This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Malware/Virus Disable all AV and Spyware Tools

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I have some really nasty malware/virus on my home PC. I am unable to run my AV software, Spybot, MalwareBytes, etc. I can't even browse the internet on that PC because the browser closes about a minute after loading a page.

I am only able to run a small amount of diagnostic .exe files from a thumb drive. HijackThis runs, but won't save a log anywhere. DDS wont run at all. I was able to get GMER to run and I have posted the log text below.

PLEASE HELP!!!

Thanks

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-18 17:19:40
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Jeff\LOCALS~1\Temp\awtyykow.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\drivers\RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.) ZwCreateKey [0xB50238D0]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcess [0xF5305794]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcessEx [0xF5305F1E]
SSDT \SystemRoot\System32\drivers\RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.) ZwDebugActiveProcess [0xB5023272]
SSDT \SystemRoot\System32\drivers\RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.) ZwOpenKey [0xB5023A1A]
SSDT \SystemRoot\System32\drivers\RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.) ZwOpenProcess [0xB5023284]
SSDT \SystemRoot\System32\drivers\RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.) ZwTerminateProcess [0xB5023114]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwWriteVirtualMemory [0xF5304384]

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.)
—- Processes - GMER 1.0.15 —-

Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\Program Files\MioNet\jvm\bin\MioNet.exe [396] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [572] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [632] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\Program Files\ISS\Proventia Desktop\blackd.exe [680] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\Program Files\Bonjour\mDNSResponder.exe [776] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1332] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [1380] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\Program Files\Java\jre6\bin\jqs.exe [1428] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1448] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1612] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\lxdicoms.exe [1632] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\spoolsv.exe [1876] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\Program Files\MioNet\MioNetManager.exe [1972] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\PROGRA~1\AVG\AVG8\avgemc.exe [2376] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [2724] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\WINDOWS\System32\alg.exe [2832] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\Program Files\MSN\Toolbar\3.0.1125.0\msntask.exe [3052] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe [3464] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe [3568] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\Program Files\iTunes\iTunesHelper.exe [3928] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\Program Files\Java\jre6\bin\jucheck.exe [4220] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\Program Files\Windows Live\Messenger\msnmsgr.exe [4604] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\Program Files\ATI Technologies\ATI.ACE\cli.exe [4836] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\Documents and Settings\Jeff\Application Data\Smilebox\SmileboxTray.exe [4864] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [5444] 0x35670000
Library \\?\globalroot\Device\__max++>\66E59CE6.x86.dll (*** hidden *** ) @ C:\Program Files\Windows Live\Toolbar\wltuser.exe [5716] 0x35670000

—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 sector 01: copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR

—- EOF - GMER 1.0.15 —-
Hello ZeroMovement and welcome to WhatTheTech. I’ll be happy to look over your log and help you with your issues. It will be very helpful if you follow these guidelines:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please follow my instructions carefully and in the order they are posted.
  • Any underlined text in my posts indicates a clickable link.
  • You should print any instructions I give you for ease of use and reference.
  • If you have any questions at all, please stop and ask before proceeding.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.This may cause a delay, but I will do my best to keep it as short as possible.

I will post back as soon as possible with instructions.
ZeroMovement,

You have a newer infection that can be rather complex to clean up. You should backup any important data before proceeding.

🖼Click to load external image (Posted Image) Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your USB drive and transfer it to the desktop of the infected PC

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please include the following in your next post:
  • ComboFix log
Here is the log file that combofix produced…. ComboFix 10-03-18.02 - Jeff 03/19/2010 10:13:15.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.506 [GMT -5:00] Running from: h:\spyware removal\ComboFix.exe AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E} FW: Proventia Desktop *enabled* {D6F73212-FB77-4C57-A4EA-F0DF4A3A0A3B} * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat c:\documents and settings\All Users\Desktop\AntiMalware Support.lnk c:\documents and settings\All Users\Desktop\AntiMalware.lnk c:\documents and settings\All Users\Start Menu\Programs\AntiMalware c:\documents and settings\All Users\Start Menu\Programs\AntiMalware\AntiMalware Support.lnk c:\documents and settings\All Users\Start Menu\Programs\AntiMalware\AntiMalware.lnk c:\documents and settings\All Users\Start Menu\Programs\AntiMalware\Uninstall AntiMalware.lnk c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk c:\program files\AntiMalware c:\program files\AntiMalware\amext.dll c:\program files\AntiMalware\antimalware.exe c:\program files\AntiMalware\help.ico c:\program files\AntiMalware\malw.db c:\program files\AntiMalware\uninstall.exe c:\windows\system32\bimadela.dll c:\windows\system32\bimuvoku.dll c:\windows\system32\drivers\ndisrd.sys c:\windows\system32\hapeweze.dll c:\windows\system32\jofamoja.dll c:\windows\system32\ndisapi.dll c:\windows\system32\pinofivu.dll c:\windows\system32\wilubore.dll c:\windows\system32\wininit.dll c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job c:\windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job c:\windows\Tasks\otlitnjd.job —– BITS: Possible infected sites —– hxxp://77.74.48.111 Infected copy of c:\windows\system32\eventlog.dll was found and disinfected Restored copy from - c:\windows\ServicePackFiles\i386\eventlog.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . ——-\Legacy_NDISRD ——-\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED} ——-\Service_NDISRD ((((((((((((((((((((((((( Files Created from 2010-02-19 to 2010-03-19 ))))))))))))))))))))))))))))))) . 2010-03-19 15:11 . 2010-03-19 15:11 ——– dc—-w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google 2010-03-18 20:42 . 2010-03-18 20:42 ——– dc—-w- c:\program files\MBytesAM 2010-03-17 16:49 . 2008-04-14 00:11 21504 -c–a-w- c:\windows\system32\hidserv.dll 2010-03-17 16:49 . 2008-04-14 00:11 21504 -c–a-w- c:\windows\system32\dllcache\hidserv.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-03-19 15:29 . 2008-10-09 04:53 ——– dc–a-w- c:\documents and settings\All Users\Application Data\TEMP 2010-03-19 15:08 . 2006-11-30 03:19 ——– dc—-w- c:\program files\Google 2010-03-18 23:03 . 2007-01-16 06:03 664 -c–a-w- c:\windows\system32\d3d9caps.dat 2010-03-18 22:32 . 2009-11-09 21:13 0 -c–a-r- c:\windows\win32k.sys 2010-03-18 20:04 . 2008-10-11 19:33 ——– dc—-w- c:\program files\Malwarebytes' Anti-Malware 2010-03-18 19:46 . 2008-10-12 14:38 ——– dc—-w- c:\program files\trend micro 2010-03-18 16:54 . 2008-07-16 02:00 ——– dc—-w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2010-03-18 16:53 . 2009-11-13 03:09 ——– dc—-w- c:\documents and settings\All Users\Application Data\NortonInstaller 2010-03-17 19:30 . 2009-09-25 16:39 ——– dc—-w- c:\program files\Microsoft Silverlight 2010-03-17 18:56 . 2008-07-16 02:00 ——– dc—-w- c:\program files\Spybot - Search & Destroy 2010-01-07 21:07 . 2008-10-11 19:33 38224 -c–a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-07 21:07 . 2008-10-11 19:33 19160 -c–a-w- c:\windows\system32\drivers\mbam.sys 1601-01-01 00:00 . 1601-01-01 00:00 60928 -csha-w- c:\windows\system32\pupumoro.dll 1601-01-01 00:03 . 1601-01-01 00:03 60928 -csha-w- c:\windows\system32\tiviruti.dll 1601-01-01 00:03 . 1601-01-01 00:03 70144 -csha-w- c:\windows\system32\vepineto.dll 1601-01-01 00:03 . 1601-01-01 00:03 96768 -csha-w- c:\windows\system32\zuyuyubu.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{27c69d06-a988-445a-b003-208b77ce2198}] 1601-01-01 00:00 60928 -csha-w- c:\windows\system32\pupumoro.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480] "DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2006-08-29 395776] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-27 68856] "MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856] "SmileboxTray"="c:\documents and settings\Jeff\Application Data\Smilebox\SmileboxTray.exe" [2008-05-19 201352] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-09 761947] "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-09-13 1384448] "SigmatelSysTrayApp"="stsystra.exe" [2006-03-25 282624] "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056] "Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-08-04 1032192] "dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035] "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920] "PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-05-02 184320] "PhiBtn"="c:\windows\System32\drivers\PhiBtn.exe" [2005-08-26 155648] "Traymin900"="c:\windows\System32\drivers\Tray900.exe" [2005-08-26 266240] "YBrowser"="c:\progra~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 129536] "lxdimon.exe"="c:\program files\Lexmark 3500-4500 Series\lxdimon.exe" [2007-07-16 434864] "lxdiamon"="c:\program files\Lexmark 3500-4500 Series\lxdiamon.exe" [2007-07-16 25264] "FaxCenterServer"="c:\program files\\Lexmark Fax Solutions\fm3032.exe" [2007-07-16 311984] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-02 149280] "ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-10-21 1168264] "EverioService"="c:\program files\CyberLink\PCM4Everio\EverioService.exe" [2007-11-01 151552] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440] "AT&T Communication Manager"="c:\program files\AT&T\Communication Manager\ATTCM.exe" [2007-04-06 22528] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440] "Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696] Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-11-29 24576] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-01-31 21:30 10520 -c–a-w- c:\windows\system32\avgrsstx.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice] @="" [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UpdatesDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"= "c:\\Program Files\\LimeWire\\LimeWire.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"= "c:\\WINDOWS\\system32\\lxdicoms.exe"= "c:\\Program Files\\Lexmark 3500-4500 Series\\lxdiamon.exe"= "c:\\Program Files\\Lexmark 3500-4500 Series\\App4R.exe"= "c:\\Program Files\\Abbyy FineReader 6.0 Sprint\\Scan\\ScanMan6.exe"= "c:\\Program Files\\Lexmark Fax Solutions\\FaxCtr.exe"= "c:\\Program Files\\Lexmark 3500-4500 Series\\lxdimon.exe"= "c:\\WINDOWS\\system32\\lxdicfg.exe"= "c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdipswx.exe"= "c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxditime.exe"= "c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdijswx.exe"= "c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdiwbgw.exe"= "c:\\Program Files\\AVG\\AVG8\\avgemc.exe"= "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\WINDOWS\\explorer.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "1700:TCP"= 1700:TCP:MioNet Remote Drive Access "1641:TCP"= 1641:TCP:MioNet Remote Drive Verification R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [11/12/2009 9:04 PM 28552] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/8/2008 2:23 AM 325128] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [10/8/2008 2:23 AM 107272] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [10/8/2008 2:23 AM 875288] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [10/8/2008 2:23 AM 231704] R2 BlackICE;BlackICE;c:\program files\ISS\Proventia Desktop\blackd.exe [8/7/2007 11:44 PM 2007382] R3 MakoNT;MakoNT;c:\windows\system32\drivers\MakoNT.sys [8/7/2007 11:44 PM 76849] R3 rap;rap;c:\windows\system32\drivers\RapDrv.sys [8/7/2007 11:44 PM 47697] R4 black;black;c:\windows\system32\drivers\Blackcat.sys [8/7/2007 11:44 PM 196978] S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [3/19/2010 10:08 AM 135664] S3 camvid40;Philips SPC 900NC PC Camera;c:\windows\system32\drivers\camdrv41.sys [6/13/2007 11:53 PM 1240576] S3 SWNC8U12;Sierra Wireless MUX NDIS Driver (UMTS12);c:\windows\system32\drivers\swnc8u12.sys [3/26/2007 2:21 PM 82432] S3 swumx12;Sierra Wireless USB MUX Driver (UMTS12);c:\windows\system32\drivers\swumx12.sys [3/26/2007 2:21 PM 66304] . Contents of the 'Scheduled Tasks' folder 2009-06-17 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34] 2010-03-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-03-19 15:08] 2010-03-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-03-19 15:08] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.yahoo.com/ uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=5061129 uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 IE: Send to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm LSP: bmnet.dll DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab . - - - - ORPHANS REMOVED - - - - WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file) HKLM-Run-vuvufawob - c:\windows\system32\jofamoja.dll HKLM-Run-kagamiviro - bimuvoku.dll SharedTaskScheduler-{c9d95284-325e-4c0a-91fc-4e37c93336b2} - c:\windows\system32\jofamoja.dll SSODL-hezobikaj-{c9d95284-325e-4c0a-91fc-4e37c93336b2} - c:\windows\system32\jofamoja.dll AddRemove-HijackThis - c:\program files\trend micro\HijackThis.exe ************************************************************************** disk not found C:\ please note that you need administrator rights to perform deep scan scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'winlogon.exe'(916) c:\windows\system32\Ati2evxx.dll - - - - - - - > 'lsass.exe'(972) c:\windows\system32\bmnet.dll - - - - - - - > 'explorer.exe'(3804) c:\windows\system32\WININET.dll c:\windows\system32\pupumoro.dll c:\windows\system32\ieframe.dll . ———————— Other Running Processes ———————— . c:\windows\system32\Ati2evxx.exe c:\windows\System32\WLTRYSVC.EXE c:\windows\System32\bcmwltry.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\windows\system32\bmwebcfg.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\System32\spool\DRIVERS\W32X86\3\lxdiserv.exe c:\windows\system32\lxdicoms.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\program files\MioNet\MioNetManager.exe c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe c:\program files\ISS\Proventia Desktop\RapApp.exe c:\program files\CyberLink\Shared Files\RichVideo.exe c:\program files\Spyware Doctor\pctsAuxs.exe c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\program files\MioNet\jvm\bin\MioNet.exe c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe c:\windows\system32\wdfmgr.exe c:\program files\ISS\Proventia Desktop\vpatch.exe c:\windows\system32\MsPMSPSv.exe c:\windows\system32\wbem\wmiapsrv.exe c:\windows\system32\Ati2evxx.exe c:\windows\stsystra.exe c:\progra~1\Yahoo!\browser\ycommon.exe c:\program files\ISS\Proventia Desktop\blackice.exe c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe c:\program files\iPod\bin\iPodService.exe c:\program files\Java\jre6\bin\jucheck.exe . ************************************************************************** . Completion time: 2010-03-19 10:45:39 - machine was rebooted ComboFix-quarantined-files.txt 2010-03-19 15:45 ComboFix2.txt 2008-10-13 01:59 Pre-Run: 47,116,730,368 bytes free Post-Run: 47,613,534,208 bytes free - - End Of File - - 13B19B0C2DFB82FC177ED8AAC37FFB5F
ZeroMovement,

ComboFix needs to be run from the desktop of the infected machine. It looks like you ran it directly from your flash drive. Please move ComboFix to the desktop of the infected machine before continuing with these instructions:

🖼Click to load external image (Posted Image) Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad ) and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above http://

http://forums.whatthetech.com/Malware_Virus_Disable_all_AV_Spyware_Tools_t111058.html&p=642141#entry642141

Collect::
c:\windows\system32\pupumoro.dll
c:\windows\system32\tiviruti.dll
c:\windows\system32\vepineto.dll
c:\windows\system32\zuyuyubu.dll

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{27c69d06-a988-445a-b003-208b77ce2198}]

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.

🖼Click to load external image (Posted Image) Run maaxlook using these instructions:

You must first verify that you can log on to the Windows Recovery Console. ComboFix should have installed it for you.
To do so, you must have the Recovery Console installed or use the Windows XP installation cd.

How to install and use the Windows XP Recovery Console


Next, please download maxlook, saving the file to your desktop.
Double click maxlook.exe to run it. Note - you must run it only once!
As instructed when the tool runs, restart the computer and logon to the Recovery Console.
Execute the following bolded command at the x:\windows> prompt <— the red x represents your operating system drive letter, usually C

batch look.bat


🖼Click to load external image (Posted Image)

You will see 1 file copied many times then return to the x:\windows> prompt.
Type Exit to restart your computer then logon in normal mode.
Please run maxlook.exe again now. Note - you must run it only once!
It will produce looklog.txt on the desktop and open it.
Please post the results here.

Please include the following in your next post:
  • ComboFix log
  • maxlook log
Ok….. I was able to complete the first part of running combofix with the script you provided and the log text produced is below. As far as the second part of running maaxlook, I started the process, but when I restarted and selected "Microsoft Windows Recovery Console" upon startup…….the next screen displayed just has the following text. NTLDR is compressed; Press Ctrl+Alt+Del to restart. It's not loading the cmd window to complete the other steps. The infected PC is a Dell, and it came with a Dell specific Windows XP Professional w/ SP 1 disk. I tried doing following the instructions listed here http://www.bleepingcomputer.com/tutorials/tutorial117.html. When I enter the file path in the run box, I get a Windows Setup msg that says "Setup cannot continue because the version of Windows on your computeris newer than the version on the CD." What are my my next steps?


Combofix Log….

ComboFix 10-03-19.04 - Jeff 03/19/2010 17:35:38.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.302 [GMT -5:00]
Running from: h:\spyware removal\ComboFix.exe
Command switches used :: h:\spyware removal\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
FW: Proventia Desktop *enabled* {D6F73212-FB77-4C57-A4EA-F0DF4A3A0A3B}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\buvoyaki.dll
c:\windows\system32\gifuyovi.dll
c:\windows\system32\pupumoro.dll
c:\windows\system32\tiviruti.dll
c:\windows\system32\vepineto.dll
c:\windows\system32\zuyuyubu.dll
c:\windows\Tasks\ztcxujzw.job

.
((((((((((((((((((((((((( Files Created from 2010-02-19 to 2010-03-19 )))))))))))))))))))))))))))))))
.

2010-03-19 16:13 . 2010-03-19 16:18 ——– dc—-w- c:\documents and settings\Jeff\Local Settings\Application Data\Temp
2010-03-19 15:11 . 2010-03-19 15:11 ——– dc—-w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-03-18 20:42 . 2010-03-18 20:42 ——– dc—-w- c:\program files\MBytesAM
2010-03-17 16:49 . 2008-04-14 00:11 21504 -c–a-w- c:\windows\system32\hidserv.dll
2010-03-17 16:49 . 2008-04-14 00:11 21504 -c–a-w- c:\windows\system32\dllcache\hidserv.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-19 22:47 . 2008-10-09 04:53 ——– dc–a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-03-19 15:08 . 2006-11-30 03:19 ——– dc—-w- c:\program files\Google
2010-03-18 23:03 . 2007-01-16 06:03 664 -c–a-w- c:\windows\system32\d3d9caps.dat
2010-03-18 22:32 . 2009-11-09 21:13 0 -c–a-r- c:\windows\win32k.sys
2010-03-18 20:04 . 2008-10-11 19:33 ——– dc—-w- c:\program files\Malwarebytes' Anti-Malware
2010-03-18 19:46 . 2008-10-12 14:38 ——– dc—-w- c:\program files\trend micro
2010-03-18 16:54 . 2008-07-16 02:00 ——– dc—-w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-03-18 16:53 . 2009-11-13 03:09 ——– dc—-w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-03-17 19:30 . 2009-09-25 16:39 ——– dc—-w- c:\program files\Microsoft Silverlight
2010-03-17 18:56 . 2008-07-16 02:00 ——– dc—-w- c:\program files\Spybot - Search & Destroy
2010-01-07 21:07 . 2008-10-11 19:33 38224 -c–a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2008-10-11 19:33 19160 -c–a-w- c:\windows\system32\drivers\mbam.sys
2010-01-05 10:00 . 2004-08-11 23:00 832512 -c–a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2004-08-11 23:00 78336 -c–a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2004-08-11 23:00 17408 -c–a-w- c:\windows\system32\corpol.dll
1601-01-01 00:03 . 1601-01-01 00:03 70144 -csha-w- c:\windows\system32\radayogu.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2006-08-29 395776]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-27 68856]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"SmileboxTray"="c:\documents and settings\Jeff\Application Data\Smilebox\SmileboxTray.exe" [2008-05-19 201352]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-09 761947]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-09-13 1384448]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-25 282624]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-08-04 1032192]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-05-02 184320]
"PhiBtn"="c:\windows\System32\drivers\PhiBtn.exe" [2005-08-26 155648]
"Traymin900"="c:\windows\System32\drivers\Tray900.exe" [2005-08-26 266240]
"YBrowser"="c:\progra~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 129536]
"lxdimon.exe"="c:\program files\Lexmark 3500-4500 Series\lxdimon.exe" [2007-07-16 434864]
"lxdiamon"="c:\program files\Lexmark 3500-4500 Series\lxdiamon.exe" [2007-07-16 25264]
"FaxCenterServer"="c:\program files\\Lexmark Fax Solutions\fm3032.exe" [2007-07-16 311984]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-02 149280]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-10-21 1168264]
"EverioService"="c:\program files\CyberLink\PCM4Everio\EverioService.exe" [2007-11-01 151552]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"AT&T Communication Manager"="c:\program files\AT&T\Communication Manager\ATTCM.exe" [2007-04-06 22528]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"vuvufawob"="c:\windows\system32\gifuyovi.dll" [BU]
"kagamiviro"="bimuvoku.dll" [BU]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-11-29 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-31 21:30 10520 -c–a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\WINDOWS\\system32\\lxdicoms.exe"=
"c:\\Program Files\\Lexmark 3500-4500 Series\\lxdiamon.exe"=
"c:\\Program Files\\Lexmark 3500-4500 Series\\App4R.exe"=
"c:\\Program Files\\Abbyy FineReader 6.0 Sprint\\Scan\\ScanMan6.exe"=
"c:\\Program Files\\Lexmark Fax Solutions\\FaxCtr.exe"=
"c:\\Program Files\\Lexmark 3500-4500 Series\\lxdimon.exe"=
"c:\\WINDOWS\\system32\\lxdicfg.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdipswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxditime.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdijswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdiwbgw.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\ISS\\Proventia Desktop\\blackice.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1700:TCP"= 1700:TCP:MioNet Remote Drive Access
"1641:TCP"= 1641:TCP:MioNet Remote Drive Verification

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [11/12/2009 9:04 PM 28552]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/8/2008 2:23 AM 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [10/8/2008 2:23 AM 107272]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [10/8/2008 2:23 AM 875288]
R2 BlackICE;BlackICE;c:\program files\ISS\Proventia Desktop\blackd.exe [8/7/2007 11:44 PM 2007382]
R2 lxdi_device;lxdi_device;c:\windows\system32\lxdicoms.exe -service –> c:\windows\system32\lxdicoms.exe -service [?]
R2 lxdiCATSCustConnectService;lxdiCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdiserv.exe [1/31/2008 9:44 PM 99248]
R2 MioNet;MioNet Service;c:\program files\MioNet\MioNetManager.exe [7/15/2005 3:38 PM 139264]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [10/8/2008 11:53 PM 356920]
R2 VPatch;ISS Buffer Overflow Exploit Prevention;c:\program files\ISS\Proventia Desktop\vpatch.exe [8/7/2007 11:44 PM 426333]
R3 MakoNT;MakoNT;c:\windows\system32\drivers\MakoNT.sys [8/7/2007 11:44 PM 76849]
R3 rap;rap;c:\windows\system32\drivers\RapDrv.sys [8/7/2007 11:44 PM 47697]
R4 black;black;c:\windows\system32\drivers\Blackcat.sys [8/7/2007 11:44 PM 196978]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [10/8/2008 2:23 AM 231704]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [3/19/2010 10:08 AM 135664]
S3 camvid40;Philips SPC 900NC PC Camera;c:\windows\system32\drivers\camdrv41.sys [6/13/2007 11:53 PM 1240576]
S3 SWNC8U12;Sierra Wireless MUX NDIS Driver (UMTS12);c:\windows\system32\drivers\swnc8u12.sys [3/26/2007 2:21 PM 82432]
S3 swumx12;Sierra Wireless USB MUX Driver (UMTS12);c:\windows\system32\drivers\swumx12.sys [3/26/2007 2:21 PM 66304]
.
Contents of the 'Scheduled Tasks' folder

2009-06-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-03-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-19 15:08]

2010-03-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-19 15:08]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=5061129
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Send to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
LSP: bmnet.dll
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
.
- - - - ORPHANS REMOVED - - - -

BHO-{27c69d06-a988-445a-b003-208b77ce2198} - (no file)
SharedTaskScheduler-{888c8aad-fbba-4093-9fc8-ab41cf64fa2d} - c:\windows\system32\gifuyovi.dll
SSODL-vuhowikek-{888c8aad-fbba-4093-9fc8-ab41cf64fa2d} - c:\windows\system32\gifuyovi.dll



**************************************************************************

disk not found C:\

please note that you need administrator rights to perform deep scan
scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(920)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(976)
c:\windows\system32\bmnet.dll

- - - - - - - > 'explorer.exe'(4288)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\bmwebcfg.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\lxdicoms.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
c:\program files\ISS\Proventia Desktop\RapApp.exe
c:\program files\MioNet\jvm\bin\MioNet.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\MsPMSPSv.exe
c:\windows\stsystra.exe
c:\progra~1\Yahoo!\browser\ycommon.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\program files\ISS\Proventia Desktop\blackice.exe
c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Java\jre6\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2010-03-19 17:59:43 - machine was rebooted
ComboFix-quarantined-files.txt 2010-03-19 22:59
ComboFix2.txt 2010-03-19 15:45
ComboFix3.txt 2008-10-13 01:59

Pre-Run: 47,351,930,880 bytes free
Post-Run: 47,522,385,920 bytes free

- - End Of File - - AB9FB716C1C286AC58D14D0E51F0D96C
ZeroMovement,

🖼Click to load external image (Posted Image) Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad ) and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above http://

http://forums.whatthetech.com/Malware_Virus_Disable_all_AV_Spyware_Tools_t111058.html&p=642141#entry642141

Collect::
c:\windows\system32\radayogu.dll

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vuvufawob"=-
"kagamiviro"=-
Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.

🖼Click to load external image (Posted Image) Click Start > Run or Press the Windows Key + R. copy and paste the following text into the run box that opens and press OK:
C:\Qoobox\Add-Remove Programs.txt

Post the contents of the text file that opens in your next reply.

🖼Click to load external image (Posted Image) Please run GMER again and post the report.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Please include the following in your next post:
  • ComboFix log
  • Add/Remove Programs log
  • GMER log
Here are the requested logs…….

ComboFix Log Text:

ComboFix 10-03-21.02 - Jeff 03/21/2010 23:36:51.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.323 [GMT -5:00]
Running from: h:\spyware removal\ComboFix.exe
Command switches used :: h:\spyware removal\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
FW: Proventia Desktop *enabled* {D6F73212-FB77-4C57-A4EA-F0DF4A3A0A3B}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\look.bat
c:\windows\system32\radayogu.dll

.
((((((((((((((((((((((((( Files Created from 2010-02-22 to 2010-03-22 )))))))))))))))))))))))))))))))
.

2010-03-22 04:24 . 2010-03-22 04:27 ——– dc—-w- c:\windows\LastGood
2010-03-19 23:01 . 2010-03-19 23:01 ——– dc—-w- c:\windows\maxdriver
2010-03-19 16:13 . 2010-03-19 16:18 ——– dc—-w- c:\documents and settings\Jeff\Local Settings\Application Data\Temp
2010-03-19 15:11 . 2010-03-19 15:11 ——– dc—-w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-03-18 20:42 . 2010-03-18 20:42 ——– dc—-w- c:\program files\MBytesAM
2010-03-17 17:21 . 2009-10-23 15:28 3558912 -c—-w- c:\windows\system32\dllcache\moviemk.exe
2010-03-17 16:49 . 2008-04-14 00:11 21504 -c–a-w- c:\windows\system32\hidserv.dll
2010-03-17 16:49 . 2008-04-14 00:11 21504 -c–a-w- c:\windows\system32\dllcache\hidserv.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-22 04:18 . 2008-10-09 04:53 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-03-19 15:08 . 2006-11-30 03:19 ——– dc—-w- c:\program files\Google
2010-03-18 23:03 . 2007-01-16 06:03 664 -c–a-w- c:\windows\system32\d3d9caps.dat
2010-03-18 22:32 . 2009-11-09 21:13 0 -c–a-r- c:\windows\win32k.sys
2010-03-18 20:04 . 2008-10-11 19:33 ——– dc—-w- c:\program files\Malwarebytes' Anti-Malware
2010-03-18 19:46 . 2008-10-12 14:38 ——– dc—-w- c:\program files\trend micro
2010-03-18 16:54 . 2008-07-16 02:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-03-18 16:53 . 2009-11-13 03:09 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2010-03-17 19:30 . 2009-09-25 16:39 ——– dc—-w- c:\program files\Microsoft Silverlight
2010-03-17 18:56 . 2008-07-16 02:00 ——– dc—-w- c:\program files\Spybot - Search & Destroy
2010-01-07 21:07 . 2008-10-11 19:33 38224 -c–a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2008-10-11 19:33 19160 -c–a-w- c:\windows\system32\drivers\mbam.sys
2010-01-05 10:00 . 2004-08-11 23:00 832512 -c—-w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2004-08-11 23:00 78336 -c–a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2004-08-11 23:00 17408 -c–a-w- c:\windows\system32\corpol.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2006-08-29 395776]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-27 68856]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"SmileboxTray"="c:\documents and settings\Jeff\Application Data\Smilebox\SmileboxTray.exe" [2008-05-19 201352]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-09 761947]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-09-13 1384448]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-25 282624]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2006-08-04 1032192]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-05-02 184320]
"PhiBtn"="c:\windows\System32\drivers\PhiBtn.exe" [2005-08-26 155648]
"Traymin900"="c:\windows\System32\drivers\Tray900.exe" [2005-08-26 266240]
"YBrowser"="c:\progra~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 129536]
"lxdimon.exe"="c:\program files\Lexmark 3500-4500 Series\lxdimon.exe" [2007-07-16 434864]
"lxdiamon"="c:\program files\Lexmark 3500-4500 Series\lxdiamon.exe" [2007-07-16 25264]
"FaxCenterServer"="c:\program files\\Lexmark Fax Solutions\fm3032.exe" [2007-07-16 311984]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-02 149280]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-10-21 1168264]
"EverioService"="c:\program files\CyberLink\PCM4Everio\EverioService.exe" [2007-11-01 151552]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"AT&T Communication Manager"="c:\program files\AT&T\Communication Manager\ATTCM.exe" [2007-04-06 22528]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-11-29 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-31 21:30 10520 -c–a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\WINDOWS\\system32\\lxdicoms.exe"=
"c:\\Program Files\\Lexmark 3500-4500 Series\\lxdiamon.exe"=
"c:\\Program Files\\Lexmark 3500-4500 Series\\App4R.exe"=
"c:\\Program Files\\Abbyy FineReader 6.0 Sprint\\Scan\\ScanMan6.exe"=
"c:\\Program Files\\Lexmark Fax Solutions\\FaxCtr.exe"=
"c:\\Program Files\\Lexmark 3500-4500 Series\\lxdimon.exe"=
"c:\\WINDOWS\\system32\\lxdicfg.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdipswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxditime.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdijswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdiwbgw.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\ISS\\Proventia Desktop\\blackice.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1700:TCP"= 1700:TCP:MioNet Remote Drive Access
"1641:TCP"= 1641:TCP:MioNet Remote Drive Verification

R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [11/12/2009 9:04 PM 28552]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/8/2008 2:23 AM 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [10/8/2008 2:23 AM 107272]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [10/8/2008 2:23 AM 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [10/8/2008 2:23 AM 231704]
R2 BlackICE;BlackICE;c:\program files\ISS\Proventia Desktop\blackd.exe [8/7/2007 11:44 PM 2007382]
R2 lxdi_device;lxdi_device;c:\windows\system32\lxdicoms.exe -service –> c:\windows\system32\lxdicoms.exe -service [?]
R2 lxdiCATSCustConnectService;lxdiCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdiserv.exe [1/31/2008 9:44 PM 99248]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [10/8/2008 11:53 PM 356920]
R2 VPatch;ISS Buffer Overflow Exploit Prevention;c:\program files\ISS\Proventia Desktop\vpatch.exe [8/7/2007 11:44 PM 426333]
R3 MakoNT;MakoNT;c:\windows\system32\drivers\MakoNT.sys [8/7/2007 11:44 PM 76849]
R3 rap;rap;c:\windows\system32\drivers\RapDrv.sys [8/7/2007 11:44 PM 47697]
R4 black;black;c:\windows\system32\drivers\Blackcat.sys [8/7/2007 11:44 PM 196978]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [3/19/2010 10:08 AM 135664]
S2 MioNet;MioNet Service;c:\program files\MioNet\MioNetManager.exe [7/15/2005 3:38 PM 139264]
S3 camvid40;Philips SPC 900NC PC Camera;c:\windows\system32\drivers\camdrv41.sys [6/13/2007 11:53 PM 1240576]
S3 SWNC8U12;Sierra Wireless MUX NDIS Driver (UMTS12);c:\windows\system32\drivers\swnc8u12.sys [3/26/2007 2:21 PM 82432]
S3 swumx12;Sierra Wireless USB MUX Driver (UMTS12);c:\windows\system32\drivers\swumx12.sys [3/26/2007 2:21 PM 66304]
.
Contents of the 'Scheduled Tasks' folder

2009-06-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-03-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-19 15:08]

2010-03-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-19 15:08]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=5061129
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Send to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
LSP: bmnet.dll
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
.
- - - - ORPHANS REMOVED - - - -

BHO-{27c69d06-a988-445a-b003-208b77ce2198} - (no file)



**************************************************************************

disk not found C:\

please note that you need administrator rights to perform deep scan
scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files:

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(920)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(976)
c:\windows\system32\bmnet.dll
.
Completion time: 2010-03-21 23:46:05
ComboFix-quarantined-files.txt 2010-03-22 04:46
ComboFix2.txt 2010-03-19 22:59
ComboFix3.txt 2010-03-19 15:45
ComboFix4.txt 2008-10-13 01:59

Pre-Run: 46,600,867,840 bytes free
Post-Run: 46,540,546,048 bytes free

- - End Of File - - 180112734139923E568631E538A1A5DD



Add/Remove Programs Log Text:

ABBYY FineReader 6.0 Sprint
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 7.0.8
AIM 6
Apple Application Support
Apple Mobile Device Support
Apple Software Update
AT&T Communication Manager
AT&T Yahoo! Applications
ATI Catalyst Control Center
ATI Display Driver
AVG Free 8.0
Bonjour
Broadcom Management Programs
Conexant HDA D110 MDC V.92 Modem
Dell Support 3.2.1
Dell System Restore
Dell Wireless WLAN Card
Digital Content Portal
Digital Line Detect
Digital Photo Navigator 1.5
Documentation & Support Launcher
EarthLink Setup Files
EducateU
Games, Music, & Photos Launcher
getPlus® for Adobe
Google Toolbar for Internet Explorer
Google Update Helper
High Definition Audio Driver Package - KB835221
Hotfix 2055 for SQL Server 2000 ENU (KB960082)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format SDK (KB902344)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB979306)
InstallMgr
Internet Service Offers Launcher
iTunes
J2SE Runtime Environment 5.0 Update 6
Java™ 6 Update 15
Java™ 6 Update 7
Junk Mail filter update
Lexmark 3500-4500 Series
Lexmark Fax Solutions
LimeWire 5.2.13
LiveUpdate 2.6 (Symantec Corporation)
Malwarebytes' Anti-Malware
MediaDirect
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Default Manager
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Live Add-in 1.3
Microsoft Office Outlook 2003 with Business Contact Manager Update
Microsoft Office Outlook Connector
Microsoft Office Small Business Edition 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft SQL Server Desktop Engine (MICROSOFTSMLBIZ)
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
MioNet
MobileMe Control Panel
Modem Helper
MSN Toolbar
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NetWaiting
NetZeroInstallers
Nokia Connectivity Adapter Cable DKU-5
OpenOffice.org Installer 1.0
OutlookAddinSetup
Panda ActiveScan 2.0
Philips SPC 900NC PC Camera
Philips VLounge
PowerCinema NE for Everio
PowerDirector Express
Punch! Super Home Suite
QuickSet
QuickTime
Safari
SearchAssist
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978706)
Segoe UI
SIPPS
Smilebox
Sonic DLA
Sonic MyDVD LE
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Spybot - Search & Destroy
Spyware Doctor 6.0
Symantec KB-DocID:2003093015493306
Synaptics Pointing Device Driver
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
URL Assistant
Viewpoint Media Player
WD Diagnostics
WebFldrs XP
WIDCOMM Bluetooth Software
Windows Genuine Advantage Notifications (KB905474)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Toolbar
Windows Live Upload Tool
Windows Live Writer
Windows Media Format Runtime
Windows Media Player 10
Windows XP Service Pack 3
XP Codec Pack
Yahoo! Toolbar



GMER Log Text:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-22 01:18:36
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Jeff\LOCALS~1\Temp\awtyykow.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\drivers\RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.) ZwCreateKey [0xF63A78D0]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcess [0xF469D794]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcessEx [0xF469DF1E]
SSDT \SystemRoot\System32\drivers\RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.) ZwDebugActiveProcess [0xF63A7272]
SSDT \SystemRoot\System32\drivers\RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.) ZwOpenKey [0xF63A7A1A]
SSDT \SystemRoot\System32\drivers\RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.) ZwOpenProcess [0xF63A7284]
SSDT \SystemRoot\System32\drivers\RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.) ZwTerminateProcess [0xF63A7114]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwWriteVirtualMemory [0xF469C384]

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.)
Device \FileSystem\Fastfat \FatCdrom RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.)
Device \Driver\Tcpip \Device\Ip RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.)

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Ip ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)

Device \Driver\Tcpip \Device\Tcp RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.)

AttachedDevice \Driver\Tcpip \Device\Tcp tcpipBM.SYS (Bytemobile Kernel Network Provider/Bytemobile, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)

Device \Driver\IpFilterDriver \Device\IPFILTERDRIVER BlackCat.sys (Network Packet Driver/Internet Security Systems, Inc.)
Device \Driver\Tcpip \Device\Udp RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.)

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)

Device \Driver\Tcpip \Device\RawIp RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.)

AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp ntkrnlpa.exe (NT Kernel & System/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.)
Device \Driver\Tcpip \Device\IPMULTICAST RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.)
Device \FileSystem\MRxSmb \Device\LanmanRedirector RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.)
Device \FileSystem\Fastfat \Fat RapDrv.sys (Rap Protection System/Internet Security Systems, Inc.)

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

—- EOF - GMER 1.0.15 —-

ZeroMovement,

Your logs are looking better. Please run these two scans for me next:

🖼Click to load external image (Posted Image) You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM
  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

🖼Click to load external image (Posted Image) Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply
Please include the following in your next post:
  • MBAM log
  • Kaspersky log
  • How is the computer running?
Hi,

My PC seems to be running better. Most of the original complaints I had "seem" to have been resolved, but I'll keep with it until you give me the all clear. The one thing that I noticed was that since we started cleaning the infection, my sound doesn't work anymore. Do you know of any malware that would disable audio drivers or anything?

Anywho here are the latest logs…..

MBAM Log Text:

Malwarebytes' Anti-Malware 1.44
Database version: 3901
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11

3/22/2010 4:02:37 PM
mbam-log-2010-03-22 (16-02-37).txt

Scan type: Quick Scan
Objects scanned: 133671
Time elapsed: 10 minute(s), 38 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\olnmraew.blke (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\olnmraew.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\Jeff\Favorites\Malware Defender.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Favorites\Protect Your Privacy.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\Documents and Settings\Jeff\Favorites\System Error Fixer.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\WINDOWS\win32k.sys (Trojan.Dropper) -> Quarantined and deleted successfully.



KasReport Log Text:

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Monday, March 22, 2010
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Monday, March 22, 2010 21:03:51
Records in database: 3848711
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\

Scan statistics:
Objects scanned: 100819
Threats found: 11
Infected objects found: 33
Suspicious objects found: 0
Scan duration: 02:39:41


File name / Threat / Threats count
C:\Documents and Settings\Jeff\Application Data\Sun\Java\Deployment\cache\6.0\60\45bf84fc-18cbb6d7 Infected: Trojan-Downloader.Java.Agent.al 1
C:\Qoobox\Quarantine\C\Program Files\AntiMalware\amext.dll.vir Infected: Packed.Win32.TDSS.aa 1
C:\Qoobox\Quarantine\C\Program Files\AntiMalware\antimalware.exe.vir Infected: Trojan.Win32.FraudPack.zve 1
C:\Qoobox\Quarantine\C\Program Files\AntiMalware\uninstall.exe.vir Infected: Trojan.Win32.Tdss.aula 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\bimadela.dll.vir Infected: Trojan.Win32.Monder.ddmk 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\bimuvoku.dll.vir Infected: Trojan.Win32.Monder.ddoj 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\buvoyaki.dll.vir Infected: Trojan.Win32.Monder.ddma 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\eventlog.dll.vir Infected: Rootkit.Win32.PMax.h 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\gifuyovi.dll.vir Infected: Trojan.Win32.Monder.ddob 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\hapeweze.dll.vir Infected: Trojan.Win32.Monder.ddoj 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\jofamoja.dll.vir Infected: Trojan.Win32.Monder.ddob 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\pinofivu.dll.vir Infected: Trojan.Win32.Monder.ddmk 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\pupumoro.dll.vir Infected: Trojan.Win32.Monder.ddoj 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\radayogu.dll.vir Infected: Trojan.Win32.Monder.ddly 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\tiviruti.dll.vir Infected: Trojan.Win32.Monder.ddoj 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\vepineto.dll.vir Infected: Trojan.Win32.Monder.ddly 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\wilubore.dll.vir Infected: Trojan.Win32.Monder.ddma 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\zuyuyubu.dll.vir Infected: Trojan.Win32.Monder.ddmh 1
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP433\A0171798.dll Infected: Packed.Win32.TDSS.aa 1
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP433\A0171799.exe Infected: Trojan.Win32.FraudPack.zve 1
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP433\A0171801.exe Infected: Trojan.Win32.Tdss.aula 1
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP433\A0171802.dll Infected: Trojan.Win32.Monder.ddmk 1
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP433\A0171803.dll Infected: Trojan.Win32.Monder.ddoj 1
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP433\A0171805.dll Infected: Trojan.Win32.Monder.ddoj 1
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP433\A0171806.dll Infected: Trojan.Win32.Monder.ddob 1
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP433\A0171808.dll Infected: Trojan.Win32.Monder.ddmk 1
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP433\A0171809.dll Infected: Trojan.Win32.Monder.ddma 1
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP433\A0171811.dll Infected: Rootkit.Win32.PMax.h 1
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP435\A0172176.dll Infected: Trojan.Win32.Monder.ddoj 1
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP435\A0172177.dll Infected: Trojan.Win32.Monder.ddoj 1
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP435\A0172178.dll Infected: Trojan.Win32.Monder.ddly 1
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP435\A0172179.dll Infected: Trojan.Win32.Monder.ddmh 1
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP436\A0172676.dll Infected: Trojan.Win32.Monder.ddly 1

Selected area has been scanned.


Please advise of next steps…..Thanks!
Whoops….I may have spoke too soon in my previous post about things running better. I tried to launch Spybot and AVG and neither would load. I tried re-installing Spybot, but upon install I keep getting an error that the spybot.exe file is read-only. Sounds like something is still locking me out of the protection tools, but the parts of the malware that were crippling performance have mostly been removed. The above post has the last logs you requested. Thanks,
ZeroMovement,

Let's see if we can resolve some of these issues:

🖼Click to load external image (Posted Image) First, I have a few questions for you:
  • Are you still using Norton Internet Worm Protection or Proventia Desktop? You have traces of both in your logs, but I don't see them in your add/remove programs list.
  • Are you running as an administrator on the infected PC?
  • At exactly what point did your sound stop working?
🖼Click to load external image (Posted Image) Go to Start > Run and copy/paste the contents of the codebox below into the Run box and click OK:

cmd /c del /a/f/q "C:\Documents and Settings\Jeff\Application Data\Sun\Java\Deployment\cache\6.0\60\45bf84fc-18cbb6d7"
A DOS window will open and close again, this is normal.

🖼Click to load external image (Posted Image) Please save this file to your desktop.
  • Click on Start > Run, and copy-paste the following command (the bolded text) into the open run box, then click OK.

    "%userprofile%\desktop\win32kdiag.exe" -f -r

  • When it's finished, there will be a log called Win32kDiag.txt on your desktop.
  • Please open it with notepad and post the contents here.
🖼Click to load external image (Posted Image) Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filelook
    *ntldr*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Please include the following in your next post:
  • Your responses to my questions
  • win32Diag log
  • SystemLook log
Hi RPMcMurphy,

1. As for the Norton Internet Worm Protection, I'm not actively using it. When the PC originally got infected I tried installing Norton to see if it could find some problems because everything that I already had installed was failing to initialize. I was never able to complete the Norton Install….or so I thought. I didn't even know that pieces of the Norton software were on this PC. Provencia Desktop was installed well before the infection. It's the intrusion software that my company uses so I figured it was good enough for my personal PC. Since we've been working on removing these problems, Provencia has been "sometimey" at best. Sometimes it starts up when I startup the PC and displays that it is running in the system tray……..sometimes it doesn't. Not sure what's going on there. Could portions of it have been removed during the cleaning process……keeping it from showing up in the add/remove programs?

2. Yes I am the administrator on the infected PC

3. The last time I remember having sound was when we were trying to access the Recovery Console. After giving the "NTLDR Compressed" msg, any key that I pressed outside of ctrl-alt-delete to restart windows, made the PC beep. I haven't heard a beep or the sound of Windows starting up though, but I think this may have been an symptom from the infection. I seem to remember noteing that to myself, and thinking that the virus perhaps didn't want me to audibly know at which point it was at in the Windows startup process. For a brief time before I sought your help Windows would restart automatically after about a minute or so after loading. That seemed to resolve itself somehow though before I requested your help.

Win32kDiag.txt:

Running from: C:\Documents and Settings\[removed]\desktop\win32kdiag.exe

Log file at : C:\Documents and Settings\Jeff\Desktop\Win32kDiag.txt

Removing all found mount points.

Attempting to reset file permissions.

WARNING: Could not get backup privileges!

Searching 'C:\WINDOWS'…



Cannot access: C:\WINDOWS\pchealth\helpctr\binaries\helpsvc.exe

Attempting to restore permissions of : C:\WINDOWS\pchealth\helpctr\binaries\helpsvc.exe

Cannot access: C:\WINDOWS\SoftwareDistribution\Download\b7b0631e184025ba37e5a4ec1d8637e7\update\update.exe

Attempting to restore permissions of : C:\WINDOWS\SoftwareDistribution\Download\b7b0631e184025ba37e5a4ec1d8637e7\update\update.exe

Cannot access: C:\WINDOWS\Temp\hsperfdata_SYSTEM\560

Attempting to restore permissions of : C:\WINDOWS\Temp\hsperfdata_SYSTEM\560



Finished!



SystemLook.txt:

SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 22:01 on 23/03/2010 by Jeff (Administrator - Elevation successful)

Invalid Context: filelook

No Context: *ntldr*

-=End Of File=-

ZeroMovement,

🖼Click to load external image (Posted Image) Download Security Check from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
🖼Click to load external image (Posted Image) Your Plug and Play service may be turned off. Please try to Set the "startup type" for Plug and Play to Automatic. To do so, follow these steps:
  • Click Start, click Run, type services.msc and then click OK.
  • Double-click Plug and Play.
    If you receive a Configuration Manager message, click OK.
  • In the "Startup Type" list, click Automatic, and then click OK.
  • Close Services.
  • Restart the computer.
🖼Click to load external image (Posted Image) Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    *ntldr*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

🖼Click to load external image (Posted Image) What other outstanding issues do you have with the computer? Are AVG and Spybot working normally now?

Please include the following in your next post:
  • Security Check log
  • SystemLook log
  • List of outstanding issues/problems

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI