This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Win32: Malware-gen

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have tried every possible effort to remove this pain in my behind trojan and it keeps coming back. I have used Malare removal, spybot, torjan removal, super anti spyware. Still it keeps poping up on the screen every 5 minutes (please see attachment). Any help getting rid of this once and for all would be very much appreciated.

Attachments:

  • [attachment removed: Win32_Malware_gen.gif]
Hi,

please do the following:

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
here are the results from my dds

Attach.txt

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 10/21/2008 4:19:24 AM
System Uptime: 12/24/2009 2:00:48 AM (3 hours ago)

Motherboard: Dell Inc. | | 0UW306
Processor: Intel® Core™2 Duo CPU T7300 @ 2.00GHz | Microprocessor | 2000/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 70 GiB total, 35.286 GiB free.
D: is FIXED (NTFS) - 79 GiB total, 53.312 GiB free.
E: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft ISATAP Adapter
Device ID: ROOT\*ISATAP\0011
Manufacturer: Microsoft
Name: Microsoft ISATAP Adapter
PNP Device ID: ROOT\*ISATAP\0011
Service: tunnel

Class GUID:
Description:
Device ID: ROOT\*ISATAP\0037
Manufacturer:
Name:
PNP Device ID: ROOT\*ISATAP\0037
Service:

Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Microsoft ISATAP Adapter
Device ID: ROOT\*ISATAP\0050
Manufacturer: Microsoft
Name: isatap.{07B4E5D3-9A8C-4D08-9AB1-DE121D61B83D}
PNP Device ID: ROOT\*ISATAP\0050
Service: tunnel

Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Cisco AnyConnect VPN Virtual Miniport Adapter for Windows
Device ID: ROOT\NET\0000
Manufacturer: Cisco Systems
Name: Cisco AnyConnect VPN Virtual Miniport Adapter for Windows
PNP Device ID: ROOT\NET\0000
Service: vpnva

Class GUID: {4d36e972-e325-11ce-bfc1-08002be10318}
Description: Cisco Systems VPN Adapter
Device ID: ROOT\NET\0001
Manufacturer: Cisco Systems
Name: Cisco Systems VPN Adapter
PNP Device ID: ROOT\NET\0001
Service: CVirtA

==== System Restore Points ===================

No restore point in system.

==== Installed Programs ======================

µTorrent
1Click DVD Copy [removed]
32 Bit HP CIO Components Installer
Adobe Acrobat 7.0 Standard - English, Français, Deutsch
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Photoshop 7.0
Advanced Audio FX Engine
Advanced Video FX Engine
AIO_Scan
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Athan Basic 3.6
Auslogics Disk Defrag
avast! Antivirus
BitTorrent 6.0.2
Bonjour
Broadcom 440x 10/100 Integrated Controller
BufferChm
C6200
C6200_Help
Cards_Calendar_OrderGift_DoMorePlugout
CCleaner
Cisco AnyConnect VPN Client
Cisco Systems VPN Client 5.0.05.0290
Compatibility Pack for the 2007 Office system
Conexant HDA D330 MDC V.92 Modem
Copy
CustomerResearchQFolder
DealAssistant
Dell Resource CD
Dell Touchpad
DELL Webcam Center
DELL Webcam Manager
Destination Component
DeviceDiscovery
DeviceManagementQFolder
DNA
DocProc
DocProcQFolder
Domino Video Converter Pro V1.0.620
DVD-CLONER V4.70 Build 926
eSupportQFolder
Fax
Google Toolbar for Internet Explorer
GPBaseService
Highlight Viewer (Windows Live Toolbar)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HP Customer Participation Program 10.0
HP Imaging Device Functions 10.0
HP Photosmart All-In-One Driver Software 10.0 Rel .2
HP Photosmart Essential 2.5
HP Smart Web Printing
HP Solution Center 10.0
HP Update
HPPhotoSmartDiscLabel_PaperLabel
HPPhotoSmartDiscLabel_PrintOnDisc
HPPhotoSmartDiscLabelContent1
hpphotosmartdisclabelplugin
HPPhotoSmartPhotobookWebPack1
HPProductAssistant
HPSSupply
Intel Matrix Storage Manager
Internet Telephone 4.60
iTunes
Java™ 6 Update 15
Junk Mail filter update
Laptop Integrated Webcam Driver (1.04.01.1011)
Live! Cam Avatar Creator
Live! Cam Avatar v1.0
LiveTV_ Toolbar
LogMeIn
Map Button (Windows Live Toolbar)
MarketResearch
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office Live Add-in 1.3
Microsoft Office Outlook Connector
Microsoft Office Professional Edition 2003
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
MobileMe Control Panel
MP3 RM Converter 1.30
MSN Toolbar
MSVCRT
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nokia Connectivity Cable Driver
Nokia Lifeblog 2.1
Nokia MTP driver
Nokia PC Connectivity Solution
Nokia PC Suite
Nokia Software Launcher
NVIDIA Drivers
OCR Software by I.R.I.S. 10.0
OGA Notifier 2.0.0048.0
PanoStandAlone
PS_AIO_02_ProductContext
PS_AIO_02_Software
PS_AIO_02_Software_Min
PSSWCORE
QuickTime
Roxio Creator Audio
Roxio Creator Copy
Roxio Creator Data
Roxio Creator DE
Roxio Creator Tools
Roxio Drag-to-Disc
Roxio Express Labeler
Roxio Update Manager
Safari
Scan
Shop for HP Supplies
SigmaTel Audio
Smart Menus (Windows Live Toolbar)
SmartWebPrintingOC
SolutionCenter
Sonic Activation Module
Status
SUPERAntiSpyware Free Edition
Toolbox
Tracks Eraser Pro v8.0 build 1001
TrayApp
UnloadSupport
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
VideoToolkit01
VLC media player 0.9.8a
WebReg
WIDCOMM Bluetooth Software 6.0.1.3100
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live Favorites for Windows Live Toolbar
Windows Live ID Sign-in Assistant
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live OneCare safety scanner
Windows Live Photo Gallery
Windows Live Sync
Windows Live Toolbar
Windows Live Toolbar Extension (Windows Live Toolbar)
Windows Live Upload Tool
Windows Live Writer
WinZip
Yahoo! Install Manager
Yahoo! Messenger
Yahoo! Search Protection
Yahoo! Software Update
Yahoo! Toolbar

==== End Of File ===========================

DDS.Txt

DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 5:12:54.08 on Thu 12/24/2009
Internet Explorer: 8.0.6001.18865
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2045.839 [GMT 3:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\aestsrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\STacSV.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
c:\program files\acesoft\tracks eraser pro\te.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Athan\Athan.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Windows\system32\notepad.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Temp\DDS\dds.com

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
uDefault_Page_URL = hxxp://www.msn.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll
mURLSearchHooks: LiveTV_ Toolbar: {59385f95-c52f-4a84-b674-4a4206b17218} - c:\program files\livetv_\tbLive.dll
mURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: LiveTV_ Toolbar: {59385f95-c52f-4a84-b674-4a4206b17218} - c:\program files\livetv_\tbLive.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn3\YTSingleInstance.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
TB: LiveTV_ Toolbar: {59385f95-c52f-4a84-b674-4a4206b17218} - c:\program files\livetv_\tbLive.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
TB: {9C93712C-80D1-4562-AF06-7DE6EECA8D12} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe"
mRun: []
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Athan] c:\program files\athan\Athan.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
dRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
dRun: [sysdiag64.exe] c:\windows\hdn54.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: 55963676-2F5E-4BAF-AC28-CF26AA587566 - vpnweb.cab
DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
IFEO: ehshell.exe - "c:\program files\logmein\x86\LogMeInSystray.exe" -MceShellRedirect
Hosts: 127.0.0.1 www.spywareinfo.com

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-11-16 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-11-23 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-11-23 74480]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2008-10-20 73728]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-11-16 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2009-11-16 53328]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-11-16 138680]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2008-7-24 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2008-10-20 47640]
R2 vpnagent;Cisco AnyConnect VPN Agent;c:\program files\cisco\cisco anyconnect vpn client\vpnagent.exe [2009-6-17 434864]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-11-16 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-11-16 352920]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-11-23 7408]
S2 sswxplore;sswxplore;"c:\updat.exe" –> c:\updat.exe [?]
S2 Wexplorer;Wexplorer;"c:\windows\temp\xboo.tmp\svchost.exe" –> c:\windows\temp\xboo.tmp\svchost.exe [?]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-10-20 21504]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2009-8-23 54632]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]

=============== Created Last 30 ================

2009-12-24 02:08:13 0 d—–w- c:\temp\GMER
2009-12-24 02:01:44 0 d—–w- c:\temp\DDS
2009-12-23 22:31:24 0 d—a-w- c:\programdata\TEMP
2009-12-23 22:30:53 77312 —-a-w- c:\windows\system32\ztvunace26.dll
2009-12-23 22:30:53 75264 —-a-w- c:\windows\system32\unacev2.dll
2009-12-23 22:30:53 69632 —-a-w- c:\windows\system32\ztvcabinet.dll
2009-12-23 22:30:53 162304 —-a-w- c:\windows\system32\ztvunrar36.dll
2009-12-23 22:30:53 153088 —-a-w- c:\windows\system32\UNRAR3.dll
2009-12-23 22:17:04 0 d—–w- c:\temp\Trojan Remover - Trial
2009-12-17 02:26:32 0 d—–w- c:\programdata\SUPERAntiSpyware.com
2009-12-17 02:26:22 0 d—–w- c:\users\popo\appdata\roaming\SUPERAntiSpyware.com
2009-12-17 02:26:22 0 d—–w- c:\program files\SUPERAntiSpyware
2009-12-17 02:25:35 0 d—–w- c:\program files\common files\Wise Installation Wizard
2009-12-17 02:21:32 0 d—–w- c:\temp\Super Anti Spyware - Free
2009-12-17 01:52:25 0 d—–w- c:\program files\Enigma Software Group
2009-12-16 22:32:37 0 d—–w- c:\programdata\Spybot - Search & Destroy
2009-12-16 22:32:37 0 d—–w- c:\program files\Spybot - Search & Destroy
2009-12-16 10:51:01 0 d—–w- c:\users\popo\F3C1DE9E5E164BA9B8547B53A45E3579.TMP
2009-12-16 09:18:58 0 d—–w- c:\program files\uTorrent
2009-12-16 05:41:57 0 d—–w- c:\program files\KAZAA
2009-12-16 05:41:57 0 d—–w- C:\My Downloads
2009-12-16 05:40:05 72192 —-a-w- c:\windows\system32\tcpip.exe
2009-12-16 05:21:57 187392 —-a-w- C:\gad.exe
2009-12-15 23:23:32 513 —-a-w- c:\windows\system32\sysservice.dll
2009-12-15 03:07:04 8 —-a-w- c:\windows\system32\DROPPEDFILEOK.tmp
2009-12-15 03:06:37 167936 —-a-w- c:\windows\hdn54.exe.vir
2009-12-15 03:06:25 168960 —-a-w- C:\fas.exe
2009-12-15 01:39:38 240 —-a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-12-15 01:32:31 0 d—–w- c:\programdata\SITEguard
2009-12-15 01:31:57 0 d—–w- c:\program files\common files\iS3
2009-12-15 01:31:55 0 d—–w- c:\programdata\STOPzilla!
2009-12-11 23:00:28 24064 —-a-w- c:\windows\system32\nshhttp.dll
2009-12-11 23:00:25 411648 —-a-w- c:\windows\system32\drivers\http.sys
2009-12-11 23:00:25 30720 —-a-w- c:\windows\system32\httpapi.dll
2009-12-11 00:47:20 369 —-a-w- C:\Up1.exe
2009-12-10 13:44:35 0 d—–w- C:\My Music
2009-12-10 12:45:29 369 —-a-w- C:\Up.exe
2009-12-09 23:06:36 0 d—–w- c:\windows\pss
2009-12-09 22:18:13 0 d—–w- c:\users\popo\appdata\roaming\Auslogics
2009-12-09 22:18:07 0 d—–w- c:\program files\Auslogics
2009-12-09 22:00:21 377344 —-a-w- c:\windows\system32\winhttp.dll
2009-12-09 21:29:09 243712 —-a-w- c:\windows\system32\rastls.dll
2009-11-25 23:03:10 2048 —-a-w- c:\windows\system32\tzres.dll
2009-11-25 06:30:36 1401856 —-a-w- c:\windows\system32\msxml6.dll
2009-11-25 06:30:35 1248768 —-a-w- c:\windows\system32\msxml3.dll
2009-11-25 06:30:25 714240 —-a-w- c:\windows\system32\timedate.cpl

==================== Find3M ====================

2009-12-23 11:18:30 51200 —-a-w- c:\windows\inf\infpub.dat
2009-12-23 11:18:30 143360 —-a-w- c:\windows\inf\infstrng.dat
2009-12-09 21:57:20 1635 —-a-w- c:\windows\option.dat
2009-11-21 06:40:20 916480 —-a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34:39 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:34:39 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-11-21 04:59:58 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-11-18 23:22:16 86016 —-a-w- c:\windows\inf\infstor.dat
2009-11-18 23:22:16 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-11-18 23:22:09 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-11-18 23:21:58 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-02 17:42:06 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-10-08 21:08:01 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-08 21:08:01 234496 —-a-w- c:\windows\system32\oleacc.dll
2009-10-08 21:07:59 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2009-10-02 09:27:05 83288 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2009-10-02 09:27:02 87352 —-a-w- c:\windows\system32\LMIinit.dll
2009-10-02 09:27:02 28984 —-a-w- c:\windows\system32\LMIport.dll
2009-10-01 01:02:17 2537472 —-a-w- c:\windows\system32\wpdshext.dll
2009-10-01 01:02:05 30208 —-a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-10-01 01:02:04 334848 —-a-w- c:\windows\system32\PortableDeviceApi.dll
2009-10-01 01:02:02 87552 —-a-w- c:\windows\system32\WPDShServiceObj.dll
2009-10-01 01:02:00 31232 —-a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-10-01 01:01:59 546816 —-a-w- c:\windows\system32\wpd_ci.dll
2009-10-01 01:01:59 160256 —-a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-10-01 01:01:56 60928 —-a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-10-01 01:01:56 350208 —-a-w- c:\windows\system32\WPDSp.dll
2009-10-01 01:01:56 196608 —-a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-10-01 01:01:56 100864 —-a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-10-01 01:01:54 81920 —-a-w- c:\windows\system32\wpdbusenum.dll
2009-10-01 01:01:50 226816 —-a-w- c:\windows\system32\WpdMtp.dll
2009-10-01 01:01:49 61952 —-a-w- c:\windows\system32\WpdMtpUS.dll
2009-10-01 01:01:49 33280 —-a-w- c:\windows\system32\WpdConns.dll
2008-10-21 01:54:06 174 –sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2008-10-20 16:20:01 76 –sh–r- c:\windows\CT4CET.bin
2007-02-21 19:49:52 8192 –sha-w- c:\windows\users\default\NTUSER.DAT

============= FINISH: 5:15:01.57 ===============

GMER is hanging my pc so i was not able to add the log from that, any other suggestions
Hi, Please try renaming GMER to svchost.exe and run it in safe mode. make sure you close all other programs including the internet. Disable all your security programs. Allow it to run uninterrupted. If you still have trouble running it, try running it in safe mode.
Hi, I give up. The application won't launch in the safe mode. I hate these Trojans. If anyone have any fix on this, please let me know. If not, i will have to reload windows again cause it is a nightmare for me every 5 minutes the message pops up. Thanks
Hi,

You don't need to give up that easily, we have other tools to use.

Please do the following:

Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI