DDS log:
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 10:47:11.71 on Fri 02/19/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.895.429 [GMT -5:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\WINDOWS\system32\ctfmon.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\8KOA8ZTB\dds[1].scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.facebook.com/
mSearchAssistant = hxxp://toolbar.inbox.com/search/ie.aspx?tbid=80305
mCustomizeSearch = hxxp://toolbar.inbox.com/help/sa_customize.aspx?tbid=80305
uURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4EFB-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
BHO: 1 (0x1) - No File
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar3.dll
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
TB: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [SunKistEM] "c:\program files\digital media reader\shwiconem.exe"
mRun: []
mRun: [NvCplDaemon] "RUNDLL32.EXE" c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] "nwiz.exe" /install
mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe
mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [CHotkey] zHotkey.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [NvMediaCenter] "RUNDLL32.EXE" c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [BlackBerryAutoUpdate] c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe /background
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\deskto~1.lnk - c:\program files\research in motion\blackberry\DesktopMgr.exe
mPolicies-system: EnableLUA = 0 (0x0)
IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\canon\easy-webprint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\canon\easy-webprint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\canon\easy-webprint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\canon\easy-webprint\Resource.dll/RC_Print.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: myfantasyleague.com
Trusted Zone: buy-is2010.com
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: {7E9D8851-2735-4B13-9CE4-C5102A25CA2D} = 137.118.1.32,137.118.1.33
Notify: WRNotifier - WRLogonNTF.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\tffsmon.sys –> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\tfsysmon.sys –> c:\windows\system32\drivers\TfSysMon.sys [?]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\tfnetmon.sys –> c:\windows\system32\drivers\TfNetMon.sys [?]
=============== Created Last 30 ================
2010-02-19 09:27 411,368 a——- c:\windows\system32\deploytk.dll
2010-02-19 09:27 73,728 a——- c:\windows\system32\javacpl.cpl
2010-02-19 08:52 –d—– c:\docume~1\owner\applic~1\Malwarebytes
2010-02-19 08:52 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-19 08:52 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-02-19 08:52 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-19 08:52 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-02-19 06:19 –d—– c:\docume~1\alluse~1\applic~1\SpeedyPC
2010-02-13 05:40 –d—– c:\docume~1\owner\applic~1\Uniblue
2010-02-13 05:40 –d—– c:\program files\Uniblue
2010-02-12 23:23 351,526 a——- c:\windows\WBDDA34I.DLL
2010-02-11 23:07 408 a——- c:\windows\wininit.ini
2010-02-11 22:05 –d—– c:\program files\Spybot - Search & Destroy
2010-02-11 22:05 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-02-11 19:30 767,952 a——- c:\windows\BDTSupport.dll.old
2010-02-11 19:30 1,640,400 a——- c:\windows\PCTBDCore.dll.old
2010-02-11 19:26 –d—– c:\program files\common files\PC Tools
2010-02-11 19:26 –d—– c:\docume~1\alluse~1\applic~1\PC Tools
2010-02-11 19:22 –d—– c:\docume~1\owner\applic~1\GetRightToGo
==================== Find3M ====================
2010-02-19 10:44 256 a——- c:\documents and settings\owner\pool.bin
2009-12-31 11:14 352,640 a——- c:\windows\system32\drivers\srv.sys
2009-12-21 14:14 916,480 a——- c:\windows\system32\wininet.dll
2009-12-16 07:58 343,040 a——- c:\windows\system32\mspaint.exe
2009-12-14 02:35 33,280 a——- c:\windows\system32\csrsrv.dll
2009-12-08 13:55 2,180,352 a——- c:\windows\system32\ntoskrnl.exe
2009-12-08 13:19 2,057,728 a——- c:\windows\system32\ntkrnlpa.exe
2009-11-27 12:04 1,291,776 a——- c:\windows\system32\quartz.dll
2009-11-27 12:04 17,920 a——- c:\windows\system32\msyuv.dll
2009-11-27 11:37 84,992 a——- c:\windows\system32\avifil32.dll
2009-11-27 11:37 48,128 a——- c:\windows\system32\iyuv_32.dll
2009-11-27 11:37 28,672 a——- c:\windows\system32\msvidc32.dll
2009-11-27 11:37 11,264 a——- c:\windows\system32\msrle32.dll
2009-11-27 11:37 8,704 a——- c:\windows\system32\tsbyuv.dll
2009-11-21 11:36 470,528 a——- c:\windows\apppatch\aclayers.dll
2009-09-05 15:25 866 a——- c:\docume~1\owner\applic~1\wklnhst.dat
2007-11-22 11:37 94,208 a——- c:\program files\Bast..d.doc
2007-11-22 11:31 1,848,526 a——- c:\program files\BestBeerCommercialoftheYear.wmv
2007-11-22 11:18 736,914 a——- c:\program files\Tequila.wmv
2007-11-22 11:09 34,590 a——- c:\program files\web_071105-N-4776G-279.zip
2007-04-09 16:02 43,132,528 a——- c:\program files\TAV15.1_GM_TAV11Upgrade_32bit.exe
============= FINISH: 10:47:22.60 ===============
GMER Log:
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-02-19 10:42:38
Windows 5.1.2600 Service Pack 2
Running: m9qeq6ti.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\kgriqpog.sys
—- System - GMER 1.0.15 —-
Code 8497B385 pIofCallDriver
—- Kernel code sections - GMER 1.0.15 —-
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF65B6360, 0x1FE48D, 0xE8000020]
.text tcpip.sys!IPTransmit + 10BC F374ACFA 6 Bytes CALL 8497B368
.text tcpip.sys!IPTransmit + 263D F374C27B 6 Bytes CALL 8497B368
.text tcpip.sys!ARPRcv + 521E F37514BE 6 Bytes CALL 8497B368
.text wanarp.sys F77D13FD 7 Bytes CALL 8497B375
? C:\DOCUME~1\Owner\LOCALS~1\Temp\kgriqpod.sys The system cannot find the file specified. !
—- Kernel IAT/EAT - GMER 1.0.15 —-
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] 8497A576
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] 8497A56C
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\asc3550p
Reg HKLM\SYSTEM\CurrentControlSet\Services\asc3550p@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\asc3550p@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\asc3550p@Group SCSI miniport
Reg HKLM\SYSTEM\CurrentControlSet\Services\asc3550p@Tag 42
Reg HKLM\SYSTEM\CurrentControlSet\Services\asc3550p@Type 1
—- EOF - GMER 1.0.15 —-