metarra
Topic Starter
Hello. This morning my WindowsUpdate was acting strange and coming up saying I was infected and automatically ran its own scan. I knew something was wrong because I know of fake antivirus programs that are actually malware. I did a scan with Malwarebytes' Anti-Malware and it found several things. I ran it once in safe mode, and removed the infected files it found. I then ran Malwarebytes again after a reboot and it never seems to remove Hijack.WindowsUpdate. Thank you for assisting me.
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 14:38:14.28 on Thu 04/01/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_03
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1376 [GMT -7:00]
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Documents and Settings\Valued Customer\Local Settings\Apps\2.0\584YRAPW.ZYV\GZENAWJ6.Y71\curs..tion_eee711038731a406_0004.0000_152ef8e82e8f5a48\CurseClient.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malware\mbam.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Valued Customer\Desktop\dds.scr
============== Pseudo HJT Report ===============
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
BHO: 1 (0x1) - No File
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
TB: {3041D03E-FD4B-44E0-B742-2D9B88305F98} - No File
uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US ee://aol/imApp
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [zsulfb58q63dyghxwkt2c7fftt] c:\docume~1\valued~1\locals~1\temp\sv5jq5f6n8jd.exe
uRun: [ybg277guru56pam6bcdhvgr4ljcyvpq5bmqzc1pwg] c:\docume~1\valued~1\locals~1\temp\h29uvxm1wce.exe
uRun: [qtuy6dco8utgmsy4ourexo781ys5kpr8o1352cj] c:\docume~1\valued~1\locals~1\temp\fq4pw1lzjr.exe
uRun: [fzpkguzcld21cz8dpo5bted4cyoa2xlx54vfmp2yy2m8w1i] c:\docume~1\valued~1\locals~1\temp\undzcd.exe
uRun: [olse6a1tah2x2g7] c:\docume~1\valued~1\locals~1\temp\mgdd1ro0jbf.exe
uRun: [ttjtjjs8pkr9kadkh8jarw4ba7rdd6ml9jpw3lnsjclz3l4zc4] c:\docume~1\valued~1\locals~1\temp\rjymo4z.exe
uRun: [bzww4pvmp3xlry01sub90m575l6twa920ciljxa] c:\docume~1\valued~1\locals~1\temp\pslqf0xghcpi.exe
uRun: [vitu6e9wa410uoqgr7wehx5in8u8ph606pe0myij4ozk45] c:\docume~1\valued~1\locals~1\temp\xc6z2hyw.exe
uRun: [vym444rzmidra24fitzk4nsg5hns39le90i] c:\docume~1\valued~1\locals~1\temp\jvzxqdby.exe
uRun: [bvtvu0118ojdwc0m7fdj5fm10v9mb10xm9] c:\docume~1\valued~1\locals~1\temp\w2d5xplnopf4.exe
uRun: [p021jfm61zvrkgtc8uqonqg5p2blkref6] c:\docume~1\valued~1\locals~1\temp\mrl29fhy.exe
uRun: [s6olsyjiz28amdr9ms6hlbuikh26e283disssmdbne] c:\docume~1\valued~1\locals~1\temp\zyzagrrn3ghk.exe
uRun: [v74y7dnqpsh1fe32ettjpeiwl9zg3nwo2cdnqzt] c:\docume~1\valued~1\locals~1\temp\mfdrp06i2.exe
uRun: [c4ndq8efi22p6gux6prkhycs1hyllz783] c:\docume~1\valued~1\locals~1\temp\wcrfurcx.exe
uRun: [n74fgw3r63vn3wtmi8tx0zpg9cbxea6yo1m] c:\docume~1\valued~1\locals~1\temp\vc074w9qu7ub.exe
uRun: [a1n8q5wa1e0murufcilykik05h9vconm3uem3w] c:\docume~1\valued~1\locals~1\temp\lfagxy.exe
uRun: [co87c40k2ik45x25y2fcl510h6vg] c:\docume~1\valued~1\locals~1\temp\bmhlbswd.exe
uRun: [ubtau15rc0xha6bisljqkf77n6qocshcjnbab3c1z4d14gtb46] c:\docume~1\valued~1\locals~1\temp\mt0oqj33.exe
uRun: [j8m9j52624d7pfq8cffhhio5hb2fah7ioymspz1w6f6361] c:\docume~1\valued~1\locals~1\temp\w7xcva9.exe
uRun: [j3vz6exgui0yzqq0d53cazh6nk9f0vnb7] c:\docume~1\valued~1\locals~1\temp\snlerc1ic2jx.exe
uRun: [t730lxu6sewvi0k1raki50k40amq23727x10gtt4f2q5zu6l] c:\docume~1\valued~1\locals~1\temp\twdlw4.exe
uRun: [g9rwvkt415mdpvbap3ibth3f7qv5ch5qf2wzxtht7dog] c:\docume~1\valued~1\locals~1\temp\wg7ym8.exe
uRun: [gc9bsltd2t27c4o8s05yihzivbrxqjsx8i30h4] c:\docume~1\valued~1\locals~1\temp\rcas75.exe
uRun: [eru0h0jugg] c:\docume~1\valued~1\locals~1\temp\cvtbdfb.exe
uRun: [rf7e2qicah357cuazgkfr] c:\docume~1\valued~1\locals~1\temp\ooysr6x92.exe
uRun: [sjvjkvylduoq] c:\docume~1\valued~1\locals~1\temp\b9tx81.exe
uRun: [xv8wdnoaov7qo1mzkmss2t121m3utyh] c:\docume~1\valued~1\locals~1\temp\agvjajb.exe
uRun: [a77thmq9z3ml5wumu21rrivcmjgc5] c:\docume~1\valued~1\locals~1\temp\d0l65f9.exe
uRun: [tercc8qijonx5ictezs6qxogs] c:\docume~1\valued~1\locals~1\temp\w6x5c1kk.exe
uRun: [ld62oswyv12nlcd7kzsqhhm58ot3zyn] c:\docume~1\valued~1\locals~1\temp\xawsw7.exe
uRun: [mqf6l9re1t9ld5uc48pf5dopg0y9nazy2egde1al0yl] c:\docume~1\valued~1\locals~1\temp\azozh1i9i1ofk.exe
uRun: [m9e39ouktcz2q2bum3y5fshz39o] c:\docume~1\valued~1\locals~1\temp\bvchyz7yjv6x2.exe
uRun: [n3i16nhts5ptpvx4uagwbjs3ai] c:\docume~1\valued~1\locals~1\temp\trj1xnyp2pi73.exe
uRun: [lemg3m4jrjmffq8beew45pw6g] c:\docume~1\valued~1\locals~1\temp\ln72dspglju0n.exe
uRun: [aqtvw9f806ct17p4t0vo6yvij71rhnil54jv8khvahhkvu6] c:\docume~1\valued~1\locals~1\temp\og7mfut90n.exe
uRun: [nzcs6la8uvza8wqxl3lot6b4] c:\docume~1\valued~1\locals~1\temp\yp9anmn295p5.exe
uRun: [tblpu9c87znyar2pzjq5mvs3lxsy4paav9snqsuxxj4ey16gkx] c:\docume~1\valued~1\locals~1\temp\bl6e2j9.exe
uRun: [p8uhogz8famjr] c:\docume~1\valued~1\locals~1\temp\tmdicv.exe
uRun: [r9fxgh4cej7j9661an4f0ig4hzaznwt6squhmbbu9rp] c:\docume~1\valued~1\locals~1\temp\avyngxze.exe
uRun: [j1hhghwv4la9zovlyo0qj87vb9ff28qqjc5] c:\docume~1\valued~1\locals~1\temp\l9m668p463d7.exe
uRun: [sat1qvsltd76xwxhqxmb5tdrhuzte] c:\docume~1\valued~1\locals~1\temp\ntei8lbnksrbf.exe
uRun: [t4xzndfusvd6ecx43yf2zvrr59ab] c:\docume~1\valued~1\locals~1\temp\fpl27q2e3m34g.exe
uRun: [ut3rdhq5yi8s87wk6rtu8rdukda25y1xiv5u] c:\docume~1\valued~1\locals~1\temp\us43rx5z047.exe
uRun: [y31xtpxx7fnf6oq8v8fkf8u7lerz3amnf2t7cadtged5r] c:\docume~1\valued~1\locals~1\temp\brbotszbg.exe
uRun: [dwlioesgt] c:\docume~1\valued~1\locals~1\temp\tni89xq2z.exe
uRun: [lhl4so93f64sp2b7ixplsif] c:\docume~1\valued~1\locals~1\temp\e6irf7sv2s.exe
uRun: [pyqdp22g0wvb1n9r7h7otlevyvhfs9ol6w] c:\docume~1\valued~1\locals~1\temp\p81r2yuo90w.exe
uRun: [vryhk29u9ntlyubcvhb5vt1tc8f3hlvump] c:\docume~1\valued~1\locals~1\temp\txdsfd7jbg83n.exe
uRun: [fkcs5m6w0ljaiwsz0ccuu6z9xmtpphce73q] c:\docume~1\valued~1\locals~1\temp\rrdwdjx.exe
uRun: [yq0z45ilwnmbv6tl3qmgjgfohezjlx62rz2uesd1k5o4] c:\docume~1\valued~1\locals~1\temp\zv6cxe6.exe
uRun: [n7lxn109ukrmwn3uigqslqa2np5fozsdmkvzw] c:\docume~1\valued~1\locals~1\temp\noky94ppfe9g.exe
uRun: [kin4bqcu907r0ocsn0uy3vvcsnj8xsrshw82ngqizytf54f7q] c:\docume~1\valued~1\locals~1\temp\nyfifkp6.exe
uRun: [s76wlyephqy24868s8aj7] c:\docume~1\valued~1\locals~1\temp\rif0chqy2kmz0.exe
uRun: [mowyjgygae8hygxm8aozismc0jxbfc] c:\docume~1\valued~1\locals~1\temp\uxm3hw.exe
uRun: [gcf6vz6g4l2hfyopcck1vlx39tp] c:\docume~1\valued~1\locals~1\temp\j9akvn5m.exe
uRun: [rehzuaio7ve] c:\docume~1\valued~1\locals~1\temp\qdt5uybk1qe.exe
uRun: [kixuqk9zl2qvk8smz02ng9hilpvzq9v] c:\docume~1\valued~1\locals~1\temp\jj5413m34elm.exe
uRun: [ln8yoh8mu1nspf] c:\docume~1\valued~1\locals~1\temp\bwco08ddn8ef.exe
uRun: [hrg9trc8z6232vgt3l] c:\docume~1\valued~1\locals~1\temp\ryaaxz8rs79.exe
uRun: [q0ti7tgeucwax1r804wo3w] c:\docume~1\valued~1\locals~1\temp\viz9ld.exe
uRun: [iu0fmetr9xac5mh78loiri5xjz5rq3rww3k4ps] c:\docume~1\valued~1\locals~1\temp\zylh692uwuv.exe
uRun: [l3ow5t892utvcjllr7twc0papgcf4pzjanlld9uwykjkjhx] c:\docume~1\valued~1\locals~1\temp\rgblvvyzfo.exe
uRun: [h43g9pxjctavt] c:\docume~1\valued~1\locals~1\temp\j76me1dn5ckj9.exe
uRun: [xxai41d4beszhh0hzgvdk2gezlddi05nn2xa] c:\docume~1\valued~1\locals~1\temp\rlu54c3df.exe
uRun: [mu4drunyq6qm8] c:\docume~1\valued~1\locals~1\temp\i2k8w1h9nic.exe
uRun: [xmurap0ifi] c:\docume~1\valued~1\locals~1\temp\bpwq3nss76j6.exe
uRun: [uqmhepv4pxnou8tghozypnhzd] c:\docume~1\valued~1\locals~1\temp\nwm5efktgl.exe
uRun: [uepfq8bdtc118l4he1i] c:\docume~1\valued~1\locals~1\temp\jy89dz6fovu.exe
uRun: [pci1y45b3bzclc1q0ympjshkutk6jihyvf] c:\docume~1\valued~1\locals~1\temp\tq3us9ogqjz.exe
uRun: [omx1wdaob4zqggucyw801q8o] c:\docume~1\valued~1\locals~1\temp\nxfuwb0a4.exe
uRun: [yvadv751t67p2lbvlt21v2to9ufag42kyx0] c:\docume~1\valued~1\locals~1\temp\p270k8lufjb.exe
uRun: [v0p19y37dr8kxbd04ggur] c:\docume~1\valued~1\locals~1\temp\p7qktpq8fj.exe
uRun: [adcc6fkwagpy4gvey40bikd93sqla82xff3c6ixtb4p] c:\docume~1\valued~1\locals~1\temp\smxnf4js1va.exe
uRun: [k6davn036mt2y9wpj4h0xqjatkvmfxzb16eyorb] c:\docume~1\valued~1\locals~1\temp\v4fwudm1.exe
uRun: [g0otwwd6i77su08m8] c:\docume~1\valued~1\locals~1\temp\owafag2h.exe
uRun: [p3ak3cc8ag2u2h1j48e4u30icr38r3gb20l3dm6m29] c:\docume~1\valued~1\locals~1\temp\slmgnvfcb4.exe
uRun: [uz2geyc0qmj9p8vf7p6seavmok2297b4ir19p46] c:\docume~1\valued~1\locals~1\temp\rg025c0y.exe
uRun: [vfblv3gor] c:\docume~1\valued~1\locals~1\temp\kmxa7pwpa.exe
uRun: [wnbh8j5qnt73buv28mde0r6i] c:\docume~1\valued~1\locals~1\temp\d95jj3m2em.exe
uRun: [mzn064w2grfc2qm4c9tw09ok6ki4nenoob8dcu0th7miur3m] c:\docume~1\valued~1\locals~1\temp\rbo2pdov04d.exe
uRun: [glvmuyqz6ye35brd6sl4mu4m1q05] c:\docume~1\valued~1\locals~1\temp\vavn8p17g.exe
uRun: [kaa0qud5it2synbb7b28av3vpblxt] c:\docume~1\valued~1\locals~1\temp\jte6ez30jy.exe
uRun: [s01odt7k2bz5m698qttmpcci1h7y] c:\docume~1\valued~1\locals~1\temp\cz75l4e235j.exe
uRun: [vv845kk4jl6f94irhzndk0ng0ta8vsripeqy3ig7gu112l0z9] c:\docume~1\valued~1\locals~1\temp\fee87j7mpyvu.exe
uRun: [itt99s2enn1o75ixmdxhk4g3bi2y] c:\docume~1\valued~1\locals~1\temp\rq2pla.exe
uRun: [avyxcd079v] c:\docume~1\valued~1\locals~1\temp\bzxa0k.exe
uRun: [iuuv4iqximrf] c:\docume~1\valued~1\locals~1\temp\j8saawpvvn8w0.exe
uRun: [my58nwkgmh93j5w5q6dqjt5xl3] c:\docume~1\valued~1\locals~1\temp\uastg6.exe
uRun: [tbv5nhsyj2jljw2u5k35nw00iz] c:\docume~1\valued~1\locals~1\temp\t56yynvaxb0c.exe
uRun: [vy2e8ecasrez92cxy3w3y5k23cxdjwt] c:\docume~1\valued~1\locals~1\temp\eopnx3.exe
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [Launch LGDCore] "c:\program files\common files\logitech\g-series software\LGDCore.exe" /SHOWHIDE
mRun: [Launch LCDMon] "c:\program files\common files\logitech\lcd manager\lcdmon.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
StartupFolder: c:\documents and settings\valued customer\start menu\programs\startup\CurseClientStartup.ccip
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\valued~1\applic~1\mozilla\firefox\profiles\vq6bpve6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/aolcom/search?invocationType=tbff50ie7&query=
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://search.aol.com/aolcom/search?invocationType=TB50TRFF;homepage=no;search=yesab&query=
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: XUL Cache: {86934F53-3CA0-4C23-8EE2-C2987DE1E67D} - c:\documents and settings\valued customer\local settings\application data\{86934F53-3CA0-4C23-8EE2-C2987DE1E67D}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1");
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-4-1 162640]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-4-1 19024]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-1 40384]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-2-17 24652]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-3-1 38224]
S2 iwingamesinstaller;iWinGamesInstaller;c:\program files\iwin games\iWinGamesInstaller.exe [2008-7-16 78104]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-1 40384]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-1 40384]
=============== Created Last 30 ================
2010-04-01 10:57 –d—– c:\docume~1\alluse~1\applic~1\Alwil Software
2010-03-04 11:48 57,956 a—h— c:\windows\system32\mlfcache.dat
2010-03-04 11:41 –d—– c:\program files\iPod
2010-03-04 11:41 –d—– c:\program files\iTunes
2010-03-02 15:16 –d—– c:\docume~1\valued~1\applic~1\Mumble
2010-03-02 15:16 –d—– c:\program files\Mumble
==================== Find3M ====================
2010-03-30 00:46 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-30 00:45 20,824 a——- c:\windows\system32\drivers\mbam.sys
2009-03-01 12:27 16,278,936 a——- c:\documents and settings\valued customer\jre-6u12-windows-i586-p.exe
2004-10-12 02:14 57,344 a——- c:\documents and settings\valued customer\InstHelp.dll
1998-12-08 19:53 186,368 a——- c:\program files\common files\IRAREG.DLL
1998-12-08 19:53 99,840 a——- c:\program files\common files\IRAABOUT.DLL
1998-12-08 19:53 70,144 a——- c:\program files\common files\IRAMDMTR.DLL
1998-12-08 19:53 48,640 a——- c:\program files\common files\IRALPTTR.DLL
1998-12-08 19:53 31,744 a——- c:\program files\common files\IRAWEBTR.DLL
1998-12-08 19:53 17,920 a——- c:\program files\common files\IRASRIAL.DLL
2009-02-28 11:26 3,163 a–sh— c:\windows\system32\IhNmoUtv.ini2
2009-02-28 21:48 16,384 a–sh— c:\windows\system32\%userprofile%\local settings\temp\cookies\index.dat
2009-02-28 21:48 16,384 a–sh— c:\windows\system32\%userprofile%\local settings\temp\history\history.ie5\index.dat
2009-02-28 21:48 32,768 a–sh— c:\windows\system32\%userprofile%\local settings\temp\temporary internet files\content.ie5\index.dat
2008-09-16 17:25 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091620080917\index.dat
============= FINISH: 14:38:28.82 ===============
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-04-01 14:58:10
Windows 5.1.2600 Service Pack 3
Running: ksu8ssj3.exe; Driver: C:\DOCUME~1\VALUED~1\LOCALS~1\Temp\afxorpow.sys
—- System - GMER 1.0.15 —-
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xAAF8A4FE]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xAAF8A322]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xAAF8A45C]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject
—- Devices - GMER 1.0.15 —-
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
—- EOF - GMER 1.0.15 —-
Attach.txt
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 14:38:14.28 on Thu 04/01/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_03
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1376 [GMT -7:00]
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\Documents and Settings\Valued Customer\Local Settings\Apps\2.0\584YRAPW.ZYV\GZENAWJ6.Y71\curs..tion_eee711038731a406_0004.0000_152ef8e82e8f5a48\CurseClient.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malware\mbam.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Valued Customer\Desktop\dds.scr
============== Pseudo HJT Report ===============
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
BHO: 1 (0x1) - No File
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
TB: {3041D03E-FD4B-44E0-B742-2D9B88305F98} - No File
uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US ee://aol/imApp
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [zsulfb58q63dyghxwkt2c7fftt] c:\docume~1\valued~1\locals~1\temp\sv5jq5f6n8jd.exe
uRun: [ybg277guru56pam6bcdhvgr4ljcyvpq5bmqzc1pwg] c:\docume~1\valued~1\locals~1\temp\h29uvxm1wce.exe
uRun: [qtuy6dco8utgmsy4ourexo781ys5kpr8o1352cj] c:\docume~1\valued~1\locals~1\temp\fq4pw1lzjr.exe
uRun: [fzpkguzcld21cz8dpo5bted4cyoa2xlx54vfmp2yy2m8w1i] c:\docume~1\valued~1\locals~1\temp\undzcd.exe
uRun: [olse6a1tah2x2g7] c:\docume~1\valued~1\locals~1\temp\mgdd1ro0jbf.exe
uRun: [ttjtjjs8pkr9kadkh8jarw4ba7rdd6ml9jpw3lnsjclz3l4zc4] c:\docume~1\valued~1\locals~1\temp\rjymo4z.exe
uRun: [bzww4pvmp3xlry01sub90m575l6twa920ciljxa] c:\docume~1\valued~1\locals~1\temp\pslqf0xghcpi.exe
uRun: [vitu6e9wa410uoqgr7wehx5in8u8ph606pe0myij4ozk45] c:\docume~1\valued~1\locals~1\temp\xc6z2hyw.exe
uRun: [vym444rzmidra24fitzk4nsg5hns39le90i] c:\docume~1\valued~1\locals~1\temp\jvzxqdby.exe
uRun: [bvtvu0118ojdwc0m7fdj5fm10v9mb10xm9] c:\docume~1\valued~1\locals~1\temp\w2d5xplnopf4.exe
uRun: [p021jfm61zvrkgtc8uqonqg5p2blkref6] c:\docume~1\valued~1\locals~1\temp\mrl29fhy.exe
uRun: [s6olsyjiz28amdr9ms6hlbuikh26e283disssmdbne] c:\docume~1\valued~1\locals~1\temp\zyzagrrn3ghk.exe
uRun: [v74y7dnqpsh1fe32ettjpeiwl9zg3nwo2cdnqzt] c:\docume~1\valued~1\locals~1\temp\mfdrp06i2.exe
uRun: [c4ndq8efi22p6gux6prkhycs1hyllz783] c:\docume~1\valued~1\locals~1\temp\wcrfurcx.exe
uRun: [n74fgw3r63vn3wtmi8tx0zpg9cbxea6yo1m] c:\docume~1\valued~1\locals~1\temp\vc074w9qu7ub.exe
uRun: [a1n8q5wa1e0murufcilykik05h9vconm3uem3w] c:\docume~1\valued~1\locals~1\temp\lfagxy.exe
uRun: [co87c40k2ik45x25y2fcl510h6vg] c:\docume~1\valued~1\locals~1\temp\bmhlbswd.exe
uRun: [ubtau15rc0xha6bisljqkf77n6qocshcjnbab3c1z4d14gtb46] c:\docume~1\valued~1\locals~1\temp\mt0oqj33.exe
uRun: [j8m9j52624d7pfq8cffhhio5hb2fah7ioymspz1w6f6361] c:\docume~1\valued~1\locals~1\temp\w7xcva9.exe
uRun: [j3vz6exgui0yzqq0d53cazh6nk9f0vnb7] c:\docume~1\valued~1\locals~1\temp\snlerc1ic2jx.exe
uRun: [t730lxu6sewvi0k1raki50k40amq23727x10gtt4f2q5zu6l] c:\docume~1\valued~1\locals~1\temp\twdlw4.exe
uRun: [g9rwvkt415mdpvbap3ibth3f7qv5ch5qf2wzxtht7dog] c:\docume~1\valued~1\locals~1\temp\wg7ym8.exe
