This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Daves HJT log

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

****System stays on for 2 minutes and locks up. Please help!!!*******


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:45:49 PM, on 7/29/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode

Running processes:
C:\Windows\Explorer.EXE
C:\Users\David\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [LSA Shellu] C:\Users\David\lsass.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O13 - Gopher Prefix:
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: lxdi_device - - C:\Windows\system32\lxdicoms.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 10884 bytes
Hi and Welcome,

NOTE:
  • Malware removal is NOT instantaneous, most infections require several courses of action to completely eradicate.
  • Absence of symptoms does not always mean the computer is clean
  • Kindly follow my instructions in the order posted.
  • Please DO NOT run any scans or fix items without my direction.

Please do the following:

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


    C:\Users\David\lsass.exe

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.


NEXT



STEP 2

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


STEP 3


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
The Isass.exe file does not exist on his computer. I am sending you this from another laptop. The laptop in question will not stay on but about 2 minutes in normal mode. It will boot in safe mode but with no internet acess. It will no stay on long enough to do the other steps. Please help!
download those programs to another computer and transfer them over to the infected computer via USB and run them in safe mode
don't worry about that for now, we need a proper diagnosis first to see what's going on, then we can start fixing his computer.
DDS (Ver_09-07-30.01) - NTFSx86 MINIMAL
Run by [removed] at 11:23:55.67 on Fri 07/31/2009
Internet Explorer: 8.0.6001.18813
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.958.587 [GMT -4:00]

AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
SP: Windows Defender *disabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: Norton Internet Security *enabled* (Outdated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\David\Desktop\dds.pif
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {1e8a6170-7264-4d0f-beae-d42a53123c75} - c:\program files\common files\symantec shared\coshared\browser\1.5\NppBho.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Show Norton Toolbar: {90222687-f593-4738-b738-fbee9c7b26df} - c:\program files\common files\symantec shared\coshared\browser\1.5\UIBHO.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: [LSA Shellu] c:\users\david\lsass.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
mRun: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
mRun: []
mRun: [MSConfig] "c:\windows\system32\msconfig.exe" /auto
mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
dRun: [minix32] c:\windows\system32\minix32.exe
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~1.0_0\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll

============= SERVICES / DRIVERS ===============

S1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\symantec\defini~1\symcdata\idsdefs\20080314.001\IDSvix86.sys [2008-3-16 261680]
S2 lxdi_device;lxdi_device;c:\windows\system32\lxdicoms.exe -service –> c:\windows\system32\lxdicoms.exe -service [?]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-1-26 24652]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2008-1-23 109616]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-7-27 38496]
S3 SYMNDISV;SYMNDISV;c:\windows\system32\drivers\symndisv.sys [2007-1-10 38200]

=============== Created Last 30 ================

2009-07-29 18:20 155,144 a——- c:\windows\system32\minix32.exe
2009-07-29 18:19 –d—– c:\program files\Windows Antivirus Pro
2009-07-29 13:14 289,792 a——- c:\windows\system32\atmfd.dll
2009-07-29 13:14 156,160 a——- c:\windows\system32\t2embed.dll
2009-07-29 13:14 72,704 a——- c:\windows\system32\fontsub.dll
2009-07-29 13:14 34,304 a——- c:\windows\system32\atmlib.dll
2009-07-29 13:14 24,064 a——- c:\windows\system32\lpk.dll
2009-07-29 13:14 10,240 a——- c:\windows\system32\dciman32.dll
2009-07-29 10:58 –d—– c:\programdata\12315654
2009-07-29 10:58 –d—– c:\progra~2\12315654
2009-07-29 10:33 –d—– c:\windows\pss
2009-07-28 00:41 389,120 a——- c:\users\david\iexplore.exe
2009-07-27 16:16 –d—– c:\users\david\appdata\roaming\Malwarebytes
2009-07-27 16:16 15,504 a——- c:\windows\system32\drivers\mbam.sys
2009-07-27 16:16 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-27 16:16 –d—– c:\programdata\Malwarebytes
2009-07-27 16:16 –d—– c:\progra~2\Malwarebytes
2009-07-27 16:16 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-07-13 12:04 127,191,180 a——- c:\windows\MEMORY.DMP
2009-07-13 11:41 347 a——- c:\users\david\sybist.bat
2009-07-13 11:41 59,392 a——- c:\users\david\pnykvy.exe
2009-07-01 19:19 –d—– c:\programdata\WEBREG
2009-07-01 19:19 –d—– c:\progra~2\WEBREG
2009-07-01 18:45 –d—– c:\programdata\NOS

==================== Find3M ====================

2009-07-21 17:52 915,456 a——- c:\windows\system32\wininet.dll
2009-07-21 17:47 109,056 a——- c:\windows\system32\iesysprep.dll
2009-07-21 17:47 71,680 a——- c:\windows\system32\iesetup.dll
2009-07-21 16:13 133,632 a——- c:\windows\system32\ieUnatt.exe
2009-07-13 20:52 49,159 a——- c:\programdata\nvModes.dat
2009-07-13 20:52 49,159 a——- c:\progra~2\nvModes.dat
2009-07-13 11:44 1,084 a——- c:\users\david\appdata\roaming\wklnhst.dat
2009-07-01 20:46 2,828 a–sh— c:\programdata\KGyGaAvL.sys
2009-07-01 20:46 2,828 a–sh— c:\progra~2\KGyGaAvL.sys
2009-07-01 19:19 165,666 a——- c:\windows\hpoins28.dat
2009-06-28 20:25 86,016 a——- c:\windows\inf\infstrng.dat
2009-06-28 20:25 51,200 a——- c:\windows\inf\infpub.dat
2009-06-28 20:24 86,016 a——- c:\windows\inf\infstor.dat
2009-06-22 08:19 425 a——- c:\users\david\ombcrd.bat
2009-06-22 08:19 23,040 a——- c:\users\david\DJKRDE.exe
2009-06-22 08:19 60,416 a——- c:\users\david\UTFPCF.exe
2009-06-22 08:14 139,776 —shr– c:\users\david\David.exe
2009-05-23 08:43 27,648 a——- c:\users\david\XCfBVct.exe.dat
2009-05-23 02:42 60,416 a——- c:\users\david\WbDaTA.exe
2009-05-23 02:42 61,440 a——- c:\users\david\CjFmjyc.exe
2009-05-23 02:12 27,648 a——- c:\users\david\EkMjCjaY.exe.dat
2009-05-23 02:12 39,940 a——- c:\users\david\EkMjCjaY.exe
2009-05-08 16:09 128 a——- c:\users\david\msiexec.exe
2009-04-23 07:37 128 a——- c:\users\david\iexplorer.exe
2009-02-14 04:01 48,271 a——- c:\users\david\appdata\roaming\nvModes.dat
2009-01-04 10:12 128 a——- c:\users\david\txnUFuxlwV.exe
2008-12-11 04:16 174 a–sh— c:\program files\desktop.ini
2008-12-06 08:32 128 a——- c:\users\david\gif.exe
2008-11-06 09:00 128 a——- c:\users\david\index.exe
2008-09-06 19:30 8 —shr– c:\programdata\B4DDBFDA18.sys
2008-09-06 19:30 8 —shr– c:\progra~2\B4DDBFDA18.sys
2008-07-01 00:04 52,224 —sh— c:\users\david\lsass.exe
2008-06-15 00:14 665,600 a——- c:\windows\inf\drvindex.dat
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2008-01-22 18:08 56 a–shr– c:\windows\system32\18DABFDDB4.sys
2008-06-06 13:31 3,558 a–sh— c:\windows\system32\KGyGaAvL.sys

============= FINISH: 11:26:51.62 ===============



UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-07-30.01)

Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 10/11/2007 6:47:43 AM
System Uptime: 7/31/2009 11:20:01 AM (0 hours ago)

Motherboard: Quanta | | 30CF
Processor: AMD Turion™ 64 X2 Mobile Technology TL-58 | Socket S1 | 1899/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 141 GiB total, 105.401 GiB free.
D: is FIXED (NTFS) - 8 GiB total, 0.002 GiB free.
E: is CDROM (CDFS)
F: is Removable
G: is CDROM (CDFS)

==== Disabled Device Manager Items =============

==== System Restore Points ===================

No restore point in system.

==== Installed Programs ======================

32 Bit HP CIO Components Installer
ABBYY FineReader 6.0 Sprint
Acrobat.com
Action Illustrated Template Editor
Activation Assistant for the 2007 Microsoft Office suites
Add or Remove Adobe Creative Suite 3 Design Premium
Adobe Acrobat 8 Professional
Adobe AIR
Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Bridge CS3
Adobe Bridge Start Meeting
Adobe BridgeTalk Plugin CS3
Adobe Camera Raw 4.0
Adobe CMaps
Adobe Color - Photoshop Specific
Adobe Color Common Settings
Adobe Color EU Extra Settings
Adobe Color JA Extra Settings
Adobe Color NA Recommended Settings
Adobe Creative Suite 3 Design Premium
Adobe Default Language CS3
Adobe Device Central CS3
Adobe ExtendScript Toolkit 2
Adobe Extension Manager CS3
Adobe Flash Player 10 ActiveX
Adobe Flash Player 9 ActiveX
Adobe Flash Player 9 Plugin
Adobe Fonts All
Adobe Help Viewer CS3
Adobe Illustrator CS3
Adobe InDesign CS3
Adobe InDesign CS3 Icon Handler
Adobe Linguistics CS3
Adobe MotionPicture Color Files
Adobe PDF Library Files
Adobe Photoshop CS3
Adobe Reader 9.1
Adobe Setup
Adobe SING CS3
Adobe Stock Photos CS3
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
Adobe WAS CS3
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS3
AHV content for Acrobat and Flash
AppCore
AV
BufferChm
Business Card Maker
Cards_Calendar_OrderGift_DoMorePlugout
ccCommon
Conexant HD Audio
Copy
CorelDRAW Graphics Suite X4
CorelDRAW Graphics Suite X4 - Capture
CorelDRAW Graphics Suite X4 - Content
CorelDRAW Graphics Suite X4 - Draw
CorelDRAW Graphics Suite X4 - Filters
CorelDRAW Graphics Suite X4 - FontNav
CorelDRAW Graphics SUite X4 - ICA
CorelDRAW Graphics Suite X4 - IPM
CorelDRAW Graphics Suite X4 - Lang EN
CorelDRAW Graphics Suite X4 - PP
CorelDRAW Graphics Suite X4 - VBA
CorelDRAW® Graphics Suite X4
CorelDRAW® Graphics Suite X4 - Windows Shell Extension
CustomerResearchQFolder
Destination Component
DeviceDiscovery
DeviceManagementQFolder
DJ_AIO_03_F4200_ProductContext
DJ_AIO_03_F4200_Software
DJ_AIO_03_F4200_Software_Min
ERUNT 1.1j
ESU for Microsoft Vista
eSupportQFolder
Google Toolbar for Internet Explorer
GPBaseService
HDAUDIO Soft Data Fax Modem with SmartCP
Hewlett-Packard Active Check
Hewlett-Packard Asset Agent
HijackThis 2.0.2
HP Active Support Library
HP Active Support Library 32 bit components
HP Customer Experience Enhancements
HP Customer Participation Program 11.0
HP Deskjet F4200 All-In-One Driver Software 11.0 Rel .3
HP Doc Viewer
HP Easy Setup - Frontend
HP Help and Support
HP Imaging Device Functions 11.0
HP Photosmart Essential 2.5
HP Photosmart Essential 3.0
HP Quick Launch Buttons 6.20 B1
HP QuickPlay 3.2
HP Smart Web Printing
HP Solution Center 11.0
HP Total Care Advisor
HP Update
HP User Guides 0057
HP Wireless Assistant
HPNetworkAssistant
HPProductAssistant
HPSSupply
Java™ 6 Update 7
Java™ SE Runtime Environment 6
Lexmark 3500-4500 Series
Lexmark Fax Solutions
LightScribe 1.6.43.1
LiveUpdate 3.2 (Symantec Corporation)
LiveUpdate Notice (Symantec Corporation)
Malwarebytes' Anti-Malware
MarketResearch
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
MSCU for Microsoft Vista
MSRedist
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
muvee autoProducer 6.0
My HP Games
Norton AntiVirus
Norton Confidential Browser Component
Norton Confidential Web Protection Component
Norton Internet Security
Norton Internet Security (Symantec Corporation)
Norton Protection Center
NVIDIA Drivers
PDF Settings
PSSWCORE
RawShooter essentials 2005
RealPlayer
Rhapsody
Rhapsody Player Engine
Roxio Activation Module
Roxio Creator Audio
Roxio Creator Basic v9
Roxio Creator Copy
Roxio Creator Data
Roxio Creator EasyArchive
Roxio Creator Tools
Roxio Express Labeler 3
Roxio MyDVD Basic v9
Scan
Security Update for Windows Media Encoder (KB954156)
Shop for HP Supplies
SmartAudio
SmartWebPrinting
Smilebox
SolutionCenter
SPBBC 32bit
Status
Symantec Real Time Storage Protection Component
SymNet
Synaptics Pointing Device Driver
Toolbox
TrayApp
Update Manager
Vector Magic
VideoToolkit01
Viewpoint Media Player
Visual Basic for Applications ® Core
Visual Basic for Applications ® Core - English
WebReg
Windows Media Encoder 9 Series
Yahoo! Anti-Spy
Yahoo! Toolbar

==== Event Viewer Messages From Past Week ========

7/31/2009 11:21:01 AM, Error: EventLog [6008] - The previous system shutdown at 11:14:25 AM on 7/31/2009 was unexpected.
7/31/2009 11:20:27 AM, Error: Microsoft-Windows-Kernel-WHEA [6] - Machine Check Event reported is a fatal memory hierarchy error. Trasaction Type: 1 Memory Hierarchy Level: 3 Request Type: 14 Address: 232992515675111
7/31/2009 11:08:39 AM, Error: EventLog [6008] - The previous system shutdown at 11:00:28 AM on 7/31/2009 was unexpected.
7/31/2009 10:55:34 AM, Error: EventLog [6008] - The previous system shutdown at 10:52:47 AM on 7/31/2009 was unexpected.
7/31/2009 10:44:05 AM, Error: EventLog [6008] - The previous system shutdown at 10:42:07 AM on 7/31/2009 was unexpected.
7/31/2009 10:41:39 AM, Error: Service Control Manager [7034] - The Automatic LiveUpdate Scheduler service terminated unexpectedly. It has done this 1 time(s).
7/31/2009 10:41:25 AM, Error: Service Control Manager [7031] - The Symantec AppCore Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
7/31/2009 10:38:08 AM, Error: Microsoft-Windows-Kernel-WHEA [6] - Machine Check Event reported is a fatal memory hierarchy error. Trasaction Type: 1 Memory Hierarchy Level: 3 Request Type: 15 Address: 268245641851895
7/29/2009 6:51:28 PM, Error: EventLog [6008] - The previous system shutdown at 6:35:11 PM on 7/29/2009 was unexpected.
7/29/2009 6:28:56 PM, Error: Microsoft-Windows-Kernel-WHEA [6] - Machine Check Event reported is a fatal memory hierarchy error. Trasaction Type: 1 Memory Hierarchy Level: 1 Request Type: 7 Address: 268279975375871
7/29/2009 12:49:12 PM, Error: Microsoft-Windows-Kernel-WHEA [6] - Machine Check Event reported is a fatal memory hierarchy error. Trasaction Type: 1 Memory Hierarchy Level: 3 Request Type: 14 Address: 268176922375143
7/29/2009 12:33:46 PM, Error: EventLog [6008] - The previous system shutdown at 12:31:57 PM on 7/29/2009 was unexpected.
7/29/2009 12:22:12 PM, Error: EventLog [6008] - The previous system shutdown at 12:17:59 PM on 7/29/2009 was unexpected.
7/29/2009 11:24:41 AM, Error: EventLog [6008] - The previous system shutdown at 11:14:51 AM on 7/29/2009 was unexpected.
7/29/2009 11:24:12 AM, Error: Microsoft-Windows-Kernel-WHEA [6] - Machine Check Event reported is a fatal memory hierarchy error. Trasaction Type: 1 Memory Hierarchy Level: 1 Request Type: 7 Address: 268279875761151
7/29/2009 11:10:07 AM, Error: EventLog [6008] - The previous system shutdown at 11:07:42 AM on 7/29/2009 was unexpected.
7/29/2009 11:03:14 AM, Error: EventLog [6008] - The previous system shutdown at 10:58:02 AM on 7/29/2009 was unexpected.
7/29/2009 10:38:12 AM, Error: EventLog [6008] - The previous system shutdown at 10:33:43 AM on 7/29/2009 was unexpected.
7/29/2009 10:21:54 AM, Error: EventLog [6008] - The previous system shutdown at 10:18:28 AM on 7/29/2009 was unexpected.
7/29/2009 10:12:40 AM, Error: EventLog [6008] - The previous system shutdown at 12:41:33 AM on 7/28/2009 was unexpected.
7/29/2009 1:07:44 PM, Error: Service Control Manager [7024] - The SL UI Notification Service service terminated with service-specific error 3221541889 (0xC004D401).
7/29/2009 1:07:40 PM, Error: LSM [1048] - Terminal Service start failed. The relevant status code was Error: 0xc004f027.
7/29/2009 1:05:15 PM, Error: EventLog [6008] - The previous system shutdown at 12:54:13 PM on 7/29/2009 was unexpected.
7/28/2009 12:35:43 AM, Error: EventLog [6008] - The previous system shutdown at 4:55:37 PM on 7/27/2009 was unexpected.
7/27/2009 3:59:13 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD DfsC eeCtrl NetBIOS netbt nsiproxy PSched RasAcd rdbss Smb SPBBCDrv spldr SRTSPX SydexFDD SYMTDI Tcpip tdx Wanarpv6
7/27/2009 3:59:13 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
7/27/2009 3:59:13 PM, Error: Service Control Manager [7001] - The WebDav Client Redirector Driver service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
7/27/2009 3:59:13 PM, Error: Service Control Manager [7001] - The WebClient service depends on the WebDav Client Redirector Driver service which failed to start because of the following error: The dependency service or group failed to start.
7/27/2009 3:59:13 PM, Error: Service Control Manager [7001] - The TCP/IP Registry Compatibility service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
7/27/2009 3:59:13 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
7/27/2009 3:59:13 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
7/27/2009 3:59:13 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
7/27/2009 3:59:13 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
7/27/2009 3:59:13 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service service which failed to start because of the following error: A device attached to the system is not functioning.
7/27/2009 3:59:13 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
7/27/2009 3:59:13 PM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
7/27/2009 3:59:13 PM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
7/27/2009 3:59:13 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
7/27/2009 3:59:13 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
7/27/2009 3:59:13 PM, Error: Service Control Manager [7001] - The ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
7/27/2009 3:57:54 PM, Error: EventLog [6008] - The previous system shutdown at 3:55:34 PM on 7/27/2009 was unexpected.
7/27/2009 3:57:20 PM, Error: Microsoft-Windows-Kernel-WHEA [6] - Machine Check Event reported is a fatal memory hierarchy error. Trasaction Type: 1 Memory Hierarchy Level: 3 Request Type: 11 Address: 162417614033847
7/27/2009 3:51:49 PM, Error: EventLog [6008] - The previous system shutdown at 3:49:49 PM on 7/27/2009 was unexpected.
7/27/2009 3:39:51 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
7/27/2009 3:29:30 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service wcncsvc with arguments "" in order to run the server: {375FF000-DD27-11D9-8F9C-0002B3988E81}
7/27/2009 3:29:30 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {D3DCB472-7261-43CE-924B-0704BD730D5F}
7/27/2009 3:28:49 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service TermService with arguments "" in order to run the server: {F9A874B6-F8A8-4D73-B5A8-AB610816828B}
7/27/2009 3:28:49 PM, Error: LSM [1048] - Terminal Service start failed. The relevant status code was This service cannot be started in Safe Mode .
7/27/2009 3:19:40 PM, Error: EventLog [6008] - The previous system shutdown at 3:17:29 PM on 7/27/2009 was unexpected.
7/27/2009 3:19:13 PM, Error: Microsoft-Windows-Kernel-WHEA [6] - Machine Check Event reported is a fatal memory hierarchy error. Trasaction Type: 1 Memory Hierarchy Level: 3 Request Type: 15 Address: 162692491023351
7/27/2009 3:13:41 PM, Error: EventLog [6008] - The previous system shutdown at 2:38:02 PM on 7/27/2009 was unexpected.
7/27/2009 2:29:38 PM, Error: EventLog [6008] - The previous system shutdown at 2:27:39 PM on 7/27/2009 was unexpected.
7/27/2009 2:23:50 PM, Error: EventLog [6008] - The previous system shutdown at 2:22:46 PM on 7/27/2009 was unexpected.
7/27/2009 2:18:58 PM, Error: EventLog [6008] - The previous system shutdown at 2:17:38 PM on 7/27/2009 was unexpected.
7/27/2009 2:13:37 PM, Error: Microsoft-Windows-Kernel-WHEA [6] - Machine Check Event reported is a fatal memory hierarchy error. Trasaction Type: 1 Memory Hierarchy Level: 3 Request Type: 15 Address: 162692490892279
7/27/2009 2:09:09 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: eeCtrl SPBBCDrv spldr SRTSPX SydexFDD SYMTDI Wanarpv6
7/27/2009 2:09:09 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
7/27/2009 2:07:48 PM, Error: EventLog [6008] - The previous system shutdown at 2:05:34 PM on 7/27/2009 was unexpected.
7/27/2009 2:03:10 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: SydexFDD
7/27/2009 2:03:10 PM, Error: Service Control Manager [7001] - The CyberLink Task Scheduler (CTS) service depends on the CyberLink Background Capture Service (CBCS) service which failed to start because of the following error: After starting, the service hung in a start-pending state.
7/27/2009 2:03:09 PM, Error: Service Control Manager [7022] - The HP CUE DeviceDiscovery Service service hung on starting.
7/27/2009 2:03:09 PM, Error: Service Control Manager [7022] - The CyberLink Background Capture Service (CBCS) service hung on starting.
7/27/2009 2:02:22 PM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
7/27/2009 2:00:34 PM, Error: Microsoft-Windows-Kernel-WHEA [6] - Machine Check Event reported is a fatal memory hierarchy error. Trasaction Type: 1 Memory Hierarchy Level: 3 Request Type: 15 Address: 233061269754871
7/27/2009 1:58:05 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
7/27/2009 1:58:03 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
7/27/2009 1:57:30 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
7/27/2009 1:57:30 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
7/27/2009 1:57:30 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
7/27/2009 1:57:24 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
7/27/2009 1:57:13 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
7/27/2009 1:56:47 PM, Error: EventLog [6008] - The previous system shutdown at 1:54:08 PM on 7/27/2009 was unexpected.
7/27/2009 1:56:21 PM, Error: Microsoft-Windows-Kernel-WHEA [2] - A fatal hardware error occurred.
7/27/2009 1:56:11 PM, Error: ACPI [6] - IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot 13, function 0. Please contact your system vendor for technical assistance.
7/27/2009 1:56:11 PM, Error: ACPI [6] - IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot 12, function 0. Please contact your system vendor for technical assistance.
7/27/2009 1:51:23 PM, Error: EventLog [6008] - The previous system shutdown at 6:36:13 PM on 7/14/2009 was unexpected.

==== End Of File ===========================

GMER 1.0.15.15011 [gmer.exe] - http://www.gmer.net
Rootkit scan 2009-07-31 12:07:17
Windows 6.0.6000


—- System - GMER 1.0.15 —-

Code 84D6EE00 ZwEnumerateKey
Code 84D66750 ZwFlushInstructionCache
Code 84D66FD6 ZwSaveKey
Code 84D638AE ZwSaveKeyEx
Code 84BB3075 IofCallDriver
Code 84D6600E IofCompleteRequest

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
—- Processes - GMER 1.0.15 —-

Library \\?\globalroot\systemroot\system32\geyekrspbdgunv.dll (*** hidden *** ) @ C:\Windows\system32\wininit.exe [348] 0x10000000
Library \\?\globalroot\systemroot\system32\geyekrspbdgunv.dll (*** hidden *** ) @ C:\Windows\system32\winlogon.exe [376] 0x10000000
Library \\?\globalroot\systemroot\system32\geyekrspbdgunv.dll (*** hidden *** ) @ C:\Windows\system32\services.exe [420] 0x10000000
Library \\?\globalroot\systemroot\system32\geyekrspbdgunv.dll (*** hidden *** ) @ C:\Windows\system32\lsass.exe [444] 0x10000000
Library \\?\globalroot\systemroot\system32\geyekrspbdgunv.dll (*** hidden *** ) @ C:\Windows\system32\lsm.exe [452] 0x10000000
Library \\?\globalroot\systemroot\system32\geyekrspbdgunv.dll (*** hidden *** ) @ C:\Windows\system32\notepad.exe [516] 0x10000000
Library \\?\globalroot\systemroot\system32\geyekrspbdgunv.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [684] 0x10000000
Library \\?\globalroot\systemroot\system32\geyekrspbdgunv.dll (*** hidden *** ) @ C:\Windows\System32\svchost.exe [724] 0x10000000
Library \\?\globalroot\systemroot\system32\geyekrspbdgunv.dll (*** hidden *** ) @ C:\Windows\System32\svchost.exe [816] 0x10000000
Library \\?\globalroot\systemroot\system32\geyekrspbdgunv.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [844] 0x10000000
Library \\?\globalroot\systemroot\system32\geyekrspbdgunv.dll (*** hidden *** ) @ C:\Users\David\Desktop\gmer\gmer.exe [872] 0x10000000
Library \\?\globalroot\systemroot\system32\geyekrspbdgunv.dll (*** hidden *** ) @ C:\Windows\system32\svchost.exe [944] 0x10000000
Library \\?\globalroot\systemroot\system32\geyekrspbdgunv.dll (*** hidden *** ) @ C:\Windows\Explorer.EXE [1188] 0x10000000
Library \\?\globalroot\systemroot\system32\geyekrspbdgunv.dll (*** hidden *** ) @ C:\Windows\system32\notepad.exe [1272] 0x10000000
Library \\?\globalroot\systemroot\system32\geyekrspbdgunv.dll (*** hidden *** ) @ C:\Windows\system32\wbem\wmiprvse.exe [1872] 0x10000000

—- Services - GMER 1.0.15 —-

Service C:\Windows\system32\drivers\geyekrlqqhmean.sys (*** hidden *** ) [SYSTEM] geyekredjpgwdd <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\ControlSet001\Services\geyekredjpgwdd (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\geyekredjpgwdd@start 1
Reg HKLM\SYSTEM\ControlSet001\Services\geyekredjpgwdd@type 1
Reg HKLM\SYSTEM\ControlSet001\Services\geyekredjpgwdd@group file system
Reg HKLM\SYSTEM\ControlSet001\Services\geyekredjpgwdd@imagepath \systemroot\system32\drivers\geyekrlqqhmean.sys
Reg HKLM\SYSTEM\ControlSet001\Services\geyekredjpgwdd\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\geyekredjpgwdd\main@aid 10033
Reg HKLM\SYSTEM\ControlSet001\Services\geyekredjpgwdd\main@sid 1
Reg HKLM\SYSTEM\ControlSet001\Services\geyekredjpgwdd\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet001\Services\geyekredjpgwdd\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\geyekredjpgwdd\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\geyekredjpgwdd\main\injector@* geyekrwsp.dll
Reg HKLM\SYSTEM\ControlSet001\Services\geyekredjpgwdd\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\geyekredjpgwdd\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\geyekredjpgwdd\[removed] \systemroot\system32\drivers\geyekrlqqhmean.sys
Reg HKLM\SYSTEM\ControlSet001\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrfmelvqby.dll
Reg HKLM\SYSTEM\ControlSet001\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrcdofnkyx.dat
Reg HKLM\SYSTEM\ControlSet001\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrspbdgunv.dll
Reg HKLM\SYSTEM\ControlSet001\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrpycdttaf.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekredjpgwdd
Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekredjpgwdd@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekredjpgwdd@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekredjpgwdd@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekredjpgwdd@imagepath \systemroot\system32\drivers\geyekrlqqhmean.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekredjpgwdd\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekredjpgwdd\main@aid 10033
Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekredjpgwdd\main@sid 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekredjpgwdd\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekredjpgwdd\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekredjpgwdd\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekredjpgwdd\main\injector@* geyekrwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekredjpgwdd\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekredjpgwdd\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekredjpgwdd\[removed] \systemroot\system32\drivers\geyekrlqqhmean.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrfmelvqby.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrcdofnkyx.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrspbdgunv.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrpycdttaf.dat
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd@imagepath \systemroot\system32\drivers\geyekrlqqhmean.sys
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd\main@aid 10033
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd\main@sid 1
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd\main\injector@* geyekrwsp.dll
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd\main\tasks\0000000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd\main\tasks\0000000001@fn (null)
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd\main\tasks\0000000001@url http://212.117.174.14/installnew6.exe
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd\main\tasks\0000000001@knock (null)
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd\main\tasks\0000000001@timeout 300
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd\main\tasks\0000000001@type 0
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd\main\tasks\0000000001@count 9
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd\[removed] \systemroot\system32\drivers\geyekrlqqhmean.sys
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrfmelvqby.dll
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrcdofnkyx.dat
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrspbdgunv.dll
Reg HKLM\SYSTEM\ControlSet003\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrpycdttaf.dat
Reg HKLM\SYSTEM\ControlSet004\Services\geyekredjpgwdd (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\geyekredjpgwdd@start 1
Reg HKLM\SYSTEM\ControlSet004\Services\geyekredjpgwdd@type 1
Reg HKLM\SYSTEM\ControlSet004\Services\geyekredjpgwdd@group file system
Reg HKLM\SYSTEM\ControlSet004\Services\geyekredjpgwdd@imagepath \systemroot\system32\drivers\geyekrlqqhmean.sys
Reg HKLM\SYSTEM\ControlSet004\Services\geyekredjpgwdd\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\geyekredjpgwdd\main@aid 10033
Reg HKLM\SYSTEM\ControlSet004\Services\geyekredjpgwdd\main@sid 1
Reg HKLM\SYSTEM\ControlSet004\Services\geyekredjpgwdd\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet004\Services\geyekredjpgwdd\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\geyekredjpgwdd\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\geyekredjpgwdd\main\injector@* geyekrwsp.dll
Reg HKLM\SYSTEM\ControlSet004\Services\geyekredjpgwdd\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\geyekredjpgwdd\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\geyekredjpgwdd\[removed] \systemroot\system32\drivers\geyekrlqqhmean.sys
Reg HKLM\SYSTEM\ControlSet004\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrfmelvqby.dll
Reg HKLM\SYSTEM\ControlSet004\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrcdofnkyx.dat
Reg HKLM\SYSTEM\ControlSet004\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrspbdgunv.dll
Reg HKLM\SYSTEM\ControlSet004\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrpycdttaf.dat
Reg HKLM\SYSTEM\ControlSet005\Services\geyekredjpgwdd (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\geyekredjpgwdd@start 1
Reg HKLM\SYSTEM\ControlSet005\Services\geyekredjpgwdd@type 1
Reg HKLM\SYSTEM\ControlSet005\Services\geyekredjpgwdd@group file system
Reg HKLM\SYSTEM\ControlSet005\Services\geyekredjpgwdd@imagepath \systemroot\system32\drivers\geyekrlqqhmean.sys
Reg HKLM\SYSTEM\ControlSet005\Services\geyekredjpgwdd\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\geyekredjpgwdd\main@aid 10033
Reg HKLM\SYSTEM\ControlSet005\Services\geyekredjpgwdd\main@sid 1
Reg HKLM\SYSTEM\ControlSet005\Services\geyekredjpgwdd\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet005\Services\geyekredjpgwdd\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\geyekredjpgwdd\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\geyekredjpgwdd\main\injector@* geyekrwsp.dll
Reg HKLM\SYSTEM\ControlSet005\Services\geyekredjpgwdd\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\geyekredjpgwdd\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\geyekredjpgwdd\[removed] \systemroot\system32\drivers\geyekrlqqhmean.sys
Reg HKLM\SYSTEM\ControlSet005\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrfmelvqby.dll
Reg HKLM\SYSTEM\ControlSet005\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrcdofnkyx.dat
Reg HKLM\SYSTEM\ControlSet005\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrspbdgunv.dll
Reg HKLM\SYSTEM\ControlSet005\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrpycdttaf.dat
Reg HKLM\SYSTEM\ControlSet006\Services\geyekredjpgwdd (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\geyekredjpgwdd@start 1
Reg HKLM\SYSTEM\ControlSet006\Services\geyekredjpgwdd@type 1
Reg HKLM\SYSTEM\ControlSet006\Services\geyekredjpgwdd@group file system
Reg HKLM\SYSTEM\ControlSet006\Services\geyekredjpgwdd@imagepath \systemroot\system32\drivers\geyekrlqqhmean.sys
Reg HKLM\SYSTEM\ControlSet006\Services\geyekredjpgwdd\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\geyekredjpgwdd\main@aid 10033
Reg HKLM\SYSTEM\ControlSet006\Services\geyekredjpgwdd\main@sid 1
Reg HKLM\SYSTEM\ControlSet006\Services\geyekredjpgwdd\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet006\Services\geyekredjpgwdd\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\geyekredjpgwdd\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\geyekredjpgwdd\main\injector@* geyekrwsp.dll
Reg HKLM\SYSTEM\ControlSet006\Services\geyekredjpgwdd\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\geyekredjpgwdd\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet006\Services\geyekredjpgwdd\[removed] \systemroot\system32\drivers\geyekrlqqhmean.sys
Reg HKLM\SYSTEM\ControlSet006\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrfmelvqby.dll
Reg HKLM\SYSTEM\ControlSet006\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrcdofnkyx.dat
Reg HKLM\SYSTEM\ControlSet006\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrspbdgunv.dll
Reg HKLM\SYSTEM\ControlSet006\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrpycdttaf.dat
Reg HKLM\SYSTEM\ControlSet007\Services\geyekredjpgwdd (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\geyekredjpgwdd@start 1
Reg HKLM\SYSTEM\ControlSet007\Services\geyekredjpgwdd@type 1
Reg HKLM\SYSTEM\ControlSet007\Services\geyekredjpgwdd@group file system
Reg HKLM\SYSTEM\ControlSet007\Services\geyekredjpgwdd@imagepath \systemroot\system32\drivers\geyekrlqqhmean.sys
Reg HKLM\SYSTEM\ControlSet007\Services\geyekredjpgwdd\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\geyekredjpgwdd\main@aid 10033
Reg HKLM\SYSTEM\ControlSet007\Services\geyekredjpgwdd\main@sid 1
Reg HKLM\SYSTEM\ControlSet007\Services\geyekredjpgwdd\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet007\Services\geyekredjpgwdd\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\geyekredjpgwdd\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\geyekredjpgwdd\main\injector@* geyekrwsp.dll
Reg HKLM\SYSTEM\ControlSet007\Services\geyekredjpgwdd\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\geyekredjpgwdd\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet007\Services\geyekredjpgwdd\[removed] \systemroot\system32\drivers\geyekrlqqhmean.sys
Reg HKLM\SYSTEM\ControlSet007\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrfmelvqby.dll
Reg HKLM\SYSTEM\ControlSet007\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrcdofnkyx.dat
Reg HKLM\SYSTEM\ControlSet007\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrspbdgunv.dll
Reg HKLM\SYSTEM\ControlSet007\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrpycdttaf.dat
Reg HKLM\SYSTEM\ControlSet008\Services\geyekredjpgwdd (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\geyekredjpgwdd@start 1
Reg HKLM\SYSTEM\ControlSet008\Services\geyekredjpgwdd@type 1
Reg HKLM\SYSTEM\ControlSet008\Services\geyekredjpgwdd@group file system
Reg HKLM\SYSTEM\ControlSet008\Services\geyekredjpgwdd@imagepath \systemroot\system32\drivers\geyekrlqqhmean.sys
Reg HKLM\SYSTEM\ControlSet008\Services\geyekredjpgwdd\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\geyekredjpgwdd\main@aid 10033
Reg HKLM\SYSTEM\ControlSet008\Services\geyekredjpgwdd\main@sid 1
Reg HKLM\SYSTEM\ControlSet008\Services\geyekredjpgwdd\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet008\Services\geyekredjpgwdd\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\geyekredjpgwdd\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\geyekredjpgwdd\main\injector@* geyekrwsp.dll
Reg HKLM\SYSTEM\ControlSet008\Services\geyekredjpgwdd\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\geyekredjpgwdd\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet008\Services\geyekredjpgwdd\[removed] \systemroot\system32\drivers\geyekrlqqhmean.sys
Reg HKLM\SYSTEM\ControlSet008\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrfmelvqby.dll
Reg HKLM\SYSTEM\ControlSet008\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrcdofnkyx.dat
Reg HKLM\SYSTEM\ControlSet008\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrspbdgunv.dll
Reg HKLM\SYSTEM\ControlSet008\Services\geyekredjpgwdd\[removed] \systemroot\system32\geyekrpycdttaf.dat

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\System32\drivers\geyekrlqqhmean.sys 70144 bytes <– ROOTKIT !!!
File C:\WINDOWS\System32\geyekrcdofnkyx.dat 48467 bytes
File C:\WINDOWS\System32\geyekrfmelvqby.dll 43008 bytes
File C:\WINDOWS\System32\geyekrpycdttaf.dat 91 bytes
File C:\WINDOWS\System32\geyekrspbdgunv.dll 18432 bytes

—- EOF - GMER 1.0.15 —-
Hi,

Please do the following:

(download this on the other computer - renaming it before saving - transfer it over to the infected computer and run in safe more if normal mode keeps crashing)

Download Combofix from either of the links below. You must rename it before saving it.
Save it to your desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


Link 1
Link 2



During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.


———————————————————–

  • Double click on Combo-Fix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\Combo-Fix.txt" for further review.
    **Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**


    ———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

Hi

can you tell me exactly what the error message was?

Please run this program:

Please download Sysprot Antirootkit from here

http://sites.google.com/site/sysprotantirootkit/

Unzip it into a folder on your desktop.

  • Double click Sysprot.exe to start the program.
  • Click on the Log tab.
  • In the Write to log box select all items.
  • Look near the bottom left, and Check "Hidden Objects Only"
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new window should appear.
  • Select Scan Root Drive. Click on the Start button.
  • When it is complete a new window will appear to indicate that the scan is finished.
  • The log will be saved automatically in the same folder Sysprot.exe was extracted to.
  • Open the text file and copy/paste the log here.
SysProt AntiRootkit v1.0.1.0 by swatkat ******************************************************************************** ********** ******************************************************************************** ********** No Hidden Processes found ******************************************************************************** ********** ******************************************************************************** ********** No Hidden Kernel Modules found ******************************************************************************** ********** ******************************************************************************** ********** No SSDT Hooks found ******************************************************************************** ********** ******************************************************************************** ********** No Kernel Hooks found ******************************************************************************** ********** ******************************************************************************** ********** No IRP Hooks found ******************************************************************************** ********** ******************************************************************************** ********** No Ports found ******************************************************************************** ********** ******************************************************************************** ********** No hidden files/folders found
Please run this scan:

Download RootRepeal from one of the following locations: Unzip it to your Desktop.
  • Double click RootRepeal.exe to start the program
  • Click on the Report tab at the bottom of the program window
  • Click the Scan button
  • In the Select Scan dialog, check:
    • Drivers
    • Files
    • Processes
    • SSDT
    • Stealth Objects
    • Hidden Services
    • Shadow SSDT
  • Click the OK button
  • In the next dialog, select all drives showing
  • Click OK to start the scan

    Note: The scan can take some time. DO NOT run any other programs while the scan is running

  • When the scan is complete, the Save Report button will become available
  • Click this and save the report to your Desktop as RootRepeal.txt
  • Go to File, then Exit to close the program
If the report is not too long, post the contents of RootRepeal.txt in your next reply. If the report is very long, it will not be complete if you post it, so please attach it to your reply instead.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI