC000A
.text C:\WINDOWS\system32\nvsvc32.exe[1972] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 006B000A
.text C:\Documents and Settings\Owner\Desktop\gmer.exe[2732] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 003B000A
.text C:\WINDOWS\system32\wscntfy.exe[3516] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00F7000A
.text …

—- Kernel IAT/EAT - GMER 1.0.15 —-

IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [B9EA9040] sphg.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [B9EA913C] sphg.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [B9EA90BE] sphg.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [B9EA97FC] sphg.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [B9EA96D2] sphg.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [B9EB9048] sphg.sys

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetModuleFileNameA] 016804A8
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] 016804D2
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] 016804FC
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] 01680526
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!FreeLibrary] 01680550
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 0168057A
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetErrorMode] 016805A4
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 016805CE
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetModuleFileNameW] 016805F8
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 01680622
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] 0168064C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!FreeLibrary] 01680676
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] 016806A0
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] 016806CA
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 016806F4
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] 0168071E
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] 01680748
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetModuleFileNameW] 01680772
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] 0168079C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!FreeLibrary] 016807C6
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 016807F0
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] 0168081A
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetModuleFileNameA] 01680844
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] 0168086E
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 01680898
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] 016808C2
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] 016808EC
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!FreeLibrary] 01680916
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetModuleFileNameW] 01680940
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 0168096A
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 01680994
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] 016809BE
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!FreeLibrary] 016809E8
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] 01680A12
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] 01680A3C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetErrorMode] 01680C34
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 01680C5E
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] 01680C88
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] 01680CB2
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!FreeLibrary] 01680CDC
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] 01680D06
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] 01680D30
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetModuleFileNameA] 01680D5A
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetModuleFileNameW] 01680D84
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 01680E02
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] 01680E2C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] 01680E56
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetModuleFileNameW] 01680E80
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetErrorMode] 01680EAA
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] 01680ED4
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] 01680EFE
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 01680F28
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!FreeLibrary] 01680F52
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] 01680F7C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 01680FA6
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetErrorMode] 01680FD0
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetModuleFileNameW] 016B0010
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] 016B003A
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 016B0064
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] 016B008E
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] 016B00B8
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] 016B00E2
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibrary] 016B010C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] 016B0136
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] 016B0160
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetModuleFileNameA] 016B018A
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] 016B01B4
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] 016B01DE
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FreeLibrary] 016B0208
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] 016B0232
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetModuleFileNameW] 016B025C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 016B0286
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] 016B02B0
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] 016B02DA
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 016B0304
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!SetErrorMode] 016B0A90
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetModuleFileNameA] 016B0ABA
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] 016B0AE4
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetModuleFileNameW] 016B0B0E
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 016B0B38
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 016B0B62
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetProcAddress] 016B0B8C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] 016B0BB6
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!FreeLibrary] 016B0BE0
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] 016C032E
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!FreeLibrary] 016C0358
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] 016C0382
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!SetUnhandledExceptionFilter] 016C03AC
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!SetErrorMode] 016C057A
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!LoadLibraryW] 016C05A4
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!LoadLibraryExA] 016C05CE
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!CreateProcessW] 016C05F8
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!GetModuleFileNameW] 016C0622
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!GetProcAddress] 016C064C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!FreeLibrary] 016C0676
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!LoadLibraryA] 016C06A0
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 016C06CA
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] 01680304
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 01680358
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] 01680286
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!FreeLibrary] 016801DE
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] 0168025C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetModuleFileNameA] 01680208
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] 0168025C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!GetModuleFileNameA] 01680208
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] 01680286
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!FreeLibrary] 016801DE
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 01680358
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!FreeLibrary] 016801DE
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 01680358
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] 01680286
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetModuleFileNameA] 01680208
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[336] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] 0168025C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetModuleFileNameA] 00D604A8
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] 00D604D2
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] 00D604FC
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] 00D60526
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!FreeLibrary] 00D60550
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00D6057A
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetErrorMode] 00D605A4
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] 00D605CE
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetModuleFileNameW] 00D605F8
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00D60622
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] 00D6064C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!FreeLibrary] 00D60676
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] 00D606A0
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] 00D606CA
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00D606F4
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] 00D6071E
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] 00D60748
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetModuleFileNameW] 00D60772
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] 00D6079C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!FreeLibrary] 00D607C6
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] 00D607F0
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CreateProcessW] 00D6081A
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetModuleFileNameA] 00D60844
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] 00D6086E
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00D60898
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] 00D608C2
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] 00D608EC
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!FreeLibrary] 00D60916
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetModuleFileNameW] 00D60940
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00D6096A
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] 00D60994
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] 00D609BE
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!FreeLibrary] 00D609E8
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] 00D60A12
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] 00D60A3C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetErrorMode] 00D60C34
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00D60C5E
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] 00D60C88
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] 00D60CB2
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!FreeLibrary] 00D60CDC
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessA] 00D60D06
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateProcessW] 00D60D30
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetModuleFileNameA] 00D60D5A
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetModuleFileNameW] 00D60D84
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00D60E02
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] 00D60E2C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CreateProcessW] 00D60E56
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetModuleFileNameW] 00D60E80
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetErrorMode] 00D60EAA
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] 00D60ED4
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] 00D60EFE
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] 00D60F28
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!FreeLibrary] 00D60F52
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] 00D60F7C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00D60FA6
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetErrorMode] 00D60FD0
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetModuleFileNameW] 00DA0010
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] 00DA003A
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] 00DA0064
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] 00DA008E
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessA] 00DA00B8
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateProcessW] 00DA00E2
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibrary] 00DA010C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] 00DA0136
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] 00DA0160
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetModuleFileNameA] 00DA018A
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] 00DA01B4
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] 00DA01DE
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!FreeLibrary] 00DA0208
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] 00DA0232
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetModuleFileNameW] 00DA025C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 00DA0286
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExA] 00DA02B0
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateProcessW] 00DA02DA
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00DA0304
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!SetErrorMode] 00DA0A90
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetModuleFileNameA] 00DA0ABA
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] 00DA0AE4
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetModuleFileNameW] 00DA0B0E
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] 00DA0B38
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00DA0B62
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetProcAddress] 00DA0B8C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] 00DA0BB6
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!FreeLibrary] 00DA0BE0
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!LoadLibraryA] 00DB010C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!FreeLibrary] 00DB0136
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] 00DB0160
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!SetUnhandledExceptionFilter] 00DB018A
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!SetErrorMode] 00DB0358
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!LoadLibraryW] 00DB0382
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!LoadLibraryExA] 00DB03AC
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!CreateProcessW] 00DB03D6
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!GetModuleFileNameW] 00DB0400
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!GetProcAddress] 00DB042A
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!FreeLibrary] 00DB0454
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!LoadLibraryA] 00DB047E
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00DB04A8
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryW] 00D60304
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00D60358
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!LoadLibraryA] 00D60286
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!FreeLibrary] 00D601DE
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] 00D6025C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetModuleFileNameA] 00D60208
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] 00D6025C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!GetModuleFileNameA] 00D60208
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] 00D60286
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!FreeLibrary] 00D601DE
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00D60358
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!FreeLibrary] 00D601DE
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00D60358
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] 00D60286
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetModuleFileNameA] 00D60208
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] 00D6025C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00D60358
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!FreeLibrary] 00D601DE
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] 00D6025C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!LoadLibraryA] 00D60286
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!FreeLibrary] 00D601DE
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] 00D6025C
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryA] 00D60286
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00D60358
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExA] 00D602B0
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!LoadLibraryExW] 00D602DA
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetModuleFileNameW] 00D60232
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetModuleFileNameA] 00D60208
IAT C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe[1552] @ C:\WINDOWS\system32\SAMLIB.dll [KERNEL32.dll!SetUnhandledExceptionFilter] 00D60358

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 8AD9B1F8
Device \Driver\PCI_PNP7722 \Device\00000040 sphg.sys
Device \Driver\NetBT \Device\NetBT_Tcpip_{96CBF330-21B9-4DB4-8D27-13DD2E7A4D5F} 8A7D24D8
Device \Driver\usbuhci \Device\USBPDO-0 8ABF31F8
Device \Driver\usbuhci \Device\USBPDO-1 8ABF31F8
Device \Driver\usbuhci \Device\USBPDO-2 8ABF31F8
Device \Driver\usbuhci \Device\USBPDO-3 8ABF31F8
Device \Driver\usbehci \Device\USBPDO-4 8ABC61F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 8AE0D1F8
Device \Driver\Cdrom \Device\CdRom0 8AB9E1F8
Device \Driver\sptd \Device\288091472 sphg.sys
Device \Driver\NetBT \Device\NetBt_Wins_Export 8A7D24D8
Device \Driver\NetBT \Device\NetbiosSmb 8A7D24D8
Device \Driver\usbuhci \Device\USBFDO-0 8ABF31F8
Device \Driver\usbuhci \Device\USBFDO-1 8ABF31F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 89F9B500
Device \Driver\usbuhci \Device\USBFDO-2 8ABF31F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 89F9B500
Device \Driver\usbuhci \Device\USBFDO-3 8ABF31F8
Device \Driver\usbehci \Device\USBFDO-4 8ABC61F8
Device \Driver\Ftdisk \Device\FtControl 8AE0D1F8
Device \Driver\amsfqlcp \Device\Scsi\amsfqlcp1 8AB701F8
Device \Driver\amsfqlcp \Device\Scsi\amsfqlcp1Port2Path0Target0Lun0 8AB701F8
Device \FileSystem\Cdfs \Cdfs 8A0C5500

—- Services - GMER 1.0.15 —-

Service C:\WINDOWS\system32\drivers\SKYNETkwkopxmy.sys (*** hidden *** ) [SYSTEM] SKYNETvkiqlrxh <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvkiqlrxh
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvkiqlrxh@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvkiqlrxh@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvkiqlrxh@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvkiqlrxh@imagepath \systemroot\system32\drivers\SKYNETkwkopxmy.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvkiqlrxh\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvkiqlrxh\main@aid 10010
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvkiqlrxh\main@sid 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvkiqlrxh\main@cmddelay 7200
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvkiqlrxh\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvkiqlrxh\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvkiqlrxh\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvkiqlrxh\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvkiqlrxh\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvkiqlrxh\[removed] \systemroot\system32\drivers\SKYNETkwkopxmy.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvkiqlrxh\[removed] \systemroot\system32\SKYNETqolemxfq.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvkiqlrxh\[removed] \systemroot\system32\SKYNEThbbolnsf.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvkiqlrxh\[removed] \systemroot\system32\SKYNETtrwpbipj.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvkiqlrxh\[removed] \systemroot\system32\SKYNETbgclovrp.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xED 0xBC 0x96 0xAB …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x59 0x89 0x81 0x9C …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x64 0x7F 0x0D 0xFD …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x03 0x1A 0x41 0x23 …
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETvkiqlrxh
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETvkiqlrxh@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETvkiqlrxh@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETvkiqlrxh@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETvkiqlrxh@imagepath \systemroot\system32\drivers\SKYNETkwkopxmy.sys
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETvkiqlrxh\main
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETvkiqlrxh\main@aid 10010
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETvkiqlrxh\main@sid 0
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETvkiqlrxh\main@cmddelay 7200
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETvkiqlrxh\main\delete
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETvkiqlrxh\main\injector
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETvkiqlrxh\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETvkiqlrxh\main\tasks
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETvkiqlrxh\modules
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETvkiqlrxh\[removed] \systemroot\system32\drivers\SKYNETkwkopxmy.sys
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETvkiqlrxh\[removed] \systemroot\system32\SKYNETqolemxfq.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETvkiqlrxh\[removed] \systemroot\system32\SKYNEThbbolnsf.dat
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETvkiqlrxh\[removed] \systemroot\system32\SKYNETtrwpbipj.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETvkiqlrxh\[removed] \systemroot\system32\SKYNETbgclovrp.dat
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Pro\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xF3 0xB9 0x94 0x5A …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x59 0x89 0x81 0x9C …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x64 0x7F 0x0D 0xFD …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x03 0x1A 0x41 0x23 …

—- EOF - GMER 1.0.15 —-
Hi,

please do the following:

Note: It is very important to disable all your security programs before running Combo-Fix

If Combo-Fix will not run in normal mode - please try it in safe mode

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2
Link 3

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–

Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt back into this thread.
Combo-Fix Log File -

ComboFix 09-06-23.01 - Owner 06/25/2009 15:30.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2728 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\kl1.sys
c:\windows\system32\drivers\SKYNETkwkopxmy.sys
c:\windows\system32\SKYNETbgclovrp.dat
c:\windows\system32\SKYNEThbbolnsf.dat
c:\windows\system32\SKYNETqolemxfq.dll
c:\windows\system32\SKYNETtrwpbipj.dll
c:\windows\system32\drivers\SKYNETkwkopxmy.sys
c:\windows\system32\SKYNETbgclovrp.dat
c:\windows\system32\SKYNEThbbolnsf.dat
c:\windows\system32\SKYNETqolemxfq.dll
c:\windows\system32\SKYNETtrwpbipj.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_SKYNETvkiqlrxh


((((((((((((((((((((((((( Files Created from 2009-05-25 to 2009-06-25 )))))))))))))))))))))))))))))))
.

2009-06-25 05:30 . 2009-06-25 05:33 90144 –sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-25 05:30 . 2009-06-25 05:33 32 –sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-23 10:10 . 2009-06-23 10:10 ——– d—–w- c:\program files\Trend Micro
2009-06-18 07:00 . 2009-06-18 07:00 206088 —-a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\avp.exe
2009-06-18 07:00 . 2009-06-18 07:00 33808 —-a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\klbg.sys
2009-06-18 07:00 . 2009-06-18 07:00 226832 —-a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP8\Data\Updater\Temporary Files\temporaryFolder\AutoPatches\kav8exec\8.0.0.506\XP\klif.sys
2009-06-18 06:47 . 2009-06-18 07:01 94643 —-a-w- c:\windows\system32\drivers\klick.dat
2009-06-18 06:47 . 2009-06-18 07:01 105395 —-a-w- c:\windows\system32\drivers\klin.dat
2009-06-18 06:47 . 2009-06-25 05:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-06-18 06:47 . 2009-06-18 06:47 ——– d—–w- c:\program files\Kaspersky Lab
2009-06-18 06:43 . 2009-06-18 06:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-06-18 06:39 . 2009-06-18 06:39 ——– d—–w- C:\CLT
2009-06-18 06:39 . 2009-06-18 06:39 ——– d—–w- C:\00000082
2009-06-14 00:30 . 2008-12-03 15:25 120832 -c–a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\8riyz6h1.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}\plugins\npietab.dll
2009-06-11 07:59 . 2009-01-09 02:46 33632 —-a-w- c:\windows\system32\DfSdkBt.exe
2009-06-09 11:25 . 2009-06-09 11:25 ——– d—–w- c:\documents and settings\Default User\Local Settings\Application Data\Microsoft Help
2009-06-09 05:55 . 2009-06-09 05:55 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Symantec
2009-06-08 07:32 . 2009-06-25 05:35 ——– d—–w- c:\documents and settings\Owner\.rainlendar2
2009-06-08 07:32 . 2009-06-08 07:32 ——– d—–w- c:\program files\Rainlendar2
2009-06-05 05:15 . 2009-06-05 05:15 1914000 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe
2009-06-05 05:15 . 2009-06-05 22:09 ——– d—–w- c:\program files\NOS
2009-06-04 06:11 . 2009-06-04 06:11 ——– d—–w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-06-04 06:11 . 2009-06-04 06:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-04 05:37 . 2009-01-09 02:46 39776 —-a-w- c:\windows\system32\DfSdkBt64.exe
2009-06-04 05:37 . 2009-06-04 05:37 ——– d—–w- c:\program files\Ashampoo

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2089-12-01 08:48 . 2009-04-05 14:21 796016 —-a-w- C:\cltLMSx.dll
2009-06-25 05:35 . 2009-06-25 05:30 1444 –sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-25 05:34 . 2009-04-04 02:46 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-25 05:33 . 2009-06-25 05:30 32 –sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-25 05:28 . 2009-03-29 23:41 ——– d—–w- c:\program files\FlashGet
2009-06-24 10:04 . 2009-04-05 10:41 ——– d—–w- c:\documents and settings\Owner\Application Data\foobar2000
2009-06-21 11:38 . 2009-04-05 12:30 ——– d—–w- c:\documents and settings\Owner\Application Data\LimeWire
2009-06-19 06:28 . 2008-04-09 06:39 ——– d—–w- c:\program files\Steam
2009-06-18 07:01 . 2008-01-29 07:29 33808 —-a-w- c:\windows\system32\drivers\klbg.sys
2009-06-18 06:41 . 2009-04-03 07:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-18 06:37 . 2009-04-03 07:15 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2009-06-17 07:47 . 2009-04-03 07:20 ——– d—–w- c:\documents and settings\Owner\Application Data\uTorrent
2009-06-10 11:20 . 2009-05-07 07:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-05 22:09 . 2008-04-09 23:16 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-06-04 23:32 . 2009-04-05 10:23 ——– d—–w- c:\program files\Advanced System Optimizer
2009-05-24 03:34 . 2009-05-24 03:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-05-21 10:01 . 2009-03-30 00:17 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-05-21 07:09 . 2009-05-21 07:09 ——– d—–w- c:\program files\DIFX
2009-05-21 06:44 . 2009-03-30 08:05 16608 —-a-w- c:\windows\gdrv.sys
2009-05-08 08:56 . 2009-03-30 02:20 ——– d—–w- c:\program files\Common Files\InstallShield
2009-05-07 15:32 . 2004-08-04 12:00 345600 —-a-w- c:\windows\system32\localspl.dll
2009-05-07 11:09 . 2009-03-30 08:05 70024 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-07 08:01 . 2009-05-07 08:01 ——– d—–w- c:\program files\Microsoft Works
2009-05-07 08:01 . 2009-05-07 08:01 ——– d—–w- c:\program files\MSBuild
2009-05-04 11:15 . 2009-05-04 11:15 ——– d—–w- c:\program files\MSXML 4.0
2009-05-03 09:58 . 2009-05-03 09:58 ——– d—–w- c:\program files\GNU
2009-05-03 09:55 . 2009-05-03 09:55 ——– d—–w- c:\documents and settings\Owner\Application Data\GRETECH
2009-05-03 09:54 . 2009-05-03 09:54 ——– d—–w- c:\program files\GRETECH
2009-05-03 08:36 . 2009-05-03 08:36 ——– d—–w- c:\program files\dayam NFO Viewer
2009-05-03 08:22 . 2009-05-03 08:22 ——– d—–w- c:\documents and settings\Owner\Application Data\Nero
2009-05-03 08:18 . 2009-05-03 07:56 ——– d—–w- c:\program files\Common Files\Nero
2009-05-03 08:07 . 2009-05-03 07:56 ——– d—–w- c:\program files\Nero
2009-05-03 08:01 . 2009-05-03 07:56 ——– d—–w- c:\documents and settings\All Users\Application Data\Nero
2009-05-03 06:16 . 2009-05-03 06:16 ——– d—–w- c:\program files\Eidos
2009-05-03 04:26 . 2009-05-03 04:26 ——– d—–w- c:\program files\Activision
2009-04-29 04:56 . 2004-08-04 12:00 827392 —-a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-04 12:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-04-28 09:46 . 2009-04-28 09:46 ——– d—–w- c:\documents and settings\Owner\Application Data\SanDisk
2009-04-28 07:48 . 2009-04-05 10:34 ——– d—–w- c:\program files\UltraISO
2009-04-24 03:23 . 2009-04-20 23:19 189072 —-a-w- c:\windows\system32\PnkBstrB.exe
2009-04-24 02:55 . 2009-04-20 23:19 138920 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-04-24 02:48 . 2009-04-20 23:18 75064 —-a-w- c:\windows\system32\PnkBstrA.exe
2009-04-20 23:19 . 2009-04-20 23:19 22328 —-a-w- c:\documents and settings\Owner\Application Data\PnkBstrK.sys
2009-04-20 23:19 . 2009-04-20 23:19 22328 —-a-w- c:\documents and settings\Owner\Application Data\PnkBstrK.sys
2009-04-17 12:26 . 2004-08-04 12:00 1847168 —-a-w- c:\windows\system32\win32k.sys
2009-04-15 15:12 . 2009-04-05 14:44 1232598 –sha-r- c:\documents and settings\All Users\Application Data\Daniel Francis1238303460.exe
2009-04-15 15:12 . 2009-04-05 14:44 1232598 –sha-r- c:\documents and settings\All Users\Application Data\Daniel Francis1238303460.exe
2009-04-15 14:51 . 2004-08-04 12:00 585216 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-05 12:01 . 2009-04-05 12:01 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-04-05 12:01 . 2009-04-05 12:01 152576 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_11\lzma.dll
2009-04-03 06:58 . 2009-03-29 05:09 76487 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-03 06:20 . 2009-04-03 06:20 167376 —-a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\8riyz6h1.default\FlashGot.exe
2009-03-30 06:13 . 2009-04-03 08:00 5063168 —-a-w- c:\windows\system32\drivers\RtkHDAud.sys
2009-03-29 05:38 . 2009-03-29 05:38 0 —-a-w- c:\windows\nsreg.dat
2009-03-29 05:08 . 2009-03-29 05:08 21640 —-a-w- c:\windows\system32\emptyregdb.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartupFaster"="c:\program files\Startup Faster\startuploader.exe" [2008-09-07 1402080]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-06-18 206088]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-27 13684736]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Games\\Gears of War\\Binaries\\WarGame-G4WLive.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [1/29/2008 5:29 PM 33808]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [3/13/2008 6:02 PM 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [4/30/2008 5:06 PM 24592]
R3 UsbFltr;Razer Copperhead Driver;c:\windows\system32\drivers\copperhd.sys [3/30/2009 10:38 AM 11596]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys –> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 .1238303460;1238303460;c:\documents and settings\All Users\Application Data\Daniel Francis1238303460.exe [4/6/2009 12:44 AM 1232598]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [4/4/2009 1:44 PM 1684736]
S3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 6\DfSdkS.exe [6/11/2009 5:59 PM 410976]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\Owner\LOCALS~1\Temp\IYW9.tmp –> c:\docume~1\Owner\LOCALS~1\Temp\IYW9.tmp [?]
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
IE: &Download; All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download; with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: Add to Banner Ad Blocker - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-25 15:35
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\Owner\LOCALS~1\Temp\IYW9.tmp"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\MSSYCLM]
@Denied: (B C D 1 2 3 4 5 6) (LocalSystem)

[HKEY_LOCAL_MACHINE\software\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NUM]
@Denied: (A C D 2 5) (LocalSystem)
"LastCompletedRun"=hex(B):00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\eeCtrl]
@Denied: (Full) (LocalSystem)
"Start"=dword:00000003

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EraserUtilDrv10910]
@Denied: (Full) (LocalSystem)

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EraserUtilRebootDrv]
@Denied: (Full) (LocalSystem)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3792)
c:\program files\FlashGet\fgmgr.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\program files\FlashGet\flashget.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Rainlendar2\Rainlendar2.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
.
**************************************************************************
.
Completion time: 2009-06-25 15:36 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-25 05:36

Pre-Run: 406,816,391,168 bytes free
Post-Run: 408,531,177,472 bytes free

211 — E O F — 2009-06-10 11:20
Hi,

Please do the following:

I would like you to upload a file to be scanned
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


    c:\documents and settings\All Users\Application Data\Daniel Francis1238303460.exe

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.


Do the same for the following file:


c:\docume~1\Owner\LOCALS~1\Temp\IYW9.tmp




NEXT


Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :dir
    C:\00000082 /s
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
When i tried the viruscan.org link I was getting a "Internet Explorer cannot display the webpage" and i tried it in firefox just to check and i got a "Page Load Error" so i couldn't go the the viruscan.org link but here is the systemLook Log File - SystemLook v1.0 by jpshortstuff (22.05.09) Log created at 20:50 on 25/06/2009 by Owner (Administrator - Elevation successful) ========== dir ========== C:\00000082 - Parameters: "/s" —Files— None found. C:\00000082\000000fb d—– [06:39 18/06/2009] C:\00000082\000000fb\000002c4 d—– [06:39 18/06/2009] cltLMS1.dat –a— 5548 bytes [14:23 05/04/2009] [04:04 01/10/2025] cltLMS2.dat –a— 5548 bytes [14:23 05/04/2009] [04:03 01/10/2025] -=End Of File=-
Hi,

try scanning those files at this site instead:



before you do that, lets clean out all of your temporary internet files and cache…

Please download ATF Cleaner by Atribune.

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.


NEXT

Please go to Virus Total
  • Copy paste the following full path into the empty box under 'Upload a file'

    c:\documents and settings\All Users\Application Data\Daniel Francis1238303460.exe

  • Click 'Send File'
Copy/paste the results into Notepad and save it to your desktop. Please post the results in your next reply.

Do the same for this one:


c:\docume~1\Owner\LOCALS~1\Temp\IYW9.tmp

Here is the log for c:\documents and settings\All Users\Application Data\Daniel Francis1238303460.exe - File Daniel_Francis1238303460.exe received on 2009.06.25 11:17:10 (UTC) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 4/40 (10%) Loading server information… Your file is queued in position: 1. Estimated start time is between 43 and 62 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Compact Print results Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result a-squared 4.5.0.18 2009.06.25 Trojan.Win32.StartPage.drb!A2 AhnLab-V3 5.0.0.2 2009.06.25 - AntiVir 7.9.0.196 2009.06.25 Worm/Sohanat.AB Antiy-AVL 2.0.3.1 2009.06.25 - Authentium 5.1.2.4 2009.06.24 - Avast 4.8.1335.0 2009.06.24 - AVG 8.5.0.339 2009.06.24 Generic_c.AKLA BitDefender 7.2 2009.06.25 - CAT-QuickHeal 10.00 2009.06.25 - ClamAV 0.94.1 2009.06.25 - Comodo 1407 2009.06.25 - DrWeb 5.0.0.12182 2009.06.24 - eSafe 7.0.17.0 2009.06.24 Suspicious File eTrust-Vet 31.6.6577 2009.06.24 - F-Prot 4.4.4.56 2009.06.24 - F-Secure 8.0.14470.0 2009.06.25 - Fortinet 3.117.0.0 2009.06.24 - GData 19 2009.06.25 - Ikarus T3.1.1.59.0 2009.06.25 - Jiangmin 11.0.706 2009.06.25 - K7AntiVirus 7.10.768 2009.06.19 - Kaspersky 7.0.0.125 2009.06.25 - McAfee 5656 2009.06.24 - McAfee+Artemis 5656 2009.06.24 - McAfee-GW-Edition 6.7.6 2009.06.25 - Microsoft 1.4803 2009.06.25 - NOD32 4186 2009.06.25 - Norman 6.01.09 2009.06.24 - nProtect 2009.1.8.0 2009.06.25 - Panda 10.0.0.16 2009.06.24 - Prevx 3.0 2009.06.25 - Rising 21.35.31.00 2009.06.25 - Sophos 4.43.0 2009.06.25 - Sunbelt 3.2.1858.2 2009.06.25 - Symantec 1.4.4.12 2009.06.25 - TheHacker 6.3.4.3.353 2009.06.24 - TrendMicro 8.950.0.1094 2009.06.25 - VBA32 3.12.10.7 2009.06.25 - ViRobot 2009.6.25.1803 2009.06.25 - VirusBuster 4.6.5.0 2009.06.24 - Additional information File size: 1232598 bytes MD5…: 57328afdff4ec706ac413a33cea40ee6 SHA1..: 4a36d3a53b5e43e60dcd94d8a32c760d464ed91c SHA256: 4acd2adf5c4f4bf29aa2dcd1d973ec748fc7cc6cee9d9d1e41e405ec586cf207 ssdeep: 24576:ftARYKeraBgg7q3X1exabVNDhFSRtmsMyRMR1lN:ftARYK2ayX1KkVN4tI jN PEiD..: UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser TrID..: File type identification UPX compressed Win32 Executable (43.8%) Win32 EXE Yoda's Crypter (38.1%) Win32 Executable Generic (12.2%) Generic Win/DOS Executable (2.8%) DOS Executable Generic (2.8%) PEInfo: PE Structure information ( base data ) entrypointaddress.: 0xaf1e0 timedatestamp…..: 0x4951fa17 (Wed Dec 24 09:00:07 2008) machinetype…….: 0x14c (I386) ( 3 sections ) name viradd virsiz rawdsiz ntrpy md5 UPX0 0x1000 0x6f000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e UPX1 0x70000 0x40000 0x3f400 7.93 5c049c3f212fd5833e6c6ba5e4dd45cb .rsrc 0xb0000 0x8000 0x7c00 4.74 d8323f69401cb696cf6753619c0bbe4c ( 16 imports ) > KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess > ADVAPI32.dll: AddAce > COMCTL32.dll: ImageList_Remove > COMDLG32.dll: GetSaveFileNameW > GDI32.dll: BitBlt > MPR.dll: WNetGetConnectionW > ole32.dll: CoInitialize > OLEAUT32.dll: - > PSAPI.DLL: EnumProcesses > SHELL32.dll: DragFinish > USER32.dll: GetDC > USERENV.dll: LoadUserProfileW > VERSION.dll: VerQueryValueW > WININET.dll: FtpOpenFileW > WINMM.dll: timeGetTime > WSOCK32.dll: - ( 0 exports ) PDFiD.: - RDS…: NSRL Reference Data Set - packers (Kaspersky): PE_Patch.UPX, UPX, PE_Patch packers (F-Prot): UPX Can't do the other file right now ill have to post it later.
Hi,

Thats fine, it's in a TEMP directory so It was probably cleaned out already.

Lets get rid of the one file then before we move on.

Please do the following:

Go Start > Run and copy/paste the following single-line command into the Run box and click OK:

cmd /c del /f/a/q "c:\documents and settings\All Users\Application Data\Daniel Francis1238303460.exe"



NEXT


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Malwarebytes Log File - Malwarebytes' Anti-Malware 1.38 Database version: 2340 Windows 5.1.2600 Service Pack 3 6/27/2009 11:12:47 AM mbam-log-2009-06-27 (11-12-47).txt Scan type: Quick Scan Objects scanned: 82718 Time elapsed: 2 minute(s), 37 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
When i tried the kaspersky online scanner the first time i got this error - Program has failed to start. Program has failed to start. Close the Kaspersky Online Scanner 7.0 window and open it again to install the program. [ERROR: java.lang.RuntimeException: You cannot run Kaspersky Online Scanner 7.0 because you already have Kaspersky Internet Security 8.0 (9.0) installed on the computer.] So i will try it again.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI