This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Rootkit warning

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have the 2nd DDS log on my desktop if required..
Thanks

Mbam
Malwarebytes' Anti-Malware 1.44
Database version: 3596
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

1/18/2010 7:47:48 PM
mbam-log-2010-01-18 (19-47-41).txt

Scan type: Quick Scan
Objects scanned: 118520
Time elapsed: 5 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{0ed403e8-470a-4a8a-85a4-d7688cfe39a3} (Adware.Gamevance) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\H8SRT (Rootkit.TDSS) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\krl32mainweq.dll (Trojan.DNSChanger) -> No action taken.
C:\WINDOWS\system32\H8SRTmfgxfwwnxh.dat (Rootkit.TDSS) -> No action taken.

GMER
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-18 20:00:23
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Me\LOCALS~1\Temp\kfdyrkog.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwAssignProcessToJobObject [0xF6F2F1CC]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwCreateThread [0xF6F2F206]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwOpenProcess [0xF6F2F51A]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwOpenThread [0xF6F2F3F6]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwProtectVirtualMemory [0xF6F2F292]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwSetContextThread [0xF6F2F18E]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwTerminateProcess [0xF6F2F64E]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwTerminateThread [0xF6F2F316]
SSDT \SystemRoot\System32\drivers\pxrts.sys (Prevx Realtime Security/Prevx) ZwWriteVirtualMemory [0xF6F2F34E]

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Tcp pxrts.sys (Prevx Realtime Security/Prevx)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@imagepath \systemroot\system32\drivers\H8SRTyrmnaawnmi.sys
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@H8SRTd \\?\globalroot\systemroot\system32\drivers\H8SRTyrmnaawnmi.sys
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@H8SRTc \\?\globalroot\systemroot\system32\H8SRTfusbnievfq.dll
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@H8SRTsrcr \\?\globalroot\systemroot\system32\H8SRTmfgxfwwnxh.dat
Reg HKLM\SYSTEM\ControlSet003\Services\H8SRTd.sys\modules@h8srtserf \\?\globalroot\systemroot\system32\H8SRTvkkvfxbuqu.dll

—- EOF - GMER 1.0.15 —-


DDS

DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 20:03:05.20 on Mon 01/18/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.759.439 [GMT -5:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Prevx\prevx.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Prevx\prevx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Me\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
uRun: [Yahoo! Pager] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.fubar.com/imgs/ImageUploader5.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1262078484046
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1262078470031
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\me\applic~1\mozilla\firefox\profiles\bj7bypjk.default\
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1808.5272\npCIDetect14.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [2009-12-29 30280]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-12-16 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-12-16 74480]
R2 CSIScanner;CSIScanner;c:\program files\prevx\prevx.exe [2009-12-29 6224896]
R2 pxrts;pxrts;c:\windows\system32\drivers\pxrts.sys [2009-12-29 47664]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-5-23 24652]
R3 pxkbf;pxkbf;c:\windows\system32\drivers\pxkbf.sys [2009-12-29 24496]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-16 135664]
S3 p17filt;p17filt;c:\windows\system32\drivers\p17filt.sys [2006-3-20 1452032]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-12-16 7408]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2009-4-6 23064]

=============== Created Last 30 ================

2010-01-19 00:34:01 0 d—–w- c:\docume~1\me\applic~1\Malwarebytes
2010-01-19 00:33:55 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-19 00:33:44 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-10 18:49:40 0 d—–w- c:\windows\system32\wbem\Repository
2009-12-29 17:04:35 53136 —-a-w- c:\windows\system32\PxSecure.dll
2009-12-29 17:04:34 47664 —-a-w- c:\windows\system32\drivers\pxrts.sys
2009-12-29 17:04:34 30280 —-a-w- c:\windows\system32\drivers\pxscan.sys
2009-12-29 17:04:33 24496 —-a-w- c:\windows\system32\drivers\pxkbf.sys
2009-12-29 17:04:33 0 d—–w- c:\program files\Prevx
2009-12-29 17:04:28 0 d—–w- c:\docume~1\alluse~1\applic~1\PrevxCSI
2009-12-29 14:47:46 202 —-a-w- c:\windows\system32\srcr.dat
2009-12-29 13:34:57 0 d—–w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-12-29 12:08:39 0 d—–w- c:\windows\system32\XPSViewer
2009-12-29 12:07:10 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-12-29 12:07:10 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-12-29 12:07:10 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-12-29 12:07:10 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-12-29 12:07:10 117760 ——w- c:\windows\system32\prntvpt.dll
2009-12-29 12:07:09 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2009-12-29 12:07:09 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-12-29 12:07:08 0 d—–w- C:\c906abf2c5710191ddc4
2009-12-29 11:57:52 32 —-a-w- c:\windows\wininit.ini
2009-12-29 10:21:46 0 d—–w- C:\cd728dc701e6fd3f3dd7e8e79bd8
2009-12-29 10:21:41 0 d—–w- C:\fffa5f25c1195355eecdca3136a36ccd
2009-12-29 10:17:25 0 d—–w- c:\program files\SUPERAntiSpyware
2009-12-29 10:17:25 0 d—–w- c:\docume~1\me\applic~1\SUPERAntiSpyware.com
2009-12-29 10:17:14 0 d—–w- c:\program files\common files\Wise Installation Wizard
2009-12-29 10:15:06 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-12-29 10:06:55 0 d-sh–w- c:\documents and settings\me\PrivacIE
2009-12-29 10:05:17 0 d-sh–w- c:\documents and settings\me\IETldCache
2009-12-29 10:00:19 0 d—–w- c:\windows\system32\KB905474
2009-12-29 09:59:00 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2009-12-29 09:58:59 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2009-12-29 09:58:54 0 d—–w- c:\windows\ie8updates
2009-12-29 09:58:51 92160 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2009-12-29 09:56:58 0 dc-h–w- c:\windows\ie8
2009-12-29 09:51:44 221184 —-a-w- c:\windows\system32\wmpns.dll
2009-12-29 09:45:12 153088 -c—-w- c:\windows\system32\dllcache\triedit.dll
2009-12-29 09:45:02 128512 -c—-w- c:\windows\system32\dllcache\dhtmled.ocx
2009-12-29 09:44:44 1315328 -c—-w- c:\windows\system32\dllcache\msoe.dll
2009-12-29 09:40:54 0 d—–w- C:\cf68edeb05ee70d59eca5b55e5f98155
2009-12-29 09:21:44 15064 —-a-w- c:\windows\system32\wuapi.dll.mui
2009-12-29 09:15:54 0 d—–w- c:\program files\MozyHome
2009-12-29 08:41:48 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-29 07:24:25 0 d—–w- c:\program files\AVG
2009-12-29 07:24:24 0 d—–w- c:\docume~1\alluse~1\applic~1\avg9
2009-12-29 07:20:57 0 d—–w- c:\docume~1\me\applic~1\AVG8

==================== Find3M ====================

2009-12-22 01:10:46 69 —-a-w- c:\documents and settings\me\jagex_runescape_preferences2.dat
2009-12-22 01:03:13 39 —-a-w- c:\documents and settings\me\jagex_runescape_preferences.dat
2009-10-31 12:08:09 13836 —ha-w- c:\windows\system32\mlfcache.dat
2009-10-29 07:45:38 916480 —-a-w- c:\windows\system32\wininet.dll
2009-10-29 04:48:52 499712 —-a-w- c:\windows\system32\msvcp71.dll
2009-10-29 04:48:52 348160 —-a-w- c:\windows\system32\msvcr71.dll

============= FINISH: 20:03:37.75 ===============
Hello talis and welcome to WhatTheTech. I’ll be happy to look over your log and help you with your issues. It will be very helpful if you follow these guidelines:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please follow my instructions carefully and in the order they are posted.
  • Any underlined text in my posts indicates a clickable link.
  • You should print any instruction I give you for ease of use and reference.
  • If you have any questions at all, please stop and ask before proceeding.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.This may cause a delay, but I will do my best to keep it as short as possible.

I will post back shortly with instructions.
Hi talis,

🖼Click to load external image (Posted Image) You are infected with a Rootkit. While we can remove it there are some very important things you should consider:

Rootkits and Backdoor Trojans are very dangerous because they use advanced techniques (backdoors) as a means of accessing a computer system that bypasses security mechanisms and steal sensitive information which they send back to the hacker. Many rootkits can hook into the Windows 32-bit kernel, and patch several APIs to hide new registry keys and files they install. Remote attackers use backdoor Trojans and rootkits as part of an exploit to gain unauthorized access to a computer and take control of it without your knowledge.

If your computer was used for online banking, has credit card information or other sensitive data on it, you should immediately disconnect from the Internet until your system is cleaned. All passwords should be changed immediately to include those used for banking, email, eBay, paypal and online forums. You should consider them to be compromisedY. You should change each password by using a different computer and not the infected one. If not, an attacker may get the new passwords and transaction information. If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connect again. Banking and credit card institutions should be notified of the possible security breach. Because your computer was compromised please read How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

🖼Click to load external image (Posted Image) Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please include the following in your next post:
  • ComboFix log
  • The attach.txt log from DDS
  • Let me know how your computer is running
ComboFix 10-01-20.04 - Me 01/20/2010 23:33:46.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.759.550 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Java\jre6\bin\jucheck.exe
c:\windows\system32\Data
c:\windows\system32\dllcache\ieframe.dll.mui
c:\windows\system32\srcr.dat

.
((((((((((((((((((((((((( Files Created from 2009-12-21 to 2010-01-21 )))))))))))))))))))))))))))))))
.

2010-01-19 00:34 . 2010-01-19 00:34 ——– d—–w- c:\documents and settings\Me\Application Data\Malwarebytes
2010-01-19 00:33 . 2010-01-07 21:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-19 00:33 . 2010-01-07 21:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-15 17:11 . 2010-01-15 17:11 910584 —-a-w- c:\documents and settings\All Users\Application Data\PrevxCSI\~PrevxCSIUpdate.exe
2010-01-10 18:49 . 2010-01-10 18:49 ——– d—–w- c:\windows\system32\wbem\Repository
2009-12-29 17:04 . 2010-01-20 22:59 53136 —-a-w- c:\windows\system32\PxSecure.dll
2009-12-29 17:04 . 2010-01-20 22:59 47664 —-a-w- c:\windows\system32\drivers\pxrts.sys
2009-12-29 17:04 . 2010-01-20 22:59 30280 —-a-w- c:\windows\system32\drivers\pxscan.sys
2009-12-29 17:04 . 2010-01-20 22:59 24496 —-a-w- c:\windows\system32\drivers\pxkbf.sys
2009-12-29 17:04 . 2010-01-15 17:11 ——– d—–w- c:\program files\Prevx
2009-12-29 17:04 . 2010-01-15 17:11 ——– d—–w- c:\documents and settings\All Users\Application Data\PrevxCSI
2009-12-29 15:39 . 2009-12-29 16:53 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-12-29 14:02 . 2009-12-29 14:02 52224 —-a-w- c:\documents and settings\Me\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2009-12-29 14:02 . 2009-12-29 14:02 117760 —-a-w- c:\documents and settings\Me\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-29 13:35 . 2009-12-29 13:35 117760 —-a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-29 13:34 . 2009-12-29 13:34 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-12-29 13:34 . 2009-12-29 13:34 ——– d—–w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2009-12-29 12:09 . 2009-12-29 12:09 65800 —-a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-12-29 11:52 . 2009-12-29 11:52 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-12-29 11:52 . 2009-12-29 11:52 ——– d-sh–w- c:\documents and settings\Administrator\PrivacIE
2009-12-29 11:52 . 2009-12-29 11:52 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2009-12-29 10:21 . 2009-12-29 10:21 ——– d—–w- C:\cd728dc701e6fd3f3dd7e8e79bd8
2009-12-29 10:21 . 2009-12-29 10:21 ——– d—–w- C:\fffa5f25c1195355eecdca3136a36ccd
2009-12-29 10:17 . 2009-12-29 14:41 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-12-29 10:17 . 2009-12-29 10:17 ——– d—–w- c:\documents and settings\Me\Application Data\SUPERAntiSpyware.com
2009-12-29 10:17 . 2009-12-29 10:17 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2009-12-29 10:15 . 2009-12-29 10:15 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-29 10:06 . 2009-12-29 10:06 ——– d-sh–w- c:\documents and settings\Me\PrivacIE
2009-12-29 10:06 . 2009-12-29 10:06 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-12-29 10:05 . 2009-12-29 10:05 ——– d-sh–w- c:\documents and settings\Me\IETldCache
2009-12-29 10:00 . 2009-12-29 10:00 ——– d—–w- c:\windows\system32\KB905474
2009-12-29 10:00 . 2009-03-11 03:26 1403264 —-a-w- c:\windows\system32\KB905474\wganotifypackageinner.exe
2009-12-29 10:00 . 2009-03-11 03:18 453512 —-a-w- c:\windows\system32\KB905474\wgasetup.exe
2009-12-29 09:59 . 2009-10-29 07:45 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2009-12-29 09:58 . 2009-10-29 07:45 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2009-12-29 09:58 . 2009-12-29 09:58 ——– d—–w- c:\windows\ie8updates
2009-12-29 09:58 . 2009-10-02 04:44 92160 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2009-12-29 09:56 . 2009-12-29 09:58 ——– dc-h–w- c:\windows\ie8
2009-12-29 09:51 . 2008-04-14 00:12 221184 —-a-w- c:\windows\system32\wmpns.dll
2009-12-29 09:45 . 2009-06-21 21:44 153088 -c—-w- c:\windows\system32\dllcache\triedit.dll
2009-12-29 09:44 . 2009-07-10 13:27 1315328 -c—-w- c:\windows\system32\dllcache\msoe.dll
2009-12-29 09:40 . 2009-12-29 09:45 ——– d—–w- C:\cf68edeb05ee70d59eca5b55e5f98155
2009-12-29 09:15 . 2009-12-29 10:07 ——– d—–w- c:\program files\MozyHome
2009-12-29 08:41 . 2010-01-19 00:33 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-29 07:24 . 2009-12-29 07:24 ——– d—–w- c:\program files\AVG
2009-12-29 07:24 . 2009-12-29 12:08 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2009-12-29 07:20 . 2009-12-29 07:20 ——– d—–w- c:\documents and settings\Me\Application Data\AVG8
2009-12-29 05:23 . 2009-12-29 12:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-12-29 05:18 . 2009-12-29 05:18 ——– d—–w- c:\documents and settings\Me\Local Settings\Application Data\Threat Expert
2009-12-29 05:16 . 2009-12-29 07:28 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-20 05:13 . 2009-10-13 21:18 ——– d—–w- c:\program files\Google
2010-01-15 17:11 . 2009-12-29 17:04 53136 —-a-w- c:\windows\system32\PxSecure.dll-upgrade263281.tmp
2010-01-10 18:49 . 2008-12-23 20:30 ——– d—–w- c:\program files\Windows Media Connect 2
2009-12-29 14:58 . 2008-12-23 17:33 13688 —-a-w- c:\documents and settings\Me\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-29 12:08 . 2009-12-29 12:08 ——– d—–w- c:\program files\MSBuild
2009-12-29 12:08 . 2009-12-29 12:08 ——– d—–w- c:\program files\Reference Assemblies
2009-12-22 01:10 . 2009-09-02 18:01 69 —-a-w- c:\documents and settings\Me\jagex_runescape_preferences2.dat
2009-12-22 01:03 . 2009-08-23 01:57 39 —-a-w- c:\documents and settings\Me\jagex_runescape_preferences.dat
2009-12-10 11:38 . 2009-10-31 12:04 ——– d—–w- c:\documents and settings\Me\Application Data\Apple Computer
2009-12-08 20:33 . 2009-12-08 20:33 593920 —-a-w- c:\documents and settings\Me\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\pmv305hw-0910190-0-main.dll
2009-12-08 20:33 . 2009-12-08 20:33 319488 —-a-w- c:\documents and settings\Me\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe
2009-12-05 09:04 . 2009-10-31 12:01 ——– d—–w- c:\program files\QuickTime
2009-12-05 09:04 . 2009-10-31 12:01 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-12-05 09:03 . 2009-12-05 09:03 ——– d—–w- c:\program files\Common Files\Apple
2009-12-05 09:03 . 2009-12-05 09:03 ——– d—–w- c:\program files\Apple Software Update
2009-10-31 12:08 . 2009-10-31 12:08 13836 —ha-w- c:\windows\system32\mlfcache.dat
2009-10-29 07:45 . 2004-08-04 00:56 916480 —-a-w- c:\windows\system32\wininet.dll
2009-10-29 04:48 . 2009-10-29 04:48 499712 —-a-w- c:\windows\system32\msvcp71.dll
2009-10-29 04:48 . 2009-10-29 04:48 348160 —-a-w- c:\windows\system32\msvcr71.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-01 7618560]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
c:\windows\system32\dumprep 0 -u [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
2004-06-29 15:06 88363 —-a-w- c:\windows\AGRSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
2004-09-07 18:47 57344 —-a-w- c:\windows\ALCXMNTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ——w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Updater]
2009-12-29 05:23 160752 —-a-w- c:\program files\Google\Google Updater\GoogleUpdater.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSConfig]
2008-04-14 00:12 169984 —-a-w- c:\windows\pchealth\helpctr\binaries\msconfig.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 17:50 155648 —-a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-06-01 22:22 7618560 —-a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2006-06-01 22:22 86016 —-a-w- c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-06-01 22:22 1519616 —-a-w- c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P17Helper]
2005-05-03 23:38 64512 —-a-w- c:\windows\system32\P17.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoShow Deluxe Media Manager]
2005-02-26 00:28 212992 —-a-w- c:\progra~1\Nero\data\Xtras\mssysmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 04:08 417792 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-04-23 00:12 148888 —-a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-12-29 05:23 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
2007-08-30 22:43 4670704 —-a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundParameterProblem"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)

R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [12/29/2009 12:04 PM 30280]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [12/16/2009 4:26 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/16/2009 4:26 PM 74480]
R2 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [12/29/2009 12:04 PM 6224896]
R2 pxrts;pxrts;c:\windows\system32\drivers\pxrts.sys [12/29/2009 12:04 PM 47664]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [5/23/2009 11:15 PM 24652]
R3 pxkbf;pxkbf;c:\windows\system32\drivers\pxkbf.sys [12/29/2009 12:04 PM 24496]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/16/2010 7:33 PM 135664]
S3 p17filt;p17filt;c:\windows\system32\drivers\p17filt.sys [3/20/2006 5:34 PM 1452032]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/16/2009 4:27 PM 7408]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [4/6/2009 1:19 PM 23064]

— Other Services/Drivers In Memory —

*NewlyCreated* - CSISCANNER
.
Contents of the 'Scheduled Tasks' folder

2010-01-20 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-29 05:23]

2010-01-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-17 00:33]

2010-01-20 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-12-29 03:18]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\Me\Application Data\Mozilla\Firefox\Profiles\bj7bypjk.default\
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1808.5272\npCIDetect14.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-20 23:38
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(660)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
.
Completion time: 2010-01-20 23:40:07
ComboFix-quarantined-files.txt 2010-01-21 04:39

Pre-Run: 70,300,774,400 bytes free
Post-Run: 70,265,053,184 bytes free

- - End Of File - - 077341BBADE5723FC7D8646ED0DBA64A
📎Attach.txt
Hi talis,

🖼Click to load external image (Posted Image) You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

🖼Click to load external image (Posted Image) Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply
Please include the following in your next post:
  • MBAM log
  • Kaspersky log
  • Let me know how your computer is running
talis, Are you still with us? Even if your scans were clean we have some cleanup work to do, but threads with no response after 5 days are closed. Let me know.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI