This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Plzz help me with Root kit agent ODG , AGAIN

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Root repeal





ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/26 08:36
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP2
==================================================

Drivers
——————-
Name: dump_dumpfve.sys
Image Path: C:\Windows\System32\Drivers\dump_dumpfve.sys
Address: 0x91526000 Size: 69632 File Visible: No Signed: -
Status: -

Name: dump_iaStor.sys
Image Path: C:\Windows\System32\Drivers\dump_iaStor.sys
Address: 0x91458000 Size: 843776 File Visible: No Signed: -
Status: -

Name: mchInjDrv.sys
Image Path: C:\Windows\system32\Drivers\mchInjDrv.sys
Address: 0x9FFEA000 Size: 2560 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x9FFEB000 Size: 49152 File Visible: No Signed: -
Status: -

Hidden/Locked Files
——————-
Path: C:\hiberfil.sys
Status: Locked to the Windows API!

Path: C:\Windows\System32\kbiwkmfisndpvm.dat
Status: Invisible to the Windows API!

Path: C:\Windows\System32\kbiwkmjfqictmp.dll
Status: Invisible to the Windows API!

Path: C:\Windows\System32\kbiwkmkkdojbmc.dll
Status: Invisible to the Windows API!

Path: C:\Windows\System32\kbiwkmnxtvxvuf.dat
Status: Invisible to the Windows API!

Path: C:\Windows\System32\kbiwkmpafwdqnp.dat
Status: Invisible to the Windows API!

Path: C:\Windows\System32\kbiwkmswpipcyr.dll
Status: Invisible to the Windows API!

Path: C:\Windows\System32\kbiwkmustvxpuv.dat
Status: Invisible to the Windows API!

Path: C:\Windows\System32\kbiwkmwiwcsxab.dll
Status: Invisible to the Windows API!

Path: C:\Windows\Temp\kbiwkmskxicqgrtc.tmp
Status: Invisible to the Windows API!

Path: C:\Users\o0 Virgo 0o\Documents\My Music
Status: Locked to the Windows API!

Path: C:\Users\o0 Virgo 0o\Documents\My Pictures
Status: Locked to the Windows API!

Path: C:\Users\o0 Virgo 0o\Documents\My Videos
Status: Locked to the Windows API!

Path: C:\Windows\System32\drivers\kbiwkmxsxvqsnu.sys
Status: Invisible to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.42_none_0e9c2a8d74fd3c
e6.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed
.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.debugcrt_1fc8b3b9a1e18e3b_9.0.30729.1_none_bb1f6aa1308c3
5eb.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_8550c6b
5d18a9128.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d
131.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_8e053
e8c6967ba9d.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_none_58b19c
2866332652.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_54c11d
f268b7c6d9.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c
.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.debugcrt_1fc8b3b9a1e18e3b_9.0.30729.1_none_61
305e07e4f1bc01.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8d
d7dea5d5a7a18a.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_9193a
620671dde41.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada.c
at
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf.c
at
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_5c4003
bc63e949f6.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.762_none_ab
ac38a907ee8801.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.762_none_7b33aa7d21850
4d2.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_7dd1e0e
bd6590e0b.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_d6c3e7af9bae13a2.
cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.42_none_588
43c41d2730d3f.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8a14c
0566bec5b24.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_db5f52fb98cb24ad.
cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_10b2f55f9bffb8f8
.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_none_dc990e4797f81af1.
cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-a..atibility-assistant_31bf3856ad364e35_6.0.6000.16386_none_318fc418263bf156\$$DeleteMe.pcadm.dll.01ca1e214478771a.00dc
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-a..atibility-assistant_31bf3856ad364e35_6.0.6000.16386_none_318fc418263bf156\$$DeleteMe.pcasvc.dll.01ca1e2142eaf17a.0094
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-a..dcredentialprovider_31bf3856ad364e35_6.0.6000.16386_none_3fd3e2bdc5a2408e\$$DeleteMe.SmartcardCredentialProvider.dll.01ca1e2143325aba.00a0
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-a..dcredentialprovider_31bf3856ad364e35_6.0.6001.18000_none_420aa4b9c28d5162\$$DeleteMe.SmartcardCredentialProvider.dll.01ca1e2558f626bb.005d
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.0.6000.16386_none_d2da41c24fcec5ef\$$DeleteMe.apphelp.dll.01ca1e21441ba17a.00c9
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-a..ence-infrastructure_31bf3856ad364e35_6.0.6001.18000_none_d51103be4cb9d6c3\$$DeleteMe.apphelp.dll.01ca1e255947157b.0081
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-a..es-interface-router_31bf3856ad364e35_6.0.6000.16386_none_55bf44ac819e1c73\$$DeleteMe.activeds.dll.01ca1e213e8e8c9a.0047
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-a..o-mmecore-wdm-audio_31bf3856ad364e35_6.0.6000.16386_none_48178a2ae8c70f33\$$DeleteMe.wdmaud.drv.01ca1e2140fbd37a.0073
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-a..on-authui.resources_31bf3856ad364e35_6.0.6000.16386_en-us_8945d572a01e6a1a\$$DeleteMe.authui.dll.mui.01ca1e214976b97a.00fc
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-a..terface-ldapc-layer_31bf3856ad364e35_6.0.6000.16386_none_5cfbb23d699248a8\$$DeleteMe.adsldpc.dll.01ca1e213ef4e7ba.0056
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-a..terface-ldapc-layer_31bf3856ad364e35_6.0.6001.18000_none_5f327439667d597c\$$DeleteMe.adsldpc.dll.01ca1e25585dcebb.002e
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-advapi32.resources_31bf3856ad364e35_6.0.6000.16386_en-us_1652b637b3e9dec3\$$DeleteMe.advapi32.dll.mui.01ca1e2149ca099a.0106
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-advapi32_31bf3856ad364e35_6.0.6000.16386_none_e1118fae8996a7dc\$$DeleteMe.advapi32.dll.01ca1e213d67621a.0032
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-advapi32_31bf3856ad364e35_6.0.6001.18000_none_e34851aa8681b8b0\$$DeleteMe.advapi32.dll.01ca1e2558035a7b.0018
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6000.16386_none_7469022ae7b4af06\$$DeleteMe.audiodg.exe.01ca1e213daecb5a.0033
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6000.16386_none_7469022ae7b4af06\$$DeleteMe.AudioEng.dll.01ca1e21422a221a.0080
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6000.16386_none_7469022ae7b4af06\$$DeleteMe.AUDIOKSE.dll.01ca1e2140f710ba.0072
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6000.16386_none_7469022ae7b4af06\$$DeleteMe.AudioSes.dll.01ca1e2143182b9a.009b
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6000.16386_none_7469022ae7b4af06\$$DeleteMe.audiosrv.dll.01ca1e2143f58b7a.00c1
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6001.18000_none_769fc426e49fbfda\$$DeleteMe.audiodg.exe.01ca1e255805bbdb.0019
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6001.18000_none_769fc426e49fbfda\$$DeleteMe.AudioSes.dll.01ca1e2558ef029b.005b
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-audio-audiocore_31bf3856ad364e35_6.0.6001.18000_none_769fc426e49fbfda\$$DeleteMe.audiosrv.dll.01ca1e25593b2e9b.007a
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-audio-mmecore-acm_31bf3856ad364e35_6.0.6000.16386_none_deaec722e41e5e07\$$DeleteMe.msacm32.dll.01ca1e213c5cc81a.0018
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-audio-mmecore-base_31bf3856ad364e35_6.0.6000.16386_none_b3a8fa3e54c50ab3\$$DeleteMe.winmm.dll.01ca1e2143b2e4fa.00b3
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-audio-mmecore-base_31bf3856ad364e35_6.0.6001.18000_none_b5dfbc3a51b01b87\$$DeleteMe.winmm.dll.01ca1e255920ff7b.006d
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-authentication-authui_31bf3856ad364e35_6.0.6000.16386_none_09bcbb1af87cd123\$$DeleteMe.authui.dll.01ca1e2142d5851a.008d
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-authentication-authui_31bf3856ad364e35_6.0.6001.18000_none_0bf37d16f567e1f7\$$DeleteMe.authui.dll.01ca1e2558d734db.0053
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-authentication-logonui_31bf3856ad364e35_6.0.6000.16386_none_635c5092764d99de\$$DeleteMe.LogonUI.exe.01ca1e2142b431da.0088
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-atl_31bf3856ad364e35_6.0.6000.16386_none_a8e97dca5cc75c13\$$DeleteMe.atl.dll.01ca1e21433be03a.00a2
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-audio-mmecore-other_31bf3856ad364e35_6.0.6000.16386_none_8ac7060813a4d0d2\$$DeleteMe.midimap.dll.01ca1e21431368da.0098
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-audio-mmecore-other_31bf3856ad364e35_6.0.6000.16386_none_8ac7060813a4d0d2\$$DeleteMe.msacm32.drv.01ca1e2145bc321a.00e5
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_sv-se_026709e97133efc3\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_tr-tr_ab7454305feff1b4\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_zh-cn_7cd1722e1027c3d3\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_zh-hk_7b7c6abc11033663\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..ager-pcat.resources_31bf3856ad364e35_6.0.6000.16386_zh-tw_80cdaf840d98a043\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_sv-se_9bfb2a309351ac4c\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_tr-tr_45087477820dae3d\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_zh-cn_166592753245805c\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_zh-hk_15108b033320f2ec\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-b..nment-pxe.resources_31bf3856ad364e35_6.0.6000.16386_zh-tw_1a61cfcb2fb65ccc\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-basesrv_31bf3856ad364e35_6.0.6000.16386_none_0a9428d9e6cfbcfc\$$DeleteMe.basesrv.dll.01ca1e21391e083a.000e
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6000.16386_none_215a02f0fc86fab8\$$DeleteMe.qmgr.dll.01ca1e2142066d7a.007c
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6001.18000_none_2390c4ecf9720b8c\$$DeleteMe.qmgr.dll.01ca1e2558b5e19b.004a
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-bits-igdsearcher_31bf3856ad364e35_6.0.6000.16386_none_af357b0d92153e84\$$DeleteMe.bitsigd.dll.01ca1e21410c7d1a.0075
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-bits-igdsearcher_31bf3856ad364e35_6.0.6001.18000_none_b16c3d098f004f58\$$DeleteMe.bitsigd.dll.01ca1e25589e13db.0043
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.0.6000.16386_none_0ab6dd2154d28f55\$$DeleteMe.es.dll.01ca1e2143e9a49a.00c0
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.0.6001.18000_none_0ced9f1d51bda029\$$DeleteMe.es.dll.01ca1e255938cd3b.0079
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-c..complus-runtime-qfe_31bf3856ad364e35_6.0.6000.16386_none_692c6c857ba3c205\$$DeleteMe.clbcatq.dll.01ca1e21445723da.00d7
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-c..ent-indexing-common_31bf3856ad364e35_6.0.6001.18000_none_06b40dcad71051f6\$$DeleteMe.Query.dll.01ca1e2558b11edb.0046
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-c..ent-indexing-common_31bf3856ad364e35_6.0.6000.16386_none_047d4bceda254122\$$DeleteMe.Query.dll.01ca1e2141f5c3da.0078
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-c..rformance-xperfcore_31bf3856ad364e35_6.0.6000.16386_none_d4dab19871ad5771\$$DeleteMe.diagperf.dll.01ca1e2144b65ada.00df
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-c..rformance-xperfcore_31bf3856ad364e35_6.0.6001.18000_none_d71173946e986845\$$DeleteMe.diagperf.dll.01ca1e2559b2335b.0090
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-cabinet_31bf3856ad364e35_6.0.6000.16386_none_35088f20e500a372\$$DeleteMe.cabinet.dll.01ca1e2143c8515a.00b6
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-cbsapi_31bf3856ad364e35_6.0.6000.16386_none_4c2b1119f37be620\$$DeleteMe.CbsApi.dll.01ca1e1f68a11364.0001
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-cmi_31bf3856ad364e35_6.0.6000.16386_none_a797884c5d9fcdc5\$$DeleteMe.cmiv2.dll.01ca1e2147879b7a.00f5
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-cmi_31bf3856ad364e35_6.0.6001.18000_none_a9ce4a485a8ade99\$$DeleteMe.cmiv2.dll.01ca1e255aa29e3b.00a1
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-coreusermodepnp_31bf3856ad364e35_6.0.6001.18000_none_7701ab362cebf905\$$DeleteMe.umpnpmgr.dll.01ca1e2559555dbb.0089
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-coreos_31bf3856ad364e35_6.0.6000.16386_none_231b844b41663663\$$DeleteMe.imagehlp.dll.01ca1e2144310dda.00ce
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-coreusermodepnp_31bf3856ad364e35_6.0.6000.16386_none_74cae93a3000e831\$$DeleteMe.umpnpmgr.dll.01ca1e1fc0fb8848.0000
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-coreusermodepnp_31bf3856ad364e35_6.0.6000.16609_none_75246f2a2fbd4c23\$$DeleteMe.cfgmgr32.dll.01ca1e214208ceda.007d
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-coreusermodepnp_31bf3856ad364e35_6.0.6000.16609_none_75246f2a2fbd4c23\$$DeleteMe.umpnpmgr.dll.01ca1e21444d9e5a.00d3
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-credui_31bf3856ad364e35_6.0.6000.16386_none_d9008ac592026334\$$DeleteMe.credui.dll.01ca1e213c44fa5a.0014
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-credui_31bf3856ad364e35_6.0.6001.18000_none_db374cc18eed7408\$$DeleteMe.credui.dll.01ca1e2557c576bb.0009
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-crypt32-dll_31bf3856ad364e35_6.0.6000.16386_none_5938ffdfe0e8b606\$$DeleteMe.crypt32.dll.01ca1e2143560f5a.00a7
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-crypt32-dll_31bf3856ad364e35_6.0.6001.18000_none_5b6fc1dbddd3c6da\$$DeleteMe.crypt32.dll.01ca1e25590df47b.0062
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-cryptdll-dll_31bf3856ad364e35_6.0.6000.16386_none_0367c3eab0da6051\$$DeleteMe.cryptdll.dll.01ca1e2142e3cd5a.0092
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6000.16386_none_73c8d7689de43d15\$$DeleteMe.cryptsvc.dll.01ca1e214057949a.0061
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6001.18000_none_75ff99649acf4de9\$$DeleteMe.cryptsvc.dll.01ca1e255877fddb.0037
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-csrsrv_31bf3856ad364e35_6.0.6000.16386_none_c7507509a87290f5\$$DeleteMe.csrsrv.dll.01ca1e213916e41a.000a
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-csrss_31bf3856ad364e35_6.0.6000.16386_none_56ad21dbe72a9d78\$$DeleteMe.csrss.exe.01ca1e213912215a.0008
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_sv-se_81fc82c1607b7353\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_zh-cn_fc66eb05ff6f4763\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_zh-hk_fb11e394004ab9f3\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_zh-tw_0063285bfce023d3\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..oryservices-ntdsapi_31bf3856ad364e35_6.0.6000.16386_none_cca68469f44b4003\$$DeleteMe.ntdsapi.dll.01ca1e213e87687a.0046
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..pwindowmanager-core_31bf3856ad364e35_6.0.6000.16386_none_8b6cd218c046ea63\$$DeleteMe.uxsms.dll.01ca1e2144310dda.00cf
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..pwindowmanager-core_31bf3856ad364e35_6.0.6001.18000_none_8da39414bd31fb37\$$DeleteMe.uxsms.dll.01ca1e25594e399b.0084
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..pwindowmanager-core_31bf3856ad364e35_6.0.6002.18005_none_8f8f0d20ba53c683\MICROS~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..files-x64.resources_31bf3856ad364e35_6.0.6000.16386_tr-tr_2b09cd084f377544\BOOTMG~1.MUI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-deltacompressionengine_31bf3856ad364e35_6.0.6000.16386_none_3df5a61c88d408ee\$$DeleteMe.mspatcha.dll.01ca1e213cc3233a.0028
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-deltapackageexpander_31bf3856ad364e35_6.0.6000.16609_none_68015a2337d92e69\$$DeleteMe.dpx.dll.01ca1e2142e8901a.0093
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.0.6000.16386_none_afb79761a4097d90\$$DeleteMe.samlib.dll.01ca1e2141e51a3a.0077
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.0.6000.16386_none_afb79761a4097d90\$$DeleteMe.samsrv.dll.01ca1e213d414c1a.002e
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.0.6001.18000_none_b1ee595da0f48e64\$$DeleteMe.samlib.dll.01ca1e2558aebd7b.0045
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-directory-services-sam_31bf3856ad364e35_6.0.6001.18000_none_b1ee595da0f48e64\$$DeleteMe.samsrv.dll.01ca1e2557fc365b.0016
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client-winrnr_31bf3856ad364e35_6.0.6000.16386_none_571790f3532b2696\$$DeleteMe.winrnr.dll.01ca1e2559c07b9b.0093
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.0.6000.16386_none_dfabbae1856e5297\$$DeleteMe.dnsapi.dll.01ca1e213d16735a.002b
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.0.6000.16386_none_dfabbae1856e5297\$$DeleteMe.dnsrslvr.dll.01ca1e213eb4a29a.004e
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.0.6001.18000_none_e1e27cdd8259636b\$$DeleteMe.dnsapi.dll.01ca1e2557f2b0db.0015
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-dns-client_31bf3856ad364e35_6.0.6001.18000_none_e1e27cdd8259636b\$$DeleteMe.dnsrslvr.dll.01ca1e25584600fb.0029
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-duser_31bf3856ad364e35_6.0.6000.16386_none_583dec4cff8f7125\$$DeleteMe.duser.dll.01ca1e214460a95a.00d9
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-e..emorydevicesservice_31bf3856ad364e35_6.0.6000.16386_none_9c552a52f9cf5068\$$DeleteMe.emdmgmt.dll.01ca1e21435f94da.00a8
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-e..emorydevicesservice_31bf3856ad364e35_6.0.6001.18000_none_9e8bec4ef6ba613c\$$DeleteMe.emdmgmt.dll.01ca1e255912b73b.0064
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-e..estorageengine-isam_31bf3856ad364e35_6.0.6000.16386_none_efad84e52f20ae35\$$DeleteMe.esent.dll.01ca1e2142df0a9a.0090
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-e..estorageengine-isam_31bf3856ad364e35_6.0.6001.18000_none_f1e446e12c0bbf09\$$DeleteMe.esent.dll.01ca1e2558e0ba5b.0056
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-eventlog-api_31bf3856ad364e35_6.0.6000.16386_none_a9fa4020685f2193\$$DeleteMe.wevtapi.dll.01ca1e213c853f7a.001e
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-eventlog-api_31bf3856ad364e35_6.0.6001.18000_none_ac31021c654a3267\$$DeleteMe.wevtapi.dll.01ca1e2557d6205b.000e
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-eventlog_31bf3856ad364e35_6.0.6000.16386_none_da8d9a1e15ee1eb0\$$DeleteMe.wevtsvc.dll.01ca1e213d5ddc9a.0030
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-eventlog_31bf3856ad364e35_6.0.6001.18000_none_dcc45c1a12d92f84\$$DeleteMe.wevtsvc.dll.01ca1e255800f91b.0017
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-failovercluster-client_31bf3856ad364e35_6.0.6000.16386_none_a4186fca55bd3a26\$$DeleteMe.clusapi.dll.01ca1e2140d81eda.006c
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-failovercluster-client_31bf3856ad364e35_6.0.6000.16386_none_a4186fca55bd3a26\$$DeleteMe.resutils.dll.01ca1e214315ca3a.009a
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-fax-common.resources_31bf3856ad364e35_6.0.6000.16386_en-us_4777ffb339c4e9f8\$$DeleteMe.FXSRESM.dll.mui.01ca1e214974581a.00fb
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-fax-service_31bf3856ad364e35_6.0.6000.16386_none_aaecd7c1835e5b9d\$$DeleteMe.FXSMON.dll.01ca1e2140d5bd7a.006b
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-feclient_31bf3856ad364e35_6.0.6000.16386_none_bca34f2f5aa9c40c\$$DeleteMe.feclient.dll.01ca1e214452611a.00d6
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-filtermanager-core_31bf3856ad364e35_6.0.6000.16386_none_0ed2b0f62de100b1\$$DeleteMe.fltMgr.sys.01ca1e213938375a.0010
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-fax-common_31bf3856ad364e35_6.0.6000.16386_none_09cdeced53b576c7\$$DeleteMe.FXSRESM.dll.01ca1e213c7e1b5a.001c
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-feclient_31bf3856ad364e35_6.0.6001.18000_none_beda112b5794d4e0\$$DeleteMe.feclient.dll.01ca1e25595a207b.008b
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-gdi32_31bf3856ad364e35_6.0.6000.16386_none_5747e8004c667a97\$$DeleteMe.gdi32.dll.01ca1e21434eeb3a.00a6
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-gdi32_31bf3856ad364e35_6.0.6001.18000_none_597ea9fc49518b6b\$$DeleteMe.gdi32.dll.01ca1e2558ffac3b.0061
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16386_none_a79c567c5d9b4c78\$$DeleteMe.lpk.dll.01ca1e21445723da.00d8
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-grouppolicy-base_31bf3856ad364e35_6.0.6001.18000_none_282361dee702a605\$$DeleteMe.gpapi.dll.01ca1e2558b3803b.0049
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-grouppolicy-base_31bf3856ad364e35_6.0.6001.18000_none_282361dee702a605\$$DeleteMe.gpsvc.dll.01ca1e25591e9e1b.006b
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-grouppolicy-base_31bf3856ad364e35_6.0.6000.16386_none_25ec9fe2ea179531\$$DeleteMe.gpapi.dll.01ca1e214201aaba.007b
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-grouppolicy-base_31bf3856ad364e35_6.0.6000.16386_none_25ec9fe2ea179531\$$DeleteMe.gpsvc.dll.01ca1e2143abc0da.00b1
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-http-api_31bf3856ad364e35_6.0.6000.16386_none_f3757b03a060c8ff\$$DeleteMe.httpapi.dll.01ca1e2144121bfa.00c7
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.18000_none_b4e317dbd6c9eb53\$$DeleteMe.urlmon.dll.01ca1e255919db5b.0069
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-i..nal-core-locale-nls_31bf3856ad364e35_6.0.6000.16386_none_68816eddac5ab0fd\$$DeleteMe.locale.nls.01ca1e2145ab887a.00e2
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-i..nal-core-locale-nls_31bf3856ad364e35_6.0.6001.18000_none_6ab830d9a945c1d1\$$DeleteMe.locale.nls.01ca1e2559bbb8db.0091
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-i..oexistencemigration_31bf3856ad364e35_6.0.6000.16386_none_0fac50d67f6f5ad2\$$DeleteMe.iphlpsvc.dll.01ca1e21390fbffa.0007
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-i..oexistencemigration_31bf3856ad364e35_6.0.6001.18000_none_11e312d27c5a6ba6\$$DeleteMe.iphlpsvc.dll.01ca1e2555a1fa7b.0004
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16386_none_ffb23181a4e80112\$$DeleteMe.wininet.dll.01ca1e2142c73cda.008a
Status: Locked to the Windows API!

Path: C:\WindoProcesses
——————-
Path: System
PID: 4 Status: Locked to the Windows API!

Path: C:\Windows\System32\audiodg.exe
PID: 1188 Status: Locked to the Windows API!

Stealth Objects
——————-
Object: Hidden Module [Name: kbiwkmwiwcsxab.dll]
Process: svchost.exe (PID: 856) Address: 0x10000000 Size: 53248

Object: Hidden Module [Name: kbiwkmjfqictmp.dll]
Process: Explorer.EXE (PID: 2124) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: kbiwkmjfqictmp.dll]
Process: iexplore.exe (PID: 4084) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: kbiwkmjfqictmp.dll]
Process: iexplore.exe (PID: 3660) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: kbiwkmjfqictmp.dll]
Process: iexplore.exe (PID: 4568) Address: 0x10000000 Size: 32768

Hidden Services
——————-
Service Name: kbiwkmmmowhqoe
Image Path: C:\Windows\system32\drivers\kbiwkmxsxvqsnu.sys

==EOF==
Hi

Please do the following:

Open RootRepeal,

click the files tab, click Scan.
Right click and select Wipe File on the following:

C:\Windows\System32\kbiwkmfisndpvm.dat


Do the same for the following files:

C:\Windows\System32\kbiwkmjfqictmp.dll
C:\Windows\System32\kbiwkmkkdojbmc.dll
C:\Windows\System32\kbiwkmnxtvxvuf.dat
C:\Windows\System32\kbiwkmpafwdqnp.dat
C:\Windows\System32\kbiwkmswpipcyr.dll
C:\Windows\System32\kbiwkmustvxpuv.dat
C:\Windows\System32\kbiwkmwiwcsxab.dll
C:\Windows\Temp\kbiwkmskxicqgrtc.tmp
C:\Windows\System32\drivers\kbiwkmxsxvqsnu.sys




Now click the hidden services tab, click Scan.
Right click and select Force Delete on the following:

kbiwkmmmowhqoe



Next: Delete all the copies of Combo-Fix that you have on your desktop, locate the folder at C:\ComboFix and delete it also.

Next - download a fresh copy - rename it to explorer.exe and run it.
Wow, I scanned with Gmer ( rmeg.com) in safe mode, and this is result


GMER

GMER 1.0.15.15077 [remg.com.exe] - http://www.gmer.net
Rootkit scan 2009-08-26 09:08:25
Windows 6.0.6002 Service Pack 2


—- System - GMER 1.0.15 —-

Code 8670A2D8 ZwEnumerateKey
Code 8671C310 ZwFlushInstructionCache
Code 866F435E ZwSaveKey
Code 8670A30E ZwSaveKeyEx
Code 866F4395 IofCallDriver
Code 866ED346 IofCompleteRequest

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \FileSystem\fastfat \Fat 829CEA7A

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Services - GMER 1.0.15 —-

Service C:\Windows\System32\alg.exe? (*** hidden *** ) [MANUAL] ALG <– ROOTKIT !!!
Service C:\Windows\system32\drivers\kbiwkmxsxvqsnu.sys (*** hidden *** ) [SYSTEM] kbiwkmmmowhqoe <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002186741b2c
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmmmowhqoe
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmmmowhqoe@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmmmowhqoe@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmmmowhqoe@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmmmowhqoe@imagepath \systemroot\system32\drivers\kbiwkmxsxvqsnu.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmmmowhqoe\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmmmowhqoe\main@aid 10093
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmmmowhqoe\main@sid 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmmmowhqoe\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmmmowhqoe\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmmmowhqoe\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmmmowhqoe\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmmmowhqoe\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmmmowhqoe\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmmmowhqoe\[removed] \systemroot\system32\drivers\kbiwkmxsxvqsnu.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmmmowhqoe\[removed] \systemroot\system32\kbiwkmwiwcsxab.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmmmowhqoe\[removed] \systemroot\system32\kbiwkmnxtvxvuf.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmmmowhqoe\[removed] \systemroot\system32\kbiwkmjfqictmp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmmmowhqoe\[removed] \systemroot\system32\kbiwkmfisndpvm.dat
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\002186741b2c (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmmmowhqoe (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmmmowhqoe@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmmmowhqoe@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmmmowhqoe@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmmmowhqoe@imagepath \systemroot\system32\drivers\kbiwkmxsxvqsnu.sys
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmmmowhqoe\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmmmowhqoe\main@aid 10093
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmmmowhqoe\main@sid 0
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmmmowhqoe\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmmmowhqoe\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmmmowhqoe\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmmmowhqoe\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmmmowhqoe\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmmmowhqoe\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmmmowhqoe\[removed] \systemroot\system32\drivers\kbiwkmxsxvqsnu.sys
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmmmowhqoe\[removed] \systemroot\system32\kbiwkmwiwcsxab.dll
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmmmowhqoe\[removed] \systemroot\system32\kbiwkmnxtvxvuf.dat
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmmmowhqoe\[removed] \systemroot\system32\kbiwkmjfqictmp.dll
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmmmowhqoe\[removed] \systemroot\system32\kbiwkmfisndpvm.dat

—- Files - GMER 1.0.15 —-

File C:\Windows\System32\drivers\kbiwkmxsxvqsnu.sys 72704 bytes executable <– ROOTKIT !!!
File C:\Windows\System32\kbiwkmfisndpvm.dat 91 bytes
File C:\Windows\System32\kbiwkmjfqictmp.dll 20480 bytes executable
File C:\Windows\System32\kbiwkmkkdojbmc.dll 45056 bytes executable
File C:\Windows\System32\kbiwkmnxtvxvuf.dat 2390 bytes
File C:\Windows\System32\kbiwkmpafwdqnp.dat 39495 bytes
File C:\Windows\System32\kbiwkmswpipcyr.dll 20992 bytes executable
File C:\Windows\System32\kbiwkmustvxpuv.dat 91 bytes
File C:\Windows\System32\kbiwkmwiwcsxab.dll 45056 bytes executable

—- EOF - GMER 1.0.15 —-
This Gmer Log, is before you posted how to delete by Root repeal I 'm doing what you said above. And then ? How about with ALG .exe notice in Gmer log ? (is it a rootkit ) o_O ========================================= Following what you said Wiping those file are ok, but, scan hidden service; = > kbiwkmmmowhqoe I can't force delete it ; A notice : Could not force-delete file ! Error code 0xc0000156 ========================================= I use root repeal in Safe mode, there aren't *.dll and *.dat , *.sys , but There is a hidden service. kbiwkmmmowhqoe. I force deleted it, and it still there if i rescan. Maybe because can't delete *.dll..etc before.
Hi, ComboFix has been updated to try and deal with this infection. (this is a new one and is proving tough to kill - so bear with us) Can you please delete the ComboFix program you have on your system and download a fresh copy from one of the links previously provided. Rename it to Combo-fix.exe and try it again
woa, this update of Combo Fix is effective. I can run the application.
First, I renamed it to Combo-fix.exe and use it in Safe mode.
And, this is a Log of combo FIx


COMBO FIX log


ComboFix 09-08-25.04 - o0 Virgo 0o 08/26/2009 18:58.1.2 - NTFSx86 MINIMAL
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.3068.2696 [GMT 7:00]
Running from: c:\users\[removed]\Desktop\Combo-fix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
PEV Error: CacheFolder
/wow section not completed

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_kbiwkmmmowhqoe
——-\Service_kbiwkmmmowhqoe


((((((((((((((((((((((((( Files Created from 2009-07-26 to 2009-08-26 )))))))))))))))))))))))))))))))
.

2009-08-25 21:33 . 2009-08-25 21:33 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Local\ESET
2009-08-25 21:16 . 2009-08-26 02:20 91 —-a-w- c:\windows\system32\kbiwkmfisndpvm.dat
2009-08-25 20:59 . 2009-08-25 20:59 20480 —-a-w- c:\windows\system32\kbiwkmjfqictmp.dll
2009-08-25 20:59 . 2009-08-26 02:20 4045 —-a-w- c:\windows\system32\kbiwkmnxtvxvuf.dat
2009-08-25 20:59 . 2009-08-25 20:59 45056 —-a-w- c:\windows\system32\kbiwkmwiwcsxab.dll
2009-08-22 11:28 . 2009-08-22 11:28 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\Media Player Classic
2009-08-20 20:20 . 2008-03-03 11:21 568 —ha-w- c:\windows\nod32fixtemdono.reg
2009-08-20 20:20 . 2008-03-03 07:25 5702 —ha-w- c:\windows\nod32restoretemdono.reg
2009-08-20 18:09 . 2009-08-20 18:09 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\Desktopicon
2009-08-20 17:52 . 2009-08-20 17:52 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\Malwarebytes
2009-08-20 17:52 . 2009-08-03 06:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-20 17:52 . 2009-08-20 17:52 ——– d—–w- c:\programdata\Malwarebytes
2009-08-20 17:52 . 2009-08-03 06:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-20 17:29 . 2008-12-11 01:38 159600 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-08-20 17:29 . 2009-04-03 03:18 130936 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2009-08-20 17:29 . 2008-12-18 04:16 73840 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-08-20 17:28 . 2009-08-20 17:31 ——– d—–w- c:\program files\Common Files\PC Tools
2009-08-20 17:28 . 2008-12-10 04:36 64392 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2009-08-20 17:28 . 2009-08-20 17:28 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\PC Tools
2009-08-20 17:28 . 2009-08-20 17:28 ——– d—–w- c:\programdata\PC Tools
2009-08-20 17:09 . 2005-12-21 04:23 14592 —-a-w- c:\windows\system32\drivers\USBICP.sys
2009-08-20 17:09 . 2005-11-02 03:54 11596 —-a-w- c:\windows\system32\drivers\copperhd.sys
2009-08-20 16:58 . 2009-08-20 16:58 ——– d—–w- c:\programdata\FLEXnet
2009-08-20 12:17 . 2009-08-20 12:17 ——– d—–w- c:\users\o0 Virgo 0o\Bluetooth Software
2009-08-20 12:17 . 2008-02-01 08:41 80936 —-a-w- c:\windows\system32\drivers\btwavdt.sys
2009-08-20 12:17 . 2008-02-01 08:41 80424 —-a-w- c:\windows\system32\drivers\btwaudio.sys
2009-08-20 12:17 . 2008-02-01 08:41 16168 —-a-w- c:\windows\system32\drivers\btwrchid.sys
2009-08-20 12:17 . 2008-02-01 08:41 233472 —-a-w- c:\windows\system32\BtwRSupport.dll
2009-08-20 12:17 . 2009-08-20 12:17 ——– d—–w- c:\windows\system32\es-MX
2009-08-20 12:17 . 2009-08-20 12:17 ——– d—–w- c:\windows\system32\es-AR
2009-08-20 12:15 . 2009-08-25 12:28 12 —-a-w- c:\windows\bthservsdp.dat
2009-08-20 12:12 . 2009-08-20 12:12 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\DigitalPersona
2009-08-20 12:12 . 2009-08-20 12:12 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Local\DigitalPersona
2009-08-20 12:05 . 2009-08-20 12:05 ——– d—–w- c:\program files\Cyberlink
2009-08-20 12:01 . 2009-08-20 12:01 10134 —-a-r- c:\users\o0 Virgo 0o\AppData\Roaming\Microsoft\Installer\{F48098CD-2D66-4861-85EC-DC1D4D09D5F9}\ARPPRODUCTICON.exe
2009-08-20 12:00 . 2009-08-20 12:00 ——– d—–w- c:\program files\Java
2009-08-20 12:00 . 2009-08-20 12:00 ——– d—–w- c:\program files\Common Files\Java
2009-08-20 11:59 . 2009-08-20 00:11 ——– d—–w- c:\windows\system32\macromed
2009-08-20 11:59 . 2009-08-20 11:59 411494 —-a-r- c:\users\o0 Virgo 0o\AppData\Roaming\Microsoft\Installer\{30DAA715-5032-40F9-A0AE-95C9AEBB3E3F}\_6FEFF9B68218417F98F549.exe
2009-08-20 11:59 . 2009-08-19 22:54 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Local\QuickPlay
2009-08-20 11:59 . 2009-08-20 11:59 ——– d—–w- c:\programdata\CyberLink
2009-08-20 11:58 . 2008-04-24 06:52 82432 —-a-w- c:\windows\system32\msxml4r.dll
2009-08-20 11:58 . 2008-04-24 06:52 44544 —-a-w- c:\windows\system32\msxml4a.dll
2009-08-20 11:58 . 2008-04-24 06:52 1233920 —-a-w- c:\windows\system32\msxml4.dll
2009-08-20 11:58 . 2008-04-24 06:52 499712 ——w- c:\windows\system32\msvcp71.dll
2009-08-20 11:52 . 2009-08-20 11:52 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\Macrovision
2009-08-20 11:49 . 2009-08-20 11:49 ——– d—–w- c:\programdata\NVIDIA
2009-08-20 11:45 . 2008-05-23 03:29 768544 —-a-w- c:\windows\system32\nvcplui.exe
2009-08-20 11:45 . 2008-05-23 03:29 313888 —-a-w- c:\windows\system32\nvexpbar.dll
2009-08-20 11:45 . 2008-05-23 03:29 1079840 —-a-w- c:\windows\system32\nvcpluir.dll
2009-08-20 11:45 . 2008-05-21 21:49 446464 —-a-w- c:\windows\system32\NVUNINST.EXE
2009-08-20 11:45 . 2009-08-20 11:54 ——– d—–w- c:\windows\Driver Cache
2009-08-20 11:45 . 2009-08-20 11:45 ——– d—–w- c:\program files\AVerMedia
2009-08-20 11:45 . 2008-04-22 12:16 934912 —-a-w- c:\windows\system32\drivers\AVerBDA716x.sys
2009-08-20 11:45 . 2008-03-04 06:53 3072 —-a-w- c:\windows\system32\716xCoInstaller.dll
2009-08-20 11:44 . 2009-08-20 11:44 ——– d—–w- c:\program files\Synaptics
2009-08-20 11:44 . 2009-08-20 11:44 ——– d—–w- c:\windows\system32\ENU
2009-08-20 11:44 . 2009-08-20 11:44 ——– d—–w- c:\windows\system32\Lang
2009-08-20 11:44 . 2008-04-18 20:29 1034776 —-a-w- c:\windows\system32\imsmudlg.exe
2009-08-20 11:44 . 2006-11-10 16:25 319456 —-a-w- c:\windows\system32\difxapi.dll
2009-08-20 11:44 . 2008-04-16 00:53 312344 —-a-w- c:\windows\system32\drivers\iaStor.sys
2009-08-20 11:43 . 2009-08-20 12:04 ——– d—–w- c:\program files\Hewlett-Packard
2009-08-20 11:43 . 2009-08-20 11:43 ——– d—–w- c:\windows\system32\HPMDP
2009-08-20 11:43 . 2009-08-20 11:43 ——– d—–w- c:\program files\Realtek
2009-08-20 11:43 . 2008-04-15 10:05 118784 —-a-w- c:\windows\system32\drivers\Rtlh86.sys
2009-08-20 11:43 . 2009-08-20 11:43 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\InstallShield
2009-08-20 11:43 . 2008-02-29 23:07 54824 ——w- c:\windows\system32\agrsmdel.exe
2009-08-20 11:42 . 2009-08-20 12:17 ——– d—–w- C:\SWSetup
2009-08-20 11:42 . 2009-08-20 11:42 ——– d—–w- c:\windows\Options
2009-08-20 11:42 . 2009-08-20 11:42 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\Hewlett Packard
2009-08-20 11:42 . 2009-08-20 11:42 ——– d—–w- c:\program files\Validity Sensors, Inc
2009-08-20 11:42 . 2009-08-20 20:14 ——– d-sh–w- c:\windows\Installer
2009-08-20 11:41 . 2009-08-20 11:41 251 —-a-w- c:\windows\xUninstall.bat
2009-08-20 11:41 . 2009-08-20 11:41 ——– d—–w- c:\windows\JMCR_DIR
2009-08-20 11:40 . 2009-08-20 11:44 ——– d—–w- c:\program files\Intel
2009-08-20 11:40 . 2008-03-26 11:15 53248 —-a-w- c:\windows\system32\CSVer.dll
2009-08-20 09:45 . 2009-08-20 09:45 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Local\Yahoo
2009-08-20 01:00 . 2009-08-20 01:00 ——– d—–w- c:\program files\Adobe Media Player
2009-08-20 00:59 . 2009-08-20 00:59 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-08-20 00:59 . 2009-08-20 16:58 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Local\Adobe
2009-08-20 00:57 . 2009-08-20 00:57 ——– d—–w- c:\program files\Common Files\Macrovision Shared
2009-08-20 00:56 . 2009-08-20 01:00 ——– d—–w- c:\program files\Common Files\Adobe
2009-08-20 00:06 . 2009-08-20 09:43 ——– d—–w- c:\programdata\Yahoo!
2009-08-20 00:06 . 2009-05-27 02:50 607472 —-a-w- c:\programdata\Yahoo!\YUpdater\yupdater.exe
2009-08-20 00:06 . 2009-08-20 00:06 ——– d—–w- c:\program files\Yahoo!
2009-08-19 23:57 . 2006-10-27 02:56 32592 —-a-w- c:\windows\system32\msonpmon.dll
2009-08-19 23:56 . 2009-08-19 23:56 ——– d—–w- c:\program files\Microsoft Works
2009-08-19 23:55 . 2009-08-19 23:55 ——– d—–w- c:\windows\PCHEALTH
2009-08-19 23:55 . 2009-08-19 23:55 ——– d—–w- c:\program files\Microsoft.NET
2009-08-19 23:50 . 2009-08-19 23:51 ——– d—–w- c:\program files\Microsoft Visual Studio 8
2009-08-19 23:50 . 2009-08-19 23:50 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Local\Microsoft Help
2009-08-19 23:50 . 2009-08-19 23:57 ——– d—–w- c:\programdata\Microsoft Help
2009-08-19 23:41 . 2009-08-19 23:41 198064 —-a-w- c:\users\o0 Virgo 0o\AppData\Roaming\IDM\idmmzcc3\components\idmmzcc.dll
2009-08-19 23:41 . 2009-08-26 11:16 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\DMCache
2009-08-19 23:41 . 2009-08-20 10:03 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\IDM
2009-08-19 23:38 . 2009-08-19 23:38 ——– d—–w- c:\program files\Common Files\PX Storage Engine
2009-08-19 23:38 . 2009-08-19 23:38 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Local\Google
2009-08-19 23:38 . 2009-08-19 23:38 ——– d—–w- c:\windows\system32\IOSUBSYS
2009-08-19 23:38 . 2009-08-19 23:38 ——– d—–w- c:\program files\Google
2009-08-19 23:26 . 2009-08-19 23:36 ——– d—–w- c:\windows\Lhsp
2009-08-19 23:26 . 2009-08-19 23:26 ——– d—–w- c:\programdata\InstallShield
2009-08-19 23:26 . 2006-05-12 20:11 58368 —-a-w- c:\windows\system32\TCaptureX.dll
2009-08-19 23:26 . 2006-05-12 20:11 27648 —-a-w- c:\windows\system32\RL.dll
2009-08-19 23:26 . 2006-05-12 20:11 98304 —-a-w- c:\windows\system32\TCapture.dll
2009-08-19 23:26 . 2006-05-12 20:11 7168 —-a-w- c:\windows\system32\TCCustom.dll
2009-08-19 23:26 . 1998-06-17 07:00 385100 —-a-w- c:\windows\system32\Msvcrtd.dll
2009-08-19 23:20 . 2009-08-19 23:20 7168 —-a-r- c:\users\o0 Virgo 0o\AppData\Roaming\Microsoft\Installer\{4A536737-E71D-452F-984F-F8C0B0298226}\Icon4A536737.exe
2009-08-19 23:15 . 2009-08-26 11:12 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\MTD
2009-08-19 23:13 . 2009-08-25 19:10 91 —-a-w- c:\windows\system32\kbiwkmustvxpuv.dat
2009-08-19 23:11 . 2009-08-19 23:12 1078 —-a-r- c:\users\o0 Virgo 0o\AppData\Roaming\Microsoft\Installer\{09BA3667-5D11-4488-8896-15A8F793081E}\_7FBACBD5C7DB60B99958DE.exe
2009-08-19 23:11 . 2009-08-19 23:12 1078 —-a-r- c:\users\o0 Virgo 0o\AppData\Roaming\Microsoft\Installer\{09BA3667-5D11-4488-8896-15A8F793081E}\_7C32ABCB52D91D23912A1B.exe
2009-08-19 23:11 . 2009-08-19 23:12 1078 —-a-r- c:\users\o0 Virgo 0o\AppData\Roaming\Microsoft\Installer\{09BA3667-5D11-4488-8896-15A8F793081E}\_2B2929C08304EDEC6FCC6C.exe
2009-08-19 23:11 . 2009-08-19 23:12 ——– d—–w- c:\program files\Common Files\L&H;
2009-08-19 23:04 . 2009-08-19 23:04 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\Foxit
2009-08-19 23:03 . 2009-08-25 15:10 20992 —-a-w- c:\windows\system32\kbiwkmswpipcyr.dll
2009-08-19 23:03 . 2009-08-25 20:50 39495 —-a-w- c:\windows\system32\kbiwkmpafwdqnp.dat
2009-08-19 23:03 . 2009-08-19 23:03 45056 —-a-w- c:\windows\system32\kbiwkmkkdojbmc.dll
2009-08-19 23:02 . 2009-08-19 23:02 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Local\Hewlett-Packard
2009-08-19 22:57 . 2009-08-19 22:57 ——– d—–w- c:\program files\Common Files\EZB Systems
2009-08-19 22:45 . 2009-03-08 11:33 18944 —-a-w- c:\windows\system32\corpol.dll
2009-08-19 22:39 . 2009-08-19 22:39 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Local\Mozilla
2009-08-19 22:39 . 2009-08-19 22:39 0 —-a-w- c:\windows\nsreg.dat
2009-08-19 22:37 . 2009-08-19 22:37 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\URSoft
2009-08-16 03:55 . 2009-08-16 03:55 ——– d—–w- c:\windows\system32\ca-ES
2009-08-16 03:55 . 2009-08-16 03:55 ——– d—–w- c:\windows\system32\vi-VN

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-26 12:12 . 2009-08-20 11:49 28409 —-a-w- c:\programdata\nvModes.dat
2009-08-23 18:02 . 2009-08-23 18:02 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-08-20 17:09 . 2009-08-20 11:39 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-20 11:58 . 2009-08-20 11:53 ——– d—–w- c:\program files\HP
2009-08-20 11:57 . 2009-08-20 11:57 ——– d—–w- c:\program files\Common Files\muvee Technologies
2009-08-20 11:56 . 2009-08-20 11:56 ——– d—–w- c:\programdata\muvee Technologies
2009-08-20 11:53 . 2009-08-20 11:53 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\GTek
2009-08-20 11:51 . 2009-08-20 11:51 ——– d—–w- c:\programdata\Macrovision
2009-08-20 11:44 . 2009-08-20 11:44 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_SynTP_01000.Wdf
2009-08-20 11:39 . 2009-08-20 11:39 ——– d—–w- c:\program files\IDT
2009-08-20 11:27 . 2009-08-16 02:41 680 —-a-w- c:\users\o0 Virgo 0o\AppData\Local\d3d9caps.dat
2009-08-19 23:56 . 2006-11-02 12:35 ——– d—–w- c:\program files\MSBuild
2009-08-19 23:25 . 2009-08-20 11:39 ——– d—–w- c:\program files\Common Files\InstallShield
2009-08-16 03:55 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Calendar
2009-08-16 03:55 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Sidebar
2009-08-16 03:55 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Journal
2009-08-16 03:55 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Collaboration
2009-08-16 03:55 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-08-16 03:55 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Photo Gallery
2009-08-16 03:55 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Defender
2009-08-16 03:54 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-08-16 03:18 . 2006-11-02 10:32 101888 —-a-w- c:\windows\system32\ifxcardm.dll
2009-08-16 03:18 . 2006-11-02 10:32 82432 —-a-w- c:\windows\system32\axaltocm.dll
2009-07-21 21:52 . 2009-08-19 22:47 915456 —-a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-08-19 22:47 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-08-19 22:47 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-08-19 22:47 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-06-02 16:11 . 2009-08-19 23:09 85504 —-a-w- c:\windows\system32\ff_vfw.dll
2009-05-29 21:37 . 2009-08-19 23:09 205824 —-a-w- c:\windows\system32\xvidvfw.dll
2009-05-29 21:31 . 2009-08-19 23:09 881664 —-a-w- c:\windows\system32\xvidcore.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-04-15 442433]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1033512]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-23 13539872]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-23 92704]
"DpAgent"="c:\swsetup\DigitalPersona\Bin\dpagent.exe" [2008-03-13 699456]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-01 202032]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-04-24 468264]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-11-02 554288]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"Copperhead"="d:\install\Razer\Copperhead\razerhid.exe" [2005-11-25 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):73,9b,c5,f6,25,1e,ca,01

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{F37CE7F3-0A15-4100-A8B9-43309CDEF30B}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{04D0E3CB-B3B4-4E31-A2E8-062453044F53}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{6858130A-3A16-4DC4-A279-C0D2D979DF47}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{A81D3BAF-2DAE-4452-8DDC-4E8AABB9FC60}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{85F15BBD-3966-4A53-BC85-4E3B6946F6DA}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{3128B626-9E7D-4C11-A7C0-F5D2F4A98ED8}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{B0FED4C7-9793-41C3-81C5-2D7D9B18BF77}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{4748A060-01ED-42A0-8ED0-85841D311823}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{56455DD1-3D14-4774-8DE9-AD907E8C46F8}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{103AEEA9-9B8F-4169-929B-7C4819AA08CD}"= UDP:5353:Adobe CSI CS4
"{BC59EA95-FB1E-427E-9C97-B23EF8008F3D}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{64360198-D8D4-4438-8D6F-6BBACFE42F7B}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R0 PCTCore;PCTools KDS;c:\windows\System32\drivers\PCTCore.sys [8/21/2009 12:29 AM 130936]
R1 ehdrv;ehdrv;c:\windows\System32\drivers\ehdrv.sys [2/6/2009 2:23 PM 106208]
R2 {22D78859-9CE9-4B77-BF18-AC83E81A9263};{22D78859-9CE9-4B77-BF18-AC83E81A9263};c:\program files\HP\QuickPlay\000.fcl [8/20/2009 6:58 PM 39408]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\AEstSrv.exe [8/20/2009 6:39 PM 73728]
R2 ekrn;ESET Service;d:\install\ESET Smart Security 4\ekrn.exe [2/6/2009 2:23 PM 727720]
R2 epfwwfp;epfwwfp;c:\windows\System32\drivers\epfwwfp.sys [2/6/2009 2:24 PM 38240]
R2 hpsrv;HP Service;c:\windows\System32\hpservice.exe [3/19/2008 6:24 AM 19456]
R2 MBAMService;MBAMService;d:\install\Malwarebytes' Anti-Malware\mbamservice.exe [8/21/2009 12:52 AM 232720]
R2 vfsFPService;Validity Fingerprint Service;c:\windows\System32\vfsFPService.exe [3/27/2008 8:27 AM 595248]
R3 AVerBDA6x;AVerBDA6x service;c:\windows\System32\drivers\AVerBDA716x.sys [8/20/2009 6:45 PM 934912]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [8/20/2009 6:57 PM 193840]
R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [10/28/2008 1:39 PM 52736]
R3 JMCR;JMCR;c:\windows\System32\drivers\jmcr.sys [10/28/2008 1:39 PM 81296]
R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [8/21/2009 12:52 AM 19096]
R3 NETw5v32;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\System32\drivers\NETw5v32.sys [10/28/2008 1:39 PM 3658752]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [10/28/2008 1:39 PM 43552]
R3 vfs101x;vfs101x;c:\windows\System32\drivers\vfs101x.sys [3/27/2008 8:28 AM 40752]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\System32\regedt32.exe [11/2/2006 3:32 PM 9216]
S3 sdAuxService;PC Tools Auxiliary Service;d:\install\Spyware Doctor\pctsAuxs.exe [8/21/2009 12:28 AM 348752]
S3 UsbFltr;Razer Copperhead Driver;c:\windows\System32\drivers\copperhd.sys [8/21/2009 12:09 AM 11596]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-UniKey - d:\install\UniKey 4.0.8


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com.vn/
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: Download all links with IDM - d:\install\Internet Download Manager 5.17\IEGetAll.htm
IE: Download FLV video content with IDM - d:\install\Internet Download Manager 5.17\IEGetVL.htm
IE: Download with IDM - d:\install\Internet Download Manager 5.17\IEExt.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth; Device… - c:\swsetup\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth; Device… - c:\swsetup\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: {A0D5BE24-2A69-4825-B6B4-232AB7C22CE6} = 203.113.131.1,203.113.131.2
FF - ProfilePath - c:\users\o0 Virgo 0o\AppData\Roaming\Mozilla\Firefox\Profiles\hbza7uts.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.vn/
FF - component: c:\users\o0 Virgo 0o\AppData\Roaming\IDM\idmmzcc3\components\idmmzcc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: d:\install\K-Lite Mega Codec Pack 5.05\Real\browser\plugins\nppl3260.dll
FF - plugin: d:\install\K-Lite Mega Codec Pack 5.05\Real\browser\plugins\nprpjplug.dll
FF - plugin: d:\install\Picasa3\npPicasa3.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-26 19:12
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{22D78859-9CE9-4B77-BF18-AC83E81A9263}]
"ImagePath"="\??\c:\program files\HP\QuickPlay\000.fcl"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(704)
c:\windows\system32\DPPWDFLT.dll

- - - - - - - > 'Explorer.exe'(1176)
c:\swsetup\DigitalPersona\Bin\DpoFeedb.dll
d:\install\UniKey 4.0.8 Final\UKHook40.dll
c:\windows\system32\btncopy.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\stacsv.exe
c:\windows\System32\audiodg.exe
c:\swsetup\DigitalPersona\Bin\DpHostW.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\agrsmsvc.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
c:\program files\HP\QuickPlay\Kernel\TV\QPSched.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
c:\windows\System32\rundll32.exe
d:\install\UniKey 4.0.8 Final\UniKey.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
d:\install\Razer\Copperhead\razerofa.exe
c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
.
**************************************************************************
.
Completion time: 2009-08-26 19:14 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-26 12:14

Pre-Run: 67,965,755,392 bytes free
Post-Run: 64,503,128,064 bytes free

401
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Plzz_help_me_Root_kit_agent_ODG_AGAIN_t106299.html&view=findpost&p=590680#entry590680

Collect::
c:\windows\system32\kbiwkmfisndpvm.dat
c:\windows\system32\kbiwkmjfqictmp.dll
c:\windows\system32\kbiwkmnxtvxvuf.dat
c:\windows\system32\kbiwkmwiwcsxab.dll
c:\windows\system32\kbiwkmustvxpuv.dat
c:\windows\system32\kbiwkmswpipcyr.dll
c:\windows\system32\kbiwkmpafwdqnp.dat
c:\windows\system32\kbiwkmkkdojbmc.dll

DirLook::
c:\users\o0 Virgo 0o\AppData\Roaming\MTD
c:\program files\Common Files\L&H

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]

  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Note: At the completion of ComboFix, it will request to upload files for analysis - please allow it to do so:
Can you please explain me why we don't care about this hidden service :
"kbiwkmmmowhqoe " from " C:\Windows\System32\drivers\kbiwkmxsxvqsnu.sys " in script we put in Combo Fix ???
Oh, I can run combofix in Normal mode.
I create a Script file like above and drag to combo fix. But, why we have the link of this topic in the script ?


This is a log of Combo Fix after scan: I see some delete failed :-(


ComboFix 09-08-25.04 - o0 Virgo 0o 08/27/2009 6:29.2.2 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.3068.2101 [GMT 7:00]
Running from: c:\users\[removed]\Desktop\Combo-fix.exe
Command switches used :: c:\users\o0 Virgo 0o\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
* Resident AV is active


file zipped: c:\windows\system32\kbiwkmfisndpvm.dat
file zipped: c:\windows\system32\kbiwkmjfqictmp.dll
file zipped: c:\windows\system32\kbiwkmkkdojbmc.dll
file zipped: c:\windows\system32\kbiwkmnxtvxvuf.dat
file zipped: c:\windows\system32\kbiwkmpafwdqnp.dat
file zipped: c:\windows\system32\kbiwkmswpipcyr.dll
file zipped: c:\windows\system32\kbiwkmustvxpuv.dat
file zipped: c:\windows\system32\kbiwkmwiwcsxab.dll
.
PEV Error: CacheFolder

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Default\NTUSER.DAT{0f69446d-6a70-11db-8eb3-985e31beb686}.TMContainer00000000000000000001.regtrans-ms
c:\windows\system32\config\systemprofile\ntuser.dat{2e8a087a-8a0c-11de-b60e-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms
c:\windows\system32\kbiwkmfisndpvm.dat
c:\windows\system32\kbiwkmjfqictmp.dll
c:\windows\system32\kbiwkmkkdojbmc.dll
c:\windows\system32\kbiwkmnxtvxvuf.dat
c:\windows\system32\kbiwkmpafwdqnp.dat
c:\windows\system32\kbiwkmswpipcyr.dll
c:\windows\system32\kbiwkmustvxpuv.dat
c:\windows\system32\kbiwkmwiwcsxab.dll
c:\users\o0 Virgo 0o\NTUSER.DAT{0f69446d-6a70-11db-8eb3-985e31beb686}.TMContainer00000000000000000001.regtrans-ms . . . . failed to delete
c:\windows\ServiceProfiles\LocalService\NTUSER.DAT{0f694465-6a70-11db-8eb3-985e31beb686}.TMContainer00000000000000000001.regtrans-ms . . . . failed to delete
c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT{0f694461-6a70-11db-8eb3-985e31beb686}.TMContainer00000000000000000001.regtrans-ms . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2009-07-26 to 2009-08-26 )))))))))))))))))))))))))))))))
.

2009-08-26 23:34 . 2009-08-26 23:37 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Local\temp
2009-08-26 23:34 . 2009-08-26 23:34 ——– d—–w- c:\users\Public\AppData\Local\temp
2009-08-26 23:34 . 2009-08-26 23:34 ——– d—–w- c:\users\Default\AppData\Local\temp
2009-08-25 21:33 . 2009-08-25 21:33 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Local\ESET
2009-08-22 11:28 . 2009-08-22 11:28 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\Media Player Classic
2009-08-20 20:20 . 2008-03-03 11:21 568 —ha-w- c:\windows\nod32fixtemdono.reg
2009-08-20 20:20 . 2008-03-03 07:25 5702 —ha-w- c:\windows\nod32restoretemdono.reg
2009-08-20 18:09 . 2009-08-20 18:09 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\Desktopicon
2009-08-20 17:52 . 2009-08-20 17:52 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\Malwarebytes
2009-08-20 17:52 . 2009-08-03 06:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-20 17:52 . 2009-08-20 17:52 ——– d—–w- c:\programdata\Malwarebytes
2009-08-20 17:52 . 2009-08-03 06:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-20 17:29 . 2008-12-11 01:38 159600 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-08-20 17:29 . 2009-04-03 03:18 130936 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2009-08-20 17:29 . 2008-12-18 04:16 73840 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-08-20 17:28 . 2009-08-20 17:31 ——– d—–w- c:\program files\Common Files\PC Tools
2009-08-20 17:28 . 2008-12-10 04:36 64392 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2009-08-20 17:28 . 2009-08-20 17:28 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\PC Tools
2009-08-20 17:28 . 2009-08-20 17:28 ——– d—–w- c:\programdata\PC Tools
2009-08-20 17:09 . 2005-12-21 04:23 14592 —-a-w- c:\windows\system32\drivers\USBICP.sys
2009-08-20 17:09 . 2005-11-02 03:54 11596 —-a-w- c:\windows\system32\drivers\copperhd.sys
2009-08-20 16:58 . 2009-08-20 16:58 ——– d—–w- c:\programdata\FLEXnet
2009-08-20 12:17 . 2009-08-20 12:17 ——– d—–w- c:\users\o0 Virgo 0o\Bluetooth Software
2009-08-20 12:17 . 2008-02-01 08:41 80936 —-a-w- c:\windows\system32\drivers\btwavdt.sys
2009-08-20 12:17 . 2008-02-01 08:41 80424 —-a-w- c:\windows\system32\drivers\btwaudio.sys
2009-08-20 12:17 . 2008-02-01 08:41 16168 —-a-w- c:\windows\system32\drivers\btwrchid.sys
2009-08-20 12:17 . 2008-02-01 08:41 233472 —-a-w- c:\windows\system32\BtwRSupport.dll
2009-08-20 12:17 . 2009-08-20 12:17 ——– d—–w- c:\windows\system32\es-MX
2009-08-20 12:17 . 2009-08-20 12:17 ——– d—–w- c:\windows\system32\es-AR
2009-08-20 12:15 . 2009-08-25 12:28 12 —-a-w- c:\windows\bthservsdp.dat
2009-08-20 12:12 . 2009-08-20 12:12 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\DigitalPersona
2009-08-20 12:12 . 2009-08-20 12:12 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Local\DigitalPersona
2009-08-20 12:05 . 2009-08-20 12:05 ——– d—–w- c:\program files\Cyberlink
2009-08-20 12:01 . 2009-08-20 12:01 10134 —-a-r- c:\users\o0 Virgo 0o\AppData\Roaming\Microsoft\Installer\{F48098CD-2D66-4861-85EC-DC1D4D09D5F9}\ARPPRODUCTICON.exe
2009-08-20 12:00 . 2009-08-20 12:00 ——– d—–w- c:\program files\Java
2009-08-20 12:00 . 2009-08-20 12:00 ——– d—–w- c:\program files\Common Files\Java
2009-08-20 11:59 . 2009-08-20 00:11 ——– d—–w- c:\windows\system32\macromed
2009-08-20 11:59 . 2009-08-20 11:59 411494 —-a-r- c:\users\o0 Virgo 0o\AppData\Roaming\Microsoft\Installer\{30DAA715-5032-40F9-A0AE-95C9AEBB3E3F}\_6FEFF9B68218417F98F549.exe
2009-08-20 11:59 . 2009-08-19 22:54 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Local\QuickPlay
2009-08-20 11:59 . 2009-08-20 11:59 ——– d—–w- c:\programdata\CyberLink
2009-08-20 11:58 . 2008-04-24 06:52 82432 —-a-w- c:\windows\system32\msxml4r.dll
2009-08-20 11:58 . 2008-04-24 06:52 44544 —-a-w- c:\windows\system32\msxml4a.dll
2009-08-20 11:58 . 2008-04-24 06:52 1233920 —-a-w- c:\windows\system32\msxml4.dll
2009-08-20 11:58 . 2008-04-24 06:52 499712 ——w- c:\windows\system32\msvcp71.dll
2009-08-20 11:52 . 2009-08-20 11:52 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\Macrovision
2009-08-20 11:49 . 2009-08-20 11:49 ——– d—–w- c:\programdata\NVIDIA
2009-08-20 11:45 . 2008-05-23 03:29 768544 —-a-w- c:\windows\system32\nvcplui.exe
2009-08-20 11:45 . 2008-05-23 03:29 313888 —-a-w- c:\windows\system32\nvexpbar.dll
2009-08-20 11:45 . 2008-05-23 03:29 1079840 —-a-w- c:\windows\system32\nvcpluir.dll
2009-08-20 11:45 . 2008-05-21 21:49 446464 —-a-w- c:\windows\system32\NVUNINST.EXE
2009-08-20 11:45 . 2009-08-20 11:54 ——– d—–w- c:\windows\Driver Cache
2009-08-20 11:45 . 2009-08-20 11:45 ——– d—–w- c:\program files\AVerMedia
2009-08-20 11:45 . 2008-04-22 12:16 934912 —-a-w- c:\windows\system32\drivers\AVerBDA716x.sys
2009-08-20 11:45 . 2008-03-04 06:53 3072 —-a-w- c:\windows\system32\716xCoInstaller.dll
2009-08-20 11:44 . 2009-08-20 11:44 ——– d—–w- c:\program files\Synaptics
2009-08-20 11:44 . 2009-08-20 11:44 ——– d—–w- c:\windows\system32\ENU
2009-08-20 11:44 . 2009-08-20 11:44 ——– d—–w- c:\windows\system32\Lang
2009-08-20 11:44 . 2008-04-18 20:29 1034776 —-a-w- c:\windows\system32\imsmudlg.exe
2009-08-20 11:44 . 2006-11-10 16:25 319456 —-a-w- c:\windows\system32\difxapi.dll
2009-08-20 11:44 . 2008-04-16 00:53 312344 —-a-w- c:\windows\system32\drivers\iaStor.sys
2009-08-20 11:43 . 2009-08-20 12:04 ——– d—–w- c:\program files\Hewlett-Packard
2009-08-20 11:43 . 2009-08-20 11:43 ——– d—–w- c:\windows\system32\HPMDP
2009-08-20 11:43 . 2009-08-20 11:43 ——– d—–w- c:\program files\Realtek
2009-08-20 11:43 . 2008-04-15 10:05 118784 —-a-w- c:\windows\system32\drivers\Rtlh86.sys
2009-08-20 11:43 . 2009-08-20 11:43 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\InstallShield
2009-08-20 11:43 . 2008-02-29 23:07 54824 ——w- c:\windows\system32\agrsmdel.exe
2009-08-20 11:42 . 2009-08-20 12:17 ——– d—–w- C:\SWSetup
2009-08-20 11:42 . 2009-08-20 11:42 ——– d—–w- c:\windows\Options
2009-08-20 11:42 . 2009-08-20 11:42 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\Hewlett Packard
2009-08-20 11:42 . 2009-08-20 11:42 ——– d—–w- c:\program files\Validity Sensors, Inc
2009-08-20 11:42 . 2009-08-20 20:14 ——– d-sh–w- c:\windows\Installer
2009-08-20 11:41 . 2009-08-20 11:41 251 —-a-w- c:\windows\xUninstall.bat
2009-08-20 11:41 . 2009-08-20 11:41 ——– d—–w- c:\windows\JMCR_DIR
2009-08-20 11:40 . 2009-08-20 11:44 ——– d—–w- c:\program files\Intel
2009-08-20 11:40 . 2008-03-26 11:15 53248 —-a-w- c:\windows\system32\CSVer.dll
2009-08-20 09:45 . 2009-08-20 09:45 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Local\Yahoo
2009-08-20 01:00 . 2009-08-20 01:00 ——– d—–w- c:\program files\Adobe Media Player
2009-08-20 00:59 . 2009-08-20 00:59 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-08-20 00:59 . 2009-08-20 16:58 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Local\Adobe
2009-08-20 00:57 . 2009-08-20 00:57 ——– d—–w- c:\program files\Common Files\Macrovision Shared
2009-08-20 00:56 . 2009-08-20 01:00 ——– d—–w- c:\program files\Common Files\Adobe
2009-08-20 00:06 . 2009-08-20 09:43 ——– d—–w- c:\programdata\Yahoo!
2009-08-20 00:06 . 2009-05-27 02:50 607472 —-a-w- c:\programdata\Yahoo!\YUpdater\yupdater.exe
2009-08-20 00:06 . 2009-08-20 00:06 ——– d—–w- c:\program files\Yahoo!
2009-08-19 23:57 . 2006-10-27 02:56 32592 —-a-w- c:\windows\system32\msonpmon.dll
2009-08-19 23:56 . 2009-08-19 23:56 ——– d—–w- c:\program files\Microsoft Works
2009-08-19 23:55 . 2009-08-19 23:55 ——– d—–w- c:\windows\PCHEALTH
2009-08-19 23:55 . 2009-08-19 23:55 ——– d—–w- c:\program files\Microsoft.NET
2009-08-19 23:50 . 2009-08-19 23:51 ——– d—–w- c:\program files\Microsoft Visual Studio 8
2009-08-19 23:50 . 2009-08-19 23:50 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Local\Microsoft Help
2009-08-19 23:50 . 2009-08-19 23:57 ——– d—–w- c:\programdata\Microsoft Help
2009-08-19 23:41 . 2009-08-19 23:41 198064 —-a-w- c:\users\o0 Virgo 0o\AppData\Roaming\IDM\idmmzcc3\components\idmmzcc.dll
2009-08-19 23:41 . 2009-08-26 11:16 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\DMCache
2009-08-19 23:41 . 2009-08-20 10:03 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\IDM
2009-08-19 23:38 . 2009-08-19 23:38 ——– d—–w- c:\program files\Common Files\PX Storage Engine
2009-08-19 23:38 . 2009-08-19 23:38 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Local\Google
2009-08-19 23:38 . 2009-08-19 23:38 ——– d—–w- c:\windows\system32\IOSUBSYS
2009-08-19 23:38 . 2009-08-19 23:38 ——– d—–w- c:\program files\Google
2009-08-19 23:26 . 2009-08-19 23:36 ——– d—–w- c:\windows\Lhsp
2009-08-19 23:26 . 2009-08-19 23:26 ——– d—–w- c:\programdata\InstallShield
2009-08-19 23:26 . 2006-05-12 20:11 58368 —-a-w- c:\windows\system32\TCaptureX.dll
2009-08-19 23:26 . 2006-05-12 20:11 27648 —-a-w- c:\windows\system32\RL.dll
2009-08-19 23:26 . 2006-05-12 20:11 98304 —-a-w- c:\windows\system32\TCapture.dll
2009-08-19 23:26 . 2006-05-12 20:11 7168 —-a-w- c:\windows\system32\TCCustom.dll
2009-08-19 23:26 . 1998-06-17 07:00 385100 —-a-w- c:\windows\system32\Msvcrtd.dll
2009-08-19 23:20 . 2009-08-19 23:20 7168 —-a-r- c:\users\o0 Virgo 0o\AppData\Roaming\Microsoft\Installer\{4A536737-E71D-452F-984F-F8C0B0298226}\Icon4A536737.exe
2009-08-19 23:15 . 2009-08-26 11:12 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\MTD
2009-08-19 23:11 . 2009-08-19 23:12 1078 —-a-r- c:\users\o0 Virgo 0o\AppData\Roaming\Microsoft\Installer\{09BA3667-5D11-4488-8896-15A8F793081E}\_7FBACBD5C7DB60B99958DE.exe
2009-08-19 23:11 . 2009-08-19 23:12 1078 —-a-r- c:\users\o0 Virgo 0o\AppData\Roaming\Microsoft\Installer\{09BA3667-5D11-4488-8896-15A8F793081E}\_7C32ABCB52D91D23912A1B.exe
2009-08-19 23:11 . 2009-08-19 23:12 1078 —-a-r- c:\users\o0 Virgo 0o\AppData\Roaming\Microsoft\Installer\{09BA3667-5D11-4488-8896-15A8F793081E}\_2B2929C08304EDEC6FCC6C.exe
2009-08-19 23:11 . 2009-08-19 23:12 ——– d—–w- c:\program files\Common Files\L&H;
2009-08-19 23:04 . 2009-08-19 23:04 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\Foxit
2009-08-19 23:02 . 2009-08-19 23:02 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Local\Hewlett-Packard
2009-08-19 22:57 . 2009-08-19 22:57 ——– d—–w- c:\program files\Common Files\EZB Systems
2009-08-19 22:45 . 2009-03-08 11:33 18944 —-a-w- c:\windows\system32\corpol.dll
2009-08-19 22:39 . 2009-08-19 22:39 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Local\Mozilla
2009-08-19 22:39 . 2009-08-19 22:39 0 —-a-w- c:\windows\nsreg.dat
2009-08-19 22:37 . 2009-08-19 22:37 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\URSoft
2009-08-16 03:55 . 2009-08-16 03:55 ——– d—–w- c:\windows\system32\ca-ES
2009-08-16 03:55 . 2009-08-16 03:55 ——– d—–w- c:\windows\system32\vi-VN
2009-08-16 03:55 . 2009-08-16 03:55 ——– d—–w- c:\windows\system32\eu-ES
2009-08-16 03:52 . 2009-08-16 03:52 ——– d—–w- c:\windows\system32\SPReview
2009-08-16 03:47 . 2009-04-11 06:28 928768 —-a-w- c:\windows\system32\scavenge.dll
2009-08-16 03:46 . 2009-04-11 06:27 57856 —-a-w- c:\windows\system32\compcln.exe
2009-08-16 03:43 . 2009-04-11 06:28 342528 —-a-w- c:\windows\system32\zipfldr.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-26 23:36 . 2009-08-20 11:49 28409 —-a-w- c:\programdata\nvModes.dat
2009-08-23 18:02 . 2009-08-23 18:02 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-08-20 17:09 . 2009-08-20 11:39 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-20 11:58 . 2009-08-20 11:53 ——– d—–w- c:\program files\HP
2009-08-20 11:57 . 2009-08-20 11:57 ——– d—–w- c:\program files\Common Files\muvee Technologies
2009-08-20 11:56 . 2009-08-20 11:56 ——– d—–w- c:\programdata\muvee Technologies
2009-08-20 11:53 . 2009-08-20 11:53 ——– d—–w- c:\users\o0 Virgo 0o\AppData\Roaming\GTek
2009-08-20 11:51 . 2009-08-20 11:51 ——– d—–w- c:\programdata\Macrovision
2009-08-20 11:44 . 2009-08-20 11:44 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_SynTP_01000.Wdf
2009-08-20 11:39 . 2009-08-20 11:39 ——– d—–w- c:\program files\IDT
2009-08-20 11:27 . 2009-08-16 02:41 680 —-a-w- c:\users\o0 Virgo 0o\AppData\Local\d3d9caps.dat
2009-08-19 23:56 . 2006-11-02 12:35 ——– d—–w- c:\program files\MSBuild
2009-08-19 23:25 . 2009-08-20 11:39 ——– d—–w- c:\program files\Common Files\InstallShield
2009-08-16 03:55 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Calendar
2009-08-16 03:55 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Sidebar
2009-08-16 03:55 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Journal
2009-08-16 03:55 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Collaboration
2009-08-16 03:55 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-08-16 03:55 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Photo Gallery
2009-08-16 03:55 . 2006-11-02 12:35 ——– d—–w- c:\program files\Windows Defender
2009-08-16 03:54 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-08-16 03:18 . 2006-11-02 10:32 101888 —-a-w- c:\windows\system32\ifxcardm.dll
2009-08-16 03:18 . 2006-11-02 10:32 82432 —-a-w- c:\windows\system32\axaltocm.dll
2009-07-21 21:52 . 2009-08-19 22:47 915456 —-a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-08-19 22:47 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-08-19 22:47 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-08-19 22:47 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-06-02 16:11 . 2009-08-19 23:09 85504 —-a-w- c:\windows\system32\ff_vfw.dll
2009-05-29 21:37 . 2009-08-19 23:09 205824 —-a-w- c:\windows\system32\xvidvfw.dll
2009-05-29 21:31 . 2009-08-19 23:09 881664 —-a-w- c:\windows\system32\xvidcore.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\program files\Common Files\L&H; —-

2001-06-22 16:55 . 2001-06-22 16:55 139264 —-a-w- c:\program files\Common Files\L&H;\SpeechEngines\1036\TTS\TTS3000\frftstpp.dll
2001-06-22 16:55 . 2001-06-22 16:55 544768 —-a-w- c:\program files\Common Files\L&H;\SpeechEngines\1036\TTS\TTS3000\frftg2p.dll
2001-06-22 16:55 . 2001-06-22 16:55 479232 —-a-w- c:\program files\Common Files\L&H;\SpeechEngines\1036\TTS\TTS3000\frftempp.dll
2001-06-22 16:54 . 2001-06-22 16:54 94208 —-a-w- c:\program files\Common Files\L&H;\SpeechEngines\FRFT3S51.dll
2001-06-22 16:54 . 2001-06-22 16:54 458752 —-a-w- c:\program files\Common Files\L&H;\SpeechEngines\1036\TTS\TTS3000\frft11m1.dll
2001-06-22 16:53 . 2001-06-22 16:53 450560 —-a-w- c:\program files\Common Files\L&H;\SpeechEngines\1036\TTS\TTS3000\frft11f1.dll
2001-06-08 00:43 . 2001-06-08 00:43 126976 —-a-w- c:\program files\Common Files\L&H;\SpeechEngines\lhcom01A.dll
2001-06-07 03:24 . 2001-06-07 03:24 842 —-a-w- c:\program files\Common Files\L&H;\SpeechEngines\1036\TTS\TTS3000\frft11m1.hdr
2001-06-07 03:24 . 2001-06-07 03:24 860 —-a-w- c:\program files\Common Files\L&H;\SpeechEngines\1036\TTS\TTS3000\frft11f1.hdr
2001-06-06 17:54 . 2001-06-06 17:54 110 —-a-w- c:\program files\Common Files\L&H;\MSSWPT10.lhk
2001-04-13 17:34 . 2001-04-13 17:34 94208 —-a-w- c:\program files\Common Files\L&H;\SpeechEngines\tscore10.dll
2000-12-18 18:15 . 2000-12-18 18:15 23 —-a-w- c:\program files\Common Files\L&H;\SpeechEngines\1036\TTS\TTS3000\Veronique.dat
2000-12-18 18:14 . 2000-12-18 18:14 20 —-a-w- c:\program files\Common Files\L&H;\SpeechEngines\1036\TTS\TTS3000\Pierre.dat
2000-11-16 18:43 . 2000-11-16 18:43 962 —-a-w- c:\program files\Common Files\L&H;\SpeechEngines\1036\TTS\TTS3000\frftempp.hdr
2000-11-03 01:25 . 2000-11-03 01:25 960 —-a-w- c:\program files\Common Files\L&H;\SpeechEngines\1036\TTS\TTS3000\frftstpp.hdr
2000-11-03 01:25 . 2000-11-03 01:25 928 —-a-w- c:\program files\Common Files\L&H;\SpeechEngines\1036\TTS\TTS3000\frftg2p.hdr
2000-08-07 18:48 . 2000-08-07 18:48 500 —-a-w- c:\program files\Common Files\L&H;\SpeechEngines\Tts3000.hdr

—- Directory of c:\users\o0 Virgo 0o\AppData\Roaming\MTD —-

2009-08-26 02:16 . 2009-08-26 11:12 81920 —-a-w- c:\users\o0 Virgo 0o\AppData\Roaming\MTD\__LV.002
2009-08-26 02:16 . 2009-08-26 11:12 8192 —-a-w- c:\users\o0 Virgo 0o\AppData\Roaming\MTD\__LV.001


((((((((((((((((((((((((((((( SnapShot@2009-08-26_12.12.28 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-16 02:43 . 2009-08-26 23:26 32510 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-08-16 02:43 . 2009-08-26 10:56 32510 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:03 . 2009-08-26 23:26 57308 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-08-16 02:43 . 2009-08-26 23:26 7734 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3838910615-2319463833-1608888379-1000_UserData.bin
- 2009-08-26 12:05 . 2009-08-26 12:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-08-26 23:35 . 2009-08-26 23:35 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-08-26 23:35 . 2009-08-26 23:35 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-08-26 12:05 . 2009-08-26 12:05 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2009-08-26 23:29 595684 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-08-26 12:11 595684 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-08-26 23:29 101350 c:\windows\System32\perfc009.dat
- 2006-11-02 10:33 . 2009-08-26 12:11 101350 c:\windows\System32\perfc009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"UniKey"="d:\install\UniKey 4.0.8" [BU]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-04-15 442433]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1033512]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-23 13539872]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-23 92704]
"DpAgent"="c:\swsetup\DigitalPersona\Bin\dpagent.exe" [2008-03-13 699456]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-01 202032]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-04-24 468264]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-11-02 554288]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-11-20 488752]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"Copperhead"="d:\install\Razer\Copperhead\razerhid.exe" [2005-11-25 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer4"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli DPPWDFLT

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):73,9b,c5,f6,25,1e,ca,01

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{F37CE7F3-0A15-4100-A8B9-43309CDEF30B}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{04D0E3CB-B3B4-4E31-A2E8-062453044F53}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{6858130A-3A16-4DC4-A279-C0D2D979DF47}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{A81D3BAF-2DAE-4452-8DDC-4E8AABB9FC60}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{85F15BBD-3966-4A53-BC85-4E3B6946F6DA}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{3128B626-9E7D-4C11-A7C0-F5D2F4A98ED8}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{B0FED4C7-9793-41C3-81C5-2D7D9B18BF77}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{4748A060-01ED-42A0-8ED0-85841D311823}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{56455DD1-3D14-4774-8DE9-AD907E8C46F8}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{103AEEA9-9B8F-4169-929B-7C4819AA08CD}"= UDP:5353:Adobe CSI CS4
"{BC59EA95-FB1E-427E-9C97-B23EF8008F3D}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{64360198-D8D4-4438-8D6F-6BBACFE42F7B}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R0 PCTCore;PCTools KDS;c:\windows\System32\drivers\PCTCore.sys [8/21/2009 12:29 AM 130936]
R1 ehdrv;ehdrv;c:\windows\System32\drivers\ehdrv.sys [2/6/2009 2:23 PM 106208]
R2 {22D78859-9CE9-4B77-BF18-AC83E81A9263};{22D78859-9CE9-4B77-BF18-AC83E81A9263};c:\program files\HP\QuickPlay\000.fcl [8/20/2009 6:58 PM 39408]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\AEstSrv.exe [8/20/2009 6:39 PM 73728]
R2 ekrn;ESET Service;d:\install\ESET Smart Security 4\ekrn.exe [2/6/2009 2:23 PM 727720]
R2 epfwwfp;epfwwfp;c:\windows\System32\drivers\epfwwfp.sys [2/6/2009 2:24 PM 38240]
R2 hpsrv;HP Service;c:\windows\System32\hpservice.exe [3/19/2008 6:24 AM 19456]
R2 MBAMService;MBAMService;d:\install\Malwarebytes' Anti-Malware\mbamservice.exe [8/21/2009 12:52 AM 232720]
R2 vfsFPService;Validity Fingerprint Service;c:\windows\System32\vfsFPService.exe [3/27/2008 8:27 AM 595248]
R3 AVerBDA6x;AVerBDA6x service;c:\windows\System32\drivers\AVerBDA716x.sys [8/20/2009 6:45 PM 934912]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [8/20/2009 6:57 PM 193840]
R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [10/28/2008 1:39 PM 52736]
R3 JMCR;JMCR;c:\windows\System32\drivers\jmcr.sys [10/28/2008 1:39 PM 81296]
R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [8/21/2009 12:52 AM 19096]
R3 NETw5v32;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\System32\drivers\NETw5v32.sys [10/28/2008 1:39 PM 3658752]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [10/28/2008 1:39 PM 43552]
R3 vfs101x;vfs101x;c:\windows\System32\drivers\vfs101x.sys [3/27/2008 8:28 AM 40752]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\System32\regedt32.exe [11/2/2006 3:32 PM 9216]
S3 sdAuxService;PC Tools Auxiliary Service;d:\install\Spyware Doctor\pctsAuxs.exe [8/21/2009 12:28 AM 348752]
S3 UsbFltr;Razer Copperhead Driver;c:\windows\System32\drivers\copperhd.sys [8/21/2009 12:09 AM 11596]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com.vn/
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: Download all links with IDM - d:\install\Internet Download Manager 5.17\IEGetAll.htm
IE: Download FLV video content with IDM - d:\install\Internet Download Manager 5.17\IEGetVL.htm
IE: Download with IDM - d:\install\Internet Download Manager 5.17\IEExt.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth; Device… - c:\swsetup\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth; Device… - c:\swsetup\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: {A0D5BE24-2A69-4825-B6B4-232AB7C22CE6} = 203.113.131.1,203.113.131.2
FF - ProfilePath - c:\users\o0 Virgo 0o\AppData\Roaming\Mozilla\Firefox\Profiles\hbza7uts.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.vn/
FF - component: c:\users\o0 Virgo 0o\AppData\Roaming\IDM\idmmzcc3\components\idmmzcc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: d:\install\K-Lite Mega Codec Pack 5.05\Real\browser\plugins\nppl3260.dll
FF - plugin: d:\install\K-Lite Mega Codec Pack 5.05\Real\browser\plugins\nprpjplug.dll
FF - plugin: d:\install\Picasa3\npPicasa3.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-27 06:37
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{22D78859-9CE9-4B77-BF18-AC83E81A9263}]
"ImagePath"="\??\c:\program files\HP\QuickPlay\000.fcl"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(700)
c:\windows\system32\DPPWDFLT.dll

- - - - - - - > 'Explorer.exe'(3120)
c:\swsetup\DigitalPersona\Bin\DpoFeedb.dll
d:\install\UniKey 4.0.8 Final\UKHook40.dll
c:\windows\system32\btncopy.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\stacsv.exe
c:\windows\System32\audiodg.exe
c:\swsetup\DigitalPersona\Bin\DpHostW.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\agrsmsvc.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
c:\program files\HP\QuickPlay\Kernel\TV\QPSched.exe
c:\windows\System32\rundll32.exe
d:\install\UniKey 4.0.8 Final\UniKey.exe
d:\install\Razer\Copperhead\razerofa.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
c:\windows\System32\wbem\WMIADAP.exe
.
**************************************************************************
.
Completion time: 2009-08-26 6:42 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-26 23:42

Pre-Run: 64,590,839,808 bytes free
Post-Run: 64,558,690,304 bytes free

457
WOW, I rescan operating memory by Eset4 Smart security and Have no infected. ( last scan have one, is win32 rootkit agent odg ) I expect to see the result from your log analysis. If you notify my Lap clean, I will leap for joy and dance :D . HUG :pullhair:
Hi,

The file I had requested be uploaded did not get submitted, so we need to do it manually.

Please do the following:

Please open this link HERE in a new window.

In the box marked Link to topic where this file was requested: please paste in the following text
http://forums.whatthetech.com/Plzz_help_me_Root_kit_agent_ODG_AGAIN_t106299.html&view=findpost&p=590680#entry590680

Click the Browse button and navigate to C:\Qoobox\Quarantine

There should be a zip file there called [4]-Submit_****-**-**_**.**.**.zip ( the * denotes the Date and Time Combofix was run - it will be close to this 08/27/2009 6:29 )
Select this file and click Open
In the Largest box please put
File Requested By CatByte
Failed Submit::

Finally click SendFile

Please return here and let me know when that file has been uploaded.

(note - the failed deletions are OK - they weren't meant to delete - don't try and read too much into these logs - they are not easy to interpret)



NEXT



  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.




NEXT

Run an on-line scan with Kaspersky

**Vista users - right click on the IE icon and run as administrator

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI