radiosnowcode
Topic Starter
Hello, I have a previous post from december of the same problem, another rootkit. Combo fix, fixed my pc before but i no longer have the program on my pc. I ran all of the same programs as before and all the same problems.
DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 13:43:59.10 on Sun 02/28/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_07
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1491 [GMT -5:00]
AV: Paladin Antivirus *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}
AV: Norton 360 *On-access scanning enabled* (Updated) {A5F1BC7C-EA33-4247-961C-0217208396C4}
FW: Norton 360 *enabled* {371C0A40-5A0C-4AD2-A6E5-69C02037FBF3}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
D:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
svchost.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
D:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Chris\Desktop\dds.com
============== Pseudo HJT Report ===============
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: NCO 2.0 IE BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\common files\symantec shared\coshared\browser\2.6\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - d:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Show Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\common files\symantec shared\coshared\browser\2.6\CoIEPlg.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Steam] "d:\program files\steam\Steam.exe" -silent
uRun: [asr64_ldm.exe] c:\docume~1\chris\locals~1\temp\asr64_ldm.exe
uRun: [Paladin Antivirus] "c:\program files\paladin antivirus\pav.exe" -noscan
mRun: [osCheck] "d:\program files\norton 360\osCheck.exe"
mRun: [nwiz] "c:\windows\system32\nwiz.exe" /install
mRun: [NvMediaCenter] "c:\windows\system32\rundll32.exe" c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] "c:\windows\system32\rundll32.exe" c:\windows\system32\NvCpl.dll,NvStartup
mRun: [CTxfiHlp] "c:\windows\system32\CTXFIHLP.EXE"
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [amd_dc_opt] "d:\program files\amd\dual-core optimizer\amd_dc_opt.exe"
mRun: [GrooveMonitor] "d:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "d:\program files\itunes\iTunesHelper.exe"
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
dRunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
uPolicies-explorer: RestrictRun = 0 (0x0)
mPolicies-system: DisableTaskMgr = 1 (0x1)
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - d:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - d:\progra~1\micros~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - d:\progra~1\micros~1\office12\REFIEBAR.DLL
TCP: {BEDC897E-5F4C-4C79-ABDE-3ABB2489E871} = 71.242.0.12 71.252.0.12
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - d:\program files\microsoft office\office12\GrooveSystemServices.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - d:\program files\microsoft office\office12\GrooveShellExtensions.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\chris\applic~1\mozilla\firefox\profiles\u0b3ucv1.default\
FF - component: d:\program files\mozilla firefox\components\coFFPlgn.dll
FF - plugin: c:\documents and settings\chris\application data\move networks\plugins\npqmp071502000008.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - plugin: d:\program files\adobe\acrobat 9.0\acrobat\browser\nppdf32.dll
FF - plugin: d:\program files\itunes\mozilla plugins\npitunes.dll
FF - plugin: d:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-10-13 102448]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20100226.006\NAVENG.SYS [2010-2-26 84912]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20100226.006\NAVEX15.SYS [2010-2-26 1324720]
S2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2008-2-18 149352]
S2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2008-2-18 149352]
S2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\common files\symantec shared\CCSVCHST.EXE [2008-2-18 149352]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-7-31 24652]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-1-12 23888]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2008-8-11 79360]
S3 Symantec Core LC;Symantec Core LC;c:\progra~1\common~1\symant~1\ccpd-lc\symlcsvc.exe [2008-7-31 1245064]
=============== Created Last 30 ================
2010-02-26 04:33:39 8 —-a-w- c:\docume~1\alluse~1\applic~1\mswintmp.dat
2010-02-23 05:47:37 10341 —-a-w- c:\documents and settings\chris\macro.docx
2010-02-10 19:36:52 33280 ——w- c:\windows\system32\dllcache\csrsrv.dll
2010-02-10 19:36:49 474112 ——w- c:\windows\system32\dllcache\shlwapi.dll
2010-02-10 19:36:46 17920 ——w- c:\windows\system32\dllcache\msyuv.dll
2010-02-10 19:36:43 8704 ——w- c:\windows\system32\dllcache\tsbyuv.dll
2010-02-10 19:36:42 48128 ——w- c:\windows\system32\dllcache\iyuv_32.dll
2010-02-10 19:36:42 28672 ——w- c:\windows\system32\dllcache\msvidc32.dll
2010-02-10 19:36:42 11264 ——w- c:\windows\system32\dllcache\msrle32.dll
2010-02-10 19:36:40 343040 ——w- c:\windows\system32\dllcache\mspaint.exe
2010-02-02 04:01:38 18688 —-a-w- c:\windows\system32\drivers\afc.sys
2010-02-02 04:01:35 0 d—–w- c:\docume~1\alluse~1\applic~1\ArcSoft
==================== Find3M ====================
2010-01-01 06:55:52 13824 ——w- c:\windows\system32\dllcache\ieudinit.exe
2010-01-01 06:55:51 70656 ——w- c:\windows\system32\dllcache\ie4uinit.exe
2009-12-31 16:50:03 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-31 16:50:03 353792 ——w- c:\windows\system32\dllcache\srv.sys
2009-12-30 20:32:15 12568 —-a-w- c:\windows\system32\drivers\PROCEXP113.SYS
2009-12-18 07:00:27 634632 ——w- c:\windows\system32\dllcache\iexplore.exe
2009-12-18 06:58:35 161792 ——w- c:\windows\system32\dllcache\ieakui.dll
2009-12-16 18:43:27 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08:23 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-10 03:54:07 261632 —-a-w- c:\windows\PEV.exe
2009-12-08 19:27:51 2189184 ——w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-12-08 19:26:15 2145280 ——w- c:\windows\system32\ntoskrnl.exe
2009-12-08 19:26:15 2145280 ——w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-12-08 18:43:51 2023936 ——w- c:\windows\system32\ntkrnlpa.exe
2009-12-08 18:43:51 2023936 ——w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-12-08 18:43:50 2066048 ——w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-12-04 18:22:22 455424 ——w- c:\windows\system32\dllcache\mrxsmb.sys
2008-12-12 20:22:18 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008121220081213\index.dat
============= FINISH: 13:44:23.34 ===============
and
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-28 13:17:16
Windows 5.1.2600 Service Pack 3
Running: svchost.exe.exe; Driver: C:\DOCUME~1\Chris\LOCALS~1\Temp\pwldyfow.sys
—- System - GMER 1.0.15 —-
Code 89624468 ZwEnumerateKey
Code 89E11870 ZwFlushInstructionCache
Code 8962449E IofCallDriver
Code 8967D286 IofCompleteRequest
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
—- Modules - GMER 1.0.15 —-
Module \systemroot\system32\drivers\_VOIDdepxnlkgbv.sys (*** hidden *** ) B3349000-B3367000 (122880 bytes)
—- Services - GMER 1.0.15 —-
Service C:\WINDOWS\system32\drivers\_VOIDdepxnlkgbv.sys (*** hidden *** ) [SYSTEM] _VOIDd.sys <– ROOTKIT !!!
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys@imagepath \systemroot\system32\drivers\_VOIDdepxnlkgbv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys\modules@_VOIDd \\?\globalroot\systemroot\system32\drivers\_VOIDdepxnlkgbv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys\modules@_VOIDc \\?\globalroot\systemroot\system32\_VOIDiykkkqefom.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys\modules@_VOIDsrcr \\?\globalroot\systemroot\system32\_VOIDuqbhdgowpc.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys\modules@_voidserf \\?\globalroot\systemroot\system32\_VOIDkrvwawfkmy.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys\modules@_voidbbr \\?\globalroot\systemroot\system32\_VOIDvirkcbwejp.dll
Reg HKLM\SYSTEM\ControlSet003\Services\_VOIDd.sys (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\_VOIDd.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\_VOIDd.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\_VOIDd.sys@imagepath \systemroot\system32\drivers\_VOIDdepxnlkgbv.sys
Reg HKLM\SYSTEM\ControlSet003\Services\_VOIDd.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\_VOIDd.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\_VOIDd.sys\modules@_VOIDd \\?\globalroot\systemroot\system32\drivers\_VOIDdepxnlkgbv.sys
Reg HKLM\SYSTEM\ControlSet003\Services\_VOIDd.sys\modules@_VOIDc \\?\globalroot\systemroot\system32\_VOIDiykkkqefom.dll
Reg HKLM\SYSTEM\ControlSet003\Services\_VOIDd.sys\modules@_VOIDsrcr \\?\globalroot\systemroot\system32\_VOIDuqbhdgowpc.dat
Reg HKLM\SYSTEM\ControlSet003\Services\_VOIDd.sys\modules@_voidserf \\?\globalroot\systemroot\system32\_VOIDkrvwawfkmy.dll
Reg HKLM\SYSTEM\ControlSet003\Services\_VOIDd.sys\modules@_voidbbr \\?\globalroot\systemroot\system32\_VOIDvirkcbwejp.dll
—- Files - GMER 1.0.15 —-
File C:\Documents and Settings\All Users\Application Data\_VOIDkrl32mainweq.dll 1526 bytes
File C:\Documents and Settings\All Users\Application Data\_VOIDmainqt.dll 10766 bytes
File C:\Documents and Settings\Chris\Local Settings\temp\_VOID419e.tmp 343040 bytes executable
File C:\WINDOWS\system32\drivers\_VOIDdepxnlkgbv.sys 42496 bytes executable <– ROOTKIT !!!
File C:\WINDOWS\system32\_VOIDiykkkqefom.dll 28160 bytes executable
File C:\WINDOWS\system32\_VOIDkrvwawfkmy.dll 49152 bytes executable
File C:\WINDOWS\system32\_VOIDuqbhdgowpc.dat 274 bytes
File C:\WINDOWS\system32\_VOIDvirkcbwejp.dll 49152 bytes executable
—- EOF - GMER 1.0.15 —-
Also i believe the problem originated from that Paladin Antivirus which i never downloaded or anything, it just took over my pc, i tried to remove it but without anyluck, any help would be appreciated. Thank you.
DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 13:43:59.10 on Sun 02/28/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_07
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1491 [GMT -5:00]
AV: Paladin Antivirus *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}
AV: Norton 360 *On-access scanning enabled* (Updated) {A5F1BC7C-EA33-4247-961C-0217208396C4}
FW: Norton 360 *enabled* {371C0A40-5A0C-4AD2-A6E5-69C02037FBF3}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
D:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
svchost.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
D:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Chris\Desktop\dds.com
============== Pseudo HJT Report ===============
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: NCO 2.0 IE BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\common files\symantec shared\coshared\browser\2.6\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - d:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Show Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\common files\symantec shared\coshared\browser\2.6\CoIEPlg.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Steam] "d:\program files\steam\Steam.exe" -silent
uRun: [asr64_ldm.exe] c:\docume~1\chris\locals~1\temp\asr64_ldm.exe
uRun: [Paladin Antivirus] "c:\program files\paladin antivirus\pav.exe" -noscan
mRun: [osCheck] "d:\program files\norton 360\osCheck.exe"
mRun: [nwiz] "c:\windows\system32\nwiz.exe" /install
mRun: [NvMediaCenter] "c:\windows\system32\rundll32.exe" c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] "c:\windows\system32\rundll32.exe" c:\windows\system32\NvCpl.dll,NvStartup
mRun: [CTxfiHlp] "c:\windows\system32\CTXFIHLP.EXE"
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [amd_dc_opt] "d:\program files\amd\dual-core optimizer\amd_dc_opt.exe"
mRun: [GrooveMonitor] "d:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "d:\program files\itunes\iTunesHelper.exe"
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
dRunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
uPolicies-explorer: RestrictRun = 0 (0x0)
mPolicies-system: DisableTaskMgr = 1 (0x1)
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - d:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - d:\progra~1\micros~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - d:\progra~1\micros~1\office12\REFIEBAR.DLL
TCP: {BEDC897E-5F4C-4C79-ABDE-3ABB2489E871} = 71.242.0.12 71.252.0.12
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - d:\program files\microsoft office\office12\GrooveSystemServices.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - d:\program files\microsoft office\office12\GrooveShellExtensions.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\chris\applic~1\mozilla\firefox\profiles\u0b3ucv1.default\
FF - component: d:\program files\mozilla firefox\components\coFFPlgn.dll
FF - plugin: c:\documents and settings\chris\application data\move networks\plugins\npqmp071502000008.dll
FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - plugin: d:\program files\adobe\acrobat 9.0\acrobat\browser\nppdf32.dll
FF - plugin: d:\program files\itunes\mozilla plugins\npitunes.dll
FF - plugin: d:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-10-13 102448]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20100226.006\NAVENG.SYS [2010-2-26 84912]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20100226.006\NAVEX15.SYS [2010-2-26 1324720]
S2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2008-2-18 149352]
S2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2008-2-18 149352]
S2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\common files\symantec shared\CCSVCHST.EXE [2008-2-18 149352]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-7-31 24652]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-1-12 23888]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2008-8-11 79360]
S3 Symantec Core LC;Symantec Core LC;c:\progra~1\common~1\symant~1\ccpd-lc\symlcsvc.exe [2008-7-31 1245064]
=============== Created Last 30 ================
2010-02-26 04:33:39 8 —-a-w- c:\docume~1\alluse~1\applic~1\mswintmp.dat
2010-02-23 05:47:37 10341 —-a-w- c:\documents and settings\chris\macro.docx
2010-02-10 19:36:52 33280 ——w- c:\windows\system32\dllcache\csrsrv.dll
2010-02-10 19:36:49 474112 ——w- c:\windows\system32\dllcache\shlwapi.dll
2010-02-10 19:36:46 17920 ——w- c:\windows\system32\dllcache\msyuv.dll
2010-02-10 19:36:43 8704 ——w- c:\windows\system32\dllcache\tsbyuv.dll
2010-02-10 19:36:42 48128 ——w- c:\windows\system32\dllcache\iyuv_32.dll
2010-02-10 19:36:42 28672 ——w- c:\windows\system32\dllcache\msvidc32.dll
2010-02-10 19:36:42 11264 ——w- c:\windows\system32\dllcache\msrle32.dll
2010-02-10 19:36:40 343040 ——w- c:\windows\system32\dllcache\mspaint.exe
2010-02-02 04:01:38 18688 —-a-w- c:\windows\system32\drivers\afc.sys
2010-02-02 04:01:35 0 d—–w- c:\docume~1\alluse~1\applic~1\ArcSoft
==================== Find3M ====================
2010-01-01 06:55:52 13824 ——w- c:\windows\system32\dllcache\ieudinit.exe
2010-01-01 06:55:51 70656 ——w- c:\windows\system32\dllcache\ie4uinit.exe
2009-12-31 16:50:03 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-31 16:50:03 353792 ——w- c:\windows\system32\dllcache\srv.sys
2009-12-30 20:32:15 12568 —-a-w- c:\windows\system32\drivers\PROCEXP113.SYS
2009-12-18 07:00:27 634632 ——w- c:\windows\system32\dllcache\iexplore.exe
2009-12-18 06:58:35 161792 ——w- c:\windows\system32\dllcache\ieakui.dll
2009-12-16 18:43:27 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08:23 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-10 03:54:07 261632 —-a-w- c:\windows\PEV.exe
2009-12-08 19:27:51 2189184 ——w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-12-08 19:26:15 2145280 ——w- c:\windows\system32\ntoskrnl.exe
2009-12-08 19:26:15 2145280 ——w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-12-08 18:43:51 2023936 ——w- c:\windows\system32\ntkrnlpa.exe
2009-12-08 18:43:51 2023936 ——w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-12-08 18:43:50 2066048 ——w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-12-04 18:22:22 455424 ——w- c:\windows\system32\dllcache\mrxsmb.sys
2008-12-12 20:22:18 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008121220081213\index.dat
============= FINISH: 13:44:23.34 ===============
and
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-28 13:17:16
Windows 5.1.2600 Service Pack 3
Running: svchost.exe.exe; Driver: C:\DOCUME~1\Chris\LOCALS~1\Temp\pwldyfow.sys
—- System - GMER 1.0.15 —-
Code 89624468 ZwEnumerateKey
Code 89E11870 ZwFlushInstructionCache
Code 8962449E IofCallDriver
Code 8967D286 IofCompleteRequest
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
—- Modules - GMER 1.0.15 —-
Module \systemroot\system32\drivers\_VOIDdepxnlkgbv.sys (*** hidden *** ) B3349000-B3367000 (122880 bytes)
—- Services - GMER 1.0.15 —-
Service C:\WINDOWS\system32\drivers\_VOIDdepxnlkgbv.sys (*** hidden *** ) [SYSTEM] _VOIDd.sys <– ROOTKIT !!!
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys@imagepath \systemroot\system32\drivers\_VOIDdepxnlkgbv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys\modules@_VOIDd \\?\globalroot\systemroot\system32\drivers\_VOIDdepxnlkgbv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys\modules@_VOIDc \\?\globalroot\systemroot\system32\_VOIDiykkkqefom.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys\modules@_VOIDsrcr \\?\globalroot\systemroot\system32\_VOIDuqbhdgowpc.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys\modules@_voidserf \\?\globalroot\systemroot\system32\_VOIDkrvwawfkmy.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\_VOIDd.sys\modules@_voidbbr \\?\globalroot\systemroot\system32\_VOIDvirkcbwejp.dll
Reg HKLM\SYSTEM\ControlSet003\Services\_VOIDd.sys (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\_VOIDd.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\_VOIDd.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\_VOIDd.sys@imagepath \systemroot\system32\drivers\_VOIDdepxnlkgbv.sys
Reg HKLM\SYSTEM\ControlSet003\Services\_VOIDd.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\_VOIDd.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\_VOIDd.sys\modules@_VOIDd \\?\globalroot\systemroot\system32\drivers\_VOIDdepxnlkgbv.sys
Reg HKLM\SYSTEM\ControlSet003\Services\_VOIDd.sys\modules@_VOIDc \\?\globalroot\systemroot\system32\_VOIDiykkkqefom.dll
Reg HKLM\SYSTEM\ControlSet003\Services\_VOIDd.sys\modules@_VOIDsrcr \\?\globalroot\systemroot\system32\_VOIDuqbhdgowpc.dat
Reg HKLM\SYSTEM\ControlSet003\Services\_VOIDd.sys\modules@_voidserf \\?\globalroot\systemroot\system32\_VOIDkrvwawfkmy.dll
Reg HKLM\SYSTEM\ControlSet003\Services\_VOIDd.sys\modules@_voidbbr \\?\globalroot\systemroot\system32\_VOIDvirkcbwejp.dll
—- Files - GMER 1.0.15 —-
File C:\Documents and Settings\All Users\Application Data\_VOIDkrl32mainweq.dll 1526 bytes
File C:\Documents and Settings\All Users\Application Data\_VOIDmainqt.dll 10766 bytes
File C:\Documents and Settings\Chris\Local Settings\temp\_VOID419e.tmp 343040 bytes executable
File C:\WINDOWS\system32\drivers\_VOIDdepxnlkgbv.sys 42496 bytes executable <– ROOTKIT !!!
File C:\WINDOWS\system32\_VOIDiykkkqefom.dll 28160 bytes executable
File C:\WINDOWS\system32\_VOIDkrvwawfkmy.dll 49152 bytes executable
File C:\WINDOWS\system32\_VOIDuqbhdgowpc.dat 274 bytes
File C:\WINDOWS\system32\_VOIDvirkcbwejp.dll 49152 bytes executable
—- EOF - GMER 1.0.15 —-
Also i believe the problem originated from that Paladin Antivirus which i never downloaded or anything, it just took over my pc, i tried to remove it but without anyluck, any help would be appreciated. Thank you.