This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] C:\SUD\SSOW\sep.exe

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Good Morning all, I've seen someone else post about this problem, and my clock changed it's date to 2016 also. I do have an MP3 player, but I've never connected it to anyone else's computer, just mine. Also, on startup I get a pop-up that says my system has recovered from a serious error, would you like to send report? I click yes, then the little pop-up with C:\SUD\SSOW\sep.exe appears, and then another one that says something about C:\WINDOWS ? ? ? ? ? ? ? \winsysdriver.exe Restart. Those question marks refer to the path that I can't remember. So here's everything that you guys had new people do: ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/11/27 06:12 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ——————- Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xF68E6000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF8A97000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xF568E000 Size: 49152 File Visible: No Signed: - Status: - SSDT ——————- #: 122 Function Name: NtOpenProcess Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys" at address 0xf87ee470 #: 257 Function Name: NtTerminateProcess Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys" at address 0xf87ee520 #: 258 Function Name: NtTerminateThread Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys" at address 0xf87ee5c0 #: 277 Function Name: NtWriteVirtualMemory Status: Hooked by "C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys" at address 0xf87ee660 ==EOF== |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||| | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||| | |||| DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 6:06:30.79 on Fri 11/27/2009 Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_17 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.43 [GMT -5:00] AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe svchost.exe svchost.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\AVG\AVG9\avgfws9.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\System32\TUProgSt.exe C:\Program Files\AVG\AVG9\avgemc.exe C:\Program Files\AVG\AVG9\avgam.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\WINDOWS\explorer.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\WINDOWS\explorer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\AVG\AVG9\avgtray.exe C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe C:\Documents and Settings\Spike\My Documents\Downloads\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html mDefault_Page_URL = hxxp://www.yahoo.com/ mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com mStart Page = hxxp://www.yahoo.com/ mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File uExplorerRun: [Microsoft Windows Operating System] c:\windows\system32\winsysdriver.exe mExplorerRun: [Microsoft Windows Operating System] c:\windows\system32\winsysdriver.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll Notify: avgrsstarter - avgrsstx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\spike\applic~1\mozilla\firefox\profiles\wvl2fd3k.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p= FF - prefs.js: browser.search.selectedEngine - Yahoo! Search FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p= FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 600 FF - user.js: content.notify.interval - 600000 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.switch.threshold - 600000 FF - user.js: yahoo.homepage.dontask - true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, falsec:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [2009-10-16 25608] R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-10-16 161800] R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-10-16 333192] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-10-16 28424] R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-10-16 360584] R2 avg9emc;AVG E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2009-10-16 906520] R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2009-10-16 285392] R2 avgfws9;AVG Firewall;c:\program files\avg\avg9\avgfws9.exe [2009-10-22 2304192] R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\avg\avg9\identity protection\agent\bin\AVGIDSAgent.exe [2009-10-22 5832712] R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2009-11-11 604488] R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2009-10-16 30104] R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSDriver.sys [2009-10-16 122376] R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSFilter.sys [2009-10-16 30216] R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSShim.sys [2009-10-16 25736] S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2009-10-16 30104] =============== Created Last 30 ================ 2009-11-27 05:29 1,110 ac—— c:\documents and settings\spike\cc_20091127_052940.reg 2009-11-27 05:26 -cd—– c:\docume~1\spike\applic~1\ScanSpyware 2009-11-24 00:03 842 ac—— c:\documents and settings\spike\cc_20091124_000322.reg 2009-11-23 23:19 -cd—– C:\stdtsa 2009-11-23 22:57 -cd—– c:\docume~1\alluse~1\applic~1\NortonInstaller 2009-11-23 03:00 164 ac—— c:\documents and settings\spike\cc_20091123_030031.reg 2009-11-20 22:16 -cd—– c:\docume~1\alluse~1\applic~1\AIM 2009-11-20 22:16 -cd—– c:\program files\AIM 2009-11-20 22:14 -cd—– c:\program files\common files\Software Update Utility 2009-11-18 22:18 -cdshr– C:\SUD 2009-11-18 15:27 19,764 ac—— c:\documents and settings\spike\cc_20091118_152651.reg 2009-11-18 03:41 2,328,832 ac—— c:\windows\system32\TUKernel.exe 2009-11-17 21:04 73,728 ac—— c:\windows\system32\javacpl.cpl 2009-11-17 21:04 411,368 ac—— c:\windows\system32\deploytk.dll 2009-11-17 09:46 29,000 ac—— c:\windows\system32\uxtuneup.dll 2009-11-17 09:46 361,288 ac—— c:\windows\system32\TuneUpDefragService.exe 2009-11-11 23:11 -cd—– c:\program files\VideoLAN 2009-11-11 22:53 -cd—– c:\program files\Yahoo! 2009-11-11 22:29 604,488 ac—— c:\windows\system32\TUProgSt.exe 2009-11-11 22:23 5,370 ac—— c:\documents and settings\spike\cc_20091111_222255.reg 2009-11-10 00:57 1,144 ac—— c:\documents and settings\spike\cc_20091110_005659.reg 2009-11-10 00:56 82 ac—— c:\documents and settings\spike\cc_20091110_005654.reg 2009-11-10 00:28 28,196 ac—— c:\documents and settings\spike\cc_20091110_002846.reg 2009-11-10 00:08 844 ac—— c:\documents and settings\spike\cc_20091110_000823.reg 2009-11-09 14:41 4,960 ac—— c:\documents and settings\spike\cc_20091109_144141.reg 2009-11-09 14:32 4,180 ac—— c:\documents and settings\spike\cc_20091109_143207.reg 2009-11-09 04:21 -cd—– c:\program files\common files\Blizzard Entertainment 2009-11-09 02:27 -cd—– c:\program files\common files\AOL 2009-11-09 02:26 920 ac–h— C:\IPH.PH 2009-11-09 01:58 1,278 ac—— c:\documents and settings\spike\cc_20091109_015801.reg 2009-11-08 02:52 -cd—– C:\Inetpub 2009-11-05 16:06 23,546 ac—— c:\documents and settings\spike\cc_20091105_160558.reg 2009-11-05 15:58 34,109 ac—— c:\windows\system32\nvapps.xml 2009-11-05 15:57 14,757 ac—— c:\windows\system32\nvdisp.nvu 2009-11-05 15:57 176,128 ac—— c:\windows\system32\nvudisp.exe 2009-11-05 15:55 -cd—– C:\NVIDIA 2009-11-05 15:36 107,596 ac—— C:\toolkit_widget.gif 2009-11-04 12:32 616 ac—— c:\documents and settings\spike\cc_20091104_123255.reg 2009-11-03 17:05 4,574 ac—— c:\documents and settings\spike\cc_20091103_170519.reg 2009-10-31 19:12 -cd—– c:\program files\Windows Media Connect 2 2009-10-31 19:02 -cd—– c:\windows\system32\LogFiles 2009-10-30 14:31 6,512 ac—— c:\documents and settings\spike\cc_20091030_153127.reg 2009-10-30 07:06 1,089,593 -c—— c:\windows\system32\dllcache\ntprint.cat 2009-10-29 11:46 -cd—– c:\windows\system32\XPSViewer 2009-10-29 11:41 117,760 -c—— c:\windows\system32\prntvpt.dll 2009-10-29 11:41 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-10-29 11:41 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-10-29 11:41 575,488 -c—— c:\windows\system32\xpsshhdr.dll 2009-10-29 11:41 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll 2009-10-29 11:41 1,676,288 -c—— c:\windows\system32\xpssvcs.dll 2009-10-29 11:41 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll 2009-10-29 11:41 -cd—– C:\43147a0d89a6323a2740f170 ==================== Find3M ==================== 2009-11-10 09:27 360,584 ac—— c:\windows\system32\drivers\avgtdix.sys 2009-11-04 00:22 1,956 ac—— c:\windows\system32\d3d8caps.dat 2009-10-27 22:31 1,278 ac—— c:\documents and settings\spike\cc_20091027_233058.reg 2009-10-26 18:39 6,696 ac—— c:\documents and settings\spike\cc_20091026_193933.reg 2009-10-22 14:14 25,608 ac—— c:\windows\system32\drivers\AVGIDSxx.sys 2009-10-22 14:13 30,104 ac—— c:\windows\system32\drivers\avgfwdx.sys 2009-10-22 14:13 50,968 ac—— c:\windows\system32\avgfwdx.dll 2009-10-22 14:11 161,800 ac—— c:\windows\system32\drivers\avgrkx86.sys 2009-10-22 01:52 86,327 ac—— c:\windows\pchealth\helpctr\offlinecache\index.dat 2009-10-16 15:46 152,904 ac—— c:\windows\system32\vghd.scr 2009-10-16 14:09 3,460 ac—— c:\documents and settings\spike\cc_20091016_150911.reg 2009-10-16 13:53 12,464 ac—— c:\windows\system32\avgrsstx.dll 2009-10-16 13:53 333,192 ac—— c:\windows\system32\drivers\avgldx86.sys 2009-10-15 01:35 21,640 ac—— c:\windows\system32\emptyregdb.dat 2009-09-25 00:37 667,136 ac—— c:\windows\system32\wininet.dll 2009-09-25 00:37 81,920 ac—— c:\windows\system32\ieencode.dll 2009-09-11 09:18 136,192 ac—— c:\windows\system32\msv1_0.dll 2009-09-04 16:03 58,880 ac—— c:\windows\system32\msasn1.dll 2006-08-01 18:55 581,632 ac-shr– c:\windows\system32\plugin.dat 2006-06-20 14:37 1,224,704 ac-shr– c:\windows\system32\winsysdriver.exe ============= FINISH: 6:07:55.24 =============== \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ Thank you guys in advance for any help you can give me, and I'm not shutting my computer off in the meantime, lol. Spike

Attachments:

Hi,

Please do the following:

Download ComboFix from either of these locations:
Link 1
Link 2


VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Hi,

Delete the copy of combofix that you have on your desktop.


Download Combofix from either of the links below but rename it to spike.com before saving it to your desktop.

save it as file type "All Files", save it directly to your desktop.

Link 1
Link 2


——————————————————————–

Double click on the renamed ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.

NOTE: Very Important! - Please disable all your security programs before running ComboFix as they will interfere
After an hour and 15 mins, here it is, lol: ComboFix 09-11-26.02 - Spike 11/27/2009 8:33:08.1.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.207 [GMT -5:00] Running from: C:\Documents and Settings\[removed]\Desktop\Spike.com.exe AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} FW: AVG Firewall *disabled* {8decf618-9569-4340-b34a-d78d28969b66} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\system32\plugin.dat Infected copy of C:\WINDOWS\system32\drivers\ntfs.sys was found and disinfected Restored copy from - C:\WINDOWS\ServicePackFiles\i386\ntfs.sys . ((((((((((((((((((((((((( Files Created from 2009-10-27 to 2009-11-27 ))))))))))))))))))))))))))))))) . 2009-11-27 11:02:37 . 2009-11-27 11:02:48 0 dc—-w- C:\Program Files\ERUNT 2009-11-27 10:29:43 . 2009-11-27 10:29:55 1110 -c–a-w- C:\Documents and Settings\Spike\cc_20091127_052940.reg 2009-11-27 10:26:16 . 2009-11-27 10:28:01 0 dc—-w- C:\Documents and Settings\Spike\Application Data\ScanSpyware 2009-11-24 05:03:23 . 2009-11-24 05:03:30 842 -c–a-w- C:\Documents and Settings\Spike\cc_20091124_000322.reg 2009-11-24 04:19:02 . 2009-11-24 04:19:15 0 dc—-w- C:\stdtsa 2009-11-24 03:57:51 . 2009-11-24 03:57:51 0 dc—-w- C:\Documents and Settings\All Users\Application Data\NortonInstaller 2009-11-23 08:00:36 . 2009-11-23 08:00:38 164 -c–a-w- C:\Documents and Settings\Spike\cc_20091123_030031.reg 2009-11-22 11:32:08 . 2009-11-22 11:32:08 0 dc—-w- C:\Documents and Settings\Spike\Local Settings\Application Data\WMTools Downloaded Files 2009-11-21 03:16:35 . 2009-11-21 03:16:35 0 dc—-w- C:\Documents and Settings\All Users\Application Data\AIM 2009-11-21 03:16:13 . 2009-11-21 03:16:22 0 dc—-w- C:\Program Files\AIM 2009-11-21 03:14:51 . 2009-11-21 03:14:51 0 dc—-w- C:\Program Files\Common Files\Software Update Utility 2009-11-19 03:18:02 . 2009-11-19 03:18:02 0 dc—-r- C:\SUD 2009-11-18 20:27:05 . 2009-11-18 20:27:09 19764 -c–a-w- C:\Documents and Settings\Spike\cc_20091118_152651.reg 2009-11-18 20:11:21 . 2009-11-18 20:11:39 0 dc—-w- C:\Program Files\7-Zip 2009-11-18 08:41:52 . 2009-11-18 08:41:54 2328832 -c–a-w- C:\WINDOWS\system32\TUKernel.exe 2009-11-18 07:55:31 . 2009-11-18 07:55:31 152576 -c–a-w- C:\Documents and Settings\Spike\Application Data\Sun\Java\jre1.6.0_17\lzma.dll 2009-11-18 07:54:34 . 2009-11-18 07:54:35 79488 -c–a-w- C:\Documents and Settings\Spike\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll 2009-11-18 03:55:37 . 2009-11-18 06:56:38 0 dc—-w- C:\Program Files\Common Files\Adobe 2009-11-18 02:07:38 . 2009-11-18 02:07:38 0 dc—-w- C:\WINDOWS\Sun 2009-11-18 02:04:08 . 2009-10-11 09:17:27 411368 -c–a-w- C:\WINDOWS\system32\deploytk.dll 2009-11-18 02:03:07 . 2009-11-18 07:57:38 0 dc—-w- C:\Program Files\Java 2009-11-18 02:02:05 . 2009-11-18 02:02:05 152576 -c–a-w- C:\Documents and Settings\Spike\Application Data\Sun\Java\jre1.6.0_16\lzma.dll 2009-11-17 14:46:19 . 2009-07-15 09:48:20 29000 -c–a-w- C:\WINDOWS\system32\uxtuneup.dll 2009-11-17 14:46:16 . 2009-11-17 14:46:17 361288 -c–a-w- C:\WINDOWS\system32\TuneUpDefragService.exe 2009-11-12 05:41:54 . 2009-11-27 03:06:15 0 dc—-w- C:\Documents and Settings\Spike\Application Data\vlc 2009-11-12 04:11:15 . 2009-11-12 04:11:15 0 dc—-w- C:\Program Files\VideoLAN 2009-11-12 03:54:20 . 2009-05-27 00:50:14 607472 -c–a-w- C:\Documents and Settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe 2009-11-12 03:53:48 . 2009-11-12 03:54:21 0 dc—-w- C:\Program Files\Yahoo! 2009-11-12 03:29:43 . 2009-11-17 14:46:25 604488 -c–a-w- C:\WINDOWS\system32\TUProgSt.exe 2009-11-12 03:23:35 . 2009-11-12 03:23:43 5370 -c–a-w- C:\Documents and Settings\Spike\cc_20091111_222255.reg 2009-11-11 10:10:57 . 2009-11-11 10:10:57 0 dc—-w- C:\Documents and Settings\Spike\Local Settings\Application Data\Identities 2009-11-10 05:57:01 . 2009-11-10 05:57:03 1144 -c–a-w- C:\Documents and Settings\Spike\cc_20091110_005659.reg 2009-11-10 05:56:57 . 2009-11-10 05:56:57 82 -c–a-w- C:\Documents and Settings\Spike\cc_20091110_005654.reg 2009-11-10 05:28:48 . 2009-11-10 05:28:57 28196 -c–a-w- C:\Documents and Settings\Spike\cc_20091110_002846.reg 2009-11-10 05:08:34 . 2009-11-10 05:08:36 844 -c–a-w- C:\Documents and Settings\Spike\cc_20091110_000823.reg 2009-11-09 19:41:45 . 2009-11-09 19:41:51 4960 -c–a-w- C:\Documents and Settings\Spike\cc_20091109_144141.reg 2009-11-09 19:32:10 . 2009-11-09 19:32:15 4180 -c–a-w- C:\Documents and Settings\Spike\cc_20091109_143207.reg 2009-11-09 09:21:36 . 2009-11-10 07:48:32 0 dc—-w- C:\Program Files\Common Files\Blizzard Entertainment 2009-11-09 07:29:01 . 2009-11-09 07:32:26 0 dc—-w- C:\Documents and Settings\Spike\Application Data\acccore 2009-11-09 07:28:50 . 2009-11-21 03:36:19 0 dc—-w- C:\Documents and Settings\Spike\Local Settings\Application Data\AIM 2009-11-09 07:28:45 . 2009-11-09 07:28:45 0 dc—-w- C:\Documents and Settings\Spike\Local Settings\Application Data\AOL 2009-11-09 07:27:02 . 2009-11-21 03:14:44 0 dc—-w- C:\Program Files\Common Files\AOL 2009-11-09 06:58:06 . 2009-11-09 06:58:12 1278 -c–a-w- C:\Documents and Settings\Spike\cc_20091109_015801.reg 2009-11-08 07:52:04 . 2009-11-08 07:53:41 0 dc—-w- C:\Inetpub 2009-11-06 00:22:25 . 2008-04-14 00:12:07 26624 -c–a-w- C:\Documents and Settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll 2009-11-05 22:17:21 . 2009-11-05 22:17:21 0 dc—-w- C:\Documents and Settings\All Users\Application Data\nView_Profiles 2009-11-05 21:06:02 . 2009-11-05 21:06:12 23546 -c–a-w- C:\Documents and Settings\Spike\cc_20091105_160558.reg 2009-11-05 20:57:40 . 2005-08-02 21:35:00 176128 -c–a-w- C:\WINDOWS\system32\nvudisp.exe 2009-11-05 20:55:23 . 2009-11-05 20:55:23 0 dc—-w- C:\NVIDIA 2009-11-05 19:20:38 . 2009-11-05 19:20:45 86016 -c–a-w- C:\Documents and Settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe 2009-11-05 19:19:33 . 2009-11-06 19:03:37 0 dc—-w- C:\Documents and Settings\All Users\Application Data\NOS 2009-11-04 17:32:59 . 2009-11-04 17:33:08 616 -c–a-w- C:\Documents and Settings\Spike\cc_20091104_123255.reg 2009-11-03 22:05:23 . 2009-11-03 22:05:26 4574 -c–a-w- C:\Documents and Settings\Spike\cc_20091103_170519.reg 2009-11-01 00:12:52 . 2009-11-01 00:13:05 0 dc—-w- C:\Program Files\Windows Media Connect 2 2009-11-01 00:02:36 . 2009-11-08 07:56:09 0 dc—-w- C:\WINDOWS\system32\drivers\UMDF 2009-11-01 00:02:35 . 2009-11-01 00:02:35 0 dc—-w- C:\WINDOWS\system32\LogFiles 2009-10-30 19:31:31 . 2009-10-30 19:31:35 6512 -c–a-w- C:\Documents and Settings\Spike\cc_20091030_153127.reg 2009-10-29 16:46:31 . 2009-10-29 16:46:32 0 dc—-w- C:\WINDOWS\system32\XPSViewer 2009-10-29 16:45:25 . 2009-10-29 16:45:25 0 dc—-w- C:\Program Files\MSBuild 2009-10-29 16:44:07 . 2009-10-29 16:44:07 0 dc—-w- C:\Program Files\Reference Assemblies 2009-10-29 16:41:13 . 2008-07-06 12:06:10 89088 -c—-w- C:\WINDOWS\system32\dllcache\filterpipelineprintproc.dll 2009-10-29 16:41:13 . 2008-07-06 12:06:10 117760 -c—-w- C:\WINDOWS\system32\prntvpt.dll 2009-10-29 16:41:12 . 2008-07-06 10:50:03 597504 -c—-w- C:\WINDOWS\system32\dllcache\printfilterpipelinesvc.exe 2009-10-29 16:41:09 . 2008-07-06 12:06:10 575488 -c—-w- C:\WINDOWS\system32\xpsshhdr.dll 2009-10-29 16:41:09 . 2008-07-06 12:06:10 575488 -c—-w- C:\WINDOWS\system32\dllcache\xpsshhdr.dll 2009-10-29 16:41:06 . 2008-07-06 12:06:10 1676288 -c—-w- C:\WINDOWS\system32\xpssvcs.dll 2009-10-29 16:41:06 . 2008-07-06 12:06:10 1676288 -c—-w- C:\WINDOWS\system32\dllcache\xpssvcs.dll 2009-10-29 16:41:00 . 2009-10-29 16:42:29 0 dc—-w- C:\43147a0d89a6323a2740f170 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-11-27 11:19:21 . 2009-10-16 18:57:21 0 -c–a-w- C:\Documents and Settings\Spike\Local Settings\Application Data\prvlcl.dat 2009-11-26 04:33:19 . 2009-10-16 04:52:59 0 dc—-w- C:\Documents and Settings\Spike\Application Data\uTorrent 2009-11-20 14:41:29 . 2009-10-16 04:37:30 13104 -c–a-w- C:\Documents and Settings\Spike\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-11-17 14:46:04 . 2009-10-22 22:25:33 0 dc—-w- C:\Program Files\TuneUp Utilities 2009 2009-11-12 03:24:58 . 2009-10-22 22:20:19 0 dcsh–w- C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357} 2009-11-10 14:27:53 . 2009-10-16 18:53:29 360584 -c–a-w- C:\WINDOWS\system32\drivers\avgtdix.sys 2009-11-10 05:15:25 . 2009-10-16 18:56:47 0 dc—-w- C:\Documents and Settings\Spike\Application Data\DMCache 2009-11-09 19:35:30 . 2009-10-23 18:30:27 0 dc—-w- C:\Documents and Settings\Spike\Application Data\Yahoo! 2009-11-09 19:35:09 . 2009-10-23 18:26:33 0 dc—-w- C:\Documents and Settings\All Users\Application Data\Yahoo! 2009-11-09 19:29:25 . 2009-10-26 23:13:49 0 dc—-w- C:\Program Files\Common Files\InstallShield 2009-11-04 05:22:52 . 2009-10-22 06:23:50 1956 -c–a-w- C:\WINDOWS\system32\d3d8caps.dat 2009-10-28 03:31:09 . 2009-10-28 03:31:02 1278 -c–a-w- C:\Documents and Settings\Spike\cc_20091027_233058.reg 2009-10-26 23:39:46 . 2009-10-26 23:39:39 6696 -c–a-w- C:\Documents and Settings\Spike\cc_20091026_193933.reg 2009-10-26 22:55:36 . 2009-10-26 22:55:36 0 dc—-w- C:\Documents and Settings\All Users\Application Data\UAB 2009-10-26 22:55:07 . 2009-10-26 22:55:07 0 dc—-w- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters 2009-10-22 22:28:07 . 2009-10-22 22:28:07 0 dc—-w- C:\Documents and Settings\Spike\Application Data\TuneUp Software 2009-10-22 22:25:48 . 2009-10-22 22:25:48 0 dc—-w- C:\Documents and Settings\All Users\Application Data\TuneUp Software 2009-10-22 19:14:43 . 2009-10-16 18:53:10 28424 -c–a-w- C:\WINDOWS\system32\drivers\avgmfx86.sys 2009-10-22 19:14:08 . 2009-10-16 18:52:15 25608 -c–a-w- C:\WINDOWS\system32\drivers\AVGIDSxx.sys 2009-10-22 19:13:11 . 2009-10-16 18:51:49 30104 -c–a-w- C:\WINDOWS\system32\drivers\avgfwdx.sys 2009-10-22 19:13:10 . 2009-10-16 18:51:49 50968 -c–a-w- C:\WINDOWS\system32\avgfwdx.dll 2009-10-22 19:11:35 . 2009-10-16 18:52:13 161800 -c–a-w- C:\WINDOWS\system32\drivers\avgrkx86.sys 2009-10-22 06:52:33 . 2009-10-15 06:46:38 86327 -c–a-w- C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat 2009-10-21 05:37:21 . 2009-10-16 20:48:39 7 -c–a-w- C:\WINDOWS\sbacknt.bin 2009-10-20 07:08:00 . 2009-10-20 07:06:57 0 dc–a-w- C:\Documents and Settings\All Users\Application Data\TEMP 2009-10-16 20:46:59 . 2009-10-16 20:46:59 152904 -c–a-w- C:\WINDOWS\system32\vghd.scr 2009-10-16 19:09:38 . 2009-10-16 19:09:29 3460 -c–a-w- C:\Documents and Settings\Spike\cc_20091016_150911.reg 2009-10-16 18:53:29 . 2009-10-16 18:53:29 12464 -c–a-w- C:\WINDOWS\system32\avgrsstx.dll 2009-10-16 18:53:11 . 2009-10-16 18:53:11 333192 -c–a-w- C:\WINDOWS\system32\drivers\avgldx86.sys 2009-10-16 18:52:45 . 2009-10-16 18:52:45 0 dc—-w- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar 2009-10-16 18:51:47 . 2009-10-16 18:51:47 0 dc—-w- C:\Program Files\AVG 2009-10-16 18:51:40 . 2009-10-16 18:51:31 0 dc—-w- C:\Documents and Settings\All Users\Application Data\avg9 2009-10-16 18:06:11 . 2009-10-16 18:06:08 0 dc—-w- C:\Program Files\CCleaner 2009-10-15 07:23:29 . 2009-10-15 07:23:29 0 -c–a-w- C:\WINDOWS\nsreg.dat 2009-10-15 06:50:56 . 2009-10-15 06:50:56 0 dc—-w- C:\Program Files\microsoft frontpage 2009-10-15 06:35:56 . 2009-10-15 06:35:56 21640 -c–a-w- C:\WINDOWS\system32\emptyregdb.dat 2009-09-25 05:37:11 . 2004-08-04 12:00:00 667136 -c–a-w- C:\WINDOWS\system32\wininet.dll 2009-09-25 05:37:09 . 2004-08-04 12:00:00 81920 -c–a-w- C:\WINDOWS\system32\ieencode.dll 2009-09-11 14:18:39 . 2004-08-04 12:00:00 136192 -c–a-w- C:\WINDOWS\system32\msv1_0.dll 2009-09-04 21:03:36 . 2004-08-04 12:00:00 58880 -c–a-w- C:\WINDOWS\system32\msasn1.dll 2006-06-20 19:37:46 . 2006-06-20 19:37:46 1224704 -csha-r- C:\WINDOWS\system32\winsysdriver.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-09-18 16:28:04 1115392] [HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}] 2009-09-18 16:28:04 1115392 -c–a-w- C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-09-18 16:28:04 1115392] [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}] [HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run] "Microsoft Windows Operating System"="C:\WINDOWS\system32\winsysdriver.exe" [2006-06-20 19:37:46 1224704] [HKEY_CURRENT_USER\software\microsoft\windows\Currentversion\policies\explorer\Run] "Microsoft Windows Operating System"="C:\WINDOWS\system32\winsysdriver.exe" [2006-06-20 19:37:46 1224704] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-10-16 18:53:29 12464 -c–a-w- C:\WINDOWS\system32\avgrsstx.dll [HKLM\~\startupfolder\C:^Documents and Settings^Spike^Start Menu^Programs^Startup^DesktopVideoPlayer.LNK] path=C:\Documents and Settings\Spike\Start Menu\Programs\Startup\DesktopVideoPlayer.LNK backup=C:\WINDOWS\pss\DesktopVideoPlayer.LNKStartup [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\AVG\\AVG9\\avgam.exe"= "C:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"= "C:\\Program Files\\AVG\\AVG9\\avgemc.exe"= "C:\\Program Files\\AVG\\AVG9\\avgupd.exe"= "C:\\Program Files\\AVG\\AVG9\\avgnsx.exe"= "C:\\Documents and Settings\\Spike\\My Documents\\Downloads\\Programs\\utorrent.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "C:\\Program Files\\AIM\\aim.exe"= R0 AVGIDSErHrxpx;AVG9IDSErHr;C:\WINDOWS\system32\drivers\AVGIDSxx.sys [10/16/2009 1:52:15 PM 25608] R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\drivers\avgrkx86.sys [10/16/2009 1:52:13 PM 161800] R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\drivers\avgldx86.sys [10/16/2009 1:53:11 PM 333192] R1 AvgTdiX;AVG Network Redirector;C:\WINDOWS\system32\drivers\avgtdix.sys [10/16/2009 1:53:29 PM 360584] R2 avg9emc;AVG E-mail Scanner;C:\Program Files\AVG\AVG9\avgemc.exe [10/16/2009 1:52:16 PM 906520] R2 avg9wd;AVG WatchDog;C:\Program Files\AVG\AVG9\avgwdsvc.exe [10/16/2009 1:52:10 PM 285392] R2 avgfws9;AVG Firewall;C:\Program Files\AVG\AVG9\avgfws9.exe [10/22/2009 2:12:37 PM 2304192] R2 AVGIDSAgent;AVG9IDSAgent;C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [10/22/2009 2:13:51 PM 5832712] R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;C:\WINDOWS\system32\TUProgSt.exe [11/11/2009 10:29:43 PM 604488] R3 Avgfwdx;Avgfwdx;C:\WINDOWS\system32\drivers\avgfwdx.sys [10/16/2009 1:51:49 PM 30104] R3 AVGIDSDriverxpx;AVG9IDSDriver;C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [10/16/2009 1:52:08 PM 122376] R3 AVGIDSFilterxpx;AVG9IDSFilter;C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [10/16/2009 1:52:08 PM 30216] R3 AVGIDSShimxpx;AVG9IDSShim;C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [10/16/2009 1:52:07 PM 25736] S3 Avgfwfd;AVG network filter service;C:\WINDOWS\system32\drivers\avgfwdx.sys [10/16/2009 1:51:49 PM 30104] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{P633N151-5PA5-0KT2-UO4I-7K1545M7N101}] C:\WINDOWS\system32\winsysdriver.exe Restart . Contents of the 'Scheduled Tasks' folder 2009-11-27 C:\WINDOWS\Tasks\1-Click Maintenance.job - C:\Program Files\TuneUp Utilities 2009\OneClickStarter.exe [2009-07-16 08:54:44 . 2009-07-16 08:54:44] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.yahoo.com/ mStart Page = hxxp://www.yahoo.com/ mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com FF - ProfilePath - C:\Documents and Settings\Spike\Application Data\Mozilla\Firefox\Profiles\wvl2fd3k.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p= FF - prefs.js: browser.search.selectedEngine - Yahoo! Search FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p= FF - component: C:\Program Files\AVG\AVG9\Firefox\components\avgssff.dll FF - component: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll FF - component: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll FF - component: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll FF - component: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ —- FIREFOX POLICIES —- FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: nglayout.initialpaint.delay - 600 FF - user.js: content.notify.interval - 600000 FF - user.js: content.max.tokenizing.time - 1800000 FF - user.js: content.switch.threshold - 600000 FF - user.js: yahoo.homepage.dontask - true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, falseC:\Program Files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); . - - - - ORPHANS REMOVED - - - - WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) AddRemove-NVIDIA Drivers - C:\WINDOWS\system32\nvudisp.exe UninstallGUI
hi,

There are some entries that I would like to investigate further:

please do the following:

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


    • C:\WINDOWS\system32\winsysdriver.exe
  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.
Please follow the same procedure for the following files:

C:\WINDOWS\system32\vghd.scr
C:\Documents and Settings\Spike\Local Settings\Application Data\prvlcl.dat



NEXT


Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :dir
    C:\SUD /s
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Here's the virscan results:

VirSCAN.org Scanned Report :
Scanned time : 2009/11/27 11:26:59 (EST)
Scanner results: 3% Scanner(s) (1/37) found malware!
File Name : winsysdriver.exe
File Size : 1224704 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 4212a9a2085285bc1a95a3fa9633c0be
SHA1 : 66800fe5b8eb347bc2b8cca3641c6d387fddb0d0
Online report : http://virscan.org/report/7551cfb7792d3f26…0a60f4b7e5.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20091127233522 2009-11-27 4.80 -
AhnLab V3 2009.11.27.01 2009.11.27 2009-11-27 1.20 -
AntiVir 8.2.1.78 7.10.1.115 2009-11-27 0.27 -
Antiy 2.0.18 20091127.3320938 2009-11-27 0.12 -
Arcavir 2009 200911270011 2009-11-27 0.07 -
Authentium 5.1.1 200911261932 2009-11-26 1.74 -
AVAST! 4.7.4 091127-1 2009-11-27 0.05 -
AVG 8.5.288 270.14.84/2530 2009-11-27 0.47 -
BitDefender 7.81008.4648844 7.29165 2009-11-27 4.54 -
CA (VET) 35.1.0 7143 2009-11-25 15.70 -
ClamAV 0.95.2 10087 2009-11-27 0.18 -
Comodo 3.12 3057 2009-11-27 2.74 -
CP Secure 1.3.0.5 2009.11.27 2009-11-27 0.38 -
Dr.Web 4.44.0.9170 2009.11.27 2009-11-27 7.25 -
F-Prot 4.4.4.56 20091126 2009-11-26 1.67 -
F-Secure 7.02.73807 2009.11.27.03 2009-11-27 0.18 -
Fortinet 11.101- 11.101 2009-11-27 0.19 -
GData 19.9031/19.591 20091127 2009-11-27 10.01 -
ViRobot 20091127 2009.11.27 2009-11-27 1.24 -
Ikarus T3.1.01.74 2009.11.27.74605 2009-11-27 4.20 -
JiangMin 11.0.800 2009.11.27 2009-11-27 28.31 -
Kaspersky 5.5.10 2009.11.27 2009-11-27 0.11 -
KingSoft 2009.2.5.15 2009.11.27.19 2009-11-27 0.93 -
McAfee 5.3.00 5814 2009-11-26 3.42 -
Microsoft 1.5302 2009.11.27 2009-11-27 11.07 -
Norman 6.01.09 6.01.00 2009-11-27 4.00 -
Panda 9.05.01 2009.11.27 2009-11-27 6.34 -
Trend Micro 9.000-1003 6.656.04 2009-11-27 0.04 -
Quick Heal 10.00 2009.11.27 2009-11-27 1.73 -
Rising 20.0 22.23.04.09 2009-11-27 0.69 -
Sophos 3.01.0 4.47 2009-11-27 3.27 Mal/VBInject-D
Sunbelt 5518 5518 2009-11-18 5.11 -
Symantec 1.3.0.24 20091126.016 2009-11-26 0.31 -
nProtect 20091127.01 6385650 2009-11-27 6.27 -
The Hacker 6.5.0.2 v00079 2009-11-26 1.19 -
VBA32 3.12.12.0 20091127.0941 2009-11-27 2.45 -
VirusBuster 4.5.11.10 10.114.1/2014172 2009-11-27 2.79 -

VirSCAN.org Scanned Report :
Scanned time : 2009/11/27 11:31:39 (EST)
Scanner results: Scanners did not find malware!
File Name : vghd.scr
File Size : 152904 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : c357e9f9799a9ba3c74f1468df12b755
SHA1 : 0a5ce308e61bce38f1bf5207e3eeaa730b923deb
Online report : http://virscan.org/report/d26d8201f5e64900…fa64e07db5.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20091127233522 2009-11-27 4.02 -
AhnLab V3 2009.11.27.01 2009.11.27 2009-11-27 0.93 -
AntiVir 8.2.1.78 7.10.1.115 2009-11-27 0.06 -
Antiy 2.0.18 20091127.3320938 2009-11-27 0.12 -
Arcavir 2009 200911270011 2009-11-27 0.06 -
Authentium 5.1.1 200911261932 2009-11-26 1.32 -
AVAST! 4.7.4 091127-1 2009-11-27 0.01 -
AVG 8.5.288 270.14.84/2530 2009-11-27 0.34 -
BitDefender 7.81008.4648844 7.29165 2009-11-27 4.00 -
CA (VET) 35.1.0 7143 2009-11-25 9.72 -
ClamAV 0.95.2 10087 2009-11-27 0.03 -
Comodo 3.12 3057 2009-11-27 0.73 -
CP Secure 1.3.0.5 2009.11.27 2009-11-27 0.07 -
Dr.Web 4.44.0.9170 2009.11.27 2009-11-27 7.31 -
F-Prot 4.4.4.56 20091126 2009-11-26 1.34 -
F-Secure 7.02.73807 2009.11.27.03 2009-11-27 0.16 -
Fortinet 11.101- 11.101 2009-11-27 0.14 -
GData 19.9031/19.591 20091127 2009-11-27 7.58 -
ViRobot 20091127 2009.11.27 2009-11-27 0.90 -
Ikarus T3.1.01.74 2009.11.27.74605 2009-11-27 4.12 -
JiangMin 11.0.800 2009.11.27 2009-11-27 5.54 -
Kaspersky 5.5.10 2009.11.27 2009-11-27 0.11 -
KingSoft 2009.2.5.15 2009.11.27.19 2009-11-27 0.52 -
McAfee 5.3.00 5814 2009-11-26 3.42 -
Microsoft 1.5302 2009.11.27 2009-11-27 7.07 -
Norman 6.01.09 6.01.00 2009-11-27 4.01 -
Panda 9.05.01 2009.11.27 2009-11-27 1.96 -
Trend Micro 9.000-1003 6.656.04 2009-11-27 0.04 -
Quick Heal 10.00 2009.11.27 2009-11-27 1.32 -
Rising 20.0 22.23.04.09 2009-11-27 1.44 -
Sophos 3.01.0 4.47 2009-11-27 3.07 -
Sunbelt 5518 5518 2009-11-18 1.74 -
Symantec 1.3.0.24 20091126.016 2009-11-26 0.06 -
nProtect 20091127.01 6385650 2009-11-27 3.93 -
The Hacker 6.5.0.2 v00079 2009-11-26 0.83 -
VBA32 3.12.12.0 20091127.0941 2009-11-27 2.37 -
VirusBuster 4.5.11.10 10.114.1/2014172 2009-11-27 2.51 -

It won't let me upload this file: C:\Documents and Settings\Spike\Local Settings\Application Data\prvlcl.dat

And here's the Look result: SystemLook v1.0 by jpshortstuff (29.08.09)
Log created at 11:52 on 27/11/2009 by Spike (Administrator - Elevation successful)

========== dir ==========

C:\SUD - Parameters: "/s"

—Files—
None found.

C:\SUD\SSOW dr-hsc [03:18 19/11/2009]
DesKTop.ini –ahsc 62 bytes [03:18 19/11/2009] [13:33 27/11/2009]
sep.exe –a–c 91136 bytes [03:18 19/11/2009] [03:57 12/11/2009]

-=End Of File=-
OK

Lets have a look at those:

please do the following:

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


    • C:\SUD\SSOW \sep.exe
  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.
Please follow the same procedure for the following file:

C:\SUD\SSOW \DesKTop.ini
Hi,

I think I may have put an extra space in there by mistake when i was copying those entries:

try these paths:

C:\SUD\SSOW\DesKTop.ini
C:\SUD\SSOW\sep.exe


If still no luck…manually navigate to that folder and make sure those files are present, right click them and tell me what the properties are.


Then try this scanner instead:

Please go to Virus Total
  • Copy paste the following full path into the empty box under 'Upload a file'

    C:\SUD\SSOW\sep.exe

  • Click 'Send File'
Copy/paste the results into Notepad and save it to your desktop. Please post the results in your next reply.
It was the space, lol. I'm surprised I didn't catch that.

Here:s the results:

VirSCAN.org Scanned Report :
Scanned time : 2009/11/27 12:32:47 (EST)
Scanner results: 43% Scanner(s) (16/37) found malware!
File Name : sep.exe
File Size : 91136 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 1b4457fdee4805295c46232e264a5613
SHA1 : 8bfae98409f63bbd10953375ba380e57de699577
Online report : http://virscan.org/report/e6a8e7df25d23be8…e524badd1a.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20091127233522 2009-11-27 9.52 Trojan.Win32.Buzus!IK
AhnLab V3 2009.11.27.01 2009.11.27 2009-11-27 1.16 -
AntiVir 8.2.1.78 7.10.1.117 2009-11-27 0.43 TR/Buzus.cnjm
Antiy 2.0.18 20091127.3320938 2009-11-27 0.12 Trojan/Win32.Buzus.cnjm
Arcavir 2009 200911271246 2009-11-27 0.08 Trojan.Buzus.Cnjm
Authentium 5.1.1 200911261932 2009-11-26 1.32 -
AVAST! 4.7.4 091127-1 2009-11-27 0.01 -
AVG 8.5.288 270.14.84/2530 2009-11-27 0.51 -
BitDefender 7.81008.4648870 7.29166 2009-11-28 4.92 Backdoor.Hamweq.B
CA (VET) 35.1.0 7143 2009-11-25 10.41 -
ClamAV 0.95.2 10088 2009-11-27 0.03 -
Comodo 3.12 3057 2009-11-27 0.79 TrojWare.Win32.Buzus.cnjm
CP Secure 1.3.0.5 2009.11.27 2009-11-27 0.06 Troj.W32.Buzus.cnjm
Dr.Web 4.44.0.9170 2009.11.27 2009-11-27 7.24 -
F-Prot 4.4.4.56 20091126 2009-11-26 1.29 -
F-Secure 7.02.73807 2009.11.27.03 2009-11-27 9.18 Trojan.Win32.Buzus.cnjm [AVP]
Fortinet 11.101- 11.101 2009-11-27 0.23 -
GData 19.9032/19.591 20091127 2009-11-27 6.90 Trojan.Win32.Buzus.cnjm [Engine:A]
ViRobot 20091127 2009.11.27 2009-11-27 0.42 -
Ikarus T3.1.01.74 2009.11.27.74606 2009-11-27 4.13 Trojan.Win32.Buzus
JiangMin 11.0.800 2009.11.27 2009-11-27 4.71 Trojan/Buzus.uel
Kaspersky 5.5.10 2009.11.27 2009-11-27 0.06 Trojan.Win32.Buzus.cnjm
KingSoft 2009.2.5.15 2009.11.27.19 2009-11-27 0.56 Win32.Troj.Buzus.91136
McAfee 5.3.00 5815 2009-11-27 3.41 -
Microsoft 1.5302 2009.11.27 2009-11-27 9.10 -
Norman 6.01.09 6.01.00 2009-11-27 4.01 -
Panda 9.05.01 2009.11.27 2009-11-27 2.07 -
Trend Micro 9.000-1003 6.656.04 2009-11-27 0.04 -
Quick Heal 10.00 2009.11.27 2009-11-27 1.26 -
Rising 20.0 22.23.04.09 2009-11-27 1.01 -
Sophos 3.01.0 4.47 2009-11-28 3.33 Mal/Generic-A
Sunbelt 5518 5518 2009-11-18 1.93 -
Symantec 1.3.0.24 20091127.003 2009-11-27 0.05 -
nProtect 20091127.01 6385650 2009-11-27 4.73 Trojan/W32.Buzus.91136.T
The Hacker 6.5.0.2 v00079 2009-11-26 0.77 -
VBA32 3.12.12.0 20091127.0941 2009-11-27 2.29 -
VirusBuster 4.5.11.10 10.114.2/2016093 2009-11-28 2.39 Trojan.Buzus.ARRY


VirSCAN.org Scanned Report :
Scanned time : 2009/11/27 12:37:03 (EST)
Scanner results: 3% Scanner(s) (1/37) found malware!
File Name : DesKTop.ini
File Size : 62 byte
File Type : ASCII text
MD5 : 7457a5df1ff47c957acf1fa000d7d9ad
SHA1 : 69d2bba827fd4de0169419a0fda280252b348514
Online report : http://virscan.org/report/56bf13d5eb145a80…a07a169332.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.8 20091127233522 2009-11-27 5.43 -
AhnLab V3 2009.11.27.01 2009.11.27 2009-11-27 1.48 -
AntiVir 8.2.1.78 7.10.1.117 2009-11-27 0.28 -
Antiy 2.0.18 20091127.3320938 2009-11-27 0.12 -
Arcavir 2009 200911271246 2009-11-27 0.02 -
Authentium 5.1.1 200911261932 2009-11-26 1.22 -
AVAST! 4.7.4 091127-1 2009-11-27 0.00 -
AVG 8.5.288 270.14.84/2530 2009-11-27 0.30 -
BitDefender 7.81008.4648870 7.29166 2009-11-28 4.01 -
CA (VET) 35.1.0 7143 2009-11-25 12.69 -
ClamAV 0.95.2 10088 2009-11-27 0.00 -
Comodo 3.12 3057 2009-11-27 1.22 -
CP Secure 1.3.0.5 2009.11.28 2009-11-28 0.00 -
Dr.Web 4.44.0.9170 2009.11.27 2009-11-27 7.20 -
F-Prot 4.4.4.56 20091126 2009-11-26 1.21 -
F-Secure 7.02.73807 2009.11.27.03 2009-11-27 0.07 -
Fortinet 11.101- 11.101 2009-11-27 1.60 -
GData 19.9032/19.591 20091127 2009-11-27 8.62 -
ViRobot 20091127 2009.11.27 2009-11-27 0.58 -
Ikarus T3.1.01.74 2009.11.27.74606 2009-11-27 4.10 -
JiangMin 11.0.800 2009.11.27 2009-11-27 13.46 -
Kaspersky 5.5.10 2009.11.27 2009-11-27 0.03 -
KingSoft 2009.2.5.15 2009.11.27.19 2009-11-27 1.38 -
McAfee 5.3.00 5815 2009-11-27 3.39 -
Microsoft 1.5302 2009.11.27 2009-11-27 7.15 -
Norman 6.01.09 6.01.00 2009-11-27 4.00 -
Panda 9.05.01 2009.11.27 2009-11-27 4.36 W32/AutoRun.APJ.worm
Trend Micro 9.000-1003 6.656.04 2009-11-27 0.02 -
Quick Heal 10.00 2009.11.27 2009-11-27 1.45 -
Rising 20.0 22.23.04.09 2009-11-27 0.34 -
Sophos 3.01.0 4.47 2009-11-28 3.05 -
Sunbelt 5518 5518 2009-11-18 1.76 -
Symantec 1.3.0.24 20091127.003 2009-11-27 0.21 -
nProtect 20091127.01 6385650 2009-11-27 3.63 -
The Hacker 6.5.0.2 v00079 2009-11-26 0.69 -
VBA32 3.12.12.0 20091127.0941 2009-11-27 2.14 -
VirusBuster 4.5.11.10 10.114.2/2016093 2009-11-28 2.38 -

It was the space, lol. I'm surprised I didn't catch that

No more than me :blush:


OK

Let's look after those files:

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/C_SUDSSOWsep_exe_t108530.html

Collect::
C:\SUD\SSOW\DesKTop.ini
C:\SUD\SSOW\sep.exe

Folder::
C:\SUD
Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]

  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

NEXT

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so.

NEXT


Using Internet Explorer or Firefox, visit Kaspersky Online Scanner:
1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.
    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Here's the next combofix log:

ComboFix 09-11-26.02 - Spike 11/27/2009 13:18.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.145 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Spike.com.exe
Command switches used :: c:\documents and settings\Spike\Desktop\CFScript.txt
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *disabled* {8decf618-9569-4340-b34a-d78d28969b66}

file zipped: c:\sud\SSOW\DesKTop.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\SUD
c:\sud\SSOW\DesKTop.ini
c:\sud\SSOW\sep.exe
.
—- Previous Run ——-
.
c:\windows\system32\plugin.dat

– Previous Run –

Infected copy of c:\windows\system32\drivers\ntfs.sys was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\ntfs.sys

——–

Infected copy of c:\windows\system32\drivers\ntfs.sys was found and disinfected
Restored copy from - c:\windows\ERDNT\cache\ntfs.sys

.
((((((((((((((((((((((((( Files Created from 2009-10-27 to 2009-11-27 )))))))))))))))))))))))))))))))
.

2009-11-27 18:47 . 2009-11-27 18:47 581632 -c–a-w- c:\windows\system32\plugin.dat
2009-11-27 16:41 . 2009-09-18 16:28 1115392 -c–a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-11-27 14:14 . 2009-11-27 14:14 ——– dc-h–w- c:\windows\PIF
2009-11-27 11:02 . 2009-11-27 11:02 ——– dc—-w- c:\program files\ERUNT
2009-11-27 10:29 . 2009-11-27 10:29 1110 -c–a-w- c:\documents and settings\Spike\cc_20091127_052940.reg
2009-11-27 10:26 . 2009-11-27 10:28 ——– dc—-w- c:\documents and settings\Spike\Application Data\ScanSpyware
2009-11-24 05:03 . 2009-11-24 05:03 842 -c–a-w- c:\documents and settings\Spike\cc_20091124_000322.reg
2009-11-24 04:19 . 2009-11-24 04:19 ——– dc—-w- C:\stdtsa
2009-11-24 03:57 . 2009-11-24 03:57 ——– dc—-w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-11-23 08:00 . 2009-11-23 08:00 164 -c–a-w- c:\documents and settings\Spike\cc_20091123_030031.reg
2009-11-22 11:32 . 2009-11-22 11:32 ——– dc—-w- c:\documents and settings\Spike\Local Settings\Application Data\WMTools Downloaded Files
2009-11-21 03:16 . 2009-11-21 03:16 ——– dc—-w- c:\documents and settings\All Users\Application Data\AIM
2009-11-21 03:16 . 2009-11-21 03:16 ——– dc—-w- c:\program files\AIM
2009-11-21 03:14 . 2009-11-21 03:14 ——– dc—-w- c:\program files\Common Files\Software Update Utility
2009-11-18 20:27 . 2009-11-18 20:27 19764 -c–a-w- c:\documents and settings\Spike\cc_20091118_152651.reg
2009-11-18 20:11 . 2009-11-18 20:11 ——– dc—-w- c:\program files\7-Zip
2009-11-18 08:41 . 2009-11-18 08:41 2328832 -c–a-w- c:\windows\system32\TUKernel.exe
2009-11-18 07:55 . 2009-11-18 07:55 152576 -c–a-w- c:\documents and settings\Spike\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-18 07:54 . 2009-11-18 07:54 79488 -c–a-w- c:\documents and settings\Spike\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-18 03:55 . 2009-11-18 06:56 ——– dc—-w- c:\program files\Common Files\Adobe
2009-11-18 02:07 . 2009-11-18 02:07 ——– dc—-w- c:\windows\Sun
2009-11-18 02:04 . 2009-10-11 09:17 411368 -c–a-w- c:\windows\system32\deploytk.dll
2009-11-18 02:03 . 2009-11-18 07:57 ——– dc—-w- c:\program files\Java
2009-11-18 02:02 . 2009-11-18 02:02 152576 -c–a-w- c:\documents and settings\Spike\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2009-11-17 14:46 . 2009-07-15 09:48 29000 -c–a-w- c:\windows\system32\uxtuneup.dll
2009-11-17 14:46 . 2009-11-17 14:46 361288 -c–a-w- c:\windows\system32\TuneUpDefragService.exe
2009-11-12 05:41 . 2009-11-27 16:32 ——– dc—-w- c:\documents and settings\Spike\Application Data\vlc
2009-11-12 04:11 . 2009-11-12 04:11 ——– dc—-w- c:\program files\VideoLAN
2009-11-12 03:54 . 2009-05-27 00:50 607472 -c–a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe
2009-11-12 03:53 . 2009-11-12 03:54 ——– dc—-w- c:\program files\Yahoo!
2009-11-12 03:29 . 2009-11-17 14:46 604488 -c–a-w- c:\windows\system32\TUProgSt.exe
2009-11-12 03:23 . 2009-11-12 03:23 5370 -c–a-w- c:\documents and settings\Spike\cc_20091111_222255.reg
2009-11-11 10:10 . 2009-11-11 10:10 ——– dc—-w- c:\documents and settings\Spike\Local Settings\Application Data\Identities
2009-11-10 05:57 . 2009-11-10 05:57 1144 -c–a-w- c:\documents and settings\Spike\cc_20091110_005659.reg
2009-11-10 05:56 . 2009-11-10 05:56 82 -c–a-w- c:\documents and settings\Spike\cc_20091110_005654.reg
2009-11-10 05:28 . 2009-11-10 05:28 28196 -c–a-w- c:\documents and settings\Spike\cc_20091110_002846.reg
2009-11-10 05:08 . 2009-11-10 05:08 844 -c–a-w- c:\documents and settings\Spike\cc_20091110_000823.reg
2009-11-09 19:41 . 2009-11-09 19:41 4960 -c–a-w- c:\documents and settings\Spike\cc_20091109_144141.reg
2009-11-09 19:32 . 2009-11-09 19:32 4180 -c–a-w- c:\documents and settings\Spike\cc_20091109_143207.reg
2009-11-09 09:21 . 2009-11-10 07:48 ——– dc—-w- c:\program files\Common Files\Blizzard Entertainment
2009-11-09 07:29 . 2009-11-09 07:32 ——– dc—-w- c:\documents and settings\Spike\Application Data\acccore
2009-11-09 07:28 . 2009-11-21 03:36 ——– dc—-w- c:\documents and settings\Spike\Local Settings\Application Data\AIM
2009-11-09 07:28 . 2009-11-09 07:28 ——– dc—-w- c:\documents and settings\Spike\Local Settings\Application Data\AOL
2009-11-09 07:27 . 2009-11-21 03:14 ——– dc—-w- c:\program files\Common Files\AOL
2009-11-09 06:58 . 2009-11-09 06:58 1278 -c–a-w- c:\documents and settings\Spike\cc_20091109_015801.reg
2009-11-08 07:52 . 2009-11-08 07:53 ——– dc—-w- C:\Inetpub
2009-11-06 00:22 . 2008-04-14 00:12 26624 -c–a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-11-05 22:17 . 2009-11-05 22:17 ——– dc—-w- c:\documents and settings\All Users\Application Data\nView_Profiles
2009-11-05 21:06 . 2009-11-05 21:06 23546 -c–a-w- c:\documents and settings\Spike\cc_20091105_160558.reg
2009-11-05 20:57 . 2005-08-02 21:35 176128 -c–a-w- c:\windows\system32\nvudisp.exe
2009-11-05 20:55 . 2009-11-05 20:55 ——– dc—-w- C:\NVIDIA
2009-11-05 19:20 . 2009-11-05 19:20 86016 -c–a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-11-05 19:19 . 2009-11-06 19:03 ——– dc—-w- c:\documents and settings\All Users\Application Data\NOS
2009-11-04 17:32 . 2009-11-04 17:33 616 -c–a-w- c:\documents and settings\Spike\cc_20091104_123255.reg
2009-11-03 22:05 . 2009-11-03 22:05 4574 -c–a-w- c:\documents and settings\Spike\cc_20091103_170519.reg
2009-11-01 00:12 . 2009-11-01 00:13 ——– dc—-w- c:\program files\Windows Media Connect 2
2009-11-01 00:02 . 2009-11-08 07:56 ——– dc—-w- c:\windows\system32\drivers\UMDF
2009-11-01 00:02 . 2009-11-01 00:02 ——– dc—-w- c:\windows\system32\LogFiles
2009-10-30 19:31 . 2009-10-30 19:31 6512 -c–a-w- c:\documents and settings\Spike\cc_20091030_153127.reg
2009-10-29 16:46 . 2009-10-29 16:46 ——– dc—-w- c:\windows\system32\XPSViewer
2009-10-29 16:45 . 2009-10-29 16:45 ——– dc—-w- c:\program files\MSBuild
2009-10-29 16:44 . 2009-10-29 16:44 ——– dc—-w- c:\program files\Reference Assemblies
2009-10-29 16:41 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-10-29 16:41 . 2008-07-06 12:06 117760 -c—-w- c:\windows\system32\prntvpt.dll
2009-10-29 16:41 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-10-29 16:41 . 2008-07-06 12:06 575488 -c—-w- c:\windows\system32\xpsshhdr.dll
2009-10-29 16:41 . 2008-07-06 12:06 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-10-29 16:41 . 2008-07-06 12:06 1676288 -c—-w- c:\windows\system32\xpssvcs.dll
2009-10-29 16:41 . 2008-07-06 12:06 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2009-10-29 16:41 . 2009-10-29 16:42 ——– dc—-w- C:\43147a0d89a6323a2740f170

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-27 16:41 . 2009-10-16 18:52 ——– dc—-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-11-27 11:19 . 2009-10-16 18:57 0 -c–a-w- c:\documents and settings\Spike\Local Settings\Application Data\prvlcl.dat
2009-11-26 04:33 . 2009-10-16 04:52 ——– dc—-w- c:\documents and settings\Spike\Application Data\uTorrent
2009-11-20 14:41 . 2009-10-16 04:37 13104 -c–a-w- c:\documents and settings\Spike\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-17 14:46 . 2009-10-22 22:25 ——– dc—-w- c:\program files\TuneUp Utilities 2009
2009-11-12 03:24 . 2009-10-22 22:20 ——– dcsh–w- c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-11-10 14:27 . 2009-10-16 18:53 360584 -c–a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-10 05:15 . 2009-10-16 18:56 ——– dc—-w- c:\documents and settings\Spike\Application Data\DMCache
2009-11-09 19:35 . 2009-10-23 18:30 ——– dc—-w- c:\documents and settings\Spike\Application Data\Yahoo!
2009-11-09 19:35 . 2009-10-23 18:26 ——– dc—-w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-11-09 19:29 . 2009-10-26 23:13 ——– dc—-w- c:\program files\Common Files\InstallShield
2009-11-04 05:22 . 2009-10-22 06:23 1956 -c–a-w- c:\windows\system32\d3d8caps.dat
2009-10-28 03:31 . 2009-10-28 03:31 1278 -c–a-w- c:\documents and settings\Spike\cc_20091027_233058.reg
2009-10-26 23:39 . 2009-10-26 23:39 6696 -c–a-w- c:\documents and settings\Spike\cc_20091026_193933.reg
2009-10-26 22:55 . 2009-10-26 22:55 ——– dc—-w- c:\documents and settings\All Users\Application Data\UAB
2009-10-26 22:55 . 2009-10-26 22:55 ——– dc—-w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2009-10-22 22:28 . 2009-10-22 22:28 ——– dc—-w- c:\documents and settings\Spike\Application Data\TuneUp Software
2009-10-22 22:25 . 2009-10-22 22:25 ——– dc—-w- c:\documents and settings\All Users\Application Data\TuneUp Software
2009-10-22 19:14 . 2009-10-16 18:53 28424 -c–a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-10-22 19:14 . 2009-10-16 18:52 25608 -c–a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2009-10-22 19:13 . 2009-10-16 18:51 30104 -c–a-w- c:\windows\system32\drivers\avgfwdx.sys
2009-10-22 19:13 . 2009-10-16 18:51 50968 -c–a-w- c:\windows\system32\avgfwdx.dll
2009-10-22 19:11 . 2009-10-16 18:52 161800 -c–a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-10-22 06:52 . 2009-10-15 06:46 86327 -c–a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-10-21 05:37 . 2009-10-16 20:48 7 -c–a-w- c:\windows\sbacknt.bin
2009-10-20 07:08 . 2009-10-20 07:06 ——– dc–a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-16 20:46 . 2009-10-16 20:46 152904 -c–a-w- c:\windows\system32\vghd.scr
2009-10-16 19:09 . 2009-10-16 19:09 3460 -c–a-w- c:\documents and settings\Spike\cc_20091016_150911.reg
2009-10-16 18:53 . 2009-10-16 18:53 12464 -c–a-w- c:\windows\system32\avgrsstx.dll
2009-10-16 18:53 . 2009-10-16 18:53 333192 -c–a-w- c:\windows\system32\drivers\avgldx86.sys
2009-10-16 18:51 . 2009-10-16 18:51 ——– dc—-w- c:\program files\AVG
2009-10-16 18:51 . 2009-10-16 18:51 ——– dc—-w- c:\documents and settings\All Users\Application Data\avg9
2009-10-16 18:06 . 2009-10-16 18:06 ——– dc—-w- c:\program files\CCleaner
2009-10-15 07:23 . 2009-10-15 07:23 0 -c–a-w- c:\windows\nsreg.dat
2009-10-15 06:50 . 2009-10-15 06:50 ——– dc—-w- c:\program files\microsoft frontpage
2009-10-15 06:35 . 2009-10-15 06:35 21640 -c–a-w- c:\windows\system32\emptyregdb.dat
2009-09-25 05:37 . 2004-08-04 12:00 667136 -c—-w- c:\windows\system32\wininet.dll
2009-09-25 05:37 . 2004-08-04 12:00 81920 -c–a-w- c:\windows\system32\ieencode.dll
2009-09-11 14:18 . 2004-08-04 12:00 136192 -c–a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2004-08-04 12:00 58880 -c–a-w- c:\windows\system32\msasn1.dll
2006-06-20 19:37 . 2006-06-20 19:37 1224704 -csha-r- c:\windows\system32\winsysdriver.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-11-27_14.02.01 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-27 18:47 . 2009-11-27 18:47 16384 c:\windows\Temp\Perflib_Perfdata_8bc.dat
+ 2005-10-24 01:05 . 2005-10-24 01:05 1005898 c:\windows\system32\WindowsErrorTemp.dat
- 2005-06-08 16:06 . 2005-06-08 16:06 1005898 c:\windows\system32\WindowsErrorTemp.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-09-18 1115392]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-18 16:28 1115392 -c–a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-09-18 1115392]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-09-18 1115392]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"Microsoft Windows Operating System"="c:\windows\system32\winsysdriver.exe" [2006-06-20 1224704]

[HKEY_CURRENT_USER\software\microsoft\windows\Currentversion\policies\explorer\Run]
"Microsoft Windows Operating System"="c:\windows\system32\winsysdriver.exe" [2006-06-20 1224704]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-10-16 18:53 12464 -c–a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^Spike^Start Menu^Programs^Startup^DesktopVideoPlayer.LNK]
path=c:\documents and settings\Spike\Start Menu\Programs\Startup\DesktopVideoPlayer.LNK
backup=c:\windows\pss\DesktopVideoPlayer.LNKStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Documents and Settings\\Spike\\My Documents\\Downloads\\Programs\\utorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\AIM\\aim.exe"=

R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [10/16/2009 1:52 PM 25608]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [10/16/2009 1:52 PM 161800]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/16/2009 1:53 PM 333192]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [10/16/2009 1:53 PM 360584]
R2 avg9emc;AVG E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [10/16/2009 1:52 PM 906520]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [10/16/2009 1:52 PM 285392]
R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [10/22/2009 2:12 PM 2304192]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [10/22/2009 2:13 PM 5832712]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [11/11/2009 10:29 PM 604488]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [10/16/2009 1:51 PM 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [10/16/2009 1:52 PM 122376]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [10/16/2009 1:52 PM 30216]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [10/16/2009 1:52 PM 25736]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [10/16/2009 1:51 PM 30104]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{P633N151-5PA5-0KT2-UO4I-7K1545M7N101}]
c:\windows\system32\winsysdriver.exe Restart
.
Contents of the 'Scheduled Tasks' folder

2009-11-27 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-07-16 08:54]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
FF - ProfilePath - c:\documents and settings\Spike\Application Data\Mozilla\Firefox\Profiles\wvl2fd3k.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: yahoo.homepage.dontask - true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, falsec:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-27 13:50
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{33e7086a-f19c-4631-98cd-fc669e6b59dd}]
@Denied: (Full) (Everyone)
"Model"=dword:00000138
"Therad"=dword:00000019

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):e9,96,28,6f,90,d5,43,9b,2d,3b,3e,2f,d7,92,dc,eb,db,29,dc,2a,6e,
18,a3,13,aa,54,af,84,80,4d,7c,5e,3f,7a,85,b6,3f,e3,48,b5,00,00,00,00,00,00,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(6432)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wscntfy.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
.
**************************************************************************
.
Completion time: 2009-11-27 14:03 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-27 19:03

Pre-Run: 2,824,720,384 bytes free
Post-Run: 2,765,266,944 bytes free

- - End Of File - - 84C15CC2F28B905A29B533A7649933C2


||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
||||||||||||||||||||||||||||||||||||||||||||||||||||


Here's the mbam log:

Malwarebytes' Anti-Malware 1.41
Database version: 3243
Windows 5.1.2600 Service Pack 3

11/27/2009 2:22:26 PM
mbam-log-2009-11-27 (14-22-26).txt

Scan type: Quick Scan
Objects scanned: 93738
Time elapsed: 9 minute(s), 17 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{p633n151-5pa5-0kt2-uo4i-7k1545m7n101} (Generic.Bot.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\r00tz (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Cerberus (Backdoor.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\winsysdriver.exe (Generic.Bot.H) -> Quarantined and deleted successfully.

And the Kaspersky results:

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Saturday, November 28, 2009
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Friday, November 27, 2009 19:36:25
Records in database: 3302496
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\

Scan statistics:
Objects scanned: 29402
Threats found: 1
Infected objects found: 1
Suspicious objects found: 0
Scan duration: 02:44:15


File name / Threat / Threats count
C:\Qoobox\Quarantine\C\SUD\SSOW\sep.exe.vir Infected: Trojan.Win32.Buzus.cnjm 1

Selected area has been scanned.
Hi,

Please do the following:


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/C_SUDSSOWsep_exe_t108530.html

Collect::[22]
c:\windows\system32\winsysdriver.exe
c:\windows\system32\winsysdriver.exe Restart

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"Microsoft Windows Operating System"=-
[HKEY_CURRENT_USER\software\microsoft\windows\Currentversion\policies\explorer\Run]
"Microsoft Windows Operating System"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{P633N151-5PA5-0KT2-UO4I-7K1545M7N101}]

DirLook::
C:\Inetpub

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.


NEXT

Please post a fresh DDS and Attach.txt and advise how your computer is running now and if there are any outstanding issues.
Hello again CatByte, sorry for the delay, work and all that.

Here's the latest log from ComboFix:

http://forums.whatthetech.com/C_SUDSSOWsep_exe_t108530.html

Collect::[22]
c:\windows\system32\winsysdriver.exe
c:\windows\system32\winsysdriver.exe Restart

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"Microsoft Windows Operating System"=-
[HKEY_CURRENT_USER\software\microsoft\windows\Currentversion\policies\explorer\Run]
"Microsoft Windows Operating System"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{P633N151-5PA5-0KT2-UO4I-7K1545M7N101}]

DirLook::
C:\Inetpub

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI