This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] random name rootkit found with AVG_antirootkit

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I need help with a rootkit that I keep finding in the Sys32 directory.

I ran combofix and then ran the old AVG Antirootkit right after it and the file the antirootkit found this time was called asy8agjp.sys in the Sys32/drivers directory.

I normally have Avira running which didn't find anything. I also ran MBAM, GMER and eset and nothing seems to fix the root problem.

I won't do any fixing on my own from here out.

Thanks in advance for any help.

ComboFix 09-12-09.04 - TPKNET 12/10/2009 12:16:21.6.2 - x86
Running from: c:\documents and settings\[removed]\Desktop\K0mb0F1x.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_NPF
——-\Service_Ndisrd


((((((((((((((((((((((((( Files Created from 2009-11-10 to 2009-12-10 )))))))))))))))))))))))))))))))
.

2009-12-10 17:40 . 2005-06-23 18:59 17408 —-a-r- c:\windows\system32\EtCo32.dll
2009-12-10 17:40 . 2005-06-15 06:08 20480 —-a-r- c:\windows\system32\NicCo32.dll
2009-12-10 17:40 . 2005-05-19 15:28 21504 —-a-r- c:\windows\system32\NicIn32.dll
2009-12-10 16:57 . 2009-12-10 16:57 ——– d—–w- c:\documents and settings\Admin
2009-12-10 13:55 . 2009-12-10 13:59 ——– d—–w- C:\K0mb0F1x
2009-12-09 03:36 . 2009-12-09 03:36 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-12-09 02:23 . 2009-05-07 07:04 157712 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2009-12-09 01:43 . 2009-12-09 01:43 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2009-12-08 23:30 . 2009-12-08 23:30 ——– d—–w- c:\documents and settings\TPKNET\DoctorWeb
2009-12-07 17:14 . 2009-12-08 05:40 73736 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-12-07 03:53 . 2009-12-07 03:53 ——– d—–w- c:\program files\7-Zip
2009-12-06 01:53 . 2009-12-06 01:53 ——– d—–w- c:\program files\ESET
2009-11-24 23:13 . 2009-11-24 23:13 ——– d—–w- C:\Atlas3
2009-11-21 02:47 . 2009-11-21 02:47 ——– d—–w- c:\documents and settings\TPKNET\Application Data\FreeVideoConverter
2009-11-21 00:54 . 2009-11-21 00:57 ——– d—–w- c:\program files\DAEMON Tools Lite
2009-11-21 00:53 . 2009-11-21 00:53 ——– d—–w- c:\documents and settings\TPKNET\Application Data\Regensoft
2009-11-11 16:04 . 2009-11-11 16:04 1413 —-a-w- c:\windows\system32\pfdnnt_actions.sys
2009-11-11 16:04 . 2009-11-11 15:56 13312 —-a-w- c:\windows\system32\pfdnnt.exe
2009-11-11 15:56 . 2009-11-11 15:56 8704 —-a-w- c:\windows\system32\drivers\styhjmlsfhqd.sys
2009-11-11 15:55 . 2009-11-11 15:55 8704 —-a-w- c:\windows\system32\drivers\secfsmikkjyb.sys
2009-11-11 15:47 . 2009-11-11 15:47 8576 —-a-w- c:\windows\system32\drivers\rvowhkgaemyl.sys
2009-11-11 14:24 . 2009-11-11 14:22 8576 —-a-w- c:\windows\system32\drivers\egefemdsdxqr.sys
2009-11-11 12:27 . 2009-11-11 12:26 8576 —-a-w- c:\windows\system32\drivers\muuumewkvbgg.sys
2009-11-11 12:26 . 2009-12-08 20:32 ——– d—–w- c:\documents and settings\TPKNET\Pavark

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-10 18:25 . 2006-10-17 13:31 ——– d—–w- c:\program files\Hauppauge MediaMVP
2009-12-10 17:54 . 2007-04-26 16:38 ——– d—–w- c:\program files\Wireshark
2009-12-10 17:27 . 2009-04-01 20:38 ——– d—–w- c:\documents and settings\TPKNET\Application Data\TeraCopy
2009-12-10 16:58 . 2006-10-19 03:31 93496 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-10 13:51 . 2007-11-14 14:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-12-09 03:22 . 2009-08-12 21:49 ——– d—–w- c:\program files\Unlocker
2009-12-09 02:51 . 2007-11-09 21:26 ——– d—–w- c:\program files\Internet Video Converter 1.50 en
2009-12-08 20:37 . 2009-08-12 17:03 56816 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-08 20:28 . 2009-07-14 21:34 117760 —-a-w- c:\documents and settings\TPKNET\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-07 08:18 . 2009-01-16 16:02 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-07 03:34 . 2009-07-14 21:33 4844296 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-05 15:02 . 2008-10-09 20:31 ——– d—–w- c:\documents and settings\TPKNET\Application Data\Skype
2009-12-05 06:02 . 2008-10-09 20:32 ——– d—–w- c:\documents and settings\TPKNET\Application Data\skypePM
2009-12-04 03:18 . 2006-10-14 01:08 ——– d—–w- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-12-03 22:14 . 2009-01-16 16:02 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-03 22:13 . 2009-01-16 16:02 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-11-30 14:58 . 2008-12-20 04:29 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-11-22 01:51 . 2008-03-06 16:24 ——– d—–w- c:\documents and settings\TPKNET\Application Data\DVD Flick
2009-11-21 00:54 . 2009-01-17 02:42 691696 —-a-w- c:\windows\system32\drivers\sptd.sys
2009-11-20 23:59 . 2009-01-08 21:12 ——– d—–w- c:\documents and settings\TPKNET\Application Data\ImgBurn
2009-11-18 18:15 . 2007-07-19 17:47 25860 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2007\qbbackup.sys
2009-11-18 00:11 . 2008-11-21 00:54 816392 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2007\Components\DownloadQB17\Patch\qbpatch2.exe
2009-11-08 15:34 . 2009-01-08 14:02 ——– d—–w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-11-05 13:25 . 2006-10-15 00:44 ——– d—–w- c:\documents and settings\TPKNET\Application Data\RipIt4Me
2009-11-05 03:00 . 2009-07-22 01:53 ——– d—–w- c:\documents and settings\TPKNET\Application Data\Red Kawa
2009-11-05 02:57 . 2009-11-05 02:57 ——– d—–w- c:\program files\Regensoft
2009-11-04 02:32 . 2009-07-18 23:08 ——– d—–w- c:\documents and settings\TPKNET\Application Data\Audacity
2009-11-03 02:42 . 2009-10-02 18:25 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-10-29 07:45 . 2006-03-04 03:33 916480 ——w- c:\windows\system32\wininet.dll
2009-10-23 18:25 . 2009-10-09 21:18 ——– d—–w- c:\program files\Ask & Record Toolbar
2009-10-21 05:38 . 2004-08-04 10:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 10:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 10:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2004-08-04 10:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-04 10:00 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-04 10:00 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-08 03:27 . 2009-10-08 16:32 2011511 —-a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\FAILSAVE\aeheur.dll
2009-10-03 04:15 . 2009-10-08 16:32 483707 —-a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\FAILSAVE\aescript.dll
2009-10-03 04:15 . 2009-10-08 16:32 479604 —-a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\FAILSAVE\aerdl.dll
2009-10-03 04:15 . 2009-10-08 16:32 393587 —-a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\FAILSAVE\aeemu.dll
2009-10-03 04:15 . 2009-10-08 16:32 364916 —-a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\FAILSAVE\aegen.dll
2009-09-15 21:58 . 2009-10-08 16:32 106867 —-a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\FAILSAVE\aevdf.dll
2009-09-15 21:58 . 2009-10-08 16:32 422261 —-a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\FAILSAVE\aepack.dll
2009-09-15 21:57 . 2009-10-08 16:32 184693 —-a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir Desktop\FAILSAVE\aecore.dll
2003-06-19 17:05 . 2003-06-19 17:05 431888 –s-a-w- c:\program files\Common Files\riched20.dll
2009-12-04 01:18 . 2007-08-13 15:24 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2007-10-22 21:02 . 2007-10-22 21:02 10856 –sha-w- c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe AcStd7_0_7 -reboot 1" [X]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe -autorun" [X]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe -atboottime" [X]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-21 39408]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-11-30 2001648]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2009-09-30 387584]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-01-09 2262352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe -hide" [X]
"IntelAudioStudio"="c:\program files\Intel Audio Studio\IntelAudioStudio.exe BOOT" [X]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe -atboottime" [X]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"nwiz"="nwiz.exe" [2006-06-01 1519616]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-01 7618560]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 19968]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-12-04 30192]
"EPSON Stylus C86 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2R1.EXE" [2003-11-25 99840]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-14 177472]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 86016]
"SigmatelSysTrayApp"="sttray.exe" [2005-09-27 393216]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"PinnacleDriverCheck"="c:\windows\system32\\PSDrvCheck.exe" [2004-03-11 406016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe -t" [X]

c:\documents and settings\TPKNET\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
WordWeb.lnk - c:\program files\WordWeb\wweb32.exe [2007-10-8 44384]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-14 07:11 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepel.sys]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=c:\windows\pss\AutoCAD Startup Accelerator.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SlimServer Tray Tool.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\SlimServer Tray Tool.lnk
backup=c:\windows\pss\SlimServer Tray Tool.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
c:\program files\DAEMON Tools\daemon.exe -lang 1033 [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelAudioStudio]
c:\program files\Intel Audio Studio\IntelAudioStudio.exe BOOT [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
2006-01-13 01:52 483328 —-a-w- c:\program files\Adobe\Acrobat 7.0\Distillr\AcroTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
2007-04-20 03:29 149024 —-a-w- c:\program files\Common Files\Seagate\Schedule2\schedhlp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
2007-04-20 03:38 1945688 —-a-w- c:\program files\Seagate\DiscWizard\TimounterMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DiscWizardMonitor.exe]
2007-04-20 03:24 1169744 —-a-w- c:\program files\Seagate\DiscWizard\DiscWizardMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-07-13 19:03 292128 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
2005-08-11 17:33 11776 —-a-w- c:\progra~1\MUSICM~1\MUSICM~1\mimboot.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
2005-08-11 17:33 110592 —-a-w- c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 15:50 155648 —-a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ProfilerU]
2007-10-02 16:10 233472 —-a-w- c:\program files\Saitek\SD6\Software\ProfilerU.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SaiMfd]
2007-10-02 16:10 131072 —-a-w- c:\program files\Saitek\SD6\Software\SaiMfd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"WmdmPmSN"=3 (0x3)
"UPS"=3 (0x3)
"slimsvc"=3 (0x3)
"QBFCService"=3 (0x3)
"Adobe LM Service"=3 (0x3)
"AcrSch2Svc"=2 (0x2)
"TQGKQV"=3 (0x3)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\program files\\OrCAD_10.5\\setconfig.exe"=
"c:\\program files\\OrCAD_10.5\\updates.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\bin\\cdsdoc.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\bin\\cdsinfo.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\bin\\cdsmps.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\bin\\cdsMsgServer.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\bin\\cdsNameServer.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\bin\\cdsRemshClient.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\bin\\cdsRunHidden.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\bin\\cdsUnzip.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\bin\\cdswhich.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\bin\\cdsZip.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\bin\\cds_root.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\bin\\clsAdminTool.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\bin\\clsbd.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\bin\\clu.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\bin\\dregprint.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\bin\\mpsinfo.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\bin\\nmp.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\bin\\nmppath.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\bin\\obServer.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\bin\\van.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\bin\\versionviewer.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\capture\\capture.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\capture\\comp16.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\capture\\pcadi.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\capture\\pspiceexplorersrvr.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\capture\\pstswp.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\capture\\regsvr32.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\capture\\sch2cap.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\capture\\SETBROWS.EXE"=
"c:\\program files\\OrCAD_10.5\\tools\\capture\\tutorial\\CAPTUTOR.EXE"=
"c:\\program files\\OrCAD_10.5\\tools\\cdsdoc\\bin\\cdsdocIndexer.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\cdsdoc\\bin\\obServer.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\dfII\\bin\\cdsservipc.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\dfII\\bin\\skill.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\dfII\\bin\\skill_g.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\fet\\bin\\mkdefcfg.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\fet\\bin\\versiontool.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\jre\\javaws-1_2_0_02-windows-i586-i.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\jre\\bin\\java.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\jre\\bin\\javaw.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\jre\\bin\\jpicpl32.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\jre\\bin\\keytool.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\jre\\bin\\kinit.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\jre\\bin\\klist.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\jre\\bin\\ktab.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\jre\\bin\\orbd.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\jre\\bin\\policytool.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\jre\\bin\\rmid.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\jre\\bin\\rmiregistry.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\jre\\bin\\servertool.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\jre\\bin\\tnameserv.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\fvupdateutil.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\gcad.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\gcam.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\gcdin.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\idfin.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\ipc356.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\layout.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\libcat.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\lsession.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\max2hyp.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\maxascb.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\maxascx.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\maxdxf.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\maxeco.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\maxfnetx.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\maxminb.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\maxminw.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\maxminx.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\maxorcad.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\maxp99x.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\maxpadb.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\maxpadx.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\maxpcadb.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\maxpcadx.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\maxprotb.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\maxprotx.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\maxstrb.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\maxstrx.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\maxtangb.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\maxtangx.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\mfceco.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\orcadodb.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\padb.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\padx.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\pcadb.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\pcadx.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\pcb2max.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\prcat.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\protb.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\protx.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\searchTool.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\setbrows.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\specin.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\strb.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\strx.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\tangb.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\tangx.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\to386.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\toidf.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\tomax.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\tospec.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\update90.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\gtool\\fonts\\f2g.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\gtool\\fonts\\g2r.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\gtool\\program\\apstub.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\gtool\\program\\custaped.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\gtool\\program\\gerbline.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\gtool\\program\\gerbtool.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\gtool\\system\\fixtbar.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\samples\\demo\\reset.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\sroute\\batch32.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\sroute\\sroute.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\tutorial\\laytutor.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\layout_plus\\vcadd\\vcadd32.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\pspice\\appmgr.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\pspice\\IndiceFileGeneration.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\pspice\\lxcwin.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\pspice\\Magneticdesigner.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\pspice\\modeled.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\pspice\\MrkSrvr.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\pspice\\msgview.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\pspice\\optimize.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\pspice\\PDesign.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\pspice\\psched.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\pspice\\pspice.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\pspice\\pspiceaa.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\pspice\\pspiceexplorersrvr.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\pspice\\psp_cmd.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\pspice\\regsvr32.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\pspice\\simmgr.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\pspice\\simsrvr.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\pspice\\stmed.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\specctra\\bin\\specctra.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\verity\\bin\\cdsdocIndexer.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\verity\\_nti40\\bin\\merge.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\verity\\_nti40\\bin\\mkvdk.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\verity\\_nti40\\bin\\search.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\verity\\_nti40\\bin\\setup.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\verity\\_nti40\\bin\\v_uninst.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\verity\\_nti40\\filters\\callback.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\verity\\_nti40\\filters\\filter.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\verity\\_nti40\\filters\\htmlini.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\verity\\_nti40\\filters\\htmserv.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\verity\\_nti40\\filters\\index.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\verity\\_nti40\\filters\\jstree.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\verity\\_nti40\\filters\\jvtree.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\verity\\_nti40\\filters\\kvoop.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\verity\\_nti40\\filters\\regsvr32.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\verity\\_nti40\\filters\\summary.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\verity\\_nti40\\filters\\viewers\\amovie.exe"=
"c:\\program files\\OrCAD_10.5\\tools\\specctra\\bin\\specctra.com"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Intuit\\QuickBooks Pro\\QBDBMgrN.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Microsoft Games\\Microsoft Flight Simulator X\\fsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\BUFFALO\\NASNAVI\\NasNavi.exe"=
"c:\\Program Files\\Microsoft Games\\Flight Simulator 9\\fs9.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9000:TCP"= 9000:TCP:SlimServer 9000 tcp
"3483:UDP"= 3483:UDP:SlimServer 3483 udp
"3483:TCP"= 3483:TCP:SlimServer 3483 tcp
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R2 CADopia License Manager;CADopia License Manager;c:\orcad\OrCAD_10.5\INTELL~1\LicenseManager\lmgrd.exe [2003-05-02 609280]
R2 lmgrd;Flexlm;c:\orcad\OrCAD_10.5\IntelliCAD 4\LicenseManager\lmgrd.exe [2003-05-02 609280]
R2 srenum;srenum;c:\windows\system32\DRIVERS\srenum.sys [x]
R3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2009-12-04 30192]
R3 rootrepeel;rootrepeel;c:\windows\system32\drivers\rootrepeel.sys [x]
R3 rootrepel;rootrepel;c:\windows\system32\drivers\rootrepel.sys [x]
R3 SaiH0255;SaiH0255;c:\windows\system32\DRIVERS\SaiH0255.sys [2007-05-01 132232]
R4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2006-12-02 2805000]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-11-21 691696]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-04-14 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-08-12 74480]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
S2 MVPMedia;MVPMedia;c:\progra~1\HAUPPA~1\MVPStart.exe [2007-01-22 53248]
S2 MVPMediaSvc;MVPMediaSvc;c:\progra~1\HAUPPA~1\Hardware\DglSvcMain.exe [2007-01-22 45056]
S2 NasPmService;NAS PM Service;c:\program files\BUFFALO\NASNAVI\nassvc.exe [2007-10-25 233472]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-04 13592]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-04 7408]
S3 SbieDrv;SbieDrv;c:\program files\Sandboxie\SbieDrv.sys [2009-09-30 116736]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.microwebinc.com/links
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to MVP Favorite Radio Stations - c:\program files\Hauppauge MediaMVP\mvp.htm
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: musicmatch.com\online
TCP: {B231E886-5737-4CD1-96DB-4E39F9399899} = 137.192.240.5,76.164.128.5
DPF: {EFFDEEEC-F9E1-4461-91D2-DAEB8CC595F1} - hxxp://192.168.1.228/CSViewer.cab
FF - ProfilePath - c:\documents and settings\TPKNET\Application Data\Mozilla\Firefox\Profiles\8lshjtg1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.microwebinc.com/links
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-10 12:28
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spbk.sys >>UNKNOWN [0x8AE0F938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba90cf28
\Driver\ACPI -> ACPI.sys @ 0xba674cb8
\Driver\atapi -> atapi.sys @ 0xba609b40
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> 0x895b41b0
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> 0x895b41b0
NDIS: Intel® PRO/1000 PL Network Connection -> SendCompleteHandler -> NDIS.sys @ 0xba512bb0
PacketIndicateHandler -> NDIS.sys @ 0xba51fa21
SendHandler -> NDIS.sys @ 0xba4fd87b
user & kernel MBR OK

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(944)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(1008)
c:\windows\system32\relog_ap.dll

- - - - - - - > 'explorer.exe'(2024)
c:\windows\system32\WININET.dll
c:\program files\Logitech\MouseWare\System\LgWndHk.dll
c:\program files\Common Files\Logitech\Scrolling\LgMsgHk.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\windows\System32\tcpsvcs.exe
c:\progra~1\HAUPPA~1\Hardware\HcwSms.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Sandboxie\SbieSvc.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\fxssvc.exe
c:\program files\Windows Defender\MSASCui.exe
c:\windows\sttray.exe
c:\program files\Logitech\MouseWare\system\em_exec.exe
c:\program files\Microsoft ActiveSync\wcescomm.exe
c:\progra~1\MICROS~3\rapimgr.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-12-10 12:34:22 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-10 18:34
ComboFix2.txt 2009-12-10 16:44
ComboFix3.txt 2009-12-10 16:06
ComboFix4.txt 2009-12-10 14:26
ComboFix5.txt 2009-12-10 18:15

Pre-Run: 24,744,087,552 bytes free
Post-Run: 24,701,325,312 bytes free

Current=8 Default=8 Failed=7 LastKnownGood=1 Sets=1,2,7,8
- - End Of File - - 0B2BEBBF8586117A00E7FC0F42ED9358
Hello, Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise. This may cause a delay, but I will do my best to keep it as short as possible. I am checking over your log , I will post back shortly with instructions.
Hi,

I will be helping you on removing malwares on your computer. Log research takes time, so please be patient and I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not install/uninstall anything on your computer unless advised.
  • Do not run any other scanning tools other than those instructed for you to use.
  • Follow the instructions on the order they are given.
  • Stay with this thread until advised when your computer is clean. Absence of symptoms does not necessarily mean a clean computer.
  • If you are being helped regarding this problem on another forum please advice us so that we can close this thread.
  • And lastly, if you have any questions, please ask before proceeding with any of the advised fixes.

_________________________________________________

Do not use Combofix without proper supervision as this can render your machine inoperable!



Please download DeFogger to your desktop.
Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.
Do not re-enable these drivers until otherwise instructed.

–Next–

Do you still have GMER? If not, then please download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
If you do not receive notice about possible rootkit activity remain on the Rootkit/Malware tab & make sure the 'Show All' button is unticked.
  • Click the Scan button and let the program do its work. GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop
–Next–

We need to see the old logs created by GMER and Combofix to see what has happened to your computer.
Post all the previous ComboFix logs from Qoobox C:\Qoobox\ComboFix2.txt, C:\Qoobox\ComboFix3.txt, C:\Qoobox\ComboFix4.txt etc. including the old log from GMER if you still have it.


To post in your next reply:
1. DeFogger log.
2. New GMER log.
3. Old logs.
4. How is your computer?
I forgot to report on how my computer is doing. I haven't really noticed any major problems. The only reason I found this problem is that I was helping a friend diagnose his computer being infected over the phone and I was running the same scans I had him do. It was then that I discovered my computer was infected. I do notice that internet explorer locks up a lot. I just had it lock up and there were 6 instances of iexplore.exe in the task manager and I couldn't kill them with end process. I only had one window and one tab of explorer open at the time. May not be related though. Thanks, tpknet
Hi,

Did you reboot your computer after running Defogger? If not, then please do so.

–Next–

Delete your copy of Combofix then download a new copy from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

Do not run it yet.

–Next–

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty in properly disabling your protective programs, refer to this link - How to Disable your Security Programs
——————————————————————–

1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:

http://forums.whatthetech.com/random_name_…712#entry616712

Collect::
c:\windows\system32\drivers\styhjmlsfhqd.sys
c:\windows\system32\drivers\secfsmikkjyb.sys
c:\windows\system32\drivers\rvowhkgaemyl.sys
c:\windows\system32\drivers\egefemdsdxqr.sys
c:\windows\system32\drivers\muuumewkvbgg.sys

File::
c:\windows\system32\drivers\rootrepeel.sys
c:\windows\system32\drivers\rootrepel.sys

Driver::
rootrepeel
rootrepel

Registry::
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepel.sys]

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.


–Next–
  • Open Malwarebytes.
  • Click on the Update tab.
  • Click Check for Updates button.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post back the log.

Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so immediately.

–Next–

Please do a scan with Kaspersky Online Scanner or from Here.
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
  • Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select: Text file [*.txt]
  • Then, click: Save
  • Please post the Kaspersky Online Scanner Report in your reply.
To post in your reply:
1. CFScript log.
2. Malwarebytes's log.
3. Kaspersky log.
4. How is your computer?
The computer ran for a very long time with the Kaspersky scan because I had network drives mapped. When it finished I came to look at the computer and the screen was black except for the mouse pointer which would let me move it around. I tried getting into the computer with no luck. I tried Ctrl/Alt/Del with no effect so I rebooted and looked for the Kaspersky log with no luck. I am going to try to run it again with the network drives turned off. By the way, if I click on "here" in your link to the Kaspersky website I can find no online scanner. When I clicked on the "Kaspersky" I found the online scanner. Thanks, Tpknet
Hi,

Please open this link HERE in a new window.

In the box marked Link to topic where this file was requested: please paste in the following text
http://forums.whatthetech.com/random_name_rootkit_found_AVG_antirootkit_t108797.html#entry617607

Click the Browse button and navigate to C:\Qoobox\Quarantine

There should be a zip file there called [4]-Submit_****-**-**_**.**.**.zip ( the * denotes Date and Time stamp )
It will be close to this: 12/12/2009 22:22:27
Select this file and click Open
In the Largest box please put
File Requested By inzanity
Failed Submit::

Finally click SendFile

Please return here and let me know when that file has been uploaded.

–Next–

If you are still having touble with Kaspersky let's try ESET instead.
Go here to run an online scanner from ESET.

  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
–Next–

To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.
Your Emulation drivers are now re-enabled.
I turned off my network drives and on the third try Kaspersky finished and let me run a scan. I am uploading the log file. I will also run Eset but that is one of the products I was using originally that didn't find anything. Thanks, Tpknet

Attachments:

Here is the ESET log. The computer seems OK. I didn't re-enable the emulation drivers yet. Thanks, Tpknet ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK esets_scanner_update returned -1 esets_gle=53251 # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=1ff7327078d4104fab5ace0884688c6f # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2009-12-07 03:16:04 # local_time=2009-12-06 09:16:04 (-0600, Central Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 9876773 9876773 0 0 # compatibility_mode=1536 16777215 100 0 0 0 0 0 # compatibility_mode=1797 16775125 100 100 0 35066040 0 0 # compatibility_mode=6143 16777215 0 0 0 0 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=472590 # found=1 # cleaned=1 # scan_time=78751 C:\WINDOWS\system32\drivers\srenum.sys Win32/Rootkit.Agent.NQA trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=1ff7327078d4104fab5ace0884688c6f # end=stopped # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2009-12-08 08:11:09 # local_time=2009-12-08 02:11:09 (-0600, Central Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 10090993 10090993 0 0 # compatibility_mode=1536 16777215 100 0 0 0 0 0 # compatibility_mode=1797 16775141 100 100 0 35280260 0 0 # compatibility_mode=6143 16777215 0 0 0 0 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=312748 # found=0 # cleaned=0 # scan_time=11835 # version=7 # IEXPLORE.EXE=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=1ff7327078d4104fab5ace0884688c6f # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2009-12-15 04:36:34 # local_time=2009-12-15 10:36:34 (-0600, Central Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 10638328 10638328 0 0 # compatibility_mode=1536 16777215 100 0 0 0 0 0 # compatibility_mode=1797 16775141 100 100 0 35827595 0 0 # compatibility_mode=6143 16777215 0 0 0 0 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=460825 # found=0 # cleaned=0 # scan_time=56425
Hi, your logs are clean. You can re-enable your CD emulations driver by following the steps above.

Please delete GMER, Defogger and all the logs we've created.

–Next–

The following will implement some cleanup procedures as well as reset System Restore points:

Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /Uninstall

[external image: Posted Image]

–Next–

Java
Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.
The latest update is Java 6 update 17

Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon.
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are two options in the window to clear the cache - Leave both Checked
    Applications and Applets
    Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.
To keep your operating system up to date visit
  • Secunia Software inspector to check your program update status.
  • Microsoft Windows Update .

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer More Secure
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.

    • Change the Download signed ActiveX controls to Prompt.
    • Change the Download unsigned ActiveX controls to Disable.
    • Change the Initialise and script ActiveX controls not marked as safe to Disable.
    • Change the Installation of desktop items to Prompt.
    • Change the Launching programs and files in an IFRAME to Prompt.
    • Change the Navigate sub-frames across different domains to Prompt.
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
2. Update your Anti-Virus Software - I can not overemphasize the need for you to update your Anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

3. Make sure you keep your Windows OS current by visiting Windows update regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.

4. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

5. Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.

6. SpywareBlaster - Download and install SpywareBlaster. This program prevents the installation of ActiveX-based spyware and other potentially unwanted programs.

7. Protect your computer from internet threats with SandboxIE. This program isolates Internet Explorer from the rest of your operating system, 'sandboxing' it away - so malicious websites can't do damage to the rest of your system. There is a Getting Started guide on their website.

8. Some excellent free firewalls. Note: Use only one firewall at a time.
Agnitum Outpost Firewall
Comodo Firewall - If you are installing this and already have an anti spyware then please do not install Comodo's anti spyware program.
Online Armor Personal Firewall

9. And finally, please read these excellent articles:
Malware: Help prevent the Infection by Sandi Hardmeier,
Preventing Malware - Tools and Practices for Safe Computing

For more safe computing tips please read the guide by Rorschach112 on how to prevent malware and about safe computing here.



Goodluck, happy computing and stay clean! ^_^

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI