This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] AntiVira Trojans, Malware, & CD/DVD not working

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A few weeks ago, my Thinkpad laptop (IBM R52, Windows XP SP3) started having trouble. First, I started getting multiple popups from Avira, mainly trojans. Then, I started receiving generic popups when starting up my computer that said I was infected with spyware, click here to scan computer, etc. Then my desktop background was changed to a message "You are infected! Please scan system for spyware" and I was getting multiple error messages popping up from the system tray on the bottom right. Finally, my CD/DVD drive stopped reading/writing, and has not been working since.

I performed the steps below per the "Are you infected?" post, and it seems to have helped. I no longer see the infected desktop background, and I am getting much less popups and seeing improved performance. My CD/DVD drive actually both reads and writes. I was still getting a couple pop ups on each restart, but even that has seemed to stop. I'm still getting some slow performance and lagging, but the big problems seem to have improved.

Thanks much in advance.

Steps taken:

- Ran ATF Cleaner
- Created System Restore Point
- Ran ERUNT
- Ran MBAM Quick Scan (see attached log)
- Ran GMER (see below - I tried to attach, but it said I am not permitted to upload this type of file, which is weird b/c it's a txt file just like the others)
- Ran DDS (see attached DDS.txt and attach.txt)

THANK YOU!



——-GMER LOG———

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-22 08:04:37
Windows 5.1.2600 Service Pack 3
Running: co6l4lhu.exe; Driver: C:\Temp\ugdirfob.sys


—- System - GMER 1.0.15 —-

SSDT F7B34FF4 ZwCreateThread
SSDT F7B34FE0 ZwOpenProcess
SSDT F7B34FE5 ZwOpenThread
SSDT F7B34FEF ZwTerminateProcess
SSDT F7B34FEA ZwWriteVirtualMemory

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwCallbackReturn + 27B8 80501FF0 4 Bytes JMP 3CF7B34F

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\Temp\login.exe[304] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00D22E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Temp\login.exe[304] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00D22C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Temp\login.exe[304] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00D22C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Temp\login.exe[304] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00D22C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[416] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00B02E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[416] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00B02C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[416] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00B02C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Logitech\QuickCam10\QuickCam10.exe[416] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00B02C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[500] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00C92E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[500] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00C92C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[500] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00C92C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[500] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00C92C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe[812] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00D12E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe[812] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00D12C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe[812] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00D12C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe[812] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00D12C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[928] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00A52E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[928] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00A52C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[928] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00A52C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe[928] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00A52C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\ctfmon.exe[984] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00522E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\ctfmon.exe[984] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00522C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\ctfmon.exe[984] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00522C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\ctfmon.exe[984] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00522C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe[996] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00CC2E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe[996] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00CC2C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe[996] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00CC2C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe[996] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00CC2C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\UserData\Desktop\co6l4lhu.exe[1384] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003C2E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\UserData\Desktop\co6l4lhu.exe[1384] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003C2C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\UserData\Desktop\co6l4lhu.exe[1384] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [003C2C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\UserData\Desktop\co6l4lhu.exe[1384] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003C2C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\IBM\Bluetooth Software\BTTray.exe[1804] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00B52E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\IBM\Bluetooth Software\BTTray.exe[1804] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00B52C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\IBM\Bluetooth Software\BTTray.exe[1804] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00B52C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\IBM\Bluetooth Software\BTTray.exe[1804] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00B52C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.EXE[2424] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [009F2E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.EXE[2424] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [009F2C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.EXE[2424] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [009F2C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.EXE[2424] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [009F2C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[2476] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00372E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[2476] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00372C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[2476] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00372C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[2476] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00372C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe[2768] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00A92E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe[2768] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00A92C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe[2768] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00A92C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe[2768] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00A92C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\Ati2evxx.exe[2892] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [009C2E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\Ati2evxx.exe[2892] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [009C2C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\Ati2evxx.exe[2892] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [009C2C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\Ati2evxx.exe[2892] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [009C2C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\rundll32.exe[3160] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00AC2E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\rundll32.exe[3160] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00AC2C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\rundll32.exe[3160] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00AC2C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\rundll32.exe[3160] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00AC2C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\iTunes\iTunesHelper.exe[3236] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00D32E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\iTunes\iTunesHelper.exe[3236] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00D32C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\iTunes\iTunesHelper.exe[3236] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00D32C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\iTunes\iTunesHelper.exe[3236] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00D32C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\TpShocks.exe[3444] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003D2E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\TpShocks.exe[3444] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003D2C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\TpShocks.exe[3444] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [003D2C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\TpShocks.exe[3444] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003D2C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Logitech\QuickCam10\COCIManager.exe[3456] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00F02E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Logitech\QuickCam10\COCIManager.exe[3456] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00F02C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Logitech\QuickCam10\COCIManager.exe[3456] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00F02C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Logitech\QuickCam10\COCIManager.exe[3456] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00F02C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe[3556] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00A32E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe[3556] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00A32C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe[3556] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00A32C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe[3556] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00A32C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\TpScrLk.exe[3636] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [009A2E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\TpScrLk.exe[3636] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [009A2C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\TpScrLk.exe[3636] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [009A2C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\TpScrLk.exe[3636] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [009A2C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe[3652] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [010F2E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe[3652] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [010F2C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe[3652] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [010F2C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe[3652] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [010F2C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe[3676] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [009D2E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe[3676] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [009D2C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe[3676] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [009D2C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe[3676] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [009D2C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\wuauclt.exe[3728] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00512E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\wuauclt.exe[3728] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00512C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\wuauclt.exe[3728] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00512C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\wuauclt.exe[3728] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00512C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[3772] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00AC2E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[3772] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00AC2C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[3772] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00AC2C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[3772] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00AC2C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe[3788] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [009F2E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe[3788] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [009F2C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe[3788] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [009F2C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe[3788] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [009F2C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe[3792] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [009B2E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe[3792] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [009B2C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe[3792] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [009B2C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe[3792] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [009B2C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[3832] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00A32E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[3832] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00A32C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[3832] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00A32C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\dla\tfswctrl.exe[3832] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00A32C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\rundll32.exe[3888] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00AC2E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\rundll32.exe[3888] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00AC2C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\rundll32.exe[3888] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00AC2C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\rundll32.exe[3888] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00AC2C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe[3960] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00A32E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe[3960] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00A32C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe[3960] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00A32C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe[3960] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00A32C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\ThinkPad\UTILIT~1\NPDTray.exe[4008] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003D2E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\ThinkPad\UTILIT~1\NPDTray.exe[4008] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003D2C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\ThinkPad\UTILIT~1\NPDTray.exe[4008] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [003D2C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\PROGRA~1\ThinkPad\UTILIT~1\NPDTray.exe[4008] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003D2C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4024] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00A52E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4024] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00A52C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4024] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00A52C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[4024] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00A52C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe[4088] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003D2E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe[4088] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003D2C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe[4088] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [003D2C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe[4088] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003D2C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Mozilla Firefox\firefox.exe[5748] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [009D2E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Mozilla Firefox\firefox.exe[5748] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [009D2C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Mozilla Firefox\firefox.exe[5748] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [009D2C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Mozilla Firefox\firefox.exe[5748] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [009D2C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Udfs \UdfsCdRom tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Udfs \UdfsDisk tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 TPInput.sys (IBM SATA Power Management Driver/IBM Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 TPInput.sys (IBM SATA Power Management Driver/IBM Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\ControlSet001\Services\BTHPORT\Parameters\Keys\000e9b90c984 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\BTHPORT\Parameters\Keys\000e9b9c5653 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\BTHPORT\Parameters\Keys\000e9b9d852d (not active ControlSet)
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000e9b90c984
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000e9b9c5653
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000e9b9d852d
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000e9b90c984 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000e9b9c5653 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000e9b9d852d (not active ControlSet)
Reg HKLM\SOFTWARE\Classes\CLSID\{00142B4A-0944-DA36-84AB-800768B60C5D}\InProcServer32@ %SystemRoot%\system32\browseui.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{00142B4A-0944-DA36-84AB-800768B60C5D}\InProcServer32@ThreadingModel Apartment
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@Í\x2039í\x2039T\x20acó` 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@Í\x2039í\x2039\x201c\x008feQ 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@\20\x90\20nÐc:y 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@\26Y\1xÐc:y 1
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@Òczz Reg HKCU\Software\Microsoft\Windows\CurrentVersion\@IQ\ahß\x8d\x8f\x2013 1

—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 sector 62: copy of MBR

—- EOF - GMER 1.0.15 —-
Hello kt_crow and welcome to WhatTheTech. I’ll be happy to look over your log and help you with your issues. It will be very helpful if you follow these guidelines:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please follow my instructions carefully and in the order they are posted.
  • Any underlined text in my posts indicates a clickable link.
  • You should print any instruction I give you for ease of use and reference.
  • If you have any questions at all, please stop and ask before proceeding.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.This may cause a delay, but I will do my best to keep it as short as possible.

I will post back as soon as possible with instructions.
kt_crow,

🖼Click to load external image (Posted Image) You are infected with a backdoor trojan. Rootkits and Backdoor Trojans are very dangerous because they use advanced techniques (backdoors) as a means of accessing a computer system that bypass security mechanisms and steal sensitive information which they send back to the hacker.

If your computer was used for online banking, has credit card information or other sensitive data on it, you should immediately limit your online activity until your system is cleaned. All passwords should be changed immediately using a different computer. Banking and credit card institutions should be notified of the possible security breach. Because your computer was compromised please read How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

🖼Click to load external image (Posted Image) P2P - I see you have P2P software (uTorrent, BTDNA, BitTorrent, Limewire) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares. I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs. If you choose to keep these applications, please do not use them until our fixes at WTT are complete.

🖼Click to load external image (Posted Image) Please download DeFogger to your desktop.
Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • If it needs to, DeFogger may ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.
Do not re-enable these drivers until otherwise instructed.

🖼Click to load external image (Posted Image) Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please include the following in your next post:
  • ComboFix log
Thanks for the info. I will take the necessary steps with the ID protection, and I have uninstalled the programs you mentioned. Please keep including other suggestions on programs to uninstall if you have any. Below are the steps taken since the last post. Thanks for the help. - Ran DeFogger - Ran Combofix (see attached log) EDIT: A quick question- I have not downloaded and installed the Windows Updates in a while (it keeps prompting me but I've been putting it off) - should I do this? Thanks.
kt_crow,

That looks better. How is the computer running? I have one more fix, then a copule of scans for you to run:

🖼Click to load external image (Posted Image) Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad ) and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above http://

http://forums.whatthetech.com/AntiVira_Trojans_Malware_and_CD_DVD_not_working_t110463.html&gopid=635402#entry635402

Collect::
c:\documents and settings\WFUR522005\Local Settings\Application Data\syssvc.exe

Folder::
c:\temp\RarSFX1

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.


🖼Click to load external image (Posted Image) You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

🖼Click to load external image (Posted Image) Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply
Please include the following in your next post:
  • MBAM log
  • Kaspersky log
  • A fresh DDS.txt log
kt_crow,

Great job - your logs look clean! Be sure to reboot if you haven't already so MBAM can remove those files. I'm sorry I overlooked your question; please run those Windows Updates now then follow these important cleanup and housekeeping instructions:

🖼Click to load external image (Posted Image) Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 6 and save it to your desktop.
  • Scroll down to where it says "Java SE Runtime Environment (JRE) 6 Update 18. The Java SE Runtime Environment (JRE) allows end-users to run Java applications."
  • Click the "Download" button to the right.
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: " I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Now go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u18-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH Checked
      Applications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.
🖼Click to load external image (Posted Image) Your Adobe reader needs to be updated. Please visit Adobe's site and grab the newest version.

Go HERE to scan for any other out of date and/or vulnerable applications on your computer and follow the instructions given for updating them.

🖼Click to load external image (Posted Image) Uninstall ComboFix
  • Press the Windows key + R on your keyboard or click Start -> Run. Copy and past the following text into the run box that opens:
    Combofix /Uninstall
🖼Click to load external image (Posted Image)

🖼Click to load external image (Posted Image) To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.
Your Emulation drivers are now re-enabled.

🖼Click to load external image (Posted Image) Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
🖼Click to load external image (Posted Image) Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.
  • Manually delete any remaining logs or tools from our fixes
🖼Click to load external image (Posted Image) Finally, I'd like to make a couple of suggestions to help you stay clean in the future:
  • Restart any anti-malware programs that we disabled while we were cleaning your machine.
  • Keep your antivirus application current and updated. Also, hang on to MBAM. Scan with them at least weekly.
  • Avoid using P2P programs! Refer back to my earlier post for more information.
  • Consider running in a limited user account. See this post for more information.
  • Please carefully review the information in our Security - Best Practices and Prevention forum located HERE
Please post once more so I know you are all set and I can close this thread. Good luck and stay safe!
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please follow the instructions here http://forums.whatthetech.com/you_Infected_t106388.html
and start a New Topic.

EDIT: Topic opened at request of Original Poster
kt_crow,

Let's have a look. I'm also going to have one of our Tech experts stop in and take a look at those crash dumps.

🖼Click to load external image (Posted Image) Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
🖼Click to load external image (Posted Image) Please download DeFogger to your desktop.
Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • If it needs to, DeFogger may ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.
Do not re-enable these drivers until otherwise instructed.

🖼Click to load external image (Posted Image) Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Please include the following in your next post:
  • DDS.txt log
  • GMER log
  • As much detail as you can possibly give about your BSOD crash.
  • How is the computer running now?
So the BSOD crashes are repeating, and happening about 5-10 minutes after on I turn on my computer and boot up to windows. It's not really related to a specific process during startup or something that I am doing that causes the crash. Sometimes I am able to stay on longer - hence how I am running your steps and posting this now. A couple pieces of info on the BSOD: 1) Now my desktop comes up and says "Active Desktop Recovery" - Windows has experienced an unexpected error and as a precaution has turned your active desktop off. 2) The error message that appears once I'm able to boot up after the BSOD crashes - "Windows has recovered from a serious error" - I was able to click more information and copy/pasted the below from the error report. It looks like these were the files affected? C:\Temp\WER4ddc.dir00\Mini022810-02.dmp C:\Temp\WER4ddc.dir00\sysdata.xml Other than that I'm not sure exactly what else to say about the BSOD, but it is recurring and I haven't been able to spend any extended period booted up without a BSOD crash. EDIT: I got no trouble running the DDS, DeFogger, or GMER. And no 'rootkit' entries from GMER… Please see below for the DDS log, and attached for the GMER and the Attach log. —————— DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 7:08:18.85 on Tue 03/02/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_18 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.521 [GMT -8:00] AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7} ============== Running Processes =============== C:\WINDOWS\system32\ibmpmsvc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe svchost.exe C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Bonjour\mDNSResponder.exe svchost.exe C:\Program Files\IBM\Bluetooth Software\bin\btwdins.exe C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\System32\TPHDEXLG.EXE C:\WINDOWS\system32\TpKmpSVC.exe C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.EXE C:\WINDOWS\system32\TpShocks.exe C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe C:\WINDOWS\system32\acs.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\TpScrLk.exe C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe C:\Program Files\Logitech\QuickCam10\QuickCam10.exe C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\PROGRA~1\ThinkPad\UTILIT~1\NPDTray.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\IBM\Bluetooth Software\BTTray.exe C:\Program Files\Logitech\QuickCam10\COCIManager.exe C:\Program Files\3M\PSNLite\PsnLite.exe C:\Program Files\iPod\bin\iPodService.exe C:\PROGRA~1\3M\PSNLite\PSNGive.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\UserData\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://student.wfu.edu/ uInternet Connection Wizard,ShellNext = hxxp://student.wfu.edu/ uSearchURL,(Default) = hxxp://www.google.com/keyword/%s BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll TB: SciFinder Scholar Bar: {4e16a8fb-0521-46d1-aa2c-d0fc7abf6af9} - mscoree.dll TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\acrobat\AdobeUpdateManager.exe" AcPro7_0_8 -reboot 1 uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [TPKMAPHELPER] c:\program files\thinkpad\utilities\TpKmapAp.exe -helper mRun: [TpShocks] TpShocks.exe mRun: [TPHOTKEY] c:\progra~1\thinkpad\pkgmgr\hotkey\TPHKMGR.exe mRun: [TP4EX] tp4ex.exe mRun: [EZEJMNAP] c:\progra~1\thinkpad\utilit~1\EzEjMnAp.Exe mRun: [dla] c:\windows\system32\dla\tfswctrl.exe mRun: [PWRMGRTR] rundll32 c:\progra~1\thinkpad\utilit~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [IMEKRMIG6.1] c:\windows\ime\imkr6_1\IMEKRMIG.EXE mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent mRun: [IMJPMIG9.0] c:\progra~1\common~1\micros~1\ime\imjp9\IMJPMIG.EXE /Preload /Migration32 mRun: [IMSCMig] c:\progra~1\common~1\micros~1\ime\imsc40a\IMSCMIG.EXE /Preload mRun: [CJIMETIPSYNC] c:\program files\common files\microsoft shared\ime\imtc65\changjie\CINTLCFG.EXE /CJIMETIPSync mRun: [PHIMETIPSYNC] c:\program files\common files\microsoft shared\ime\imtc65\phonetic\TINTLCFG.EXE /PHIMETIPSync mRun: [BLOG] rundll32 c:\progra~1\thinkpad\utilit~1\BatLogEx.DLL,StartBattLog mRun: [TPKBDLED] c:\windows\system32\TpScrLk.exe mRun: [LogitechCommunicationsManager] "c:\program files\common files\logitech\lcommgr\Communications_Helper.exe" mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam10\QuickCam10.exe" /hide mRun: [LVCOMSX] "c:\program files\common files\logitech\lcommgr\LVComSX.exe" mRun: [ACTray] c:\program files\thinkpad\connectutilities\ACTray.exe mRun: [ACWLIcon] c:\program files\thinkpad\connectutilities\ACWLIcon.exe mRun: [mxomssmenu] "c:\program files\maxtor\onetouch status\maxmenumgr.exe" mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [avgnt] "c:\program files\avira\antivir personaledition classic\avgnt.exe" /min mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [NPDTRAY] c:\progra~1\thinkpad\utilit~1\NPDTray.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-7760-100000000002}\SC_Acrobat.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\bttray.lnk - c:\program files\ibm\bluetooth software\BTTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\post-i~1.lnk - c:\program files\3m\psnlite\PsnLite.exe IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: Send To &Bluetooth - c:\program files\ibm\bluetooth software\btsendto_ie_ctx.htm IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\ibm\bluetooth software\btsendto_ie.htm IE: {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - c:\program files\thinkpad\pkgmgr\\PkgMgr.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {3BA494B1-D507-4C11-9BDA-D47E1A65DFCF} - hxxps://access.thehartford.com/llclient/Juniper503/winxp/,DanaInfo=wholesecurity.thehartford.com,CT=java+AXXPEE.dll DPF: {41F17733-B041-4099-A042-B518BB6A408C} - hxxp://appldnld.m7z.net/qtinstall.info.apple.com/pthalo/us/win/QuickTimeFullInstaller.exe DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} - hxxp://acs.pandasoftware.com/activescan/as5free/asinst.cab DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - hxxp://fdl.msn.com/zone/datafiles/heartbeat.cab DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://access.thehartford.com/dana-cached/setup/JuniperSetupSP1.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Handler: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - c:\windows\system32\BTXPPanel.dll Notify: AtiExtEvent - Ati2evxx.dll STS: IE Component Categories cache daemon: {553858a7-4922-4e7e-b1c1-97140c1c16ef} - c:\windows\system32\ieframe.dll SEH: CShellExecuteHookImpl Object: {57b86673-276a-48b2-bae7-c6dbb3020eb8} - c:\program files\grisoft\avg anti-spyware 7.5\shellexecutehook.dll SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll Hosts: 94.232.248.66 browser-security.microsoft.com Hosts: 94.232.248.66 antivirprotection.com Hosts: 94.232.248.66 www.antivirprotection.com ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\wfur52~1\applic~1\mozilla\firefox\profiles\8nss0saj.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.usatoday.com/sports/tv.htm FF - component: c:\program files\mozilla firefox\components\ffwt.dll FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R0 TPDiskPM;TPDiskPM;c:\windows\system32\drivers\TPDiskPM.sys [2005-3-21 14208] R1 AVG Anti-Spyware Driver;AVG Anti-Spyware Driver;c:\program files\grisoft\avg anti-spyware 7.5\guard.sys [2007-5-30 11000] R1 AvgAsCln;AVG Anti-Spyware Clean Driver;c:\windows\system32\drivers\AvgAsCln.sys [2007-8-29 10872] R1 avgio;avgio;c:\program files\avira\antivir personaledition classic\avgio.sys [2009-3-5 11608] R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler;c:\program files\avira\antivir personaledition classic\sched.exe [2009-3-5 68865] R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard;c:\program files\avira\antivir personaledition classic\avguard.exe [2009-3-5 151297] R2 AVG Anti-Spyware Guard;AVG Anti-Spyware Guard;c:\program files\grisoft\avg anti-spyware 7.5\guard.exe [2007-5-30 312880] R2 ZDCNDIS5;ZDCNDIS5 NDIS5.1 Protocol Driver;c:\windows\system32\ZDCndis5.sys [2009-1-5 20736] R3 avgntflt;avgntflt;c:\program files\avira\antivir personaledition classic\avgntflt.sys [2009-3-5 52056] R3 TPInput;TPInput;c:\windows\system32\drivers\TPInput.sys [2005-3-21 6016] S4 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [2005-11-14 155136] S4 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [2005-11-14 5248] =============== Created Last 30 ================ 2010-03-02 15:08:17 0 d—–w- c:\temp\B.tmp 2010-03-02 15:07:14 0 d-sh–w- c:\documents and settings\wfur522005\IECompatCache 2010-03-02 14:52:03 16384 —-atw- c:\temp\Perflib_Perfdata_3f4.dat 2010-03-02 14:49:09 16384 —-atw- c:\temp\Perflib_Perfdata_478.dat 2010-03-02 14:39:48 16384 —-atw- c:\temp\Perflib_Perfdata_3fc.dat 2010-03-02 14:27:00 16384 —-atw- c:\temp\Perflib_Perfdata_4e4.dat 2010-03-02 14:13:51 16384 —-atw- c:\temp\Perflib_Perfdata_28c.dat 2010-03-02 13:23:33 16384 —-atw- c:\temp\Perflib_Perfdata_4c8.dat 2010-03-02 13:10:38 16384 —-atw- c:\temp\Perflib_Perfdata_4a4.dat 2010-03-02 12:57:30 16384 —-atw- c:\temp\Perflib_Perfdata_490.dat 2010-03-02 12:44:39 16384 —-atw- c:\temp\Perflib_Perfdata_450.dat 2010-03-02 12:31:34 16384 —-atw- c:\temp\Perflib_Perfdata_48c.dat 2010-03-02 12:18:39 16384 —-atw- c:\temp\Perflib_Perfdata_4c4.dat 2010-03-02 12:05:10 16384 —-atw- c:\temp\Perflib_Perfdata_3f0.dat 2010-03-02 11:51:51 16384 —-atw- c:\temp\Perflib_Perfdata_3ec.dat 2010-03-02 11:38:46 16384 —-atw- c:\temp\Perflib_Perfdata_444.dat 2010-03-02 11:25:48 16384 —-atw- c:\temp\Perflib_Perfdata_454.dat 2010-03-02 11:12:46 16384 —-atw- c:\temp\Perflib_Perfdata_404.dat 2010-03-02 10:59:52 16384 —-atw- c:\temp\Perflib_Perfdata_3cc.dat 2010-03-02 10:46:49 16384 —-atw- c:\temp\Perflib_Perfdata_4dc.dat 2010-03-02 10:07:30 16384 —-atw- c:\temp\Perflib_Perfdata_3e4.dat 2010-03-02 09:15:11 16384 —-atw- c:\temp\Perflib_Perfdata_440.dat 2010-03-02 09:02:11 16384 —-atw- c:\temp\Perflib_Perfdata_47c.dat 2010-03-02 08:23:22 16384 —-atw- c:\temp\Perflib_Perfdata_468.dat 2010-03-02 06:50:05 16384 —-atw- c:\temp\Perflib_Perfdata_4d4.dat 2010-03-02 06:48:50 0 d—–w- c:\temp\WER58df.dir00 2010-03-02 06:18:29 16384 —-atw- c:\temp\Perflib_Perfdata_d34.dat 2010-03-02 06:17:03 0 d—–w- c:\temp\WER738a.dir00 2010-03-02 06:15:13 16384 —-atw- c:\temp\Perflib_Perfdata_434.dat 2010-03-02 05:59:00 16384 —-atw- c:\temp\Perflib_Perfdata_46c.dat 2010-03-02 05:34:33 16384 —-atw- c:\temp\Perflib_Perfdata_42c.dat 2010-03-02 05:19:35 16384 —-atw- c:\temp\Perflib_Perfdata_40c.dat 2010-03-02 05:06:37 16384 —-atw- c:\temp\Perflib_Perfdata_488.dat 2010-03-02 04:57:15 16384 —-atw- c:\temp\Perflib_Perfdata_3d0.dat 2010-03-02 04:39:18 16384 —-atw- c:\temp\Perflib_Perfdata_4bc.dat 2010-03-02 04:06:19 16384 —-atw- c:\temp\Perflib_Perfdata_f20.dat 2010-03-02 04:03:01 16384 —-atw- c:\temp\Perflib_Perfdata_3d8.dat 2010-03-02 03:39:27 16384 —-atw- c:\temp\Perflib_Perfdata_ecc.dat 2010-03-02 03:36:40 16384 —-atw- c:\temp\Perflib_Perfdata_470.dat 2010-03-02 03:20:13 16384 —-atw- c:\temp\Perflib_Perfdata_3e8.dat 2010-03-02 03:03:46 16384 —-atw- c:\temp\Perflib_Perfdata_2b0.dat 2010-03-02 03:00:56 16384 —-atw- c:\temp\Perflib_Perfdata_424.dat 2010-03-02 02:42:53 16384 —-atw- c:\temp\Perflib_Perfdata_a78.dat 2010-03-02 02:38:49 16384 —-atw- c:\temp\Perflib_Perfdata_3f8.dat 2010-03-01 08:08:27 0 d-sh–w- c:\documents and settings\wfur522005\PrivacIE 2010-03-01 08:06:24 16384 —-atw- c:\temp\Perflib_Perfdata_ef8.dat 2010-03-01 08:03:11 16384 —-atw- c:\temp\Perflib_Perfdata_4b4.dat 2010-03-01 04:50:15 0 d—–w- c:\temp\hsperfdata_crowkt3 2010-03-01 04:37:00 16384 —-atw- c:\temp\Perflib_Perfdata_fb8.dat 2010-03-01 04:34:05 16384 —-atw- c:\temp\Perflib_Perfdata_4d0.dat 2010-03-01 03:59:42 16384 —-atw- c:\temp\Perflib_Perfdata_648.dat 2010-03-01 03:55:13 16384 —-atw- c:\temp\Perflib_Perfdata_474.dat 2010-03-01 03:41:58 16384 —-atw- c:\temp\Perflib_Perfdata_43c.dat 2010-03-01 03:26:20 16384 —-atw- c:\temp\Perflib_Perfdata_44c.dat 2010-03-01 03:14:27 16384 —-atw- c:\temp\Perflib_Perfdata_380.dat 2010-03-01 00:42:19 1089593 -c—-w- c:\windows\system32\dllcache\ntprint.cat 2010-02-28 04:47:04 16384 —-atw- c:\temp\Perflib_Perfdata_430.dat 2010-02-28 04:29:03 73728 —-a-w- c:\windows\system32\javacpl.cpl 2010-02-28 01:07:55 0 d—–w- c:\windows\system32\XPSViewer 2010-02-28 01:06:57 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll 2010-02-28 01:06:57 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2010-02-28 01:06:57 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll 2010-02-28 01:06:57 575488 ——w- c:\windows\system32\xpsshhdr.dll 2010-02-28 01:06:57 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll 2010-02-28 01:06:57 1676288 ——w- c:\windows\system32\xpssvcs.dll 2010-02-28 01:06:57 117760 ——w- c:\windows\system32\prntvpt.dll 2010-02-28 01:06:57 0 d—–w- C:\c5e604d1486180724c8b2227b2c2 2010-02-26 05:07:20 0 d-sh–w- c:\documents and settings\wfur522005\IETldCache 2010-02-26 04:37:29 69120 -c—-w- c:\windows\system32\dllcache\iecompat.dll 2010-02-26 04:36:47 0 d—–w- c:\windows\ie8updates 2010-02-26 04:36:19 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll 2010-02-26 04:36:16 594432 -c—-w- c:\windows\system32\dllcache\msfeeds.dll 2010-02-26 04:36:16 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll 2010-02-26 04:36:15 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll 2010-02-26 04:36:15 1985536 -c—-w- c:\windows\system32\dllcache\iertutil.dll 2010-02-26 04:32:59 0 dc-h–w- c:\windows\ie8 2010-02-24 04:22:33 50176 -c–a-w- c:\windows\system32\dllcache\proquota.exe 2010-02-24 04:22:33 50176 —-a-w- c:\windows\system32\proquota.exe 2010-02-22 03:29:42 52 —-a-w- c:\documents and settings\wfur522005\defogger_reenable ==================== Find3M ==================== 2010-02-28 04:28:38 411368 —-a-w- c:\windows\system32\deploytk.dll 2010-01-08 00:07:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-08 00:07:04 19160 —-a-w- c:\windows\system32\drivers\mbam.sys 2009-12-21 19:14:05 916480 —-a-w- c:\windows\system32\wininet.dll 2009-12-16 18:43:27 343040 —-a-w- c:\windows\system32\mspaint.exe 2009-12-14 07:08:23 33280 —-a-w- c:\windows\system32\csrsrv.dll 2009-12-08 19:27:51 2189184 ——w- c:\windows\system32\ntoskrnl.exe 2009-12-08 18:43:50 2066048 ——w- c:\windows\system32\ntkrnlpa.exe 2007-09-20 03:35:30 10 —-a-w- c:\program files\.autoreg 2009-03-14 15:56:09 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009031420090315\index.dat ============= FINISH: 7:09:46.64 ===============
kt_crow,

You have some strange looking HOST file entries there, let's reset it:

🖼Click to load external image (Posted Image) To reset the hosts file back to the default, follow these steps:
  • Click Start, click Run, type %systemroot% \system32\drivers\etc, and then click OK.
  • Rename the hosts file to hosts.bak. (Right click on the file and select "rename" from the menu)
  • Create the new default hosts file. To do this, follow these steps:
  • Right-click an open space in the %WinDir%\system32\drivers\etc folder
  • Point to New, click Text Document, type hosts, and then press ENTER
  • Click Yes to confirm that the file name extension will not be txt
  • Open the new created hosts file in a text editor, for example, in the Notepad
  • Copy the following text to the file:
    127.0.0.1 localhost
🖼Click to load external image (Posted Image) Turn On Minidumps
If you havn't already turned on minidumps, go to the Control Panel and follow this steps:

1. Click Start,click Control Panel.
2. Double-click System.
3. In the next panel (System Properties) Click the Advanced tab, and then click Settings under Startup and Recovery.
4. In the Write debugging information list, Select Small memory dump (64k) (arrow-down menu).

🖼Click to load external image (Posted Image) The next time you have a BSOD, either take a Screen Shoot, or write down with paper and pencil, the Stop/Error warning code information, including "all" of the details "exactly" as they appear on the Blue screen. Post them as you get them.

🖼Click to load external image (Posted Image) Navigate to this folder
C:\Temp\WER4ddc.dir00

Attach the 3 most recent files in there to your next post.
1) I navigated to the directory mentioned in your host reset instructions, and there was no "host" file to rename to host.bak. I created the new host file per your instructions, but could not find that file to rename. 2) I turned on minidumps per instructions, no problem 3) BSOD - see attached screenshot 4) There was no directory "C:\Temp\WER4ddc.dir00" I have 2 similar directories, "C;\Temp\WER58df.dir00" and C:\Temp\WER738a.dir00" - each have 3 files in them (a manifest file, a mini.dmp file, and sysdata file) - would you like me to post the files from one of those directories? I'm still getting the BSOD crashes about 10 minutes after booting up, and the active desktop warning message I posted earlier is still coming up as well. Please let me know what other info I can provide, and thanks again for all your help.

Attachments:

kt_crow,

This tool should help with your HOST file:

🖼Click to load external image (Posted Image) Please download HostsXpert
  • Unzip HostsXpert to it's own folder a convenient place such as C:\HostsXpert
  • Run HostsXpert.exe
  • Click: Make Writable? in the upper left corner.
  • Click: Restore MS Hosts File
  • Click: OK
  • Click: Make ReadOnly
  • Close HostsXpert.
Note: If a custom Hosts file was in place, you will have to run those programs again to reset detections.
If needed Tutorial

🖼Click to load external image (Posted Image) Find the three most recent mini.dmp files and attach them to your next post, along with a fresh DDS log.
kt_crow,

Your logs don't show any malware hanging around, so I'm going to turn you over to our Tech. Team. They can better help you with your BSOD issues. Please run the following tool to re-enable your emulation drivers, then start a new topic HERE in our Microsoft Windows forum. Be sure to include a link to this thread so whomever helps you can access the information you have already provided.

🖼Click to load external image (Posted Image) To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.
Your Emulation drivers are now re-enabled.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI