This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] High Cpu usage

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The last time I had really high cpu usage was due to viruses, I had it fixed, but I think I may have downloaded something, so here is my hijack log, any help would be appreciated. Thank You. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 5:19:30 PM, on 8/4/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16876) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\PnkBstrA.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\Documents and Settings\Anthony\Desktop\Ghost\GHostOne\ghost.exe C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrobat.exe C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe C:\Documents and Settings\Anthony\Desktop\Listchecker\pickup.listchecker.exe C:\Program Files\Ventrilo\Ventrilo.exe C:\Program Files\AVG\AVG8\avgtray.exe C:\WINDOWS\system32\taskmgr.exe C:\Program Files\DotA Gaming Network\DotAClient.exe C:\Program Files\DotA Gaming Network\dprotect.dc C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Mozilla Firefox 3.1 Beta 2\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe – End of file - 2824 bytes
Hi and Welcome,

NOTE:
  • Malware removal is NOT instantaneous, most infections require several courses of action to completely eradicate.
  • Absence of symptoms does not always mean the computer is clean
  • Kindly follow my instructions in the order posted.
  • Please DO NOT run any scans or fix items without my direction.



Please do the following:

STEP #1

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


STEP #2


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 12:41:48.21 on Wed 08/05/2009 Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_05 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.354 [GMT -7:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\system32\PnkBstrA.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe C:\Program Files\Registry Mechanic\RegMech.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Documents and Settings\Anthony\Application Data\mjusbsp\magicJack.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE c:\program files\aol\aim toolbar 5.0\AolTbServer.exe C:\PROGRA~1\Yahoo!\browser\ycommon.exe C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\YTBSDK.exe C:\Program Files\Garena\Garena.exe C:\Program Files\Mozilla Firefox 3.1 Beta 2\firefox.exe C:\Program Files\Technitium\TMACv5.0R3\TMAC.exe C:\WINDOWS\system32\taskmgr.exe C:\Download\dds.scr ============== Pseudo HJT Report =============== uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=4070613 uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local mSearchAssistant = hxxp://www.google.com/hws/sb/dell-usuk-rel/en/side.html?channel=us uURLSearchHooks: AOLTBSearch Class: {ea756889-2338-43db-8f07-d1ca6fb9c90d} - c:\program files\aol\aim toolbar 5.0\aoltb.dll uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll mURLSearchHooks: AOLTBSearch Class: {ea756889-2338-43db-8f07-d1ca6fb9c90d} - c:\program files\aol\aim toolbar 5.0\aoltb.dll mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\progra~1\yahoo!\common\yiesrvc.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL BHO: EWPBrowseObject Class: {68f9551e-0411-48e4-9aaf-4bc42a6a46be} - c:\program files\canon\easy-webprint\EWPBrowseLoader.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll BHO: AOL Toolbar Launcher: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol\aim toolbar 5.0\aoltb.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll BHO: SidebarAutoLaunch Class: {f2aa9440-6328-4933-b7c9-a6ccdf9cbf6d} - c:\program files\yahoo!\browser\YSidebarIEBHO.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll TB: AIM Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol\aim toolbar 5.0\aoltb.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll EB: AT&&T Yahoo! Sidebar: {51085e3d-a958-42a2-a6be-a6a9b0baf276} - c:\program files\yahoo!\browser\ysidebarIE.dll uRun: [RegistryMechanic] c:\program files\registry mechanic\RegMech.exe /H uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [cdloader] "c:\documents and settings\anthony\application data\mjusbsp\cdloader2.exe" MAGICJACK uRun: [Google Update] "c:\documents and settings\anthony\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [AdobeUpdater] "c:\program files\common files\adobe\updater5\AdobeUpdater.exe" mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll" mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent IE: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-us\local\search.html IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000 IE: Easy-WebPrint Add To Print List - c:\program files\canon\easy-webprint\Toolband.dll/RC_AddToList.html IE: Easy-WebPrint High Speed Print - c:\program files\canon\easy-webprint\Toolband.dll/RC_HSPrint.html IE: Easy-WebPrint Preview - c:\program files\canon\easy-webprint\Toolband.dll/RC_Preview.html IE: Easy-WebPrint Print - c:\program files\canon\easy-webprint\Toolband.dll/RC_Print.html IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mi1933~1\office12\ONBttnIE.dll IE: {3369AF0D-62E9-4bda-8103-B4C75499B578} - {DE9C389F-3316-41A7-809B-AA305ED9D922} - c:\program files\aol\aim toolbar 5.0\aoltb.dll IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\progra~1\yahoo!\common\yiesrvc.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxdev.dll AppInit_DLLs: c:\progra~1\google\google~1\goec62~1.dll,avgrsstx.dll c:\progra~1\google\google~1\GOEC62~1.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\anthony\applic~1\mozilla\firefox\profiles\29vdt56o.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.search.selectedEngine - Google FF - plugin: c:\documents and settings\anthony\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll —- FIREFOX POLICIES —- c:\program files\mozilla firefox 3.1 beta 2\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox 3.1 beta 2\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox 3.1 beta 2\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox 3.1 beta 2\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox 3.1 beta 2\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox 3.1 beta 2\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox 3.1 beta 2\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox 3.1 beta 2\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox 3.1 beta 2\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox 3.1 beta 2\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox 3.1 beta 2\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox 3.1 beta 2\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox 3.1 beta 2\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox 3.1 beta 2\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox 3.1 beta 2\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox 3.1 beta 2\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox 3.1 beta 2\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox 3.1 beta 2\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-4-26 335752] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-4-26 27784] R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-1-28 298776] R2 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-6-13 1251720] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-12-5 24652] R3 GarenaPEngine;GarenaPEngine;c:\docume~1\anthony\locals~1\temp\FOR3E.tmp [2009-8-5 18704] S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-8-2 32512] =============== Created Last 30 ================ 2009-08-04 17:01 –d—– c:\program files\Technitium 2009-08-04 09:19 –d—– C:\ghost 2009-08-01 15:54 –d—– c:\docume~1\anthony\applic~1\mIRC 2009-08-01 15:53 –d—– c:\program files\mIRC 2009-07-28 15:57 2,036,576 a——- c:\windows\system32\D3DCompiler_40.dll 2009-07-28 15:57 452,440 a——- c:\windows\system32\d3dx10_40.dll 2009-07-28 15:57 4,379,984 a——- c:\windows\system32\D3DX9_40.dll 2009-07-28 15:57 81,768 a——- c:\windows\system32\xinput1_3.dll 2009-07-28 15:56 –d—– c:\windows\Logs 2009-07-28 15:56 –d—– c:\program files\Heroes of Newerth 2009-07-12 20:28 –d—– c:\program files\Full Tilt Poker 2009-07-12 17:56 –d—– c:\docume~1\anthony\applic~1\mjusbsp 2009-07-12 17:55 60,032 a——- c:\windows\system32\drivers\USBAUDIO.sys 2009-07-12 17:55 60,032 a——- c:\windows\system32\dllcache\usbaudio.sys 2009-07-09 14:28 –d—– c:\program files\DotAzilla ==================== Find3M ==================== 2009-08-04 10:40 78,470 a——- c:\windows\War3Unin.dat 2009-08-03 13:36 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-03 13:36 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-07-19 06:33 3,597,824 a——- c:\windows\system32\dllcache\mshtml.dll 2009-07-19 06:32 6,067,200 ——– c:\windows\system32\dllcache\ieframe.dll 2009-07-17 09:30 335,752 a——- c:\windows\system32\drivers\avgldx86.sys 2009-06-29 04:07 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe 2009-06-29 04:07 70,656 a——- c:\windows\system32\dllcache\ie4uinit.exe 2009-06-29 01:35 634,632 a——- c:\windows\system32\dllcache\iexplore.exe 2009-06-29 01:33 2,452,872 ——– c:\windows\system32\dllcache\ieapfltr.dat 2009-06-29 01:33 161,792 a——- c:\windows\system32\dllcache\ieakui.dll 2009-06-16 07:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 07:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-16 07:36 119,808 ——– c:\windows\system32\dllcache\t2embed.dll 2009-06-16 07:36 81,920 ——– c:\windows\system32\dllcache\fontsub.dll 2009-06-03 12:09 1,291,264 a——- c:\windows\system32\quartz.dll 2009-06-03 12:09 1,291,264 ——– c:\windows\system32\dllcache\quartz.dll 2009-05-28 21:08 5,174 a–sh— c:\windows\system32\KGyGaAvL.sys 2009-05-27 21:37 384 a——- c:\program files\iswcx.txt 2009-05-24 07:23 77,859 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2009-05-19 16:06 11,952 a——- c:\windows\system32\avgrsstx.dll 2007-10-28 09:14 138,413 a——- c:\docume~1\anthony\applic~1\mq9ur25.exe ============= FINISH: 12:42:41.17 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-07-30.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume2 Install Date: 6/21/2007 7:08:00 PM System Uptime: 8/5/2009 9:14:32 AM (3 hours ago) Motherboard: Dell Inc. | | 0WG864 Processor: Intel® Pentium® D CPU 3.00GHz | Microprocessor | 2992/800mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 146 GiB total, 108.753 GiB free. D: is CDROM (CDFS) E: is CDROM () F: is Removable G: is CDROM (CDFS) H: is Removable ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP387: 5/6/2009 10:15:12 PM - Software Distribution Service 3.0 RP388: 5/7/2009 8:19:44 AM - Software Distribution Service 3.0 RP389: 5/7/2009 9:51:04 PM - Software Distribution Service 3.0 RP390: 5/8/2009 8:14:56 PM - Software Distribution Service 3.0 RP391: 5/9/2009 9:33:04 PM - Software Distribution Service 3.0 RP392: 5/9/2009 10:30:29 PM - Software Distribution Service 3.0 RP393: 5/10/2009 11:28:29 PM - System Checkpoint RP394: 5/11/2009 3:00:15 AM - Software Distribution Service 3.0 RP395: 5/12/2009 6:53:50 PM - System Checkpoint RP396: 5/13/2009 10:24:06 PM - Software Distribution Service 3.0 RP397: 5/14/2009 10:58:27 PM - Software Distribution Service 3.0 RP398: 5/15/2009 10:17:50 PM - Software Distribution Service 3.0 RP399: 5/16/2009 8:17:21 PM - Software Distribution Service 3.0 RP400: 5/17/2009 10:25:26 PM - Software Distribution Service 3.0 RP401: 5/18/2009 9:27:14 PM - Software Distribution Service 3.0 RP402: 5/19/2009 4:02:33 PM - Avg8 Update RP403: 5/19/2009 4:06:43 PM - Avg8 Update RP404: 5/20/2009 12:33:36 AM - Software Distribution Service 3.0 RP405: 5/21/2009 6:48:37 PM - System Checkpoint RP406: 5/21/2009 9:02:14 PM - Software Distribution Service 3.0 RP407: 5/21/2009 11:09:25 PM - Software Distribution Service 3.0 RP408: 5/22/2009 10:26:01 PM - Software Distribution Service 3.0 RP409: 5/23/2009 7:07:03 AM - Software Distribution Service 3.0 RP410: 5/23/2009 6:32:20 PM - Software Distribution Service 3.0 RP411: 5/23/2009 10:53:03 PM - Software Distribution Service 3.0 RP412: 5/24/2009 6:49:06 AM - Software Distribution Service 3.0 RP413: 5/24/2009 6:51:19 AM - Software Distribution Service 3.0 RP414: 5/24/2009 4:28:44 PM - Restore Operation RP415: 5/24/2009 4:31:42 PM - PokerStars RP416: 5/24/2009 4:36:18 PM - Restore Operation RP417: 5/24/2009 10:44:51 PM - Software Distribution Service 3.0 RP418: 5/27/2009 5:36:14 PM - System Checkpoint RP419: 5/29/2009 5:46:04 PM - System Checkpoint RP420: 5/30/2009 7:50:10 AM - Configured Microsoft Office Enterprise 2007 RP421: 5/31/2009 5:41:15 PM - System Checkpoint RP422: 6/2/2009 7:02:54 PM - System Checkpoint RP423: 6/9/2009 9:33:21 PM - System Checkpoint RP424: 6/10/2009 10:33:08 PM - Software Distribution Service 3.0 RP425: 6/11/2009 8:26:48 PM - Avg8 Update RP426: 6/11/2009 8:28:37 PM - Avg8 Update RP427: 6/13/2009 8:58:29 PM - System Checkpoint RP428: 6/13/2009 11:56:26 PM - Software Distribution Service 3.0 RP429: 6/16/2009 9:17:17 PM - Avg8 Update RP430: 6/16/2009 9:18:22 PM - Avg8 Update RP431: 6/23/2009 9:08:05 PM - Avg8 Update RP432: 6/24/2009 10:56:34 PM - System Checkpoint RP433: 6/26/2009 10:16:14 PM - System Checkpoint RP434: 7/2/2009 9:44:30 PM - System Checkpoint RP435: 7/8/2009 8:24:57 AM - System Checkpoint RP436: 7/8/2009 9:24:36 AM - Software Distribution Service 3.0 RP437: 7/10/2009 8:02:47 PM - System Checkpoint RP438: 7/12/2009 8:28:11 PM - Installed Full Tilt Poker RP439: 7/13/2009 9:19:19 PM - System Checkpoint RP440: 7/15/2009 8:16:34 AM - System Checkpoint RP441: 7/15/2009 10:31:41 PM - Software Distribution Service 3.0 RP442: 7/17/2009 9:29:52 AM - Avg8 Update RP443: 7/17/2009 9:31:07 AM - Avg8 Update RP444: 7/21/2009 11:08:29 AM - Configured Microsoft Office Enterprise 2007 RP445: 7/22/2009 8:24:25 PM - Configured Microsoft Office Enterprise 2007 RP446: 7/22/2009 8:30:06 PM - Configured Microsoft Office Enterprise 2007 RP447: 7/22/2009 10:24:37 PM - Software Distribution Service 3.0 RP448: 7/25/2009 9:37:43 PM - System Checkpoint RP449: 7/28/2009 3:56:55 PM - Installed DirectX RP450: 7/29/2009 7:08:34 AM - Software Distribution Service 3.0 RP451: 7/30/2009 9:16:40 AM - System Checkpoint RP452: 7/31/2009 9:40:45 PM - Software Distribution Service 3.0 RP453: 8/3/2009 10:31:27 PM - System Checkpoint ==== Installed Programs ====================== 2007 Microsoft Office Suite Service Pack 1 (SP1) 2Wire Wireless Client 5700_Help Adobe Acrobat 4.0 Adobe Acrobat 8 Professional - English, Français, Deutsch Adobe Acrobat 8.1.3 Professional Adobe Flash Player 10 Plugin Adobe Flash Player 9 ActiveX Adobe Reader 7.0.8 Adobe Shockwave Player AIM Pro AIM Toolbar 5.0 Apple Mobile Device Support Apple Software Update ArcSoft PhotoStudio 5.5 AT&T Yahoo! Applications AT&T Yahoo! High Speed Internet Installer AutoUpdate AVG Free 8.5 Bonjour BPD_HPSU BPD_Scan BPDfax BPDSoftware BPDSoftware_Ini BufferChm Canon MP Navigator 3.0 Canon MP150 Canon MP160 Canon MP160 User Registration Canon My Printer Canon Utilities Easy-PhotoPrint CMN3 4.0 Corel Paint Shop Pro Photo XI Corel Snapfire Plus Counter-Strike: Source Critical Update for Windows Media Player 11 (KB959772) CustomerResearchQFolder Dell CinePlayer Dell Driver Reset Tool Dell Support 3.2.1 Dell System Restore Destinations DeviceManagementQFolder DivX Codec DivX Content Uploader DivX Converter DivX Player DivX Web Player DocProc DocProcQFolder DotA Client Build 2.0 Beta DotA Client Build 2.1 Beta DotA Client Build 2.2 Beta DotA Client Build 2.31 Beta DotAzilla Easy-WebPrint eSupportQFolder Full Tilt Poker Garena Google Chrome Google Desktop Google Toolbar for Firefox Heroes of Newerth High Definition Audio Driver Package - KB835221 HijackThis 2.0.2 Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Format SDK (KB902344) Hotfix for Windows Media Format SDK (KB910998) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) HP Customer Participation Program 7.0 HP Imaging Device Functions 7.0 HP Officejet All-In-One Series HP Photosmart Essential HP Software Update HP Solution Center 7.0 HPProductAssistant ijji FireFox Launcher 1.0 Intel® Graphics Media Accelerator Driver Intel® Matrix Storage Manager Intel® PRO Network Connections iTunes J2SE Runtime Environment 5.0 Update 6 J5700 Java™ 6 Update 2 Java™ 6 Update 5 Java™ SE Runtime Environment 6 Update 1 LiveUpdate 3.0 (Symantec Corporation) LiveUpdate Notice (Symantec Corporation) Malwarebytes' Anti-Malware MarketResearch Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 1 Microsoft .NET Framework 3.0 Service Pack 1 Microsoft .NET Framework 3.5 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Professional Edition 2003 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Plus! Digital Media Edition Installer Microsoft Plus! Photo Story 2 LE Microsoft Silverlight Microsoft Software Update for Web Folders (English) 12 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Works mIRC Mozilla Firefox (3.0.5) Mozilla Firefox (3.5.2) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 6 Service Pack 2 (KB954459) Norton Security Scan OCR Software by I.R.I.S 7.0 PokerStars ProductContext QuickTime Registry Easy v5.1 Registry Mechanic 8.0 Roxio DLA Roxio RecordNow Audio Roxio RecordNow Copy Roxio RecordNow Data Scan ScanSoft OmniPage SE 4.0 SearchAssist Security Update for 2007 Microsoft Office System (KB951550) Security Update for 2007 Microsoft Office System (KB951944) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB969679) Security Update for CAPICOM (KB931906) Security Update for Microsoft Office Excel 2007 (KB969682) Security Update for Microsoft Office OneNote 2007 (KB950130) Security Update for Microsoft Office PowerPoint 2007 (KB957789) Security Update for Microsoft Office Publisher 2007 (KB969693) Security Update for Microsoft Office system 2007 (KB954326) Security Update for Microsoft Office system 2007 (KB969613) Security Update for Microsoft Office Word 2007 (KB969604) Security Update for Step By Step Interactive Training (KB923723) Security Update for Visio 2007 (KB947590) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 7 (KB972260) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB973346) Skype™ 4.0 SolutionCenter Sonic Activation Module Sonic Update Manager Starcraft StarForge StarForge (C:\Program Files\StarForge\) Status StealthBot v2.6 Revision 3 (remove only) Steam Symantec KB-DocID:2003093015493306 Technitium MAC Address Changer v5.0 Release 3 Toolbox TrayApp Update for 2007 Microsoft Office System (KB967642) Update for Microsoft Office Outlook 2007 (KB969907) Update for Outlook 2007 Junk Email Filter (kb971933) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) URL Assistant Ventrilo Client Versal FileDownload ActiveX Control Trial Version Viewpoint Media Player WC3Banlist WebFldrs XP WebReg Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Imaging Component Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Media Format 11 runtime Windows Media Player 10 Windows Media Player 11 Windows XP Service Pack 3 WinPcap 3.1 WinRAR archiver XML Paper Specification Shared Components Pack 1.0 Yahoo! Toolbar ==== Event Viewer Messages From Past Week ======== 8/4/2009 5:10:04 PM, error: Dhcp [1002] - The IP address lease 192.168.1.69 for the Network Card with network address 001479222465 has been denied by the DHCP server 192.168.1.254 (The DHCP Server sent a DHCPNACK message). ==== End Of File ===========================
Any luck getting the GMER program to run?

If it will not run, try it in safe mode

To Enter Safemode
  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY repeatedly,
  • this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Safemode
  • Then press the Enter Key on your Keyboard
  • go into your usual account
GMER 1.0.15.15011 [gmer.exe] - http://www.gmer.net
Rootkit scan 2009-08-05 15:12:17
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

SSDT \??\C:\DOCUME~1\Anthony\LOCALS~1\Temp\FOR3E.tmp ZwOpenProcess [0xA582F786]
SSDT \??\C:\DOCUME~1\Anthony\LOCALS~1\Temp\FOR3E.tmp ZwWriteVirtualMemory [0xA582F75A]

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)

—- EOF - GMER 1.0.15 —-
Hi

Please do the following:

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


    c:\docume~1\anthony\applic~1\mq9ur25.exe

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.
Try it,

If it wont work with firefox try this scanner instead:

submit a file to virustotal for analysis
  • Use the browse button on that page to navigate to the location of the file to be scanned.
  • In the right hand panel,
  • click on the file c:\docume~1\anthony\applic~1\mq9ur25.exe
  • then click the open button.
  • The file will now be displayed in the submit box.
  • Scroll down a bit and click "send file", wait for the results
Hi,

Those results indicate an infection with backdoor capabilities.

This type of infection allows hackers to remotely control your computer, steal critical system information and download and execute files without your knowledge.
If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Please read this: How Do I Handle Possible Identify Theft, Internet Fraud, and CC Fraud?

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
ComboFix 09-08-04.04 - Anthony 08/05/2009 17:19.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.213 [GMT -7:00]
Running from: c:\download\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\smp.bat
c:\windows\system32\Drivers\pqetccvi.sys

.
((((((((((((((((((((((((( Files Created from 2009-07-06 to 2009-08-06 )))))))))))))))))))))))))))))))
.

2009-08-05 16:15 . 2009-08-01 16:16 6256600 —ha-w- c:\documents and settings\Anthony\Application Data\mjusbsp\in00000\setup.exe
2009-08-05 16:15 . 2009-08-01 16:12 728600 —ha-w- c:\documents and settings\Anthony\Application Data\mjusbsp\ar00000\install.exe
2009-08-05 00:01 . 2009-08-05 00:01 ——– d—–w- c:\program files\Technitium
2009-08-04 16:19 . 2009-08-04 16:19 ——– d—–w- C:\ghost
2009-08-02 19:18 . 2009-08-01 16:16 6256600 —ha-w- c:\documents and settings\Anthony\Application Data\mjusbsp\Upgrade\setup2.exe
2009-08-02 19:18 . 2009-08-01 16:12 728600 —ha-w- c:\documents and settings\Anthony\Application Data\mjusbsp\Upgrade\install2.exe
2009-08-01 22:54 . 2009-08-06 00:26 ——– d—–w- c:\documents and settings\Anthony\Application Data\mIRC
2009-08-01 22:53 . 2009-08-05 20:55 ——– d—–w- c:\program files\mIRC
2009-08-01 16:16 . 2009-08-01 16:16 95576 —-a-w- c:\documents and settings\Anthony\Application Data\mjusbsp\ug00000\magicJack.dll
2009-08-01 16:16 . 2009-08-01 16:16 6256600 —-a-w- c:\documents and settings\Anthony\Application Data\mjusbsp\ug00000\setup.exe
2009-08-01 16:16 . 2009-08-01 16:16 413304 —-a-w- c:\documents and settings\Anthony\Application Data\mjusbsp\magicJackLoader.exe
2009-08-01 16:16 . 2009-08-01 16:16 480608 —-a-w- c:\documents and settings\Anthony\Application Data\mjusbsp\octvqe1_apiw.dll
2009-08-01 16:16 . 2009-08-01 16:16 214360 —-a-w- c:\documents and settings\Anthony\Application Data\mjusbsp\TjVista.dll
2009-08-01 16:16 . 2009-08-01 16:16 325040 —-a-w- c:\documents and settings\Anthony\Application Data\mjusbsp\TjIpSys.dll
2009-08-01 16:16 . 2009-08-01 16:16 570736 —-a-w- c:\documents and settings\Anthony\Application Data\mjusbsp\SJHandsetMagicJack.dll
2009-08-01 16:15 . 2009-08-01 16:15 87384 —-a-w- c:\documents and settings\Anthony\Application Data\mjusbsp\st00000\mjsetup.exe
2009-08-01 16:15 . 2009-08-01 16:15 95576 —-a-w- c:\documents and settings\Anthony\Application Data\mjusbsp\st00000\magicJack.dll
2009-08-01 16:15 . 2009-08-01 16:15 95576 —-a-w- c:\documents and settings\Anthony\Application Data\mjusbsp\magicJack.dll
2009-08-01 16:13 . 2009-08-01 16:13 12231512 —-a-w- c:\documents and settings\Anthony\Application Data\mjusbsp\magicJack.exe
2009-08-01 16:12 . 2009-08-01 16:12 728600 —-a-w- c:\documents and settings\Anthony\Application Data\mjusbsp\ug00000\install.exe
2009-08-01 16:12 . 2009-08-01 16:12 87384 —-a-w- c:\documents and settings\Anthony\Application Data\mjusbsp\in00000\mjsetup.exe
2009-08-01 16:12 . 2009-08-01 16:12 95576 —-a-w- c:\documents and settings\Anthony\Application Data\mjusbsp\in00000\magicJack.dll
2009-08-01 16:11 . 2009-08-01 16:11 441704 —-a-w- c:\documents and settings\Anthony\Application Data\mjusbsp\ug00000\magicJackSplash.exe
2009-08-01 16:11 . 2009-08-01 16:11 441704 —-a-w- c:\documents and settings\Anthony\Application Data\mjusbsp\st00000\magicJackSplash.exe
2009-08-01 16:11 . 2009-08-01 16:11 441704 —-a-w- c:\documents and settings\Anthony\Application Data\mjusbsp\magicJackSplash.exe
2009-08-01 16:11 . 2009-08-01 16:11 441704 —-a-w- c:\documents and settings\Anthony\Application Data\mjusbsp\in00000\magicJackSplash.exe
2009-08-01 16:11 . 2009-08-01 16:11 50520 —-a-w- c:\documents and settings\Anthony\Application Data\mjusbsp\cdloader2.exe
2009-07-31 02:17 . 2009-07-31 02:17 ——– d—–w- c:\documents and settings\Anthony\Local Settings\Application Data\magicJack
2009-07-30 16:00 . 2009-04-10 13:58 6327408 —ha-w- c:\documents and settings\Lucy\Application Data\mjusbsp\in00001\setup.exe
2009-07-30 16:00 . 2009-04-10 13:55 725296 —ha-w- c:\documents and settings\Lucy\Application Data\mjusbsp\ar00001\install.exe
2009-07-17 01:32 . 2009-08-05 02:37 ——– d—–w- c:\documents and settings\Anthony\Local Settings\Application Data\Temp
2009-07-13 14:57 . 2009-07-13 14:57 ——– d—–w- c:\documents and settings\Anthony\Local Settings\Application Data\tjnet
2009-07-13 04:27 . 2009-07-15 03:31 ——– d—–w- c:\documents and settings\Anthony\Local Settings\Application Data\FullTiltPoker
2009-07-13 03:28 . 2009-07-15 23:19 ——– d—–w- c:\program files\Full Tilt Poker
2009-07-13 00:56 . 2009-08-05 16:16 ——– d—–w- c:\documents and settings\Anthony\Application Data\mjusbsp
2009-07-13 00:55 . 2008-04-13 18:45 60032 —-a-w- c:\windows\system32\drivers\USBAUDIO.sys
2009-07-13 00:55 . 2008-04-13 18:45 60032 —-a-w- c:\windows\system32\dllcache\usbaudio.sys
2009-07-09 21:28 . 2009-07-09 23:22 ——– d—–w- c:\program files\DotAzilla

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-06 00:27 . 2009-05-25 17:17 ——– d—–w- c:\documents and settings\Anthony\Application Data\Skype
2009-08-06 00:22 . 2009-01-21 04:25 ——– d—–w- c:\program files\Mozilla Firefox 3.1 Beta 2
2009-08-06 00:16 . 2007-06-25 14:32 ——– d—–w- c:\program files\Starcraft
2009-08-06 00:04 . 2008-05-18 20:42 ——– d—–w- c:\program files\Warcraft III
2009-08-05 23:05 . 2009-05-25 17:18 ——– d—–w- c:\documents and settings\Anthony\Application Data\skypePM
2009-08-05 22:50 . 2008-10-11 23:27 ——– d—–w- c:\program files\Garena
2009-08-05 22:20 . 2009-07-28 22:56 ——– d—–w- c:\program files\Heroes of Newerth
2009-08-05 17:54 . 2009-05-25 05:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-05 17:53 . 2009-07-21 19:01 3942048 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-05 16:15 . 2009-05-24 23:33 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-04 17:40 . 2008-05-18 20:45 78470 —-a-w- c:\windows\War3Unin.dat
2009-08-03 20:36 . 2009-05-25 05:14 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 20:36 . 2009-05-25 05:14 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-01 15:34 . 2009-03-20 03:19 ——– d—–w- c:\program files\Microsoft Silverlight
2009-07-30 16:00 . 2009-07-19 16:50 ——– d—–w- c:\documents and settings\Lucy\Application Data\mjusbsp
2009-07-23 03:30 . 2007-06-24 02:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-07-21 22:39 . 2007-06-22 02:08 72080 —-a-w- c:\documents and settings\Anthony\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-21 21:01 . 2009-05-16 22:40 ——– d—–w- c:\program files\PokerStars
2009-07-21 16:09 . 2007-07-28 04:01 ——– d—–w- c:\program files\Steam
2009-07-17 16:30 . 2008-04-26 15:42 335752 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-13 03:28 . 2007-06-13 14:37 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-05 20:48 . 2008-11-18 03:06 ——– d—–w- c:\program files\DotA Gaming Network
2009-07-04 22:12 . 2009-06-12 03:29 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-06-29 16:12 . 2004-08-10 17:51 827392 —-a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-10 17:51 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2004-08-10 17:50 17408 ——w- c:\windows\system32\corpol.dll
2009-06-17 04:18 . 2008-04-26 15:42 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-16 14:36 . 2004-08-10 17:51 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2004-08-10 17:51 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-12 04:45 . 2009-06-12 04:45 ——– d—–w- c:\documents and settings\Lucy\Application Data\Skype
2009-06-12 03:29 . 2009-06-12 03:29 ——– d—–w- c:\documents and settings\LocalService\Application Data\AVGTOOLBAR
2009-06-11 05:39 . 2007-06-13 14:44 ——– d—–w- c:\program files\Microsoft Works
2009-06-03 19:09 . 2004-08-10 17:51 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-06-02 20:37 . 2009-07-04 22:12 1004800 —-a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-05-29 04:08 . 2008-03-09 02:36 5174 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-05-29 04:08 . 2008-03-09 02:36 168 –sh–r- c:\windows\system32\1BC592EBBA.sys
2009-05-28 04:37 . 2009-05-28 04:37 384 —-a-w- c:\program files\iswcx.txt
2009-05-25 17:18 . 2009-05-25 17:18 56 —ha-w- c:\windows\system32\ezsidmv.dat
2009-05-24 14:23 . 2004-08-10 18:03 77859 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-19 23:06 . 2009-01-29 02:47 11952 —-a-w- c:\windows\system32\avgrsstx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-26 1008896]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-26 17:36 1008896 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-26 1008896]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-26 1008896]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-09 2828184]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-04-16 24264488]
"cdloader"="c:\documents and settings\Anthony\Application Data\mjusbsp\cdloader2.exe" [2009-08-01 50520]
"Google Update"="c:\documents and settings\Anthony\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-07-17 133104]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-11-11 2356088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-12 1948440]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-30 583048]

c:\documents and settings\Lucy\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-19 23:06 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"c:\\Documents and Settings\\Anthony\\Desktop\\Stealth Bot\\Warden.exe"=
"c:\\Documents and Settings\\Anthony\\Desktop\\Listchecker\\pickup.listchecker.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\AIM\\AIM Pro\\aimpro.exe"=
"c:\\Documents and Settings\\Anthony\\Local Settings\\Application Data\\Chat Republic Games\\Superstar Racing\\ChatRepublicPlayer.exe"=
"c:\\Documents and Settings\\Lucy\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\Anthony\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:TCP"= 6112:TCP:WC3 TFT

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [4/26/2008 8:42 AM 335752]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [1/28/2009 7:47 PM 298776]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [12/5/2007 7:11 PM 24652]
R3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\Anthony\LOCALS~1\Temp\LQZ91.tmp –> c:\docume~1\Anthony\LOCALS~1\Temp\LQZ91.tmp [?]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [8/2/2005 2:10 PM 32512]

— Other Services/Drivers In Memory —

*NewlyCreated* - GARENAPENGINE
*NewlyCreated* - MBAMSWISSARMY
*Deregistered* - MBAMSwissArmy

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder

2009-08-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4016265716-1404377972-3314742646-1007Core.job
- c:\documents and settings\Anthony\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-17 01:32]

2009-08-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4016265716-1404377972-3314742646-1007UA.job
- c:\documents and settings\Anthony\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-17 01:32]

2009-07-26 c:\windows\Tasks\Schedule Task Weekly.job
- c:\program files\Registry Easy\RE.exe [2009-05-24 00:47]
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-PRISMSVR - (no file)


.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
FF - ProfilePath - c:\documents and settings\Anthony\Application Data\Mozilla\Firefox\Profiles\29vdt56o.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\Mozilla Firefox 3.1 Beta 2\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\documents and settings\Anthony\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox 3.1 Beta 2\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-05 17:27
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\Anthony\LOCALS~1\Temp\LQZ91.tmp"
.
Completion time: 2009-08-06 17:29
ComboFix-quarantined-files.txt 2009-08-06 00:29

Pre-Run: 116,687,368,192 bytes free
Post-Run: 118,984,794,112 bytes free

265 — E O F — 2009-08-01 04:41
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/High_Cpu_usage_t105825.html&view=findpost&p=584898#entry584898

Collect::
c:\docume~1\anthony\applic~1\mq9ur25.exe

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.


NEXT


Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT



Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • ComboFix Log
  • MBAM Log
  • Kaspersky report

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI