rocker44
Topic Starter
I have tried everything the different web sites and forums say to do to remove this. I have tried Malwarebytes,AVG,Symantec,SpyDr. and nothing. I have tried Gmer and DDS. Here are the logs of all..Please help
rocker44
MALWAREBYTES LOG:
Malwarebytes' Anti-Malware 1.40
Database version: 2628
Windows 5.1.2600 Service Pack 2
8/15/2009 6:36:17 AM
mbam-log-2009-08-15 (06-36-09).txt
Scan type: Quick Scan
Objects scanned: 101613
Time elapsed: 7 minute(s), 24 second(s)
Memory Processes Infected: 2
Memory Modules Infected: 0
Registry Keys Infected: 11
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 6
Files Infected: 13
Memory Processes Infected:
C:\Program Files\Ascentive\Performance Center\ApcMain.exe (Adware.Ascentive) -> No action taken.
C:\Program Files\Ascentive\PC SpeedScan Pro\PCSpeedScan.exe (Rogue.PCSpeedScan) -> No action taken.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{10b3a0d2-3960-4d38-8158-d828a30f8db1} (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{497dddb6-6eee-4561-9621-b77dc82c1f84} (Adware.Ascentive) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{4e980492-027b-47f1-a7ab-ab086dacbb9e} (Adware.Ascentive) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{5ead8321-fcbb-4c3f-888c-ac373d366c3f} (Adware.Ascentive) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{31f3cf6e-a71a-4daa-852b-39ac230940b4} (Adware.Ascentive) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe (Adware.DoubleD) -> No action taken.
HKEY_CLASSES_ROOT\aquaplay (Trojan.DNSChanger) -> No action taken.
HKEY_CURRENT_USER\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\DoubleD (Adware.DoubleD) -> No action taken.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\system32\SysRestore.dll (Adware.Ascentive) -> No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Documents and Settings\allen\Local Settings\Application Data\DoubleD (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Application Data\DoubleD\Desktop Smiley Toolbar (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Application Data\DoubleD\Desktop Smiley Toolbar\3.11.5.14760 (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Application Data\DoubleD\Desktop Smiley Toolbar\3.11.5.14760\bin (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\Data (Adware.DoubleD) -> No action taken.
Files Infected:
C:\Program Files\Ascentive\Performance Center\ApcMain.exe (Adware.Ascentive) -> No action taken.
C:\Program Files\Ascentive\PC SpeedScan Pro\PCSpeedScan.exe (Rogue.PCSpeedScan) -> No action taken.
C:\WINDOWS\system32\SysRestore.dll (Adware.Ascentive) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Application Data\DoubleD\Desktop Smiley Toolbar\3.11.5.14760\bin\stbup.exe (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\bg.jpg (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\CurrentVersion.xml (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\icon.ico (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\productinfo.dll (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\Setup.exe (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\stbup.exe (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\tdf.dat (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\Data\ProductInfo.mx (Adware.DoubleD) -> No action taken.
C:\Program Files\SFX Machine LT.dll (Spyware.OnlineGames) -> No action taken.
DDS LOG:
DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 13:01:06.95 on Sat 08/15/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2045.1360 [GMT -4:00]
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative Professional\E-MU USB Audio\E-MU USB Audio\EmuUsbAudioCP.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
D:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\CodeMeter\Runtime\bin\CodeMeter.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
D:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\emaudsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\allen\Desktop\dds.pif
============== Pseudo HJT Report ===============
uDefault_Page_URL = hxxp://www.msn.com
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - No File
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No File
BHO: {AA58ED58-01DD-4d91-8333-CF10577473F7} - No File
BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No File
BHO: {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - No File
BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [Performance Center] c:\program files\ascentive\performance center\ApcMain.exe -m
uRun: [E-MU USB Audio Control Panel] "c:\program files\creative professional\e-mu usb audio\e-mu usb audio\EmuUsbAudioCP.exe"
uRun: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\RegistryBooster.exe /S
uRun: [UniblueSpeedUpMyPC] c:\program files\uniblue\speedupmypc\Launcher.exe -minimize
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [Lexmark X74-X75] "c:\program files\lexmark x74-x75\lxbbbmgr.exe"
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [H2O] c:\program files\syncrosoft\pos\h2o\cledx.exe
mRun: [VerizonServicepoint.exe] "c:\program files\verizon\vsp\VerizonServicepoint.exe" /AUTORUN
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\docume~1\allen\startm~1\programs\startup\openof~1.lnk - d:\program files\openoffice.org 2.4\program\quickstart.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,77,65,62,5c,72,65,6c-,61,74,65,64,2e,68,74,6d,00
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07}
LSP: c:\windows\system32\dcsource.dll
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1248703385718
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Notify: NavLogon - c:\windows\system32\NavLogon.dll
AppInit_DLLs: c:\progra~1\google\google~4\GOEC62~1.DLL
================= FIREFOX ===================
FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-7-21 130936]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2006-9-6 337592]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2006-9-6 54968]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2006-7-19 192160]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2006-7-19 169632]
R2 CodeMeter.exe;CodeMeter Runtime Server;c:\program files\codemeter\runtime\bin\CodeMeter.exe [2009-4-3 1680704]
R2 emaudsv;E-MU Audio Service;c:\windows\system32\emaudsv.exe [2006-11-20 10240]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2006-10-24 1813184]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [2009-8-1 33792]
R3 emusba10;E-MU USB-Audio 1.0 Driver;c:\windows\system32\drivers\emusba10.sys [2006-11-20 142208]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-8-12 101936]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090814.004\naveng.sys [2009-8-14 87888]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090814.004\navex15.sys [2009-8-14 875728]
S0 bhpftp;bhpftp;c:\windows\system32\drivers\hkztnm.sys –> c:\windows\system32\drivers\hkztnm.sys [?]
S2 gupdate1ca0a71a4770151;Google Update Service (gupdate1ca0a71a4770151);c:\program files\google\update\GoogleUpdate.exe [2009-7-21 133104]
S3 EraserUtilDrv10910;EraserUtilDrv10910;\??\c:\program files\common files\symantec shared\eengine\eraserutildrv10910.sys –> c:\program files\common files\symantec shared\eengine\EraserUtilDrv10910.sys [?]
S3 GoogleDesktopManager-110408-113106;Google Desktop Manager 5.8.811.4345;c:\program files\google\google desktop search\GoogleDesktop.exe [2009-6-24 30192]
S3 Radialpoint Security Services;Verizon PC Security Checkup Service;c:\program files\verizon\pc security checkup\RpsSecurityAwareR.exe [2009-8-14 170736]
S3 Rpcsvrvca_pr;Rpcsvrvca_pr;c:\windows\system32\drivers\amdk6.sys [2004-8-3 36992]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2006-10-24 116416]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-7-21 348752]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-7-21 1095560]
=============== Created Last 30 ================
2009-08-15 07:47 –d—– c:\program files\Trend Micro
2009-08-14 23:50 –d—– c:\docume~1\allen\applic~1\Malwarebytes
2009-08-14 23:49 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-14 23:49 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-14 23:49 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-08-14 23:49 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-08-14 14:35 –d—– c:\program files\Radialpoint
2009-08-14 12:09 73,728 a——- c:\windows\system32\rmpHTML.dll
2009-08-14 12:09 45,056 a——- c:\windows\system32\AxrmpHTML.dll
2009-08-14 12:09 868,352 a——- c:\windows\system32\rmpHTML.ocx
2009-08-14 12:09 249 a——- c:\windows\system32\windefht.bin
2009-08-14 12:09 –d—– C:\Abdio
2009-08-14 12:00 -cd-h— c:\docume~1\alluse~1\applic~1\{D9010FDD-3EED-44D9-9863-33B2D7362EC5}
2009-08-14 11:33 186,624 a——- c:\windows\system32\dcsource.dll
2009-08-14 11:32 –d—– c:\program files\BestAddress HTML Editor 2009 Professional
2009-08-14 11:24 –d—– c:\program files\qxyeed
2009-08-13 14:14 286,720 a——- c:\windows\iun507.exe
2009-08-13 14:14 –d—– c:\program files\PersonalWebKit3
2009-08-12 20:29 –d—– c:\documents and settings\allen\ErrorLogs
2009-08-12 19:57 –d—– c:\program files\Uniblue
2009-08-12 19:57 -cd-h— c:\docume~1\alluse~1\applic~1\{C4C0E335-EDDF-46A0-A57D-F3802AE44275}
2009-08-12 12:42 0 a——- c:\windows\VPC32.INI
2009-08-12 12:40 109,744 a——- c:\windows\system32\drivers\SYMEVENT.SYS
2009-08-12 12:40 48,816 a——- c:\windows\system32\S32EVNT1.DLL
2009-08-12 12:38 –d—– c:\program files\Symantec
2009-08-12 12:38 –d—– c:\program files\Symantec AntiVirus
2009-08-12 12:38 –d—– c:\docume~1\alluse~1\applic~1\Symantec
2009-08-12 12:33 –d—– C:\Symantec10.1.5
2009-08-10 22:28 –d—– c:\program files\common files\xing shared
2009-08-10 17:43 –d—– c:\docume~1\allen\applic~1\Forexyard
2009-08-10 17:42 –d—– C:\Forexyard
2009-08-08 22:53 –d—– c:\docume~1\allen\applic~1\Uniblue
2009-08-08 22:41 –d—– c:\docume~1\alluse~1\applic~1\Cakewalk
2009-08-08 22:29 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll
2009-08-08 22:29 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-08 22:29 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-08 22:29 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-08 21:43 –d—– c:\program files\MSXML 6.0
2009-08-08 21:41 –d—– c:\docume~1\allen\applic~1\Verizon
2009-08-08 21:41 –d—– c:\program files\Verizon
2009-08-08 21:41 –d—– c:\docume~1\alluse~1\applic~1\Verizon
2009-08-08 15:54 13 a——- c:\windows\system32\MSVC60SVV.DLL
2009-08-08 15:54 13 a——- c:\windows\MSOCREG.DAT
2009-08-04 13:16 57,344 a——- c:\windows\system32\Wnaspint.dll
2009-08-04 13:16 –d—– c:\program files\Acoustica Shared Effects
2009-08-04 13:16 –d—– c:\program files\Acoustica Mixcraft 3
2009-08-04 09:50 –d—– c:\docume~1\allen\applic~1\Digital Support
2009-08-04 09:49 –d—– c:\program files\Digital Support
2009-08-03 14:30 606,293 a——- c:\windows\system32\wbocx.ocx
2009-08-03 14:30 50,688 a——- c:\windows\system32\wbhelp2.dll
2009-08-03 14:30 –d—– c:\program files\Ipswitch
2009-08-03 13:41 319,488 a——- c:\windows\system32\PolarZIPLight.dll
2009-08-03 13:35 –d—– c:\docume~1\allen\applic~1\CoreFTP
2009-08-03 13:34 –d—– c:\program files\CoreFTP
2009-08-03 13:18 –d—– c:\docume~1\allen\applic~1\CoffeeCup Software
2009-08-02 11:32 189 a——- c:\windows\system32\.MySCMServerInfo
2009-08-02 11:32 –d—– c:\program files\DigiDesign
2009-08-01 22:23 –d—– c:\docume~1\alluse~1\applic~1\Steinberg
2009-08-01 22:12 –d—– c:\program files\common files\Steinberg
2009-08-01 19:01 87,040 a——- c:\windows\system32\ra32sipr.dll
2009-08-01 19:01 72,704 a——- c:\windows\system32\ra3228_8.dll
2009-08-01 19:01 21,504 a——- c:\windows\system32\ra32dnet.dll
2009-08-01 19:01 487,936 a——- c:\windows\system32\rmbe3260.dll
2009-08-01 19:01 352,768 a——- c:\windows\system32\pngu3263.dll
2009-08-01 19:01 131,072 a——- c:\windows\system32\pneng50.dll
2009-08-01 19:01 130,560 a——- c:\windows\system32\pnc3250.dll
2009-08-01 19:01 85,504 a——- c:\windows\system32\encdnet.dll
2009-08-01 19:01 81,920 a——- c:\windows\system32\ra3214_4.dll
2009-08-01 19:01 61,952 a——- c:\windows\system32\decdnet.dll
2009-08-01 18:59 33,792 a——- c:\windows\system32\drivers\cledx.sys
2009-08-01 18:59 147,425 a——- c:\windows\system32\SYNSOACC-Aide.chm
2009-08-01 18:59 120,468 a——- c:\windows\system32\SYNSOACC-Hilfe.chm
2009-08-01 18:59 114,279 a——- c:\windows\system32\SYNSOACC-Help.chm
2009-08-01 18:59 16,896 a——- c:\windows\system32\drivers\synasUSB.sys
2009-08-01 18:59 45,056 a——- c:\windows\system32\Synsopos.exe
2009-08-01 18:59 147,456 a——- c:\windows\system32\SynsoLChk.dll
2009-08-01 18:59 35,328 a——- c:\windows\system32\SYNSOACC.dll
2009-08-01 18:59 17,784 a——- c:\windows\system32\drivers\NSynas32.sys
2009-08-01 18:59 –d—– c:\program files\Syncrosoft
2009-08-01 14:45 –d—– c:\program files\Forex Strategy Builder
2009-07-30 14:01 416 a——- c:\windows\BeatBox.INI
2009-07-30 13:54 28 a——- c:\windows\Robota.INI
2009-07-30 11:17 1,294,336 a——- c:\windows\system32\vorbis.acm
2009-07-30 11:15 –d—– c:\program files\Image-Line
2009-07-30 10:20 0 a——- c:\windows\MusicStudio.INI
2009-07-30 10:19 –d—– c:\docume~1\alluse~1\applic~1\MAGIX
2009-07-30 10:19 –d—– c:\program files\common files\MAGIX Shared
2009-07-30 10:18 1,089,536 a——- c:\windows\system32\ROBOEX32.DLL
2009-07-30 10:18 49,152 a——- c:\windows\system32\INETWH32.dll
2009-07-30 10:18 –d—– c:\program files\MAGIX
2009-07-30 10:18 85,504 a——- c:\windows\system32\HtmlWH.dll
2009-07-30 10:18 663,552 a——- c:\windows\system32\mgxoschk.dll
2009-07-30 10:18 5,817 a——- c:\windows\mgxoschk.ini
2009-07-30 10:18 –d—– c:\windows\system32\MAGIX
2009-07-30 10:14 53,248 a——- c:\windows\system32\IKStompIO1API.dll
2009-07-30 10:06 –d—– c:\program files\common files\Acon Digital Media
2009-07-30 10:06 –d—– c:\program files\Acon Digital Media
2009-07-30 10:04 –d—– c:\docume~1\allen\applic~1\Thinstall
2009-07-30 00:58 –d—– c:\program files\EDIROL
2009-07-29 22:52 –d—– c:\docume~1\allen\applic~1\com.kewlshare.KewlManager.7FDCF29DEFD40899D06AD7AA1B082BD679DAC8B0.1
2009-07-29 01:20 594,432 -c—— c:\windows\system32\dllcache\msfeeds.dll
2009-07-29 01:20 55,296 -c—— c:\windows\system32\dllcache\msfeedsbs.dll
2009-07-28 14:44 73,728 a——- c:\windows\system32\javacpl.cpl
2009-07-27 10:55 -cd-h— c:\windows\ie8
2009-07-27 10:54 101,376 -c—— c:\windows\system32\dllcache\iecompat.dll
2009-07-27 10:54 1,985,536 -c—— c:\windows\system32\dllcache\iertutil.dll
2009-07-27 10:54 246,272 -c—— c:\windows\system32\dllcache\ieproxy.dll
2009-07-27 10:54 12,800 -c—— c:\windows\system32\dllcache\xpshims.dll
2009-07-27 10:54 11,067,392 -c—— c:\windows\system32\dllcache\ieframe.dll
2009-07-27 10:10 –d—– c:\windows\system32\CatRoot_bak
2009-07-27 10:10 272,128 -c—— c:\windows\system32\dllcache\bthport.sys
2009-07-27 10:10 2,186,112 -c—— c:\windows\system32\dllcache\ntoskrnl.exe
2009-07-27 10:10 2,142,720 -c—— c:\windows\system32\dllcache\ntkrnlmp.exe
2009-07-27 10:10 2,062,976 -c—— c:\windows\system32\dllcache\ntkrnlpa.exe
2009-07-27 10:10 2,020,864 -c—— c:\windows\system32\dllcache\ntkrpamp.exe
2009-07-27 10:10 453,632 -c—— c:\windows\system32\dllcache\mrxsmb.sys
2009-07-27 09:28 –d-h— c:\windows\msdownld.tmp
2009-07-27 01:13 19 a——- c:\documents and settings\allen\Settings.dat
2009-07-26 12:38 –d—– c:\program files\Steinberg
2009-07-26 12:38 –d—– c:\docume~1\allen\applic~1\Proteus VX
2009-07-26 12:37 1,706,800 ——– c:\windows\system32\gdiplus.dll
2009-07-25 18:25 –d—– c:\program files\Enigma Software Group
2009-07-25 16:32 69,632 ac—— c:\windows\system32\dllcache\ehresko.dll
2009-07-25 16:32 73,728 ac—— c:\windows\system32\dllcache\ehresja.dll
2009-07-25 16:32 69,632 ac—— c:\windows\system32\dllcache\ehresfr.dll
2009-07-25 16:32 69,632 ac—— c:\windows\system32\dllcache\ehresde.dll
2009-07-25 16:32 61,440 ac—— c:\windows\system32\dllcache\ehreschs.dll
2009-07-25 16:32 113,222 ac—— c:\windows\system32\dllcache\zoneclim.dll
2009-07-25 16:32 41,029 ac—— c:\windows\system32\dllcache\zcorem.dll
2009-07-25 16:32 36,937 ac—— c:\windows\system32\dllcache\zclientm.exe
2009-07-25 16:32 29,760 ac—— c:\windows\system32\dllcache\znetm.dll
2009-07-25 16:32 13,894 ac—— c:\windows\system32\dllcache\zonelibm.dll
2009-07-25 16:32 4,677 ac—— c:\windows\system32\dllcache\zeeverm.dll
2009-07-25 16:31 5,632 ac—— c:\windows\system32\dllcache\write.exe
2009-07-25 16:31 214,528 ac—— c:\windows\system32\dllcache\wordpad.exe
2009-07-25 16:31 221,184 ac—— c:\windows\system32\dllcache\wmpns.dll
2009-07-25 16:31 119,808 ac—— c:\windows\system32\dllcache\winmine.exe
2009-07-25 16:31 35,328 ac—— c:\windows\system32\dllcache\winchat.exe
2009-07-25 16:31 31,232 ac—— c:\windows\system32\dllcache\weitekp9.sys
2009-07-25 16:31 53,248 ac—— c:\windows\system32\dllcache\wamreg51.dll
2009-07-25 16:31 41,600 ac—— c:\windows\system32\dllcache\weitekp9.dll
2009-07-25 16:31 76,800 ac—— c:\windows\system32\dllcache\wam51.dll
2009-07-25 16:31 9,216 ac—— c:\windows\system32\dllcache\wamps51.dll
2009-07-25 16:31 363,520 ac—— c:\windows\system32\dllcache\w3svc.dll
2009-07-25 16:31 5,632 ac—— c:\windows\system32\dllcache\w3svapi.dll
2009-07-25 16:30 73,728 ac—— c:\windows\system32\dllcache\w3ext.dll
2009-07-25 16:30 48,256 ac—— c:\windows\system32\dllcache\w32.dll
2009-07-25 16:30 4,608 ac—— c:\windows\system32\dllcache\w3ctrs51.dll
2009-07-25 16:30 32,339 ac—— c:\windows\system32\dllcache\uniansi.dll
2009-07-25 16:30 103,424 ac—— c:\windows\system32\dllcache\uihelper.dll
2009-07-25 16:30 14,336 ac—— c:\windows\system32\dllcache\tsprof.exe
2009-07-25 16:30 31,232 ac—— c:\windows\system32\dllcache\tools.dll
2009-07-25 16:30 10,240 ac—— c:\windows\system32\dllcache\tmigrate.dll
2009-07-25 16:28 42,573 ac—— c:\windows\system32\dllcache\shvlzm.exe
2009-07-25 16:27 281,088 ac—— c:\windows\system32\dllcache\pinball.exe
2009-07-25 16:26 37,888 ac—— c:\windows\system32\dllcache\md5filt.dll
2009-07-25 16:25 6,144 ac—— c:\windows\system32\dllcache\kbdinpun.dll
2009-07-25 16:24 79,872 ac—— c:\windows\system32\dllcache\iislog51.dll
2009-07-25 16:24 60,928 ac—— c:\windows\system32\dllcache\iisclex4.dll
2009-07-25 16:24 19,456 ac—— c:\windows\system32\dllcache\iiscrmap.dll
2009-07-25 16:24 7,168 ac—— c:\windows\system32\dllcache\iisfecnv.dll
2009-07-25 16:24 6,656 ac—— c:\windows\system32\dllcache\iissync.exe
2009-07-25 16:24 3,584 ac—— c:\windows\system32\dllcache\iismui.dll
2009-07-25 16:24 145,408 ac—— c:\windows\system32\dllcache\iische51.dll
2009-07-25 16:24 25,088 ac—— c:\windows\system32\dllcache\iisadmin.dll
2009-07-25 16:23 10,096,640 ac—— c:\windows\system32\dllcache\hwxcht.dll
2009-07-25 16:23 61,440 ac—— c:\windows\system32\dllcache\httpod51.dll
2009-07-25 16:23 268,288 ac—— c:\windows\system32\dllcache\httpext.dll
2009-07-25 16:23 8,192 ac—— c:\windows\system32\dllcache\httpmb51.dll
2009-07-25 16:21 27,136 ac—— c:\windows\system32\dllcache\fxsdrv.dll
2009-07-25 16:20 33,792 ac—— c:\windows\system32\dllcache\controt.dll
2009-07-25 16:19 66,082 ac—— c:\windows\system32\dllcache\c_20284.nls
2009-07-25 16:18 19,456 ac—— c:\windows\system32\dllcache\agt040d.dll
2009-07-25 16:18 19,456 ac—— c:\windows\system32\dllcache\agt0401.dll
2009-07-25 16:18 49,664 ac—— c:\windows\system32\dllcache\adrot.dll
2009-07-25 16:18 5,632 ac—— c:\windows\system32\dllcache\EXCH_adsiisex.dll
2009-07-25 16:18 6,144 ac—— c:\windows\system32\dllcache\admxprox.dll
2009-07-25 16:18 29,696 ac—— c:\windows\system32\dllcache\admexs.dll
2009-07-25 16:18 183,808 ac—— c:\windows\system32\dllcache\accwiz.exe
2009-07-25 16:18 68,608 ac—— c:\windows\system32\dllcache\access.cpl
2009-07-25 16:18 10,240 ac—— c:\windows\system32\dllcache\npwmsdrm.dll
2009-07-25 16:16 20,541 ac—— c:\windows\system32\dllcache\fpexedll.dll
2009-07-25 16:15 188,480 ac—— c:\windows\system32\dllcache\cfgwiz.exe
2009-07-25 16:15 76,288 ac—— c:\windows\system32\dllcache\cnfgprts.ocx
2009-07-25 16:15 275,968 ac—— c:\windows\system32\dllcache\certwiz.ocx
2009-07-25 16:15 94,720 ac—— c:\windows\system32\dllcache\certmap.ocx
2009-07-25 16:15 290,816 ac—— c:\windows\system32\dllcache\adsiis51.dll
2009-07-25 16:15 20,540 ac—— c:\windows\system32\dllcache\author.dll
2009-07-25 16:15 16,439 ac—— c:\windows\system32\dllcache\author.exe
2009-07-25 16:15 43,520 ac—— c:\windows\system32\dllcache\admwprox.dll
2009-07-25 16:15 20,540 ac—— c:\windows\system32\dllcache\admin.dll
2009-07-25 16:15 16,439 ac—— c:\windows\system32\dllcache\admin.exe
2009-07-25 16:15 –d—– c:\program files\msn gaming zone
2009-07-25 16:10 488 a—hr– c:\windows\system32\logonui.exe.manifest
2009-07-25 16:10 749 a—hr– c:\windows\WindowsShell.Manifest
2009-07-25 16:10 749 a—hr– c:\windows\system32\wuaucpl.cpl.manifest
2009-07-25 16:10 749 a—hr– c:\windows\system32\sapi.cpl.manifest
2009-07-25 16:10 749 a—hr– c:\windows\system32\nwc.cpl.manifest
2009-07-25 16:10 749 a—hr– c:\windows\system32\ncpa.cpl.manifest
2009-07-25 16:09 16,384 ac—— c:\windows\system32\dllcache\isignup.exe
2009-07-25 16:04 86,016 ac—— c:\windows\system32\dllcache\icwconn2.exe
2009-07-25 16:04 32,768 ac—— c:\windows\system32\dllcache\icwdl.dll
2009-07-25 16:04 20,480 ac—— c:\windows\system32\dllcache\inetwiz.exe
2009-07-25 16:03 214,528 ac—— c:\windows\system32\dllcache\icwconn1.exe
2009-07-25 15:44 24,661 ac—— c:\windows\system32\dllcache\spxcoins.dll
2009-07-25 15:44 13,312 ac—— c:\windows\system32\dllcache\irclass.dll
2009-07-25 15:44 24,661 a——- c:\windows\system32\spxcoins.dll
2009-07-25 15:44 13,312 a——- c:\windows\system32\irclass.dll
2009-07-23 14:32 –d—– c:\program files\Cakewalk
2009-07-23 14:32 –d—– C:\Cakewalk Projects
2009-07-22 15:53 138,752 ac—— c:\windows\system32\dllcache\sndvol32.exe
2009-07-22 15:53 138,752 a——- c:\windows\system32\sndvol32.exe
2009-07-22 13:49 –d—– c:\windows\system32\XPSViewer
2009-07-22 13:48 117,760 a——- c:\windows\system32\prntvpt.dll
2009-07-22 13:48 1,676,288 a——- c:\windows\system32\xpssvcs.dll
2009-07-22 13:48 575,488 a——- c:\windows\system32\xpsshhdr.dll
2009-07-21 22:16 159,600 a——- c:\windows\system32\drivers\pctgntdi.sys
2009-07-21 22:16 130,936 a——- c:\windows\system32\drivers\PCTCore.sys
2009-07-21 22:16 73,840 a——- c:\windows\system32\drivers\PCTAppEvent.sys
2009-07-21 22:16 64,392 a——- c:\windows\system32\drivers\pctplsg.sys
2009-07-21 22:16 –d—– c:\program files\common files\PC Tools
2009-07-21 22:16 –d—– c:\program files\Spyware Doctor
2009-07-21 22:16 –d—– c:\docume~1\alluse~1\applic~1\PC Tools
2009-07-21 22:16 –d—– c:\docume~1\allen\applic~1\PC Tools
2009-07-18 20:07 –d—– c:\program files\energyXT2
2009-07-17 16:14 –d—– c:\docume~1\allen\applic~1\CMplay
2009-07-17 12:13 –d—– c:\program files\REAPER
==================== Find3M ====================
2009-08-09 10:00 118,784 a——- c:\windows\dsdxirmv.exe
2009-08-05 05:11 204,800 a——- c:\windows\system32\mswebdvd.dll
2009-07-28 14:44 410,984 a——- c:\windows\system32\deploytk.dll
2009-07-26 12:31 12,400 a——- c:\windows\system32\drivers\secdrv.sys
2009-07-25 16:01 34,284 a——- c:\windows\system32\emptyregdb.dat
2009-07-17 14:55 58,880 a——- c:\windows\system32\atl.dll
2009-07-13 10:08 286,720 a——- c:\windows\system32\wmpdxm.dll
2009-07-04 12:51 2,771,968 ——– c:\windows\system32\ReWire.dll
2009-07-03 13:09 915,456 a——- c:\windows\system32\wininet.dll
2009-06-27 21:11 87,747 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-06-25 14:36 661,504 a——- c:\windows\system32\mqqm.dll
2009-06-25 14:36 517,120 a——- c:\windows\system32\mqsnap.dll
2009-06-25 14:36 471,552 a——- c:\windows\system32\mqutil.dll
2009-06-25 14:36 225,280 a——- c:\windows\system32\mqoa.dll
2009-06-25 14:36 186,880 a——- c:\windows\system32\mqtrig.dll
2009-06-25 14:36 177,152 a——- c:\windows\system32\mqrt.dll
2009-06-25 14:36 138,240 a——- c:\windows\system32\mqad.dll
2009-06-25 14:36 123,392 a——- c:\windows\system32\mqrtdep.dll
2009-06-25 14:36 95,744 a——- c:\windows\system32\mqsec.dll
2009-06-25 14:36 48,640 a——- c:\windows\system32\mqupgrd.dll
2009-06-25 14:36 47,104 a——- c:\windows\system32\mqdscli.dll
2009-06-25 14:36 16,896 a——- c:\windows\system32\mqise.dll
2009-06-24 15:51 118,784 a——- c:\windows\SeaMonkeyUninstall.exe
2009-06-24 15:51 8,653 a——- c:\windows\mozver.dat
2009-06-24 15:51 118,784 a——- c:\windows\GREUninstall.exe
2009-06-22 07:49 117,248 a——- c:\windows\system32\mqtgsvc.exe
2009-06-22 07:49 19,968 a——- c:\windows\system32\mqbkup.exe
2009-06-22 07:49 4,608 a——- c:\windows\system32\mqsvc.exe
2009-06-22 07:48 91,776 a——- c:\windows\system32\drivers\mqac.sys
2009-06-16 10:55 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 10:55 82,432 a——- c:\windows\system32\fontsub.dll
2009-06-14 15:43 24 a——- C:\DUKE3D.BAT
2009-06-12 07:50 80,896 a——- c:\windows\system32\tlntsess.exe
2009-06-12 07:50 76,288 a——- c:\windows\system32\telnet.exe
2009-06-10 10:21 84,992 a——- c:\windows\system32\avifil32.dll
2009-06-10 02:32 132,096 a——- c:\windows\system32\wkssvc.dll
2009-06-06 21:23 43,520 a——- c:\windows\system32\CmdLineExt03.dll
2009-06-06 12:22 17,233 a——- c:\windows\unins000.dat
2009-06-06 12:21 678,746 a——- c:\windows\unins000.exe
2009-06-05 03:42 655,872 a——- c:\windows\system32\mstscax.dll
2009-06-03 15:27 1,290,752 a——- c:\windows\system32\quartz.dll
2009-05-30 14:08 737,280 a——- c:\windows\iun6002.exe
2009-05-25 00:34 13 —-h— c:\docume~1\alluse~1\applic~1\ÐÝÃÄ›.sys
2009-05-23 16:28 33,256 a—h— c:\windows\system32\mlfcache.dat
2009-05-21 19:22 27,136 a——- c:\windows\system32\pubdlg.dll
2009-05-21 19:22 12,288 a——- c:\windows\system32\picstore.dll
2009-05-21 19:22 161,552 a——- c:\windows\system32\asycpict.dll
2007-04-24 15:15 458,752 a——- c:\program files\common files\AmpliTubeJimiHendrix.dpm
2007-03-07 12:07 286 a——- c:\program files\common files\AmpliTubeJimiHendrix.dpm.rsr
2003-11-05 22:37 11,838 a——- c:\program files\SFX Machine LT Read Me.rtf
2002-07-31 19:55 106 —sh— c:\windows\WSYS049.SYS
============= FINISH: 13:01:57.06 ===============
GMER LOG:
GMER 1.0.15.15020 [gmer.exe] - http://www.gmer.net
Rootkit scan 2009-08-15 16:05:32
Windows 5.1.2600 Service Pack 2
—- System - GMER 1.0.15 —-
SSDT 89B8BB90 ZwAlertResumeThread
SSDT 89BC2808 ZwAlertThread
SSDT 89A9DC28 ZwAllocateVirtualMemory
SSDT 89A9E5E0 ZwConnectPort
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateKey [0xBA6AF514]
SSDT 89B8C910 ZwCreateMutant
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0xBA69E282]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0xBA69E474]
SSDT 899C38C8 ZwCreateThread
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteKey [0xBA6AFD00]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteValueKey [0xBA6AFFB8]
SSDT 89BD6910 ZwFreeVirtualMemory
SSDT 89B8C720 ZwImpersonateAnonymousToken
SSDT 89B8BD30 ZwImpersonateThread
SSDT 89D1A890 ZwMapViewOfSection
SSDT 89B8CA98 ZwOpenEvent
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwOpenKey [0xBA6AE3FA]
SSDT 89BD67C8 ZwOpenProcessToken
SSDT 89ADA718 ZwOpenThreadToken
SSDT 89B8C7F0 ZwQueryValueKey
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwRenameKey [0xBA6B0422]
SSDT 89ABCAE0 ZwResumeThread
SSDT 89AEE728 ZwSetContextThread
SSDT 89BDB890 ZwSetInformationProcess
SSDT 89AEE760 ZwSetInformationThread
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwSetValueKey [0xBA6AF7D8]
SSDT 89B8DC50 ZwSuspendProcess
SSDT 89BC2730 ZwSuspendThread
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0xBA69DF32]
SSDT 89AEE8E0 ZwTerminateThread
SSDT 89AB9730 ZwUnmapViewOfSection
SSDT 89710368 ZwWriteVirtualMemory
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \FileSystem\Fastfat \Fat AFA54C8A
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
—- EOF - GMER 1.0.15 —-
rocker44
MALWAREBYTES LOG:
Malwarebytes' Anti-Malware 1.40
Database version: 2628
Windows 5.1.2600 Service Pack 2
8/15/2009 6:36:17 AM
mbam-log-2009-08-15 (06-36-09).txt
Scan type: Quick Scan
Objects scanned: 101613
Time elapsed: 7 minute(s), 24 second(s)
Memory Processes Infected: 2
Memory Modules Infected: 0
Registry Keys Infected: 11
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 6
Files Infected: 13
Memory Processes Infected:
C:\Program Files\Ascentive\Performance Center\ApcMain.exe (Adware.Ascentive) -> No action taken.
C:\Program Files\Ascentive\PC SpeedScan Pro\PCSpeedScan.exe (Rogue.PCSpeedScan) -> No action taken.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{10b3a0d2-3960-4d38-8158-d828a30f8db1} (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> No action taken.
HKEY_CLASSES_ROOT\TypeLib\{497dddb6-6eee-4561-9621-b77dc82c1f84} (Adware.Ascentive) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{4e980492-027b-47f1-a7ab-ab086dacbb9e} (Adware.Ascentive) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{5ead8321-fcbb-4c3f-888c-ac373d366c3f} (Adware.Ascentive) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{31f3cf6e-a71a-4daa-852b-39ac230940b4} (Adware.Ascentive) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe (Adware.DoubleD) -> No action taken.
HKEY_CLASSES_ROOT\aquaplay (Trojan.DNSChanger) -> No action taken.
HKEY_CURRENT_USER\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\DoubleD (Adware.DoubleD) -> No action taken.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\system32\SysRestore.dll (Adware.Ascentive) -> No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Documents and Settings\allen\Local Settings\Application Data\DoubleD (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Application Data\DoubleD\Desktop Smiley Toolbar (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Application Data\DoubleD\Desktop Smiley Toolbar\3.11.5.14760 (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Application Data\DoubleD\Desktop Smiley Toolbar\3.11.5.14760\bin (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\Data (Adware.DoubleD) -> No action taken.
Files Infected:
C:\Program Files\Ascentive\Performance Center\ApcMain.exe (Adware.Ascentive) -> No action taken.
C:\Program Files\Ascentive\PC SpeedScan Pro\PCSpeedScan.exe (Rogue.PCSpeedScan) -> No action taken.
C:\WINDOWS\system32\SysRestore.dll (Adware.Ascentive) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Application Data\DoubleD\Desktop Smiley Toolbar\3.11.5.14760\bin\stbup.exe (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\bg.jpg (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\CurrentVersion.xml (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\icon.ico (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\productinfo.dll (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\Setup.exe (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\stbup.exe (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\tdf.dat (Adware.DoubleD) -> No action taken.
C:\Documents and Settings\allen\Local Settings\Temporary Internet Files\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}\Data\ProductInfo.mx (Adware.DoubleD) -> No action taken.
C:\Program Files\SFX Machine LT.dll (Spyware.OnlineGames) -> No action taken.
DDS LOG:
DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 13:01:06.95 on Sat 08/15/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2045.1360 [GMT -4:00]
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative Professional\E-MU USB Audio\E-MU USB Audio\EmuUsbAudioCP.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
D:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\CodeMeter\Runtime\bin\CodeMeter.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
D:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\emaudsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\allen\Desktop\dds.pif
============== Pseudo HJT Report ===============
uDefault_Page_URL = hxxp://www.msn.com
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - No File
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No File
BHO: {AA58ED58-01DD-4d91-8333-CF10577473F7} - No File
BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No File
BHO: {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - No File
BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [Performance Center] c:\program files\ascentive\performance center\ApcMain.exe -m
uRun: [E-MU USB Audio Control Panel] "c:\program files\creative professional\e-mu usb audio\e-mu usb audio\EmuUsbAudioCP.exe"
uRun: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\RegistryBooster.exe /S
uRun: [UniblueSpeedUpMyPC] c:\program files\uniblue\speedupmypc\Launcher.exe -minimize
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [Lexmark X74-X75] "c:\program files\lexmark x74-x75\lxbbbmgr.exe"
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [H2O] c:\program files\syncrosoft\pos\h2o\cledx.exe
mRun: [VerizonServicepoint.exe] "c:\program files\verizon\vsp\VerizonServicepoint.exe" /AUTORUN
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
StartupFolder: c:\docume~1\allen\startm~1\programs\startup\openof~1.lnk - d:\program files\openoffice.org 2.4\program\quickstart.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,77,65,62,5c,72,65,6c-,61,74,65,64,2e,68,74,6d,00
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07}
LSP: c:\windows\system32\dcsource.dll
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1248703385718
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Notify: NavLogon - c:\windows\system32\NavLogon.dll
AppInit_DLLs: c:\progra~1\google\google~4\GOEC62~1.DLL
================= FIREFOX ===================
FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-7-21 130936]
R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2006-9-6 337592]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2006-9-6 54968]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2006-7-19 192160]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2006-7-19 169632]
R2 CodeMeter.exe;CodeMeter Runtime Server;c:\program files\codemeter\runtime\bin\CodeMeter.exe [2009-4-3 1680704]
R2 emaudsv;E-MU Audio Service;c:\windows\system32\emaudsv.exe [2006-11-20 10240]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2006-10-24 1813184]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [2009-8-1 33792]
R3 emusba10;E-MU USB-Audio 1.0 Driver;c:\windows\system32\drivers\emusba10.sys [2006-11-20 142208]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-8-12 101936]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090814.004\naveng.sys [2009-8-14 87888]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090814.004\navex15.sys [2009-8-14 875728]
S0 bhpftp;bhpftp;c:\windows\system32\drivers\hkztnm.sys –> c:\windows\system32\drivers\hkztnm.sys [?]
S2 gupdate1ca0a71a4770151;Google Update Service (gupdate1ca0a71a4770151);c:\program files\google\update\GoogleUpdate.exe [2009-7-21 133104]
S3 EraserUtilDrv10910;EraserUtilDrv10910;\??\c:\program files\common files\symantec shared\eengine\eraserutildrv10910.sys –> c:\program files\common files\symantec shared\eengine\EraserUtilDrv10910.sys [?]
S3 GoogleDesktopManager-110408-113106;Google Desktop Manager 5.8.811.4345;c:\program files\google\google desktop search\GoogleDesktop.exe [2009-6-24 30192]
S3 Radialpoint Security Services;Verizon PC Security Checkup Service;c:\program files\verizon\pc security checkup\RpsSecurityAwareR.exe [2009-8-14 170736]
S3 Rpcsvrvca_pr;Rpcsvrvca_pr;c:\windows\system32\drivers\amdk6.sys [2004-8-3 36992]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2006-10-24 116416]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-7-21 348752]
S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-7-21 1095560]
=============== Created Last 30 ================
2009-08-15 07:47 –d—– c:\program files\Trend Micro
2009-08-14 23:50 –d—– c:\docume~1\allen\applic~1\Malwarebytes
2009-08-14 23:49 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-14 23:49 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-14 23:49 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-08-14 23:49 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-08-14 14:35 –d—– c:\program files\Radialpoint
2009-08-14 12:09 73,728 a——- c:\windows\system32\rmpHTML.dll
2009-08-14 12:09 45,056 a——- c:\windows\system32\AxrmpHTML.dll
2009-08-14 12:09 868,352 a——- c:\windows\system32\rmpHTML.ocx
2009-08-14 12:09 249 a——- c:\windows\system32\windefht.bin
2009-08-14 12:09 –d—– C:\Abdio
2009-08-14 12:00 -cd-h— c:\docume~1\alluse~1\applic~1\{D9010FDD-3EED-44D9-9863-33B2D7362EC5}
2009-08-14 11:33 186,624 a——- c:\windows\system32\dcsource.dll
2009-08-14 11:32 –d—– c:\program files\BestAddress HTML Editor 2009 Professional
2009-08-14 11:24 –d—– c:\program files\qxyeed
2009-08-13 14:14 286,720 a——- c:\windows\iun507.exe
2009-08-13 14:14 –d—– c:\program files\PersonalWebKit3
2009-08-12 20:29 –d—– c:\documents and settings\allen\ErrorLogs
2009-08-12 19:57 –d—– c:\program files\Uniblue
2009-08-12 19:57 -cd-h— c:\docume~1\alluse~1\applic~1\{C4C0E335-EDDF-46A0-A57D-F3802AE44275}
2009-08-12 12:42 0 a——- c:\windows\VPC32.INI
2009-08-12 12:40 109,744 a——- c:\windows\system32\drivers\SYMEVENT.SYS
2009-08-12 12:40 48,816 a——- c:\windows\system32\S32EVNT1.DLL
2009-08-12 12:38 –d—– c:\program files\Symantec
2009-08-12 12:38 –d—– c:\program files\Symantec AntiVirus
2009-08-12 12:38 –d—– c:\docume~1\alluse~1\applic~1\Symantec
2009-08-12 12:33 –d—– C:\Symantec10.1.5
2009-08-10 22:28 –d—– c:\program files\common files\xing shared
2009-08-10 17:43 –d—– c:\docume~1\allen\applic~1\Forexyard
2009-08-10 17:42 –d—– C:\Forexyard
2009-08-08 22:53 –d—– c:\docume~1\allen\applic~1\Uniblue
2009-08-08 22:41 –d—– c:\docume~1\alluse~1\applic~1\Cakewalk
2009-08-08 22:29 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll
2009-08-08 22:29 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-08 22:29 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-08 22:29 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-08 21:43 –d—– c:\program files\MSXML 6.0
2009-08-08 21:41 –d—– c:\docume~1\allen\applic~1\Verizon
2009-08-08 21:41 –d—– c:\program files\Verizon
2009-08-08 21:41 –d—– c:\docume~1\alluse~1\applic~1\Verizon
2009-08-08 15:54 13 a——- c:\windows\system32\MSVC60SVV.DLL
2009-08-08 15:54 13 a——- c:\windows\MSOCREG.DAT
2009-08-04 13:16 57,344 a——- c:\windows\system32\Wnaspint.dll
2009-08-04 13:16 –d—– c:\program files\Acoustica Shared Effects
2009-08-04 13:16 –d—– c:\program files\Acoustica Mixcraft 3
2009-08-04 09:50 –d—– c:\docume~1\allen\applic~1\Digital Support
2009-08-04 09:49 –d—– c:\program files\Digital Support
2009-08-03 14:30 606,293 a——- c:\windows\system32\wbocx.ocx
2009-08-03 14:30 50,688 a——- c:\windows\system32\wbhelp2.dll
2009-08-03 14:30 –d—– c:\program files\Ipswitch
2009-08-03 13:41 319,488 a——- c:\windows\system32\PolarZIPLight.dll
2009-08-03 13:35 –d—– c:\docume~1\allen\applic~1\CoreFTP
2009-08-03 13:34 –d—– c:\program files\CoreFTP
2009-08-03 13:18 –d—– c:\docume~1\allen\applic~1\CoffeeCup Software
2009-08-02 11:32 189 a——- c:\windows\system32\.MySCMServerInfo
2009-08-02 11:32 –d—– c:\program files\DigiDesign
2009-08-01 22:23 –d—– c:\docume~1\alluse~1\applic~1\Steinberg
2009-08-01 22:12 –d—– c:\program files\common files\Steinberg
2009-08-01 19:01 87,040 a——- c:\windows\system32\ra32sipr.dll
2009-08-01 19:01 72,704 a——- c:\windows\system32\ra3228_8.dll
2009-08-01 19:01 21,504 a——- c:\windows\system32\ra32dnet.dll
2009-08-01 19:01 487,936 a——- c:\windows\system32\rmbe3260.dll
2009-08-01 19:01 352,768 a——- c:\windows\system32\pngu3263.dll
2009-08-01 19:01 131,072 a——- c:\windows\system32\pneng50.dll
2009-08-01 19:01 130,560 a——- c:\windows\system32\pnc3250.dll
2009-08-01 19:01 85,504 a——- c:\windows\system32\encdnet.dll
2009-08-01 19:01 81,920 a——- c:\windows\system32\ra3214_4.dll
2009-08-01 19:01 61,952 a——- c:\windows\system32\decdnet.dll
2009-08-01 18:59 33,792 a——- c:\windows\system32\drivers\cledx.sys
2009-08-01 18:59 147,425 a——- c:\windows\system32\SYNSOACC-Aide.chm
2009-08-01 18:59 120,468 a——- c:\windows\system32\SYNSOACC-Hilfe.chm
2009-08-01 18:59 114,279 a——- c:\windows\system32\SYNSOACC-Help.chm
2009-08-01 18:59 16,896 a——- c:\windows\system32\drivers\synasUSB.sys
2009-08-01 18:59 45,056 a——- c:\windows\system32\Synsopos.exe
2009-08-01 18:59 147,456 a——- c:\windows\system32\SynsoLChk.dll
2009-08-01 18:59 35,328 a——- c:\windows\system32\SYNSOACC.dll
2009-08-01 18:59 17,784 a——- c:\windows\system32\drivers\NSynas32.sys
2009-08-01 18:59 –d—– c:\program files\Syncrosoft
2009-08-01 14:45 –d—– c:\program files\Forex Strategy Builder
2009-07-30 14:01 416 a——- c:\windows\BeatBox.INI
2009-07-30 13:54 28 a——- c:\windows\Robota.INI
2009-07-30 11:17 1,294,336 a——- c:\windows\system32\vorbis.acm
2009-07-30 11:15 –d—– c:\program files\Image-Line
2009-07-30 10:20 0 a——- c:\windows\MusicStudio.INI
2009-07-30 10:19 –d—– c:\docume~1\alluse~1\applic~1\MAGIX
2009-07-30 10:19 –d—– c:\program files\common files\MAGIX Shared
2009-07-30 10:18 1,089,536 a——- c:\windows\system32\ROBOEX32.DLL
2009-07-30 10:18 49,152 a——- c:\windows\system32\INETWH32.dll
2009-07-30 10:18 –d—– c:\program files\MAGIX
2009-07-30 10:18 85,504 a——- c:\windows\system32\HtmlWH.dll
2009-07-30 10:18 663,552 a——- c:\windows\system32\mgxoschk.dll
2009-07-30 10:18 5,817 a——- c:\windows\mgxoschk.ini
2009-07-30 10:18 –d—– c:\windows\system32\MAGIX
2009-07-30 10:14 53,248 a——- c:\windows\system32\IKStompIO1API.dll
2009-07-30 10:06 –d—– c:\program files\common files\Acon Digital Media
2009-07-30 10:06 –d—– c:\program files\Acon Digital Media
2009-07-30 10:04 –d—– c:\docume~1\allen\applic~1\Thinstall
2009-07-30 00:58 –d—– c:\program files\EDIROL
2009-07-29 22:52 –d—– c:\docume~1\allen\applic~1\com.kewlshare.KewlManager.7FDCF29DEFD40899D06AD7AA1B082BD679DAC8B0.1
2009-07-29 01:20 594,432 -c—— c:\windows\system32\dllcache\msfeeds.dll
2009-07-29 01:20 55,296 -c—— c:\windows\system32\dllcache\msfeedsbs.dll
2009-07-28 14:44 73,728 a——- c:\windows\system32\javacpl.cpl
2009-07-27 10:55 -cd-h— c:\windows\ie8
2009-07-27 10:54 101,376 -c—— c:\windows\system32\dllcache\iecompat.dll
2009-07-27 10:54 1,985,536 -c—— c:\windows\system32\dllcache\iertutil.dll
2009-07-27 10:54 246,272 -c—— c:\windows\system32\dllcache\ieproxy.dll
2009-07-27 10:54 12,800 -c—— c:\windows\system32\dllcache\xpshims.dll
2009-07-27 10:54 11,067,392 -c—— c:\windows\system32\dllcache\ieframe.dll
2009-07-27 10:10 –d—– c:\windows\system32\CatRoot_bak
2009-07-27 10:10 272,128 -c—— c:\windows\system32\dllcache\bthport.sys
2009-07-27 10:10 2,186,112 -c—— c:\windows\system32\dllcache\ntoskrnl.exe
2009-07-27 10:10 2,142,720 -c—— c:\windows\system32\dllcache\ntkrnlmp.exe
2009-07-27 10:10 2,062,976 -c—— c:\windows\system32\dllcache\ntkrnlpa.exe
2009-07-27 10:10 2,020,864 -c—— c:\windows\system32\dllcache\ntkrpamp.exe
2009-07-27 10:10 453,632 -c—— c:\windows\system32\dllcache\mrxsmb.sys
2009-07-27 09:28 –d-h— c:\windows\msdownld.tmp
2009-07-27 01:13 19 a——- c:\documents and settings\allen\Settings.dat
2009-07-26 12:38 –d—– c:\program files\Steinberg
2009-07-26 12:38 –d—– c:\docume~1\allen\applic~1\Proteus VX
2009-07-26 12:37 1,706,800 ——– c:\windows\system32\gdiplus.dll
2009-07-25 18:25 –d—– c:\program files\Enigma Software Group
2009-07-25 16:32 69,632 ac—— c:\windows\system32\dllcache\ehresko.dll
2009-07-25 16:32 73,728 ac—— c:\windows\system32\dllcache\ehresja.dll
2009-07-25 16:32 69,632 ac—— c:\windows\system32\dllcache\ehresfr.dll
2009-07-25 16:32 69,632 ac—— c:\windows\system32\dllcache\ehresde.dll
2009-07-25 16:32 61,440 ac—— c:\windows\system32\dllcache\ehreschs.dll
2009-07-25 16:32 113,222 ac—— c:\windows\system32\dllcache\zoneclim.dll
2009-07-25 16:32 41,029 ac—— c:\windows\system32\dllcache\zcorem.dll
2009-07-25 16:32 36,937 ac—— c:\windows\system32\dllcache\zclientm.exe
2009-07-25 16:32 29,760 ac—— c:\windows\system32\dllcache\znetm.dll
2009-07-25 16:32 13,894 ac—— c:\windows\system32\dllcache\zonelibm.dll
2009-07-25 16:32 4,677 ac—— c:\windows\system32\dllcache\zeeverm.dll
2009-07-25 16:31 5,632 ac—— c:\windows\system32\dllcache\write.exe
2009-07-25 16:31 214,528 ac—— c:\windows\system32\dllcache\wordpad.exe
2009-07-25 16:31 221,184 ac—— c:\windows\system32\dllcache\wmpns.dll
2009-07-25 16:31 119,808 ac—— c:\windows\system32\dllcache\winmine.exe
2009-07-25 16:31 35,328 ac—— c:\windows\system32\dllcache\winchat.exe
2009-07-25 16:31 31,232 ac—— c:\windows\system32\dllcache\weitekp9.sys
2009-07-25 16:31 53,248 ac—— c:\windows\system32\dllcache\wamreg51.dll
2009-07-25 16:31 41,600 ac—— c:\windows\system32\dllcache\weitekp9.dll
2009-07-25 16:31 76,800 ac—— c:\windows\system32\dllcache\wam51.dll
2009-07-25 16:31 9,216 ac—— c:\windows\system32\dllcache\wamps51.dll
2009-07-25 16:31 363,520 ac—— c:\windows\system32\dllcache\w3svc.dll
2009-07-25 16:31 5,632 ac—— c:\windows\system32\dllcache\w3svapi.dll
2009-07-25 16:30 73,728 ac—— c:\windows\system32\dllcache\w3ext.dll
2009-07-25 16:30 48,256 ac—— c:\windows\system32\dllcache\w32.dll
2009-07-25 16:30 4,608 ac—— c:\windows\system32\dllcache\w3ctrs51.dll
2009-07-25 16:30 32,339 ac—— c:\windows\system32\dllcache\uniansi.dll
2009-07-25 16:30 103,424 ac—— c:\windows\system32\dllcache\uihelper.dll
2009-07-25 16:30 14,336 ac—— c:\windows\system32\dllcache\tsprof.exe
2009-07-25 16:30 31,232 ac—— c:\windows\system32\dllcache\tools.dll
2009-07-25 16:30 10,240 ac—— c:\windows\system32\dllcache\tmigrate.dll
2009-07-25 16:28 42,573 ac—— c:\windows\system32\dllcache\shvlzm.exe
2009-07-25 16:27 281,088 ac—— c:\windows\system32\dllcache\pinball.exe
2009-07-25 16:26 37,888 ac—— c:\windows\system32\dllcache\md5filt.dll
2009-07-25 16:25 6,144 ac—— c:\windows\system32\dllcache\kbdinpun.dll
2009-07-25 16:24 79,872 ac—— c:\windows\system32\dllcache\iislog51.dll
2009-07-25 16:24 60,928 ac—— c:\windows\system32\dllcache\iisclex4.dll
2009-07-25 16:24 19,456 ac—— c:\windows\system32\dllcache\iiscrmap.dll
2009-07-25 16:24 7,168 ac—— c:\windows\system32\dllcache\iisfecnv.dll
2009-07-25 16:24 6,656 ac—— c:\windows\system32\dllcache\iissync.exe
2009-07-25 16:24 3,584 ac—— c:\windows\system32\dllcache\iismui.dll
2009-07-25 16:24 145,408 ac—— c:\windows\system32\dllcache\iische51.dll
2009-07-25 16:24 25,088 ac—— c:\windows\system32\dllcache\iisadmin.dll
2009-07-25 16:23 10,096,640 ac—— c:\windows\system32\dllcache\hwxcht.dll
2009-07-25 16:23 61,440 ac—— c:\windows\system32\dllcache\httpod51.dll
2009-07-25 16:23 268,288 ac—— c:\windows\system32\dllcache\httpext.dll
2009-07-25 16:23 8,192 ac—— c:\windows\system32\dllcache\httpmb51.dll
2009-07-25 16:21 27,136 ac—— c:\windows\system32\dllcache\fxsdrv.dll
2009-07-25 16:20 33,792 ac—— c:\windows\system32\dllcache\controt.dll
2009-07-25 16:19 66,082 ac—— c:\windows\system32\dllcache\c_20284.nls
2009-07-25 16:18 19,456 ac—— c:\windows\system32\dllcache\agt040d.dll
2009-07-25 16:18 19,456 ac—— c:\windows\system32\dllcache\agt0401.dll
2009-07-25 16:18 49,664 ac—— c:\windows\system32\dllcache\adrot.dll
2009-07-25 16:18 5,632 ac—— c:\windows\system32\dllcache\EXCH_adsiisex.dll
2009-07-25 16:18 6,144 ac—— c:\windows\system32\dllcache\admxprox.dll
2009-07-25 16:18 29,696 ac—— c:\windows\system32\dllcache\admexs.dll
2009-07-25 16:18 183,808 ac—— c:\windows\system32\dllcache\accwiz.exe
2009-07-25 16:18 68,608 ac—— c:\windows\system32\dllcache\access.cpl
2009-07-25 16:18 10,240 ac—— c:\windows\system32\dllcache\npwmsdrm.dll
2009-07-25 16:16 20,541 ac—— c:\windows\system32\dllcache\fpexedll.dll
2009-07-25 16:15 188,480 ac—— c:\windows\system32\dllcache\cfgwiz.exe
2009-07-25 16:15 76,288 ac—— c:\windows\system32\dllcache\cnfgprts.ocx
2009-07-25 16:15 275,968 ac—— c:\windows\system32\dllcache\certwiz.ocx
2009-07-25 16:15 94,720 ac—— c:\windows\system32\dllcache\certmap.ocx
2009-07-25 16:15 290,816 ac—— c:\windows\system32\dllcache\adsiis51.dll
2009-07-25 16:15 20,540 ac—— c:\windows\system32\dllcache\author.dll
2009-07-25 16:15 16,439 ac—— c:\windows\system32\dllcache\author.exe
2009-07-25 16:15 43,520 ac—— c:\windows\system32\dllcache\admwprox.dll
2009-07-25 16:15 20,540 ac—— c:\windows\system32\dllcache\admin.dll
2009-07-25 16:15 16,439 ac—— c:\windows\system32\dllcache\admin.exe
2009-07-25 16:15 –d—– c:\program files\msn gaming zone
2009-07-25 16:10 488 a—hr– c:\windows\system32\logonui.exe.manifest
2009-07-25 16:10 749 a—hr– c:\windows\WindowsShell.Manifest
2009-07-25 16:10 749 a—hr– c:\windows\system32\wuaucpl.cpl.manifest
2009-07-25 16:10 749 a—hr– c:\windows\system32\sapi.cpl.manifest
2009-07-25 16:10 749 a—hr– c:\windows\system32\nwc.cpl.manifest
2009-07-25 16:10 749 a—hr– c:\windows\system32\ncpa.cpl.manifest
2009-07-25 16:09 16,384 ac—— c:\windows\system32\dllcache\isignup.exe
2009-07-25 16:04 86,016 ac—— c:\windows\system32\dllcache\icwconn2.exe
2009-07-25 16:04 32,768 ac—— c:\windows\system32\dllcache\icwdl.dll
2009-07-25 16:04 20,480 ac—— c:\windows\system32\dllcache\inetwiz.exe
2009-07-25 16:03 214,528 ac—— c:\windows\system32\dllcache\icwconn1.exe
2009-07-25 15:44 24,661 ac—— c:\windows\system32\dllcache\spxcoins.dll
2009-07-25 15:44 13,312 ac—— c:\windows\system32\dllcache\irclass.dll
2009-07-25 15:44 24,661 a——- c:\windows\system32\spxcoins.dll
2009-07-25 15:44 13,312 a——- c:\windows\system32\irclass.dll
2009-07-23 14:32 –d—– c:\program files\Cakewalk
2009-07-23 14:32 –d—– C:\Cakewalk Projects
2009-07-22 15:53 138,752 ac—— c:\windows\system32\dllcache\sndvol32.exe
2009-07-22 15:53 138,752 a——- c:\windows\system32\sndvol32.exe
2009-07-22 13:49 –d—– c:\windows\system32\XPSViewer
2009-07-22 13:48 117,760 a——- c:\windows\system32\prntvpt.dll
2009-07-22 13:48 1,676,288 a——- c:\windows\system32\xpssvcs.dll
2009-07-22 13:48 575,488 a——- c:\windows\system32\xpsshhdr.dll
2009-07-21 22:16 159,600 a——- c:\windows\system32\drivers\pctgntdi.sys
2009-07-21 22:16 130,936 a——- c:\windows\system32\drivers\PCTCore.sys
2009-07-21 22:16 73,840 a——- c:\windows\system32\drivers\PCTAppEvent.sys
2009-07-21 22:16 64,392 a——- c:\windows\system32\drivers\pctplsg.sys
2009-07-21 22:16 –d—– c:\program files\common files\PC Tools
2009-07-21 22:16 –d—– c:\program files\Spyware Doctor
2009-07-21 22:16 –d—– c:\docume~1\alluse~1\applic~1\PC Tools
2009-07-21 22:16 –d—– c:\docume~1\allen\applic~1\PC Tools
2009-07-18 20:07 –d—– c:\program files\energyXT2
2009-07-17 16:14 –d—– c:\docume~1\allen\applic~1\CMplay
2009-07-17 12:13 –d—– c:\program files\REAPER
==================== Find3M ====================
2009-08-09 10:00 118,784 a——- c:\windows\dsdxirmv.exe
2009-08-05 05:11 204,800 a——- c:\windows\system32\mswebdvd.dll
2009-07-28 14:44 410,984 a——- c:\windows\system32\deploytk.dll
2009-07-26 12:31 12,400 a——- c:\windows\system32\drivers\secdrv.sys
2009-07-25 16:01 34,284 a——- c:\windows\system32\emptyregdb.dat
2009-07-17 14:55 58,880 a——- c:\windows\system32\atl.dll
2009-07-13 10:08 286,720 a——- c:\windows\system32\wmpdxm.dll
2009-07-04 12:51 2,771,968 ——– c:\windows\system32\ReWire.dll
2009-07-03 13:09 915,456 a——- c:\windows\system32\wininet.dll
2009-06-27 21:11 87,747 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-06-25 14:36 661,504 a——- c:\windows\system32\mqqm.dll
2009-06-25 14:36 517,120 a——- c:\windows\system32\mqsnap.dll
2009-06-25 14:36 471,552 a——- c:\windows\system32\mqutil.dll
2009-06-25 14:36 225,280 a——- c:\windows\system32\mqoa.dll
2009-06-25 14:36 186,880 a——- c:\windows\system32\mqtrig.dll
2009-06-25 14:36 177,152 a——- c:\windows\system32\mqrt.dll
2009-06-25 14:36 138,240 a——- c:\windows\system32\mqad.dll
2009-06-25 14:36 123,392 a——- c:\windows\system32\mqrtdep.dll
2009-06-25 14:36 95,744 a——- c:\windows\system32\mqsec.dll
2009-06-25 14:36 48,640 a——- c:\windows\system32\mqupgrd.dll
2009-06-25 14:36 47,104 a——- c:\windows\system32\mqdscli.dll
2009-06-25 14:36 16,896 a——- c:\windows\system32\mqise.dll
2009-06-24 15:51 118,784 a——- c:\windows\SeaMonkeyUninstall.exe
2009-06-24 15:51 8,653 a——- c:\windows\mozver.dat
2009-06-24 15:51 118,784 a——- c:\windows\GREUninstall.exe
2009-06-22 07:49 117,248 a——- c:\windows\system32\mqtgsvc.exe
2009-06-22 07:49 19,968 a——- c:\windows\system32\mqbkup.exe
2009-06-22 07:49 4,608 a——- c:\windows\system32\mqsvc.exe
2009-06-22 07:48 91,776 a——- c:\windows\system32\drivers\mqac.sys
2009-06-16 10:55 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 10:55 82,432 a——- c:\windows\system32\fontsub.dll
2009-06-14 15:43 24 a——- C:\DUKE3D.BAT
2009-06-12 07:50 80,896 a——- c:\windows\system32\tlntsess.exe
2009-06-12 07:50 76,288 a——- c:\windows\system32\telnet.exe
2009-06-10 10:21 84,992 a——- c:\windows\system32\avifil32.dll
2009-06-10 02:32 132,096 a——- c:\windows\system32\wkssvc.dll
2009-06-06 21:23 43,520 a——- c:\windows\system32\CmdLineExt03.dll
2009-06-06 12:22 17,233 a——- c:\windows\unins000.dat
2009-06-06 12:21 678,746 a——- c:\windows\unins000.exe
2009-06-05 03:42 655,872 a——- c:\windows\system32\mstscax.dll
2009-06-03 15:27 1,290,752 a——- c:\windows\system32\quartz.dll
2009-05-30 14:08 737,280 a——- c:\windows\iun6002.exe
2009-05-25 00:34 13 —-h— c:\docume~1\alluse~1\applic~1\ÐÝÃÄ›.sys
2009-05-23 16:28 33,256 a—h— c:\windows\system32\mlfcache.dat
2009-05-21 19:22 27,136 a——- c:\windows\system32\pubdlg.dll
2009-05-21 19:22 12,288 a——- c:\windows\system32\picstore.dll
2009-05-21 19:22 161,552 a——- c:\windows\system32\asycpict.dll
2007-04-24 15:15 458,752 a——- c:\program files\common files\AmpliTubeJimiHendrix.dpm
2007-03-07 12:07 286 a——- c:\program files\common files\AmpliTubeJimiHendrix.dpm.rsr
2003-11-05 22:37 11,838 a——- c:\program files\SFX Machine LT Read Me.rtf
2002-07-31 19:55 106 —sh— c:\windows\WSYS049.SYS
============= FINISH: 13:01:57.06 ===============
GMER LOG:
GMER 1.0.15.15020 [gmer.exe] - http://www.gmer.net
Rootkit scan 2009-08-15 16:05:32
Windows 5.1.2600 Service Pack 2
—- System - GMER 1.0.15 —-
SSDT 89B8BB90 ZwAlertResumeThread
SSDT 89BC2808 ZwAlertThread
SSDT 89A9DC28 ZwAllocateVirtualMemory
SSDT 89A9E5E0 ZwConnectPort
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateKey [0xBA6AF514]
SSDT 89B8C910 ZwCreateMutant
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0xBA69E282]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0xBA69E474]
SSDT 899C38C8 ZwCreateThread
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteKey [0xBA6AFD00]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteValueKey [0xBA6AFFB8]
SSDT 89BD6910 ZwFreeVirtualMemory
SSDT 89B8C720 ZwImpersonateAnonymousToken
SSDT 89B8BD30 ZwImpersonateThread
SSDT 89D1A890 ZwMapViewOfSection
SSDT 89B8CA98 ZwOpenEvent
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwOpenKey [0xBA6AE3FA]
SSDT 89BD67C8 ZwOpenProcessToken
SSDT 89ADA718 ZwOpenThreadToken
SSDT 89B8C7F0 ZwQueryValueKey
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwRenameKey [0xBA6B0422]
SSDT 89ABCAE0 ZwResumeThread
SSDT 89AEE728 ZwSetContextThread
SSDT 89BDB890 ZwSetInformationProcess
SSDT 89AEE760 ZwSetInformationThread
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwSetValueKey [0xBA6AF7D8]
SSDT 89B8DC50 ZwSuspendProcess
SSDT 89BC2730 ZwSuspendThread
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0xBA69DF32]
SSDT 89AEE8E0 ZwTerminateThread
SSDT 89AB9730 ZwUnmapViewOfSection
SSDT 89710368 ZwWriteVirtualMemory
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \FileSystem\Fastfat \Fat AFA54C8A
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
—- EOF - GMER 1.0.15 —-