uRun: [gc9bsltd2t27c4o8s05yihzivbrxqjsx8i30h4] c:\docume~1\valued~1\locals~1\temp\rcas75.exe
uRun: [eru0h0jugg] c:\docume~1\valued~1\locals~1\temp\cvtbdfb.exe
uRun: [rf7e2qicah357cuazgkfr] c:\docume~1\valued~1\locals~1\temp\ooysr6x92.exe
uRun: [sjvjkvylduoq] c:\docume~1\valued~1\locals~1\temp\b9tx81.exe
uRun: [xv8wdnoaov7qo1mzkmss2t121m3utyh] c:\docume~1\valued~1\locals~1\temp\agvjajb.exe
uRun: [a77thmq9z3ml5wumu21rrivcmjgc5] c:\docume~1\valued~1\locals~1\temp\d0l65f9.exe
uRun: [tercc8qijonx5ictezs6qxogs] c:\docume~1\valued~1\locals~1\temp\w6x5c1kk.exe
uRun: [ld62oswyv12nlcd7kzsqhhm58ot3zyn] c:\docume~1\valued~1\locals~1\temp\xawsw7.exe
uRun: [mqf6l9re1t9ld5uc48pf5dopg0y9nazy2egde1al0yl] c:\docume~1\valued~1\locals~1\temp\azozh1i9i1ofk.exe
uRun: [m9e39ouktcz2q2bum3y5fshz39o] c:\docume~1\valued~1\locals~1\temp\bvchyz7yjv6x2.exe
uRun: [n3i16nhts5ptpvx4uagwbjs3ai] c:\docume~1\valued~1\locals~1\temp\trj1xnyp2pi73.exe
uRun: [lemg3m4jrjmffq8beew45pw6g] c:\docume~1\valued~1\locals~1\temp\ln72dspglju0n.exe
uRun: [aqtvw9f806ct17p4t0vo6yvij71rhnil54jv8khvahhkvu6] c:\docume~1\valued~1\locals~1\temp\og7mfut90n.exe
uRun: [nzcs6la8uvza8wqxl3lot6b4] c:\docume~1\valued~1\locals~1\temp\yp9anmn295p5.exe
uRun: [tblpu9c87znyar2pzjq5mvs3lxsy4paav9snqsuxxj4ey16gkx] c:\docume~1\valued~1\locals~1\temp\bl6e2j9.exe
uRun: [p8uhogz8famjr] c:\docume~1\valued~1\locals~1\temp\tmdicv.exe
uRun: [r9fxgh4cej7j9661an4f0ig4hzaznwt6squhmbbu9rp] c:\docume~1\valued~1\locals~1\temp\avyngxze.exe
uRun: [j1hhghwv4la9zovlyo0qj87vb9ff28qqjc5] c:\docume~1\valued~1\locals~1\temp\l9m668p463d7.exe
uRun: [sat1qvsltd76xwxhqxmb5tdrhuzte] c:\docume~1\valued~1\locals~1\temp\ntei8lbnksrbf.exe
uRun: [t4xzndfusvd6ecx43yf2zvrr59ab] c:\docume~1\valued~1\locals~1\temp\fpl27q2e3m34g.exe
uRun: [ut3rdhq5yi8s87wk6rtu8rdukda25y1xiv5u] c:\docume~1\valued~1\locals~1\temp\us43rx5z047.exe
uRun: [y31xtpxx7fnf6oq8v8fkf8u7lerz3amnf2t7cadtged5r] c:\docume~1\valued~1\locals~1\temp\brbotszbg.exe
uRun: [dwlioesgt] c:\docume~1\valued~1\locals~1\temp\tni89xq2z.exe
uRun: [lhl4so93f64sp2b7ixplsif] c:\docume~1\valued~1\locals~1\temp\e6irf7sv2s.exe
uRun: [pyqdp22g0wvb1n9r7h7otlevyvhfs9ol6w] c:\docume~1\valued~1\locals~1\temp\p81r2yuo90w.exe
uRun: [vryhk29u9ntlyubcvhb5vt1tc8f3hlvump] c:\docume~1\valued~1\locals~1\temp\txdsfd7jbg83n.exe
uRun: [fkcs5m6w0ljaiwsz0ccuu6z9xmtpphce73q] c:\docume~1\valued~1\locals~1\temp\rrdwdjx.exe
uRun: [yq0z45ilwnmbv6tl3qmgjgfohezjlx62rz2uesd1k5o4] c:\docume~1\valued~1\locals~1\temp\zv6cxe6.exe
uRun: [n7lxn109ukrmwn3uigqslqa2np5fozsdmkvzw] c:\docume~1\valued~1\locals~1\temp\noky94ppfe9g.exe
uRun: [kin4bqcu907r0ocsn0uy3vvcsnj8xsrshw82ngqizytf54f7q] c:\docume~1\valued~1\locals~1\temp\nyfifkp6.exe
uRun: [s76wlyephqy24868s8aj7] c:\docume~1\valued~1\locals~1\temp\rif0chqy2kmz0.exe
uRun: [mowyjgygae8hygxm8aozismc0jxbfc] c:\docume~1\valued~1\locals~1\temp\uxm3hw.exe
uRun: [gcf6vz6g4l2hfyopcck1vlx39tp] c:\docume~1\valued~1\locals~1\temp\j9akvn5m.exe
uRun: [rehzuaio7ve] c:\docume~1\valued~1\locals~1\temp\qdt5uybk1qe.exe
uRun: [kixuqk9zl2qvk8smz02ng9hilpvzq9v] c:\docume~1\valued~1\locals~1\temp\jj5413m34elm.exe
uRun: [ln8yoh8mu1nspf] c:\docume~1\valued~1\locals~1\temp\bwco08ddn8ef.exe
uRun: [hrg9trc8z6232vgt3l] c:\docume~1\valued~1\locals~1\temp\ryaaxz8rs79.exe
uRun: [q0ti7tgeucwax1r804wo3w] c:\docume~1\valued~1\locals~1\temp\viz9ld.exe
uRun: [iu0fmetr9xac5mh78loiri5xjz5rq3rww3k4ps] c:\docume~1\valued~1\locals~1\temp\zylh692uwuv.exe
uRun: [l3ow5t892utvcjllr7twc0papgcf4pzjanlld9uwykjkjhx] c:\docume~1\valued~1\locals~1\temp\rgblvvyzfo.exe
uRun: [h43g9pxjctavt] c:\docume~1\valued~1\locals~1\temp\j76me1dn5ckj9.exe
uRun: [xxai41d4beszhh0hzgvdk2gezlddi05nn2xa] c:\docume~1\valued~1\locals~1\temp\rlu54c3df.exe
uRun: [mu4drunyq6qm8] c:\docume~1\valued~1\locals~1\temp\i2k8w1h9nic.exe
uRun: [xmurap0ifi] c:\docume~1\valued~1\locals~1\temp\bpwq3nss76j6.exe
uRun: [uqmhepv4pxnou8tghozypnhzd] c:\docume~1\valued~1\locals~1\temp\nwm5efktgl.exe
uRun: [uepfq8bdtc118l4he1i] c:\docume~1\valued~1\locals~1\temp\jy89dz6fovu.exe
uRun: [pci1y45b3bzclc1q0ympjshkutk6jihyvf] c:\docume~1\valued~1\locals~1\temp\tq3us9ogqjz.exe
uRun: [omx1wdaob4zqggucyw801q8o] c:\docume~1\valued~1\locals~1\temp\nxfuwb0a4.exe
uRun: [yvadv751t67p2lbvlt21v2to9ufag42kyx0] c:\docume~1\valued~1\locals~1\temp\p270k8lufjb.exe
uRun: [v0p19y37dr8kxbd04ggur] c:\docume~1\valued~1\locals~1\temp\p7qktpq8fj.exe
uRun: [adcc6fkwagpy4gvey40bikd93sqla82xff3c6ixtb4p] c:\docume~1\valued~1\locals~1\temp\smxnf4js1va.exe
uRun: [k6davn036mt2y9wpj4h0xqjatkvmfxzb16eyorb] c:\docume~1\valued~1\locals~1\temp\v4fwudm1.exe
uRun: [g0otwwd6i77su08m8] c:\docume~1\valued~1\locals~1\temp\owafag2h.exe
uRun: [p3ak3cc8ag2u2h1j48e4u30icr38r3gb20l3dm6m29] c:\docume~1\valued~1\locals~1\temp\slmgnvfcb4.exe
uRun: [uz2geyc0qmj9p8vf7p6seavmok2297b4ir19p46] c:\docume~1\valued~1\locals~1\temp\rg025c0y.exe
uRun: [vfblv3gor] c:\docume~1\valued~1\locals~1\temp\kmxa7pwpa.exe
uRun: [wnbh8j5qnt73buv28mde0r6i] c:\docume~1\valued~1\locals~1\temp\d95jj3m2em.exe
uRun: [mzn064w2grfc2qm4c9tw09ok6ki4nenoob8dcu0th7miur3m] c:\docume~1\valued~1\locals~1\temp\rbo2pdov04d.exe
uRun: [glvmuyqz6ye35brd6sl4mu4m1q05] c:\docume~1\valued~1\locals~1\temp\vavn8p17g.exe
uRun: [kaa0qud5it2synbb7b28av3vpblxt] c:\docume~1\valued~1\locals~1\temp\jte6ez30jy.exe
uRun: [s01odt7k2bz5m698qttmpcci1h7y] c:\docume~1\valued~1\locals~1\temp\cz75l4e235j.exe
uRun: [vv845kk4jl6f94irhzndk0ng0ta8vsripeqy3ig7gu112l0z9] c:\docume~1\valued~1\locals~1\temp\fee87j7mpyvu.exe
uRun: [itt99s2enn1o75ixmdxhk4g3bi2y] c:\docume~1\valued~1\locals~1\temp\rq2pla.exe
uRun: [avyxcd079v] c:\docume~1\valued~1\locals~1\temp\bzxa0k.exe
uRun: [iuuv4iqximrf] c:\docume~1\valued~1\locals~1\temp\j8saawpvvn8w0.exe
uRun: [my58nwkgmh93j5w5q6dqjt5xl3] c:\docume~1\valued~1\locals~1\temp\uastg6.exe
uRun: [tbv5nhsyj2jljw2u5k35nw00iz] c:\docume~1\valued~1\locals~1\temp\t56yynvaxb0c.exe
uRun: [vy2e8ecasrez92cxy3w3y5k23cxdjwt] c:\docume~1\valued~1\locals~1\temp\eopnx3.exe
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [Launch LGDCore] "c:\program files\common files\logitech\g-series software\LGDCore.exe" /SHOWHIDE
mRun: [Launch LCDMon] "c:\program files\common files\logitech\lcd manager\lcdmon.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
StartupFolder: c:\documents and settings\valued customer\start menu\programs\startup\CurseClientStartup.ccip
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\valued~1\applic~1\mozilla\firefox\profiles\vq6bpve6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/aolcom/search?invocationType=tbff50ie7&query=
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://search.aol.com/aolcom/search?invocationType=TB50TRFF;homepage=no;search=yesab&query=
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: XUL Cache: {86934F53-3CA0-4C23-8EE2-C2987DE1E67D} - c:\documents and settings\valued customer\local settings\application data\{86934F53-3CA0-4C23-8EE2-C2987DE1E67D}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1");
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-4-1 162640]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-4-1 19024]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-1 40384]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-2-17 24652]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-3-1 38224]
S2 iwingamesinstaller;iWinGamesInstaller;c:\program files\iwin games\iWinGamesInstaller.exe [2008-7-16 78104]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-1 40384]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-4-1 40384]
=============== Created Last 30 ================
2010-04-01 10:57 –d—– c:\docume~1\alluse~1\applic~1\Alwil Software
2010-03-04 11:48 57,956 a—h— c:\windows\system32\mlfcache.dat
2010-03-04 11:41 –d—– c:\program files\iPod
2010-03-04 11:41 –d—– c:\program files\iTunes
2010-03-02 15:16 –d—– c:\docume~1\valued~1\applic~1\Mumble
2010-03-02 15:16 –d—– c:\program files\Mumble
==================== Find3M ====================
2010-03-30 00:46 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-30 00:45 20,824 a——- c:\windows\system32\drivers\mbam.sys
2009-03-01 12:27 16,278,936 a——- c:\documents and settings\valued customer\jre-6u12-windows-i586-p.exe
2004-10-12 02:14 57,344 a——- c:\documents and settings\valued customer\InstHelp.dll
1998-12-08 19:53 186,368 a——- c:\program files\common files\IRAREG.DLL
1998-12-08 19:53 99,840 a——- c:\program files\common files\IRAABOUT.DLL
1998-12-08 19:53 70,144 a——- c:\program files\common files\IRAMDMTR.DLL
1998-12-08 19:53 48,640 a——- c:\program files\common files\IRALPTTR.DLL
1998-12-08 19:53 31,744 a——- c:\program files\common files\IRAWEBTR.DLL
1998-12-08 19:53 17,920 a——- c:\program files\common files\IRASRIAL.DLL
2009-02-28 11:26 3,163 a–sh— c:\windows\system32\IhNmoUtv.ini2
2009-02-28 21:48 16,384 a–sh— c:\windows\system32\%userprofile%\local settings\temp\cookies\index.dat
2009-02-28 21:48 16,384 a–sh— c:\windows\system32\%userprofile%\local settings\temp\history\history.ie5\index.dat
2009-02-28 21:48 32,768 a–sh— c:\windows\system32\%userprofile%\local settings\temp\temporary internet files\content.ie5\index.dat
2008-09-16 17:25 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091620080917\index.dat
============= FINISH: 14:38:28.82 ===============
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-04-01 14:58:10
Windows 5.1.2600 Service Pack 3
Running: ksu8ssj3.exe; Driver: C:\DOCUME~1\VALUED~1\LOCALS~1\Temp\afxorpow.sys
—- System - GMER 1.0.15 —-
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xAAF8A4FE]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0xAAF8A322]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xAAF8A45C]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject
—- Devices - GMER 1.0.15 —-
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
—- EOF - GMER 1.0.15 —-
Attach.txt