This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Google Redirect Virus... So much <3

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Good evening, Wanted to take a moment and say thanks for all you do. Your time and hard work is very appreciated. This one after messing with it all after noon is a little out of my league, and I humbly bow down to the ones who sacrifice their time and energy to help us so willingly..

Thank You!!


So lets get to it shall we ?

Off a site I was browsing ( thinking maybe an Ad ) I got the Security Guard, Rogue Antivirus carp**. I am not sure what it was in terms of 2k9 2k10 etc etc.. It didn't say but using MalwareBytes I was able to remove it.

I currently have installed Malwarebytes, Spybot S&D and then using Windows Defender… There usually hasn't been anything in question that I haven't been able to remove my self.

Except for This Google Redirect BS that is very annoying…. Following your guides here are the requested logs/Files.

DDS.txt

DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 23:07:23.89 on Tue 03/16/2010
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1542 [GMT -5:00]

AV: Security Guard *On-access scanning enabled* (Updated) {7E2ABF11-F640-4EFE-8CAF-F915E22467DE}
FW: Security Guard *enabled* {AB93FA31-CAF4-45BB-BDD3-D9C647862F93}

============== Running Processes ===============

C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\explorer.exe
C:\Program Files\World of Warcraft\BackgroundDownloader.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\robert\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

mWindow Title =
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\robert\applic~1\mozilla\firefox\profiles\lwnrqh36.default\
FF - plugin: c:\documents and settings\robert\application data\facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\documents and settings\robert\application data\facebook\npfbplugin_1_0_3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1");
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [2009-6-4 171032]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [2009-6-4 1324056]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [2009-6-4 72728]
S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2010-1-8 79360]
S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [2009-6-4 171032]
S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [2009-6-4 1324056]
S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [2009-6-4 72728]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\dragon age\bin_ship\daupdatersvc.service.exe [2009-12-15 25832]

=============== Created Last 30 ================

2010-03-16 12:15

–d—– c:\program files\Trend Micro
2010-03-16 10:43 a-dshr– C:\cmdcons
2010-03-16 10:42 261,632 a——- c:\windows\PEV.exe
2010-03-16 10:42 161,792 a——- c:\windows\SWREG.exe
2010-03-16 10:42 98,816 a——- c:\windows\sed.exe
2010-03-16 10:42 77,312 a——- c:\windows\MBR.exe
2010-03-16 09:45 –d—– c:\docume~1\robert\applic~1\.BitTornado
2010-03-16 09:45 –d—– c:\program files\BitTornado
2010-03-16 08:48 67 a——- C:\snl2w.drv
2010-03-16 08:47 –d—– c:\docume~1\alluse~1\applic~1\bbf34
2010-03-16 08:47 –dsh— c:\docume~1\alluse~1\applic~1\SGEQD
2010-03-16 08:46 –dsh— c:\documents and settings\all users\946dec7
2010-03-10 16:21 3,558,912 -c—— c:\windows\system32\dllcache\moviemk.exe
2010-03-09 18:45 –ds—- c:\documents and settings\robert\UserData
2010-03-08 14:11 –d—– c:\docume~1\robert\applic~1\Malwarebytes
2010-03-08 14:11 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-08 14:11 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-03-08 14:11 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-03-08 14:11 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-03-06 00:15 552 a——- c:\windows\system32\d3d8caps.dat
2010-03-03 21:52 181,632 ——– c:\windows\system32\MpSigStub.exe
2010-03-03 18:52 664 a——- c:\windows\system32\d3d9caps.dat
2010-03-02 08:53 1,089,593 -c—— c:\windows\system32\dllcache\ntprint.cat
2010-03-01 18:40 268 a——- c:\windows\wininit.ini
2010-03-01 17:13 –d—– c:\program files\Spybot - Search & Destroy
2010-03-01 17:13 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-03-01 12:29 –d—– c:\windows\system32\XPSViewer
2010-03-01 12:29 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll
2010-03-01 12:29 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-03-01 12:29 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll
2010-03-01 12:29 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-03-01 12:29 –d—– C:\f45cf379c667103524b169839e
2010-03-01 12:29 1,676,288 ——– c:\windows\system32\xpssvcs.dll
2010-03-01 12:29 575,488 ——– c:\windows\system32\xpsshhdr.dll
2010-03-01 12:29 117,760 ——– c:\windows\system32\prntvpt.dll
2010-02-27 14:08 –d—– c:\docume~1\alluse~1\applic~1\BioWare
2010-02-27 13:17 –d—– c:\program files\Dragon Age
2010-02-27 13:15 –d—– c:\program files\common files\BioWare
2010-02-17 16:21 –d—– c:\program files\The KMPlayer

==================== Find3M ====================

2010-01-09 13:09 86,327 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2010-01-08 22:17 444,952 a——- c:\windows\system32\wrap_oal.dll
2010-01-08 22:17 109,080 a——- c:\windows\system32\OpenAL32.dll
2010-01-08 21:27 21,640 a——- c:\windows\system32\emptyregdb.dat
2009-12-22 00:21 667,136 ——– c:\windows\system32\wininet.dll
2009-12-22 00:20 81,920 a——- c:\windows\system32\ieencode.dll
2009-12-17 18:14 411,368 a——- c:\windows\system32\deploytk.dll

============= FINISH: 23:08:21.54 ===============




Gmer.Txt

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-03-16 23:14:05
Windows 5.1.2600 Service Pack 3
Running: u26259t2.exe; Driver: C:\DOCUME~1\robert\LOCALS~1\Temp\pxtdrpob.sys


—- System - GMER 1.0.15 —-

Code \??\C:\DOCUME~1\robert\LOCALS~1\Temp\catchme.sys pIofCallDriver

—- Devices - GMER 1.0.15 —-

Device \Driver\00000845 -> \Driver\nvgts \Device\Harddisk0\DR0 8A8CA50C

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\drivers\nvgts.sys suspicious modification

—- EOF - GMER 1.0.15 —-





I look forward to your time and help !!!

Attachments:

Hello kaxfenix and welcome to WhatTheTech. I’ll be happy to look over your log and help you with your issues. It will be very helpful if you follow these guidelines:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please follow my instructions carefully and in the order they are posted.
  • Any underlined text in my posts indicates a clickable link.
  • You should print any instructions I give you for ease of use and reference.
  • If you have any questions at all, please stop and ask before proceeding.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.This may cause a delay, but I will do my best to keep it as short as possible.

I will post back as soon as possible with instructions.
kaxfenix,

🖼Click to load external image (Posted Image) P2P - I see you have P2P software (BitTornado) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to malware infections. Malware authors use P2P filesharing as a major conduit to spread their wares. I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs. If you choose to keep these applications, please do not use them until our fixes at WTT are complete.

🖼Click to load external image (Posted Image) I see that you may have ran ComboFix earlier. I'd like to see the log. Click Start > Run or press Windows Key + R copy/paste the following into the run box that opens and press OK:
c:\ComboFix.txt

That should open the ComboFix log. Please include it with your next post.

🖼Click to load external image (Posted Image) Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    *nvgts*
    
    :dir
    c:\docume~1\alluse~1\applic~1\bbf34
    c:\docume~1\alluse~1\applic~1\SGEQD
    c:\documents and settings\all users\946dec7
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

🖼Click to load external image (Posted Image) Go to My Computer-> Tools-> Folder Options-> View tab:
  • Under the Hidden files and folders heading:
  • Select - Show hidden files and folders.
  • Uncheck- Hide protected operating system files (recommended) option.
  • Also, make sure there is no checkmark beside Hide file extensions for known file types.
  • Click OK. (Remember to Hide files and folders once done)
Please go to one of the below sites to scan the following files:
jotti.org
Kaspersky Virus File Scanner
Virus Total

click on Browse, and upload the following file for analysis:
c:\snl2w.drv

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.

Please include the following in your next post:
  • ComboFix log (If avaiable)
  • systemlook log
  • File upload results
Note: In the future, please don't put your logs into quote boxes. Thanks!
ComboFix Log

ComboFix 10-03-16.03 - robert 03/16/2010 18:01:01.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1704 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Security Guard *On-access scanning enabled* (Updated) {7E2ABF11-F640-4EFE-8CAF-F915E22467DE}
FW: Security Guard *enabled* {AB93FA31-CAF4-45BB-BDD3-D9C647862F93}
.

((((((((((((((((((((((((( Files Created from 2010-02-16 to 2010-03-16 )))))))))))))))))))))))))))))))
.

2010-03-16 17:15 . 2010-03-16 17:15 ——– d—–w- c:\program files\Trend Micro
2010-03-16 14:45 . 2010-03-16 14:45 ——– d—–w- c:\documents and settings\robert\Application Data\.BitTornado
2010-03-16 14:45 . 2010-03-16 14:45 ——– d—–w- c:\program files\BitTornado
2010-03-16 13:48 . 2010-03-16 13:48 67 —-a-w- C:\snl2w.drv
2010-03-16 13:47 . 2010-03-16 13:47 ——– d—–w- c:\documents and settings\All Users\Application Data\bbf34
2010-03-16 13:47 . 2010-03-16 13:46 2326528 —-a-w- c:\documents and settings\All Users\Application Data\bbf34\SG289.exe
2010-03-16 13:47 . 2010-03-16 13:49 ——– d-sh–w- c:\documents and settings\NetworkService\Application Data\Security Guard
2010-03-16 13:47 . 2010-03-16 13:47 ——– d-sh–w- c:\documents and settings\All Users\Application Data\SGEQD
2010-03-16 13:46 . 2010-03-16 13:47 ——– d-sh–w- c:\documents and settings\All Users\946dec7
2010-03-15 16:31 . 2010-03-15 16:31 ——– d-s—w- c:\documents and settings\LocalService\UserData
2010-03-10 21:21 . 2009-10-23 15:28 3558912 -c—-w- c:\windows\system32\dllcache\moviemk.exe
2010-03-09 23:46 . 2010-03-09 23:47 ——– d—–w- c:\documents and settings\robert\Local Settings\Application Data\Temp
2010-03-09 23:46 . 2010-03-09 23:46 ——– d—–w- c:\documents and settings\robert\Local Settings\Application Data\Deployment
2010-03-09 23:45 . 2010-03-09 23:45 ——– d-s—w- c:\documents and settings\robert\UserData
2010-03-08 19:11 . 2010-03-08 19:11 ——– d—–w- c:\documents and settings\robert\Application Data\Malwarebytes
2010-03-08 19:11 . 2010-01-07 22:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-08 19:11 . 2010-03-08 19:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-08 19:11 . 2010-03-08 19:11 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-08 19:11 . 2010-01-07 22:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-06 05:30 . 2010-03-06 05:30 5582848 —-a-w- c:\documents and settings\robert\Application Data\Facebook\npfbplugin_1_0_3.dll
2010-03-06 05:15 . 2010-03-06 05:15 552 —-a-w- c:\windows\system32\d3d8caps.dat
2010-03-04 02:52 . 2010-02-24 15:16 181632 ——w- c:\windows\system32\MpSigStub.exe
2010-03-04 02:48 . 2010-03-04 02:48 ——– d—–w- c:\program files\Windows Defender
2010-03-03 23:52 . 2010-03-04 04:49 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-03-03 23:52 . 2010-03-15 15:55 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-03-03 21:54 . 2010-03-03 21:54 ——– d-s—w- c:\documents and settings\NetworkService\UserData
2010-03-01 22:22 . 2010-03-01 22:22 1923768 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player.exe
2010-03-01 22:13 . 2010-03-16 17:35 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-03-01 22:13 . 2010-03-01 22:31 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-27 19:08 . 2010-02-27 19:08 ——– d—–w- c:\documents and settings\All Users\Application Data\BioWare
2010-02-27 18:17 . 2010-03-08 22:00 ——– d—–w- c:\program files\Dragon Age
2010-02-27 18:15 . 2010-02-27 18:37 ——– d—–w- c:\program files\Common Files\BioWare
2010-02-17 21:21 . 2010-02-17 21:30 ——– d—–w- c:\program files\The KMPlayer

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-15 19:05 . 2010-01-29 16:15 50354 —-a-w- c:\documents and settings\robert\Application Data\Facebook\uninstall.exe
2010-03-15 19:05 . 2010-01-29 16:15 ——– d—–w- c:\documents and settings\robert\Application Data\Facebook
2010-03-15 00:46 . 2010-01-09 04:19 ——– d—–w- c:\program files\World of Warcraft
2010-03-04 02:48 . 2010-01-09 15:21 17576 —-a-w- c:\documents and settings\robert\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-01 23:44 . 2010-01-30 19:32 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-03-01 17:29 . 2010-03-01 17:29 ——– d—–w- c:\program files\MSBuild
2010-03-01 17:29 . 2010-03-01 17:29 ——– d—–w- c:\program files\Reference Assemblies
2010-02-27 18:37 . 2010-01-11 00:29 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-02-15 16:40 . 2010-01-19 18:45 ——– d—–w- c:\documents and settings\robert\Application Data\.ABC
2010-01-30 19:34 . 2010-01-30 19:34 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-30 19:33 . 2010-01-30 19:33 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-01-30 19:32 . 2010-01-30 19:32 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-01-29 01:07 . 2010-01-29 01:07 ——– d—–w- c:\program files\Common Files\Java
2010-01-29 00:17 . 2010-01-29 00:17 503808 —-a-w- c:\documents and settings\robert\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2a4dc205-n\msvcp71.dll
2010-01-29 00:17 . 2010-01-29 00:17 499712 —-a-w- c:\documents and settings\robert\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2a4dc205-n\jmc.dll
2010-01-29 00:17 . 2010-01-29 00:17 348160 —-a-w- c:\documents and settings\robert\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2a4dc205-n\msvcr71.dll
2010-01-29 00:17 . 2010-01-29 00:17 61440 —-a-w- c:\documents and settings\robert\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6b8243c3-n\decora-sse.dll
2010-01-29 00:17 . 2010-01-29 00:17 12800 —-a-w- c:\documents and settings\robert\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6b8243c3-n\decora-d3d.dll
2010-01-29 00:17 . 2010-01-11 00:42 ——– d—–w- c:\program files\Java
2010-01-27 03:21 . 2010-01-27 03:21 847040 —-a-w- c:\documents and settings\robert\Application Data\Facebook\axfbootloader.dll
2010-01-27 03:20 . 2010-01-27 03:20 5578752 —-a-w- c:\documents and settings\robert\Application Data\Facebook\npfbplugin_1_0_1.dll
2010-01-19 19:30 . 2010-01-09 03:18 ——– d—–w- c:\program files\Creative
2010-01-19 19:22 . 2010-01-09 03:17 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-01-11 00:42 . 2010-01-11 00:42 152576 —-a-w- c:\documents and settings\robert\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-01-11 00:42 . 2010-01-11 00:42 79488 —-a-w- c:\documents and settings\robert\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-10 23:08 . 2010-01-10 23:08 75 —-a-w- c:\windows\system32\nvUnsupRes.dat
2010-01-09 18:09 . 2010-01-09 02:29 86327 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-01-09 04:03 . 2010-01-09 04:03 0 —-a-w- c:\windows\nsreg.dat
2010-01-09 03:17 . 2010-01-09 03:17 444952 —-a-w- c:\windows\system32\wrap_oal.dll
2010-01-09 03:17 . 2010-01-09 03:17 109080 —-a-w- c:\windows\system32\OpenAL32.dll
2010-01-09 02:27 . 2010-01-09 02:27 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2009-12-31 16:50 . 2004-08-04 12:00 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 05:21 . 2004-08-04 12:00 667136 ——w- c:\windows\system32\wininet.dll
2009-12-22 05:20 . 2004-08-04 12:00 81920 —-a-w- c:\windows\system32\ieencode.dll
2009-12-17 23:14 . 2010-01-11 00:43 411368 —-a-w- c:\windows\system32\deploytk.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-03-16_17.06.09 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-16 22:51 . 2010-03-16 22:51 16384 c:\windows\temp\Perflib_Perfdata_5b4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-11-21 110184]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-11-21 12669544]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"=
"c:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"c:\\Documents and Settings\\All Users\\946dec7\\SG946d.exe"=

R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [6/4/2009 3:46 AM 171032]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [6/4/2009 3:46 AM 1324056]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [6/4/2009 3:46 AM 72728]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 8:19 PM 13592]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [1/8/2010 10:18 PM 79360]
S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [6/4/2009 3:46 AM 171032]
S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [6/4/2009 3:46 AM 1324056]
S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [6/4/2009 3:46 AM 72728]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [12/15/2009 3:07 PM 25832]
.
.
——- Supplementary Scan ——-
.
mWindow Title =
FF - ProfilePath - c:\documents and settings\robert\Application Data\Mozilla\Firefox\Profiles\lwnrqh36.default\
FF - plugin: c:\documents and settings\robert\Application Data\Facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\documents and settings\robert\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-16 18:06
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A8CA50C]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xb810cf28
\Driver\ACPI -> ACPI.sys @ 0xb7f7fcb8
\Driver\atapi -> atapi.sys @ 0xb7f11852
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579022
ParseProcedure -> ntkrnlpa.exe @ 0x80577c84
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579022
ParseProcedure -> ntkrnlpa.exe @ 0x80577c84
NDIS: NVIDIA nForce 10/100/1000 Mbps Ethernet -> SendCompleteHandler -> NDIS.sys @ 0xb7de0bb0
PacketIndicateHandler -> NDIS.sys @ 0xb7deda21
SendHandler -> NDIS.sys @ 0xb7dcb87b
user & kernel MBR OK
copy of MBR has been found in sector 0x012A14C00
malicious code @ sector 0x012A14C03 !
PE file found in sector at 0x012A14C19 !

**************************************************************************
.
Completion time: 2010-03-16 18:09:16
ComboFix-quarantined-files.txt 2010-03-16 23:09
ComboFix2.txt 2010-03-16 17:08
ComboFix3.txt 2010-03-16 15:53

Pre-Run: 105,222,541,312 bytes free
Post-Run: 105,187,168,256 bytes free

Current=1 Default=1 Failed=4 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - DD40AE581055D028A414E3CF9F16978B




System Look Log

SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 17:35 on 17/03/2010 by robert (Administrator - Elevation successful)

========== filefind ==========

Searching for "*nvgts*"
C:\NVIDIA\nForceWin2k\15.23\IS\IDE\WinXP\sataraid\nvgts.sys –a— 145952 bytes [00:54 19/08/2008] [00:54 19/08/2008] 37954CD1D0AFC11BECD149F7C3EC88C2
C:\NVIDIA\nForceWin2k\15.23\IS\IDE\WinXP\sata_ide\nvgts.inf –a— 4986 bytes [23:50 03/09/2008] [23:50 03/09/2008] DB85D6BD294E3EB4604B46850A4C5280
C:\NVIDIA\nForceWin2k\15.23\IS\IDE\WinXP\sata_ide\nvgts.sys –a— 145952 bytes [00:54 19/08/2008] [00:54 19/08/2008] EA98BFE4931BD13D747D647C1859796E
C:\WINDOWS\system32\drivers\nvgts.sys –a— 145952 bytes [00:54 19/08/2008] [00:54 19/08/2008] F127FB76A5571D2C0549DC4DE0FF12E7

========== dir ==========

c:\docume~1\alluse~1\applic~1\bbf34 - Parameters: "(none)"

—Files—
SG289.exe –a— 2326528 bytes [13:47 16/03/2010] [13:46 16/03/2010]
SGD.ico –a— 4286 bytes [13:47 16/03/2010] [13:47 16/03/2010]

—Folders—
None found.

c:\docume~1\alluse~1\applic~1\SGEQD - Parameters: "(none)"

—Files—
SGBVUCUD.cfg –ahs- 6329 bytes [13:47 16/03/2010] [14:12 16/03/2010]

—Folders—
None found.

c:\documents and settings\all users\946dec7 - Parameters: "(none)"

—Files—
26.mof –a— 326 bytes [13:47 16/03/2010] [13:47 16/03/2010]
SG946d.exe –a— 2326528 bytes [13:46 16/03/2010] [13:46 16/03/2010]

—Folders—
Quarantine Items d—– [13:47 16/03/2010]
SGDSys d—– [13:47 16/03/2010]

-=End Of File=-




Results of File Scan snl2w.drv

[ArcaVir]
2010-03-17 Found nothing
[F-Secure Anti-Virus]
2010-03-17 Found nothing
[A-Squared]
2010-03-17 Found nothing
[G DATA]
2010-03-17 Found nothing
[Avast! antivirus]
2010-03-17 Found nothing
[Ikarus]
2010-03-17 Found nothing
[Grisoft AVG Anti-Virus]
2010-03-17 Found nothing
[Kaspersky Anti-Virus]
2010-03-17 Found nothing
[Avira AntiVir]
2010-03-17 Found nothing
[ESET NOD32]
2010-03-17 Found nothing
[Softwin BitDefender]
2010-03-17 Found nothing
[Panda Antivirus]
2010-03-17 Found nothing
[ClamAV]
2010-03-17 Found nothing
[Quick Heal]
2010-03-17 Found nothing
[CPsecure]
2010-03-17 Found nothing
[Sophos]
2010-03-17 Found nothing
[Dr.Web]
2010-03-17 Found nothing
[VirusBlokAda VBA32]
2010-03-16 Found nothing
[Frisk F-Prot Antivirus]
2010-03-17 Found nothing
[VirusBuster]
2010-03-17 Found nothing
kaxfenix,

🖼Click to load external image (Posted Image) Download TDSSKiller and save it to your Desktop.
  • Extract the file and run it.
  • Once completed it will create a log in your C:\ drive called TDSSKiller_* (* denotes version & date)
  • Please post the content of that log TDSSKiller
🖼Click to load external image (Posted Image) Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad ) and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above Folder::

Folder::
c:\documents and settings\All Users\Application Data\bbf34
c:\documents and settings\NetworkService\Application Data\Security Guard
c:\documents and settings\All Users\Application Data\SGEQD
c:\documents and settings\All Users\946dec7

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Documents and Settings\\All Users\\946dec7\\SG946d.exe"=-

SecCenter::
AV: Security Guard *On-access scanning enabled* (Updated) {7E2ABF11-F640-4EFE-8CAF-F915E22467DE}
FW: Security Guard *enabled* {AB93FA31-CAF4-45BB-BDD3-D9C647862F93}

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.

🖼Click to load external image (Posted Image) I see that you may have ran ComboFix earlier. I'd like to see the log. Click Start > Run or press Windows Key + R copy/paste the following into the run box that opens and press OK:
c:\ComboFix-quarantined-files.txt

That should open a log file of the quarantine. Please post it.

Just for future reference, ComboFix is a very powerful tool that is not recommended for unsupervised use.

Please include the following in your next post:
  • TDSSKiller log
  • ComboFix log
  • ComboFix Quarantine log
  • How is your computer running?
THank you for the inquiry on how my PC is running.. PC is runnign fine as always with the exception of the Google Redirect issues.. I really appreciate you helping me with this..



TDSSKiller.2.2.8_18.03.2010_22.40.01_log.txt\

NOTE:
Upon running this I did a reboot and windows would not start. Giving me an error saying Missing c:\windows\system32\drivers\tsk5.tmp was missing or corrupt.

I had to reboot and F8 into last known good configuration to get windows to load so I am afraid anything TDSkiller did was undone. Upon reboot I did it once again and it could not find Tsk87.tmp in C:\WINDOWS\system32\drivers

Again rebooted into last know good config. Any Advice ? Log below.

22:40:01:203 3484 TDSS rootkit removing tool 2.2.8 Mar 10 2010 15:53:20
22:40:01:203 3484 ================================================================================
22:40:01:203 3484 SystemInfo:

22:40:01:203 3484 OS Version: 5.1.2600 ServicePack: 3.0
22:40:01:203 3484 Product type: Workstation
22:40:01:203 3484 ComputerName: ROB
22:40:01:203 3484 UserName: robert
22:40:01:203 3484 Windows directory: C:\WINDOWS
22:40:01:203 3484 Processor architecture: Intel x86
22:40:01:203 3484 Number of processors: 1
22:40:01:203 3484 Page size: 0x1000
22:40:01:203 3484 Boot type: Normal boot
22:40:01:203 3484 ================================================================================
22:40:01:218 3484 UnloadDriverW: NtUnloadDriver error 2
22:40:01:218 3484 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
22:40:01:281 3484 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
22:40:01:281 3484 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
22:40:01:281 3484 wfopen_ex: Trying to KLMD file open
22:40:01:281 3484 wfopen_ex: File opened ok (Flags 2)
22:40:01:281 3484 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
22:40:01:281 3484 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
22:40:01:281 3484 wfopen_ex: Trying to KLMD file open
22:40:01:281 3484 wfopen_ex: File opened ok (Flags 2)
22:40:01:281 3484 Initialize success
22:40:01:281 3484
22:40:01:281 3484 Scanning Services …
22:40:01:375 3484 GetAdvancedServicesInfo: Raw services enum returned 324 services
22:40:01:375 3484
22:40:01:375 3484 Scanning Kernel memory …
22:40:01:375 3484 Devices to scan: 4
22:40:01:375 3484
22:40:01:375 3484 Driver Name: Disk
22:40:01:375 3484 IRP_MJ_CREATE : B810EBB0
22:40:01:375 3484 IRP_MJ_CREATE_NAMED_PIPE : 804F355A
22:40:01:375 3484 IRP_MJ_CLOSE : B810EBB0
22:40:01:375 3484 IRP_MJ_READ : B8108D1F
22:40:01:375 3484 IRP_MJ_WRITE : B8108D1F
22:40:01:375 3484 IRP_MJ_QUERY_INFORMATION : 804F355A
22:40:01:375 3484 IRP_MJ_SET_INFORMATION : 804F355A
22:40:01:375 3484 IRP_MJ_QUERY_EA : 804F355A
22:40:01:375 3484 IRP_MJ_SET_EA : 804F355A
22:40:01:375 3484 IRP_MJ_FLUSH_BUFFERS : B81092E2
22:40:01:375 3484 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F355A
22:40:01:375 3484 IRP_MJ_SET_VOLUME_INFORMATION : 804F355A
22:40:01:375 3484 IRP_MJ_DIRECTORY_CONTROL : 804F355A
22:40:01:375 3484 IRP_MJ_FILE_SYSTEM_CONTROL : 804F355A
22:40:01:375 3484 IRP_MJ_DEVICE_CONTROL : B81093BB
22:40:01:375 3484 IRP_MJ_INTERNAL_DEVICE_CONTROL : B810CF28
22:40:01:375 3484 IRP_MJ_SHUTDOWN : B81092E2
22:40:01:375 3484 IRP_MJ_LOCK_CONTROL : 804F355A
22:40:01:375 3484 IRP_MJ_CLEANUP : 804F355A
22:40:01:375 3484 IRP_MJ_CREATE_MAILSLOT : 804F355A
22:40:01:375 3484 IRP_MJ_QUERY_SECURITY : 804F355A
22:40:01:375 3484 IRP_MJ_SET_SECURITY : 804F355A
22:40:01:375 3484 IRP_MJ_POWER : B810AC82
22:40:01:375 3484 IRP_MJ_SYSTEM_CONTROL : B810F99E
22:40:01:375 3484 IRP_MJ_DEVICE_CHANGE : 804F355A
22:40:01:375 3484 IRP_MJ_QUERY_QUOTA : 804F355A
22:40:01:375 3484 IRP_MJ_SET_QUOTA : 804F355A
22:40:01:421 3484 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
22:40:01:421 3484
22:40:01:421 3484 Driver Name: Disk
22:40:01:421 3484 IRP_MJ_CREATE : B810EBB0
22:40:01:421 3484 IRP_MJ_CREATE_NAMED_PIPE : 804F355A
22:40:01:421 3484 IRP_MJ_CLOSE : B810EBB0
22:40:01:421 3484 IRP_MJ_READ : B8108D1F
22:40:01:421 3484 IRP_MJ_WRITE : B8108D1F
22:40:01:421 3484 IRP_MJ_QUERY_INFORMATION : 804F355A
22:40:01:421 3484 IRP_MJ_SET_INFORMATION : 804F355A
22:40:01:421 3484 IRP_MJ_QUERY_EA : 804F355A
22:40:01:421 3484 IRP_MJ_SET_EA : 804F355A
22:40:01:421 3484 IRP_MJ_FLUSH_BUFFERS : B81092E2
22:40:01:421 3484 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F355A
22:40:01:421 3484 IRP_MJ_SET_VOLUME_INFORMATION : 804F355A
22:40:01:421 3484 IRP_MJ_DIRECTORY_CONTROL : 804F355A
22:40:01:421 3484 IRP_MJ_FILE_SYSTEM_CONTROL : 804F355A
22:40:01:421 3484 IRP_MJ_DEVICE_CONTROL : B81093BB
22:40:01:421 3484 IRP_MJ_INTERNAL_DEVICE_CONTROL : B810CF28
22:40:01:421 3484 IRP_MJ_SHUTDOWN : B81092E2
22:40:01:421 3484 IRP_MJ_LOCK_CONTROL : 804F355A
22:40:01:421 3484 IRP_MJ_CLEANUP : 804F355A
22:40:01:421 3484 IRP_MJ_CREATE_MAILSLOT : 804F355A
22:40:01:421 3484 IRP_MJ_QUERY_SECURITY : 804F355A
22:40:01:421 3484 IRP_MJ_SET_SECURITY : 804F355A
22:40:01:421 3484 IRP_MJ_POWER : B810AC82
22:40:01:421 3484 IRP_MJ_SYSTEM_CONTROL : B810F99E
22:40:01:421 3484 IRP_MJ_DEVICE_CHANGE : 804F355A
22:40:01:421 3484 IRP_MJ_QUERY_QUOTA : 804F355A
22:40:01:421 3484 IRP_MJ_SET_QUOTA : 804F355A
22:40:01:421 3484 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
22:40:01:421 3484
22:40:01:421 3484 Driver Name: Disk
22:40:01:421 3484 IRP_MJ_CREATE : B810EBB0
22:40:01:421 3484 IRP_MJ_CREATE_NAMED_PIPE : 804F355A
22:40:01:421 3484 IRP_MJ_CLOSE : B810EBB0
22:40:01:421 3484 IRP_MJ_READ : B8108D1F
22:40:01:421 3484 IRP_MJ_WRITE : B8108D1F
22:40:01:421 3484 IRP_MJ_QUERY_INFORMATION : 804F355A
22:40:01:421 3484 IRP_MJ_SET_INFORMATION : 804F355A
22:40:01:421 3484 IRP_MJ_QUERY_EA : 804F355A
22:40:01:421 3484 IRP_MJ_SET_EA : 804F355A
22:40:01:421 3484 IRP_MJ_FLUSH_BUFFERS : B81092E2
22:40:01:421 3484 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F355A
22:40:01:421 3484 IRP_MJ_SET_VOLUME_INFORMATION : 804F355A
22:40:01:421 3484 IRP_MJ_DIRECTORY_CONTROL : 804F355A
22:40:01:421 3484 IRP_MJ_FILE_SYSTEM_CONTROL : 804F355A
22:40:01:421 3484 IRP_MJ_DEVICE_CONTROL : B81093BB
22:40:01:421 3484 IRP_MJ_INTERNAL_DEVICE_CONTROL : B810CF28
22:40:01:421 3484 IRP_MJ_SHUTDOWN : B81092E2
22:40:01:421 3484 IRP_MJ_LOCK_CONTROL : 804F355A
22:40:01:421 3484 IRP_MJ_CLEANUP : 804F355A
22:40:01:421 3484 IRP_MJ_CREATE_MAILSLOT : 804F355A
22:40:01:421 3484 IRP_MJ_QUERY_SECURITY : 804F355A
22:40:01:421 3484 IRP_MJ_SET_SECURITY : 804F355A
22:40:01:421 3484 IRP_MJ_POWER : B810AC82
22:40:01:421 3484 IRP_MJ_SYSTEM_CONTROL : B810F99E
22:40:01:421 3484 IRP_MJ_DEVICE_CHANGE : 804F355A
22:40:01:421 3484 IRP_MJ_QUERY_QUOTA : 804F355A
22:40:01:421 3484 IRP_MJ_SET_QUOTA : 804F355A
22:40:01:421 3484 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
22:40:01:421 3484
22:40:01:421 3484 Driver Name: nvgts
22:40:01:421 3484 IRP_MJ_CREATE : 8A4F550C
22:40:01:421 3484 IRP_MJ_CREATE_NAMED_PIPE : 8A4F550C
22:40:01:421 3484 IRP_MJ_CLOSE : 8A4F550C
22:40:01:421 3484 IRP_MJ_READ : 8A4F550C
22:40:01:421 3484 IRP_MJ_WRITE : 8A4F550C
22:40:01:421 3484 IRP_MJ_QUERY_INFORMATION : 8A4F550C
22:40:01:421 3484 IRP_MJ_SET_INFORMATION : 8A4F550C
22:40:01:421 3484 IRP_MJ_QUERY_EA : 8A4F550C
22:40:01:421 3484 IRP_MJ_SET_EA : 8A4F550C
22:40:01:421 3484 IRP_MJ_FLUSH_BUFFERS : 8A4F550C
22:40:01:421 3484 IRP_MJ_QUERY_VOLUME_INFORMATION : 8A4F550C
22:40:01:421 3484 IRP_MJ_SET_VOLUME_INFORMATION : 8A4F550C
22:40:01:421 3484 IRP_MJ_DIRECTORY_CONTROL : 8A4F550C
22:40:01:421 3484 IRP_MJ_FILE_SYSTEM_CONTROL : 8A4F550C
22:40:01:421 3484 IRP_MJ_DEVICE_CONTROL : 8A4F550C
22:40:01:421 3484 IRP_MJ_INTERNAL_DEVICE_CONTROL : 8A4F550C
22:40:01:421 3484 IRP_MJ_SHUTDOWN : 8A4F550C
22:40:01:421 3484 IRP_MJ_LOCK_CONTROL : 8A4F550C
22:40:01:421 3484 IRP_MJ_CLEANUP : 8A4F550C
22:40:01:421 3484 IRP_MJ_CREATE_MAILSLOT : 8A4F550C
22:40:01:421 3484 IRP_MJ_QUERY_SECURITY : 8A4F550C
22:40:01:421 3484 IRP_MJ_SET_SECURITY : 8A4F550C
22:40:01:421 3484 IRP_MJ_POWER : 8A4F550C
22:40:01:421 3484 IRP_MJ_SYSTEM_CONTROL : 8A4F550C
22:40:01:421 3484 IRP_MJ_DEVICE_CHANGE : 8A4F550C
22:40:01:421 3484 IRP_MJ_QUERY_QUOTA : 8A4F550C
22:40:01:421 3484 IRP_MJ_SET_QUOTA : 8A4F550C
22:40:01:421 3484 Driver "nvgts" infected by TDSS rootkit!
22:40:01:437 3484 C:\WINDOWS\system32\DRIVERS\nvgts.sys - Verdict: 2
22:40:01:437 3484 File "C:\WINDOWS\system32\DRIVERS\nvgts.sys" infected by TDSS rootkit … 22:40:01:437 3484 Processing driver file: C:\WINDOWS\system32\DRIVERS\nvgts.sys
22:40:01:437 3484 ProcessDirEnumEx: FindFirstFile(C:\WINDOWS\system32\DriverStore\FileRepository\*) error 3
22:40:01:625 3484 ProcessDirEnumEx: FindFirstFile(C:\WINDOWS\OemDir\*) error 3
22:40:03:593 3484 !fdfb7
22:40:03:656 3484 !vdf5
22:40:03:656 3484 Backup copy not found, trying to cure infected file..
22:40:03:656 3484 Cure success, using it..
22:40:03:703 3484 will be cured on next reboot
22:40:03:703 3484 Reboot required for cure complete..
22:40:03:765 3484 Cure on reboot scheduled successfully
22:40:03:765 3484
22:40:03:765 3484 Completed
22:40:03:765 3484
22:40:03:765 3484 Results:
22:40:03:765 3484 Memory objects infected / cured / cured on reboot: 1 / 0 / 0
22:40:03:765 3484 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
22:40:03:765 3484 File objects infected / cured / cured on reboot: 1 / 0 / 1
22:40:03:765 3484
22:40:03:765 3484 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
22:40:03:765 3484 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
22:40:03:765 3484 UnloadDriverW: NtUnloadDriver error 1
22:40:03:765 3484 KLMD_Unload: UnloadDriverW(klmd21) error 1
22:40:03:765 3484 KLMD(ARK) unloaded successfully




COMBOFIX LOG

ComboFix 10-03-18.01 - robert 03/18/2010 22:55:05.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1691 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\robert\Desktop\CFScript.txt
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\946dec7
c:\documents and settings\All Users\946dec7\26.mof
c:\documents and settings\All Users\946dec7\SG946d.exe
c:\documents and settings\All Users\946dec7\SGDSys\vd952342.bd
c:\documents and settings\all users\application data\adobe\sp.Dll
c:\documents and settings\All Users\Application Data\bbf34
c:\documents and settings\All Users\Application Data\bbf34\SG289.exe
c:\documents and settings\All Users\Application Data\bbf34\SGD.ico
c:\documents and settings\All Users\Application Data\SGEQD
c:\documents and settings\All Users\Application Data\SGEQD\SGBVUCUD.cfg
c:\documents and settings\NetworkService\Application Data\Security Guard
c:\documents and settings\NetworkService\Application Data\Security Guard\Instructions.ini
c:\recycler\S-1-5-21-1542905631-2818295564-705087578-0613
c:\recycler\S-1-5-21-2877962434-1007090996-171546349-9170
c:\recycler\S-1-5-21-3649827759-8246146172-757355827-6667
c:\recycler\S-1-5-21-3868480154-4435818445-680241127-4901
c:\recycler\S-1-5-21-4137705396-4949901426-529612421-4098
c:\recycler\S-1-5-21-4570558363-6315369927-100041970-1248
c:\recycler\S-1-5-21-4570558363-6315369927-100041970-1248\Desktop.ini
c:\recycler\S-1-5-21-4570558363-6315369927-100041970-1248\svchost.exe
c:\recycler\S-1-5-21-6055866078-2596602739-297286967-3041
c:\recycler\S-1-5-21-7901678809-5949946621-904802848-4902
c:\recycler\S-1-5-21-8203409535-8113324684-660928854-4232
c:\recycler\S-1-5-21-8368322452-6144371813-459354266-8733
c:\recycler\S-1-5-21-8811083124-4394478608-859312412-3821

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_SPService


((((((((((((((((((((((((( Files Created from 2010-02-19 to 2010-03-19 )))))))))))))))))))))))))))))))
.

2010-03-19 03:04 . 2010-03-19 03:40 36488 —-a-w- c:\windows\system32\drivers\klmdb.sys
2010-03-17 22:38 . 2010-03-17 22:38 ——– d—–w- C:\New Folder
2010-03-17 14:08 . 2010-03-17 14:08 ——– d—–w- c:\documents and settings\robert\Application Data\DisplayTune
2010-03-17 14:05 . 2009-07-15 18:43 17136 —-a-w- c:\windows\system32\drivers\PdiPorts.sys
2010-03-17 14:05 . 2010-03-17 14:05 ——– d—–w- c:\program files\Portrait Displays
2010-03-17 14:05 . 2007-02-09 17:17 17465 —-a-w- c:\windows\system32\drivers\pivot.sys
2010-03-17 14:04 . 2010-03-17 14:04 ——– d—–w- c:\program files\Acer Display
2010-03-17 14:04 . 2009-07-12 05:55 554832 —-a-w- c:\windows\msvcp80.dll
2010-03-17 14:04 . 2009-07-12 05:55 479232 —-a-w- c:\windows\msvcm80.dll
2010-03-17 14:04 . 2009-07-11 23:10 97280 —-a-w- c:\windows\atl80.dll
2010-03-17 14:04 . 2001-06-01 14:26 372736 —-a-w- c:\windows\ijl15.dll
2010-03-17 06:14 . 2010-03-17 06:14 ——– d—–w- c:\windows\system32\wbem\Repository
2010-03-16 14:45 . 2010-03-16 14:45 ——– d—–w- c:\documents and settings\robert\Application Data\.BitTornado
2010-03-16 14:45 . 2010-03-16 14:45 ——– d—–w- c:\program files\BitTornado
2010-03-16 13:48 . 2010-03-16 13:48 67 —-a-w- C:\snl2w.drv
2010-03-15 16:31 . 2010-03-15 16:31 ——– d-s—w- c:\documents and settings\LocalService\UserData
2010-03-10 21:21 . 2009-10-23 15:28 3558912 -c—-w- c:\windows\system32\dllcache\moviemk.exe
2010-03-09 23:46 . 2010-03-18 17:23 ——– d—–w- c:\documents and settings\robert\Local Settings\Application Data\Temp
2010-03-09 23:46 . 2010-03-09 23:46 ——– d—–w- c:\documents and settings\robert\Local Settings\Application Data\Deployment
2010-03-09 23:45 . 2010-03-09 23:45 ——– d-s—w- c:\documents and settings\robert\UserData
2010-03-08 19:11 . 2010-03-08 19:11 ——– d—–w- c:\documents and settings\robert\Application Data\Malwarebytes
2010-03-08 19:11 . 2010-01-07 22:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-08 19:11 . 2010-03-08 19:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-08 19:11 . 2010-03-08 19:11 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-08 19:11 . 2010-01-07 22:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-06 05:30 . 2010-03-06 05:30 5582848 —-a-w- c:\documents and settings\robert\Application Data\Facebook\npfbplugin_1_0_3.dll
2010-03-06 05:15 . 2010-03-06 05:15 552 —-a-w- c:\windows\system32\d3d8caps.dat
2010-03-04 02:52 . 2010-02-24 15:16 181632 ——w- c:\windows\system32\MpSigStub.exe
2010-03-04 02:48 . 2010-03-04 02:48 ——– d—–w- c:\program files\Windows Defender
2010-03-03 23:52 . 2010-03-04 04:49 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-03-03 23:52 . 2010-03-17 17:09 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-03-03 21:54 . 2010-03-03 21:54 ——– d-s—w- c:\documents and settings\NetworkService\UserData
2010-03-01 22:22 . 2010-03-01 22:22 1923768 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player.exe
2010-03-01 22:13 . 2010-03-16 17:35 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-03-01 22:13 . 2010-03-01 22:31 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-27 19:08 . 2010-02-27 19:08 ——– d—–w- c:\documents and settings\All Users\Application Data\BioWare
2010-02-27 18:17 . 2010-03-08 22:00 ——– d—–w- c:\program files\Dragon Age
2010-02-27 18:15 . 2010-02-27 18:37 ——– d—–w- c:\program files\Common Files\BioWare
2010-02-17 21:21 . 2010-02-17 21:30 ——– d—–w- c:\program files\The KMPlayer

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-19 03:40 . 2010-03-19 03:40 145952 —-a-w- c:\windows\system32\drivers\tsk5.tmp
2010-03-19 03:04 . 2010-03-19 03:04 145952 —-a-w- c:\windows\system32\drivers\tsk87.tmp
2010-03-17 14:25 . 2010-03-17 06:12 ——– d—–w- c:\program files\NVIDIA Corporation
2010-03-17 14:05 . 2010-01-09 03:17 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-03-17 14:05 . 2010-03-17 14:04 ——– d—–w- c:\program files\Common Files\Portrait Displays
2010-03-17 06:14 . 2010-03-17 06:13 ——– d—–w- c:\program files\AGEIA Technologies
2010-03-17 06:13 . 2010-01-09 03:07 ——– d—–w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2010-03-17 06:12 . 2010-03-17 05:33 ——– d—–w- c:\program files\NVIDIA Corporation(2)
2010-03-17 05:29 . 2010-03-17 05:29 ——– d—–w- c:\program files\Phyxion.net
2010-03-16 17:15 . 2010-03-16 17:15 ——– d—–w- c:\program files\Trend Micro
2010-03-15 19:05 . 2010-01-29 16:15 50354 —-a-w- c:\documents and settings\robert\Application Data\Facebook\uninstall.exe
2010-03-15 19:05 . 2010-01-29 16:15 ——– d—–w- c:\documents and settings\robert\Application Data\Facebook
2010-03-15 00:46 . 2010-01-09 04:19 ——– d—–w- c:\program files\World of Warcraft
2010-03-04 02:48 . 2010-01-09 15:21 17576 —-a-w- c:\documents and settings\robert\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-01 23:44 . 2010-01-30 19:32 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-03-01 17:29 . 2010-03-01 17:29 ——– d—–w- c:\program files\MSBuild
2010-03-01 17:29 . 2010-03-01 17:29 ——– d—–w- c:\program files\Reference Assemblies
2010-02-27 18:37 . 2010-01-11 00:29 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-02-15 16:40 . 2010-01-19 18:45 ——– d—–w- c:\documents and settings\robert\Application Data\.ABC
2010-01-30 19:34 . 2010-01-30 19:34 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-30 19:33 . 2010-01-30 19:33 ——– d—–w- c:\program files\Common Files\Adobe AIR
2010-01-30 19:32 . 2010-01-30 19:32 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-01-29 01:07 . 2010-01-29 01:07 ——– d—–w- c:\program files\Common Files\Java
2010-01-29 00:17 . 2010-01-29 00:17 503808 —-a-w- c:\documents and settings\robert\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2a4dc205-n\msvcp71.dll
2010-01-29 00:17 . 2010-01-29 00:17 499712 —-a-w- c:\documents and settings\robert\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2a4dc205-n\jmc.dll
2010-01-29 00:17 . 2010-01-29 00:17 348160 —-a-w- c:\documents and settings\robert\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2a4dc205-n\msvcr71.dll
2010-01-29 00:17 . 2010-01-29 00:17 61440 —-a-w- c:\documents and settings\robert\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6b8243c3-n\decora-sse.dll
2010-01-29 00:17 . 2010-01-29 00:17 12800 —-a-w- c:\documents and settings\robert\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-6b8243c3-n\decora-d3d.dll
2010-01-29 00:17 . 2010-01-11 00:42 ——– d—–w- c:\program files\Java
2010-01-27 03:21 . 2010-01-27 03:21 847040 —-a-w- c:\documents and settings\robert\Application Data\Facebook\axfbootloader.dll
2010-01-27 03:20 . 2010-01-27 03:20 5578752 —-a-w- c:\documents and settings\robert\Application Data\Facebook\npfbplugin_1_0_1.dll
2010-01-19 19:30 . 2010-01-09 03:18 ——– d—–w- c:\program files\Creative
2010-01-12 17:03 . 2010-01-12 17:03 61440 —-a-w- c:\windows\system32\OpenCL.dll
2010-01-12 17:03 . 2010-01-12 17:03 11632640 —-a-w- c:\windows\system32\nvcompiler.dll
2010-01-12 04:03 . 2010-01-09 03:04 6359168 —-a-w- c:\windows\system32\nv4_disp(2).dll
2010-01-11 00:42 . 2010-01-11 00:42 152576 —-a-w- c:\documents and settings\robert\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-01-11 00:42 . 2010-01-11 00:42 79488 —-a-w- c:\documents and settings\robert\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-09 18:09 . 2010-01-09 02:29 86327 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-01-09 04:03 . 2010-01-09 04:03 0 —-a-w- c:\windows\nsreg.dat
2010-01-09 03:17 . 2010-01-09 03:17 444952 —-a-w- c:\windows\system32\wrap_oal.dll
2010-01-09 03:17 . 2010-01-09 03:17 109080 —-a-w- c:\windows\system32\OpenAL32.dll
2010-01-09 02:27 . 2010-01-09 02:27 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2009-12-31 16:50 . 2004-08-04 12:00 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-22 05:21 . 2004-08-04 12:00 667136 —-a-w- c:\windows\system32\wininet.dll
2009-12-22 05:20 . 2004-08-04 12:00 81920 —-a-w- c:\windows\system32\ieencode.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\robert\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-03-09 135664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTxfiHlp"="CTXFIHLP.EXE" [2009-06-04 25600]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"PivotSoftware"="c:\program files\Portrait Displays\Pivot Software\wpctrl.exe" [2007-02-09 694008]
"DT ACR"="c:\program files\Common Files\Portrait Displays\Shared\DT_startup.exe" [2009-11-12 92784]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-09-24 1657448]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"=
"c:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"20463:TCP"= 20463:TCP:spport
"8897:TCP"= 8897:TCP:spport

R2 PdiService;Portrait Displays SDK Service;c:\program files\Common Files\Portrait Displays\Drivers\pdisrvc.exe [3/17/2010 9:16 AM 109168]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [6/4/2009 3:46 AM 171032]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [6/4/2009 3:46 AM 1324056]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [6/4/2009 3:46 AM 72728]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 8:19 PM 13592]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [1/8/2010 10:18 PM 79360]
S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [6/4/2009 3:46 AM 171032]
S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [6/4/2009 3:46 AM 1324056]
S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [6/4/2009 3:46 AM 72728]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [12/15/2009 3:07 PM 25832]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [3/8/2010 2:11 PM 38224]
.
Contents of the 'Scheduled Tasks' folder

2010-03-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-436374069-2147007999-839522115-1003Core.job
- c:\documents and settings\robert\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-09 23:46]

2010-03-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-436374069-2147007999-839522115-1003UA.job
- c:\documents and settings\robert\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-09 23:46]
.
.
——- Supplementary Scan ——-
.
FF - ProfilePath - c:\documents and settings\robert\Application Data\Mozilla\Firefox\Profiles\vlzmuj2w.default\
FF - plugin: c:\documents and settings\robert\Application Data\Facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\documents and settings\robert\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\robert\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -

ShellIconOverlayIdentifiers-{96AFBE69-C3B0-4b00-8578-D933D2896EE2} - (no file)
HKU-Default-Run-Security Guard - c:\documents and settings\All Users\Application Data\bbf34\SG289.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-18 23:02
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTxfiHlp = CTXFIHLP.EXE?

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A95950C]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xb810cf28
\Driver\ACPI -> ACPI.sys @ 0xb7f7fcb8
\Driver\atapi -> atapi.sys @ 0xb7f11852
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579022
ParseProcedure -> ntkrnlpa.exe @ 0x80577c84
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579022
ParseProcedure -> ntkrnlpa.exe @ 0x80577c84
NDIS: NVIDIA nForce 10/100/1000 Mbps Ethernet -> SendCompleteHandler -> NDIS.sys @ 0xb7de0bb0
PacketIndicateHandler -> NDIS.sys @ 0xb7deda21
SendHandler -> NDIS.sys @ 0xb7dcb87b
user & kernel MBR OK
copy of MBR has been found in sector 0x012A14C00
malicious code @ sector 0x012A14C03 !
PE file found in sector at 0x012A14C19 !

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\System\ControlSet004\Enum\HID\Vid_1532&Pid_0007\6&179a389a&0&0000\LogConf]
@DACL=(02 0000)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(748)
c:\program files\Portrait Displays\Pivot Software\winphook.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\nvsvc32.exe
c:\program files\Creative\Shared Files\CTAudSvc.exe
c:\program files\Common Files\Portrait Displays\Shared\dtsrvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Acer Display\eDisplay Management\DTHtml.exe
c:\program files\Common Files\Portrait Displays\Shared\HookManager.exe
c:\program files\Portrait Displays\Pivot Software\floater.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-03-18 23:08:31 - machine was rebooted
ComboFix-quarantined-files.txt 2010-03-19 04:08
ComboFix2.txt 2010-03-16 23:09

Pre-Run: 100,516,663,296 bytes free
Post-Run: 100,888,190,976 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

Current=4 Default=4 Failed=6 LastKnownGood=7 Sets=4,5,6,7
- - End Of File - - F89CAEF6A754AD8FB26D259AB403D624




I do not have a Quarantine Log for Combofix
kaxfenix,

🖼Click to load external image (Posted Image) Open notepad and then copy and paste the contents of the code box below into it. Go to File > save as and name the file “look.bat” (WITH the quotation marks) and save it to your desktop.

@echo off
reg query "HKLM\system\currentcontrolset\services\nvgts" /v imagepath > result.txt
start result.txt
del %0

Double-click on look.bat file to execute it.
A report (result.txt) should open. Please post the contents of that file.

🖼Click to load external image (Posted Image) Go to Start > Run and copy/paste the contents of the codebox below into the Run box and click OK:

cmd /c del /a/f/q "C:\snl2w.drv"

A DOS window will open and close again, this is normal.

Please include the following in your next post:
  • result.txt log
! REG.EXE VERSION 3.0 HKEY_LOCAL_MACHINE\system\currentcontrolset\services\nvgts imagepath REG_EXPAND_SZ system32\DRIVERS\nvgts.sys
kaxfenix,

We need to rename a file, then use the Recovery Console to replace an infected driver:

1. Open Notepad
2. Copy and paste the content of the following codebox into Notepad:

@echo off
copy /y C:\NVIDIA\nForceWin2k\15.23\IS\IDE\WinXP\sata_ide\nvgts.sys c:\
del %0
3. Save the file to your DESKTOP as "fix.bat". Make sure to save it with the quotes.
4. Double click fix.bat. to run it. A small black box should open and close - this is normal.

Print out these instructions to use while in the Recovery Console:

1. Restart your computer.
2. Before Windows loads, you will be prompted to choose which Operating System to start.
3. Use the up and down arrow key to select Microsoft Windows Recovery Console
4. You must enter which Windows installation to log onto. Type 1 and press 'Enter'.
5. At the C:\Windows prompt, type the following bolded entries, one at a time and press 'Enter' after each line. (refer to the quote box under the commands for the location of the spaces which are very important):

cd c:\windows\system32\drivers
ren nvgts.sys nvgts.old
copy c:\nvgts.sys
exit


cdc:\windows\system32\drivers
rennvgts.sysnvgts.old
copyc:\nvgts.sys


You should see a message '1 file copied'. If you did not see that message, try again and ensure there is a space after the word copy and another space between the file paths.

If you do not see 1 file copied on the screen, even after ensuring the commands are correct, rename the file back to it's original name by typing the following command then hitting Enter.
ren nvgts.old nvgts.sys

You should NOT be prompted to overwrite an existing file, but if you are, select No then type exit to restart and notify me of your results)

6. Type exit and press 'Enter'. Your computer should reboot.

🖼Click to load external image (Posted Image) Press Start > Run or Windows Key + R then copy and paste the following command into the run box that opens and press "Enter"
cmd /c mbr -t>"%userprofile%\Desktop\mbr.txt"

That will place a file called MBR.txt on your desktop. Please copy and paste the contents of that file into your next post.

Please include the following in your next post:
  • Let me know how the file copy went
  • MBR log
  • How is your computer running?
File copy went fine.


Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll SCSIPORT.SYS nvgts.sys
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 0x012A14C00
malicious code @ sector 0x012A14C03 !
PE file found in sector at 0x012A14C19 !
kaxfenix,

Are you still being redirected? Please run these two scans for me now:

🖼Click to load external image (Posted Image) You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM
  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

🖼Click to load external image (Posted Image) Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply
🖼Click to load external image (Posted Image) Please run DDS again and post the fresh DDS.txt log

Please include the following in your next post:
  • MBAM log
  • Kaspersky log
  • DDS.txt log
  • How is your computer running?
MBAM Log
Malwarebytes' Anti-Malware 1.44
Database version: 3900
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

3/22/2010 12:19:03 PM
mbam-log-2010-03-22 (12-19-03).txt

Scan type: Quick Scan
Objects scanned: 113347
Time elapsed: 5 minute(s), 58 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\sp (TrojanProxy.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\dll (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\Documents and Settings\robert\Application Data\dll\svchost.exe,) Good: (Userinit.exe) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)




Kas Report

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Monday, March 22, 2010
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Monday, March 22, 2010 13:34:19
Records in database: 3846667
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan statistics:
Objects scanned: 53777
Threats found: 4
Infected objects found: 7
Suspicious objects found: 0
Scan duration: 02:05:20


File name / Threat / Threats count
C:\Qoobox\Quarantine\C\Documents and Settings\All Users\946dec7\SG946d.exe.vir Infected: Trojan.Win32.Tdss.ayhl 1
C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\bbf34\SG289.exe.vir Infected: Trojan.Win32.Tdss.ayhl 1
C:\Qoobox\Quarantine\C\RECYCLER\S-1-5-21-4570558363-6315369927-100041970-1248\svchost.exe.vir Infected: P2P-Worm.Win32.Palevo.ddm 1
C:\System Volume Information\_restore{68B3B0C6-0D55-415F-B472-C386406AF5EA}\RP89\A0041795.exe Infected: Trojan.Win32.Tdss.ayhl 1
C:\System Volume Information\_restore{68B3B0C6-0D55-415F-B472-C386406AF5EA}\RP89\A0041798.exe Infected: Trojan.Win32.Tdss.ayhl 1
C:\System Volume Information\_restore{68B3B0C6-0D55-415F-B472-C386406AF5EA}\RP89\A0041803.exe Infected: P2P-Worm.Win32.Palevo.ddm 1
C:\WINDOWS\system32\drivers\nvgts.old Infected: Rootkit.Win32.TDSS.y 1

Selected area has been scanned.


DDS LOG

DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 15:14:56.37 on Mon 03/22/2010
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1550 [GMT -5:00]


============== Running Processes ===============

C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Portrait Displays\Pivot Software\floater.exe
C:\Program Files\Common Files\Portrait Displays\Shared\HookManager.exe
svchost.exe
C:\Program Files\Common Files\Portrait Displays\Shared\dtsrvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Portrait Displays\Drivers\pdisrvc.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Documents and Settings\robert\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [Google Update] "c:\documents and settings\robert\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [PivotSoftware] "c:\program files\portrait displays\pivot software\wpctrl.exe"
mRun: [DT ACR] c:\program files\common files\portrait displays\shared\DT_startup.exe -ACR
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /install
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\robert\applic~1\mozilla\firefox\profiles\vlzmuj2w.default\
FF - plugin: c:\documents and settings\robert\application data\facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\documents and settings\robert\application data\facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\robert\local settings\application data\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1");
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R2 PdiService;Portrait Displays SDK Service;c:\program files\common files\portrait displays\drivers\pdisrvc.exe [2010-3-17 109168]
R3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [2009-6-4 171032]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [2009-6-4 1324056]
R3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [2009-6-4 72728]
S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2010-1-8 79360]
S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [2009-6-4 171032]
S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [2009-6-4 1324056]
S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [2009-6-4 72728]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\dragon age\bin_ship\daupdatersvc.service.exe [2009-12-15 25832]

=============== Created Last 30 ================

2010-03-21 19:42 691,696 a——- c:\windows\system32\drivers\sptd.sys
2010-03-21 19:42 –d—– c:\program files\DAEMON Tools Lite
2010-03-21 19:42 –d—– c:\docume~1\robert\applic~1\DAEMON Tools Lite
2010-03-21 19:42 –d—– c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite
2010-03-21 09:04 145,952 a——- c:\windows\system32\drivers\NVGTS.SYS
2010-03-21 09:04 145,952 a——- C:\nvgts.sys
2010-03-20 23:07 69 a——- c:\windows\NeroDigital.ini
2010-03-20 21:59 1,757,184 a——- c:\windows\system32\imagX7.dll
2010-03-20 21:59 802,816 a——- c:\windows\system32\imagXRA7.dll
2010-03-20 21:59 497,296 a——- c:\windows\system32\imagXpr7.dll
2010-03-20 21:59 368,640 a——- c:\windows\system32\TwnLib4.dll
2010-03-20 21:59 258,048 a——- c:\windows\system32\imagXR7.dll
2010-03-20 21:59 –d—– c:\program files\Nero
2010-03-20 21:59 –d—– c:\docume~1\alluse~1\applic~1\Nero
2010-03-20 21:59 –dshr– c:\docume~1\robert\applic~1\dll
2010-03-18 22:53 a-dshr– C:\cmdcons
2010-03-18 22:52 261,632 a——- c:\windows\PEV.exe
2010-03-18 22:52 161,792 a——- c:\windows\SWREG.exe
2010-03-18 22:52 98,816 a——- c:\windows\sed.exe
2010-03-18 22:52 77,312 a——- c:\windows\MBR.exe
2010-03-18 22:40 145,952 a——- c:\windows\system32\drivers\tsk5.tmp
2010-03-18 22:04 145,952 a——- c:\windows\system32\drivers\tsk87.tmp
2010-03-18 22:04 36,488 a——- c:\windows\system32\drivers\klmdb.sys
2010-03-17 17:38 –d—– C:\New Folder
2010-03-17 09:08 –d—– c:\docume~1\robert\applic~1\DisplayTune
2010-03-17 09:05 17,136 a——- c:\windows\system32\drivers\PdiPorts.sys
2010-03-17 09:05 62,009 a——- c:\windows\system32\WPFB.DLL
2010-03-17 09:05 17,465 a——- c:\windows\system32\drivers\pivot.sys
2010-03-17 09:05 11,323 a——- c:\windows\system32\drivers\pivotmou.sys
2010-03-17 09:05 2,304 a——- c:\windows\system32\Machnm32.sys
2010-03-17 09:05 –d—– c:\program files\Portrait Displays
2010-03-17 09:04 –d—– c:\program files\common files\Portrait Displays
2010-03-17 09:04 –d—– c:\program files\Acer Display
2010-03-17 01:14 –d—– c:\windows\system32\wbem\Repository
2010-03-17 01:14 –d—– c:\program files\Online Services
2010-03-17 01:12 –d—– c:\program files\NVIDIA Corporation
2010-03-17 01:12 –d—– C:\NVIDIA
2010-03-17 00:33 –d—– c:\program files\NVIDIA Corporation(2)
2010-03-17 00:33 –d—– C:\NVIDIA(2)
2010-03-17 00:29 –d—– c:\program files\Phyxion.net
2010-03-17 00:28 –d—– C:\RECYCLER(2)
2010-03-16 12:15 –d—– c:\program files\Trend Micro
2010-03-16 11:55 –d—– C:\Qoobox(2)
2010-03-16 09:45 –d—– c:\docume~1\robert\applic~1\.BitTornado
2010-03-16 09:45 –d—– c:\program files\BitTornado
2010-03-10 16:21 3,558,912 -c—— c:\windows\system32\dllcache\moviemk.exe
2010-03-09 18:45 –ds—- c:\documents and settings\robert\UserData
2010-03-08 14:11 –d—– c:\docume~1\robert\applic~1\Malwarebytes
2010-03-08 14:11 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-08 14:11 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-03-08 14:11 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-03-08 14:11 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-03-06 00:15 552 a——- c:\windows\system32\d3d8caps.dat
2010-03-03 21:52 181,632 ——– c:\windows\system32\MpSigStub.exe
2010-03-03 18:52 664 a——- c:\windows\system32\d3d9caps.dat
2010-03-02 08:53 1,089,593 -c—— c:\windows\system32\dllcache\ntprint.cat
2010-03-01 18:40 268 a——- c:\windows\wininit.ini
2010-03-01 17:13 –d—– c:\program files\Spybot - Search & Destroy
2010-03-01 17:13 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-03-01 12:29 –d—– c:\windows\system32\XPSViewer
2010-03-01 12:29 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll
2010-03-01 12:29 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2010-03-01 12:29 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll
2010-03-01 12:29 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll
2010-03-01 12:29 –d—– C:\f45cf379c667103524b169839e
2010-03-01 12:29 1,676,288 ——– c:\windows\system32\xpssvcs.dll
2010-03-01 12:29 575,488 ——– c:\windows\system32\xpsshhdr.dll
2010-03-01 12:29 117,760 ——– c:\windows\system32\prntvpt.dll
2010-02-27 14:08 –d—– c:\docume~1\alluse~1\applic~1\BioWare
2010-02-27 13:17 –d—– c:\program files\Dragon Age
2010-02-27 13:15 –d—– c:\program files\common files\BioWare

==================== Find3M ====================

2010-01-12 12:03 11,632,640 a——- c:\windows\system32\nvcompiler.dll
2010-01-12 12:03 61,440 a——- c:\windows\system32\OpenCL.dll
2010-01-11 23:03 6,359,168 a——- c:\windows\system32\nv4_disp(2).dll
2010-01-09 13:09 86,327 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2010-01-08 22:17 444,952 a——- c:\windows\system32\wrap_oal.dll
2010-01-08 22:17 109,080 a——- c:\windows\system32\OpenAL32.dll
2010-01-08 21:27 21,640 a——- c:\windows\system32\emptyregdb.dat

============= FINISH: 15:15:34.81 ===============
kaxfenix,

Good job! Your logs look clean. Let's remove that infected driver once and for all, then take care of some important cleanup work that will take care of the rest of those Kaspersky detections:

🖼Click to load external image (Posted Image) Please download OTM
  • Save it to your desktop.
  • Please double-click OTM to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Files
    c:\WINDOWS\system32\drivers\nvgts.old
    c:\nvgts.sys
    c:\windows\system32\drivers\tsk5.tmp
    c:\windows\system32\drivers\tsk87.tmp
    c:\windows\system32\drivers\klmdb.sys
    :Commands
    [emptytemp]
  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
🖼Click to load external image (Posted Image) Uninstall ComboFix
  • Press the Windows key + R on your keyboard or click Start -> Run. Copy and past the following text into the run box that opens:
    Combofix /Uninstall
🖼Click to load external image (Posted Image)

🖼Click to load external image (Posted Image) Cleanup with OTM
  • Double-click OTM.exe to start the program.
  • Close all other programs apart from OTM as this step will require a reboot
  • On the OTM main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.
  • Manually delete any remaining tools or logs from our work
🖼Click to load external image (Posted Image) Finally, I'd like to make a couple of suggestions to help you stay clean in the future:
  • Restart any anti-malware programs that we disabled while we were cleaning your machine.
  • Keep your antivirus application current and updated. Also, hang on to MBAM. Scan with them at least weekly.
  • Avoid using P2P programs! Refer back to my earlier post for more information.
  • Consider running in a limited user account. See this post for more information.
  • Please carefully review the information in our Security - Best Practices and Prevention forum located HERE
Please post once more with your OTM results so I know you are all set and I can close this thread. Good luck and stay safe!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI