This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Experiencing Computer Slow down

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey all, been a while since i last posted but My computer is acting quite strange.

I ran SS&D and found

Virtumonde.sdn
Microsoft.WindowsSecurityCenter.AntiVirusOverride
Microsoft.WindowsSecurityCenter.FirewallOverride
Virtumonde
Virtumonde.prx


I was able to fix all of the above problems however I am still concerned about more problems what should I do???
Here is my Hijack This log please help me as any assistance would be greatly appreciated.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:35:12 AM, on 7/14/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\Explorer.EXE
G:\WINDOWS\RTHDCPL.EXE
G:\WINDOWS\system32\RUNDLL32.EXE
G:\WINDOWS\system32\ctfmon.exe
G:\Program Files\Common Files\Apple\Mobile Device

Support\bin\AppleMobileDeviceService.exe
G:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
G:\Program Files\Java\jre6\bin\jqs.exe
G:\Program Files\Marvell\61xx\Apache2\bin\Apache.exe
G:\WINDOWS\system32\nvsvc32.exe
G:\Program Files\Viewpoint\Common\ViewpointService.exe
G:\Program Files\Marvell\61xx\Apache2\bin\Apache.exe
G:\Program Files\Marvell\61xx\svc\mvraidsvc.exe
G:\Program Files\Marvell\61xx\tray\zRaidTray.exe
G:\Program Files\Mozilla Firefox\firefox.exe
G:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
G:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no

file)
O1 - Hosts: 195.245.119.131 browser-security.microsoft.com
O2 - BHO: Adobe PDF Reader Link Helper -

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C}

- G:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} -

G:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} -

G:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java™ Plug-In SSV Helper -

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - G:\Program

Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO -

{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - G:\Program

Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: (no name) - {b12c2a62-4c71-4f9d-b531-9690db1be910} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper -

{DBC80044-A445-435b-BC74-9C25C1C588A9} - G:\Program

Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} -

G:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} -

G:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} -

G:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] "RTHDCPL.EXE"
O4 - HKLM\..\Run: [Alcmtr] "ALCMTR.EXE"
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] "KHALMNPR.EXE"
O4 - HKLM\..\Run: [NeroFilterCheck] "G:\WINDOWS\system32\NeroCheck.exe"
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE"

G:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE"

G:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "G:\Program Files\QuickTime\qttask.exe"

-atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] "%systemroot%\system32\dumprep" 0 -k
O4 - HKLM\..\Run: [BDAgent] "G:\Program Files\BitDefender\BitDefender

2009\bdagent.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "G:\Program

Files\BitDefender\BitDefender 2009\IEShow.exe"
O4 - HKCU\..\Run: [ctfmon.exe] G:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "G:\Documents and Settings\Koib\Local

Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Steam] "g:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [DAEMON Tools Lite] "G:\Program Files\DAEMON Tools

Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [SpybotSD TeaTimer] G:\Program Files\Spybot - Search &

Destroy\TeaTimer.exe
O4 - Startup: MarvellTrayStartup.lnk = G:\Program

Files\Marvell\61xx\tray\RaidTray.bat
O4 - Global Startup: Adobe Reader Speed Launch.lnk = G:\Program

Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = G:\Program

Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: &Winamp Search - G:\Documents and Settings\All

Users\Application Data\Winamp

Toolbar\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} -

G:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -

G:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration -

{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - G:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} -

G:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -

{e2e2dd38-d088-4134-82b7-f2ba38496583} - G:\WINDOWS\Network

Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

G:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program

Files\Messenger\msmsgs.exe
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) -

http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) -

http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) -

http://www.nvidia.com/content/DriverDownlo…iaSmartScan.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -

http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -

G:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: osrrvz.dll
O20 - Winlogon Notify: !SASWinLogon - G:\Program

Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple Inc. - G:\Program Files\Common

Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: BitDefender Arrakis Server (Arrakis3) - Unknown owner -

G:\Program Files\Common Files\BitDefender\BitDefender Arrakis

Server\bin\Arrakis3.exe
O23 - Service: Google Software Updater (gusvc) - Google - G:\Program

Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun

Microsystems, Inc. - G:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL

- G:\Program Files\Common Files\BitDefender\BitDefender Update

Service\livesrv.exe
O23 - Service: Marvell RAID Event Agent (Marvell RAID) - Unknown owner -

G:\Program Files\Marvell\61xx\svc\mvraidsvc.exe
O23 - Service: MRU Web Service (MRUWebService) - Apache Software Foundation -

G:\Program Files\Marvell\61xx\Apache2\bin\Apache.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -

G:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - G:\Program

Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. -

G:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Unknown owner -

G:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (file missing)

–
End of file - 8279 bytes
My computer is running really slow and i tried right clicking malewarebytes and selecting "run as" and running it as administrator and it gave me a message saying… Run-time error '481': Invalid picture It seems like my computer is running slower and slower. I am almost at the point of reinstalling completely please help
Hi and Welcome,

NOTE:
  • Malware removal is NOT instantaneous, most infections require several courses of action to completely eradicate.
  • Absence of symptoms does not always mean the computer is clean
  • Kindly follow my instructions in the order posted.
  • Please DO NOT run any scans or fix items without my direction.



Please do the following:

STEP #1

Please download DDS from either of these links
LINK 1
LINK 2
and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.




STEP #2


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries




NOTE: Please make sure WORD WRAP is UNCHECKED in notepad before you post your logs
.
I have finished all things in correct order.

DDS
Gmer
I zipped the "Attach"
and took off word wrap for the txt documents


Awaiting further instructions, I will be here at the keyboard all day/night.



DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 13:02:16.00 on Wed 07/15/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1345 [GMT -6:00]

AV: BitDefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Webroot Internet Security Essentials *On-access scanning disabled* (Updated) {77E10C7F-2CCA-4187-9394-BDBC267AD597}
AV: Sunbelt VIPRE *On-access scanning disabled* (Outdated) {964FCE60-0B18-4D30-ADD6-EB178909041C}
FW: Webroot Internet Security Essentials *disabled* {63671000-11A2-46DD-BADD-A084CABCDEAE}
FW: BitDefender Firewall *disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}

============== Running Processes ===============

G:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
G:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
svchost.exe
G:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
G:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
G:\Program Files\Java\jre6\bin\jqs.exe
G:\Program Files\Marvell\61xx\Apache2\bin\Apache.exe
G:\WINDOWS\system32\nvsvc32.exe
G:\Program Files\Viewpoint\Common\ViewpointService.exe
G:\Program Files\Marvell\61xx\Apache2\bin\Apache.exe
G:\PROGRA~1\AVG\AVG8\avgemc.exe
G:\PROGRA~1\AVG\AVG8\avgrsx.exe
G:\PROGRA~1\AVG\AVG8\avgnsx.exe
G:\WINDOWS\Explorer.EXE
G:\Program Files\AVG\AVG8\avgcsrvx.exe
G:\WINDOWS\RTHDCPL.EXE
G:\WINDOWS\system32\RUNDLL32.EXE
G:\PROGRA~1\AVG\AVG8\avgtray.exe
G:\WINDOWS\system32\ctfmon.exe
G:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
G:\Program Files\Marvell\61xx\svc\mvraidsvc.exe
G:\Program Files\Marvell\61xx\tray\zRaidTray.exe
G:\Program Files\Mozilla Firefox\firefox.exe
G:\Documents and Settings\Koib\Desktop\dds.pif

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uURLSearchHooks: H - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - g:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - g:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: Winamp Toolbar Loader: {25cee8ec-5730-41bc-8b58-22ddc8ab8c20} - g:\program files\winamp toolbar\winamptb.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - g:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - g:\progra~1\spybot~1\SDHelper.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - g:\program files\java\jre6\bin\ssv.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - g:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: {b12c2a62-4c71-4f9d-b531-9690db1be910} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - g:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - g:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - g:\program files\winamp toolbar\winamptb.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
uRun: [ctfmon.exe] g:\windows\system32\ctfmon.exe
uRun: [Aim6]
uRun: [Google Update] "g:\documents and settings\koib\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [DAEMON Tools Lite] "g:\program files\daemon tools lite\daemon.exe" -autorun
uRun: [SpybotSD TeaTimer] g:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [Steam] "g:\program files\steam\steam.exe" -silent
mRun: [RTHDCPL] "RTHDCPL.EXE"
mRun: [Alcmtr] "ALCMTR.EXE"
mRun: [nwiz] "nwiz.exe" /install
mRun: [Kernel and Hardware Abstraction Layer] "KHALMNPR.EXE"
mRun: [NeroFilterCheck] "g:\windows\system32\NeroCheck.exe"
mRun: [NvCplDaemon] "RUNDLL32.EXE" g:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] "RUNDLL32.EXE" g:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [QuickTime Task] "g:\program files\quicktime\qttask.exe" -atboottime
mRun: [AVG8_TRAY] g:\progra~1\avg\avg8\avgtray.exe
StartupFolder: g:\docume~1\koib\startm~1\programs\startup\marvel~1.lnk - g:\program files\marvell\61xx\tray\RaidTray.bat
StartupFolder: g:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - g:\program files\adobe\reader 8.0\reader\reader_sl.exe
StartupFolder: g:\docume~1\alluse~1\startm~1\programs\startup\adober~2.lnk - g:\program files\adobe\reader 8.0\reader\AdobeCollabSync.exe
IE: &Winamp Search - g:\documents and settings\all users\application data\winamp toolbar\ietoolbar\resources\en-us\local\search.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - g:\program files\messenger\msmsgs.exe
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - g:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - g:\progra~1\spybot~1\SDHelper.dll
DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} - hxxp://support.asus.com/common/asusTek_sys_ctrl.cab
DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} - hxxp://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - g:\program files\avg\avg8\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - g:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - g:\program files\superantispyware\SASWINLO.dll
Notify: avgrsstarter - avgrsstx.dll
AppInit_DLLs: osrrvz.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - g:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - g:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - g:\docume~1\koib\applic~1\mozilla\firefox\profiles\vkd103lr.default\
FF - prefs.js: browser.search.selectedEngine - Answers.com
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: g:\program files\mozilla firefox\components\FFComm.dll
FF - plugin: g:\documents and settings\koib\application data\move networks\plugins\npqmp071500000347.dll
FF - plugin: g:\documents and settings\koib\application data\move networks\plugins\npqmp071503000010.dll
FF - plugin: g:\documents and settings\koib\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: g:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: g:\program files\mozilla firefox\plugins\npbittorrent.dll
FF - plugin: g:\program files\mozilla firefox\plugins\npijjiCHPlugin.dll
FF - plugin: g:\program files\mozilla firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: g:\program files\mozilla firefox\plugins\npPandoWebInst.dll
FF - plugin: g:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: g:\program files\viewpoint\viewpoint media player\npViewpoint.dll

============= SERVICES / DRIVERS ===============

R0 mv61xx;mv61xx;g:\windows\system32\drivers\mv61xx.sys [2007-6-15 143256]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;g:\windows\system32\drivers\avgldx86.sys [2009-7-15 327688]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;g:\windows\system32\drivers\avgmfx86.sys [2009-7-15 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;g:\windows\system32\drivers\avgtdix.sys [2009-7-15 108552]
R1 SASDIFSV;SASDIFSV;g:\program files\superantispyware\sasdifsv.sys [2009-1-15 8944]
R1 SASKUTIL;SASKUTIL;g:\program files\superantispyware\SASKUTIL.SYS [2009-1-15 55024]
R2 avg8emc;AVG Free8 E-mail Scanner;g:\progra~1\avg\avg8\avgemc.exe [2009-7-15 906520]
R2 avg8wd;AVG Free8 WatchDog;g:\progra~1\avg\avg8\avgwdsvc.exe [2009-7-15 298776]
R2 MRUWebService;MRU Web Service;g:\program files\marvell\61xx\apache2\bin\Apache.exe [2007-5-22 20539]
R2 Viewpoint Manager Service;Viewpoint Manager Service;g:\program files\viewpoint\common\ViewpointService.exe [2008-6-19 24652]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;g:\windows\system32\drivers\l151x86.sys [2008-6-18 37376]
R3 Marvell RAID;Marvell RAID Event Agent;g:\program files\marvell\61xx\svc\mvraidsvc.exe [2007-6-12 61440]
S1 SBRE;SBRE;\??\g:\windows\system32\drivers\sbredrv.sys –> g:\windows\system32\drivers\SBREdrv.sys [?]
S2 WRConsumerService;Webroot Client Service;"g:\program files\webroot\webrootsecurity\wrconsumerservice.exe" –> g:\program files\webroot\webrootsecurity\WRConsumerService.exe [?]
S3 LachesisFltr;Lachesis Mouse Driver;g:\windows\system32\drivers\Lachesis.sys [2009-5-19 12032]
S3 MBAMSwissArmy;MBAMSwissArmy;g:\windows\system32\drivers\mbamswissarmy.sys [2008-12-12 38496]
S3 SASENUM;SASENUM;g:\program files\superantispyware\SASENUM.SYS [2009-1-15 7408]
S4 Boonty Games;Boonty Games;g:\program files\common files\boonty shared\service\Boonty.exe [2009-1-30 69120]

=============== Created Last 30 ================

2009-07-15 12:25 –d-h— g:\windows\PIF
2009-07-15 12:09 –d—– g:\program files\Steam
2009-07-15 01:44 –d-h— G:\$AVG8.VAULT$
2009-07-15 01:19 11,952 a——- g:\windows\system32\avgrsstx.dll
2009-07-15 01:19 108,552 a——- g:\windows\system32\drivers\avgtdix.sys
2009-07-15 01:19 327,688 a——- g:\windows\system32\drivers\avgldx86.sys
2009-07-15 01:19 –d—– g:\windows\system32\drivers\Avg
2009-07-15 01:18 –d—– g:\docume~1\alluse~1\applic~1\avg8
2009-07-14 10:02 1,089,593 -c—— g:\windows\system32\dllcache\ntprint.cat
2009-07-14 06:51 54 a——- g:\windows\system32\rp_stats.dat
2009-07-14 06:51 39 a——- g:\windows\system32\rp_rules.dat
2009-07-14 05:59 850 a——- g:\windows\system32\ProductTweaks.xml
2009-07-14 05:59 385 a——- g:\windows\system32\user_gensett.xml
2009-07-14 05:56 –d—– G:\9730defa55092ed98421161886824de3
2009-07-14 05:53 –d—– G:\4ff181e91bb7a14437d6194a4e47f989
2009-07-14 05:43 –d—– G:\abe1124a1e68c47e519c6362
2009-07-14 05:43 –d—– G:\452011e74e259b6fac71557b6119
2009-07-14 05:19 –d—– g:\docume~1\alluse~1\applic~1\BitDefender
2009-06-27 09:39 –d—– g:\program files\common files\DivX Shared
2009-06-26 19:47 –d—– g:\docume~1\alluse~1\applic~1\Sunbelt
2009-06-26 19:47 –d—– g:\docume~1\koib\applic~1\Sunbelt
2009-06-26 19:44 –d—– g:\program files\Sunbelt Software
2009-06-26 19:13 181,024 a–sh— g:\windows\system32\drivers\fidbox.dat
2009-06-26 19:13 16,416 a–sh— g:\windows\system32\drivers\fidbox2.dat
2009-06-26 19:13 6,608 a–sh— g:\windows\system32\drivers\fidbox.idx
2009-06-26 19:13 2,612 a–sh— g:\windows\system32\drivers\fidbox2.idx
2009-06-26 19:13 3,117 a——- G:\rollback.ini
2009-06-26 19:03 –d—– g:\program files\common files\ParetoLogic
2009-06-26 19:03 –d—– g:\docume~1\alluse~1\applic~1\ParetoLogic
2009-06-20 23:28 –d—– g:\program files\Razor
2009-06-17 04:22 –d—– g:\program files\SoundSpectrum

==================== Find3M ====================

2009-07-15 01:07 81,984 a——- g:\windows\system32\bdod.bin
2009-05-29 13:49 828,160 a——- g:\windows\boinc.scr
2009-05-07 09:32 345,600 a——- g:\windows\system32\localspl.dll
2009-05-01 15:02 90,112 a——- g:\windows\system32\dpl100.dll
2009-05-01 15:02 823,296 a——- g:\windows\system32\divx_xx0c.dll
2009-05-01 15:02 823,296 a——- g:\windows\system32\divx_xx07.dll
2009-05-01 15:02 815,104 a——- g:\windows\system32\divx_xx0a.dll
2009-05-01 15:02 811,008 a——- g:\windows\system32\divx_xx16.dll
2009-05-01 15:02 802,816 a——- g:\windows\system32\divx_xx11.dll
2009-05-01 15:02 685,056 a——- g:\windows\system32\DivX.dll
2009-04-28 22:56 827,392 a——- g:\windows\system32\wininet.dll
2009-04-28 22:55 78,336 a——- g:\windows\system32\ieencode.dll
2009-04-17 06:26 1,847,168 a——- g:\windows\system32\win32k.sys
2006-06-23 08:48 32,768 a—-r– g:\windows\inf\UpdateUSB.exe

============= FINISH: 13:02:48.96 ===============






GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-15 15:12:17
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

SSDT spyl.sys ZwCreateKey [0xBA6A80E0]
SSDT spyl.sys ZwEnumerateKey [0xBA6C6CA2]
SSDT spyl.sys ZwEnumerateValueKey [0xBA6C7030]
SSDT spyl.sys ZwOpenKey [0xBA6A80C0]
SSDT spyl.sys ZwQueryKey [0xBA6C7108]
SSDT spyl.sys ZwQueryValueKey [0xBA6C6F88]
SSDT spyl.sys ZwSetValueKey [0xBA6C719A]

INT 0x63 ? 8A5A4BF8
INT 0x63 ? 8A5A4BF8
INT 0x63 ? 8A5A4BF8
INT 0x63 ? 8A5A4BF8
INT 0x63 ? 8A5A4BF8
INT 0x83 ? 8A5A6BF8
INT 0x83 ? 89A81BF8
INT 0x83 ? 8A5A6BF8
INT 0x84 ? 89A81BF8
INT 0x94 ? 89A81BF8
INT 0xA4 ? 89A81BF8
INT 0xA4 ? 89A81BF8
INT 0xA4 ? 89A81BF8
INT 0xA4 ? 89A81BF8
INT 0xB4 ? 89A81BF8

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 8A6131F8
Device \FileSystem\Fastfat \FatCdrom 899191F8

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\usbuhci \Device\USBPDO-0 89A761F8
Device \Driver\usbuhci \Device\USBPDO-1 89A761F8
Device \Driver\usbuhci \Device\USBPDO-2 89A761F8
Device \Driver\usbehci \Device\USBPDO-3 89A4B1F8
Device \Driver\usbuhci \Device\USBPDO-4 89A761F8
Device \Driver\PCI_PNP5790 \Device\00000048 spyl.sys

AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\usbuhci \Device\USBPDO-5 89A761F8
Device \Driver\usbuhci \Device\USBPDO-6 89A761F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 8A6151F8
Device \Driver\usbehci \Device\USBPDO-7 89A4B1F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 8A6151F8
Device \Driver\Cdrom \Device\CdRom0 89A3E1F8
Device \Driver\sptd \Device\931582040 spyl.sys
Device \Driver\Ftdisk \Device\HarddiskVolume3 8A6151F8
Device \Driver\Cdrom \Device\CdRom1 89A3E1F8
Device \Driver\Ftdisk \Device\HarddiskVolume4 8A6151F8
Device \Driver\Cdrom \Device\CdRom2 89A3E1F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 8973C1F8
Device \Driver\NetBT \Device\NetbiosSmb 8973C1F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{EBE3B430-CD65-47C2-B522-2699EAF07DCF} 8973C1F8

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\usbuhci \Device\USBFDO-0 89A761F8
Device \Driver\usbuhci \Device\USBFDO-1 89A761F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 899411F8
Device \Driver\usbuhci \Device\USBFDO-2 89A761F8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 899411F8
Device \Driver\usbehci \Device\USBFDO-3 89A4B1F8
Device \Driver\usbuhci \Device\USBFDO-4 89A761F8
Device \Driver\Ftdisk \Device\FtControl 8A6151F8
Device \Driver\usbuhci \Device\USBFDO-5 89A761F8
Device \Driver\usbuhci \Device\USBFDO-6 89A761F8
Device \Driver\usbehci \Device\USBFDO-7 89A4B1F8
Device \Driver\a29h88al \Device\Scsi\a29h88al1Port5Path0Target1Lun0 89A3D500
Device \Driver\mv61xx \Device\Scsi\mv61xx1 8A6141F8
Device \Driver\a29h88al \Device\Scsi\a29h88al1 89A3D500
Device \Driver\a29h88al \Device\Scsi\a29h88al1Port5Path0Target0Lun0 89A3D500
Device \Driver\mv61xx \Device\Scsi\mv61xx1Port4Path0Target0Lun0 8A6141F8
Device \Driver\mv61xx \Device\Scsi\mv61xx1Port4Path0Target19Lun0 8A6141F8
Device \FileSystem\Fastfat \Fat 899191F8

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs 899341F8

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 G:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x6B 0x97 0xDE 0xF6 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x9E 0x82 0x73 0xBB …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xF7 0x5A 0xAB 0xE6 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0xBC 0x9B 0x37 0x20 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 G:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x6B 0x97 0xDE 0xF6 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x9E 0x82 0x73 0xBB …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xFB 0xC9 0x31 0xC5 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x59 0x93 0x2F 0xB2 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 G:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x6B 0x97 0xDE 0xF6 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x9E 0x82 0x73 0xBB …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xFB 0xC9 0x31 0xC5 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x59 0x93 0x2F 0xB2 …
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\17\Shell@MaxPos8\x00b00x600(1).y -1

—- EOF - GMER 1.0.15 —-

Attachments:

Hi,

Please do the following

Download Combofix from either of the links below. You must rename it before saving it.
Save it to your desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


Link 1
Link 2



During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.


———————————————————–

  • Double click on Combo-Fix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\Combo-Fix.txt" for further review.
    **Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**


    ———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

Here is the combo fix info




ComboFix 09-07-14.08 - Koib 07/15/2009 15:56.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1326 [GMT -6:00]
Running from: g:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: BitDefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
AV: Sunbelt VIPRE *On-access scanning disabled* (Outdated) {964FCE60-0B18-4D30-ADD6-EB178909041C}
AV: Webroot Internet Security Essentials *On-access scanning disabled* (Updated) {77E10C7F-2CCA-4187-9394-BDBC267AD597}
FW: BitDefender Firewall *disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
FW: Webroot Internet Security Essentials *disabled* {63671000-11A2-46DD-BADD-A084CABCDEAE}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

G:\install.exe
g:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_BOONTY_GAMES
——-\Service_Boonty Games


((((((((((((((((((((((((( Files Created from 2009-06-15 to 2009-07-15 )))))))))))))))))))))))))))))))
.

2009-07-15 18:25 . 2009-07-15 18:25 ——– d–h–w- g:\windows\PIF
2009-07-15 18:09 . 2009-07-15 21:25 ——– d—–w- g:\program files\Steam
2009-07-15 07:44 . 2009-07-15 07:44 ——– d–h–w- G:\$AVG8.VAULT$
2009-07-15 07:22 . 2009-07-15 07:18 2052888 —-a-w- g:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-07-15 07:19 . 2009-07-15 07:19 11952 —-a-w- g:\windows\system32\avgrsstx.dll
2009-07-15 07:19 . 2009-07-15 07:19 108552 —-a-w- g:\windows\system32\drivers\avgtdix.sys
2009-07-15 07:19 . 2009-07-15 07:19 327688 —-a-w- g:\windows\system32\drivers\avgldx86.sys
2009-07-15 07:19 . 2009-07-15 07:19 27784 —-a-w- g:\windows\system32\drivers\avgmfx86.sys
2009-07-15 07:19 . 2009-07-15 07:20 ——– d—–w- g:\windows\system32\drivers\Avg
2009-07-15 07:18 . 2009-07-15 07:18 ——– d—–w- g:\documents and settings\All Users\Application Data\avg8
2009-07-14 12:51 . 2009-07-14 12:56 54 —-a-w- g:\windows\system32\rp_stats.dat
2009-07-14 12:51 . 2009-07-14 12:56 39 —-a-w- g:\windows\system32\rp_rules.dat
2009-07-14 11:56 . 2009-07-14 11:56 ——– d—–w- G:\9730defa55092ed98421161886824de3
2009-07-14 11:53 . 2009-07-14 11:53 ——– d—–w- G:\4ff181e91bb7a14437d6194a4e47f989
2009-07-14 11:43 . 2009-07-14 11:43 ——– d—–w- G:\abe1124a1e68c47e519c6362
2009-07-14 11:43 . 2009-07-14 11:53 ——– d—–w- G:\452011e74e259b6fac71557b6119
2009-07-14 11:19 . 2009-07-14 11:23 ——– d—–w- g:\documents and settings\All Users\Application Data\BitDefender
2009-06-28 07:51 . 2009-06-28 07:51 ——– d—–w- g:\program files\Common Files\Skype
2009-06-27 15:39 . 2009-06-27 15:39 ——– d—–w- g:\program files\Common Files\DivX Shared
2009-06-27 01:47 . 2009-06-27 01:47 ——– d—–w- g:\documents and settings\All Users\Application Data\Sunbelt
2009-06-27 01:47 . 2009-06-27 01:47 ——– d—–w- g:\documents and settings\Koib\Application Data\Sunbelt
2009-06-27 01:44 . 2009-06-27 01:45 ——– d—–w- g:\program files\Sunbelt Software
2009-06-27 01:13 . 2009-06-27 01:45 181024 –sha-w- g:\windows\system32\drivers\fidbox.dat
2009-06-27 01:13 . 2009-06-27 01:45 16416 –sha-w- g:\windows\system32\drivers\fidbox2.dat
2009-06-27 01:03 . 2009-06-27 01:39 ——– d—–w- g:\documents and settings\All Users\Application Data\ParetoLogic
2009-06-27 01:03 . 2009-06-27 01:39 ——– d—–w- g:\program files\Common Files\ParetoLogic
2009-06-27 01:02 . 2009-06-27 01:02 ——– d—–w- g:\documents and settings\Koib\Local Settings\Application Data\Downloaded Installations
2009-06-21 05:28 . 2009-06-21 05:37 ——– d—–w- g:\program files\Razor
2009-06-20 01:44 . 2009-06-20 01:44 1685856 —-a-w- g:\documents and settings\Koib\Application Data\Move Networks\MoveMediaPlayerWinSilent_071503000010.exe
2009-06-19 06:21 . 2009-06-19 06:21 ——– d—–w- g:\documents and settings\All Users\Application Data\nView_Profiles
2009-06-17 10:23 . 2009-06-17 10:23 ——– d—–w- g:\documents and settings\Koib\Application Data\SoundSpectrum
2009-06-17 10:22 . 2009-06-17 10:22 ——– d—–w- g:\program files\SoundSpectrum
2009-06-16 06:35 . 2009-06-16 06:35 97144 —-a-w- g:\documents and settings\Koib\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe
2009-06-16 06:35 . 2009-06-20 01:45 4183416 —-a-w- g:\documents and settings\Koib\Application Data\Move Networks\plugins\npqmp071503000010.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-15 22:04 . 2008-06-17 23:29 9 —-a-w- g:\windows\mvraidver.dat
2009-07-15 07:08 . 2009-05-13 18:45 ——– d—–w- g:\program files\Common Files\BitDefender
2009-07-15 07:08 . 2009-05-13 18:47 ——– d—–w- g:\program files\BitDefender
2009-07-15 07:07 . 2009-05-13 18:57 81984 —-a-w- g:\windows\system32\bdod.bin
2009-07-15 05:50 . 2008-06-20 15:23 ——– d—–w- g:\documents and settings\Koib\Application Data\mIRC
2009-07-15 05:21 . 2008-06-20 15:23 ——– d—–w- g:\program files\mIRC
2009-07-14 22:37 . 2009-01-12 20:22 ——– d—–w- g:\documents and settings\All Users\Application Data\Google Updater
2009-07-14 12:58 . 2009-01-15 03:58 ——– d—–w- g:\documents and settings\All Users\Application Data\Lavasoft
2009-07-14 12:54 . 2009-01-15 04:01 ——– d—–w- g:\program files\Spybot - Search & Destroy
2009-07-14 12:19 . 2009-01-15 04:01 ——– d—–w- g:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-14 12:00 . 2008-06-18 06:14 14648 —-a-w- g:\documents and settings\Koib\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-14 11:55 . 2009-01-28 21:10 64648 —-a-w- g:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-06-30 18:09 . 2008-12-19 08:39 ——– d—–w- g:\documents and settings\Koib\Application Data\Skype
2009-06-30 17:15 . 2008-12-19 08:41 ——– d—–w- g:\documents and settings\Koib\Application Data\skypePM
2009-06-28 07:51 . 2008-12-19 08:39 ——– d—–r- g:\program files\Skype
2009-06-28 07:51 . 2008-12-19 08:39 ——– d—–w- g:\documents and settings\All Users\Application Data\Skype
2009-06-27 18:59 . 2008-06-23 09:58 ——– d—–w- g:\program files\Soulseek
2009-06-27 17:45 . 2008-08-02 15:44 ——– d—–w- g:\documents and settings\Koib\Application Data\uTorrent
2009-06-27 15:41 . 2009-01-14 09:43 ——– d—–w- g:\program files\DivX
2009-06-27 01:45 . 2009-06-27 01:13 6608 –sha-w- g:\windows\system32\drivers\fidbox.idx
2009-06-27 01:45 . 2009-06-27 01:13 2612 –sha-w- g:\windows\system32\drivers\fidbox2.idx
2009-06-27 01:00 . 2009-06-12 19:28 ——– d—–w- g:\documents and settings\Koib\Application Data\Webroot
2009-06-20 01:45 . 2009-06-04 12:59 127872 —-a-w- g:\documents and settings\Koib\Application Data\Move Networks\uninstall.exe
2009-06-20 01:45 . 2009-03-20 03:20 ——– d—–w- g:\documents and settings\Koib\Application Data\Move Networks
2009-06-17 23:39 . 2009-06-10 02:23 117760 —-a-w- g:\documents and settings\Koib\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-17 23:38 . 2009-02-10 15:39 ——– d—–w- g:\program files\ProxyFirewall
2009-06-17 10:21 . 2008-12-24 23:23 ——– d—–w- g:\program files\iTunes
2009-06-14 21:02 . 2009-06-14 21:02 ——– d—–w- g:\program files\MSXML 4.0
2009-06-12 20:24 . 2009-06-06 11:41 ——– d—–w- g:\documents and settings\All Users\Application Data\BOINC
2009-06-12 19:29 . 2009-06-12 19:29 ——– d—–w- g:\program files\MSSOAP
2009-06-12 19:28 . 2009-06-12 19:28 ——– d—–w- g:\program files\Webroot
2009-06-12 19:27 . 2009-06-12 19:27 164 —-a-w- g:\windows\install.dat
2009-06-07 02:00 . 2009-06-07 01:59 267776 —-a-w- g:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\setigraphics_6.03_windows_intelx86.exe
2009-06-07 02:00 . 2009-06-07 01:59 406016 —-a-w- g:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\setiathome_6.03_windows_intelx86.exe
2009-06-07 02:00 . 2009-06-07 01:59 448600 —-a-w- g:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\libfftw3f-3-1-1a_upx.dll
2009-06-07 02:00 . 2009-06-07 01:59 389120 —-a-w- g:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\cufft.dll
2009-06-07 02:00 . 2009-06-07 01:59 1445888 —-a-w- g:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\setiathome_6.08_windows_intelx86__cuda.exe
2009-06-07 02:00 . 2009-06-07 01:59 192512 —-a-w- g:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\cudart.dll
2009-06-07 01:53 . 2009-06-06 11:41 ——– d—–w- g:\program files\BOINC
2009-06-04 12:59 . 2009-05-01 06:30 4183416 —-a-w- g:\documents and settings\Koib\Application Data\Move Networks\plugins\npqmp071500000347.dll
2009-06-04 12:59 . 2009-06-04 12:59 1685856 —-a-w- g:\documents and settings\Koib\Application Data\Move Networks\MoveMediaPlayerWin_071500000347.exe
2009-05-29 19:49 . 2009-05-29 19:49 828160 —-a-w- g:\windows\boinc.scr
2009-05-25 12:56 . 2009-05-25 12:56 ——– d—–w- g:\program files\The Rosetta Stone
2009-05-23 08:40 . 2008-08-07 15:08 ——– d—a-w- g:\documents and settings\All Users\Application Data\TEMP
2009-05-22 13:01 . 2008-06-18 07:09 ——– d–h–w- g:\program files\InstallShield Installation Information
2009-05-19 20:56 . 2009-05-19 20:56 ——– d—–w- g:\documents and settings\All Users\Application Data\Razer
2009-05-19 20:56 . 2009-05-19 20:56 ——– d—–w- g:\program files\DIFX
2009-05-19 07:36 . 2009-06-21 04:43 2884832 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\vwpt.exe
2009-05-19 07:36 . 2009-06-21 04:43 28 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\unregister.bat
2009-05-19 07:36 . 2009-06-21 04:43 1484856 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\toolbar.exe
2009-05-19 07:36 . 2009-06-21 04:43 25 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\register.bat
2009-05-19 07:36 . 2009-06-21 04:43 97072 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\bsetutil.exe
2009-05-19 07:36 . 2009-06-21 04:43 142040 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\alsetup.exe
2009-05-19 07:36 . 2009-06-21 04:43 30512 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\Uninstaller.exe
2009-05-19 07:36 . 2009-06-21 04:43 111920 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\AOLSearch.dll
2009-05-07 15:32 . 2006-02-28 12:00 345600 —-a-w- g:\windows\system32\localspl.dll
2009-05-01 21:02 . 2009-05-01 21:02 90112 —-a-w- g:\windows\system32\dpl100.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 —-a-w- g:\windows\system32\divx_xx0c.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 —-a-w- g:\windows\system32\divx_xx07.dll
2009-05-01 21:02 . 2009-05-01 21:02 815104 —-a-w- g:\windows\system32\divx_xx0a.dll
2009-05-01 21:02 . 2009-05-01 21:02 811008 —-a-w- g:\windows\system32\divx_xx16.dll
2009-05-01 21:02 . 2009-05-01 21:02 802816 —-a-w- g:\windows\system32\divx_xx11.dll
2009-05-01 21:02 . 2009-05-01 21:02 685056 —-a-w- g:\windows\system32\DivX.dll
2009-04-29 04:56 . 2006-02-28 12:00 827392 —-a-w- g:\windows\system32\wininet.dll
2009-04-29 04:55 . 2006-02-28 12:00 78336 —-a-w- g:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2006-02-28 12:00 1847168 —-a-w- g:\windows\system32\win32k.sys
2009-06-12 16:56 . 2008-06-17 23:58 134648 —-a-w- g:\program files\mozilla firefox\components\brwsrcmp.dll
2009-03-06 00:08 . 2009-07-14 11:24 49664 —-a-w- g:\program files\mozilla firefox\components\FFComm.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- g:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- g:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="g:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Google Update"="g:\documents and settings\Koib\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-12-30 133104]
"DAEMON Tools Lite"="g:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
"SpybotSD TeaTimer"="g:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Steam"="g:\program files\steam\steam.exe" [2009-07-15 1217784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="g:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"NvCplDaemon"="g:\windows\system32\NvCpl.dll" [2008-09-18 13574144]
"NvMediaCenter"="g:\windows\system32\NvMcTray.dll" [2008-09-18 86016]
"QuickTime Task"="g:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"AVG8_TRAY"="g:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-15 1948440]
"RTHDCPL"="RTHDCPL.EXE" - g:\windows\RTHDCPL.exe [2007-03-21 16126464]
"nwiz"="nwiz.exe" - g:\windows\system32\nwiz.exe [2008-09-18 1657376]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - g:\windows\KHALMNPR.Exe [2007-04-11 56080]

g:\documents and settings\Koib\Start Menu\Programs\Startup\
MarvellTrayStartup.lnk - g:\program files\Marvell\61xx\tray\RaidTray.bat [2008-6-17 201]

g:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - g:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - g:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "g:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 18:05 356352 —-a-w- g:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-15 07:19 11952 —-a-w- g:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WZCSVC"=2 (0x2)
"Spooler"=2 (0x2)
"RDSessMgr"=3 (0x3)
"RasAuto"=3 (0x3)
"FastUserSwitchingCompatibility"=3 (0x3)
"RasMan"=3 (0x3)
"RemoteAccess"=2 (0x2)
"iPod Service"=3 (0x3)
"Boonty Games"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"g:\\Program Files\\mIRC\\mirc.exe"=
"g:\\Valve\\Condition Zero\\czero.exe"=
"g:\\Program Files\\EA Games\\Ultima Online Mondain's Legacy\\client.exe"=
"c:\\ijji\\ENGLISH\\u_gbound.exe"=
"g:\\Program Files\\AIM6\\aim6.exe"=
"g:\\Program Files\\iTunes\\iTunes.exe"=
"g:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"g:\\Program Files\\DNA\\btdna.exe"=
"g:\\WINDOWS\\system32\\sessmgr.exe"=
"g:\\Program Files\\Soulseek\\slsk.exe"=
"g:\\Program Files\\uTorrent\\uTorrent.exe"=
"g:\\Program Files\\Steam\\steam.exe"=
"g:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"g:\\Program Files\\EA Games\\Ultima Online 2D Client\\client.exe"=
"g:\\Program Files\\Steam\\steamapps\\ommited\\counter-strike\\hl.exe"=
"g:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"g:\\Program Files\\Skype\\Phone\\Skype.exe"=
"g:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"g:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"g:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"g:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58354:TCP"= 58354:TCP:*:Disabled:Pando Media Booster
"58354:UDP"= 58354:UDP:*:Disabled:Pando Media Booster

R0 mv61xx;mv61xx;g:\windows\system32\drivers\mv61xx.sys [6/15/2007 1:52 AM 143256]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;g:\windows\system32\drivers\avgldx86.sys [7/15/2009 1:19 AM 327688]
R1 AvgTdiX;AVG Free8 Network Redirector;g:\windows\system32\drivers\avgtdix.sys [7/15/2009 1:19 AM 108552]
R1 SASDIFSV;SASDIFSV;g:\program files\SUPERAntiSpyware\sasdifsv.sys [1/15/2009 5:17 PM 8944]
R1 SASKUTIL;SASKUTIL;g:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/15/2009 5:17 PM 55024]
R2 avg8emc;AVG Free8 E-mail Scanner;g:\progra~1\AVG\AVG8\avgemc.exe [7/15/2009 1:18 AM 906520]
R2 avg8wd;AVG Free8 WatchDog;g:\progra~1\AVG\AVG8\avgwdsvc.exe [7/15/2009 1:18 AM 298776]
R2 MRUWebService;MRU Web Service;g:\program files\Marvell\61xx\Apache2\bin\Apache.exe [5/22/2007 6:17 PM 20539]
R2 Viewpoint Manager Service;Viewpoint Manager Service;g:\program files\Viewpoint\Common\ViewpointService.exe [6/19/2008 11:42 AM 24652]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;g:\windows\system32\drivers\l151x86.sys [6/18/2008 1:09 AM 37376]
R3 Marvell RAID;Marvell RAID Event Agent;g:\program files\Marvell\61xx\svc\mvraidsvc.exe [6/12/2007 12:54 PM 61440]
S1 SBRE;SBRE;\??\g:\windows\system32\drivers\SBREdrv.sys –> g:\windows\system32\drivers\SBREdrv.sys [?]
S2 WRConsumerService;Webroot Client Service;"g:\program files\Webroot\WebrootSecurity\WRConsumerService.exe" –> g:\program files\Webroot\WebrootSecurity\WRConsumerService.exe [?]
S3 LachesisFltr;Lachesis Mouse Driver;g:\windows\system32\drivers\Lachesis.sys [5/19/2009 2:56 PM 12032]
S3 MBAMSwissArmy;MBAMSwissArmy;g:\windows\system32\drivers\mbamswissarmy.sys [12/12/2008 12:46 AM 38496]
S3 SASENUM;SASENUM;g:\program files\SUPERAntiSpyware\SASENUM.SYS [1/15/2009 5:17 PM 7408]
.
Contents of the 'Scheduled Tasks' folder

2009-07-15 g:\windows\Tasks\Google Software Updater.job
- g:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-12 21:13]

2009-07-15 g:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1229272821-1343024091-682003330-1004Core.job
- g:\documents and settings\Koib\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-30 13:41]

2009-07-15 g:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1229272821-1343024091-682003330-1004UA.job
- g:\documents and settings\Koib\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-30 13:41]
.
- - - - ORPHANS REMOVED - - - -

URLSearchHooks-CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
BHO-{b12c2a62-4c71-4f9d-b531-9690db1be910} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKCU-Run-Aim6 - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: &Winamp; Search - g:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
FF - ProfilePath - g:\documents and settings\Koib\Application Data\Mozilla\Firefox\Profiles\vkd103lr.default\
FF - prefs.js: browser.search.selectedEngine - Answers.com
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: g:\program files\Mozilla Firefox\components\FFComm.dll
FF - plugin: g:\documents and settings\Koib\Application Data\Move Networks\plugins\npqmp071500000347.dll
FF - plugin: g:\documents and settings\Koib\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: g:\documents and settings\Koib\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: g:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: g:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: g:\program files\Mozilla Firefox\plugins\npijjiCHPlugin.dll
FF - plugin: g:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: g:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: g:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: g:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-15 16:04
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(720)
g:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(3888)
g:\windows\system32\WPDShServiceObj.dll
g:\windows\system32\PortableDeviceTypes.dll
g:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
g:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
g:\program files\Java\jre6\bin\jqs.exe
g:\windows\system32\nvsvc32.exe
g:\program files\AVG\AVG8\avgrsx.exe
g:\progra~1\AVG\AVG8\avgnsx.exe
g:\program files\AVG\AVG8\avgcsrvx.exe
g:\windows\system32\wscntfy.exe
g:\windows\system32\rundll32.exe
g:\windows\system32\rundll32.exe
g:\program files\Marvell\61xx\tray\zRaidTray.exe
.
**************************************************************************
.
Completion time: 2009-07-15 16:10 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-15 22:10

Pre-Run: 125,280,350,208 bytes free
Post-Run: 125,167,980,544 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe

296 — E O F — 2009-07-15 07:03

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: BitDefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
AV: Sunbelt VIPRE *On-access scanning disabled* (Outdated) {964FCE60-0B18-4D30-ADD6-EB178909041C}
AV: Webroot Internet Security Essentials *On-access scanning disabled* (Updated) {77E10C7F-2CCA-4187-9394-BDBC267AD597}
FW: BitDefender Firewall *disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
FW: Webroot Internet Security Essentials *disabled* {63671000-11A2-46DD-BADD-A084CABCDEAE}



Having more than one antivirus causes system instability, slowdowns and crashes.
It is important to only have ONE antivirus and ONE firewall installed.

Please choose which you wish to keep and uninstall the others.

Next

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Boonty Games"=-

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

NEXT

P2P - I see you have P2P software utorrent and bittorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.


NEXT


Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :dir
    G:\452011e74e259b6fac71557b6119 /s
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Here is the combofix and i will add the SystemLook in 1 minute.

EDIT: here is the system look it will be below the combo fix information.

Also I might add that I do not see the vipre bit defender and webroot in my add/delete programs list. I already deleted them.


ComboFix 09-07-14.08 - Koib 07/15/2009 16:43.2.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1429 [GMT -6:00]
Running from: g:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: g:\documents and settings\Koib\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: BitDefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
AV: Sunbelt VIPRE *On-access scanning disabled* (Outdated) {964FCE60-0B18-4D30-ADD6-EB178909041C}
AV: Webroot Internet Security Essentials *On-access scanning disabled* (Updated) {77E10C7F-2CCA-4187-9394-BDBC267AD597}
FW: BitDefender Firewall *disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
FW: Webroot Internet Security Essentials *disabled* {63671000-11A2-46DD-BADD-A084CABCDEAE}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2009-06-15 to 2009-07-15 )))))))))))))))))))))))))))))))
.

2009-07-15 18:25 . 2009-07-15 18:25 ——– d–h–w- g:\windows\PIF
2009-07-15 18:09 . 2009-07-15 22:15 ——– d—–w- g:\program files\Steam
2009-07-15 07:44 . 2009-07-15 07:44 ——– d–h–w- G:\$AVG8.VAULT$
2009-07-15 07:22 . 2009-07-15 07:18 2052888 —-a-w- g:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-07-15 07:19 . 2009-07-15 07:19 11952 —-a-w- g:\windows\system32\avgrsstx.dll
2009-07-15 07:19 . 2009-07-15 07:19 108552 —-a-w- g:\windows\system32\drivers\avgtdix.sys
2009-07-15 07:19 . 2009-07-15 07:19 327688 —-a-w- g:\windows\system32\drivers\avgldx86.sys
2009-07-15 07:19 . 2009-07-15 07:19 27784 —-a-w- g:\windows\system32\drivers\avgmfx86.sys
2009-07-15 07:19 . 2009-07-15 07:20 ——– d—–w- g:\windows\system32\drivers\Avg
2009-07-15 07:18 . 2009-07-15 07:18 ——– d—–w- g:\documents and settings\All Users\Application Data\avg8
2009-07-14 12:51 . 2009-07-14 12:56 54 —-a-w- g:\windows\system32\rp_stats.dat
2009-07-14 12:51 . 2009-07-14 12:56 39 —-a-w- g:\windows\system32\rp_rules.dat
2009-07-14 11:56 . 2009-07-14 11:56 ——– d—–w- G:\9730defa55092ed98421161886824de3
2009-07-14 11:53 . 2009-07-14 11:53 ——– d—–w- G:\4ff181e91bb7a14437d6194a4e47f989
2009-07-14 11:43 . 2009-07-14 11:43 ——– d—–w- G:\abe1124a1e68c47e519c6362
2009-07-14 11:43 . 2009-07-14 11:53 ——– d—–w- G:\452011e74e259b6fac71557b6119
2009-07-14 11:19 . 2009-07-14 11:23 ——– d—–w- g:\documents and settings\All Users\Application Data\BitDefender
2009-06-28 07:51 . 2009-06-28 07:51 ——– d—–w- g:\program files\Common Files\Skype
2009-06-27 15:39 . 2009-06-27 15:39 ——– d—–w- g:\program files\Common Files\DivX Shared
2009-06-27 01:47 . 2009-06-27 01:47 ——– d—–w- g:\documents and settings\All Users\Application Data\Sunbelt
2009-06-27 01:47 . 2009-06-27 01:47 ——– d—–w- g:\documents and settings\Koib\Application Data\Sunbelt
2009-06-27 01:44 . 2009-06-27 01:45 ——– d—–w- g:\program files\Sunbelt Software
2009-06-27 01:13 . 2009-06-27 01:45 181024 –sha-w- g:\windows\system32\drivers\fidbox.dat
2009-06-27 01:13 . 2009-06-27 01:45 16416 –sha-w- g:\windows\system32\drivers\fidbox2.dat
2009-06-27 01:03 . 2009-06-27 01:39 ——– d—–w- g:\documents and settings\All Users\Application Data\ParetoLogic
2009-06-27 01:03 . 2009-06-27 01:39 ——– d—–w- g:\program files\Common Files\ParetoLogic
2009-06-27 01:02 . 2009-06-27 01:02 ——– d—–w- g:\documents and settings\Koib\Local Settings\Application Data\Downloaded Installations
2009-06-21 05:28 . 2009-06-21 05:37 ——– d—–w- g:\program files\Razor
2009-06-20 01:44 . 2009-06-20 01:44 1685856 —-a-w- g:\documents and settings\Koib\Application Data\Move Networks\MoveMediaPlayerWinSilent_071503000010.exe
2009-06-19 06:21 . 2009-06-19 06:21 ——– d—–w- g:\documents and settings\All Users\Application Data\nView_Profiles
2009-06-17 10:23 . 2009-06-17 10:23 ——– d—–w- g:\documents and settings\Koib\Application Data\SoundSpectrum
2009-06-17 10:22 . 2009-06-17 10:22 ——– d—–w- g:\program files\SoundSpectrum
2009-06-16 06:35 . 2009-06-16 06:35 97144 —-a-w- g:\documents and settings\Koib\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe
2009-06-16 06:35 . 2009-06-20 01:45 4183416 —-a-w- g:\documents and settings\Koib\Application Data\Move Networks\plugins\npqmp071503000010.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-15 22:04 . 2008-06-17 23:29 9 —-a-w- g:\windows\mvraidver.dat
2009-07-15 07:08 . 2009-05-13 18:45 ——– d—–w- g:\program files\Common Files\BitDefender
2009-07-15 07:08 . 2009-05-13 18:47 ——– d—–w- g:\program files\BitDefender
2009-07-15 07:07 . 2009-05-13 18:57 81984 —-a-w- g:\windows\system32\bdod.bin
2009-07-15 05:50 . 2008-06-20 15:23 ——– d—–w- g:\documents and settings\Koib\Application Data\mIRC
2009-07-15 05:21 . 2008-06-20 15:23 ——– d—–w- g:\program files\mIRC
2009-07-14 22:37 . 2009-01-12 20:22 ——– d—–w- g:\documents and settings\All Users\Application Data\Google Updater
2009-07-14 12:58 . 2009-01-15 03:58 ——– d—–w- g:\documents and settings\All Users\Application Data\Lavasoft
2009-07-14 12:54 . 2009-01-15 04:01 ——– d—–w- g:\program files\Spybot - Search & Destroy
2009-07-14 12:19 . 2009-01-15 04:01 ——– d—–w- g:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-14 12:00 . 2008-06-18 06:14 14648 —-a-w- g:\documents and settings\Koib\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-14 11:55 . 2009-01-28 21:10 64648 —-a-w- g:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-06-30 18:09 . 2008-12-19 08:39 ——– d—–w- g:\documents and settings\Koib\Application Data\Skype
2009-06-30 17:15 . 2008-12-19 08:41 ——– d—–w- g:\documents and settings\Koib\Application Data\skypePM
2009-06-28 07:51 . 2008-12-19 08:39 ——– d—–r- g:\program files\Skype
2009-06-28 07:51 . 2008-12-19 08:39 ——– d—–w- g:\documents and settings\All Users\Application Data\Skype
2009-06-27 18:59 . 2008-06-23 09:58 ——– d—–w- g:\program files\Soulseek
2009-06-27 15:41 . 2009-01-14 09:43 ——– d—–w- g:\program files\DivX
2009-06-27 01:45 . 2009-06-27 01:13 6608 –sha-w- g:\windows\system32\drivers\fidbox.idx
2009-06-27 01:45 . 2009-06-27 01:13 2612 –sha-w- g:\windows\system32\drivers\fidbox2.idx
2009-06-27 01:00 . 2009-06-12 19:28 ——– d—–w- g:\documents and settings\Koib\Application Data\Webroot
2009-06-20 01:45 . 2009-06-04 12:59 127872 —-a-w- g:\documents and settings\Koib\Application Data\Move Networks\uninstall.exe
2009-06-20 01:45 . 2009-03-20 03:20 ——– d—–w- g:\documents and settings\Koib\Application Data\Move Networks
2009-06-17 23:39 . 2009-06-10 02:23 117760 —-a-w- g:\documents and settings\Koib\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-17 23:38 . 2009-02-10 15:39 ——– d—–w- g:\program files\ProxyFirewall
2009-06-17 10:21 . 2008-12-24 23:23 ——– d—–w- g:\program files\iTunes
2009-06-14 21:02 . 2009-06-14 21:02 ——– d—–w- g:\program files\MSXML 4.0
2009-06-12 20:24 . 2009-06-06 11:41 ——– d—–w- g:\documents and settings\All Users\Application Data\BOINC
2009-06-12 19:29 . 2009-06-12 19:29 ——– d—–w- g:\program files\MSSOAP
2009-06-12 19:28 . 2009-06-12 19:28 ——– d—–w- g:\program files\Webroot
2009-06-12 19:27 . 2009-06-12 19:27 164 —-a-w- g:\windows\install.dat
2009-06-07 02:00 . 2009-06-07 01:59 267776 —-a-w- g:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\setigraphics_6.03_windows_intelx86.exe
2009-06-07 02:00 . 2009-06-07 01:59 406016 —-a-w- g:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\setiathome_6.03_windows_intelx86.exe
2009-06-07 02:00 . 2009-06-07 01:59 448600 —-a-w- g:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\libfftw3f-3-1-1a_upx.dll
2009-06-07 02:00 . 2009-06-07 01:59 389120 —-a-w- g:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\cufft.dll
2009-06-07 02:00 . 2009-06-07 01:59 1445888 —-a-w- g:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\setiathome_6.08_windows_intelx86__cuda.exe
2009-06-07 02:00 . 2009-06-07 01:59 192512 —-a-w- g:\documents and settings\All Users\Application Data\BOINC\projects\setiathome.berkeley.edu\cudart.dll
2009-06-07 01:53 . 2009-06-06 11:41 ——– d—–w- g:\program files\BOINC
2009-06-04 12:59 . 2009-05-01 06:30 4183416 —-a-w- g:\documents and settings\Koib\Application Data\Move Networks\plugins\npqmp071500000347.dll
2009-06-04 12:59 . 2009-06-04 12:59 1685856 —-a-w- g:\documents and settings\Koib\Application Data\Move Networks\MoveMediaPlayerWin_071500000347.exe
2009-05-29 19:49 . 2009-05-29 19:49 828160 —-a-w- g:\windows\boinc.scr
2009-05-25 12:56 . 2009-05-25 12:56 ——– d—–w- g:\program files\The Rosetta Stone
2009-05-23 08:40 . 2008-08-07 15:08 ——– d—a-w- g:\documents and settings\All Users\Application Data\TEMP
2009-05-22 13:01 . 2008-06-18 07:09 ——– d–h–w- g:\program files\InstallShield Installation Information
2009-05-19 20:56 . 2009-05-19 20:56 ——– d—–w- g:\documents and settings\All Users\Application Data\Razer
2009-05-19 20:56 . 2009-05-19 20:56 ——– d—–w- g:\program files\DIFX
2009-05-19 07:36 . 2009-06-21 04:43 2884832 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\vwpt.exe
2009-05-19 07:36 . 2009-06-21 04:43 28 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\unregister.bat
2009-05-19 07:36 . 2009-06-21 04:43 1484856 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\toolbar.exe
2009-05-19 07:36 . 2009-06-21 04:43 25 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\register.bat
2009-05-19 07:36 . 2009-06-21 04:43 97072 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\bsetutil.exe
2009-05-19 07:36 . 2009-06-21 04:43 142040 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\alsetup.exe
2009-05-19 07:36 . 2009-06-21 04:43 30512 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\Uninstaller.exe
2009-05-19 07:36 . 2009-06-21 04:43 111920 ——w- g:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_EC96FFC0\CACHE\4426.0.4\AOLSearch.dll
2009-05-07 15:32 . 2006-02-28 12:00 345600 —-a-w- g:\windows\system32\localspl.dll
2009-05-01 21:02 . 2009-05-01 21:02 90112 —-a-w- g:\windows\system32\dpl100.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 —-a-w- g:\windows\system32\divx_xx0c.dll
2009-05-01 21:02 . 2009-05-01 21:02 823296 —-a-w- g:\windows\system32\divx_xx07.dll
2009-05-01 21:02 . 2009-05-01 21:02 815104 —-a-w- g:\windows\system32\divx_xx0a.dll
2009-05-01 21:02 . 2009-05-01 21:02 811008 —-a-w- g:\windows\system32\divx_xx16.dll
2009-05-01 21:02 . 2009-05-01 21:02 802816 —-a-w- g:\windows\system32\divx_xx11.dll
2009-05-01 21:02 . 2009-05-01 21:02 685056 —-a-w- g:\windows\system32\DivX.dll
2009-04-29 04:56 . 2006-02-28 12:00 827392 —-a-w- g:\windows\system32\wininet.dll
2009-04-29 04:55 . 2006-02-28 12:00 78336 —-a-w- g:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2006-02-28 12:00 1847168 —-a-w- g:\windows\system32\win32k.sys
2009-06-12 16:56 . 2008-06-17 23:58 134648 —-a-w- g:\program files\mozilla firefox\components\brwsrcmp.dll
2009-03-06 00:08 . 2009-07-14 11:24 49664 —-a-w- g:\program files\mozilla firefox\components\FFComm.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- g:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- g:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="g:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Google Update"="g:\documents and settings\Koib\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-12-30 133104]
"DAEMON Tools Lite"="g:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
"SpybotSD TeaTimer"="g:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Steam"="g:\program files\steam\steam.exe" [2009-07-15 1217784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="g:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"NvCplDaemon"="g:\windows\system32\NvCpl.dll" [2008-09-18 13574144]
"NvMediaCenter"="g:\windows\system32\NvMcTray.dll" [2008-09-18 86016]
"QuickTime Task"="g:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"AVG8_TRAY"="g:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-15 1948440]
"RTHDCPL"="RTHDCPL.EXE" - g:\windows\RTHDCPL.exe [2007-03-21 16126464]
"nwiz"="nwiz.exe" - g:\windows\system32\nwiz.exe [2008-09-18 1657376]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - g:\windows\KHALMNPR.Exe [2007-04-11 56080]

g:\documents and settings\Koib\Start Menu\Programs\Startup\
MarvellTrayStartup.lnk - g:\program files\Marvell\61xx\tray\RaidTray.bat [2008-6-17 201]

g:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - g:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - g:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "g:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 18:05 356352 —-a-w- g:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-15 07:19 11952 —-a-w- g:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WZCSVC"=2 (0x2)
"Spooler"=2 (0x2)
"RDSessMgr"=3 (0x3)
"RasAuto"=3 (0x3)
"FastUserSwitchingCompatibility"=3 (0x3)
"RasMan"=3 (0x3)
"RemoteAccess"=2 (0x2)
"iPod Service"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"g:\\Program Files\\mIRC\\mirc.exe"=
"g:\\Valve\\Condition Zero\\czero.exe"=
"g:\\Program Files\\EA Games\\Ultima Online Mondain's Legacy\\client.exe"=
"c:\\ijji\\ENGLISH\\u_gbound.exe"=
"g:\\Program Files\\AIM6\\aim6.exe"=
"g:\\Program Files\\iTunes\\iTunes.exe"=
"g:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"g:\\Program Files\\DNA\\btdna.exe"=
"g:\\WINDOWS\\system32\\sessmgr.exe"=
"g:\\Program Files\\Soulseek\\slsk.exe"=
"g:\\Program Files\\Steam\\steam.exe"=
"g:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"g:\\Program Files\\EA Games\\Ultima Online 2D Client\\client.exe"=
"g:\\Program Files\\Steam\\steamapps\\[removed]\\counter-strike\\hl.exe"=
"g:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"g:\\Program Files\\Skype\\Phone\\Skype.exe"=
"g:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"g:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"g:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"g:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58354:TCP"= 58354:TCP:*:Disabled:Pando Media Booster
"58354:UDP"= 58354:UDP:*:Disabled:Pando Media Booster

R0 mv61xx;mv61xx;g:\windows\system32\drivers\mv61xx.sys [6/15/2007 1:52 AM 143256]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;g:\windows\system32\drivers\avgldx86.sys [7/15/2009 1:19 AM 327688]
R1 AvgTdiX;AVG Free8 Network Redirector;g:\windows\system32\drivers\avgtdix.sys [7/15/2009 1:19 AM 108552]
R1 SASDIFSV;SASDIFSV;g:\program files\SUPERAntiSpyware\sasdifsv.sys [1/15/2009 5:17 PM 8944]
R1 SASKUTIL;SASKUTIL;g:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/15/2009 5:17 PM 55024]
R2 avg8emc;AVG Free8 E-mail Scanner;g:\progra~1\AVG\AVG8\avgemc.exe [7/15/2009 1:18 AM 906520]
R2 avg8wd;AVG Free8 WatchDog;g:\progra~1\AVG\AVG8\avgwdsvc.exe [7/15/2009 1:18 AM 298776]
R2 MRUWebService;MRU Web Service;g:\program files\Marvell\61xx\Apache2\bin\Apache.exe [5/22/2007 6:17 PM 20539]
R2 Viewpoint Manager Service;Viewpoint Manager Service;g:\program files\Viewpoint\Common\ViewpointService.exe [6/19/2008 11:42 AM 24652]
R3 AtcL001;NDIS Miniport Driver for Atheros L1 Gigabit Ethernet Controller;g:\windows\system32\drivers\l151x86.sys [6/18/2008 1:09 AM 37376]
R3 Marvell RAID;Marvell RAID Event Agent;g:\program files\Marvell\61xx\svc\mvraidsvc.exe [6/12/2007 12:54 PM 61440]
S1 SBRE;SBRE;\??\g:\windows\system32\drivers\SBREdrv.sys –> g:\windows\system32\drivers\SBREdrv.sys [?]
S2 WRConsumerService;Webroot Client Service;"g:\program files\Webroot\WebrootSecurity\WRConsumerService.exe" –> g:\program files\Webroot\WebrootSecurity\WRConsumerService.exe [?]
S3 LachesisFltr;Lachesis Mouse Driver;g:\windows\system32\drivers\Lachesis.sys [5/19/2009 2:56 PM 12032]
S3 MBAMSwissArmy;MBAMSwissArmy;g:\windows\system32\drivers\mbamswissarmy.sys [12/12/2008 12:46 AM 38496]
S3 SASENUM;SASENUM;g:\program files\SUPERAntiSpyware\SASENUM.SYS [1/15/2009 5:17 PM 7408]
.
Contents of the 'Scheduled Tasks' folder

2009-07-15 g:\windows\Tasks\Google Software Updater.job
- g:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-12 21:13]

2009-07-15 g:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1229272821-1343024091-682003330-1004Core.job
- g:\documents and settings\Koib\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-30 13:41]

2009-07-15 g:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1229272821-1343024091-682003330-1004UA.job
- g:\documents and settings\Koib\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-30 13:41]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: &Winamp; Search - g:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
FF - ProfilePath - g:\documents and settings\Koib\Application Data\Mozilla\Firefox\Profiles\vkd103lr.default\
FF - prefs.js: browser.search.selectedEngine - Answers.com
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: g:\program files\Mozilla Firefox\components\FFComm.dll
FF - plugin: g:\documents and settings\Koib\Application Data\Move Networks\plugins\npqmp071500000347.dll
FF - plugin: g:\documents and settings\Koib\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: g:\documents and settings\Koib\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: g:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: g:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: g:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: g:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-15 16:47
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(720)
g:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(3968)
g:\windows\system32\WPDShServiceObj.dll
g:\windows\system32\PortableDeviceTypes.dll
g:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-07-15 16:51
ComboFix-quarantined-files.txt 2009-07-15 22:50
ComboFix2.txt 2009-07-15 22:10

Pre-Run: 125,166,792,704 bytes free
Post-Run: 125,147,951,104 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe

262 — E O F — 2009-07-15 07:03









SystemLook v1.0 by jpshortstuff (22.05.09)
Log created at 16:56 on 15/07/2009 by Koib (Administrator - Elevation successful)

========== dir ==========

G:\452011e74e259b6fac71557b6119 - Parameters: "/s"

—Files—
dotnetfx35setup.exe –a— 2959376 bytes [06:26 30/07/2008] [06:26 30/07/2008]

G:\452011e74e259b6fac71557b6119\dotnetfx20 d—– [11:43 14/07/2009]
aspnet.msp –a— 2926080 bytes [23:29 29/07/2008] [23:29 29/07/2008]
clr.msp –a— 6083072 bytes [23:31 29/07/2008] [23:31 29/07/2008]
crt.msp –a— 506368 bytes [23:33 29/07/2008] [23:33 29/07/2008]
dw.msp –a— 553472 bytes [23:35 29/07/2008] [23:35 29/07/2008]
netfx20a_x86.msi –a— 93184 bytes [23:27 29/07/2008] [23:27 29/07/2008]
netfx_ca.msp –a— 911360 bytes [23:37 29/07/2008] [23:37 29/07/2008]
netfx_core.msp –a— 3403264 bytes [23:39 29/07/2008] [23:39 29/07/2008]
netfx_other.msp –a— 6487040 bytes [23:41 29/07/2008] [23:41 29/07/2008]
prexp.msp –a— 1013248 bytes [23:43 29/07/2008] [23:43 29/07/2008]
winforms.msp –a— 2543616 bytes [23:45 29/07/2008] [23:45 29/07/2008]

G:\452011e74e259b6fac71557b6119\dotnetfx30 d—– [11:43 14/07/2009]
netfx30a_x86.msi –a— 142336 bytes [01:12 30/07/2008] [01:12 30/07/2008]
rgb9rast_x86.msi –a— 94720 bytes [04:40 30/07/2008] [04:40 30/07/2008]
wcf.msp –a— 3376640 bytes [01:18 30/07/2008] [01:18 30/07/2008]
wcs.msp –a— 1043456 bytes [01:26 30/07/2008] [01:26 30/07/2008]
wf.msp –a— 1448448 bytes [01:34 30/07/2008] [01:34 30/07/2008]
wf_32.msp –a— 291840 bytes [01:40 30/07/2008] [01:40 30/07/2008]
wic_x86_enu.exe –a— 1227048 bytes [04:40 30/07/2008] [04:40 30/07/2008]
wpf1.msp –a— 4137984 bytes [02:22 30/07/2008] [02:22 30/07/2008]
wpf2.msp –a— 2679808 bytes [02:37 30/07/2008] [02:37 30/07/2008]
wpf2_32.msp –a— 23040 bytes [03:07 30/07/2008] [03:07 30/07/2008]
wpf_other.msp –a— 3697664 bytes [03:15 30/07/2008] [03:15 30/07/2008]
wpf_other_32.msp –a— 250880 bytes [03:23 30/07/2008] [03:23 30/07/2008]
xps.msp –a— 278016 bytes [03:28 30/07/2008] [03:28 30/07/2008]
xpsepsc-x86-en-us.exe –a— 3049000 bytes [04:40 30/07/2008] [04:40 30/07/2008]

G:\452011e74e259b6fac71557b6119\dotnetfx30\x86 d—– [11:43 14/07/2009]
msxml6.msi –a— 1527296 bytes [05:13 30/07/2008] [05:13 30/07/2008]

G:\452011e74e259b6fac71557b6119\dotnetfx35 d—– [11:43 14/07/2009]

G:\452011e74e259b6fac71557b6119\dotnetfx35\x86 d—– [11:43 14/07/2009]
netfx35_x86.exe –a— 8164360 bytes [05:47 30/07/2008] [05:47 30/07/2008]

G:\452011e74e259b6fac71557b6119\tools d—– [11:43 14/07/2009]
clwireg.exe –a— 114200 bytes [00:43 30/07/2008] [00:43 30/07/2008]

-=End Of File=-
Hi,

Please do the following:


Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
It's normal after running TFC cleaner that the PC will be slower to boot the first time.

NEXT

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report


Also, please advise how your computer is running now and if you have any outstanding issues.
Hi i did the TFC and restarted but when it restarted the video was on 4 bit and running at a small resolution and i would only get online through IE cause mozilla firefox wasn't accessible said something about DEP. So now im in 4bit and small resolution i am going to try restarting. I'm hoping i dont have to reinstall the video driver but if i do it should be fine be back in a little while, EDIT: ok i am downloading a new video driver so it is looking good i will get that MBAM and kaspersky list to you
Ok I fixed the video issue and reinstalled the video driver. I have no idea how that even happened. Thank you so much for your help. I am kinda on a time crunch here I have to leave but promise to be back in the next 3 days. I will run the mbam and kaspersky. And again than you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI