This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] HELP ME PLEASE! INFECTED WITH ROOTKIT TROJAN

28 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there, I'm new to the forum. I did some searching and out of a lot of forums the people here really seem to know what they're talking about. Here is my problem. A few days ago my PC got infected. Big time.I'm not a n00b at computers so I tried my best to solve the issue. Some spyware I found were b.exe and msa.exe which after many scans, etc. I found a quick way to delete them from CMD.exe. Unfortunately things look grim as the virus is locking all my AntiVirus software. Basically it lets me run the program once, kills it quickly as the scan starts, locks the file and I cannot access it again. Uninstalling and re-installing has yielded the same results. This was all tried in Safe Mode with or without Networking. So far it has also killed off HiJackThis, Combofix,Firefox (when i tried to do an online scan–cannot run Firefox anymore), AVG FREE Edition, Spybot Search and Destroy,Malwarebytes Anti-Malware. It kills them all and locks the file. I can only access the net via IE and its constantly redirecting me to random sites. The only scan that worked was Kaspersky online scanner and hopefully somebody can help me from the following information: AMD Athlon 64 3700+ 2.22 Ghz 1GB RAM XP PRO SP2 (build 2600) 2002 Edition Kaspersky Online Scanner results: Infections found: C:\Documents and Settings\Administrator\.housecall6.6\Quarantine\t0XIpPJl.exe.bac_a00920 Infected: Trojan-Downloader.Win32.Agent.axdj C:\Documents and Settings\ZEUS85\housecall6.6\Quarantine\32does.exe.bac_a03160 Infected: not-a-virus: Adware.Win32.Lop.bw C:\Documents and Settings\ZEUS85\housecall6.6\Quarantine\qusdcioh.bac_a03160 Infected: not-a-virus: Adware.Win32.Lop.bw C:\Program Files\Accessdiver\ad4.120.exe Infected: not-a-virus: NetTool.Win32.Accessdiver.4103 C:\SDFix\backups\backups.zip Infected: Trojan.Win32.Agent.cctw C:\WINDOWS\system32\drivers\UACrubuplrgjw.sys Infected: Rootkit.Win32.Agent.oxr C:\WINDOWS\system32\UACaapocnqrov.dll Infected: Trojan.Win32.Tdss.anrc Hope anybody has any advice whatsoever. This is the worst computer virus I've ever dealt with in my life. Thank you in advance. :(
[external image: Posted Image]

Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to help you with your malware issues. I'd be grateful if you would note the following:

  • Absence of symptoms does not always mean the computer is clean
  • Please do not run any scans or fixes without my direction.
  • Finally, stay with this topic until I give you the final 'All clear' post.

I realise that not all of these tools may run - try all of them and post as many of the logs as you can.

1) win32kdiag
Please download ad13's win32ksys to your desktop
  • Double click to run it
  • A black window will appear, let this run
  • On completion a log will appear on your desktop called Win32kDiag.txt please post this in your next reply.

2) RR
Please download RootRepeal.zip.
Save it to your Desktop. Alternate download links here or here.
Please print these instructions, you will not have an Internet connection!
If you have a 3rd party "unzipping" program…use it to open the zipped file…then skip to Step 5. Otherwise…
  • Right click on RootRepeal.zip and select "Extract All"….
  • Click Next on the "Welcome to the Compressed (zipped) Folders Extraction Wizard."
  • Click on the Browse…button, then click on Desktop, then click OK.
  • Once done, check (tick) the Show extracted files box and click Finish.
  • Before running RootRepeal:
    • Disconnect from the Internet as your system will be unprotected while using this tool.
      Close all programs and temporarily disable your anti-virus, Firewall and any anti-malware real-time protection before performing a scan.
  • Open the RootRepeal folder and double-click on RootRepeal.exe to launch it.
  • When the program opens, click the Report tab at the bottom, then click the Scan button.
  • In the Select Scan, dialog which asks What do you want to include in the scan?, check ALL the boxes.
    🖼Click to load external image (Posted Image)
  • Click OK.
  • In the Select Drives, dialog Please select drives to scan: select all drives showing, then click OK.
    The scan can take some time to finish. Do not use the computer while the scan is running.
    When the scan has completed, a list of files will be generated in the RootRepeal window.
  • Click on the Save Report button and save it as "rootrepeal.txt" to your desktop.
  • Close and exit RootRepeal
  • Double-click on the file rootrepeal.txt… Notepad will open… copy/paste the file contents in your next reply.

Make sure to enable your anti-virus, Firewall and any other security programs you disabled.
Note: If RootRepeal cannot complete a scan and results in a crash report, try repeating the scan in "safe mode".

3) SysProt
Please download Sysprot Antirootkit from here

http://sites.google.com/site/sysprotantirootkit/

Unzip it into a folder on your desktop.

  • Double click Sysprot.exe to start the program.
  • Click on the Log tab.
  • In the Write to log box select all items.
  • Click on the Create Log button on the bottom right.
  • After a few seconds a new window should appear.
  • Select Scan Root Drive. Click on the Start button.
  • When it is complete a new window will appear to indicate that the scan is finished.
  • The log will be saved automatically in the same folder Sysprot.exe was extracted to.
  • Open the text file and copy/paste the log here.

4) What You Will Need To Post:
  • wink32diag log
  • RR log
  • SysProt log
Hi Raktor. Glad to see you took the time out to reply and offer your help. Before I read your message I tried to run an Anti Virus boot disk - BitDefender. It ran a Linux based antiscanner right on start up. I left it to scan my pc overnight. This is what it found: GenTrojan.Heur@30@r5xGcRbjy Rootkit.TDss.AA Trojan.FatObfus.Gen Trojan.Generic.1239323 Trojan.Generic.1273483 Trojan.Generic.1711897 Trojan.TDss.WB Trojan.TDss.WU Win32.Bagle.SWO I clicked the option to Delete them. It said it successfully deleted them. So i restarted my pc and tried running Windows. Again it would not let me run Firefox (locked file) or AVG or any anti-virus software. I then went back here to see if anybody replied. I took your advice, unfortunately as I said before the virus is not letting me do much. The Root Repeal froze almost instantly as I tried running it. (Mouse froze too, whole system froze). I tried in Safe Mode as well, same results. SysProt would not work either. When i ran it it gave me the message "SysProt AntiRootkit needs to be run with Admin priviliges." It then let me run the scan which of course finished in a second and said Processes: NONE, NONE for everything. etc. Win32kdiag was the only one that worked successfully. Hopefully its log can provide you with some insight on what I should do next. Thank you again for your help and I hope there is some small hope I will be able to somehow get this thing fix. Here is the log: Log file is located at: C:\Documents and Settings\Administrator\Desktop\Win32kDiag.txt WARNING: Could not get backup privileges! Searching 'C:\WINDOWS'… Found mount point : C:\WINDOWS\$hf_mig$\KB960859\KB960859 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\$hf_mig$\KB968389\KB968389 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\$hf_mig$\KB971032\KB971032 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\$hf_mig$\KB971557\KB971557 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\$hf_mig$\KB971657\KB971657 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\$hf_mig$\KB972260\KB972260 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\$hf_mig$\KB973507\KB973507 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\$hf_mig$\KB973815\KB973815 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\addins\addins Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\Config\Config Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\Connection Wizard\Connection Wizard Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\CSC\d1\d1 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\CSC\d2\d2 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\CSC\d3\d3 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\CSC\d4\d4 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\CSC\d5\d5 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\CSC\d6\d6 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\CSC\d7\d7 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\CSC\d8\d8 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\ftpcache\ftpcache Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\ime\chsime\applets\applets Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\ime\CHTIME\Applets\Applets Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\ime\imejp\applets\applets Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\ime\imejp98\imejp98 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\ime\imjp8_1\applets\applets Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\ime\imkr6_1\applets\applets Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\ime\imkr6_1\dicts\dicts Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\ime\shared\res\res Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\D7314F9862C648A4DB8BE2A5B47BE100\1.0.0\1.0.0 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\java\classes\classes Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\java\trustlib\trustlib Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\Minidump\Minidump Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\msapps\msinfo\msinfo Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\pchealth\ERRORREP\QHEADLES\QHEADLES Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\pchealth\ERRORREP\QSIGNOFF\QSIGNOFF Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\pchealth\helpctr\BATCH\BATCH Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\pchealth\helpctr\Config\CheckPoint\CheckPoint Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\pchealth\helpctr\Config\News\News Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\pchealth\helpctr\HelpFiles\HelpFiles Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\pchealth\helpctr\InstalledSKUs\InstalledSKUs Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\pchealth\helpctr\System\DFS\DFS Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\pchealth\helpctr\System_OEM\System_OEM Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\pchealth\helpctr\Temp\Temp Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\PIF\PIF Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\Registration\CRMLog\CRMLog Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\SoftwareDistribution\AuthCabs\Downloaded\Downloaded Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\SoftwareDistribution\Download\07a96de176867bc25b7dc839d22b07e2\backup\backup Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\SoftwareDistribution\Download\555558d2c7916b118ad5baef62b18136\backup\backup Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\SoftwareDistribution\Download\6913c676e5d33978934caa46c49fdc75\backup\backup Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\SoftwareDistribution\Download\d48a3b967ba5709df048e8f2a49cf8a6\backup\backup Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\10\10 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\52\msft\msft Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\60\msft\msft Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\70\70 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dfd20fda6478d599fc1417f0319287a1\backup\backup Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\Sun\Java\Deployment\Deployment Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\1025\1025 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\1028\1028 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\1031\1031 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\1037\1037 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\1041\1041 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\1042\1042 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\1054\1054 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\2052\2052 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\3076\3076 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\3com_dmi\3com_dmi Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\appmgmt\MACHINE\MACHINE Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\appmgmt\S-1-5-21-3421744925-564012677-1258165160-1004\S-1-5-21-3421744925-564012677-1258165160-1004 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\appmgmt\S-1-5-21-3421744925-564012677-1258165160-500\S-1-5-21-3421744925-564012677-1258165160-500 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\CatRoot_bak\CatRoot_bak Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Identities\{7D5B7165-EA32-475C-AFDB-BF352EEE69B6}\{7D5B7165-EA32-475C-AFDB-BF352EEE69B6} Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Credentials\Credentials Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Crypto\RSA\RSA Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Media Player\Media Player Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\MMC\MMC Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\Certificates\Certificates Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\CRLs\CRLs Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\CTLs\CTLs Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\config\systemprofile\Desktop\Desktop Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\CD Burning\CD Burning Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Credentials\Credentials Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\temp\temp Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\34NIDK6D\34NIDK6D Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\JW9MEO4H\JW9MEO4H Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\RYBC4ZFS\RYBC4ZFS Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\ZFY2XYQR\ZFY2XYQR Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\config\systemprofile\NetHood\NetHood Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\config\systemprofile\PrintHood\PrintHood Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\dhcp\dhcp Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\drivers\disdn\disdn Mount point destination : \Device\__max++>\^ Cannot access: C:\WINDOWS\system32\eventlog.dll [1] 2008-04-13 17:11:53 56320 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\eventlog.dll (Microsoft Corporation) [1] 2004-08-04 05:00:00 55808 C:\WINDOWS\system32\dllcache\eventlog.dll (Microsoft Corporation) [1] 2004-08-04 05:00:00 62464 C:\WINDOWS\system32\eventlog.dll () [2] 2004-08-04 05:00:00 55808 C:\WINDOWS\system32\logevent.dll (Microsoft Corporation) Found mount point : C:\WINDOWS\system32\export\export Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\GroupPolicy\Machine\Machine Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\GroupPolicy\User\User Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\IME\CINTLGNT\CINTLGNT Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\IME\PINTLGNT\PINTLGNT Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\IME\TINTLGNT\TINTLGNT Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\inetsrv\inetsrv Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\mui\dispspec\dispspec Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\oobe\html\ispsgnup\ispsgnup Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\oobe\html\oemcust\oemcust Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\oobe\html\oemhw\oemhw Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\oobe\html\oemreg\oemreg Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\oobe\sample\sample Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\ShellExt\ShellExt Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\spool\drivers\w32x86\3\3 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\spool\PRINTERS\PRINTERS Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\spool\prtprocs\w32x86\w32x86 Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\wbem\mof\bad\bad Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\wbem\mof\good\good Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\wbem\snmp\snmp Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\wins\wins Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\system32\xircom\xircom Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\temp\_avast4_\_avast4_ Mount point destination : \Device\__max++>\^ Found mount point : C:\WINDOWS\WinSxS\InstallTemp\InstallTemp Mount point destination : \Device\__max++>\^ Finished!
1) Win32kdiag
Let's rerun win32kdiag in a different way. Make sure win32kdiag.exe is still on your desktop.
  • Go to Start->Run, copy/paste the following command (it's one long command) into the box and press OK:

    "%userprofile%\desktop\Win32kDiag.exe" -f -r

  • A black box will open and a file will appear on your Desktop called Win32kDiag.txt.
  • Please wait until the black box closes before opening it, and post the contents of Win32kDiag.txt in your next response.

2) Combofix
Please read through the instructions to familiarize yourself with what to expect when the tool runs.

Please download Combofix from either of the links below, and save it to your desktop.
You must rename it before saving it. Save it as Combo-Fix.exe.

[external image: Posted Image]

Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link:How to Disable your Security Programs
  • Double click on Combo-Fix.exe & follow the prompts. Close all browsers/windows first.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

3) What You Will Need To Post:
  • Win32kDiag log
  • Combofix log
So far so good. I am suprised both programs seemed to work fine. I uninstalled and re-installed Firefox and that seems to be running as well, for now.

Here are the logs:

Win32kDiag:

Log file is located at: C:\Documents and Settings\ZEUS85\Desktop\Win32kDiag.txt

Removing all found mount points.

Attempting to reset file permissions.

WARNING: Could not get backup privileges!

Searching 'C:\WINDOWS'…



Found mount point : C:\WINDOWS\$hf_mig$\KB960859\KB960859

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\$hf_mig$\KB960859\KB960859

Found mount point : C:\WINDOWS\$hf_mig$\KB968389\KB968389

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\$hf_mig$\KB968389\KB968389

Found mount point : C:\WINDOWS\$hf_mig$\KB971032\KB971032

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\$hf_mig$\KB971032\KB971032

Found mount point : C:\WINDOWS\$hf_mig$\KB971557\KB971557

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\$hf_mig$\KB971557\KB971557

Found mount point : C:\WINDOWS\$hf_mig$\KB971657\KB971657

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\$hf_mig$\KB971657\KB971657

Found mount point : C:\WINDOWS\$hf_mig$\KB972260\KB972260

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\$hf_mig$\KB972260\KB972260

Found mount point : C:\WINDOWS\$hf_mig$\KB973507\KB973507

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\$hf_mig$\KB973507\KB973507

Found mount point : C:\WINDOWS\$hf_mig$\KB973815\KB973815

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\$hf_mig$\KB973815\KB973815

Found mount point : C:\WINDOWS\addins\addins

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\addins\addins

Found mount point : C:\WINDOWS\Config\Config

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Config\Config

Found mount point : C:\WINDOWS\Connection Wizard\Connection Wizard

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Connection Wizard\Connection Wizard

Found mount point : C:\WINDOWS\CSC\d1\d1

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\CSC\d1\d1

Found mount point : C:\WINDOWS\CSC\d2\d2

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\CSC\d2\d2

Found mount point : C:\WINDOWS\CSC\d3\d3

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\CSC\d3\d3

Found mount point : C:\WINDOWS\CSC\d4\d4

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\CSC\d4\d4

Found mount point : C:\WINDOWS\CSC\d5\d5

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\CSC\d5\d5

Found mount point : C:\WINDOWS\CSC\d6\d6

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\CSC\d6\d6

Found mount point : C:\WINDOWS\CSC\d7\d7

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\CSC\d7\d7

Found mount point : C:\WINDOWS\CSC\d8\d8

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\CSC\d8\d8

Found mount point : C:\WINDOWS\ftpcache\ftpcache

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ftpcache\ftpcache

Found mount point : C:\WINDOWS\ime\chsime\applets\applets

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ime\chsime\applets\applets

Found mount point : C:\WINDOWS\ime\CHTIME\Applets\Applets

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ime\CHTIME\Applets\Applets

Found mount point : C:\WINDOWS\ime\imejp\applets\applets

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ime\imejp\applets\applets

Found mount point : C:\WINDOWS\ime\imejp98\imejp98

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ime\imejp98\imejp98

Found mount point : C:\WINDOWS\ime\imjp8_1\applets\applets

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ime\imjp8_1\applets\applets

Found mount point : C:\WINDOWS\ime\imkr6_1\applets\applets

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ime\imkr6_1\applets\applets

Found mount point : C:\WINDOWS\ime\imkr6_1\dicts\dicts

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ime\imkr6_1\dicts\dicts

Found mount point : C:\WINDOWS\ime\shared\res\res

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\ime\shared\res\res

Found mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\D7314F9862C648A4DB8BE2A5B47BE100\1.0.0\1.0.0

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Installer\$PatchCache$\Managed\D7314F9862C648A4DB8BE2A5B47BE100\1.0.0\1.0.0

Found mount point : C:\WINDOWS\java\classes\classes

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\java\classes\classes

Found mount point : C:\WINDOWS\java\trustlib\trustlib

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\java\trustlib\trustlib

Found mount point : C:\WINDOWS\Minidump\Minidump

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Minidump\Minidump

Found mount point : C:\WINDOWS\msapps\msinfo\msinfo

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\msapps\msinfo\msinfo

Found mount point : C:\WINDOWS\pchealth\ERRORREP\QHEADLES\QHEADLES

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\pchealth\ERRORREP\QHEADLES\QHEADLES

Found mount point : C:\WINDOWS\pchealth\ERRORREP\QSIGNOFF\QSIGNOFF

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\pchealth\ERRORREP\QSIGNOFF\QSIGNOFF

Found mount point : C:\WINDOWS\pchealth\helpctr\BATCH\BATCH

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\pchealth\helpctr\BATCH\BATCH

Found mount point : C:\WINDOWS\pchealth\helpctr\Config\CheckPoint\CheckPoint

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\pchealth\helpctr\Config\CheckPoint\CheckPoint

Found mount point : C:\WINDOWS\pchealth\helpctr\Config\News\News

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\pchealth\helpctr\Config\News\News

Found mount point : C:\WINDOWS\pchealth\helpctr\HelpFiles\HelpFiles

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\pchealth\helpctr\HelpFiles\HelpFiles

Found mount point : C:\WINDOWS\pchealth\helpctr\InstalledSKUs\InstalledSKUs

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\pchealth\helpctr\InstalledSKUs\InstalledSKUs

Found mount point : C:\WINDOWS\pchealth\helpctr\System\DFS\DFS

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\pchealth\helpctr\System\DFS\DFS

Found mount point : C:\WINDOWS\pchealth\helpctr\System_OEM\System_OEM

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\pchealth\helpctr\System_OEM\System_OEM

Found mount point : C:\WINDOWS\pchealth\helpctr\Temp\Temp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\pchealth\helpctr\Temp\Temp

Found mount point : C:\WINDOWS\PIF\PIF

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\PIF\PIF

Found mount point : C:\WINDOWS\Registration\CRMLog\CRMLog

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Registration\CRMLog\CRMLog

Found mount point : C:\WINDOWS\SoftwareDistribution\AuthCabs\Downloaded\Downloaded

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\SoftwareDistribution\AuthCabs\Downloaded\Downloaded

Found mount point : C:\WINDOWS\SoftwareDistribution\Download\07a96de176867bc25b7dc839d22b07e2\backup\backup

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\SoftwareDistribution\Download\07a96de176867bc25b7dc839d22b07e2\backup\backup

Found mount point : C:\WINDOWS\SoftwareDistribution\Download\555558d2c7916b118ad5baef62b18136\backup\backup

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\SoftwareDistribution\Download\555558d2c7916b118ad5baef62b18136\backup\backup

Found mount point : C:\WINDOWS\SoftwareDistribution\Download\6913c676e5d33978934caa46c49fdc75\backup\backup

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\SoftwareDistribution\Download\6913c676e5d33978934caa46c49fdc75\backup\backup

Found mount point : C:\WINDOWS\SoftwareDistribution\Download\d48a3b967ba5709df048e8f2a49cf8a6\backup\backup

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\SoftwareDistribution\Download\d48a3b967ba5709df048e8f2a49cf8a6\backup\backup

Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\10\10

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\10\10

Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\52\msft\msft

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\52\msft\msft

Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\60\msft\msft

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\60\msft\msft

Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\70\70

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\backup\asms\70\70

Found mount point : C:\WINDOWS\SoftwareDistribution\Download\dfd20fda6478d599fc1417f0319287a1\backup\backup

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\SoftwareDistribution\Download\dfd20fda6478d599fc1417f0319287a1\backup\backup

Found mount point : C:\WINDOWS\Sun\Java\Deployment\Deployment

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\Sun\Java\Deployment\Deployment

Found mount point : C:\WINDOWS\system32\1025\1025

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\1025\1025

Found mount point : C:\WINDOWS\system32\1028\1028

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\1028\1028

Found mount point : C:\WINDOWS\system32\1031\1031

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\1031\1031

Found mount point : C:\WINDOWS\system32\1037\1037

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\1037\1037

Found mount point : C:\WINDOWS\system32\1041\1041

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\1041\1041

Found mount point : C:\WINDOWS\system32\1042\1042

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\1042\1042

Found mount point : C:\WINDOWS\system32\1054\1054

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\1054\1054

Found mount point : C:\WINDOWS\system32\2052\2052

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\2052\2052

Found mount point : C:\WINDOWS\system32\3076\3076

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\3076\3076

Found mount point : C:\WINDOWS\system32\3com_dmi\3com_dmi

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\3com_dmi\3com_dmi

Found mount point : C:\WINDOWS\system32\appmgmt\MACHINE\MACHINE

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\appmgmt\MACHINE\MACHINE

Found mount point : C:\WINDOWS\system32\appmgmt\S-1-5-21-3421744925-564012677-1258165160-1004\S-1-5-21-3421744925-564012677-1258165160-1004

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\appmgmt\S-1-5-21-3421744925-564012677-1258165160-1004\S-1-5-21-3421744925-564012677-1258165160-1004

Found mount point : C:\WINDOWS\system32\appmgmt\S-1-5-21-3421744925-564012677-1258165160-500\S-1-5-21-3421744925-564012677-1258165160-500

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\appmgmt\S-1-5-21-3421744925-564012677-1258165160-500\S-1-5-21-3421744925-564012677-1258165160-500

Found mount point : C:\WINDOWS\system32\CatRoot_bak\CatRoot_bak

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\CatRoot_bak\CatRoot_bak

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Identities\{7D5B7165-EA32-475C-AFDB-BF352EEE69B6}\{7D5B7165-EA32-475C-AFDB-BF352EEE69B6}

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Identities\{7D5B7165-EA32-475C-AFDB-BF352EEE69B6}\{7D5B7165-EA32-475C-AFDB-BF352EEE69B6}

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Credentials\Credentials

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Credentials\Credentials

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Crypto\RSA\RSA

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Crypto\RSA\RSA

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Media Player\Media Player

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Media Player\Media Player

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\MMC\MMC

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\MMC\MMC

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\Certificates\Certificates

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\Certificates\Certificates

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\CRLs\CRLs

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\CRLs\CRLs

Found mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\CTLs\CTLs

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\SystemCertificates\My\CTLs\CTLs

Found mount point : C:\WINDOWS\system32\config\systemprofile\Desktop\Desktop

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Desktop\Desktop

Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\CD Burning\CD Burning

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\CD Burning\CD Burning

Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Credentials\Credentials

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Credentials\Credentials

Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\temp\temp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\temp\temp

Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\34NIDK6D\34NIDK6D

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\34NIDK6D\34NIDK6D

Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\JW9MEO4H\JW9MEO4H

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\JW9MEO4H\JW9MEO4H

Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\RYBC4ZFS\RYBC4ZFS

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\RYBC4ZFS\RYBC4ZFS

Found mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\ZFY2XYQR\ZFY2XYQR

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\ZFY2XYQR\ZFY2XYQR

Found mount point : C:\WINDOWS\system32\config\systemprofile\NetHood\NetHood

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\NetHood\NetHood

Found mount point : C:\WINDOWS\system32\config\systemprofile\PrintHood\PrintHood

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\config\systemprofile\PrintHood\PrintHood

Found mount point : C:\WINDOWS\system32\dhcp\dhcp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\dhcp\dhcp

Found mount point : C:\WINDOWS\system32\drivers\disdn\disdn

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\drivers\disdn\disdn

Cannot access: C:\WINDOWS\system32\eventlog.dll

Attempting to restore permissions of : C:\WINDOWS\system32\eventlog.dll

[1] 2008-04-13 17:11:53 56320 C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\eventlog.dll (Microsoft Corporation)

[1] 2004-08-04 05:00:00 55808 C:\WINDOWS\system32\dllcache\eventlog.dll (Microsoft Corporation)

[1] 2004-08-04 05:00:00 62464 C:\WINDOWS\system32\eventlog.dll ()

[2] 2004-08-04 05:00:00 55808 C:\WINDOWS\system32\logevent.dll (Microsoft Corporation)



Found mount point : C:\WINDOWS\system32\export\export

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\export\export

Found mount point : C:\WINDOWS\system32\GroupPolicy\Machine\Machine

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\GroupPolicy\Machine\Machine

Found mount point : C:\WINDOWS\system32\GroupPolicy\User\User

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\GroupPolicy\User\User

Found mount point : C:\WINDOWS\system32\IME\CINTLGNT\CINTLGNT

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\IME\CINTLGNT\CINTLGNT

Found mount point : C:\WINDOWS\system32\IME\PINTLGNT\PINTLGNT

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\IME\PINTLGNT\PINTLGNT

Found mount point : C:\WINDOWS\system32\IME\TINTLGNT\TINTLGNT

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\IME\TINTLGNT\TINTLGNT

Found mount point : C:\WINDOWS\system32\inetsrv\inetsrv

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\inetsrv\inetsrv

Found mount point : C:\WINDOWS\system32\mui\dispspec\dispspec

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\mui\dispspec\dispspec

Found mount point : C:\WINDOWS\system32\oobe\html\ispsgnup\ispsgnup

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\oobe\html\ispsgnup\ispsgnup

Found mount point : C:\WINDOWS\system32\oobe\html\oemcust\oemcust

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\oobe\html\oemcust\oemcust

Found mount point : C:\WINDOWS\system32\oobe\html\oemhw\oemhw

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\oobe\html\oemhw\oemhw

Found mount point : C:\WINDOWS\system32\oobe\html\oemreg\oemreg

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\oobe\html\oemreg\oemreg

Found mount point : C:\WINDOWS\system32\oobe\sample\sample

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\oobe\sample\sample

Found mount point : C:\WINDOWS\system32\ShellExt\ShellExt

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\ShellExt\ShellExt

Found mount point : C:\WINDOWS\system32\spool\drivers\w32x86\3\3

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\spool\drivers\w32x86\3\3

Found mount point : C:\WINDOWS\system32\spool\PRINTERS\PRINTERS

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\spool\PRINTERS\PRINTERS

Found mount point : C:\WINDOWS\system32\spool\prtprocs\w32x86\w32x86

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\spool\prtprocs\w32x86\w32x86

Found mount point : C:\WINDOWS\system32\wbem\mof\bad\bad

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\wbem\mof\bad\bad

Found mount point : C:\WINDOWS\system32\wbem\mof\good\good

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\wbem\mof\good\good

Found mount point : C:\WINDOWS\system32\wbem\snmp\snmp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\wbem\snmp\snmp

Found mount point : C:\WINDOWS\system32\wins\wins

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\wins\wins

Found mount point : C:\WINDOWS\system32\xircom\xircom

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\system32\xircom\xircom

Found mount point : C:\WINDOWS\temp\_avast4_\_avast4_

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\temp\_avast4_\_avast4_

Found mount point : C:\WINDOWS\WinSxS\InstallTemp\InstallTemp

Mount point destination : \Device\__max++>\^

Removing mount point : C:\WINDOWS\WinSxS\InstallTemp\InstallTemp



Finished!


Combofix:

ComboFix 09-09-01.04 - ZEUS85 09/01/2009 21:05.2.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.659 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\ayeshut.dll
c:\windows\easdsave.dll
c:\windows\Fonts\THIRDPAR.TTF
c:\windows\inicea.dll
c:\windows\run.log
c:\windows\system32\3.tmp
c:\windows\system32\4.tmp
c:\windows\system32\5.tmp
c:\windows\system32\drivers\kbiwkmkwbivkos.sys
c:\windows\system32\kbiwkmcpeybxvq.dll
c:\windows\system32\kbiwkmhoawxwvj.dat
c:\windows\system32\kbiwkmiurtqwux.dat
c:\windows\system32\kbiwkmnvpfypie.dll
c:\windows\system32\Plugins
c:\windows\system32\Plugins\ml\ml_pmp_device_Creative Zen V Plus.ini
c:\windows\system32\uacinit.dll
c:\windows\system32\UACmrndpmxpwg.dat

Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\system32\dllcache\eventlog.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
——-\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
——-\Service_kbiwkmlilrkmas


((((((((((((((((((((((((( Files Created from 2009-08-02 to 2009-09-02 )))))))))))))))))))))))))))))))
.

2037-06-10 08:08 . 2037-06-10 08:08 4263 –sh–w- c:\windows\windllreg1c.sys
2009-09-01 02:46 . 2009-09-01 02:47 117760 —-a-w- c:\documents and settings\ZEUS85\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-09-01 02:46 . 2009-09-01 02:46 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-09-01 02:46 . 2009-09-02 04:10 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-09-01 02:46 . 2009-09-01 02:46 ——– d—–w- c:\documents and settings\ZEUS85\Application Data\SUPERAntiSpyware.com
2009-09-01 01:41 . 2009-09-01 02:59 ——– d—–w- c:\program files\Sophos
2009-09-01 01:36 . 2009-09-01 01:36 ——– d-s—w- c:\documents and settings\Administrator\UserData
2009-08-31 07:31 . 2009-09-01 00:09 ——– d—–w- c:\program files\Trend Micro
2009-08-31 07:19 . 2009-08-31 07:19 152576 —-a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-30 22:10 . 2009-08-30 22:10 ——– d—–w- c:\program files\Alwil Software
2009-08-30 21:18 . 2009-08-30 21:18 ——– d—–w- c:\program files\CCleaner
2009-08-30 08:58 . 2009-07-16 22:37 1032192 —-a-w- c:\documents and settings\ZEUS85\Application Data\Mozilla\Firefox\Profiles\7shwdqjc.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
2009-08-30 07:57 . 2009-08-30 19:30 ——– d–h–w- C:\$AVG8.VAULT$
2009-08-30 07:41 . 2009-08-30 07:41 ——– d—–w- c:\program files\BitCometZ
2009-08-30 03:07 . 2009-08-30 03:07 ——– d—–w- C:\spoolerlogs
2009-08-29 19:09 . 2009-07-24 16:55 1090816 —-a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-08-16 09:04 . 2009-08-16 09:04 ——– d—–w- c:\documents and settings\ZEUS85\Application Data\dvdcss
2009-08-13 02:22 . 2009-08-13 02:22 ——– d—–w- c:\windows\ServicePackFiles
2009-08-08 19:37 . 2009-08-08 19:37 ——– d—–w- c:\documents and settings\ZEUS85\Local Settings\Application Data\AVG Security Toolbar
2009-08-08 19:34 . 2009-08-08 19:34 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-08-08 19:34 . 2009-08-08 19:34 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-08 19:34 . 2009-08-08 19:34 335240 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-08 19:34 . 2009-08-08 19:34 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-08 19:34 . 2009-09-01 14:55 ——– d—–w- c:\windows\system32\drivers\Avg
2009-08-08 19:34 . 2009-08-08 19:34 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-08-08 19:28 . 2009-08-08 19:28 ——– d—–w- c:\documents and settings\ZEUS85\Application Data\AVG8
2009-08-08 06:51 . 2009-08-31 04:39 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-08-08 03:18 . 2009-08-08 03:18 ——– d—–w- c:\program files\u-he
2009-08-08 03:18 . 2009-08-08 03:18 ——– d—–w- c:\program files\Common Files\Digidesign
2009-08-08 03:18 . 2009-08-08 03:18 ——– d—–w- c:\program files\Celemony

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-02 03:59 . 2004-08-04 12:00 55808 —-a-w- c:\windows\system32\eventlog.dll
2009-09-01 03:00 . 2007-06-06 06:40 ——– d—–w- c:\program files\BitTorrent
2009-09-01 02:45 . 2007-05-23 05:26 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-08-31 04:33 . 2007-07-16 04:09 ——– d—–w- c:\program files\Audible
2009-08-31 04:32 . 2008-12-27 02:15 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-08-31 04:32 . 2008-12-27 02:15 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-31 03:51 . 2008-12-23 06:00 ——– d—–w- c:\program files\ADAWARE
2009-08-30 21:36 . 2008-12-23 04:22 102664 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2009-08-30 21:26 . 2006-09-21 17:10 ——– d—–w- c:\program files\GetRight
2009-08-30 09:22 . 2006-04-24 01:55 ——– d—–w- c:\program files\Aye Shutdown
2009-08-29 08:26 . 2008-08-28 01:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Soulseek
2009-08-18 20:49 . 2009-08-18 20:49 784810 —-a-w- c:\windows\system32\xa.tmp
2009-08-16 19:09 . 2008-04-26 07:03 ——– d—–w- c:\program files\Microsoft Silverlight
2009-08-16 09:19 . 2008-01-26 21:57 ——– d—–w- c:\program files\Steam
2009-08-14 00:14 . 2006-05-06 23:54 ——– d—–w- c:\documents and settings\ZEUS85\Application Data\AdobeUM
2009-08-10 14:29 . 2006-04-22 21:02 82736 —-a-w- c:\documents and settings\ZEUS85\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-09 08:47 . 2008-03-28 21:56 ——– d—–w- c:\program files\DOSBox-0.72
2009-08-08 03:18 . 2006-04-20 18:43 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-31 04:38 . 2009-07-31 04:38 ——– d—–w- c:\program files\Wondershare
2009-07-31 04:34 . 2009-07-31 04:13 ——– d—–w- c:\program files\Free Music Zilla
2009-07-31 04:15 . 2009-07-31 04:15 ——– d—–w- c:\documents and settings\ZEUS85\Application Data\FMZilla
2009-07-19 00:39 . 2007-08-18 04:03 ——– d—–w- c:\documents and settings\ZEUS85\Application Data\Skype
2009-07-18 23:10 . 2009-06-24 00:06 ——– d—–w- c:\documents and settings\ZEUS85\Application Data\skypePM
2009-06-24 00:06 . 2009-06-24 00:06 56 —ha-w- c:\windows\system32\ezsidmv.dat
2009-06-16 14:55 . 2004-08-04 12:00 82432 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 2004-08-04 12:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-05 07:42 . 2006-04-20 18:27 655872 —-a-w- c:\windows\system32\mstscax.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 16:55 1090816 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2005-10-24 307200]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-08-05 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-09 7561216]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-03-09 86016]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2006-03-21 213936]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-21 86960]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-21 213936]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-08-09 185896]
"ASUS Probe"="c:\program files\ASUS\Asus Probe\AsusProb.exe" [2002-12-06 617984]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-02-13 564496]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-20 2007832]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-06-19 155648]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-11-15 77824]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2004-08-04 53760]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-08 19:34 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^ZEUS85^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\ZEUS85\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\QUAKE\\darkplaces.exe"=
"c:\\Games\\NES\\NESTCL95.EXE"=
"c:\\Program Files\\Steam\\steamapps\\zeusmega\\counter-strike\\hl.exe"=
"c:\\Program Files\\SoulseekNS\\slsk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Free Music Zilla\\FMZilla.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\BitCometZ\\BitComet.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9840:TCP"= 9840:TCP:BitComet 9840 TCP
"9840:UDP"= 9840:UDP:BitComet 9840 UDP
"16018:TCP"= 16018:TCP:BitComet 16018 TCP
"16018:UDP"= 16018:UDP:BitComet 16018 UDP
"9589:TCP"= 9589:TCP:BitComet 9589 TCP
"9589:UDP"= 9589:UDP:BitComet 9589 UDP
"17472:TCP"= 17472:TCP:BitComet 17472 TCP
"17472:UDP"= 17472:UDP:BitComet 17472 UDP
"9987:TCP"= 9987:TCP:BitComet 9987 TCP
"9987:UDP"= 9987:UDP:BitComet 9987 UDP
"21325:TCP"= 21325:TCP:BitComet 21325 TCP
"21325:UDP"= 21325:UDP:BitComet 21325 UDP
"15058:TCP"= 15058:TCP:BitComet 15058 TCP
"15058:UDP"= 15058:UDP:BitComet 15058 UDP
"19472:TCP"= 19472:TCP:BitComet 19472 TCP
"19472:UDP"= 19472:UDP:BitComet 19472 UDP
"26165:TCP"= 26165:TCP:BitComet 26165 TCP
"26165:UDP"= 26165:UDP:BitComet 26165 UDP
"20737:TCP"= 20737:TCP:BitComet 20737 TCP
"20737:UDP"= 20737:UDP:BitComet 20737 UDP
"11676:TCP"= 11676:TCP:BitComet 11676 TCP
"11676:UDP"= 11676:UDP:BitComet 11676 UDP
"25362:TCP"= 25362:TCP:BitComet 25362 TCP
"25362:UDP"= 25362:UDP:BitComet 25362 UDP
"20977:TCP"= 20977:TCP:BitComet 20977 TCP
"20977:UDP"= 20977:UDP:BitComet 20977 UDP
"24471:TCP"= 24471:TCP:BitComet 24471 TCP
"24471:UDP"= 24471:UDP:BitComet 24471 UDP

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/8/2009 12:34 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8/8/2009 12:34 PM 108552]
R1 nltdi;nltdi;c:\windows\system32\drivers\nltdi.sys [6/14/2006 12:44 PM 93824]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [8/5/2009 4:06 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [8/5/2009 4:06 PM 74480]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/8/2009 12:34 PM 297752]
R2 gearsec;gearsec;c:\windows\system32\gearsec.exe [12/1/2003 3:27 PM 53248]
R3 WsAudioDevice_383;WsAudioDevice_383;c:\windows\system32\drivers\WsAudioDevice_383.sys [7/30/2009 9:38 PM 16640]
S0 pxark;pxark;c:\windows\system32\drivers\pxark.sys –> c:\windows\system32\drivers\pxark.sys [?]
S1 DW;DW; [x]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [8/8/2009 12:34 PM 908056]
S2 CSIScanner;CSIScanner;"c:\program files\PrevxCSI\prevxcsi.exe" /service –> c:\program files\PrevxCSI\prevxcsi.exe [?]
S2 RPCHE;Remote Procedure Call (RPCE);c:\program files\Common Files\Microsoft Shared\Speech\csvd.exe –> c:\program files\Common Files\Microsoft Shared\Speech\csvd.exe [?]
S3 DiagnosticScan;DiagnosticScan;\??\c:\program files\Adware Away\DiagnosticScan.SYS –> c:\program files\Adware Away\DiagnosticScan.SYS [?]
S3 dwusbdnt;dwusbdnt;c:\windows\system32\drivers\dwusbdnt.sys [4/23/2006 3:48 PM 10368]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\1.tmp –> c:\windows\system32\1.tmp [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [8/5/2009 4:06 PM 7408]
S3 uti0ote4;AVZ Kernel Driver;\??\c:\windows\system32\Drivers\uti0ote4.sys –> c:\windows\system32\Drivers\uti0ote4.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2009-09-02 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-07 05:18]
.
- - - - ORPHANS REMOVED - - - -

BHO-{a789f652-2fda-430d-b72e-f40e25f6c55e} - c:\windows\system32\vevinaho.dll
HKCU-Run-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe


.
——- Supplementary Scan ——-
.
uStart Page = www.google.ca
mStart Page = www.google.ca
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Download with GetRight - c:\program files\GetRight\GRdownload.htm
IE: Open with GetRight Browser - c:\program files\GetRight\GRbrowse.htm
FF - ProfilePath - c:\documents and settings\ZEUS85\Application Data\Mozilla\Firefox\Profiles\7shwdqjc.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - prefs.js: keyword.URL - hxxp://ca.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_ca&p=
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\ZEUS85\Application Data\Mozilla\Firefox\Profiles\7shwdqjc.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-01 21:15
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\1.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\kbiwkmlilrkmas]
"imagepath"="\systemroot\system32\drivers\kbiwkmkwbivkos.sys"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3421744925-564012677-1258165160-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*Z%º*µ*]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-3421744925-564012677-1258165160-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*Z%º*µ*\OpenWithList]
@Class="Shell"

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\kbiwkmlilrkmas]
@DACL=(02 0000)
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=expand:"\\systemroot\\system32\\drivers\\kbiwkmkwbivkos.sys"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(780)
c:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(3940)
c:\windows\system32\shdoclc.dll
.
———————— Other Running Processes ————————
.
c:\program files\ADAWARE\aawservice.exe
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\NetLimiter 2 Pro\nlsvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Completion time: 2009-09-02 21:21 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-02 04:21

Pre-Run: 4,011,601,920 bytes free
Post-Run: 4,164,050,944 bytes free

307 — E O F — 2009-07-15 14:11

Thank you for the prompt response!
1) P2P Warning
P2P - I see you have P2P software (BitComet, BitTorrent) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs. If you wish to keep them, please cease from using them until you are 'all clean'.

2) CFScript
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    http://forums.whatthetech.com/HELP_ME_PLEASE_INFECTED_ROOTKIT_TROJAN_t106625.html
    
    Collect:: 
    c:\windows\system32\xa.tmp
    
    Driver:: 
    DW
    
    RegLockDel::
    [HKEY_LOCAL_MACHINE\System\ControlSet003\Services\kbiwkmlilrkmas]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

3) Scan some files
Go to My Computer-> Tools-> Folder Options-> View tab:
  • Under the Hidden files and folders heading:
  • Select - Show hidden files and folders.
  • Uncheck- Hide protected operating system files (recommended) option.
  • Also, make sure there is no checkmark beside Hide file extensions for known file types.
  • Click OK. (Remember to Hide files and folders once done)

Please go to one of the below sites to scan the following files:
VirScan
Virus Total

Click on Browse, and upload the following file for analysis:
c:\windows\windllreg1c.sys

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.

4) What You Will Need To Post:
  • Combofix log
  • VirScan log
Hi Raktor, I went ahead as you requested. Here are the results. FYI I am now working in Normal Mode as explorer.exe is running again (it would previously shut it down on start up) and can now use Firefox or IE without any issues (previously it would re-direct me to random sites constantly).


Combofix Log:

ComboFix 09-09-01.07 - ZEUS85 09/02/2009 10:48.3.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.632 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\ZEUS85\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

file zipped: c:\windows\system32\xa.tmp
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\xa.tmp
c:\windows\TEMP\logishrd\LVPrcInj01.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_kbiwkmlilrkmas
——-\Service_DW
——-\Service_kbiwkmlilrkmas


((((((((((((((((((((((((( Files Created from 2009-08-02 to 2009-09-02 )))))))))))))))))))))))))))))))
.

2037-06-10 08:08 . 2037-06-10 08:08 4263 –sh–w- c:\windows\windllreg1c.sys
2009-09-01 02:46 . 2009-09-01 02:46 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-09-01 02:46 . 2009-09-02 17:53 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-09-01 02:46 . 2009-09-01 02:46 ——– d—–w- c:\documents and settings\ZEUS85\Application Data\SUPERAntiSpyware.com
2009-09-01 01:41 . 2009-09-01 02:59 ——– d—–w- c:\program files\Sophos
2009-09-01 01:36 . 2009-09-01 01:36 ——– d-s—w- c:\documents and settings\Administrator\UserData
2009-08-31 07:31 . 2009-09-01 00:09 ——– d—–w- c:\program files\Trend Micro
2009-08-30 22:10 . 2009-08-30 22:10 ——– d—–w- c:\program files\Alwil Software
2009-08-30 21:18 . 2009-08-30 21:18 ——– d—–w- c:\program files\CCleaner
2009-08-30 07:57 . 2009-08-30 19:30 ——– d–h–w- C:\$AVG8.VAULT$
2009-08-30 07:41 . 2009-09-02 17:41 ——– d—–w- c:\program files\BitCometZ
2009-08-30 03:07 . 2009-08-30 03:07 ——– d—–w- C:\spoolerlogs
2009-08-16 09:04 . 2009-08-16 09:04 ——– d—–w- c:\documents and settings\ZEUS85\Application Data\dvdcss
2009-08-13 02:22 . 2009-08-13 02:22 ——– d—–w- c:\windows\ServicePackFiles
2009-08-08 19:37 . 2009-08-08 19:37 ——– d—–w- c:\documents and settings\ZEUS85\Local Settings\Application Data\AVG Security Toolbar
2009-08-08 19:34 . 2009-08-08 19:34 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-08-08 19:34 . 2009-08-08 19:34 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-08 19:34 . 2009-08-08 19:34 335240 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-08 19:34 . 2009-08-08 19:34 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-08 19:34 . 2009-09-02 17:37 ——– d—–w- c:\windows\system32\drivers\Avg
2009-08-08 19:34 . 2009-08-08 19:34 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-08-08 19:28 . 2009-08-08 19:28 ——– d—–w- c:\documents and settings\ZEUS85\Application Data\AVG8
2009-08-08 06:51 . 2009-08-31 04:39 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-08-08 03:18 . 2009-08-08 03:18 ——– d—–w- c:\program files\u-he
2009-08-08 03:18 . 2009-08-08 03:18 ——– d—–w- c:\program files\Common Files\Digidesign
2009-08-08 03:18 . 2009-08-08 03:18 ——– d—–w- c:\program files\Celemony

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-02 17:42 . 2007-05-23 05:26 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-09-02 03:59 . 2004-08-04 12:00 55808 ——w- c:\windows\system32\eventlog.dll
2009-09-01 03:00 . 2007-06-06 06:40 ——– d—–w- c:\program files\BitTorrent
2009-08-31 04:33 . 2007-07-16 04:09 ——– d—–w- c:\program files\Audible
2009-08-31 04:32 . 2008-12-27 02:15 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-08-31 04:32 . 2008-12-27 02:15 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-31 03:51 . 2008-12-23 06:00 ——– d—–w- c:\program files\ADAWARE
2009-08-30 21:36 . 2008-12-23 04:22 102664 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2009-08-30 21:26 . 2006-09-21 17:10 ——– d—–w- c:\program files\GetRight
2009-08-30 09:22 . 2006-04-24 01:55 ——– d—–w- c:\program files\Aye Shutdown
2009-08-29 08:26 . 2008-08-28 01:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Soulseek
2009-08-16 19:09 . 2008-04-26 07:03 ——– d—–w- c:\program files\Microsoft Silverlight
2009-08-16 09:19 . 2008-01-26 21:57 ——– d—–w- c:\program files\Steam
2009-08-14 00:14 . 2006-05-06 23:54 ——– d—–w- c:\documents and settings\ZEUS85\Application Data\AdobeUM
2009-08-10 14:29 . 2006-04-22 21:02 82736 —-a-w- c:\documents and settings\ZEUS85\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-09 08:47 . 2008-03-28 21:56 ——– d—–w- c:\program files\DOSBox-0.72
2009-08-08 03:18 . 2006-04-20 18:43 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-31 04:38 . 2009-07-31 04:38 ——– d—–w- c:\program files\Wondershare
2009-07-31 04:34 . 2009-07-31 04:13 ——– d—–w- c:\program files\Free Music Zilla
2009-07-31 04:15 . 2009-07-31 04:15 ——– d—–w- c:\documents and settings\ZEUS85\Application Data\FMZilla
2009-07-19 00:39 . 2007-08-18 04:03 ——– d—–w- c:\documents and settings\ZEUS85\Application Data\Skype
2009-07-18 23:10 . 2009-06-24 00:06 ——– d—–w- c:\documents and settings\ZEUS85\Application Data\skypePM
2009-06-24 00:06 . 2009-06-24 00:06 56 —ha-w- c:\windows\system32\ezsidmv.dat
2009-06-16 14:55 . 2004-08-04 12:00 82432 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:55 . 2004-08-04 12:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-05 07:42 . 2006-04-20 18:27 655872 —-a-w- c:\windows\system32\mstscax.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-09-02_04.15.54 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-02 17:59 . 2009-09-02 17:59 32768 c:\windows\temp\Temporary Internet Files\Content.IE5\index.dat
- 2009-08-30 21:30 . 2009-09-02 04:15 32768 c:\windows\temp\Temporary Internet Files\Content.IE5\index.dat
+ 2009-09-02 17:59 . 2009-09-02 17:59 32768 c:\windows\temp\History\History.IE5\MSHist012009090220090903\index.dat
+ 2009-09-02 17:59 . 2009-09-02 17:59 32768 c:\windows\temp\History\History.IE5\index.dat
- 2009-08-30 21:30 . 2009-09-02 04:15 32768 c:\windows\temp\History\History.IE5\index.dat
+ 2009-09-02 17:59 . 2009-09-02 17:59 16384 c:\windows\temp\Cookies\index.dat
- 2009-08-30 21:30 . 2009-09-02 04:15 16384 c:\windows\temp\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 16:55 1090816 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2005-10-24 307200]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-08-05 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-09 7561216]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-03-09 86016]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2006-03-21 213936]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-03-21 86960]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-03-21 213936]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-08-09 185896]
"ASUS Probe"="c:\program files\ASUS\Asus Probe\AsusProb.exe" [2002-12-06 617984]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-02-13 564496]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-20 2007832]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-06-19 155648]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-11-15 77824]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2004-08-04 53760]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-08 19:34 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^ZEUS85^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\ZEUS85\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\QUAKE\\darkplaces.exe"=
"c:\\Games\\NES\\NESTCL95.EXE"=
"c:\\Program Files\\Steam\\steamapps\\zeusmega\\counter-strike\\hl.exe"=
"c:\\Program Files\\SoulseekNS\\slsk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Free Music Zilla\\FMZilla.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9840:TCP"= 9840:TCP:BitComet 9840 TCP
"9840:UDP"= 9840:UDP:BitComet 9840 UDP
"16018:TCP"= 16018:TCP:BitComet 16018 TCP
"16018:UDP"= 16018:UDP:BitComet 16018 UDP
"9589:TCP"= 9589:TCP:BitComet 9589 TCP
"9589:UDP"= 9589:UDP:BitComet 9589 UDP
"17472:TCP"= 17472:TCP:BitComet 17472 TCP
"17472:UDP"= 17472:UDP:BitComet 17472 UDP
"9987:TCP"= 9987:TCP:BitComet 9987 TCP
"9987:UDP"= 9987:UDP:BitComet 9987 UDP
"21325:TCP"= 21325:TCP:BitComet 21325 TCP
"21325:UDP"= 21325:UDP:BitComet 21325 UDP
"15058:TCP"= 15058:TCP:BitComet 15058 TCP
"15058:UDP"= 15058:UDP:BitComet 15058 UDP
"19472:TCP"= 19472:TCP:BitComet 19472 TCP
"19472:UDP"= 19472:UDP:BitComet 19472 UDP
"26165:TCP"= 26165:TCP:BitComet 26165 TCP
"26165:UDP"= 26165:UDP:BitComet 26165 UDP
"20737:TCP"= 20737:TCP:BitComet 20737 TCP
"20737:UDP"= 20737:UDP:BitComet 20737 UDP
"11676:TCP"= 11676:TCP:BitComet 11676 TCP
"11676:UDP"= 11676:UDP:BitComet 11676 UDP
"25362:TCP"= 25362:TCP:BitComet 25362 TCP
"25362:UDP"= 25362:UDP:BitComet 25362 UDP
"20977:TCP"= 20977:TCP:BitComet 20977 TCP
"20977:UDP"= 20977:UDP:BitComet 20977 UDP
"24471:TCP"= 24471:TCP:BitComet 24471 TCP
"24471:UDP"= 24471:UDP:BitComet 24471 UDP

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/8/2009 12:34 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8/8/2009 12:34 PM 108552]
R1 nltdi;nltdi;c:\windows\system32\drivers\nltdi.sys [6/14/2006 12:44 PM 93824]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/8/2009 12:34 PM 297752]
R2 gearsec;gearsec;c:\windows\system32\gearsec.exe [12/1/2003 3:27 PM 53248]
R3 WsAudioDevice_383;WsAudioDevice_383;c:\windows\system32\drivers\WsAudioDevice_383.sys [7/30/2009 9:38 PM 16640]
S0 pxark;pxark;c:\windows\system32\drivers\pxark.sys –> c:\windows\system32\drivers\pxark.sys [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys –> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [8/8/2009 12:34 PM 908056]
S2 CSIScanner;CSIScanner;"c:\program files\PrevxCSI\prevxcsi.exe" /service –> c:\program files\PrevxCSI\prevxcsi.exe [?]
S2 RPCHE;Remote Procedure Call (RPCE);c:\program files\Common Files\Microsoft Shared\Speech\csvd.exe –> c:\program files\Common Files\Microsoft Shared\Speech\csvd.exe [?]
S3 DiagnosticScan;DiagnosticScan;\??\c:\program files\Adware Away\DiagnosticScan.SYS –> c:\program files\Adware Away\DiagnosticScan.SYS [?]
S3 dwusbdnt;dwusbdnt;c:\windows\system32\drivers\dwusbdnt.sys [4/23/2006 3:48 PM 10368]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\1.tmp –> c:\windows\system32\1.tmp [?]
S3 uti0ote4;AVZ Kernel Driver;\??\c:\windows\system32\Drivers\uti0ote4.sys –> c:\windows\system32\Drivers\uti0ote4.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2009-09-02 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-07 05:18]
.
.
——- Supplementary Scan ——-
.
uStart Page = www.google.ca
mStart Page = www.google.ca
IE: Download with GetRight - c:\program files\GetRight\GRdownload.htm
IE: Open with GetRight Browser - c:\program files\GetRight\GRbrowse.htm
FF - ProfilePath - c:\documents and settings\ZEUS85\Application Data\Mozilla\Firefox\Profiles\7shwdqjc.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/
FF - prefs.js: keyword.URL - hxxp://ca.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_ca&p=
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\ZEUS85\Application Data\Mozilla\Firefox\Profiles\7shwdqjc.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-02 10:59
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\1.tmp"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3421744925-564012677-1258165160-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*Z%º*µ*]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-3421744925-564012677-1258165160-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*Z%º*µ*\OpenWithList]
@Class="Shell"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(2548)
c:\windows\system32\shdoclc.dll
.
———————— Other Running Processes ————————
.
c:\program files\ADAWARE\aawservice.exe
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\NetLimiter 2 Pro\nlsvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Completion time: 2009-09-02 11:02 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-02 18:02
ComboFix2.txt 2009-09-02 04:21

Pre-Run: 4,426,477,568 bytes free
Post-Run: 4,368,719,872 bytes free

274 — E O F — 2009-07-15 14:11
Upload was successful

VirScan results:

File information
File Name : windllreg1c.sys
File Size : 4263 byte
File Type : Non-ISO extended-ASCII text, with very long lines, with CRLF
MD5 : c235a9df989a6df7ac8e2864e6ac075a
SHA1 : 2c6e4271a10c8f5f1565f5c4d60831b65a76b16f

Scanner results
Scanner results : All Scanners reported not find malware!
Time : 2009/09/02 17:19:44 (PDT)

Virus Total results:

File size: 4263 bytes
MD5…: c235a9df989a6df7ac8e2864e6ac075a
SHA1..: 2c6e4271a10c8f5f1565f5c4d60831b65a76b16f
SHA256: 17c2633595786ac903e660d0786508785dbd4e196c81cf463e715ed806c41168
ssdeep: 96:qEiynpT5QGOHnxQwNRXFD+lblUCd66xSrbJdyDz:qWnpT5uHTXFsTSrDyH
PEiD..: -
PEInfo: -
RDS…: NSRL Reference Data Set
-
pdfid.: -
trid..: Unknown!

File windllreg1c.sys received on 2009.09.03 00:31:27 (UTC)
Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED
Result: 0/41 (0%)

Both anti-virus scanners say the file is not infected.

Should I re-try in Safe Mode or…?

I'm glad at least Combofix worked and I was able to run CFScript just fine. Thanks again
That's fine, we were just checking to see if it was malicious - it isn't. :)

1) Programs List
C:\Qoobox\Add-Remove Programs.txt
Please post the contents of this file in your next reply.

2) MBAM
Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

3) ESET
You can use either Internet Explorer or Mozilla FireFox for this scan.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

4) What You Will Need To Post:
  • C:\Qoobox\Add-Remove Programs.txt
  • MBAM log
  • ESET log
So far so good. First time I managed to run a scan in Malwarebytes in a few days without it prematurely shutting down. Qoobox Add or Remove files.txt: AccessDiver v4.120 AccessDiver v4.250 Ad-Aware Adobe Download Manager 2.0 (Remove Only) Adobe Flash Player 10 Plugin Adobe Flash Player ActiveX Adobe Reader 7.0.7 Audacity 1.2.4 AutoUpdate AVG Free 8.5 AVI Splitter Aye Shutdown CCleaner (remove only) CDisplay 1.8 Counter-Strike Creative MediaSource 5 Creative Removable Disk Manager Creative System Information Creative ZEN V Series (R2) DAEMON Tools DivX Converter DivX Player DivX Web Player Dziobas Rar Player 0.007PL Easy Video Splitter 1.28 Free Music Zilla Free Natural Text to Speech Reader 2007 Free Video Dub version 1.4 GetRight GTA San Andreas Hotfix for Windows XP (KB952287) iPod for Windows 2006-03-23 IsoBuster 1.9 iTunes J2SE Runtime Environment 5.0 Update 6 K-Lite Codec Pack 2.53 Standard Logitech Gaming Software Logitech QuickCam Logitech QuickCam Driver Package Logitech Updater LucasArts' Jedi Knight Macromedia Extension Manager Macromedia Flash 8 Macromedia Flash 8 Video Encoder Macromedia Flash Player 8 MediaJoin Melodyne 3.1 Microsoft Silverlight Microsoft Text-to-Speech Engine 4.0 (English) Microsoft Visual C++ 2005 Redistributable Miranda IM 0.7.14 MixMeister Pro 6 Mozilla Firefox (3.5.2) MPEG-VCR 3.14.6.6 (12/2008) MPEG Joiner MPIO Manager 2 MSN MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 Parser and SDK Nero 6 Ultra Edition NetLimiter 2 Pro (remove only) NVIDIA Drivers Oblivion Open Video Joiner version 3.21 OpenOffice.org 2.1 Plasma Pong v1.3b PowerDVD PowerISO Prince of Persia T2T Project64 1.6 Quake QuickTime RapidCheck v0.1 RealPlayer Realtek AC'97 Audio Reason Reason 4.0 Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB911565) Security Update for Windows Media Player 9 (KB917734) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899589) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913433) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928090) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB929969) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931768) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933566) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937143) Security Update for Windows XP (KB937894) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB939653) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB941644) Security Update for Windows XP (KB941693) Security Update for Windows XP (KB942615) Security Update for Windows XP (KB943055) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB943485) Security Update for Windows XP (KB944338) Security Update for Windows XP (KB944533) Security Update for Windows XP (KB944653) Security Update for Windows XP (KB945553) Security Update for Windows XP (KB946026) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB947864) Security Update for Windows XP (KB948590) Security Update for Windows XP (KB948881) Security Update for Windows XP (KB950749) Security Update for Windows XP (KB950759) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953838) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956390) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958215) Security Update for Windows XP (KB958470) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960714) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB963027) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969897) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB973346) Skype™ 4.0 SoulSeek 157 NS 13c Star Trek Voyager Elite Force Starcraft Steam Swiff Player 1.1 System Requirements Lab Tame version 5.0 (remove only) Tetris Uninstall 1.0.0.0 Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB933360) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Update for Windows XP (KB942840) Update for Windows XP (KB946627) Update for Windows XP (KB951072-v2) Update for Windows XP (KB955839) Update for Windows XP (KB967715) VideoLAN VLC media player 0.8.6a Warcraft II BNE Warcraft III Wav2MP3 Wizard WebFldrs XP Winamp WinAVIVideoConverter Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Installer 3.1 (KB893803) Windows Live installer Windows Live Messenger Windows Media Format Runtime Windows Media Player 10 Windows Media Player 10 Hotfix - KB895316 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 WinRAR archiver Wondershare Streaming Audio Recorder(Build 1.0.4.0) Xfire (remove only) XP TCP/IP Repair 1.0 Yahoo! Toolbar ZENcast Organizer MBAM log: Malwarebytes' Anti-Malware 1.40 Database version: 2734 Windows 5.1.2600 Service Pack 2 9/2/2009 11:44:04 PM mbam-log-2009-09-02 (23-44-04).txt Scan type: Quick Scan Objects scanned: 92042 Time elapsed: 3 minute(s), 44 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\RPCHE (Backdoor.Bot) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Documents and Settings\ZEUS85\Application Data\ptidle (Trojan.Downloader) -> Quarantined and deleted successfully. Files Infected: (No malicious items detected) ESET Log: C:\Qoobox\Quarantine\[4]-Submit_2009-09-02_10.48.14.zip Win32/TrojanDownloader.Agent.OYU trojan C:\Qoobox\Quarantine\C\WINDOWS\system32\awesozik.ini.vir Win32/Adware.Virtumonde.NEO application C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\_kbiwkmkwbivkos_.sys.zip a variant of Win32/Rootkit.Kryptik.I trojan C:\SDFix\apps\Process.exe Win32/PrcView application
1) Backdoor Warning
I hate to the bearer of bad news but, your log shows a very dangerous Trojan was residing on your PC.

Backdoor.Bot
The Trojan attempts to steal passwords, as well as logging key presses and open window titles to text files and periodically sends the collected information to a remote user via HTTP. The Trojan downloads and executes additional files from a remote site. Configuration files may also be downloaded which define further behaviors.

As you can see, it not only includes a key logger, but back door functionality.

If you do any banking or other financial transactions on the PC or it if it contains any other sensitive information, please get to a known clean computer and change all passwords where applicable and it would be wise to contact those same financial institutions to apprise them of your situation.

Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall

Should you have any questions, please feel free to ask.

2) Update Adobe
Your current version of Adobe Reader is out of date, and may contain security issues. Please uninstall the version you have now from Add/Remove programs, and then download and install the latest Adobe Reader.

3) Update Java
Your version of Java is outdated.

Please download JavaRa to your desktop and unzip it to its own folder

Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
Accept any prompts.
Open JavaRa.exe again and select Search For Updates.
Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

4) What You Will Need To Post:
  • How the computer is performing now - Any remaining issues?
Hey, everything is working great! I scanned again with Ant Malware Bytes in normal mode, it found some minor things. I scanned again in normal mode and then safe mode just to be sure and its all clean. I used CC Cleaner to clean up my registry and now it's running better than before. Thanks again for all your help, I took note of the Backdoor Bot and changed all my passwords, etc. from a different computer and notified my bank just in case of any suspicious activity. Your help is much appreciated and have a great Labor Day weekend! :notworthy:
:thumbup:

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • [external image: Posted Image]
The above procedure will reset your System Restore and clear out the backups and quarantines created during the course of this fix.

You can delete DDS, RR and the other tools we used during your fix.

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer More Secure
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.

    • Change the Download signed ActiveX controls to Prompt.
    • Change the Download unsigned ActiveX controls to Disable.
    • Change the Initialise and script ActiveX controls not marked as safe to Disable.
    • Change the Installation of desktop items to Prompt.
    • Change the Launching programs and files in an IFRAME to Prompt.
    • Change the Navigate sub-frames across different domains to Prompt.
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. Update your Anti-Virus Software - I can not overemphasize the need for you to update your Anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

3. Make sure you keep your Windows OS current by visiting Windows update regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.

4. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

5. Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

6. Protect your computer from internet threats with SandboxIE. This program isolates Internet Explorer from the rest of your operating system, 'sandboxing' it away - so malicious websites can't do damage to the rest of your system. There is a Getting Started guide on their website.

7. Finally, I strongly recommend that you read Miekiemoses' good advice - How to prevent Malware

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI