tiny_7205
Topic Starter
Hi,
I am getting a message popping up "Do you really want close?", am getting script errors and the desktop is in active desktop recovery mode. Before Active Desktop Recovery turned on, there were multiple search windows popping up without me doing anything. The computer is also running slow. I have followed the steps in "Are You infected". Malwarebytes found around 30 infections on my first scan and removed them, but still having problems. The Malwarebytes log included here shows no infections. Here are my MBAM, Gmer and DDS logs.
Malwarebytes' Anti-Malware 1.44
Database version: 3588
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
1/18/2010 9:40:23 AM
mbam-log-2010-01-18 (09-40-23).txt
Scan type: Quick Scan
Objects scanned: 120344
Time elapsed: 11 minute(s), 52 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-18 00:10:57
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\CRISTI~1\LOCALS~1\Temp\pxdiypog.sys
—- System - GMER 1.0.15 —-
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwAdjustPrivilegesToken [0xF0B4F58C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwClose [0xF0B4FE0C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwConnectPort [0xF0B50922]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateEvent [0xF0B50E94]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateFile [0xF0B500EE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateKey [0xF0B4E436]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateMutant [0xF0B50D6C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateNamedPipeFile [0xF0B4F192]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreatePort [0xF0B50C28]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSection [0xF0B4F34E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSemaphore [0xF0B50FC6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSymbolicLinkObject [0xF0B52C08]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateThread [0xF0B4FAAA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateWaitablePort [0xF0B50CCA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDebugActiveProcess [0xF0B525FA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteKey [0xF0B4E9FA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteValueKey [0xF0B4ED88]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeviceIoControlFile [0xF0B50576]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDuplicateObject [0xF0B535CA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateKey [0xF0B4EECA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateValueKey [0xF0B4EF74]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwFsControlFile [0xF0B50382]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadDriver [0xF0B5268C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey [0xF0B4E412]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey2 [0xF0B4E424]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwMapViewOfSection [0xF0B52CBC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwNotifyChangeKey [0xF0B4F0C0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenEvent [0xF0B50F36]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenFile [0xF0B4FE8E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenKey [0xF0B4E5DC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenMutant [0xF0B50E04]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenProcess [0xF0B4F792]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSection [0xF0B52C32]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSemaphore [0xF0B51068]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenThread [0xF0B4F6B6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryKey [0xF0B4F01E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryMultipleValueKey [0xF0B4EC46]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQuerySection [0xF0B52FD4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryValueKey [0xF0B4E896]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueueApcThread [0xF0B52922]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRenameKey [0xF0B4EB0E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplaceKey [0xF0B4E2B0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyPort [0xF0B513F2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0xF0B512B8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRequestWaitReplyPort [0xF0B5239A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRestoreKey [0xF0B55E2C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwResumeThread [0xF0B534AC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSaveKey [0xF0B4E248]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSecureConnectPort [0xF0B5065C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetContextThread [0xF0B4FCC8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetInformationToken [0xF0B51C4A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSecurityObject [0xF0B52786]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSystemInformation [0xF0B53114]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetValueKey [0xF0B4E71E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendProcess [0xF0B531F8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendThread [0xF0B53320]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSystemDebugControl [0xF0B52526]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateProcess [0xF0B4F90A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateThread [0xF0B4F860]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwUnmapViewOfSection [0xF0B52E8A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwWriteVirtualMemory [0xF0B4F9EA]
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) FsRtlCheckLockForReadAccess
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) IoIsOperationSynchronous
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\Tcpip \Device\Ip kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
—- EOF - GMER 1.0.15 —-
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 0:12:23.65 on Mon 01/18/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.254.26 [GMT -6:00]
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\WINDOWS\System32\lxdvcoms.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark X5400 Series\lxdvmon.exe
C:\Program Files\Lexmark X5400 Series\lxdvamon.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtblfs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Cristina Reyes\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.dell4me.com/myway
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
mSearchAssistant = hxxp://www.google.com
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky anti-virus 2010\ievkbd.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky anti-virus 2010\klwtbbho.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
TB: {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - No File
TB: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [NBJ] "c:\program files\ahead\nero backitup\NBJ.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [lxdvmon.exe] "c:\program files\lexmark x5400 series\lxdvmon.exe"
mRun: [lxdvamon] "c:\program files\lexmark x5400 series\lxdvamon.exe"
mRun: [Lexmark X5400 Series Fax Server] "c:\program files\lexmark x5400 series\fm3032.exe" /s
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky anti-virus 2010\avp.exe"
uPolicies-system: DisableTaskMgr = 0
IE: &AOL Toolbar search - c:\program files\aol toolbar\toolbar.dll/SEARCH.HTML
IE: Yahoo! Dictionary - file:///c:\program files\yahoo!\Common/ycdict.htm
IE: Yahoo! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - blank
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky anti-virus 2010\klwtbbho.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky anti-virus 2010\klwtbbho.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38018.7625347222
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: cbxuttt - cbxuttt.dll
Notify: gebaayy - gebaayy.dll
Notify: igfxcui - igfxsrvc.dll
Notify: klogon - c:\windows\system32\klogon.dll
AppInit_DLLs: karna.dat,c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll
============= SERVICES / DRIVERS ===============
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-14 36880]
R1 kl1;Kl1;c:\windows\system32\drivers\kl1.sys [2009-9-1 128016]
R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2010-1-16 315408]
R2 AVP;Kaspersky Anti-Virus;c:\program files\kaspersky lab\kaspersky anti-virus 2010\avp.exe [2009-10-20 340456]
R2 lxdv_device;lxdv_device;c:\windows\system32\lxdvcoms.exe -service –> c:\windows\system32\lxdvcoms.exe -service [?]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2009-9-14 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-10-2 19472]
S2 lxdvCATSCustConnectService;lxdvCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdvserv.exe [2008-8-28 98984]
S2 NAVAPEL;NAVAPEL;\??\c:\program files\symantec_client_security\symantec antivirus\navapel.sys –> c:\program files\symantec_client_security\symantec antivirus\NAVAPEL.SYS [?]
S3 NAVAP;NAVAP;\??\c:\progra~1\symant~1\symant~1\navap.sys –> c:\progra~1\symant~1\symant~1\NAVAP.sys [?]
=============== Created Last 30 ================
2010-01-16 22:56 –dsh— c:\documents and settings\cristina reyes\PrivacIE
2010-01-16 22:51 –dsh— c:\documents and settings\cristina reyes\IETldCache
2010-01-16 21:39 12,800 ——– c:\windows\system32\dllcache\xpshims.dll
2010-01-16 21:39 11,069,952 ——– c:\windows\system32\dllcache\ieframe.dll
2010-01-16 21:39 1,985,536 ——– c:\windows\system32\dllcache\iertutil.dll
2010-01-16 21:39 594,432 ——– c:\windows\system32\dllcache\msfeeds.dll
2010-01-16 21:39 246,272 ——– c:\windows\system32\dllcache\ieproxy.dll
2010-01-16 21:39 55,296 ——– c:\windows\system32\dllcache\msfeedsbs.dll
2010-01-16 21:39 –d—– c:\windows\ie8updates
2010-01-16 21:39 92,160 ——– c:\windows\system32\dllcache\iecompat.dll
2010-01-16 21:35 -cd-h— c:\windows\ie8
2010-01-16 20:55 –d—– c:\program files\MSXML 4.0
2010-01-16 20:45 272,128 ——– c:\windows\system32\dllcache\bthport.sys
2010-01-16 20:44 471,552 ——– c:\windows\system32\dllcache\aclayers.dll
2010-01-16 20:44 1,089,593 ——– c:\windows\system32\dllcache\ntprint.cat
2010-01-16 20:42 203,136 ——– c:\windows\system32\dllcache\rmcast.sys
2010-01-16 20:42 455,296 ——– c:\windows\system32\dllcache\mrxsmb.sys
2010-01-16 20:42 333,952 ——– c:\windows\system32\dllcache\srv.sys
2010-01-16 20:42 331,776 ——– c:\windows\system32\dllcache\msadce.dll
2010-01-16 20:42 1,315,328 ——– c:\windows\system32\dllcache\msoe.dll
2010-01-16 20:41 691,712 ——– c:\windows\system32\dllcache\inetcomm.dll
2010-01-16 20:39 2,145,280 ——– c:\windows\system32\dllcache\ntkrnlmp.exe
2010-01-16 20:39 2,023,936 ——– c:\windows\system32\dllcache\ntkrpamp.exe
2010-01-16 20:39 2,066,048 ——– c:\windows\system32\dllcache\ntkrnlpa.exe
2010-01-16 20:38 337,408 ——– c:\windows\system32\dllcache\netapi32.dll
2010-01-16 20:38 1,172,480 ——– c:\windows\system32\dllcache\msxml3.dll
2010-01-16 20:37 2,560 ——– c:\windows\system32\xpsp4res.dll
2010-01-16 20:37 1,206,508 ——– c:\windows\system32\dllcache\sysmain.sdb
2010-01-16 20:37 215,552 ——– c:\windows\system32\dllcache\wordpad.exe
2010-01-16 20:37 726,528 a——- c:\windows\system32\dllcache\jscript.dll
2010-01-16 19:49 108,059 a——- c:\windows\system32\drivers\klin.dat
2010-01-16 19:49 95,259 a——- c:\windows\system32\drivers\klick.dat
2010-01-16 19:39 –d—– c:\program files\Kaspersky Lab
2010-01-16 19:39 –d—– c:\docume~1\alluse~1\applic~1\Kaspersky Lab
2010-01-16 18:06 –d—– c:\docume~1\alluse~1\applic~1\Kaspersky Lab Setup Files
2010-01-16 17:57 –d—– c:\windows\system32\XPSViewer
2010-01-16 17:53 597,504 ——– c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-01-16 17:53 117,760 ——– c:\windows\system32\prntvpt.dll
2010-01-16 17:53 89,088 ——– c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-01-16 17:53 1,676,288 ——– c:\windows\system32\xpssvcs.dll
2010-01-16 17:53 1,676,288 ——– c:\windows\system32\dllcache\xpssvcs.dll
2010-01-16 17:53 575,488 ——– c:\windows\system32\xpsshhdr.dll
2010-01-16 17:53 575,488 ——– c:\windows\system32\dllcache\xpsshhdr.dll
2010-01-16 17:53 –d—– C:\2b1d13dd4c042712ae8f9145
2010-01-16 14:49 –d—– c:\windows\system32\scripting
2010-01-16 14:49 –d—– c:\windows\l2schemas
2010-01-16 14:49 –d—– c:\windows\system32\en
2010-01-16 14:42 –d—– c:\windows\network diagnostic
2010-01-16 14:26 276,992 ——– c:\windows\system32\wmphoto.dll
2010-01-16 14:26 69,120 ——– c:\windows\system32\wlanapi.dll
2010-01-16 14:26 712,704 ——– c:\windows\system32\windowscodecs.dll
2010-01-16 14:26 346,112 ——– c:\windows\system32\windowscodecsext.dll
2010-01-16 14:26 53,248 ——– c:\windows\system32\tsgqec.dll
2010-01-16 14:26 50,688 ——– c:\windows\system32\tspkg.dll
2010-01-16 14:24 37,376 ——– c:\windows\system32\l2gpstore.dll
2010-01-16 13:27 –d—– c:\windows\system32\wbem\AutoRecover
2010-01-16 12:56 –d—– c:\windows\peernet
2010-01-16 12:56 –d—– c:\windows\provisioning
2010-01-16 12:52 –d—– c:\windows\ServicePackFiles
2010-01-16 12:42 –d—– c:\windows\EHome
2010-01-16 09:26 –d—– c:\docume~1\cristi~1\applic~1\Malwarebytes
2010-01-16 09:26 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-16 09:26 18,520 a——- c:\windows\system32\drivers\mbam.sys
2010-01-16 09:26 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-01-16 09:26 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-01-16 09:01 373 a——- c:\windows\system32\MRT.INI
2010-01-16 09:01 –d—– c:\windows\system32\MpEngineStore
2010-01-16 08:46 14,592 a——- c:\windows\system32\drivers\kbdhid.sys
==================== Find3M ====================
2010-01-16 14:54 78,879 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-11-21 09:51 471,552 a——- c:\windows\apppatch\aclayers.dll
2009-10-29 01:45 916,480 a——- c:\windows\system32\wininet.dll
2009-10-29 01:45 916,480 ——– c:\windows\system32\dllcache\wininet.dll
2009-10-29 01:45 5,940,736 ——– c:\windows\system32\dllcache\mshtml.dll
2009-10-29 01:45 1,208,832 ——– c:\windows\system32\dllcache\urlmon.dll
2009-10-29 01:45 206,848 ——– c:\windows\system32\dllcache\occache.dll
2009-10-29 01:45 25,600 ——– c:\windows\system32\dllcache\jsproxy.dll
2009-10-29 01:45 184,320 ——– c:\windows\system32\dllcache\iepeers.dll
2009-10-29 01:45 387,584 ——– c:\windows\system32\dllcache\iedkcs32.dll
2009-10-28 23:38 1,509,888 ——– c:\windows\system32\dllcache\shdocvw.dll
2009-10-28 08:40 173,056 ——– c:\windows\system32\dllcache\ie4uinit.exe
2009-10-20 23:38 75,776 a——- c:\windows\system32\strmfilt.dll
2009-10-20 23:38 25,088 a——- c:\windows\system32\httpapi.dll
2009-10-20 23:38 75,776 ——– c:\windows\system32\dllcache\strmfilt.dll
2009-10-20 23:38 25,088 ——– c:\windows\system32\dllcache\httpapi.dll
2009-10-20 19:34 219,664 a——- c:\windows\system32\klogon.dll
2009-10-20 10:20 265,728 ——– c:\windows\system32\dllcache\http.sys
2007-04-13 21:16 800,272 ac—— c:\documents and settings\cristina reyes\ppctl.dll
2007-04-13 13:22 102 ac—— c:\docume~1\cristi~1\applic~1\Dxcuknwrd.dll
2007-04-13 13:19 76 ac—— c:\docume~1\cristi~1\applic~1\Dxcdmns.dll
2007-04-06 13:27 139,264 ac—— c:\program files\common files\hopese.dll
2003-07-25 11:38 132,096 ac—— c:\program files\common files\PCSBoff.exe
2007-04-13 16:48 1,391,967 -c-sh— c:\windows\system32\cfhkj.bak1
============= FINISH: 0:13:56.25 ===============
I am getting a message popping up "Do you really want close?", am getting script errors and the desktop is in active desktop recovery mode. Before Active Desktop Recovery turned on, there were multiple search windows popping up without me doing anything. The computer is also running slow. I have followed the steps in "Are You infected". Malwarebytes found around 30 infections on my first scan and removed them, but still having problems. The Malwarebytes log included here shows no infections. Here are my MBAM, Gmer and DDS logs.
Malwarebytes' Anti-Malware 1.44
Database version: 3588
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
1/18/2010 9:40:23 AM
mbam-log-2010-01-18 (09-40-23).txt
Scan type: Quick Scan
Objects scanned: 120344
Time elapsed: 11 minute(s), 52 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-18 00:10:57
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\CRISTI~1\LOCALS~1\Temp\pxdiypog.sys
—- System - GMER 1.0.15 —-
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwAdjustPrivilegesToken [0xF0B4F58C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwClose [0xF0B4FE0C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwConnectPort [0xF0B50922]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateEvent [0xF0B50E94]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateFile [0xF0B500EE]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateKey [0xF0B4E436]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateMutant [0xF0B50D6C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateNamedPipeFile [0xF0B4F192]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreatePort [0xF0B50C28]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSection [0xF0B4F34E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSemaphore [0xF0B50FC6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSymbolicLinkObject [0xF0B52C08]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateThread [0xF0B4FAAA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateWaitablePort [0xF0B50CCA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDebugActiveProcess [0xF0B525FA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteKey [0xF0B4E9FA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteValueKey [0xF0B4ED88]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeviceIoControlFile [0xF0B50576]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDuplicateObject [0xF0B535CA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateKey [0xF0B4EECA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateValueKey [0xF0B4EF74]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwFsControlFile [0xF0B50382]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadDriver [0xF0B5268C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey [0xF0B4E412]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey2 [0xF0B4E424]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwMapViewOfSection [0xF0B52CBC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwNotifyChangeKey [0xF0B4F0C0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenEvent [0xF0B50F36]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenFile [0xF0B4FE8E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenKey [0xF0B4E5DC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenMutant [0xF0B50E04]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenProcess [0xF0B4F792]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSection [0xF0B52C32]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSemaphore [0xF0B51068]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenThread [0xF0B4F6B6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryKey [0xF0B4F01E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryMultipleValueKey [0xF0B4EC46]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQuerySection [0xF0B52FD4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryValueKey [0xF0B4E896]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueueApcThread [0xF0B52922]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRenameKey [0xF0B4EB0E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplaceKey [0xF0B4E2B0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyPort [0xF0B513F2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0xF0B512B8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRequestWaitReplyPort [0xF0B5239A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRestoreKey [0xF0B55E2C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwResumeThread [0xF0B534AC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSaveKey [0xF0B4E248]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSecureConnectPort [0xF0B5065C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetContextThread [0xF0B4FCC8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetInformationToken [0xF0B51C4A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSecurityObject [0xF0B52786]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSystemInformation [0xF0B53114]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetValueKey [0xF0B4E71E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendProcess [0xF0B531F8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendThread [0xF0B53320]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSystemDebugControl [0xF0B52526]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateProcess [0xF0B4F90A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateThread [0xF0B4F860]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwUnmapViewOfSection [0xF0B52E8A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwWriteVirtualMemory [0xF0B4F9EA]
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) FsRtlCheckLockForReadAccess
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) IoIsOperationSynchronous
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\Tcpip \Device\Ip kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
—- EOF - GMER 1.0.15 —-
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 0:12:23.65 on Mon 01/18/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.254.26 [GMT -6:00]
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\WINDOWS\System32\lxdvcoms.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark X5400 Series\lxdvmon.exe
C:\Program Files\Lexmark X5400 Series\lxdvamon.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtblfs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Cristina Reyes\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.dell4me.com/myway
uSearch Bar = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
mSearchAssistant = hxxp://www.google.com
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky anti-virus 2010\ievkbd.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky anti-virus 2010\klwtbbho.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
TB: {4E7BD74F-2B8D-469E-C0FF-FD60B590A87D} - No File
TB: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [NBJ] "c:\program files\ahead\nero backitup\NBJ.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [lxdvmon.exe] "c:\program files\lexmark x5400 series\lxdvmon.exe"
mRun: [lxdvamon] "c:\program files\lexmark x5400 series\lxdvamon.exe"
mRun: [Lexmark X5400 Series Fax Server] "c:\program files\lexmark x5400 series\fm3032.exe" /s
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky anti-virus 2010\avp.exe"
uPolicies-system: DisableTaskMgr = 0
IE: &AOL Toolbar search - c:\program files\aol toolbar\toolbar.dll/SEARCH.HTML
IE: Yahoo! Dictionary - file:///c:\program files\yahoo!\Common/ycdict.htm
IE: Yahoo! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - blank
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky anti-virus 2010\klwtbbho.dll
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky anti-virus 2010\klwtbbho.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38018.7625347222
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: cbxuttt - cbxuttt.dll
Notify: gebaayy - gebaayy.dll
Notify: igfxcui - igfxsrvc.dll
Notify: klogon - c:\windows\system32\klogon.dll
AppInit_DLLs: karna.dat,c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll
============= SERVICES / DRIVERS ===============
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-14 36880]
R1 kl1;Kl1;c:\windows\system32\drivers\kl1.sys [2009-9-1 128016]
R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2010-1-16 315408]
R2 AVP;Kaspersky Anti-Virus;c:\program files\kaspersky lab\kaspersky anti-virus 2010\avp.exe [2009-10-20 340456]
R2 lxdv_device;lxdv_device;c:\windows\system32\lxdvcoms.exe -service –> c:\windows\system32\lxdvcoms.exe -service [?]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2009-9-14 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-10-2 19472]
S2 lxdvCATSCustConnectService;lxdvCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdvserv.exe [2008-8-28 98984]
S2 NAVAPEL;NAVAPEL;\??\c:\program files\symantec_client_security\symantec antivirus\navapel.sys –> c:\program files\symantec_client_security\symantec antivirus\NAVAPEL.SYS [?]
S3 NAVAP;NAVAP;\??\c:\progra~1\symant~1\symant~1\navap.sys –> c:\progra~1\symant~1\symant~1\NAVAP.sys [?]
=============== Created Last 30 ================
2010-01-16 22:56 –dsh— c:\documents and settings\cristina reyes\PrivacIE
2010-01-16 22:51 –dsh— c:\documents and settings\cristina reyes\IETldCache
2010-01-16 21:39 12,800 ——– c:\windows\system32\dllcache\xpshims.dll
2010-01-16 21:39 11,069,952 ——– c:\windows\system32\dllcache\ieframe.dll
2010-01-16 21:39 1,985,536 ——– c:\windows\system32\dllcache\iertutil.dll
2010-01-16 21:39 594,432 ——– c:\windows\system32\dllcache\msfeeds.dll
2010-01-16 21:39 246,272 ——– c:\windows\system32\dllcache\ieproxy.dll
2010-01-16 21:39 55,296 ——– c:\windows\system32\dllcache\msfeedsbs.dll
2010-01-16 21:39 –d—– c:\windows\ie8updates
2010-01-16 21:39 92,160 ——– c:\windows\system32\dllcache\iecompat.dll
2010-01-16 21:35 -cd-h— c:\windows\ie8
2010-01-16 20:55 –d—– c:\program files\MSXML 4.0
2010-01-16 20:45 272,128 ——– c:\windows\system32\dllcache\bthport.sys
2010-01-16 20:44 471,552 ——– c:\windows\system32\dllcache\aclayers.dll
2010-01-16 20:44 1,089,593 ——– c:\windows\system32\dllcache\ntprint.cat
2010-01-16 20:42 203,136 ——– c:\windows\system32\dllcache\rmcast.sys
2010-01-16 20:42 455,296 ——– c:\windows\system32\dllcache\mrxsmb.sys
2010-01-16 20:42 333,952 ——– c:\windows\system32\dllcache\srv.sys
2010-01-16 20:42 331,776 ——– c:\windows\system32\dllcache\msadce.dll
2010-01-16 20:42 1,315,328 ——– c:\windows\system32\dllcache\msoe.dll
2010-01-16 20:41 691,712 ——– c:\windows\system32\dllcache\inetcomm.dll
2010-01-16 20:39 2,145,280 ——– c:\windows\system32\dllcache\ntkrnlmp.exe
2010-01-16 20:39 2,023,936 ——– c:\windows\system32\dllcache\ntkrpamp.exe
2010-01-16 20:39 2,066,048 ——– c:\windows\system32\dllcache\ntkrnlpa.exe
2010-01-16 20:38 337,408 ——– c:\windows\system32\dllcache\netapi32.dll
2010-01-16 20:38 1,172,480 ——– c:\windows\system32\dllcache\msxml3.dll
2010-01-16 20:37 2,560 ——– c:\windows\system32\xpsp4res.dll
2010-01-16 20:37 1,206,508 ——– c:\windows\system32\dllcache\sysmain.sdb
2010-01-16 20:37 215,552 ——– c:\windows\system32\dllcache\wordpad.exe
2010-01-16 20:37 726,528 a——- c:\windows\system32\dllcache\jscript.dll
2010-01-16 19:49 108,059 a——- c:\windows\system32\drivers\klin.dat
2010-01-16 19:49 95,259 a——- c:\windows\system32\drivers\klick.dat
2010-01-16 19:39 –d—– c:\program files\Kaspersky Lab
2010-01-16 19:39 –d—– c:\docume~1\alluse~1\applic~1\Kaspersky Lab
2010-01-16 18:06 –d—– c:\docume~1\alluse~1\applic~1\Kaspersky Lab Setup Files
2010-01-16 17:57 –d—– c:\windows\system32\XPSViewer
2010-01-16 17:53 597,504 ——– c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-01-16 17:53 117,760 ——– c:\windows\system32\prntvpt.dll
2010-01-16 17:53 89,088 ——– c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-01-16 17:53 1,676,288 ——– c:\windows\system32\xpssvcs.dll
2010-01-16 17:53 1,676,288 ——– c:\windows\system32\dllcache\xpssvcs.dll
2010-01-16 17:53 575,488 ——– c:\windows\system32\xpsshhdr.dll
2010-01-16 17:53 575,488 ——– c:\windows\system32\dllcache\xpsshhdr.dll
2010-01-16 17:53 –d—– C:\2b1d13dd4c042712ae8f9145
2010-01-16 14:49 –d—– c:\windows\system32\scripting
2010-01-16 14:49 –d—– c:\windows\l2schemas
2010-01-16 14:49 –d—– c:\windows\system32\en
2010-01-16 14:42 –d—– c:\windows\network diagnostic
2010-01-16 14:26 276,992 ——– c:\windows\system32\wmphoto.dll
2010-01-16 14:26 69,120 ——– c:\windows\system32\wlanapi.dll
2010-01-16 14:26 712,704 ——– c:\windows\system32\windowscodecs.dll
2010-01-16 14:26 346,112 ——– c:\windows\system32\windowscodecsext.dll
2010-01-16 14:26 53,248 ——– c:\windows\system32\tsgqec.dll
2010-01-16 14:26 50,688 ——– c:\windows\system32\tspkg.dll
2010-01-16 14:24 37,376 ——– c:\windows\system32\l2gpstore.dll
2010-01-16 13:27 –d—– c:\windows\system32\wbem\AutoRecover
2010-01-16 12:56 –d—– c:\windows\peernet
2010-01-16 12:56 –d—– c:\windows\provisioning
2010-01-16 12:52 –d—– c:\windows\ServicePackFiles
2010-01-16 12:42 –d—– c:\windows\EHome
2010-01-16 09:26 –d—– c:\docume~1\cristi~1\applic~1\Malwarebytes
2010-01-16 09:26 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-16 09:26 18,520 a——- c:\windows\system32\drivers\mbam.sys
2010-01-16 09:26 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-01-16 09:26 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-01-16 09:01 373 a——- c:\windows\system32\MRT.INI
2010-01-16 09:01 –d—– c:\windows\system32\MpEngineStore
2010-01-16 08:46 14,592 a——- c:\windows\system32\drivers\kbdhid.sys
==================== Find3M ====================
2010-01-16 14:54 78,879 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-11-21 09:51 471,552 a——- c:\windows\apppatch\aclayers.dll
2009-10-29 01:45 916,480 a——- c:\windows\system32\wininet.dll
2009-10-29 01:45 916,480 ——– c:\windows\system32\dllcache\wininet.dll
2009-10-29 01:45 5,940,736 ——– c:\windows\system32\dllcache\mshtml.dll
2009-10-29 01:45 1,208,832 ——– c:\windows\system32\dllcache\urlmon.dll
2009-10-29 01:45 206,848 ——– c:\windows\system32\dllcache\occache.dll
2009-10-29 01:45 25,600 ——– c:\windows\system32\dllcache\jsproxy.dll
2009-10-29 01:45 184,320 ——– c:\windows\system32\dllcache\iepeers.dll
2009-10-29 01:45 387,584 ——– c:\windows\system32\dllcache\iedkcs32.dll
2009-10-28 23:38 1,509,888 ——– c:\windows\system32\dllcache\shdocvw.dll
2009-10-28 08:40 173,056 ——– c:\windows\system32\dllcache\ie4uinit.exe
2009-10-20 23:38 75,776 a——- c:\windows\system32\strmfilt.dll
2009-10-20 23:38 25,088 a——- c:\windows\system32\httpapi.dll
2009-10-20 23:38 75,776 ——– c:\windows\system32\dllcache\strmfilt.dll
2009-10-20 23:38 25,088 ——– c:\windows\system32\dllcache\httpapi.dll
2009-10-20 19:34 219,664 a——- c:\windows\system32\klogon.dll
2009-10-20 10:20 265,728 ——– c:\windows\system32\dllcache\http.sys
2007-04-13 21:16 800,272 ac—— c:\documents and settings\cristina reyes\ppctl.dll
2007-04-13 13:22 102 ac—— c:\docume~1\cristi~1\applic~1\Dxcuknwrd.dll
2007-04-13 13:19 76 ac—— c:\docume~1\cristi~1\applic~1\Dxcdmns.dll
2007-04-06 13:27 139,264 ac—— c:\program files\common files\hopese.dll
2003-07-25 11:38 132,096 ac—— c:\program files\common files\PCSBoff.exe
2007-04-13 16:48 1,391,967 -c-sh— c:\windows\system32\cfhkj.bak1
============= FINISH: 0:13:56.25 ===============