This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Please help remove: Win32:Rootkit-gen [Rtk]

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Avast has picked up Win32:Rootkit-gen [Rtk] and cannot remove it. Also while downloading the necessary tools suggested to help remove infections, Malwarebytes will not download. Thankyou. Crystal
Hello Crystal and welcome to WhatTheTech. I’ll be happy to look over your log and help you with your issues. It will be very helpful if you follow these guidelines:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please follow my instructions carefully and in the order they are posted.
  • Any underlined text in my posts indicates a clickable link.
  • You should print any instruction I give you for ease of use and reference.
  • If you have any questions at all, please stop and ask before proceeding.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.This may cause a delay, but I will do my best to keep it as short as possible.

I will post back as soon as possible with instructions.
Hi Crystal,

Were you able to download and run DDS or GMER? If you attempted and failed, please let me know what happed. If you stopped after MBAM failed, please try to continue with these instructions. If you can, I'd like the details of the warning Avast is giving you (ie: file location, etc) also.

🖼Click to load external image (Posted Image) Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
🖼Click to load external image (Posted Image) Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Please include the following in your next post:
  • DDS.txt & Attach.txt logs
  • GMER log
  • Details from Avast warning
Hi
Thankyou so much for helping me. Here is what you requested.


DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 17:51:57.10 on Fri 26/02/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.2.1252.61.1033.18.511.101 [GMT 10:00]

AV: avast! antivirus 4.8.1368 [VPS 100225-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\vVX1000.exe
C:\Program Files\Telstra\BigPond Wireless Broadband 2.0\BigPond_CM.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe -k bthsvcs
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com.au/
uSearch Page = hxxp://ffinder.com/
uSearch Bar = hxxp://ffinder.com/
uWindow Title =
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}
uInternet Settings,ProxyServer = localhost:2323
uInternet Settings,ProxyOverride = local;*.local
uSearchAssistant = hxxp://www.google.com/ie
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: BigPond Wireless Broadband 2.0 Auto Dial: {db92ec3f-697d-4c3b-9a3b-3abbd23d4a85} - c:\program files\telstra\bigpond wireless broadband 2.0\bpwbb2ad.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [LifeCam] "c:\program files\microsoft lifecam\LifeExp.exe"
mRun: [VX1000] c:\windows\vVX1000.exe
mRun: [BigPondWirelessBroadbandCM] "c:\program files\telstra\bigpond wireless broadband 2.0\BigPond_CM.exe" -tsr
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Pgiqazopesi] rundll32.exe "c:\windows\axebuhogeh.dll",Startup
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\documents and settings\crystal & addz.home-8b021c13ce\start menu\programs\startup\monnid32.exe
uPolicies-explorer: NoViewOnDrive = 67108352 (0x3fffe00)
uPolicies-system: NoVisualStyleChoice = 0 (0x0)
uPolicies-system: NoColorChoice = 0 (0x0)
uPolicies-system: NoSizeChoice = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office10\EXCEL.EXE/3000
IE: Transfer by Image Converter 2 - c:\program files\sony\image converter 2\menu.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1189190842093
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - hxxp://awbeta.net-nucleus.com/FIX/WinATS.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} - hxxp://support.packardbell.com/files/activex/InfosFinder2.CAB
AppInit_DLLs: winmm.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: {92050ffb-b796-4146-ae27-7e5e1d93b8a8} - No File
LSA: Notification Packages = scecli upwmil.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\crysta~1.hom\applic~1\mozilla\firefox\profiles\mppc2bn9.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - plugin: c:\progra~1\yahoo!\common\npyaxmpb.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: XULRunner: {B868EC20-08F5-4129-B6E1-D0577ACF3EEE} - c:\documents and settings\crystal & addz.home-8b021c13ce\local settings\application data\{B868EC20-08F5-4129-B6E1-D0577ACF3EEE}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-8-4 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-8-4 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-8-4 138680]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [2009-8-17 235648]
S2 BT848;AVerMedia, AVerTV WDM Video Capture;c:\windows\system32\drivers\bt848.sys [2002-5-13 261696]
S2 BTTUNER;AVerMedia, AVerTV WDM TvTuner;c:\windows\system32\drivers\bttuner.sys [2002-1-27 22016]
S2 BTXBAR;AVerMedia, AVerTV WDM Crossbar;c:\windows\system32\drivers\btxbar.sys [2002-1-27 792064]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-8-4 254040]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-8-4 352920]
S3 cmusbnet;WAN Driver @ 3GPP (6280);c:\windows\system32\drivers\cmusbnet.sys [2006-11-23 87424]
S3 cmusbser;%CMUSBSER%;c:\windows\system32\drivers\cmusbser.sys [2006-12-13 87040]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-2-24 38224]
S3 SNCT511;PC Camera (6005 CIF);c:\windows\system32\drivers\snct511.sys [2007-8-24 219264]

=============== Created Last 30 ================

2010-02-23 17:03:11 0 d—–w- c:\docume~1\crysta~1.hom\applic~1\Malwarebytes
2010-02-23 17:03:05 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-23 17:03:03 0 d—–w- c:\docume~1\alluse~1.win\applic~1\Malwarebytes
2010-02-23 17:03:02 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-23 17:03:02 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-23 16:03:47 0 —-a-w- c:\windows\Obapezupewada.bin
2010-02-23 16:03:45 120 —-a-w- c:\windows\Ydicejukoze.dat
2010-02-23 15:58:50 4 —-a-w- c:\docume~1\crysta~1.hom\applic~1\avdrn.dat
2010-02-08 23:53:24 0 d—–w- c:\docume~1\crysta~1.hom\applic~1\Office Genuine Advantage
2010-02-07 10:18:48 0 d–h–w- c:\windows\system32\GroupPolicy
2010-02-06 14:47:03 0 d—–w- c:\documents and settings\crystal & addz.home-8b021c13ce\Shared
2010-02-06 14:46:56 0 d—–w- c:\documents and settings\crystal & addz.home-8b021c13ce\Incomplete
2010-02-01 11:08:53 0 d—–w- c:\documents and settings\crystal & addz.home-8b021c13ce\Tracing
2010-02-01 11:07:29 0 d—–w- c:\program files\Microsoft
2010-02-01 11:07:10 0 d—–w- c:\program files\Windows Live SkyDrive
2010-02-01 10:57:30 0 d—–w- c:\program files\common files\Windows Live
2010-02-01 10:37:26 0 d-sh–w- c:\documents and settings\crystal & addz.home-8b021c13ce\IETldCache
2010-02-01 10:28:58 69120 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2010-02-01 10:28:19 0 d—–w- c:\windows\ie8updates
2010-02-01 10:27:31 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2010-02-01 10:27:22 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2010-02-01 10:22:08 0 dc-h–w- c:\windows\ie8
2010-02-01 09:52:11 0 d—–w- c:\docume~1\alluse~1.win\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-02-01 09:16:59 0 d—–w- c:\docume~1\alluse~1.win\applic~1\Sony Corporation
2010-02-01 09:00:18 294912 -c—-w- c:\windows\system32\dllcache\msctf.dll

==================== Find3M ====================

2010-02-24 13:31:38 792064 —-a-w- c:\windows\system32\drivers\btxbar.sys
2010-02-23 16:08:51 792064 —-a-w- c:\windows\system32\drivers\btxbar.sys.bak
2009-12-31 16:14:12 352640 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14:05 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-16 12:58:04 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 19:15:14 2146304 —-a-w- c:\windows\system32\GPhotos.scr
2009-12-14 07:35:35 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-08 18:53:08 2136064 —-a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:19:32 2015744 —-a-w- c:\windows\system32\ntkrnlpa.exe

============= FINISH: 17:52:42.25 ===============

DDS.pif comes up with a page of symbols when I try to open it.

"Access is denied" to GMER.txt

Avast :

File name: C:\WINDOWS\upwmil.dll
Malware name: Win32:Hilot [Trj]
Malware Type: Trojan Horse
VPS Version: 100224-1, 24/02/2010
Crystal,

🖼Click to load external image (Posted Image) You are infected with a trojan know to sometimes have backdoor properties. Rootkits and Backdoor Trojans are very dangerous because they use advanced techniques (backdoors) to bypass security mechanisms and steal sensitive information which they send back to the hacker.

If your computer was used for online banking, has credit card information or other sensitive data on it, you should immediately limit your online activity until your system is cleaned. All passwords should be changed immediately using a different computer. Banking and credit card institutions should be notified of the possible security breach. Because your computer was compromised please read How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

🖼Click to load external image (Posted Image) Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please include the following in your next post:
  • ComboFix log
ComboFix 10-02-26.01 - Crystal & Addz 27/02/2010 8:56.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.61.1033.18.511.132 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100226-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\avdrn.dat
c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Favorites\Online Security Test.url
c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Local Settings\Application Data\{B868EC20-08F5-4129-B6E1-D0577ACF3EEE}
c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Local Settings\Application Data\{B868EC20-08F5-4129-B6E1-D0577ACF3EEE}\chrome.manifest
c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Local Settings\Application Data\{B868EC20-08F5-4129-B6E1-D0577ACF3EEE}\chrome\content\_cfg.js
c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Local Settings\Application Data\{B868EC20-08F5-4129-B6E1-D0577ACF3EEE}\chrome\content\overlay.xul
c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Local Settings\Application Data\{B868EC20-08F5-4129-B6E1-D0577ACF3EEE}\install.rdf
c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Start Menu\Programs\Startup\monnid32.exe
c:\program files\AntiVirGear 3.8
c:\program files\AntiVirGear 3.8\AntiVirGear 3.8.exe
c:\program files\AntiVirGear 3.8\vpp.ini
c:\recycler\S-1-5-21-448539723-527237240-725345543-1003
c:\windows\system32\cfg.dat
c:\windows\system32\drivers\btxbar.sys
c:\windows\system32\ieffse32.dll
c:\windows\system32\veptlh.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_BTXBAR


((((((((((((((((((((((((( Files Created from 2010-01-26 to 2010-02-26 )))))))))))))))))))))))))))))))
.

2010-02-23 17:03 . 2010-02-23 17:03 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Malwarebytes
2010-02-23 17:03 . 2010-01-07 06:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-23 17:03 . 2010-02-23 17:03 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2010-02-23 17:03 . 2010-02-23 19:34 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-23 17:03 . 2010-01-07 06:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-23 16:58 . 2010-02-23 16:58 ——– d—–w- c:\program files\ERUNT
2010-02-23 16:03 . 2010-02-25 00:36 0 —-a-w- c:\windows\Obapezupewada.bin
2010-02-23 16:03 . 2010-02-25 00:37 120 —-a-w- c:\windows\Ydicejukoze.dat
2010-02-08 23:53 . 2010-02-08 23:53 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Office Genuine Advantage
2010-02-08 23:53 . 2010-02-08 23:53 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Office Genuine Advantage
2010-02-07 10:18 . 2010-02-07 10:18 ——– d–h–w- c:\windows\system32\GroupPolicy
2010-02-06 14:47 . 2010-02-22 10:40 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Shared
2010-02-06 14:46 . 2010-02-22 10:40 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Incomplete
2010-02-01 11:54 . 2010-02-01 11:54 ——– d-sh–w- c:\documents and settings\LocalService.NT AUTHORITY.000\IETldCache
2010-02-01 11:08 . 2010-02-23 13:25 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Tracing
2010-02-01 11:07 . 2010-02-01 11:07 ——– d—–w- c:\program files\Microsoft
2010-02-01 11:07 . 2010-02-01 11:07 ——– d—–w- c:\program files\Windows Live SkyDrive
2010-02-01 11:06 . 2010-02-01 11:07 ——– d—–w- c:\program files\Windows Live
2010-02-01 10:57 . 2010-02-01 10:57 ——– d—–w- c:\program files\Common Files\Windows Live
2010-02-01 10:37 . 2010-02-01 10:37 ——– d-sh–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\IETldCache
2010-02-01 10:28 . 2009-12-11 08:38 69120 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2010-02-01 10:28 . 2010-02-25 01:31 ——– d—–w- c:\windows\ie8updates
2010-02-01 10:27 . 2009-12-21 19:14 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2010-02-01 10:27 . 2009-12-21 19:14 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2010-02-01 10:22 . 2010-02-01 10:27 ——– dc-h–w- c:\windows\ie8
2010-02-01 09:52 . 2010-02-01 09:54 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-02-01 09:31 . 2010-02-01 09:32 ——– d—–w- c:\program files\Safari
2010-02-01 09:16 . 2010-02-01 09:16 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Sony Corporation
2010-02-01 09:16 . 2010-02-01 09:16 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Sony Corporation
2010-02-01 09:00 . 2008-02-26 11:59 294912 -c—-w- c:\windows\system32\dllcache\msctf.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-23 16:16 . 2010-02-23 16:13 20 —-a-w- c:\windows\system32\config\systemprofile\Application Data\cqfyto.dat
2010-02-23 16:08 . 2002-01-26 19:02 792064 —-a-w- c:\windows\system32\drivers\btxbar.sys.bak
2010-02-23 16:01 . 2010-02-23 15:59 20 —-a-w- c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\cqfyto.dat
2010-02-22 15:28 . 2007-08-09 11:26 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\LimeWire
2010-02-13 13:12 . 2007-07-20 13:14 ——– d—–w- c:\program files\iTunes
2010-02-13 13:10 . 2007-07-20 13:14 ——– d—–w- c:\program files\iPod
2010-02-13 13:10 . 2009-08-04 10:39 ——– d—–w- c:\program files\Common Files\Apple
2010-02-13 12:57 . 2010-02-13 12:57 72488 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-03 05:51 . 2010-01-09 12:49 ——– d—–w- c:\program files\Google
2010-02-01 11:08 . 2007-07-21 13:56 32400 —-a-w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-01 11:05 . 2007-07-20 07:38 ——– d—–w- c:\program files\JannieBall
2010-02-01 11:05 . 2007-07-20 06:28 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-02-01 10:29 . 2009-08-04 10:44 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Apple Computer
2010-02-01 09:49 . 2007-07-20 13:14 ——– d—–w- c:\program files\QuickTime
2010-02-01 09:26 . 2010-02-01 09:26 79144 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2010-02-01 09:05 . 2007-08-03 11:49 ——– d—–w- c:\program files\Samsung
2010-01-18 15:03 . 2010-01-18 15:03 1924744 —-a-w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2009-12-31 16:14 . 2004-08-04 12:00 352640 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2004-08-04 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-16 12:58 . 2007-07-21 11:22 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-15 01:57 . 2009-12-15 01:57 0 —-a-w- c:\windows\nsreg.dat
2009-12-14 19:15 . 2009-12-14 19:15 2146304 —-a-w- c:\windows\system32\GPhotos.scr
2009-12-14 07:35 . 2004-08-04 12:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-08 18:53 . 2004-08-04 12:00 2136064 —-a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:19 . 2004-08-03 22:59 2015744 —-a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 14:41 . 2004-08-04 12:00 453760 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-01-13 275800]
"VX1000"="c:\windows\vVX1000.exe" [2006-12-05 707360]
"BigPondWirelessBroadbandCM"="c:\program files\Telstra\BigPond Wireless Broadband 2.0\BigPond_CM.exe" [2007-09-18 2093056]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-10 149280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-22 141608]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli upwmil.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CursorXP"=c:\program files\CursorXP\CursorXP.exe
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"CoolSwitch"=c:\windows\system32\taskswitch.exe
"PowerMenu"="%systemroot%\system32\powermenu.exe" -hideself on
"CAVRID"="c:\program files\CA\eTrust Vet Antivirus\CAVRID.exe"
"CaAvTray"="c:\program files\CA\eTrust Vet Antivirus\CAVTray.exe"
"nwiz"=nwiz.exe /install
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"CreativeMouse "=c:\program files\Mouse Driver\MouseDrv.exe
"NeroFilterCheck"=c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"SunJavaUpdateSched"=c:\program files\Java\jre1.5.0_03\bin\jusched.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [4/08/2009 8:16 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/08/2009 8:16 PM 20560]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [17/08/2009 9:10 PM 235648]
S2 BT848;AVerMedia, AVerTV WDM Video Capture;c:\windows\system32\drivers\bt848.sys [13/05/2002 7:40 PM 261696]
S2 BTTUNER;AVerMedia, AVerTV WDM TvTuner;c:\windows\system32\drivers\bttuner.sys [27/01/2002 4:57 AM 22016]
S3 cmusbnet;WAN Driver @ 3GPP (6280);c:\windows\system32\drivers\cmusbnet.sys [23/11/2006 3:03 PM 87424]
S3 cmusbser;%CMUSBSER%;c:\windows\system32\drivers\cmusbser.sys [13/12/2006 6:31 PM 87040]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [24/02/2010 3:03 AM 38224]
S3 SNCT511;PC Camera (6005 CIF);c:\windows\system32\drivers\snct511.sys [24/08/2007 11:55 PM 219264]
.
Contents of the 'Scheduled Tasks' folder

2010-02-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 02:34]

2010-02-26 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 05:07]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com.au/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}
uInternet Settings,ProxyServer = localhost:2323
uInternet Settings,ProxyOverride = local;*.local
uSearchAssistant = hxxp://www.google.com/ie
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
IE: Transfer by Image Converter 2 - c:\program files\Sony\Image Converter 2\menu.htm
DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - hxxp://awbeta.net-nucleus.com/FIX/WinATS.cab
DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} - hxxp://support.packardbell.com/files/activex/InfosFinder2.CAB
FF - ProfilePath - c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Mozilla\Firefox\Profiles\mppc2bn9.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Pgiqazopesi - c:\windows\axebuhogeh.dll
SharedTaskScheduler-{92050ffb-b796-4146-ae27-7e5e1d93b8a8} - (no file)
AddRemove-MPower - c:\program files\Mindbeat\MPower\DeIsL1.isu



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-27 09:07
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(872)
c:\windows\upwmil.dll
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(1128)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\progra~1\MICROS~3\Office10\MCPS.DLL
c:\windows\system32\browselc.dll
c:\windows\system32\WpdShext.dll
.
———————— Other Running Processes ————————
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Mozilla Firefox\firefox.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2010-02-27 09:15:44 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-26 23:15

Pre-Run: 106,484,584,448 bytes free
Post-Run: 106,385,383,424 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /noexecute=optin /TUTag=17YW0Q /Kernel=TUKernel.exe
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional (TuneUp Backup)" /fastdetect /noexecute=optin /TUTag=17YW0Q-BAK

- - End Of File - - BF057AF6DDE30187FFCB6AF50F67A978
Crystal,

🖼Click to load external image (Posted Image) P2P - I see you have P2P software (Limewire) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares. I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs. If you choose to keep these applications, please do not use them until our fixes at WTT are complete.

🖼Click to load external image (Posted Image) Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad ) and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above http://

http://forums.whatthetech.com/Please_help_remove_Win32_Rootkit_gen_Rtk_t110497.html

Collect::
c:\windows\Ydicejukoze.dat
c:\windows\system32\config\systemprofile\Application Data\cqfyto.dat
c:\windows\system32\drivers\btxbar.sys.bak
c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\cqfyto.dat
c:\windows\upwmil.dll

File::
c:\windows\Obapezupewada.bin

DDS::
uInternet Settings,ProxyServer = localhost:2323
uInternet Settings,ProxyOverride = local;*.local
DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - hxxp://awbeta.net-nucleus.com/FIX/WinATS.cab

Registry::
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Notification Packages"=hex(7):73,63,65,63,6c,69,00,00

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.

Please include the following in your next post:
  • ComboFix log
  • How is your computer running?
Hello
Here is the log. I had to remove Avast as I could not locate it in the systems tray to disable it so I will put on Alvira now. Thought I should tell you as you may notice there is no antivirus software showing in the log report at present. Limewire is also removed; yes I know it is a terrible risk to use. I will now use the computer and let you know how it is faring. Thankyou extremely for you your help. Crystal

ComboFix 10-02-26.01 - Crystal & Addz 28/02/2010 10:45:15.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.61.1033.18.511.196 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2010-01-28 to 2010-02-28 )))))))))))))))))))))))))))))))
.

2010-02-23 17:03 . 2010-02-23 17:03 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Malwarebytes
2010-02-23 17:03 . 2010-01-07 06:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-23 17:03 . 2010-02-23 17:03 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2010-02-23 17:03 . 2010-02-23 19:34 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-23 17:03 . 2010-01-07 06:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-23 16:58 . 2010-02-23 16:58 ——– d—–w- c:\program files\ERUNT
2010-02-23 16:03 . 2010-02-25 00:36 0 —-a-w- c:\windows\Obapezupewada.bin
2010-02-23 16:03 . 2010-02-25 00:37 120 —-a-w- c:\windows\Ydicejukoze.dat
2010-02-13 12:57 . 2010-02-13 12:57 72488 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-08 23:53 . 2010-02-08 23:53 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Office Genuine Advantage
2010-02-08 23:53 . 2010-02-08 23:53 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Office Genuine Advantage
2010-02-07 10:18 . 2010-02-07 10:18 ——– d–h–w- c:\windows\system32\GroupPolicy
2010-02-06 14:47 . 2010-02-22 10:40 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Shared
2010-02-06 14:46 . 2010-02-22 10:40 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Incomplete
2010-02-01 11:54 . 2010-02-01 11:54 ——– d-sh–w- c:\documents and settings\LocalService.NT AUTHORITY.000\IETldCache
2010-02-01 11:08 . 2010-02-23 13:25 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Tracing
2010-02-01 11:07 . 2010-02-01 11:07 ——– d—–w- c:\program files\Microsoft
2010-02-01 11:07 . 2010-02-01 11:07 ——– d—–w- c:\program files\Windows Live SkyDrive
2010-02-01 11:06 . 2010-02-01 11:07 ——– d—–w- c:\program files\Windows Live
2010-02-01 10:57 . 2010-02-01 10:57 ——– d—–w- c:\program files\Common Files\Windows Live
2010-02-01 10:37 . 2010-02-01 10:37 ——– d-sh–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\IETldCache
2010-02-01 10:28 . 2009-12-11 08:38 69120 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2010-02-01 10:28 . 2010-02-25 01:31 ——– d—–w- c:\windows\ie8updates
2010-02-01 10:27 . 2009-12-21 19:14 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2010-02-01 10:27 . 2009-12-21 19:14 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2010-02-01 10:22 . 2010-02-01 10:27 ——– dc-h–w- c:\windows\ie8
2010-02-01 09:52 . 2010-02-01 09:54 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-02-01 09:31 . 2010-02-01 09:32 ——– d—–w- c:\program files\Safari
2010-02-01 09:26 . 2010-02-01 09:26 79144 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2010-02-01 09:16 . 2010-02-01 09:16 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Sony Corporation
2010-02-01 09:16 . 2010-02-01 09:16 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Sony Corporation
2010-02-01 09:00 . 2008-02-26 11:59 294912 -c—-w- c:\windows\system32\dllcache\msctf.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-28 00:28 . 2007-07-28 04:20 ——– d—–w- c:\program files\LimeWire
2010-02-23 16:16 . 2010-02-23 16:13 20 —-a-w- c:\windows\system32\config\systemprofile\Application Data\cqfyto.dat
2010-02-23 16:08 . 2002-01-26 19:02 792064 —-a-w- c:\windows\system32\drivers\btxbar.sys.bak
2010-02-23 16:01 . 2010-02-23 15:59 20 —-a-w- c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\cqfyto.dat
2010-02-22 15:28 . 2007-08-09 11:26 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\LimeWire
2010-02-13 13:12 . 2007-07-20 13:14 ——– d—–w- c:\program files\iTunes
2010-02-13 13:10 . 2007-07-20 13:14 ——– d—–w- c:\program files\iPod
2010-02-13 13:10 . 2009-08-04 10:39 ——– d—–w- c:\program files\Common Files\Apple
2010-02-03 05:51 . 2010-01-09 12:49 ——– d—–w- c:\program files\Google
2010-02-01 11:08 . 2007-07-21 13:56 32400 —-a-w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-01 11:05 . 2007-07-20 07:38 ——– d—–w- c:\program files\JannieBall
2010-02-01 11:05 . 2007-07-20 06:28 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-02-01 10:29 . 2009-08-04 10:44 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Apple Computer
2010-02-01 09:49 . 2007-07-20 13:14 ——– d—–w- c:\program files\QuickTime
2010-02-01 09:05 . 2007-08-03 11:49 ——– d—–w- c:\program files\Samsung
2010-01-18 15:03 . 2010-01-18 15:03 1924744 —-a-w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2009-12-31 16:14 . 2004-08-04 12:00 352640 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2004-08-04 12:00 916480 ——w- c:\windows\system32\wininet.dll
2009-12-16 12:58 . 2007-07-21 11:22 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-15 01:57 . 2009-12-15 01:57 0 —-a-w- c:\windows\nsreg.dat
2009-12-14 19:15 . 2009-12-14 19:15 2146304 —-a-w- c:\windows\system32\GPhotos.scr
2009-12-14 07:35 . 2004-08-04 12:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-08 18:53 . 2004-08-04 12:00 2136064 ——w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:19 . 2004-08-03 22:59 2015744 ——w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 14:41 . 2004-08-04 12:00 453760 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-01-13 275800]
"VX1000"="c:\windows\vVX1000.exe" [2006-12-05 707360]
"BigPondWirelessBroadbandCM"="c:\program files\Telstra\BigPond Wireless Broadband 2.0\BigPond_CM.exe" [2007-09-18 2093056]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-10 149280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-22 141608]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CursorXP"=c:\program files\CursorXP\CursorXP.exe
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"CoolSwitch"=c:\windows\system32\taskswitch.exe
"PowerMenu"="%systemroot%\system32\powermenu.exe" -hideself on
"CAVRID"="c:\program files\CA\eTrust Vet Antivirus\CAVRID.exe"
"CaAvTray"="c:\program files\CA\eTrust Vet Antivirus\CAVTray.exe"
"nwiz"=nwiz.exe /install
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"CreativeMouse "=c:\program files\Mouse Driver\MouseDrv.exe
"NeroFilterCheck"=c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"SunJavaUpdateSched"=c:\program files\Java\jre1.5.0_03\bin\jusched.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [17/08/2009 9:10 PM 235648]
S2 BT848;AVerMedia, AVerTV WDM Video Capture;c:\windows\system32\drivers\bt848.sys [13/05/2002 7:40 PM 261696]
S2 BTTUNER;AVerMedia, AVerTV WDM TvTuner;c:\windows\system32\drivers\bttuner.sys [27/01/2002 4:57 AM 22016]
S3 cmusbnet;WAN Driver @ 3GPP (6280);c:\windows\system32\drivers\cmusbnet.sys [23/11/2006 3:03 PM 87424]
S3 cmusbser;%CMUSBSER%;c:\windows\system32\drivers\cmusbser.sys [13/12/2006 6:31 PM 87040]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [24/02/2010 3:03 AM 38224]
S3 SNCT511;PC Camera (6005 CIF);c:\windows\system32\drivers\snct511.sys [24/08/2007 11:55 PM 219264]
.
Contents of the 'Scheduled Tasks' folder

2010-02-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 02:34]

2010-02-28 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 05:07]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com.au/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}
uInternet Settings,ProxyServer = localhost:2323
uInternet Settings,ProxyOverride = local;*.local
uSearchAssistant = hxxp://www.google.com/ie
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
IE: Transfer by Image Converter 2 - c:\program files\Sony\Image Converter 2\menu.htm
DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - hxxp://awbeta.net-nucleus.com/FIX/WinATS.cab
DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} - hxxp://support.packardbell.com/files/activex/InfosFinder2.CAB
FF - ProfilePath - c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Mozilla\Firefox\Profiles\mppc2bn9.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-28 10:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3812)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-02-28 10:59:19 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-28 00:59
ComboFix2.txt 2010-02-26 23:15

Pre-Run: 106,579,197,952 bytes free
Post-Run: 106,543,489,024 bytes free

- - End Of File - - CE2B01A9CA6857528B3BE96D12211605
Crystal,

We need to run that fix again. Carefully follow the instructions below (note they are different than last time):

🖼Click to load external image (Posted Image) Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad ) and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above http://

http://forums.whatthetech.com/Please_help_remove_Win32_Rootkit_gen_Rtk_t110497.html

Collect::
c:\windows\Ydicejukoze.dat
c:\windows\system32\config\systemprofile\Application Data\cqfyto.dat
c:\windows\system32\drivers\btxbar.sys.bak
c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\cqfyto.dat

File::
c:\windows\Obapezupewada.bin

DDS::
uInternet Settings,ProxyServer = localhost:2323
uInternet Settings,ProxyOverride = local;*.local
DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - hxxp://awbeta.net-nucleus.com/FIX/WinATS.cab

Save this as CFScript to your desktop.

Now, click Start > Run or Press the Windows Key + R copy and paste the following command in the run box that opens and press OK:

ComboFix "C:\Documents and Settings\User\Desktop\CFscript.txt"


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.

Please include the following in your next post:
  • ComboFix log
  • How is your computer running?
Hello I am posting this from another computer. For some reason the script wasn't accepted. Maybe I didn't do it properly; I don't know. But now I cannot connect to the internet on the infected computer. Also between our posts I tried to install Ad-Aware and there was some kind of conflict…the computer froze; so I uninstalled it. But basically I cannot connect to communicate with you from the infected computer. Cheers Crystal
Hi
Sorry for replying to my own post but it was my mistake re the posting of the script to notepad. I managed to connect to the internet and run the Combofix scan with the 'proper' script so here are the results. Thanks.
Crystal

ComboFix 10-02-26.01 - Crystal & Addz 28/02/2010 12:47:11.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.61.1033.18.511.145 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\User\Desktop\CFscript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

((((((((((((((((((((((((( Files Created from 2010-01-28 to 2010-02-28 )))))))))))))))))))))))))))))))
.

2010-02-28 02:15 . 2010-02-28 02:18 ——– d—–w- c:\windows\SxsCaPendDel
2010-02-28 02:02 . 2010-02-28 02:02 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-02-28 01:56 . 2010-02-28 02:16 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft
2010-02-28 01:56 . 2010-02-28 02:15 ——– d—–w- c:\program files\Lavasoft
2010-02-28 01:18 . 2009-03-29 23:33 96104 —-a-w- c:\windows\system32\drivers\avipbb.sys
2010-02-28 01:18 . 2009-07-28 05:33 55656 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-02-28 01:18 . 2009-02-13 01:29 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-02-28 01:18 . 2009-02-13 01:17 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2010-02-28 01:18 . 2010-02-28 01:18 ——– d—–w- c:\program files\Avira
2010-02-28 01:18 . 2010-02-28 01:18 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Avira
2010-02-23 17:03 . 2010-02-23 17:03 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Malwarebytes
2010-02-23 17:03 . 2010-01-07 06:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-23 17:03 . 2010-02-23 17:03 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2010-02-23 17:03 . 2010-02-23 19:34 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-23 17:03 . 2010-01-07 06:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-23 16:58 . 2010-02-23 16:58 ——– d—–w- c:\program files\ERUNT
2010-02-23 16:03 . 2010-02-25 00:36 0 —-a-w- c:\windows\Obapezupewada.bin
2010-02-23 16:03 . 2010-02-25 00:37 120 —-a-w- c:\windows\Ydicejukoze.dat
2010-02-13 12:57 . 2010-02-13 12:57 72488 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-02-08 23:53 . 2010-02-08 23:53 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Office Genuine Advantage
2010-02-08 23:53 . 2010-02-08 23:53 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Office Genuine Advantage
2010-02-07 10:18 . 2010-02-07 10:18 ——– d–h–w- c:\windows\system32\GroupPolicy
2010-02-06 14:47 . 2010-02-22 10:40 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Shared
2010-02-06 14:46 . 2010-02-22 10:40 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Incomplete
2010-02-01 11:54 . 2010-02-01 11:54 ——– d-sh–w- c:\documents and settings\LocalService.NT AUTHORITY.000\IETldCache
2010-02-01 11:08 . 2010-02-23 13:25 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Tracing
2010-02-01 11:07 . 2010-02-01 11:07 ——– d—–w- c:\program files\Microsoft
2010-02-01 11:07 . 2010-02-01 11:07 ——– d—–w- c:\program files\Windows Live SkyDrive
2010-02-01 11:06 . 2010-02-01 11:07 ——– d—–w- c:\program files\Windows Live
2010-02-01 10:57 . 2010-02-01 10:57 ——– d—–w- c:\program files\Common Files\Windows Live
2010-02-01 10:37 . 2010-02-01 10:37 ——– d-sh–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\IETldCache
2010-02-01 10:28 . 2009-12-11 08:38 69120 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2010-02-01 10:28 . 2010-02-25 01:31 ——– d—–w- c:\windows\ie8updates
2010-02-01 10:27 . 2009-12-21 19:14 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2010-02-01 10:27 . 2009-12-21 19:14 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2010-02-01 10:22 . 2010-02-01 10:27 ——– dc-h–w- c:\windows\ie8
2010-02-01 09:52 . 2010-02-01 09:54 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-02-01 09:31 . 2010-02-01 09:32 ——– d—–w- c:\program files\Safari
2010-02-01 09:26 . 2010-02-01 09:26 79144 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2010-02-01 09:16 . 2010-02-01 09:16 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Sony Corporation
2010-02-01 09:16 . 2010-02-01 09:16 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Sony Corporation
2010-02-01 09:00 . 2008-02-26 11:59 294912 -c—-w- c:\windows\system32\dllcache\msctf.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-23 16:16 . 2010-02-23 16:13 20 —-a-w- c:\windows\system32\config\systemprofile\Application Data\cqfyto.dat
2010-02-23 16:08 . 2002-01-26 19:02 792064 —-a-w- c:\windows\system32\drivers\btxbar.sys.bak
2010-02-23 16:01 . 2010-02-23 15:59 20 —-a-w- c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\cqfyto.dat
2010-02-22 15:28 . 2007-08-09 11:26 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\LimeWire
2010-02-13 13:12 . 2007-07-20 13:14 ——– d—–w- c:\program files\iTunes
2010-02-13 13:10 . 2007-07-20 13:14 ——– d—–w- c:\program files\iPod
2010-02-13 13:10 . 2009-08-04 10:39 ——– d—–w- c:\program files\Common Files\Apple
2010-02-03 05:51 . 2010-01-09 12:49 ——– d—–w- c:\program files\Google
2010-02-01 11:08 . 2007-07-21 13:56 32400 —-a-w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-01 11:05 . 2007-07-20 07:38 ——– d—–w- c:\program files\JannieBall
2010-02-01 11:05 . 2007-07-20 06:28 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-02-01 10:29 . 2009-08-04 10:44 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Apple Computer
2010-02-01 09:49 . 2007-07-20 13:14 ——– d—–w- c:\program files\QuickTime
2010-02-01 09:05 . 2007-08-03 11:49 ——– d—–w- c:\program files\Samsung
2010-01-18 15:03 . 2010-01-18 15:03 1924744 —-a-w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe
2009-12-31 16:14 . 2004-08-04 12:00 352640 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-21 19:14 . 2004-08-04 12:00 916480 ——w- c:\windows\system32\wininet.dll
2009-12-16 12:58 . 2007-07-21 11:22 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-15 01:57 . 2009-12-15 01:57 0 —-a-w- c:\windows\nsreg.dat
2009-12-14 19:15 . 2009-12-14 19:15 2146304 —-a-w- c:\windows\system32\GPhotos.scr
2009-12-14 07:35 . 2004-08-04 12:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-08 18:53 . 2004-08-04 12:00 2136064 ——w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:19 . 2004-08-03 22:59 2015744 ——w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 14:41 . 2004-08-04 12:00 453760 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-01-13 275800]
"VX1000"="c:\windows\vVX1000.exe" [2006-12-05 707360]
"BigPondWirelessBroadbandCM"="c:\program files\Telstra\BigPond Wireless Broadband 2.0\BigPond_CM.exe" [2007-09-18 2093056]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-10 149280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-22 141608]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CursorXP"=c:\program files\CursorXP\CursorXP.exe
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"CoolSwitch"=c:\windows\system32\taskswitch.exe
"PowerMenu"="%systemroot%\system32\powermenu.exe" -hideself on
"CAVRID"="c:\program files\CA\eTrust Vet Antivirus\CAVRID.exe"
"CaAvTray"="c:\program files\CA\eTrust Vet Antivirus\CAVTray.exe"
"nwiz"=nwiz.exe /install
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"CreativeMouse "=c:\program files\Mouse Driver\MouseDrv.exe
"NeroFilterCheck"=c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"SunJavaUpdateSched"=c:\program files\Java\jre1.5.0_03\bin\jusched.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [28/02/2010 11:18 AM 108289]
R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [17/08/2009 9:10 PM 235648]
S2 BT848;AVerMedia, AVerTV WDM Video Capture;c:\windows\system32\drivers\bt848.sys [13/05/2002 7:40 PM 261696]
S2 BTTUNER;AVerMedia, AVerTV WDM TvTuner;c:\windows\system32\drivers\bttuner.sys [27/01/2002 4:57 AM 22016]
S3 cmusbnet;WAN Driver @ 3GPP (6280);c:\windows\system32\drivers\cmusbnet.sys [23/11/2006 3:03 PM 87424]
S3 cmusbser;%CMUSBSER%;c:\windows\system32\drivers\cmusbser.sys [13/12/2006 6:31 PM 87040]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [24/02/2010 3:03 AM 38224]
S3 SNCT511;PC Camera (6005 CIF);c:\windows\system32\drivers\snct511.sys [24/08/2007 11:55 PM 219264]
.
Contents of the 'Scheduled Tasks' folder

2010-02-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 02:34]

2010-02-28 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 05:07]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com.au/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}
uInternet Settings,ProxyServer = localhost:2323
uInternet Settings,ProxyOverride = local;*.local
uSearchAssistant = hxxp://www.google.com/ie
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
IE: Transfer by Image Converter 2 - c:\program files\Sony\Image Converter 2\menu.htm
DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - hxxp://awbeta.net-nucleus.com/FIX/WinATS.cab
DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} - hxxp://support.packardbell.com/files/activex/InfosFinder2.CAB
FF - ProfilePath - c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Mozilla\Firefox\Profiles\mppc2bn9.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-28 12:52
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(812)
c:\windows\system32\cscui.dll

- - - - - - - > 'explorer.exe'(3952)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-02-28 12:56:06
ComboFix-quarantined-files.txt 2010-02-28 02:56
ComboFix2.txt 2010-02-28 00:59
ComboFix3.txt 2010-02-26 23:15

Pre-Run: 106,009,657,344 bytes free
Post-Run: 106,060,107,776 bytes free

- - End Of File - - 0AC11174BAEB19999F6EFD1332986CB6
Crystal,

I'm sorry, but we need to do it once more. Note that the command that you enter into the run box is different this time:

🖼Click to load external image (Posted Image) Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad ) and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above http://

http://forums.whatthetech.com/Please_help_remove_Win32_Rootkit_gen_Rtk_t110497.html

Collect::
c:\windows\Ydicejukoze.dat
c:\windows\system32\config\systemprofile\Application Data\cqfyto.dat
c:\windows\system32\drivers\btxbar.sys.bak
c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\cqfyto.dat

File::
c:\windows\Obapezupewada.bin

DDS::
uInternet Settings,ProxyServer = localhost:2323
uInternet Settings,ProxyOverride = local;*.local
DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - hxxp://awbeta.net-nucleus.com/FIX/WinATS.cab

Save this as CFScript to your desktop.

Now, click Start > Run or Press the Windows Key + R copy and paste the following command in the run box that opens and press OK:

ComboFix "C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Desktop\CFscript.txt"


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.

Please include the following in your next post:
  • ComboFix log
  • How is your computer running?
ComboFix 10-02-26.01 - Crystal & Addz 28/02/2010 13:18:14.4.2 - x86 Microsoft Windows XP Professional 5.1.2600.2.1252.61.1033.18.511.168 [GMT 10:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} . ((((((((((((((((((((((((( Files Created from 2010-01-28 to 2010-02-28 ))))))))))))))))))))))))))))))) . 2010-02-28 02:15 . 2010-02-28 02:18 ——– d—–w- c:\windows\SxsCaPendDel 2010-02-28 02:02 . 2010-02-28 02:02 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys 2010-02-28 01:56 . 2010-02-28 02:16 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft 2010-02-28 01:56 . 2010-02-28 02:15 ——– d—–w- c:\program files\Lavasoft 2010-02-28 01:18 . 2009-03-29 23:33 96104 —-a-w- c:\windows\system32\drivers\avipbb.sys 2010-02-28 01:18 . 2009-07-28 05:33 55656 —-a-w- c:\windows\system32\drivers\avgntflt.sys 2010-02-28 01:18 . 2009-02-13 01:29 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys 2010-02-28 01:18 . 2009-02-13 01:17 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys 2010-02-28 01:18 . 2010-02-28 01:18 ——– d—–w- c:\program files\Avira 2010-02-28 01:18 . 2010-02-28 01:18 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Avira 2010-02-23 17:03 . 2010-02-23 17:03 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Malwarebytes 2010-02-23 17:03 . 2010-01-07 06:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-02-23 17:03 . 2010-02-23 17:03 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes 2010-02-23 17:03 . 2010-02-23 19:34 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-02-23 17:03 . 2010-01-07 06:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-02-23 16:58 . 2010-02-23 16:58 ——– d—–w- c:\program files\ERUNT 2010-02-23 16:03 . 2010-02-25 00:36 0 —-a-w- c:\windows\Obapezupewada.bin 2010-02-23 16:03 . 2010-02-25 00:37 120 —-a-w- c:\windows\Ydicejukoze.dat 2010-02-13 12:57 . 2010-02-13 12:57 72488 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe 2010-02-08 23:53 . 2010-02-08 23:53 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Office Genuine Advantage 2010-02-08 23:53 . 2010-02-08 23:53 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Office Genuine Advantage 2010-02-07 10:18 . 2010-02-07 10:18 ——– d–h–w- c:\windows\system32\GroupPolicy 2010-02-06 14:47 . 2010-02-22 10:40 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Shared 2010-02-06 14:46 . 2010-02-22 10:40 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Incomplete 2010-02-01 11:54 . 2010-02-01 11:54 ——– d-sh–w- c:\documents and settings\LocalService.NT AUTHORITY.000\IETldCache 2010-02-01 11:08 . 2010-02-23 13:25 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Tracing 2010-02-01 11:07 . 2010-02-01 11:07 ——– d—–w- c:\program files\Microsoft 2010-02-01 11:07 . 2010-02-01 11:07 ——– d—–w- c:\program files\Windows Live SkyDrive 2010-02-01 11:06 . 2010-02-01 11:07 ——– d—–w- c:\program files\Windows Live 2010-02-01 10:57 . 2010-02-01 10:57 ——– d—–w- c:\program files\Common Files\Windows Live 2010-02-01 10:37 . 2010-02-01 10:37 ——– d-sh–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\IETldCache 2010-02-01 10:28 . 2009-12-11 08:38 69120 -c—-w- c:\windows\system32\dllcache\iecompat.dll 2010-02-01 10:28 . 2010-02-25 01:31 ——– d—–w- c:\windows\ie8updates 2010-02-01 10:27 . 2009-12-21 19:14 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll 2010-02-01 10:27 . 2009-12-21 19:14 246272 -c—-w- c:\windows\system32\dllcache\ieproxy.dll 2010-02-01 10:22 . 2010-02-01 10:27 ——– dc-h–w- c:\windows\ie8 2010-02-01 09:52 . 2010-02-01 09:54 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2010-02-01 09:31 . 2010-02-01 09:32 ——– d—–w- c:\program files\Safari 2010-02-01 09:26 . 2010-02-01 09:26 79144 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe 2010-02-01 09:16 . 2010-02-01 09:16 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Sony Corporation 2010-02-01 09:16 . 2010-02-01 09:16 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Sony Corporation 2010-02-01 09:00 . 2008-02-26 11:59 294912 -c—-w- c:\windows\system32\dllcache\msctf.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-02-23 16:16 . 2010-02-23 16:13 20 —-a-w- c:\windows\system32\config\systemprofile\Application Data\cqfyto.dat 2010-02-23 16:08 . 2002-01-26 19:02 792064 —-a-w- c:\windows\system32\drivers\btxbar.sys.bak 2010-02-23 16:01 . 2010-02-23 15:59 20 —-a-w- c:\documents and settings\NetworkService.NT AUTHORITY.000\Application Data\cqfyto.dat 2010-02-22 15:28 . 2007-08-09 11:26 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\LimeWire 2010-02-13 13:12 . 2007-07-20 13:14 ——– d—–w- c:\program files\iTunes 2010-02-13 13:10 . 2007-07-20 13:14 ——– d—–w- c:\program files\iPod 2010-02-13 13:10 . 2009-08-04 10:39 ——– d—–w- c:\program files\Common Files\Apple 2010-02-03 05:51 . 2010-01-09 12:49 ——– d—–w- c:\program files\Google 2010-02-01 11:08 . 2007-07-21 13:56 32400 —-a-w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-02-01 11:05 . 2007-07-20 07:38 ——– d—–w- c:\program files\JannieBall 2010-02-01 11:05 . 2007-07-20 06:28 ——– d–h–w- c:\program files\InstallShield Installation Information 2010-02-01 10:29 . 2009-08-04 10:44 ——– d—–w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Apple Computer 2010-02-01 09:49 . 2007-07-20 13:14 ——– d—–w- c:\program files\QuickTime 2010-02-01 09:05 . 2007-08-03 11:49 ——– d—–w- c:\program files\Samsung 2010-01-18 15:03 . 2010-01-18 15:03 1924744 —-a-w- c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdatepl\fpupdatepl.exe 2009-12-31 16:14 . 2004-08-04 12:00 352640 —-a-w- c:\windows\system32\drivers\srv.sys 2009-12-21 19:14 . 2004-08-04 12:00 916480 ——w- c:\windows\system32\wininet.dll 2009-12-16 12:58 . 2007-07-21 11:22 343040 —-a-w- c:\windows\system32\mspaint.exe 2009-12-15 01:57 . 2009-12-15 01:57 0 —-a-w- c:\windows\nsreg.dat 2009-12-14 19:15 . 2009-12-14 19:15 2146304 —-a-w- c:\windows\system32\GPhotos.scr 2009-12-14 07:35 . 2004-08-04 12:00 33280 —-a-w- c:\windows\system32\csrsrv.dll 2009-12-08 18:53 . 2004-08-04 12:00 2136064 ——w- c:\windows\system32\ntoskrnl.exe 2009-12-08 18:19 . 2004-08-03 22:59 2015744 ——w- c:\windows\system32\ntkrnlpa.exe 2009-12-04 14:41 . 2004-08-04 12:00 453760 —-a-w- c:\windows\system32\drivers\mrxsmb.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-01-13 275800] "VX1000"="c:\windows\vVX1000.exe" [2006-12-05 707360] "BigPondWirelessBroadbandCM"="c:\program files\Telstra\BigPond Wireless Broadband 2.0\BigPond_CM.exe" [2007-09-18 2093056] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-10 149280] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-22 141608] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "CursorXP"=c:\program files\CursorXP\CursorXP.exe "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "CoolSwitch"=c:\windows\system32\taskswitch.exe "PowerMenu"="%systemroot%\system32\powermenu.exe" -hideself on "CAVRID"="c:\program files\CA\eTrust Vet Antivirus\CAVRID.exe" "CaAvTray"="c:\program files\CA\eTrust Vet Antivirus\CAVTray.exe" "nwiz"=nwiz.exe /install "NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup "CreativeMouse "=c:\program files\Mouse Driver\MouseDrv.exe "NeroFilterCheck"=c:\program files\Common Files\Ahead\Lib\NeroCheck.exe "BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent "NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit "SunJavaUpdateSched"=c:\program files\Java\jre1.5.0_03\bin\jusched.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\WINDOWS\\system32\\mmc.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [28/02/2010 11:18 AM 108289] R3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [17/08/2009 9:10 PM 235648] S2 BT848;AVerMedia, AVerTV WDM Video Capture;c:\windows\system32\drivers\bt848.sys [13/05/2002 7:40 PM 261696] S2 BTTUNER;AVerMedia, AVerTV WDM TvTuner;c:\windows\system32\drivers\bttuner.sys [27/01/2002 4:57 AM 22016] S3 cmusbnet;WAN Driver @ 3GPP (6280);c:\windows\system32\drivers\cmusbnet.sys [23/11/2006 3:03 PM 87424] S3 cmusbser;%CMUSBSER%;c:\windows\system32\drivers\cmusbser.sys [13/12/2006 6:31 PM 87040] S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [24/02/2010 3:03 AM 38224] S3 SNCT511;PC Camera (6005 CIF);c:\windows\system32\drivers\snct511.sys [24/08/2007 11:55 PM 219264] . Contents of the 'Scheduled Tasks' folder 2010-02-27 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 02:34] 2010-02-28 c:\windows\Tasks\OGALogon.job - c:\windows\system32\OGAEXEC.exe [2009-08-03 05:07] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com.au/ uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms} uInternet Settings,ProxyServer = localhost:2323 uInternet Settings,ProxyOverride = local;*.local uSearchAssistant = hxxp://www.google.com/ie IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000 IE: Transfer by Image Converter 2 - c:\program files\Sony\Image Converter 2\menu.htm DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - hxxp://awbeta.net-nucleus.com/FIX/WinATS.cab DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} - hxxp://support.packardbell.com/files/activex/InfosFinder2.CAB FF - ProfilePath - c:\documents and settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Mozilla\Firefox\Profiles\mppc2bn9.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ —- FIREFOX POLICIES —- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); . ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'winlogon.exe'(812) c:\windows\system32\cscui.dll - - - - - - - > 'explorer.exe'(1344) c:\windows\system32\WININET.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . Completion time: 2010-02-28 13:24:42 ComboFix-quarantined-files.txt 2010-02-28 03:24 ComboFix2.txt 2010-02-28 02:56 ComboFix3.txt 2010-02-28 00:59 ComboFix4.txt 2010-02-26 23:15 Pre-Run: 106,074,947,584 bytes free Post-Run: 106,056,294,400 bytes free - - End Of File - - FF03BD2C9E42AF8069C002F04BEB36A8
Crystal,

I need you to run this tool for me now:

🖼Click to load external image (Posted Image) Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them.

Please include the following in your next post:
  • OTL & OTL Extras logs
Hi
Avira keeps popping up with a box and the name of something which it want me to 'deny access' to. It would not let me continue the OTL scan until I performed these actions (about 7 times).
Crystal



OTL logfile created on: 28/02/2010 2:51:52 PM - Run 1
OTL by OldTimer - Version 3.1.30.3 Folder = C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

511.00 Mb Total Physical Memory | 335.00 Mb Available Physical Memory | 66.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 98.78 Gb Free Space | 88.37% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PUNKY
Current User Name: Crystal & Addz
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Telstra\BigPond Wireless Broadband 2.0\BigPond_CM.exe (Telstra)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (NMIndexingService) – File not found
SRV - (iPod Service) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (gusvc) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (Bonjour Service) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (LightScribeService) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (ServiceLayer) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (NVSvc) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local;*.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = localhost:2323

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.com"
FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.0.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20091028
FF - prefs.js..network.proxy.ftp: "localhost"
FF - prefs.js..network.proxy.ftp_port: 2323
FF - prefs.js..network.proxy.gopher: "localhost"
FF - prefs.js..network.proxy.gopher_port: 2323
FF - prefs.js..network.proxy.http: "localhost"
FF - prefs.js..network.proxy.http_port: 2323
FF - prefs.js..network.proxy.no_proxies_on: "local,*.local"
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "localhost"
FF - prefs.js..network.proxy.socks_port: 2323
FF - prefs.js..network.proxy.ssl: "localhost"
FF - prefs.js..network.proxy.ssl_port: 2323

FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/01 20:50:15 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/01 20:50:15 | 000,000,000 | —D | M]

[2009/12/15 11:58:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Mozilla\Extensions
[2009/08/13 02:20:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Mozilla\Extensions\[removed]
[2010/02/28 11:24:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Mozilla\Firefox\Profiles\mppc2bn9.default\extensions
[2010/02/28 11:24:46 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Mozilla\Firefox\Profiles\mppc2bn9.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/02/07 19:59:34 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Mozilla\Firefox\Profiles\mppc2bn9.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2009/12/15 11:57:08 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/02/28 10:53:18 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (BigPond Wireless Broadband 2.0 Auto Dial) - {DB92EC3F-697D-4C3B-9A3B-3ABBD23D4A85} - C:\Program Files\Telstra\BigPond Wireless Broadband 2.0\bpwbb2ad.dll (Telstra)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [BigPondWirelessBroadbandCM] C:\Program Files\Telstra\BigPond Wireless Broadband 2.0\BigPond_CM.exe (Telstra)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [VX1000] C:\WINDOWS\vVX1000.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClassicShell = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Feed Discovery present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Feeds present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Security present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbar present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeKeyboardNavigationIndicators = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1189190842093 (MUWebControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} http://awbeta.net-nucleus.com/FIX/WinATS.cab (Mirar_Dummy_ATS1 Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} http://support.packardbell.com/files/activ…nfosFinder2.CAB (InfosFinder2.InfosFinder)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.138
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/07/20 13:49:10 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 14 Days ==========

[2010/02/28 14:48:18 | 000,549,888 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Desktop\OTL.exe
[2010/02/28 13:42:33 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\PrivacIE
[2010/02/28 13:16:06 | 000,000,000 | —D | C] – C:\ComboFix
[2010/02/28 12:16:29 | 000,000,000 | —D | C] – C:\Config.Msi
[2010/02/28 12:15:52 | 000,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2010/02/28 12:02:43 | 000,095,024 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/02/28 11:56:58 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2010/02/28 11:56:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
[2010/02/28 11:18:26 | 000,096,104 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2010/02/28 11:18:25 | 000,055,656 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2010/02/28 11:18:25 | 000,045,416 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntdd.sys
[2010/02/28 11:18:25 | 000,022,360 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntmgr.sys
[2010/02/28 11:18:23 | 000,028,520 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\ssmdrv.sys
[2010/02/28 11:18:20 | 000,000,000 | —D | C] – C:\Program Files\Avira
[2010/02/28 11:18:20 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Avira
[2010/02/27 08:53:27 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/02/27 08:51:42 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/02/27 08:51:42 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/02/27 08:51:42 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/02/27 08:51:42 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/02/27 08:50:57 | 000,000,000 | —D | C] – C:\Qoobox
[2010/02/24 03:03:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Malwarebytes
[2010/02/24 03:03:05 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/02/24 03:03:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
[2010/02/24 03:03:02 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/02/24 03:03:02 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/02/24 02:59:27 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/02/24 02:58:12 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2007/07/20 13:52:41 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/07/20 13:52:40 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2007/07/20 13:48:46 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2007/07/20 13:48:46 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[4 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 14 Days ==========

[2010/02/28 14:48:25 | 000,549,888 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Desktop\OTL.exe
[2010/02/28 13:24:43 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/02/28 13:23:22 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/02/28 12:40:54 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/02/28 12:40:32 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2010/02/28 12:40:28 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/02/28 12:39:03 | 004,980,736 | —- | M] () – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\ntuser.dat
[2010/02/28 12:39:03 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\ntuser.ini
[2010/02/28 12:02:41 | 000,095,024 | —- | M] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/02/28 11:18:44 | 000,001,707 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Avira AntiVir Control Center.lnk
[2010/02/28 10:53:18 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/02/28 10:42:15 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/02/27 17:41:03 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/02/27 08:53:40 | 000,000,460 | RHS- | M] () – C:\boot.ini
[2010/02/27 08:50:17 | 003,873,931 | R— | M] () – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Desktop\ComboFix.exe
[2010/02/26 17:57:40 | 000,293,376 | —- | M] () – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Desktop\gymer.exe
[2010/02/25 11:31:00 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/02/25 10:37:24 | 000,000,120 | —- | M] () – C:\WINDOWS\Ydicejukoze.dat
[2010/02/25 10:36:10 | 000,000,000 | —- | M] () – C:\WINDOWS\Obapezupewada.bin
[2010/02/24 05:34:00 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/24 02:58:13 | 000,000,611 | —- | M] () – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Desktop\NTREGOPT.lnk
[2010/02/24 02:58:13 | 000,000,592 | —- | M] () – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Desktop\ERUNT.lnk
[2010/02/23 21:30:07 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\iTunes.lnk
[2010/02/21 19:31:27 | 000,040,960 | —- | M] () – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[4 C:\WINDOWS\System32\dllcache\*.tmp files -> C:\WINDOWS\System32\dllcache\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/02/28 11:18:44 | 000,001,707 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Avira AntiVir Control Center.lnk
[2010/02/27 08:53:40 | 000,000,389 | —- | C] () – C:\Boot.bak
[2010/02/27 08:53:34 | 000,260,272 | —- | C] () – C:\cmldr
[2010/02/27 08:51:42 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/02/27 08:51:42 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/02/27 08:51:42 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/02/27 08:51:42 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/02/27 08:51:42 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/02/27 08:50:06 | 003,873,931 | R— | C] () – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Desktop\ComboFix.exe
[2010/02/26 17:57:40 | 000,293,376 | —- | C] () – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Desktop\gymer.exe
[2010/02/24 03:03:07 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users.WINDOWS\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/24 02:58:13 | 000,000,611 | —- | C] () – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Desktop\NTREGOPT.lnk
[2010/02/24 02:58:13 | 000,000,592 | —- | C] () – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Desktop\ERUNT.lnk
[2010/02/24 02:03:47 | 000,000,000 | —- | C] () – C:\WINDOWS\Obapezupewada.bin
[2010/02/24 02:03:45 | 000,000,120 | —- | C] () – C:\WINDOWS\Ydicejukoze.dat
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2008/02/05 13:28:20 | 000,000,051 | —- | C] () – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Local Settings\Application Data\setup.txt
[2007/10/23 20:34:23 | 000,000,276 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2007/10/09 06:46:06 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/10/04 17:14:48 | 002,067,140 | R— | C] () – C:\WINDOWS\System32\avcodec.dll
[2007/09/08 20:53:03 | 000,000,151 | —- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2007/09/08 18:26:11 | 000,015,498 | R— | C] () – C:\WINDOWS\VX1000.ini
[2007/08/25 16:47:53 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/08/24 23:55:40 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\dsnct511.dll
[2007/08/24 23:55:40 | 000,015,541 | R— | C] () – C:\WINDOWS\snct511.ini
[2007/08/24 23:55:39 | 000,219,264 | R— | C] () – C:\WINDOWS\System32\drivers\snct511.sys
[2007/08/24 23:55:39 | 000,028,672 | R— | C] () – C:\WINDOWS\System32\vsnct511.dll
[2007/08/12 15:46:24 | 000,000,093 | —- | C] () – C:\WINDOWS\AVerTV2K.ini
[2007/08/11 20:39:01 | 000,000,046 | —- | C] () – C:\WINDOWS\System32\Oeminfo.ini
[2007/08/02 15:12:50 | 000,000,288 | —- | C] () – C:\WINDOWS\_delis32.ini
[2007/07/28 20:30:52 | 000,000,091 | —- | C] () – C:\WINDOWS\msiosd.ini
[2007/07/28 15:12:43 | 000,000,153 | —- | C] () – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Local Settings\Application Data\fusioncache.dat
[2007/07/28 04:34:44 | 000,000,041 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2007/07/28 03:10:21 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS7I.DLL
[2007/07/27 18:42:49 | 000,040,960 | —- | C] () – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/02/21 11:27:25 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\REGOBJ.DLL
[2004/08/04 22:00:00 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2002/01/27 05:02:00 | 000,792,064 | —- | C] () – C:\WINDOWS\System32\drivers\btxbar.sys.bak

========== LOP Check ==========

[2007/08/11 18:57:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Avg7
[2007/08/11 20:00:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\CA
[2007/08/25 17:03:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\LightScribe
[2007/08/02 01:28:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\PC Suite
[2007/07/28 08:57:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Playtonium Games
[2007/10/05 15:54:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
[2007/08/11 20:35:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\TuneUp Software
[2007/08/27 04:11:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Ulead Systems
[2010/02/01 19:54:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/08/04 20:44:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2007/08/12 16:11:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Application Data\AverAlbum
[2007/10/09 06:42:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Canon
[2010/02/23 01:28:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Application Data\LimeWire
[2007/08/10 07:44:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Application Data\MSNInstaller
[2007/08/24 01:48:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Nokia
[2007/07/27 18:42:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Application Data\PC Suite
[2009/08/04 21:21:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Red Chair Software
[2007/07/27 23:52:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Registry Cleaner
[2007/10/04 17:23:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Samsung
[2007/07/27 17:45:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Systweak
[2007/08/11 20:35:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Application Data\TuneUp Software
[2007/08/13 18:50:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Ulead Systems
[2007/08/12 04:41:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Application Data\Vso
[2010/02/28 12:40:32 | 000,000,236 | —- | M] () – C:\WINDOWS\Tasks\OGALogon.job

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:27AAAD97
< End of report >


OTL Extras logfile created on: 28/02/2010 2:51:52 PM - Run 1
OTL by OldTimer - Version 3.1.30.3 Folder = C:\Documents and Settings\Crystal & Addz.HOME-8B021C13CE\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

511.00 Mb Total Physical Memory | 335.00 Mb Available Physical Memory | 66.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 98.78 Gb Free Space | 88.37% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PUNKY
Current User Name: Crystal & Addz
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Minimal
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\msncall.exe" = C:\Program Files\MSN Messenger\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone) – File not found
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console – (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeExp.exe" = C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe – (Microsoft Corporation)
"C:\Program Files\Microsoft LifeCam\LifeCam.exe" = C:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe – (Microsoft Corporation)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour – (Apple Inc.)
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{068502DA-6979-4D9A-BBE1-C3AD0FF11F19}" = Ulead DVD MovieFactory 3 SE
"{06C32EA0-4A22-4919-979A-8700715865B8}" = Microsoft LifeCam
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0EEE3193-5E0D-471B-BFB0-0C2034F17B3B}" = BigPond Wireless Broadband 2.8.13
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216015FF}" = Java™ 6 Update 17
"{2EBA5473-558B-462C-AEE4-FE50FA799F2A}" = Mouse Driver
"{3248F0A8-6813-11D6-A77B-00B0D0150030}" = J2SE Runtime Environment 5.0 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45534579-B75B-4A42-953B-2EF8E1DEB4F3}" = Microsoft XML Parser
"{49FC50FC-F965-40D9-89B4-CBFF80941033}" = Windows Movie Maker 2.0
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{888019C0-54D4-40C2-9274-27B9DAB17017}" = Intel® Network Connections [removed]
"{8AD824A5-1CCC-4BB7-82C9-E6FB25CC0479}" = VIMICRO USB PC Camera VC0305
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A87B11AC-4344-4E5D-8B12-8F471A87DAD9}" = LightScribe 1.4.136.1
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AB2347E4-153B-4194-AA3B-97C0A662B369}" = PC Connectivity Solution
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{ACCA20B0-C4D1-4BF5-BF21-0A0EB5EF9730}" = REALTEK GbE & FE Ethernet PCI NIC Driver
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C4A4722E-79F9-417C-BD72-8D359A090C97}" = Samsung PC Studio
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CECFDD53-35DB-4235-9363-7964A0C88E0E}" = Samsung PC Studio
"{D6E4E5D6-7693-4BB4-95BA-21F38FAFEE90}" = Safari
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{EBA29752-DDD2-4B62-B2E3-9841F92A3E3A}" = Samsung PC Studio 3 USB Driver Installer
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F439D7AF-03F3-4F8E-AEC4-571BFE977C61}" = iTunes
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"ERUNT_is1" = ERUNT 1.1j
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6)" = Mozilla Firefox (3.6)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Display Driver" = NVIDIA Display Driver
"Picasa 3" = Picasa 3
"SAMSUNG CDMA Modem" = SAMSUNG CDMA Modem Driver Set
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"TweakMP9" = Windows Media Player 9 Series TweakMP PowerToy
"WIC" = Windows Imaging Component
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01005" = Microsoft User-Mode Driver Framework Feature Pack 1.5

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/10/2007 1:59:05 AM | Computer Name = HOME-8B021C13CE | Source = MsiInstaller | ID = 11606
Description = Product: Java™ 6 Update 3 – Error 1606.Could not access network
location http://javadl.sun.com/webapps/download/Get…86/jb160000.cab.

Error - 4/08/2009 6:05:23 AM | Computer Name = PUNKY | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 4/08/2009 6:05:23 AM | Computer Name = PUNKY | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 4/08/2009 6:05:38 AM | Computer Name = PUNKY | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 4/08/2009 6:05:49 AM | Computer Name = PUNKY | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 15/10/2009 7:45:04 AM | Computer Name = PUNKY | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16876, faulting
module user32.dll, version 5.1.2600.3099, fault address 0x0001d3df.

Error - 18/10/2009 2:32:10 PM | Computer Name = PUNKY | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16915, faulting
module mshtml.dll, version 7.0.6000.16915, fault address 0x002d0b0a.

Error - 18/10/2009 2:32:46 PM | Computer Name = PUNKY | Source = Application Error | ID = 1001
Description = Fault bucket 1513272013.

Error - 26/10/2009 5:06:32 AM | Computer Name = PUNKY | Source = Ci | ID = 4124
Description = Content index on c:\system volume information\catalog.wci is corrupt.
Please shutdown and restart the Indexing Service (cisvc).

Error - 26/10/2009 5:06:32 AM | Computer Name = PUNKY | Source = Ci | ID = 4126
Description = Cleaning up corrupt content index metadata on c:\system volume information\catalog.wci.
Index will be automatically restored by refiltering all documents.

[ System Events ]
Error - 27/02/2010 8:22:19 PM | Computer Name = PUNKY | Source = Service Control Manager | ID = 7000
Description = The AVerMedia, AVerTV WDM Video Capture service failed to start due
to the following error: %%1058

Error - 27/02/2010 8:22:19 PM | Computer Name = PUNKY | Source = Service Control Manager | ID = 7000
Description = The AVerMedia, AVerTV WDM TvTuner service failed to start due to the
following error: %%1058

Error - 27/02/2010 8:53:10 PM | Computer Name = PUNKY | Source = Service Control Manager | ID = 7000
Description = The AVerMedia, AVerTV WDM Video Capture service failed to start due
to the following error: %%1058

Error - 27/02/2010 8:53:10 PM | Computer Name = PUNKY | Source = Service Control Manager | ID = 7000
Description = The AVerMedia, AVerTV WDM TvTuner service failed to start due to the
following error: %%1058

Error - 27/02/2010 10:08:32 PM | Computer Name = PUNKY | Source = Service Control Manager | ID = 7000
Description = The AVerMedia, AVerTV WDM Video Capture service failed to start due
to the following error: %%1058

Error - 27/02/2010 10:08:32 PM | Computer Name = PUNKY | Source = Service Control Manager | ID = 7000
Description = The AVerMedia, AVerTV WDM TvTuner service failed to start due to the
following error: %%1058

Error - 27/02/2010 10:18:38 PM | Computer Name = PUNKY | Source = Service Control Manager | ID = 7000
Description = The AVerMedia, AVerTV WDM Video Capture service failed to start due
to the following error: %%1058

Error - 27/02/2010 10:18:38 PM | Computer Name = PUNKY | Source = Service Control Manager | ID = 7000
Description = The AVerMedia, AVerTV WDM TvTuner service failed to start due to the
following error: %%1058

Error - 27/02/2010 10:40:34 PM | Computer Name = PUNKY | Source = Service Control Manager | ID = 7000
Description = The AVerMedia, AVerTV WDM Video Capture service failed to start due
to the following error: %%1058

Error - 27/02/2010 10:40:34 PM | Computer Name = PUNKY | Source = Service Control Manager | ID = 7000
Description = The AVerMedia, AVerTV WDM TvTuner service failed to start due to the
following error: %%1058


< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI