This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] HELP NEED, Problems with google redirect and popups

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

HI everyone.

After numerous attempts to fix the google redirects and popup issue in firefox i am still having issues with these two problems.

Have ran atf cleaner and cc cleaner.

Malwarebytes came back clean:

Malwarebytes log:
Malwarebytes' Anti-Malware 1.44
Database version: 3544
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18865

1/11/2010 5:55:37 PM
mbam-log-2010-01-11 (17-55-37).txt

Scan type: Quick Scan
Objects scanned: 110482
Time elapsed: 4 minute(s), 0 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

gmer log:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-11 18:15:49
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\RG\AppData\Local\Temp\pxldrpoc.sys


—- System - GMER 1.0.15 —-

SSDT 9C68F2F4 ZwCreateThread
SSDT 9C68F2E0 ZwOpenProcess
SSDT 9C68F2E5 ZwOpenThread
SSDT 9C68F2EF ZwTerminateProcess

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy1 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy2 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy3 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy4 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy5 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy6 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy7 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy8 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy9 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\tdx \Device\Tcp tcpipBM.SYS (Bytemobile Kernel Network Provider/Bytemobile, Inc.)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume6 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy10 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume7 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy11 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy12 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy13 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy14 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy15 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy16 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy17 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy18 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \Driver\volsnap \Device\HarddiskVolumeShadowCopy19 SaibIa32.sys (Disk Filter Driver/Sonic Solutions)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device -> \Driver\atapi \Device\Harddisk0\DR0 85127841

—- Files - GMER 1.0.15 —-

File C:\Users\RG\AppData\Local\Temp\BABD.tmp 909312 bytes
File C:\Windows\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-


dds log:

DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 17:27:49.51 on Mon 01/11/2010
Internet Explorer: 8.0.6001.18865 BrowserJavaVersion: 1.6.0_17
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3326.2226 [GMT -6:00]


============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Program Files\Google\Update\1.2.183.13\GoogleCrashHandler.exe
C:\Program Files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe
C:\Program Files\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\alg.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\HP\HP Wireless Comfort Desktop\TSR\xDaemon.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Sprint\Sprint SmartView\RDVCHG.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\CyberLink\Shared Files\brs.exe
C:\Program Files\Roxio 2010\5.0\CPMonitor.exe
C:\Program Files\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe
C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\PX Storage Engine\VxBlockServer.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\System32\mobsync.exe
C:\Windows\explorer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\RG\Saved Games\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.lenovo.com
BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Foxit Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [HydraVisionDesktopManager] "c:\program files\ati technologies\hydravision\HydraDM.exe"
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [IDMan] c:\program files\internet download manager\IDMan.exe /onboot
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [Daemon] c:\program files\hp\hp wireless comfort desktop\tsr\xDaemon.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"
mRun: [Sprint SmartView] "c:\program files\sprint\sprint smartview\SprintSV.exe" -a
mRun: [RDVCHG] "c:\program files\sprint\sprint smartview\RDVCHG.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [RemoteControl9] "c:\program files\cyberlink\powerdvd9\PDVD9Serv.exe"
mRun: [PDVD9LanguageShortcut] "c:\program files\cyberlink\powerdvd9\language\Language.exe"
mRun: [BDRegion] c:\program files\cyberlink\shared files\brs.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\12.0\sharedcom\RoxWatchTray12.exe"
mRun: [CPMonitor] "c:\program files\roxio 2010\5.0\CPMonitor.exe"
mRun: [Desktop Disc Tool] "c:\program files\roxio 2010\roxio burn\RoxioBurnLauncher.exe"
mRun: [Google Updater] "c:\program files\google\google updater\GoogleUpdater.exe" -systray -startup
mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\users\rg\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\users\rg\appdata\roaming\micros~1\windows\startm~1\programs\startup\twibble.lnk - c:\program files\twibble\twibble.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\wirele~1.lnk - c:\program files\d-link\d-link dwa-556 xtreme n pcie desktop adapter\wirelesscm.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\internet download manager\IEGetVL.htm
IE: Download with IDM - c:\program files\internet download manager\IEExt.htm
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
LSP: bmnet.dll
Trusted Zone: cinemanow.com
Trusted Zone: qflix.com
Trusted Zone: roxio.com
Trusted Zone: sonic.com\redirect
Trusted Zone: sonic.com\redirect2
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper20073151.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~4\GoogleDesktopNetwork3.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\rg\appdata\roaming\mozilla\firefox\profiles\2ba353fa.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1808.5272\npCIDetect14.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\nplalaDl.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R0 SahdIa32;HDD Filter Driver;c:\windows\system32\drivers\SahdIa32.sys [2009-12-30 21488]
R0 SaibIa32;Volume Filter Driver;c:\windows\system32\drivers\SaibIa32.sys [2009-12-30 15856]
R1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\system32\drivers\jswpslwf.sys [2009-9-10 20384]
R1 SaibVd32;Virtual Disk Driver;c:\windows\system32\drivers\SaibVd32.sys [2009-12-30 25584]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2009/12/10 04:58:19];c:\program files\cyberlink\powerdvd9\000.fcl [2009-2-28 87536]
R2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269;Roxio SAIB Service;c:\program files\roxio\backontrack\disaster recovery\SaibSVC.exe [2009-6-2 457200]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-7-14 172032]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-9-10 108289]
R2 CinemaNow Service;CinemaNow Service;c:\program files\cinemanow\cinemanow media manager\CinemaNowSvc.exe [2009-6-23 127352]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2009-6-29 100368]
R3 HpWkm001;USB K + M Packet Filter Driver;c:\windows\system32\drivers\HpWkm001.sys [2009-9-10 11264]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-12-31 133104]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files\common files\roxio shared\12.0\sharedcom\RoxWatch12.exe [2009-7-24 219632]
S3 CASprint;Sprint Con App Svc;c:\program files\sprint\sprint smartview\ConAppsSvc.exe [2009-5-26 124160]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2009-12-31 30192]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\d-link\d-link dwa-556 xtreme n pcie desktop adapter\jswpsapi.exe [2009-9-10 954368]
S3 RoxMediaDB12;RoxMediaDB12;c:\program files\common files\roxio shared\12.0\sharedcom\RoxMediaDB12.exe [2009-7-24 1116656]

=============== Created Last 30 ================

2010-01-11 17:23 292,740,058 a——- c:\windows\MEMORY.DMP
2010-01-06 08:14 –d—– c:\programdata\NOS
2010-01-06 08:02 –dsh— C:\$RECYCLE.BIN
2010-01-06 07:54 261,632 a——- c:\windows\PEV.exe
2010-01-06 07:54 161,792 a——- c:\windows\SWREG.exe
2010-01-06 07:54 98,816 a——- c:\windows\sed.exe
2010-01-06 07:54 77,312 a——- c:\windows\MBR.exe
2010-01-06 05:00 –d—– c:\users\rg\appdata\roaming\Malwarebytes
2010-01-06 05:00 –d—– c:\programdata\Malwarebytes
2010-01-06 05:00 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-01-06 05:00 –d—– c:\progra~2\Malwarebytes
2010-01-06 01:28 –d—– c:\programdata\Lavasoft
2010-01-06 00:22 –d—– c:\program files\CCleaner
2010-01-05 18:01 –d—– c:\users\rg\appdata\roaming\IDM
2010-01-05 18:01 –d—– c:\users\rg\appdata\roaming\DMCache
2010-01-05 18:01 –d—– c:\program files\Internet Download Manager
2010-01-01 18:25 –d—– c:\users\rg\appdata\roaming\Participatory Culture Foundation
2010-01-01 18:25 –d—– c:\program files\Participatory Culture Foundation
2009-12-31 17:58 –d—– c:\users\rg\appdata\roaming\Intel
2009-12-31 17:28 –d—– c:\programdata\Google
2009-12-31 17:28 –d—– c:\programdata\Google Updater
2009-12-30 03:17 –d—– c:\programdata\BIAS
2009-12-30 03:17 –d—– c:\progra~2\BIAS
2009-12-30 03:11 –d—– c:\users\rg\appdata\roaming\LightZone
2009-12-30 03:00 –d—– c:\program files\MSXML 4.0
2009-12-30 02:50 –d—– c:\users\rg\appdata\roaming\Macrovision
2009-12-30 02:37 –d—– c:\program files\common files\MSSoap
2009-12-30 02:37 –d—– c:\program files\BIAS
2009-12-30 02:37 –d—– C:\Binaries
2009-12-30 02:37 –d—– c:\program files\common files\eSellerate
2009-12-30 02:37 –d—– c:\program files\LightZone 3
2009-12-30 02:21 –d—– c:\programdata\Uninstall
2009-12-30 02:21 –d—– c:\progra~2\Uninstall
2009-12-30 02:19 25,584 ——– c:\windows\system32\drivers\SaibVd32.sys
2009-12-30 02:19 21,488 ——– c:\windows\system32\drivers\SahdIa32.sys
2009-12-30 02:19 15,856 ——– c:\windows\system32\drivers\SaibIa32.sys
2009-12-30 02:18 –d—– c:\programdata\CinemaNow
2009-12-30 02:18 –d—– c:\progra~2\CinemaNow
2009-12-30 02:18 –d—– c:\program files\CinemaNow
2009-12-30 02:17 –d—– c:\users\rg\appdata\roaming\Simple Star
2009-12-30 02:17 –d—– c:\programdata\PhotoShow Shared Assets
2009-12-30 02:17 –d—– c:\progra~2\PhotoShow Shared Assets
2009-12-30 02:17 –d—– c:\program files\Roxio
2009-12-30 02:16 –d—– c:\programdata\eSellerate
2009-12-30 02:16 –d—– c:\progra~2\eSellerate
2009-12-30 02:16 –d—– c:\programdata\SmartSound Software Inc
2009-12-30 02:16 –d—– c:\program files\SmartSound Software
2009-12-30 02:16 –d—– c:\progra~2\SmartSound Software Inc
2009-12-30 02:14 –d—– c:\programdata\Sonic
2009-12-30 02:09 –d—– c:\programdata\Roxio
2009-12-30 02:09 –d—– c:\programdata\Macrovision
2009-12-30 02:09 –d—– c:\program files\Roxio 2010
2009-12-30 02:09 –d—– c:\program files\common files\Sonic Shared
2009-12-30 02:08 2,297,552 a——- c:\windows\system32\d3dx9_26.dll
2009-12-30 02:03 –d—– c:\users\rg\appdata\roaming\Roxio Log Files
2009-12-29 21:18 –d—– c:\program files\RAR Password Recovery Magic
2009-12-16 20:25 –d—– c:\programdata\Apple Computer
2009-12-16 20:24 –d—– c:\programdata\Apple

==================== Find3M ====================

2009-12-30 02:15 51,200 a——- c:\windows\inf\infpub.dat
2009-12-30 02:15 143,360 a——- c:\windows\inf\infstrng.dat
2009-12-30 02:15 143,360 a——- c:\windows\inf\infstor.dat
2009-12-10 04:56 505,128 a——- c:\windows\system32\msvcp71.dll
2009-12-10 04:56 353,576 a——- c:\windows\system32\msvcr71.dll
2009-12-08 01:56 56,816 a——- c:\windows\system32\drivers\avgntflt.sys
2009-11-21 00:40 916,480 a——- c:\windows\system32\wininet.dll
2009-11-21 00:34 109,056 a——- c:\windows\system32\iesysprep.dll
2009-11-21 00:34 71,680 a——- c:\windows\system32\iesetup.dll
2009-11-20 22:59 133,632 a——- c:\windows\system32\ieUnatt.exe
2009-11-17 03:02 665,600 a——- c:\windows\inf\drvindex.dat
2009-11-17 03:02 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-09 06:31 24,064 a——- c:\windows\system32\nshhttp.dll
2009-11-09 06:30 30,720 a——- c:\windows\system32\httpapi.dll
2009-11-02 20:42 195,456 ——– c:\windows\system32\MpSigStub.exe
2009-10-29 03:17 2,048 a——- c:\windows\system32\tzres.dll
2008-01-20 20:43 174 a–sh— c:\program files\desktop.ini
2006-11-02 06:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 06:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 06:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 06:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 03:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 03:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 03:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 03:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
2009-09-14 23:16 245,760 a–sh— c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\ietldcache\index.dat

============= FINISH: 17:29:12.00 ===============

Thanks in advance.
Hi,

If you already have a copy of ComboFix, please delete it.

Please download ComboFix to your desktop from one of these locations. You must rename it before saving it. Save it to your desktop.
Link 1
Link 2
Link 3

[external image: Posted Image]

[external image: Posted Image]

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on Combo-Fix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making IE the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
thanks for your quick reply.
here is the combofix log:

ComboFix 10-01-11.01 - RG 01/11/2010 18:39:41.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3326.1978 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2009-12-12 to 2010-01-12 )))))))))))))))))))))))))))))))
.

2010-01-12 00:44 . 2010-01-12 00:44 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-01-12 00:44 . 2010-01-12 00:44 ——– d—–w- c:\users\Mcx1\AppData\Local\temp
2010-01-12 00:44 . 2010-01-12 00:44 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-01-11 23:50 . 2010-01-11 23:50 5115824 —-a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-11 23:49 . 2010-01-07 22:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-11 23:49 . 2010-01-07 22:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-11 23:16 . 2010-01-11 23:16 ——– d—–w- c:\program files\ERUNT
2010-01-08 07:29 . 2010-01-08 07:29 ——– d—–w- c:\windows\Sun
2010-01-06 14:15 . 2010-01-06 14:15 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-06 14:14 . 2010-01-06 14:16 ——– d—–w- c:\users\RG\AppData\Local\Adobe
2010-01-06 14:14 . 2010-01-06 14:14 86016 —-a-w- c:\programdata\NOS\Adobe_Downloads\arh.exe
2010-01-06 14:14 . 2010-01-07 05:29 ——– d—–w- c:\programdata\NOS
2010-01-06 11:00 . 2010-01-06 11:00 ——– d—–w- c:\users\RG\AppData\Roaming\Malwarebytes
2010-01-06 11:00 . 2010-01-11 23:50 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-06 11:00 . 2010-01-06 11:00 ——– d—–w- c:\programdata\Malwarebytes
2010-01-06 07:30 . 2010-01-06 09:07 ——– dc—-w- c:\windows\system32\DRVSTORE
2010-01-06 07:28 . 2010-01-06 09:07 ——– d—–w- c:\programdata\Lavasoft
2010-01-06 06:22 . 2010-01-06 06:22 ——– d—–w- c:\program files\CCleaner
2010-01-06 00:02 . 2010-01-06 00:02 198064 —-a-w- c:\users\RG\AppData\Roaming\IDM\idmmzcc3\components\idmmzcc.dll
2010-01-06 00:01 . 2010-01-11 23:47 ——– d—–w- c:\users\RG\AppData\Roaming\DMCache
2010-01-06 00:01 . 2010-01-06 00:02 ——– d—–w- c:\users\RG\AppData\Roaming\IDM
2010-01-06 00:01 . 2010-01-06 00:25 ——– d—–w- c:\program files\Internet Download Manager
2010-01-02 08:34 . 2010-01-02 08:34 1230960 —-a-w- c:\programdata\Google\Google Toolbar\Component\GoogleCld_3F6C343113693CD9.dll
2010-01-02 00:26 . 2010-01-02 00:26 ——– d—–w- c:\users\RG\AppData\Roaming\gtk-2.0
2010-01-02 00:25 . 2010-01-02 00:25 ——– d—–w- c:\users\RG\AppData\Roaming\Participatory Culture Foundation
2010-01-02 00:25 . 2010-01-02 00:25 ——– d—–w- c:\program files\Participatory Culture Foundation
2009-12-31 23:58 . 2009-12-31 23:58 ——– d—–w- c:\users\RG\AppData\Roaming\Intel
2009-12-31 23:28 . 2010-01-02 08:34 ——– d—–w- c:\users\RG\AppData\Local\Google
2009-12-31 23:28 . 2009-12-31 23:59 ——– d—–w- c:\programdata\Google Updater
2009-12-31 23:28 . 2010-01-01 04:36 ——– d—–w- c:\program files\Google
2009-12-30 09:17 . 2009-12-30 09:17 ——– d—–w- c:\programdata\BIAS
2009-12-30 09:11 . 2009-12-30 09:11 ——– d—–w- c:\users\RG\AppData\Roaming\LightZone
2009-12-30 09:00 . 2009-12-30 09:00 ——– d—–w- c:\program files\MSXML 4.0
2009-12-30 08:50 . 2009-12-30 08:50 ——– d—–w- c:\users\RG\AppData\Roaming\Macrovision
2009-12-30 08:50 . 2009-12-30 09:25 ——– d—–w- c:\users\RG\AppData\Roaming\Roxio
2009-12-30 08:50 . 2009-12-30 08:50 ——– d—–w- c:\users\RG\AppData\Local\Sonic_Solutions
2009-12-30 08:38 . 2009-12-30 08:38 10134 —-a-r- c:\users\RG\AppData\Roaming\Microsoft\Installer\{38F48AED-66D8-464C-993E-C7296C7A199B}\ARPPRODUCTICON.exe
2009-12-30 08:37 . 2009-12-30 08:37 ——– d—–w- c:\program files\BIAS
2009-12-30 08:37 . 2009-12-30 08:37 ——– d—–w- C:\Binaries
2009-12-30 08:37 . 2009-12-30 08:37 ——– d—–w- c:\program files\Common Files\eSellerate
2009-12-30 08:37 . 2009-12-30 08:37 ——– d—–w- c:\program files\LightZone 3
2009-12-30 08:21 . 2009-12-30 08:21 ——– d—–w- c:\programdata\Uninstall
2009-12-30 08:21 . 2009-07-22 21:14 4890096 —-a-w- c:\programdata\Uninstall\{89A15676-78AE-4D51-BF5B-DEE3E0D46C94}\setup.exe
2009-12-30 08:21 . 2009-07-22 09:53 594432 —-a-w- c:\programdata\Uninstall\{89A15676-78AE-4D51-BF5B-DEE3E0D46C94}\bin\setupresENU.dll
2009-12-30 08:21 . 2009-05-26 14:10 190960 —-a-w- c:\programdata\Uninstall\{89A15676-78AE-4D51-BF5B-DEE3E0D46C94}\bin\rsl.dll
2009-12-30 08:19 . 2009-06-02 07:00 25584 ——w- c:\windows\system32\drivers\SaibVd32.sys
2009-12-30 08:09 . 2009-12-30 08:17 ——– d—–w- c:\program files\Common Files\Sonic Shared
2009-12-30 08:08 . 2005-05-26 21:34 2297552 —-a-w- c:\windows\system32\d3dx9_26.dll
2009-12-30 08:03 . 2009-12-30 08:36 ——– d—–w- c:\users\RG\AppData\Roaming\Roxio Log Files
2009-12-30 03:18 . 2009-12-30 03:38 ——– d—–w- c:\program files\RAR Password Recovery Magic
2009-12-17 02:28 . 2009-12-17 02:28 ——– d—–w- c:\users\RG\AppData\Local\Apple Computer
2009-12-17 02:25 . 2009-12-17 02:25 ——– d—–w- c:\program files\QuickTime
2009-12-17 02:25 . 2009-12-17 02:25 ——– d—–w- c:\programdata\Apple Computer
2009-12-17 02:24 . 2009-12-17 02:24 ——– d—–w- c:\program files\Common Files\Apple
2009-12-17 02:24 . 2009-12-17 02:24 ——– d—–w- c:\users\RG\AppData\Local\Apple
2009-12-17 02:24 . 2009-12-17 02:24 ——– d—–w- c:\program files\Apple Software Update
2009-12-17 02:24 . 2009-12-17 02:24 ——– d—–w- c:\programdata\Apple

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-08 12:35 . 2009-09-18 04:20 ——– d—–w- c:\users\RG\AppData\Roaming\vlc
2010-01-07 05:30 . 2009-12-30 08:14 ——– d—–w- c:\programdata\Sonic
2010-01-06 14:14 . 2009-11-05 06:34 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-01-06 13:22 . 2009-09-10 06:26 2032 —-a-w- c:\users\RG\AppData\Local\d3d9caps.dat
2010-01-05 22:54 . 2009-09-10 08:14 ——– d—–w- c:\program files\ATI
2010-01-05 09:48 . 2009-12-30 08:18 ——– d—–w- c:\programdata\CinemaNow
2010-01-04 22:25 . 2009-10-15 05:25 1 —-a-w- c:\users\RG\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-12-31 23:58 . 2009-09-10 06:42 ——– d—–w- c:\program files\Intel
2009-12-30 09:14 . 2009-12-30 08:16 ——– d—–w- c:\programdata\SmartSound Software Inc
2009-12-30 08:50 . 2009-09-10 06:26 68224 —-a-w- c:\users\RG\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-30 08:37 . 2009-12-30 08:16 ——– d—–w- c:\program files\SmartSound Software
2009-12-30 08:21 . 2009-09-11 07:21 ——– d—–w- c:\program files\Common Files\PX Storage Engine
2009-12-30 08:21 . 2009-09-10 06:39 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-30 08:19 . 2009-12-30 08:09 ——– d—–w- c:\program files\Roxio 2010
2009-12-30 08:18 . 2009-12-30 08:17 ——– d—–w- c:\program files\Roxio
2009-12-30 08:18 . 2009-12-30 08:18 ——– d—–w- c:\program files\CinemaNow
2009-12-30 08:17 . 2009-12-30 08:17 ——– d—–w- c:\users\RG\AppData\Roaming\Simple Star
2009-12-30 08:17 . 2009-12-30 08:17 ——– d—–w- c:\programdata\PhotoShow Shared Assets
2009-12-30 08:16 . 2009-12-30 08:16 ——– d—–w- c:\programdata\eSellerate
2009-12-30 08:16 . 2009-09-10 06:44 ——– d—–w- c:\program files\Common Files\InstallShield
2009-12-30 08:15 . 2009-12-30 08:09 ——– d—–w- c:\program files\Common Files\Roxio Shared
2009-12-30 08:12 . 2009-12-30 08:09 ——– d—–w- c:\programdata\Roxio
2009-12-30 08:09 . 2009-12-30 08:09 ——– d—–w- c:\programdata\Macrovision
2009-12-30 08:09 . 2009-12-30 08:09 10134 —-a-r- c:\users\RG\AppData\Roaming\Microsoft\Installer\{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}\ARPPRODUCTICON.exe
2009-12-10 11:02 . 2009-12-10 11:02 53319 —-a-w- c:\programdata\Temp\{8C20787A-7402-4FA7-BF25-6E5750930FDC}\PostBuild.exe
2009-12-10 10:58 . 2009-09-10 08:25 ——– d—–w- c:\programdata\CyberLink
2009-12-10 10:58 . 2009-12-10 10:57 ——– d—–w- c:\program files\CyberLink
2009-12-10 10:58 . 2009-12-10 10:58 ——– d—–w- c:\program files\Common Files\CyberLink
2009-12-10 10:56 . 2009-11-18 10:27 53319 —-a-w- c:\programdata\Temp\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}\PostBuild.exe
2009-12-10 10:56 . 2009-09-10 08:23 505128 —-a-w- c:\windows\system32\msvcp71.dll
2009-12-10 10:56 . 2009-09-10 08:23 353576 —-a-w- c:\windows\system32\msvcr71.dll
2009-12-09 09:17 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-12-08 07:56 . 2009-09-10 08:58 56816 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-11-26 11:09 . 2009-09-10 08:28 ——– d—–w- c:\users\RG\AppData\Roaming\CyberLink
2009-11-21 06:40 . 2009-12-09 01:35 916480 —-a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-09 01:35 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:34 . 2009-12-09 01:35 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-11-21 04:59 . 2009-12-09 01:35 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-11-20 11:08 . 2009-11-05 06:34 38784 —-a-w- c:\users\RG\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-20 11:08 . 2009-11-05 06:34 38784 —-a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-18 20:14 . 2009-09-16 07:06 ——– d—–w- c:\program files\Java
2009-11-18 10:10 . 2009-09-18 04:20 ——– d—–w- c:\users\RG\AppData\Roaming\dvdcss
2009-11-17 09:02 . 2009-11-17 09:02 ——– d—–w- c:\program files\Windows Portable Devices
2009-11-17 09:02 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-11-17 09:02 . 2009-11-17 09:02 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-09 12:31 . 2009-12-09 09:01 24064 —-a-w- c:\windows\system32\nshhttp.dll
2009-11-09 12:30 . 2009-12-09 09:01 30720 —-a-w- c:\windows\system32\httpapi.dll
2009-11-09 10:36 . 2009-12-09 09:01 411648 —-a-w- c:\windows\system32\drivers\http.sys
2009-11-03 02:42 . 2009-10-03 11:57 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-10-29 10:44 . 2009-09-10 08:23 53319 —-a-w- c:\programdata\Temp\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\PostBuild.exe
2009-10-29 09:17 . 2009-11-25 09:00 2048 —-a-w- c:\windows\system32\tzres.dll
2009-10-15 19:52 . 2009-10-15 19:52 593920 —-a-w- c:\users\RG\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\pmv305hw-0910150-0-main.dll
2009-10-15 19:52 . 2009-10-15 19:52 319488 —-a-w- c:\users\RG\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe
2009-12-31 23:29 . 2009-12-31 23:29 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-01-06_14.00.33 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:58 . 2010-01-11 23:40 46794 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2010-01-11 23:40 78544 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-09-10 06:26 . 2010-01-06 13:41 49152 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-09-10 06:26 . 2010-01-11 23:37 49152 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-01-06 19:55 . 2010-01-06 19:48 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Internet Explorer\UserData\index.dat
+ 2010-01-06 16:01 . 2010-01-06 16:06 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012010010620100107\index.dat
+ 2009-09-10 06:26 . 2010-01-11 23:37 65536 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-01-06 16:01 . 2010-01-06 16:06 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat
- 2009-09-15 05:36 . 2010-01-06 09:09 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-09-15 05:36 . 2010-01-11 23:39 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-09-15 05:36 . 2010-01-11 23:39 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-09-15 05:36 . 2010-01-06 09:09 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-09-15 05:36 . 2010-01-11 23:39 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-09-15 05:36 . 2010-01-06 09:09 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-09-16 06:10 . 2010-01-06 13:41 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-09-16 06:10 . 2010-01-11 23:38 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-09-16 06:10 . 2010-01-11 23:38 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-09-16 06:10 . 2010-01-06 13:41 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-09-16 06:10 . 2010-01-06 13:41 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-09-16 06:10 . 2010-01-11 23:38 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-01-06 14:14 . 2010-01-06 14:14 24576 c:\windows\Installer\7a455.msi
+ 2010-01-06 14:14 . 2010-01-06 14:14 27648 c:\windows\Installer\7a44f.msi
+ 2009-09-10 06:27 . 2010-01-11 23:40 6924 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-81399222-1990902642-3393529205-1000_UserData.bin
+ 2010-01-11 22:47 . 2010-01-11 22:48 1502 c:\windows\SoftwareDistribution\EventCache\{974AA2B9-8C76-4299-B17A-FF89607B73DF}.bin
+ 2010-01-11 23:37 . 2010-01-11 23:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-01-06 13:41 . 2010-01-06 13:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-01-06 13:41 . 2010-01-06 13:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-01-11 23:37 . 2010-01-11 23:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2010-01-11 23:43 595446 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2010-01-06 13:47 595446 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2010-01-11 23:43 101144 c:\windows\System32\perfc009.dat
- 2006-11-02 10:33 . 2010-01-06 13:47 101144 c:\windows\System32\perfc009.dat
- 2006-11-02 12:47 . 2010-01-06 13:41 285600 c:\windows\System32\FNTCACHE.DAT
+ 2006-11-02 12:47 . 2010-01-11 23:37 285600 c:\windows\System32\FNTCACHE.DAT
- 2009-09-12 22:03 . 2010-01-06 13:41 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-09-12 22:03 . 2010-01-12 00:02 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-09-10 06:26 . 2010-01-11 23:37 311296 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-01-11 23:34 . 2005-10-20 18:02 163328 c:\windows\ERDNT\1-11-2010\ERDNT.EXE
+ 2010-01-06 14:16 . 2010-01-06 14:16 3940352 c:\windows\Installer\7a45b.msi
+ 2010-01-11 23:34 . 2010-01-11 23:34 2572288 c:\windows\ERDNT\1-11-2010\Users\00000002\UsrClass.dat
+ 2010-01-11 23:34 . 2010-01-11 23:34 1765376 c:\windows\ERDNT\1-11-2010\Users\00000001\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-11-18 19:58 333192 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-18 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-18 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"HydraVisionDesktopManager"="c:\program files\ATI Technologies\HydraVision\HydraDM.exe" [2008-12-01 380928]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-12-31 39408]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-11-13 3171760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Daemon"="c:\program files\HP\HP Wireless Comfort Desktop\TSR\xDaemon.exe" [2008-08-01 356352]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-08 6037504]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-15 98304]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]
"Sprint SmartView"="c:\program files\Sprint\Sprint SmartView\SprintSV.exe" [2009-05-26 75008]
"RDVCHG"="c:\program files\Sprint\Sprint SmartView\RDVCHG.exe" [2009-05-26 316672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"RemoteControl9"="c:\program files\CyberLink\PowerDVD9\PDVD9Serv.exe" [2009-02-16 87336]
"PDVD9LanguageShortcut"="c:\program files\CyberLink\PowerDVD9\Language\Language.exe" [2008-10-14 50472]
"BDRegion"="c:\program files\Cyberlink\Shared Files\brs.exe" [2009-03-01 75048]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe" [2009-07-24 240112]
"CPMonitor"="c:\program files\Roxio 2010\5.0\CPMonitor.exe" [2009-07-21 84464]
"Desktop Disc Tool"="c:\program files\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe" [2009-06-23 494064]
"Google Updater"="c:\program files\Google\Google Updater\GoogleUpdater.exe" [2009-12-31 160752]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-12-31 122880]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-12-31 30192]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]

c:\users\RG\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-12-15 384000]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Wireless Connection Manager.lnk - c:\program files\D-Link\D-Link DWA-556 Xtreme N PCIe Desktop Adapter\wirelesscm.exe [2009-9-10 30143744]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~4\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):ec,97,db,7e,9b,35,ca,01

R0 SahdIa32;HDD Filter Driver;c:\windows\System32\drivers\SahdIa32.sys [12/30/2009 2:19 AM 21488]
R0 SaibIa32;Volume Filter Driver;c:\windows\System32\drivers\SaibIa32.sys [12/30/2009 2:19 AM 15856]
R1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\System32\drivers\jswpslwf.sys [9/10/2009 10:47 PM 20384]
R1 SaibVd32;Virtual Disk Driver;c:\windows\System32\drivers\SaibVd32.sys [12/30/2009 2:19 AM 25584]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2009/12/10 04:58];c:\program files\CyberLink\PowerDVD9\000.fcl [2/28/2009 7:40 PM 87536]
R2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269;Roxio SAIB Service;c:\program files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe [6/2/2009 7:05 PM 457200]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\System32\atiesrxx.exe [7/14/2009 8:14 PM 172032]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [9/10/2009 2:58 AM 108289]
R2 CinemaNow Service;CinemaNow Service;c:\program files\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe [6/23/2009 5:40 PM 127352]
R3 HpWkm001;USB K + M Packet Filter Driver;c:\windows\System32\drivers\HpWkm001.sys [9/10/2009 12:39 AM 11264]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/31/2009 5:29 PM 133104]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe [7/24/2009 8:33 AM 219632]
S3 CASprint;Sprint Con App Svc;c:\program files\Sprint\Sprint SmartView\ConAppsSvc.exe [5/26/2009 4:48 PM 124160]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [1/20/2008 8:23 PM 21504]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [12/31/2009 5:29 PM 30192]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\D-Link\D-Link DWA-556 Xtreme N PCIe Desktop Adapter\jswpsapi.exe [9/10/2009 10:47 PM 954368]
S3 RoxMediaDB12;RoxMediaDB12;c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe [7/24/2009 8:33 AM 1116656]

— Other Services/Drivers In Memory —

*Deregistered* - pxldrpoc

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-01-11 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-31 23:28]

2010-01-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-31 23:29]

2010-01-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-31 23:29]

2010-01-11 c:\windows\Tasks\User_Feed_Synchronization-{46A75F5E-2D28-4C96-9889-39C352AFCD88}.job
- c:\windows\system32\msfeedssync.exe [2009-12-09 04:59]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.lenovo.com
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
LSP: bmnet.dll
Trusted Zone: cinemanow.com
Trusted Zone: qflix.com
Trusted Zone: roxio.com
Trusted Zone: sonic.com\redirect
Trusted Zone: sonic.com\redirect2
FF - ProfilePath - c:\users\RG\AppData\Roaming\Mozilla\Firefox\Profiles\2ba353fa.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1808.5272\npCIDetect14.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nplalaDl.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-11 18:44
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys SahdIa32.sys acpi.sys hal.dll >>UNKNOWN [0x85127841]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0x8a7b9d24
\Driver\ACPI -> acpi.sys @ 0x80697d68
\Driver\atapi -> ataport.SYS @ 0x807a6a2c
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{B154377D-700F-42cc-9474-23858FBDF4BD}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD9\000.fcl"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(676)
c:\windows\system32\bmnet.dll

- - - - - - - > 'Explorer.exe'(5148)
c:\program files\ATI Technologies\HydraVision\HydraDMH.dll
.
Completion time: 2010-01-11 18:46:53
ComboFix-quarantined-files.txt 2010-01-12 00:46
ComboFix2.txt 2010-01-06 14:02

Pre-Run: 440,162,799,616 bytes free
Post-Run: 440,270,626,816 bytes free

- - End Of File - - FCF86F96B985C8388F389888EEB774A4
Hi,

Please post the contents of C:\QooBox\ComboFix2.txt.

We need to run a batch file.
  • Copy the contents of the Code Box below to Notepad.
  • Name the file as look.bat
  • Change the Save as Type to All Files
  • and Save it on your Desktop
@echo off
PEV C:\atapi.sys > "%userprofile%\Desktop\log.txt"
start notepad "%userprofile%\Desktop\log.txt"
del /Q %0
Then double-click on the look.bat file. A log will open, please post the contents of that log in your next reply (unless blank).
Here is combofix text:

ComboFix 10-01-04.01 - RG 01/06/2010 7:55.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3326.2314 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2009-12-06 to 2010-01-06 )))))))))))))))))))))))))))))))
.

2010-01-06 11:00 . 2010-01-06 11:00 ——– d—–w- c:\users\RG\AppData\Roaming\Malwarebytes
2010-01-06 11:00 . 2009-12-30 20:55 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-06 11:00 . 2010-01-06 11:00 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-06 11:00 . 2010-01-06 11:00 ——– d—–w- c:\programdata\Malwarebytes
2010-01-06 11:00 . 2009-12-30 20:54 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-06 07:30 . 2010-01-06 09:07 ——– dc—-w- c:\windows\system32\DRVSTORE
2010-01-06 07:28 . 2010-01-06 09:07 ——– d—–w- c:\programdata\Lavasoft
2010-01-06 06:22 . 2010-01-06 06:22 ——– d—–w- c:\program files\CCleaner
2010-01-06 00:02 . 2010-01-06 00:02 198064 —-a-w- c:\users\RG\AppData\Roaming\IDM\idmmzcc3\components\idmmzcc.dll
2010-01-06 00:01 . 2010-01-06 13:42 ——– d—–w- c:\users\RG\AppData\Roaming\DMCache
2010-01-06 00:01 . 2010-01-06 00:02 ——– d—–w- c:\users\RG\AppData\Roaming\IDM
2010-01-06 00:01 . 2010-01-06 00:25 ——– d—–w- c:\program files\Internet Download Manager
2010-01-02 08:34 . 2010-01-02 08:34 1230960 —-a-w- c:\programdata\Google\Google Toolbar\Component\GoogleCld_3F6C343113693CD9.dll
2010-01-02 00:26 . 2010-01-02 00:26 ——– d—–w- c:\users\RG\AppData\Roaming\gtk-2.0
2010-01-02 00:25 . 2010-01-02 00:25 ——– d—–w- c:\users\RG\AppData\Roaming\Participatory Culture Foundation
2010-01-02 00:25 . 2010-01-02 00:25 ——– d—–w- c:\program files\Participatory Culture Foundation
2009-12-31 23:58 . 2009-12-31 23:58 ——– d—–w- c:\users\RG\AppData\Roaming\Intel
2009-12-31 23:28 . 2010-01-02 08:34 ——– d—–w- c:\users\RG\AppData\Local\Google
2009-12-31 23:28 . 2009-12-31 23:59 ——– d—–w- c:\programdata\Google Updater
2009-12-31 23:28 . 2010-01-01 04:36 ——– d—–w- c:\program files\Google
2009-12-30 09:17 . 2009-12-30 09:17 ——– d—–w- c:\programdata\BIAS
2009-12-30 09:11 . 2009-12-30 09:11 ——– d—–w- c:\users\RG\AppData\Roaming\LightZone
2009-12-30 09:00 . 2009-12-30 09:00 ——– d—–w- c:\program files\MSXML 4.0
2009-12-30 08:50 . 2009-12-30 08:50 ——– d—–w- c:\users\RG\AppData\Roaming\Macrovision
2009-12-30 08:50 . 2009-12-30 09:25 ——– d—–w- c:\users\RG\AppData\Roaming\Roxio
2009-12-30 08:50 . 2009-12-30 08:50 ——– d—–w- c:\users\RG\AppData\Local\Sonic_Solutions
2009-12-30 08:38 . 2009-12-30 08:38 10134 —-a-r- c:\users\RG\AppData\Roaming\Microsoft\Installer\{38F48AED-66D8-464C-993E-C7296C7A199B}\ARPPRODUCTICON.exe
2009-12-30 08:37 . 2009-12-30 08:37 ——– d—–w- c:\program files\BIAS
2009-12-30 08:37 . 2009-12-30 08:37 ——– d—–w- C:\Binaries
2009-12-30 08:37 . 2009-12-30 08:37 ——– d—–w- c:\program files\Common Files\eSellerate
2009-12-30 08:37 . 2009-12-30 08:37 ——– d—–w- c:\program files\LightZone 3
2009-12-30 08:21 . 2009-12-30 08:21 ——– d—–w- c:\programdata\Uninstall
2009-12-30 08:21 . 2009-07-22 21:14 4890096 —-a-w- c:\programdata\Uninstall\{89A15676-78AE-4D51-BF5B-DEE3E0D46C94}\setup.exe
2009-12-30 08:21 . 2009-07-22 09:53 594432 —-a-w- c:\programdata\Uninstall\{89A15676-78AE-4D51-BF5B-DEE3E0D46C94}\bin\setupresENU.dll
2009-12-30 08:21 . 2009-05-26 14:10 190960 —-a-w- c:\programdata\Uninstall\{89A15676-78AE-4D51-BF5B-DEE3E0D46C94}\bin\rsl.dll
2009-12-30 08:19 . 2009-06-02 07:00 25584 ——w- c:\windows\system32\drivers\SaibVd32.sys
2009-12-30 08:09 . 2009-12-30 08:17 ——– d—–w- c:\program files\Common Files\Sonic Shared
2009-12-30 08:08 . 2005-05-26 21:34 2297552 —-a-w- c:\windows\system32\d3dx9_26.dll
2009-12-30 08:03 . 2009-12-30 08:36 ——– d—–w- c:\users\RG\AppData\Roaming\Roxio Log Files
2009-12-30 03:18 . 2009-12-30 03:38 ——– d—–w- c:\program files\RAR Password Recovery Magic
2009-12-17 02:28 . 2009-12-17 02:28 ——– d—–w- c:\users\RG\AppData\Local\Apple Computer
2009-12-17 02:25 . 2009-12-17 02:25 ——– d—–w- c:\program files\QuickTime
2009-12-17 02:25 . 2009-12-17 02:25 ——– d—–w- c:\programdata\Apple Computer
2009-12-17 02:24 . 2009-12-17 02:24 ——– d—–w- c:\program files\Common Files\Apple
2009-12-17 02:24 . 2009-12-17 02:24 ——– d—–w- c:\users\RG\AppData\Local\Apple
2009-12-17 02:24 . 2009-12-17 02:24 ——– d—–w- c:\program files\Apple Software Update
2009-12-17 02:24 . 2009-12-17 02:24 ——– d—–w- c:\programdata\Apple
2009-12-10 11:02 . 2009-12-10 11:02 53319 —-a-w- c:\programdata\Temp\{8C20787A-7402-4FA7-BF25-6E5750930FDC}\PostBuild.exe
2009-12-10 10:58 . 2009-12-10 11:33 ——– d—–w- c:\users\RG\AppData\Local\PowerDVDCinema
2009-12-10 10:58 . 2009-12-10 10:58 ——– d—–w- c:\users\RG\AppData\Local\PowerDVDCox
2009-12-10 10:58 . 2009-12-10 10:58 ——– d—–w- c:\program files\Common Files\CyberLink
2009-12-10 10:57 . 2009-12-10 10:58 ——– d—–w- c:\program files\CyberLink
2009-12-09 09:01 . 2009-11-09 12:31 24064 —-a-w- c:\windows\system32\nshhttp.dll
2009-12-09 09:01 . 2009-11-09 12:30 30720 —-a-w- c:\windows\system32\httpapi.dll
2009-12-09 09:01 . 2009-11-09 10:36 411648 —-a-w- c:\windows\system32\drivers\http.sys
2009-12-09 01:36 . 2009-08-24 11:36 377344 —-a-w- c:\windows\system32\winhttp.dll
2009-12-09 01:32 . 2009-10-07 11:36 243712 —-a-w- c:\windows\system32\rastls.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-06 13:42 . 2009-12-30 08:14 ——– d—–w- c:\programdata\Sonic
2010-01-06 13:22 . 2009-09-10 06:26 2032 —-a-w- c:\users\RG\AppData\Local\d3d9caps.dat
2010-01-06 07:27 . 2009-09-18 04:20 ——– d—–w- c:\users\RG\AppData\Roaming\vlc
2010-01-05 22:54 . 2009-09-10 08:14 ——– d—–w- c:\program files\ATI
2010-01-05 09:48 . 2009-12-30 08:18 ——– d—–w- c:\programdata\CinemaNow
2010-01-04 22:25 . 2009-10-15 05:25 1 —-a-w- c:\users\RG\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-12-31 23:58 . 2009-09-10 06:42 ——– d—–w- c:\program files\Intel
2009-12-30 09:14 . 2009-12-30 08:16 ——– d—–w- c:\programdata\SmartSound Software Inc
2009-12-30 08:50 . 2009-09-10 06:26 68224 —-a-w- c:\users\RG\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-30 08:37 . 2009-12-30 08:16 ——– d—–w- c:\program files\SmartSound Software
2009-12-30 08:21 . 2009-09-11 07:21 ——– d—–w- c:\program files\Common Files\PX Storage Engine
2009-12-30 08:21 . 2009-09-10 06:39 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-30 08:19 . 2009-12-30 08:09 ——– d—–w- c:\program files\Roxio 2010
2009-12-30 08:18 . 2009-12-30 08:17 ——– d—–w- c:\program files\Roxio
2009-12-30 08:18 . 2009-12-30 08:18 ——– d—–w- c:\program files\CinemaNow
2009-12-30 08:17 . 2009-12-30 08:17 ——– d—–w- c:\users\RG\AppData\Roaming\Simple Star
2009-12-30 08:17 . 2009-12-30 08:17 ——– d—–w- c:\programdata\PhotoShow Shared Assets
2009-12-30 08:16 . 2009-12-30 08:16 ——– d—–w- c:\programdata\eSellerate
2009-12-30 08:16 . 2009-09-10 06:44 ——– d—–w- c:\program files\Common Files\InstallShield
2009-12-30 08:15 . 2009-12-30 08:09 ——– d—–w- c:\program files\Common Files\Roxio Shared
2009-12-30 08:12 . 2009-12-30 08:09 ——– d—–w- c:\programdata\Roxio
2009-12-30 08:09 . 2009-12-30 08:09 ——– d—–w- c:\programdata\Macrovision
2009-12-30 08:09 . 2009-12-30 08:09 10134 —-a-r- c:\users\RG\AppData\Roaming\Microsoft\Installer\{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}\ARPPRODUCTICON.exe
2009-12-10 10:58 . 2009-09-10 08:25 ——– d—–w- c:\programdata\CyberLink
2009-12-10 10:56 . 2009-11-18 10:27 53319 —-a-w- c:\programdata\Temp\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}\PostBuild.exe
2009-12-10 10:56 . 2009-09-10 08:23 505128 —-a-w- c:\windows\system32\msvcp71.dll
2009-12-10 10:56 . 2009-09-10 08:23 353576 —-a-w- c:\windows\system32\msvcr71.dll
2009-12-09 09:17 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-12-08 07:56 . 2009-09-10 08:58 56816 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-11-26 11:09 . 2009-09-10 08:28 ——– d—–w- c:\users\RG\AppData\Roaming\CyberLink
2009-11-21 06:40 . 2009-12-09 01:35 916480 —-a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-09 01:35 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:34 . 2009-12-09 01:35 109056 —-a-w- c:\windows\system32\iesysprep.dll
2009-11-21 04:59 . 2009-12-09 01:35 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2009-11-18 20:14 . 2009-09-16 07:06 ——– d—–w- c:\program files\Java
2009-11-18 10:10 . 2009-09-18 04:20 ——– d—–w- c:\users\RG\AppData\Roaming\dvdcss
2009-11-17 09:02 . 2009-11-17 09:02 ——– d—–w- c:\program files\Windows Portable Devices
2009-11-17 09:02 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat
2009-11-17 09:02 . 2009-11-17 09:02 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-05 06:34 . 2009-11-05 06:34 38208 —-a-w- c:\users\RG\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-05 06:34 . 2009-11-05 06:34 38208 —-a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-03 02:42 . 2009-10-03 11:57 195456 ——w- c:\windows\system32\MpSigStub.exe
2009-10-29 10:44 . 2009-09-10 08:23 53319 —-a-w- c:\programdata\Temp\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\PostBuild.exe
2009-10-29 09:17 . 2009-11-25 09:00 2048 —-a-w- c:\windows\system32\tzres.dll
2009-10-15 19:52 . 2009-10-15 19:52 593920 —-a-w- c:\users\RG\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\pmv305hw-0910150-0-main.dll
2009-10-15 19:52 . 2009-10-15 19:52 319488 —-a-w- c:\users\RG\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe
2009-10-11 10:17 . 2009-09-16 09:05 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-10-08 21:08 . 2009-11-17 09:00 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-08 21:08 . 2009-11-17 09:00 234496 —-a-w- c:\windows\system32\oleacc.dll
2009-10-08 21:07 . 2009-11-17 09:00 4096 —-a-w- c:\windows\system32\oleaccrc.dll
2009-12-31 23:29 . 2009-12-31 23:29 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-11-18 19:58 333192 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-18 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-18 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"HydraVisionDesktopManager"="c:\program files\ATI Technologies\HydraVision\HydraDM.exe" [2008-12-01 380928]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-12-31 39408]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-11-13 3171760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Daemon"="c:\program files\HP\HP Wireless Comfort Desktop\TSR\xDaemon.exe" [2008-08-01 356352]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-08 6037504]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-15 98304]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-07-01 37888]
"Sprint SmartView"="c:\program files\Sprint\Sprint SmartView\SprintSV.exe" [2009-05-26 75008]
"RDVCHG"="c:\program files\Sprint\Sprint SmartView\RDVCHG.exe" [2009-05-26 316672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"RemoteControl9"="c:\program files\CyberLink\PowerDVD9\PDVD9Serv.exe" [2009-02-16 87336]
"PDVD9LanguageShortcut"="c:\program files\CyberLink\PowerDVD9\Language\Language.exe" [2008-10-14 50472]
"BDRegion"="c:\program files\Cyberlink\Shared Files\brs.exe" [2009-03-01 75048]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe" [2009-07-24 240112]
"CPMonitor"="c:\program files\Roxio 2010\5.0\CPMonitor.exe" [2009-07-21 84464]
"Desktop Disc Tool"="c:\program files\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe" [2009-06-23 494064]
"Google Updater"="c:\program files\Google\Google Updater\GoogleUpdater.exe" [2009-12-31 160752]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-12-31 122880]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-12-31 30192]

c:\users\RG\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-12-15 384000]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Wireless Connection Manager.lnk - c:\program files\D-Link\D-Link DWA-556 Xtreme N PCIe Desktop Adapter\wirelesscm.exe [2009-9-10 30143744]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~4\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):ec,97,db,7e,9b,35,ca,01

R0 SahdIa32;HDD Filter Driver;c:\windows\System32\drivers\SahdIa32.sys [12/30/2009 2:19 AM 21488]
R0 SaibIa32;Volume Filter Driver;c:\windows\System32\drivers\SaibIa32.sys [12/30/2009 2:19 AM 15856]
R1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\System32\drivers\jswpslwf.sys [9/10/2009 10:47 PM 20384]
R1 SaibVd32;Virtual Disk Driver;c:\windows\System32\drivers\SaibVd32.sys [12/30/2009 2:19 AM 25584]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2009/12/10 04:58];c:\program files\CyberLink\PowerDVD9\000.fcl [2/28/2009 7:40 PM 87536]
R2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269;Roxio SAIB Service;c:\program files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe [6/2/2009 7:05 PM 457200]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\System32\atiesrxx.exe [7/14/2009 8:14 PM 172032]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [9/10/2009 2:58 AM 108289]
R2 CinemaNow Service;CinemaNow Service;c:\program files\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe [6/23/2009 5:40 PM 127352]
R3 HpWkm001;USB K + M Packet Filter Driver;c:\windows\System32\drivers\HpWkm001.sys [9/10/2009 12:39 AM 11264]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/31/2009 5:29 PM 133104]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe [7/24/2009 8:33 AM 219632]
S3 CASprint;Sprint Con App Svc;c:\program files\Sprint\Sprint SmartView\ConAppsSvc.exe [5/26/2009 4:48 PM 124160]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [1/20/2008 8:23 PM 21504]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [12/31/2009 5:29 PM 30192]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\D-Link\D-Link DWA-556 Xtreme N PCIe Desktop Adapter\jswpsapi.exe [9/10/2009 10:47 PM 954368]
S3 RoxMediaDB12;RoxMediaDB12;c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe [7/24/2009 8:33 AM 1116656]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder

2010-01-06 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-31 23:28]

2010-01-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-31 23:29]

2010-01-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-31 23:29]

2010-01-06 c:\windows\Tasks\User_Feed_Synchronization-{46A75F5E-2D28-4C96-9889-39C352AFCD88}.job
- c:\windows\system32\msfeedssync.exe [2009-12-09 04:59]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.lenovo.com
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
LSP: bmnet.dll
Trusted Zone: cinemanow.com
Trusted Zone: qflix.com
Trusted Zone: roxio.com
Trusted Zone: sonic.com\redirect
Trusted Zone: sonic.com\redirect2
FF - ProfilePath - c:\users\RG\AppData\Roaming\Mozilla\Firefox\Profiles\2ba353fa.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p;=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\users\RG\AppData\Roaming\IDM\idmmzcc3\components\idmmzcc.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1808.5272\npCIDetect14.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nplalaDl.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-06 08:00
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys SahdIa32.sys acpi.sys hal.dll >>UNKNOWN [0x85929841]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0x82fb3d24
\Driver\ACPI -> acpi.sys @ 0x8069cd68
\Driver\atapi -> ataport.SYS @ 0x807aba2c
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{B154377D-700F-42cc-9474-23858FBDF4BD}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD9\000.fcl"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(680)
c:\windows\system32\bmnet.dll

- - - - - - - > 'Explorer.exe'(1520)
c:\program files\ATI Technologies\HydraVision\HydraDMH.dll
.
Completion time: 2010-01-06 08:02:38
ComboFix-quarantined-files.txt 2010-01-06 14:02

Pre-Run: 444,325,515,264 bytes free
Post-Run: 444,293,550,080 bytes free

- - End Of File - - 7AE151E5AFD47E809363FA718335541C


Log from bat file came up blank, ran it twice.

Log from bat file came up blank, ran it twice.

Please try again, but this time right-click on the look.bat icon and select Run As Administrator.
it worked ! log: C:\Windows\ERDNT\cache\atapi.sys C:\Windows\System32\drivers\atapi.sys C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
Excellent. OK, just one more .bat to run:

@echo off
PEV C:\atapi.sys –c"#f #s #5 #m" > "%userprofile%\Desktop\log.txt"
start notepad "%userprofile%\Desktop\log.txt"
del /Q %0

Basically, one of your system files has been patched by Malware, and we just need to find a valid replacement.
log: C:\Windows\ERDNT\cache\atapi.sys 19,944 1F05B78AB91C9075565A9D8A4B880BC4 2009-04-11 06:32:26 C:\Windows\System32\drivers\atapi.sys 19,944 1F05B78AB91C9075565A9D8A4B880BC4 2009-04-11 06:32:26 C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys 19,944 1F05B78AB91C9075565A9D8A4B880BC4 2009-04-11 06:32:26 C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys 19,048 4F4FCB8B6EA06784FB6D475B7EC7300F 2006-11-02 09:49:36 C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys 21,560 2D9C903DC76A66813D350A562DE40ED9 2008-01-21 02:23:00 C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys 21,560 2D9C903DC76A66813D350A562DE40ED9 2008-01-21 02:23:00 C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys 19,944 1F05B78AB91C9075565A9D8A4B880BC4 2009-04-11 06:32:26
OK, let's make the replacement. If you do not understand any of the below let me know.

Click Start and type cmd in 'Start Search'.
When cmd.exe populates above, right-click it and select Run as Administrator to open an elevated command prompt.

Copy this command, then right click in the command window and select paste:
copy C:\Windows\ERDNT\cache\atapi.sys c:\

Hit Enter, and you should see 1 file copied on the screen (if you do not see 1 file copied do not continue, but instead post back and let me know.)


Click Start and type notepad in 'Start Search'.
When notepad.exe populates above, right-click it and select Run as Administrator to open an elevated notepad window.

Copy/paste the following text into the notepad window:
ren c:\windows\system32\drivers\atapi.sys atapi.old
copy c:\atapi.sys c:\windows\system32\drivers\atapi.sys
exit


Save this as "C:\fix.bat" <- Be sure to save to C:\ and to use quotes!


Reboot your computer, and tap F8 on startup to enter the advanced options menu. Select Repair your computer from the list of startup options.

If Repair your computer is not an option on the Advanced Startup menu, insert your Windows Vista dvd and restart the computer, then when prompted, select Repair your computer


  • Select your keyboard layout
  • Enter your username and password (if you use one)
  • Then the System Recovery Options menu comes up
  • Select Command Prompt

It should open to a x:\sources> prompt

(this may vary depending if you boot from cd or an installed RE)


At the prompt type c:\fix.bat

The command window will close automatically after the batch runs.

Select Restart on the System Recovery Options menu.


Let me know how things are running after reboot.
sorry for the delay can't seem to access the advanced startup menu with a "repair your computer" option with the dics i have the system either tries to install a new version of windows or give me a f8 "advanced options" menu (safe mode, etc) with some other options i have a lenovo system that only came with a system recovery disc and a driver disc is there another way to go about using this fix or another option i am supposed to select at the "advanced options" screen ??
OK, no worries, we will try a different method.

Please download The Avenger. Save it to your Desktop and extract avenger.exe to your Desktop. Right click it and select Run As Administrator.

Copy/paste the following script into the script box:
File to move:
C:\atapi.sys | C:\WINDOWS\system32\drivers\atapi.sys


Click Execute. You computer will reboot. After it has rebooted and finished executing, please reboot again. After this reboot, open Avenger again and click File -> Open log, post the contents of this log in your next reply. Let me know if you are still experiencing problems after this.
lol no problem.

still having issues with redirects.

here is avenger log file:
//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows NT 6.0 (build 6002, Service Pack 2)
Tue Jan 12 14:03:45 2010

14:03:45: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows NT 6.0 (build 6002, Service Pack 2)
Tue Jan 12 14:04:52 2010

14:04:52: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows NT 6.0 (build 6002, Service Pack 2)
Tue Jan 12 14:05:18 2010

14:05:18: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows NT 6.0 (build 6002, Service Pack 2)
Tue Jan 12 14:08:14 2010

14:08:14: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows NT 6.0 (build 6002, Service Pack 2)
Tue Jan 12 14:09:21 2010

14:09:21: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows NT 6.0 (build 6002, Service Pack 2)
Tue Jan 12 14:09:26 2010

14:09:26: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows NT 6.0 (build 6002, Service Pack 2)
Tue Jan 12 14:10:36 2010

14:10:36: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows Vista

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error: could not move file "C:\atapi.sys"
File move operation "C:\atapi.sys|C:\WINDOWS\system32\drivers\atapi.sys" failed!
Status: 0xc0000022 (STATUS_ACCESS_DENIED)


Completed script processing.

*******************

Finished! Terminate.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI