This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Devil Monster....

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Dear Person:….

About 2 weeks ago I had a wierd problem….This below (Edited) is from this thread:==>..
http://forums.whatthetech.com/Emails_video…ks_t105545.html


About 2 weeks ago while I was helping someone with a TV problem at another website,my computer went ABSOLUTELY BONKERS,whacko,etc….Now this happened while I was typeing up a PM….
I lost the blinking "|" where you type at….Then copy & paste dissappeared…..BUMMER!!!
Since I was getting whacked by a virus (Personal bug,I was sick , NOT my computer)…,I decided to logoff & call it a night…..
Then the "SHOCKER"!!!!
This is what I saw when I went offline….
Looks like something from outer space invaded my computer….
Now I have NEVER seen that graphic before EVER,& it's NOT part of ANY file OR program…
System restore was gone also,so I used Erunt to get rid of that "Alien"…
Wednesday evening I ran a DEEP scan with Avast…..Perfectly CLEAN…
Thursday AM ,I ran SpyBot……Full scan,Perfectly CLEAN….
So that pretty much ruled out my computer having any trojans,viruses ,etc….
I opened up a few of my desktop files & waddyaknow???..They worked perfectly….
Copy & paste returned & so did this thing >>"|"….
What I did next was to remove IE-7 & re-install it…..Waddyaknow ?? It fixed the prob!!!
What I don't know is IF this "Glitch" is related to my "Email with Video Probs" OR not….
SOOOooo, you'll need to give me some time to see if that is fixed also….

[attachment removed]

Doug & Abydos suggested I come here as the above graphic resembles this according to Abydos's quote:==>

has an icon of a red devil smiley with 2 horns on its head. & " That devil smiley thing with horns, sounds a lot like your desktop looks ""


I do NOT know what caused this,where I got it or how I got it….I CAN tell you where I did NOT get it from….
ie; Email attachments,banners(?), & possibly embedded links…..

More misc info about this:….

I was smart enough to capture a picture of that "Alien" before I used Erunt to back up to an earlier date & to show you OR anyone else who may know what that's all about…THAT ALIEN IS a LOGO of the problem & I'm CERTAIN that somebody somewhere has seen it & knows exactly what it represents…. The fact that the "Alien" was put on my computer as a desktop display bothers me to no end…
Needless to say I'm upset…
Someone somehow got past a Firewall & Avast to change my desktop against my will..


FYI:…. I've re-ran full scans of Avast! , SpyBot & MBAM (ALL fully updated)…& All came back with NO problems…
Since I have seemingly repaired the problem by removing IE-7 & re-installing IE-7 , I doubt that there's much you can do….
What REALLY UPSETS me is that someway someone somehow got past Avast & my Firewall to not only screw up some functions on my computer via IE-7 , but ALSO change MY desktop & disable the Windows "Restore" function !!!

Whatever you decide to do is PERFECTLY fine with me…..

THANK you VERY MUCH for your expertise & help….

Later…..Ron.M…. :popcorn:
Hi Ron.M,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Download HijackThis from Here .
  • If using Internet Explorer, Please select RUN
  • If Using Firefox, Download to your Desktop and then Double-Click on Icon to start installation.
  • Choose the default location of C:\Program Files\Trend Micro\HijackThis as the destination. HJT needs to be in its own folder so that the program itself isn't deleted by accident. Having the backups could be VITAL to restoring your system if something went wrong in the FIX process!
  • Click the Install button.
  • Accept the license agreement .
  • The progam will place a shortcut on your desktop. This will make it easier for you to access the tool when required.
  • Click Do a system scan and save a log file. A Notepad file will open.
  • To post the text, first you must highlight the entire text and then press the (Ctrl+C) keys which copies it to your clipboard.
  • Now paste the log into this thread using the (Ctrl + V) buttons.


DO NOT MAKE ANY CHANGES OR CLICK "FIX CHECKED" UNTIL WE CHECK THE LOG, AS MOST OF THE FILES ARE LEGIT AND VITAL TO THE FUNCTION OF YOUR COMPUTER

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here
Mr. Tomk:…
Good to see ya again….. :wavey:

Here are the logs you requested…

1st the HiJackThis log:…

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:22:51 PM, on 8/19/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\slserv.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Ron.M\Desktop\New Folder\NetZero\exec.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Greenshot\Greenshot.exe
C:\Documents and Settings\Ron.M\Desktop\New Folder\NetZero\exec.exe
C:\Documents and Settings\Ron.M\Desktop\New Folder\NetZero\qsacc\x1exec.exe
C:\WINDOWS\system32\slrundll.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Ron.M\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://my.netzero.net/s/sp?r=al&cf=sp&…amp;O=I&UT=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:7900
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = searchap.untd.com;127.0.0.1;localhost;*microsoft.com;*windowsupdate.com;*wustat.
windows.com;*test-speed.com;liveupdate.symantecliveupdate.com;*symantec.com;*.nai.com;*.networkass
ociates.com;cf.netzero.net;qs.netzero.net;*.quicken.com;*.pogo.com;
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Documents and Settings\Ron.M\Desktop\New Folder\NetZero\SearchEnh1.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Pop-up Blocker - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Documents and Settings\Ron.M\Desktop\New Folder\NetZero\qsacc\X1IEBHO.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Ask.com Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: (no name) - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - (no file)
O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [LXCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Documents and Settings\Ron.M\Desktop\New Folder\NetZero\exec.exe regrun
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: Greenshot.lnk = C:\Program Files\Greenshot\Greenshot.exe
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Documents and Settings\Ron.M\Desktop\New Folder\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Documents and Settings\Ron.M\Desktop\New Folder\NetZero\qsacc\appres.dll/227
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~1\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~1\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~1\sblsp.dll
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - http://pcpitstop.com/pcpitstop/pcpitstop.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.systemrequirementslab.com/srl_b…sreqlab_srl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1240693214421
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{F4D53855-1F88-4FE7-873A-E5693E89EF5E}: NameServer = 64.136.52.73 64.136.44.73
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxcf_device - - C:\WINDOWS\system32\lxcfcoms.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe

–
End of file - 9762 bytes



Now the Rooter file:…..


Rooter.exe (v1.0.2) by Eric_71
.
SeDebugPrivilege granted successfully …
.
Windows XP . (5.1.2600) Service Pack 3
[32_bits] - x86 Family 15 Model 4 Stepping 1, GenuineIntel
.
[wscsvc] (Security Center) RUNNING (state:4)
[SharedAccess] RUNNING (state:4)
Windows Firewall -> Enabled
.
Internet Explorer 7.0.5730.13
.
A:\ [Removable]
C:\ [Fixed-NTFS] .. ( Total:37 Go - Free:28 Go )
D:\ [CD_Rom]
.
Scan : 19:25.49
Path : C:\Documents and Settings\Ron.M\Desktop\Rooter.exe
User : Ron.M ( Administrator -> YES )
.
———————-\\ Processes
.
Locked [System Process] (0)
______ System (4)
______ \SystemRoot\System32\smss.exe (376)
______ \??\C:\WINDOWS\system32\csrss.exe (424)
______ \??\C:\WINDOWS\system32\winlogon.exe (448)
______ C:\WINDOWS\system32\services.exe (496)
______ C:\WINDOWS\system32\lsass.exe (508)
______ C:\WINDOWS\system32\svchost.exe (672)
______ C:\WINDOWS\system32\svchost.exe (740)
______ C:\Program Files\Windows Defender\MsMpEng.exe (796)
______ C:\WINDOWS\System32\svchost.exe (836)
______ C:\WINDOWS\system32\svchost.exe (892)
______ C:\WINDOWS\system32\svchost.exe (932)
______ C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (1004)
______ C:\Program Files\Alwil Software\Avast4\ashServ.exe (1088)
______ C:\WINDOWS\system32\spoolsv.exe (1324)
______ C:\WINDOWS\system32\svchost.exe (1388)
______ C:\Program Files\Java\jre6\bin\jqs.exe (1452)
______ C:\Program Files\CDBurnerXP\NMSAccessU.exe (1484)
______ C:\WINDOWS\system32\slserv.exe (1544)
______ C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe (1580)
______ C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (1780)
______ C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (1832)
______ C:\WINDOWS\System32\alg.exe (2044)
______ C:\WINDOWS\Explorer.EXE (2416)
______ C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe (2576)
______ C:\Program Files\Analog Devices\Core\smax4pnp.exe (2620)
______ C:\WINDOWS\system32\hkcmd.exe (2676)
______ C:\Program Files\Java\jre6\bin\jusched.exe (2688)
______ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (2708)
______ C:\Program Files\Windows Defender\MSASCui.exe (2752)
______ C:\WINDOWS\system32\ctfmon.exe (2760)
______ C:\Documents and Settings\Ron.M\Desktop\New Folder\NetZero\exec.exe (2800)
______ C:\Program Files\DNA\btdna.exe (2828)
______ C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (2836)
______ C:\Program Files\Greenshot\Greenshot.exe (2900)
______ C:\Documents and Settings\Ron.M\Desktop\New Folder\NetZero\exec.exe (3112)
______ C:\Documents and Settings\Ron.M\Desktop\New Folder\NetZero\qsacc\x1exec.exe (3488)
______ C:\WINDOWS\system32\slrundll.exe (3756)
______ C:\Program Files\Internet Explorer\IEXPLORE.EXE (412)
______ C:\Documents and Settings\Ron.M\Desktop\Rooter.exe (1428)
______ C:\WINDOWS\system32\NOTEPAD.EXE (2408)
.
———————-\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 –[ MBR ]– (Start_Offset:32256 | Length:39991279104)
.
———————-\\ Scheduled Tasks
.
C:\WINDOWS\Tasks\desktop.ini
C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-602162358-1801674531-1005Core.job
C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-602162358-1801674531-1005UA.job
C:\WINDOWS\Tasks\MP Scheduled Scan.job
C:\WINDOWS\Tasks\SA.DAT
C:\WINDOWS\Tasks\User_Feed_Synchronization-{683CD518-5D3E-4546-AE4B-855F5DFEEAB7}.job
.
———————-\\ Registry
.
.
———————-\\ Files & Folders
.
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Privacy Guardian
C:\PROGRA~1\Privacy Guardian
==> Rogues <==
.
———————-\\ Scan completed at 19:25.50
.
C:\Rooter$\Rooter_3.txt - (19/08/2009 | 19:25.50)



I hope these 2 files help…..
BTW:….I'm not too keen about having my real name listed in some of the
items above….
So when you say I can,I'd like to delete some or all as soon as possible….

THANK YOU VERY MUCH for your help….. :thumbup:


Later…..Ron.M……. B) …..
Ron.M,

I believe I've removed you name from the logs.

Let's try this.

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Dear Tomk;…

I believe I've removed you name from the logs.

You did & Thank you….

I downloaded & ran TFC…..It rebooted without leaving a file to upload……

I already have MBAM on my desktop….However….
BEFORE I got that "Devil" on my desktop I had no problem updateing MBAM…..
Today when I tried to update it , I got the error message below..==>
[attachment removed]
If you like , I'll uninstall my version of MBAM, download yours & install it, re-run MBAM
& re-post with the newer results…Just say the word….

I ran it anyway & here's the log:…

Malwarebytes' Anti-Malware 1.39
Database version: 2421
Windows 5.1.2600 Service Pack 3

8/20/2009 12:12:10 PM
mbam-log-2009-08-20 (12-12-10).txt

Scan type: Quick Scan
Objects scanned: 79532
Time elapsed: 4 minute(s), 17 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Here's the HiJackThis Log;…

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:19:48 AM, on 8/20/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\slserv.exe
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SPEEDB~1\VideoAcceleratorEngine.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Ron.M\Desktop\New Folder\NetZero\exec.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\Program Files\Greenshot\Greenshot.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\LIVING~1.SCR
C:\Documents and Settings\Ron.M\Desktop\New Folder\NetZero\exec.exe
C:\Documents and Settings\Ron.M\Desktop\New Folder\NetZero\qsacc\x1exec.exe
C:\Documents and Settings\Ron.M\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.netzero.net/s/search?r=minisearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.netzero.net/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://my.netzero.net/s/sp?r=al&cf=sp&…amp;O=I&UT=
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Documents and Settings\Ron.M\Desktop\New Folder\NetZero\SearchEnh1.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Pop-up Blocker - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Documents and Settings\Ron.M\Desktop\New Folder\NetZero\qsacc\X1IEBHO.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Ask.com Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: (no name) - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - (no file)
O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [LXCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Documents and Settings\Ron.M\Desktop\New Folder\NetZero\exec.exe regrun
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: Greenshot.lnk = C:\Program Files\Greenshot\Greenshot.exe
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~1\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~1\sblsp.dll
O10 - Unknown file in Winsock LSP: c:\progra~1\speedb~1\sblsp.dll
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - http://pcpitstop.com/pcpitstop/pcpitstop.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.systemrequirementslab.com/srl_b…sreqlab_srl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1240693214421
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - http://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxcf_device - - C:\WINDOWS\system32\lxcfcoms.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: VideoAcceleratorService - Speedbit Ltd. - C:\PROGRA~1\SPEEDB~1\VideoAcceleratorService.exe

–
End of file - 8866 bytes


One of us can do the name thing again….


When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.

I did not see that show up…
Right after scanning up popped the log file….


Also please describe how your computer behaves at the moment.

At this moment it seems OK…..However as you said ("" Absence of symptoms does not mean that everything is clear."")
it doesn't mean all is well……SOOoooo…..


Have a GREAT day…….



Later…..Ron.M…… :popcorn:
Ron.M,

Your Mbam is out-of-date. You need to update it.

Start it, Click on the Updates tab, then click the Check of updates button.

Then please re-run the scan. (I don't expect much from it but I'd like to see it)

Then:


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Tomk;….

NOT one word of the following has ANY anger,sarcasm or maliciousness behind them….That said;….

In your last post you said:…""Your Mbam is out-of-date. You need to update it.""

From an earlier post I made;…""Today when I tried to update it , I got the error message below..==>
[attachment removed]
So I decided to uninstall my version & download & install your version (from the link)….
When I tried to update it after I installed it I got this:….
[attachment removed]
Exactly the same error message….
I ran it anyway & here's the log:…..

Malwarebytes' Anti-Malware 1.40
Database version: 2551
Windows 5.1.2600 Service Pack 3

8/21/2009 6:18:14 PM
mbam-log-2009-08-21 (18-18-14).txt

Scan type: Quick Scan
Objects scanned: 83265
Time elapsed: 5 minute(s), 27 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



Now for Kaspersky:….
What a fun day with that……
I went to the site link you put in your post….
I'm on dial-up with NetZero…Kaspersky starts to download files etc….
Long story short:….There's 123MB + of stuff being downloaded to my computer…..After 5 + hours
of baby sitting this , (NetZero cuts you offline after 1 hour of inactivity–so I have to come back & move something on a webpage to keep it online ) I come back & hit any keyboard key to bring it back & I get the BSOD!!!!…..See below;…
[attachment removed]
That is the error message that was sent to MS for the BSOD….
As much as I would've liked to have taken a pix of the actual BSOD , I could not….
We seem to be headed in the wrong direction….

EDIT;….Sunday , Aug,23,09…Mr.Tomk:…

Here's what I did today…
In the BSOD graphic there's a link to Microsoft……See below:…

Follow these steps to solve the problem with a device driver
You received this message because a device driver installed on your computer caused Windows to stop unexpectedly. This type of error is referred to as a "stop error." A stop error requires you to restart your computer.
Troubleshooting
——————————————————————————–
Depending on which situation is applicable to you, do one of the following:
If this problem occurred after you installed a new hardware device on your computer, the problem might be caused by the device driver. Use the Dell Driver Reset Tool or uninstall the driver.
How do I disable or uninstall a device driver?
Click Start, and then click Control Panel. If you are using Classic View, click Switch to Category View.
Click Performance and Maintenance, and then click System.
Click the Hardware tab, and then click Device Manager.
Click the plus sign (+) next to the faulting device. You should now see the device listed.
Right-click the device, and then click Disable or Uninstall.
If this problem occurred after you installed new software, the software might have installed a driver that caused the problem. Try uninstalling the software.
How do I uninstall a program?
Click Start, click Control Panel, and then click Add or Remove Programs.
Click Change or Remove Programs, click the program you want to remove, and then click Change/Remove or Remove.
Note
If the program that you want to uninstall isn't listed, it might not have been written for this version of Windows. To uninstall the program, check the information that came with the program.
If you don't know the specific driver or software, try performing a System Restore.
Go online to check for updated drivers for a device driver on the Windows Update website
Go online to the Windows Update website:
Windows Update
Note
If Microsoft Update is installed, you'll be taken to the Microsoft Update website.
Click Custom to check for available updates.
In the left pane, under Select by Type, click Hardware, Optional. Select the updates for a device driver, click Review and install updates, and then click Install Updates.
For information about your support options, go online to the Support.Dell.Com website.

I did NOT install ANY new hardware , software , OR drivers , so I have NO clue what they're talking about….
I went to the Dell site & downloaded the "Dell Driver Reset Tool ….I saved it to desktop & did NOT install it…
I then turned off my screensaver & went back to the "Kaspersky" link…(This at about 10:00 AM )….
5 + hours later it finally fully downloaded ALL 123+ MB's….
I started the scan as you requested….It ran for 42 minutes….
Here's the report:….
——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Sunday, August 23, 2009
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Sunday, August 23, 2009 22:53:03
Records in database: 2681820
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\

Scan statistics:
Objects scanned: 34646
Threats found: 0
Infected objects found: 0
Suspicious objects found: 0
Scan duration: 00:42:20

No threats found. Scanned area is clean.

Selected area has been scanned.

Persistence paid off !!!….



Later…Ron.M….. :popcorn:
Ron.M,

I completely missed that you had already tried to update Mbam. :blush: Sorry about that.

We haven't yet found the cause of your issues. Let's do this:

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Mr.Tomk;…

A couple of quick questions before they get lost in the shuffle of my mind…. :rofl:
1st:…Can you tell my why I can not update MBAM ???(The error code thing ???)
2nd:…Can you explain the BSOD when I first tried to run Kaspersky ???

Here's the ComboFix log you asked for:….

ComboFix 09-08-24.05 - Ron.M 08/24/2009 15:23.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.551 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1351 [VPS 090824-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\Installer\159cd77.msi

.
((((((((((((((((((((((((( Files Created from 2009-07-24 to 2009-08-24 )))))))))))))))))))))))))))))))
.

2009-08-22 01:09 . 2009-08-03 20:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-22 01:09 . 2009-08-22 01:09 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-22 01:09 . 2009-08-03 20:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-20 02:23 . 2009-08-20 19:52 ——– d—–w- C:\Rooter$
2009-08-17 17:47 . 2009-08-17 17:47 ——– d—–w- c:\documents and settings\Ron.M\Application Data\Blitware
2009-08-16 21:40 . 2009-08-22 21:11 ——– d—–w- c:\documents and settings\Ron.M\Application Data\vlc
2009-08-11 21:30 . 2009-08-12 00:49 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-08-11 21:30 . 2009-08-12 00:49 ——– d—–w- c:\program files\NOS
2009-08-02 20:54 . 2009-08-02 20:54 16344 —ha-w- c:\windows\system32\mlfcache.dat
2009-08-02 20:19 . 2009-08-02 20:19 ——– d—–w- c:\documents and settings\Ron.M\Application Data\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
2009-08-02 20:19 . 2009-08-02 19:25 38208 —-a-w- c:\documents and settings\Ron.M\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-08-02 20:19 . 2009-08-02 20:19 ——– d—–w- c:\program files\Market Samurai
2009-08-02 20:19 . 2009-08-02 19:25 38208 —-a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-08-02 20:19 . 2009-08-02 20:19 ——– d—–w- c:\program files\Common Files\Adobe AIR

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-24 22:27 . 2009-04-26 21:54 ——– d—–w- c:\documents and settings\Ron.M\Application Data\DNA
2009-08-24 20:06 . 2009-04-26 21:54 ——– d—–w- c:\program files\DNA
2009-08-20 20:07 . 2009-04-30 21:32 1 —-a-w- c:\documents and settings\Ron.M\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-08-17 18:37 . 2009-04-13 22:14 ——– d—–w- c:\program files\Lx_cats
2009-08-17 16:10 . 2009-04-11 23:51 1279456 —-a-w- c:\windows\system32\aswBoot.exe
2009-08-17 16:06 . 2009-04-11 23:51 93392 —-a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-17 16:06 . 2009-04-11 23:51 94160 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-17 16:05 . 2009-04-11 23:51 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-17 16:05 . 2009-04-11 23:51 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 16:04 . 2009-04-11 23:51 51376 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-17 16:04 . 2009-04-11 23:51 23152 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-17 16:03 . 2009-04-11 23:51 26944 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-17 16:02 . 2009-04-11 23:51 97480 —-a-w- c:\windows\system32\AvastSS.scr
2009-08-10 00:57 . 2009-04-26 21:54 ——– d—–w- c:\documents and settings\Ron.M\Application Data\BitTorrent
2009-08-05 18:09 . 2009-04-16 01:16 ——– d—–w- c:\program files\SpeedBit Video Accelerator
2009-08-05 09:01 . 2008-04-14 08:42 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-01 01:19 . 2009-05-16 22:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-25 17:53 . 2009-07-25 17:53 ——– d—–w- c:\program files\PCPitstop
2009-07-17 19:01 . 2008-04-14 08:41 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-15 02:59 . 2009-06-04 19:59 ——– d—–w- c:\program files\Free Offers from Freeze.com
2009-07-14 06:43 . 2008-04-14 08:42 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-09 01:00 . 2009-07-09 01:00 ——– d—–w- c:\program files\IGC
2009-07-09 01:00 . 2009-04-03 16:46 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-07 18:40 . 2009-07-07 19:29 801992 —-a-w- c:\documents and settings\All Users\Application Data\NetZero\Isp\NZHiSpeedUpdate.exe
2009-07-07 16:34 . 2009-07-07 04:36 ——– d—–w- c:\documents and settings\All Users\Application Data\DriverCure
2009-07-07 04:36 . 2009-07-07 04:36 ——– d—–w- c:\documents and settings\Ron.M\Application Data\DriverCure
2009-07-07 04:36 . 2009-07-07 04:36 ——– d—–w- c:\documents and settings\All Users\Application Data\ParetoLogic
2009-07-04 23:06 . 2009-07-04 23:06 ——– d—–w- c:\program files\QuickTime
2009-06-29 16:12 . 2008-04-14 08:42 827392 —-a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2009-07-22 05:33 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2008-04-14 08:41 17408 —-a-w- c:\windows\system32\corpol.dll
2009-06-26 09:41 . 2008-04-14 08:41 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:41 . 2008-04-14 08:42 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:41 . 2008-04-14 08:42 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:41 . 2008-04-14 08:42 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:41 . 2008-04-14 08:42 136704 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:41 . 2008-04-14 08:41 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-24 10:28 . 2008-04-14 03:01 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2008-04-14 08:42 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2008-04-14 08:41 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2008-04-14 08:42 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2008-04-14 08:42 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 16:19 . 2009-04-03 16:23 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2008-04-14 08:41 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:17 . 2008-04-14 08:42 134144 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-06 00:25 . 2009-06-06 00:25 1002044 —-a-w- c:\windows\system32\IDPExe.zip
2009-06-06 00:22 . 2009-06-06 00:22 1669117 —-a-w- c:\windows\system32\IDPSig.zip
2009-06-03 19:09 . 2008-04-14 08:42 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-05-29 01:23 . 2009-05-29 01:22 70984 —-a-w- c:\documents and settings\Ron.M\g2mdlhlpx.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NetZero_uoltray"="c:\documents and settings\Ron.M\Desktop\New Folder\NetZero\exec.exe" [2008-05-07 1701376]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-04-26 321344]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-07-12 160592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-04 148888]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"LXCFCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll" [2005-07-20 73728]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]

c:\documents and settings\Ron.M\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
Greenshot.lnk - c:\program files\Greenshot\Greenshot.exe [2009-5-16 528384]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [4/11/2009 4:51 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/11/2009 4:51 PM 20560]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm –> c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm [?]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S3 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [5/18/2009 1:16 PM 12672]
.
Contents of the 'Scheduled Tasks' folder

2009-08-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-602162358-1801674531-1005Core.job
- c:\documents and settings\Ron.M\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-25 20:37]

2009-08-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-602162358-1801674531-1005UA.job
- c:\documents and settings\Ron.M\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-25 20:37]

2009-08-24 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 02:20]

2009-08-24 c:\windows\Tasks\User_Feed_Synchronization-{683CD518-5D3E-4546-AE4B-855F5DFEEAB7}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 01:36]
.
- - - - ORPHANS REMOVED - - - -

BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)


.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = hxxp://my.netzero.net/s/sp?r=al&cf;=sp&ClientVersion;=8.4.0&mem;=ron.m&login;=3a0ba2a1607571fd0cce61dbca618e1b/ron.m:netzero.net/1239416131/30/sss.8.48463/&ts;=49dffd43&A;=739741990000009&B;=1212476400000&C;=1212476400000&D;=1222153200000&I;=8.NH4&N;=PLHSNAVUSERSSUSER&O;=I&UT;=
uInternet Settings,ProxyServer = http=127.0.0.1:7900
uInternet Settings,ProxyOverride = searchap.untd.com;127.0.0.1;localhost;*microsoft.com;*windowsupdate.com;*wustat.
windows.com;*test-speed.com;liveupdate.symantecliveupdate.com;*symantec.com;*.nai.com;*.networkass
ociates.com;cf.netzero.net;qs.netzero.net;*.quicken.com;*.pogo.com;
uSearchURL,(Default) = hxxp://my.netzero.net/s/search?r=minisearch
IE: Display All Images with Full Quality - c:\documents and settings\Ron.M\Desktop\New Folder\NetZero\qsacc\appres.dll/228
IE: Display Image with Full Quality - c:\documents and settings\Ron.M\Desktop\New Folder\NetZero\qsacc\appres.dll/227
LSP: c:\progra~1\SPEEDB~1\sblsp.dll
TCP: {F4D53855-1F88-4FE7-873A-E5693E89EF5E} = 64.136.52.73 64.136.44.73
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-24 15:27
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCFCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …


c:\windows\TEMP\TMP000000A63D8BE5F6C41CCA17 524288 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-823518204-602162358-1801674531-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(512)
c:\progra~1\SPEEDB~1\sblsp.dll
c:\program files\SpeedBit Video Accelerator\ConfigDB.dll
c:\program files\SpeedBit Video Accelerator\Accelerator.dll
c:\windows\system32\WININET.dll
c:\program files\SpeedBit Video Accelerator\CommPipe.dll
c:\program files\SpeedBit Video Accelerator\Collector.dll
.
Completion time: 2009-08-24 15:28
ComboFix-quarantined-files.txt 2009-08-24 22:28

Pre-Run: 30,945,005,568 bytes free
Post-Run: 30,935,543,808 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

199 — E O F — 2009-08-24 21:12


Once again, the name removal exercize….You or me ???

I really hope all this helps…. :D

Thank you VERY much…..

Later….Ron.M….. :popcorn: ….

Edit: Name removed to protect the innocent. B)

A couple of quick questions before they get lost in the shuffle of my mind…. rofl.gif
1st:…Can you tell my why I can not update MBAM ???(The error code thing ???)
2nd:…Can you explain the BSOD when I first tried to run Kaspersky ???

Unfortunately no. I still have not found the cause for that behavior.

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    Rootkit::
    c:\windows\TEMP\TMP000000A63D8BE5F6C41CCA17
    
    RegLock::
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

We Need to check for Rootkits with RootRepeal
  • Download RootRepeal from one of the following locations and save it to your desktop.
  • Open [external image: Posted Image] on your desktop.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • In the Select Scan dialog, check:
    • Drivers
    • Processes
    • SSDT
    • Hidden Services
  • Push Ok
  • Check the box for your main system drive (Usually C:), and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt.
Mr. Tomk;….

Here's the newest ComboFix report you asked for;…..


ComboFix 09-08-24.05 - Ron.M 08/25/2009 11:44.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.589 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Ron.M\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1351 [VPS 090825-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((( Files Created from 2009-07-25 to 2009-08-25 )))))))))))))))))))))))))))))))
.

2009-08-22 01:09 . 2009-08-03 20:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-22 01:09 . 2009-08-22 01:09 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-22 01:09 . 2009-08-03 20:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-20 02:23 . 2009-08-20 19:52 ——– d—–w- C:\Rooter$
2009-08-17 17:47 . 2009-08-17 17:47 ——– d—–w- c:\documents and settings\Ron.M\Application Data\Blitware
2009-08-16 21:40 . 2009-08-22 21:11 ——– d—–w- c:\documents and settings\Ron.M\Application Data\vlc
2009-08-11 21:30 . 2009-08-12 00:49 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-08-11 21:30 . 2009-08-12 00:49 ——– d—–w- c:\program files\NOS
2009-08-02 20:54 . 2009-08-02 20:54 16344 —ha-w- c:\windows\system32\mlfcache.dat
2009-08-02 20:19 . 2009-08-02 20:19 ——– d—–w- c:\documents and settings\Ron.M\Application Data\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
2009-08-02 20:19 . 2009-08-02 19:25 38208 —-a-w- c:\documents and settings\Ron.M\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-08-02 20:19 . 2009-08-02 20:19 ——– d—–w- c:\program files\Market Samurai
2009-08-02 20:19 . 2009-08-02 19:25 38208 —-a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-08-02 20:19 . 2009-08-02 20:19 ——– d—–w- c:\program files\Common Files\Adobe AIR

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-25 18:48 . 2009-04-26 21:54 ——– d—–w- c:\program files\DNA
2009-08-25 18:48 . 2009-04-26 21:54 ——– d—–w- c:\documents and settings\Ron.M\Application Data\DNA
2009-08-20 20:07 . 2009-04-30 21:32 1 —-a-w- c:\documents and settings\Ron.M\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-08-17 18:37 . 2009-04-13 22:14 ——– d—–w- c:\program files\Lx_cats
2009-08-17 16:10 . 2009-04-11 23:51 1279456 —-a-w- c:\windows\system32\aswBoot.exe
2009-08-17 16:06 . 2009-04-11 23:51 93392 —-a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-17 16:06 . 2009-04-11 23:51 94160 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-17 16:05 . 2009-04-11 23:51 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-17 16:05 . 2009-04-11 23:51 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 16:04 . 2009-04-11 23:51 51376 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-17 16:04 . 2009-04-11 23:51 23152 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-17 16:03 . 2009-04-11 23:51 26944 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-17 16:02 . 2009-04-11 23:51 97480 —-a-w- c:\windows\system32\AvastSS.scr
2009-08-10 00:57 . 2009-04-26 21:54 ——– d—–w- c:\documents and settings\Ron.M\Application Data\BitTorrent
2009-08-05 18:09 . 2009-04-16 01:16 ——– d—–w- c:\program files\SpeedBit Video Accelerator
2009-08-05 09:01 . 2008-04-14 08:42 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-01 01:19 . 2009-05-16 22:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-25 17:53 . 2009-07-25 17:53 ——– d—–w- c:\program files\PCPitstop
2009-07-17 19:01 . 2008-04-14 08:41 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-15 02:59 . 2009-06-04 19:59 ——– d—–w- c:\program files\Free Offers from Freeze.com
2009-07-14 06:43 . 2008-04-14 08:42 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-09 01:00 . 2009-07-09 01:00 ——– d—–w- c:\program files\IGC
2009-07-09 01:00 . 2009-04-03 16:46 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-07 18:40 . 2009-07-07 19:29 801992 —-a-w- c:\documents and settings\All Users\Application Data\NetZero\Isp\NZHiSpeedUpdate.exe
2009-07-07 16:34 . 2009-07-07 04:36 ——– d—–w- c:\documents and settings\All Users\Application Data\DriverCure
2009-07-07 04:36 . 2009-07-07 04:36 ——– d—–w- c:\documents and settings\Ron.M\Application Data\DriverCure
2009-07-07 04:36 . 2009-07-07 04:36 ——– d—–w- c:\documents and settings\All Users\Application Data\ParetoLogic
2009-07-04 23:06 . 2009-07-04 23:06 ——– d—–w- c:\program files\QuickTime
2009-06-29 16:12 . 2008-04-14 08:42 827392 ——w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2009-07-22 05:33 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2008-04-14 08:41 17408 —-a-w- c:\windows\system32\corpol.dll
2009-06-26 09:41 . 2008-04-14 08:41 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:41 . 2008-04-14 08:42 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:41 . 2008-04-14 08:42 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:41 . 2008-04-14 08:42 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:41 . 2008-04-14 08:42 136704 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:41 . 2008-04-14 08:41 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-24 10:28 . 2008-04-14 03:01 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2008-04-14 08:42 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2008-04-14 08:41 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2008-04-14 08:42 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2008-04-14 08:42 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 16:19 . 2009-04-03 16:23 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2008-04-14 08:41 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:17 . 2008-04-14 08:42 134144 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-06 00:25 . 2009-06-06 00:25 1002044 —-a-w- c:\windows\system32\IDPExe.zip
2009-06-06 00:22 . 2009-06-06 00:22 1669117 —-a-w- c:\windows\system32\IDPSig.zip
2009-06-03 19:09 . 2008-04-14 08:42 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-05-29 01:23 . 2009-05-29 01:22 70984 —-a-w- c:\documents and settings\Ron.M\g2mdlhlpx.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-08-24_22.27.21 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-25 18:32 . 2009-08-25 18:32 167936 c:\windows\ERDNT\AutoBackup\8-25-2009\Users\00000002\UsrClass.dat
+ 2009-08-25 18:32 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\8-25-2009\ERDNT.EXE
+ 2009-08-25 18:32 . 2009-08-25 18:32 5967872 c:\windows\ERDNT\AutoBackup\8-25-2009\Users\00000001\ntuser.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NetZero_uoltray"="c:\documents and settings\Ron.M\Desktop\New Folder\NetZero\exec.exe" [2008-05-07 1701376]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-04-26 321344]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-07-12 160592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-04 148888]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"LXCFCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll" [2005-07-20 73728]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]

c:\documents and settings\Ron.M\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
Greenshot.lnk - c:\program files\Greenshot\Greenshot.exe [2009-5-16 528384]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [4/11/2009 4:51 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/11/2009 4:51 PM 20560]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm –> c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm [?]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S3 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [5/18/2009 1:16 PM 12672]
.
Contents of the 'Scheduled Tasks' folder

2009-08-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-602162358-1801674531-1005Core.job
- c:\documents and settings\Ron.M\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-25 20:37]

2009-08-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-823518204-602162358-1801674531-1005UA.job
- c:\documents and settings\Ron.M\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-07-25 20:37]

2009-08-25 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 02:20]

2009-08-25 c:\windows\Tasks\User_Feed_Synchronization-{683CD518-5D3E-4546-AE4B-855F5DFEEAB7}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 01:36]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = hxxp://my.netzero.net/s/sp?r=al&cf;=sp&ClientVersion;=8.4.0&mem;=ron.m&login;=3a0ba2a1607571fd0cce61dbca618e1b/ron.m:netzero.net/1239416131/30/sss.8.48463/&ts;=49dffd43&A;=739741990000009&B;=1212476400000&C;=1212476400000&D;=1222153200000&I;=8.NH4&N;=PLHSNAVUSERSSUSER&O;=I&UT;=
uSearchURL,(Default) = hxxp://my.netzero.net/s/search?r=minisearch
IE: Display All Images with Full Quality - c:\documents and settings\Ron.M\Desktop\New Folder\NetZero\qsacc\appres.dll/228
IE: Display Image with Full Quality - c:\documents and settings\Ron.M\Desktop\New Folder\NetZero\qsacc\appres.dll/227
LSP: c:\progra~1\SPEEDB~1\sblsp.dll
TCP: {F4D53855-1F88-4FE7-873A-E5693E89EF5E} = 64.136.52.73 64.136.44.73
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-25 11:49
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCFCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-823518204-602162358-1801674531-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(516)
c:\progra~1\SPEEDB~1\sblsp.dll
c:\program files\SpeedBit Video Accelerator\ConfigDB.dll
c:\program files\SpeedBit Video Accelerator\Accelerator.dll
c:\windows\system32\WININET.dll
c:\program files\SpeedBit Video Accelerator\CommPipe.dll
c:\program files\SpeedBit Video Accelerator\Collector.dll

- - - - - - - > 'explorer.exe'(2328)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe
c:\progra~1\SPEEDB~1\VideoAcceleratorEngine.exe
c:\documents and settings\Ron.M\Desktop\New Folder\NetZero\qsacc\X1Exec.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-08-25 11:53 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-25 18:53
ComboFix2.txt 2009-08-24 22:28

Pre-Run: 30,930,800,640 bytes free
Post-Run: 30,886,395,904 bytes free

188 — E O F — 2009-08-24 21:12


Altho you did not ask for me to post the RootRepealReport , I'm assuming
you did not want it to just sit on my desktop…So here it is:….


ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/25 12:05
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================

Drivers
——————-
Name: catchme.sys
Image Path: C:\ComboFix\catchme.sys
Address: 0xF78C6000 Size: 31744 File Visible: No Signed: -
Status: -

Name: Combo-Fix.sys
Image Path: Combo-Fix.sys
Address: 0xF760E000 Size: 60416 File Visible: No Signed: -
Status: -

Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xA90FF000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7AE2000 Size: 8192 File Visible: No Signed: -
Status: -

Name: PROCEXP90.SYS
Image Path: C:\WINDOWS\system32\Drivers\PROCEXP90.SYS
Address: 0xF7B58000 Size: 6464 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA7C03000 Size: 49152 File Visible: No Signed: -
Status: -

SSDT
——————-
#: 025 Function Name: NtClose
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa911f6b8

#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa911f574

#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa911fa52

#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa911f14c

#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa911f64e

#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa911f08c

#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa911f0f0

#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa911f76e

#: 204 Function Name: NtRestoreKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa911f72e

#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xa911f8ae

==EOF==


THANK you for your help & removing my name from the item lists….

Have a GREAT day…..


Later…Ron.M… :popcorn:
Ron.M,

Altho you did not ask for me to post the RootRepealReport , I'm assuming
you did not want it to just sit on my desktop…So here it is:….

Oops. :blush: You are correct. I did actually want to see it.

Things are looking good. How is it running?
Mr.Tomk;….

Things are looking good. How is it running?

About the same…Nothing dramatic to report…

Ya missed a couple places where my name is listed (in lower case ) in some items… :smack: …..You want to get them or shall I do it ???
They're right under:==>
"""Supplementary Scan """


What do we do next ???


Later…Ron.M…. :popcorn:
My dear Mr.Tomk;…..

With ALL DUE RESPECT:…..

Does this mean you still have the Devil on your desktop?

From Post #1:

System restore was gone also,so I used Erunt to get rid of that "Alien"…

Just a suggestion: You might want to go back to post #1 & refresh your memory as I often do…

Mbam won't update?

At this moment that is 100% correct !!!

Are you still getting BSOD's?

I got only the one when I tried to start the Kaspersky scan….


Anything else ????


Later….Ron.M…. :popcorn:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI