This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] tidserv request 2 removal

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi I keep getting warnings from norton's about a blocked attempt from - tidserv requets 2 - how do I remove this problem
Hello and Welcome to the forums!

My name is Gringo and I'll be glad to help you with your computer problems.

Somethings to remember while we are working together.

1.Please do not run any other tool untill instructed to do so!
2.Please reply to this thread, do not start another!
3.Please tell me about any problems that have occurred during the fix.
4.Please tell me of any other symptoms you may be having as these can help also.
5.Please try as much as possible not to run anything while executing a fix.

If you follow these instructions, everything should go smoothly.

Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe.

I would like to get a better look at your system, please do the following so I can get some more detailed logs.


DeFogger:

  • Please download DeFogger to your desktop.

    Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger may ask you to reboot the machine, if it does - click OK
Do not re-enable these drivers until otherwise instructed.
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Download DDS:

  • Please download DDS by sUBs from one of the links below and save it to your desktop:

    [external image: Posted Image]
    Download DDS and save it to your desktop

    Link1
    Link2
    Link3

    Please disable any anti-malware program that will block scripts from running before running DDS.

    • Double-Click on dds.scr and a command window will appear. This is normal.
    • Shortly after two logs will appear:
    • DDS.txt
    • Attach.txt
  • A window will open instructing you save & post the logs
  • Save the logs to a convenient place such as your desktop
  • Copy the contents of both logs & post in your next reply

GMER:

  • Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan..
    [external image: Posted Image]
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "ark.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

information and logs:

In your next post I need the following

1.logs from DDS
2.log from GMER
3.let me know of any problems you may have had

Gringo
Thanks for the prompt reply problems include
- nortons "tidserv request 2" blocked constant when on net
- browser redirecting
- sound being disabled


DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 7:56:09.21 on Mon 05/04/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.2038.1247 [GMT 10:00]

AV: Norton AntiVirus *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
C:\WINDOWS\system32\ntvdm.exe
C:\OPLIMIT\ocrawr32.exe
C:\Program Files\Adobe\Acrobat 6.0\Acrobat\Acrobat.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Documents and Settings\User\Desktop\Defogger.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\User\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.abc.net.au/
uSearch Bar = hxxp://www.google.com
mSearch Bar = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\engine\16.8.0.41\IPSBHO.DLL
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [DriverCure] c:\program files\paretologic\drivercure\DriverCure.exe -scan
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [Creative Detector] c:\program files\creative\mediasource\detector\CTDetect.exe /R
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [HDAudDeck] c:\program files\via\viaudioi\hdadeck\HDeck.exe 1
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Easy-PrintToolBox] c:\program files\canon\easy-printtoolbox\BJPSMAIN.EXE /logon
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [PE2CKFNT SE] c:\program files\ulead systems\ulead photo express 2 se\ChkFont.exe
mRun: [Fax Machine]
mRun: [EfficientDiary]
mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
StartupFolder: c:\docume~1\user\startm~1\programs\startup\ocraware.lnk - c:\oplimit\OCRAWARE.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\acrobat 6.0\distillr\acrotray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\reader 8.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~2.lnk - c:\program files\adobe\reader 8.0\reader\AdobeCollabSync.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\photoe~1.lnk - c:\program files\ulead systems\ulead photo express 2 se\CalCheck.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\canon\easy-webprint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\canon\easy-webprint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\canon\easy-webprint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\canon\easy-webprint\Resource.dll/RC_Print.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/buxus/docs/OnlineScanner.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: dsmobkzx - dsmobkzx32.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com

============= SERVICES / DRIVERS ===============

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1008000.029\SymEFA.sys [2010-1-28 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nav\1008000.029\BHDrvx86.sys [2010-1-28 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nav\1008000.029\cchpx86.sys [2010-1-28 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20100326.001\IDSXpx86.sys [2010-3-26 329592]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\norton antivirus\engine\16.8.0.41\ccSvcHst.exe [2010-1-28 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-8-26 102448]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20100404.004\NAVENG.SYS [2010-4-5 84912]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20100404.004\NAVEX15.SYS [2010-4-5 1324720]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-1-19 222976]
S0 ati0jixx;ati0jixx;c:\windows\system32\drivers\ati0jixx.sys –> c:\windows\system32\drivers\ati0jixx.sys [?]
S0 ati3etxx;ati3etxx;c:\windows\system32\drivers\ati3etxx.sys –> c:\windows\system32\drivers\ati3etxx.sys [?]
S0 ati3woxx;ati3woxx;c:\windows\system32\drivers\ati3woxx.sys –> c:\windows\system32\drivers\ati3woxx.sys [?]
S0 ati4mlxx;ati4mlxx;c:\windows\system32\drivers\ati4mlxx.sys –> c:\windows\system32\drivers\ati4mlxx.sys [?]
S0 ati5qpxx;ati5qpxx;c:\windows\system32\drivers\ati5qpxx.sys –> c:\windows\system32\drivers\ati5qpxx.sys [?]
S0 ati6ayxx;ati6ayxx;c:\windows\system32\drivers\ati6ayxx.sys –> c:\windows\system32\drivers\ati6ayxx.sys [?]
S0 ati7tcxx;ati7tcxx;c:\windows\system32\drivers\ati7tcxx.sys –> c:\windows\system32\drivers\ati7tcxx.sys [?]
S0 ati8xexx;ati8xexx;c:\windows\system32\drivers\ati8xexx.sys –> c:\windows\system32\drivers\ati8xexx.sys [?]
S2 gupdate1c9d697d19c9338;Google Update Service (gupdate1c9d697d19c9338);c:\program files\google\update\GoogleUpdate.exe [2009-5-17 133104]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\aspi32.sys [2009-5-21 16512]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\30.tmp –> c:\windows\system32\30.tmp [?]
S3 Winpnsem;Winpnsem; [x]

=============== Created Last 30 ================

2010-04-04 21:50:06 0 —-a-w- c:\documents and settings\user\defogger_reenable
2010-04-04 10:18:14 108 —-a-w- c:\windows\system32\temp_0000_30437.aok
2010-04-04 07:41:55 0 d—–w- c:\program files\Sophos
2010-04-02 02:28:35 120 —-a-w- c:\windows\Xbejinodu.dat
2010-04-02 02:28:35 0 —-a-w- c:\windows\Mjimujoxumu.bin
2010-04-02 02:24:41 45056 —-a-w- c:\windows\ftxa07573.exe
2010-03-21 21:46:41 0 d—–w- c:\program files\EwisoftWeb
2010-03-21 21:46:41 0 d—–w- c:\docume~1\alluse~1\applic~1\EwisoftWeb

==================== Find3M ====================

2010-04-04 01:25:49 8832 —-a-w- c:\windows\system32\drivers\rasacd.sys
2010-03-29 13:46:30 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-29 13:45:52 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-02-26 04:17:34 50 —-a-w- C:\xcrashdump.dat
2010-02-26 00:19:57 203776 –sh–w- c:\windows\system32\unrar.exe
2010-02-25 06:24:37 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-03 04:24:44 86480 —-a-w- c:\docume~1\user\applic~1\GDIPFONTCACHEV1.DAT
2008-04-13 14:10:32 96512 —-a-w- c:\program files\atapi.sys

============= FINISH: 7:57:30.32 ===============

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 19/01/2009 3:08:52 PM
System Uptime: 4/05/2010 7:30:23 AM (-696 hours ago)

Motherboard: ASUSTeK Computer INC. | | P5KPL-CM
Processor: Intel® Core™2 Quad CPU Q6600 @ 2.40GHz | Socket 775 | 2399/266mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 298 GiB total, 211.418 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 233 GiB total, 42.967 GiB free.

==== Disabled Device Manager Items =============

Class GUID: {4D36E96B-E325-11CE-BFC1-08002BE10318}
Description: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
Device ID: ACPI\PNP0303\4&2C575ACB&0
Manufacturer: (Standard keyboards)
Name: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
PNP Device ID: ACPI\PNP0303\4&2C575ACB&0
Service: i8042prt

Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318}
Description: Microsoft PS/2 Mouse
Device ID: ACPI\PNP0F03\4&2C575ACB&0
Manufacturer: Microsoft
Name: Microsoft PS/2 Mouse
PNP Device ID: ACPI\PNP0F03\4&2C575ACB&0
Service: i8042prt

==== System Restore Points ===================

RP549: 5/01/2010 7:50:11 PM - System Checkpoint
RP550: 6/01/2010 8:09:46 PM - System Checkpoint
RP551: 7/01/2010 8:59:11 PM - System Checkpoint
RP552: 8/01/2010 9:08:32 PM - System Checkpoint
RP553: 9/01/2010 9:13:13 PM - System Checkpoint
RP554: 10/01/2010 10:17:03 PM - System Checkpoint
RP555: 12/01/2010 5:28:38 PM - System Checkpoint
RP556: 20/01/2010 10:17:09 PM - System Checkpoint
RP557: 13/01/2010 12:49:50 PM - System Checkpoint
RP558: 13/01/2010 12:53:14 PM - Software Distribution Service 3.0
RP559: 14/01/2010 1:24:24 PM - System Checkpoint
RP560: 15/01/2010 3:46:58 PM - System Checkpoint
RP561: 16/01/2010 6:46:40 PM - System Checkpoint
RP562: 17/01/2010 7:29:41 PM - System Checkpoint
RP563: 18/01/2010 2:08:56 PM - Installed PowerDirector
RP564: 18/01/2010 2:17:41 PM - Configured PowerDirector
RP565: 19/01/2010 2:49:41 PM - System Checkpoint
RP566: 20/01/2010 3:48:06 PM - System Checkpoint
RP567: 21/01/2010 3:58:03 PM - System Checkpoint
RP568: 22/01/2010 4:27:23 PM - System Checkpoint
RP569: 23/01/2010 1:03:57 AM - Software Distribution Service 3.0
RP570: 24/01/2010 1:32:34 AM - System Checkpoint
RP571: 25/01/2010 7:25:33 PM - System Checkpoint
RP572: 26/01/2010 7:49:17 PM - System Checkpoint
RP573: 27/01/2010 10:26:22 PM - System Checkpoint
RP574: 29/01/2010 9:20:47 AM - System Checkpoint
RP575: 30/01/2010 10:05:22 AM - System Checkpoint
RP576: 31/01/2010 10:08:54 AM - System Checkpoint
RP577: 1/02/2010 12:07:38 PM - System Checkpoint
RP578: 2/02/2010 2:43:17 PM - System Checkpoint
RP579: 3/02/2010 3:05:13 PM - System Checkpoint
RP580: 4/02/2010 6:31:34 PM - System Checkpoint
RP581: 8/02/2010 1:02:43 PM - System Checkpoint
RP582: 9/02/2010 1:28:42 PM - System Checkpoint
RP583: 10/02/2010 7:10:51 PM - System Checkpoint
RP584: 10/02/2010 11:05:37 PM - Software Distribution Service 3.0
RP585: 12/02/2010 7:27:01 AM - System Checkpoint
RP586: 13/02/2010 8:51:34 AM - System Checkpoint
RP587: 14/02/2010 9:17:07 AM - System Checkpoint
RP588: 15/02/2010 12:16:05 PM - System Checkpoint
RP589: 16/02/2010 12:37:00 PM - System Checkpoint
RP590: 17/02/2010 7:30:59 PM - System Checkpoint
RP591: 18/02/2010 9:03:26 PM - System Checkpoint
RP592: 19/02/2010 9:12:48 PM - System Checkpoint
RP593: 20/02/2010 10:46:00 PM - System Checkpoint
RP594: 22/02/2010 11:51:33 AM - System Checkpoint
RP595: 23/02/2010 5:46:32 PM - System Checkpoint
RP596: 24/02/2010 1:30:05 PM - Software Distribution Service 3.0
RP597: 25/02/2010 1:42:54 PM - System Checkpoint
RP598: 25/02/2010 5:52:35 PM - Installed FSEdit SDK
RP599: 26/02/2010 11:26:17 AM - Removed FSEdit SDK
RP600: 26/02/2010 5:52:01 PM - Restore Operation
RP601: 26/02/2010 5:58:37 PM - Restore Operation
RP602: 26/02/2010 6:02:41 PM - Restore Operation
RP603: 26/02/2010 11:23:11 PM - Restore Operation
RP604: 27/02/2010 10:47:53 AM - Installed AVG 9.0
RP605: 28/02/2010 10:50:28 AM - System Checkpoint
RP606: 1/03/2010 5:25:22 PM - System Checkpoint
RP607: 2/03/2010 8:02:35 PM - System Checkpoint
RP608: 3/03/2010 9:00:40 PM - System Checkpoint
RP609: 4/03/2010 9:22:37 PM - System Checkpoint
RP610: 5/03/2010 10:10:56 PM - System Checkpoint
RP611: 6/03/2010 10:15:39 PM - System Checkpoint
RP612: 8/03/2010 10:01:18 AM - System Checkpoint
RP613: 9/03/2010 10:09:25 AM - System Checkpoint
RP614: 10/03/2010 10:46:27 AM - System Checkpoint
RP615: 11/03/2010 11:53:17 AM - System Checkpoint
RP616: 11/03/2010 10:37:26 PM - Software Distribution Service 3.0
RP617: 12/03/2010 10:43:14 PM - System Checkpoint
RP618: 14/03/2010 9:47:14 AM - System Checkpoint
RP619: 15/03/2010 10:25:31 AM - System Checkpoint
RP620: 16/03/2010 10:46:30 AM - System Checkpoint
RP621: 17/03/2010 8:20:56 PM - System Checkpoint
RP622: 18/03/2010 8:51:43 PM - System Checkpoint
RP623: 19/03/2010 10:43:21 PM - System Checkpoint
RP624: 21/03/2010 8:12:02 AM - System Checkpoint
RP625: 22/03/2010 9:50:13 AM - System Checkpoint
RP626: 23/03/2010 9:59:54 AM - System Checkpoint
RP627: 24/03/2010 10:21:08 AM - System Checkpoint
RP628: 25/03/2010 2:06:41 PM - System Checkpoint
RP629: 26/03/2010 8:03:33 PM - System Checkpoint
RP630: 27/03/2010 9:54:43 PM - System Checkpoint
RP631: 28/03/2010 9:59:00 PM - System Checkpoint
RP632: 29/03/2010 10:06:08 PM - System Checkpoint
RP633: 30/03/2010 10:06:13 PM - System Checkpoint
RP634: 31/03/2010 10:15:40 PM - Software Distribution Service 3.0
RP635: 2/04/2010 9:34:37 AM - System Checkpoint
RP636: 3/04/2010 7:00:56 PM - System Checkpoint
RP637: 4/04/2010 10:12:02 AM - Restore Operation
RP638: 4/04/2010 10:17:17 AM - Restore Operation

==== Installed Programs ======================

4Videosoft DVD to QuickTime Converter
Adobe Acrobat 6.0.1 Professional - English, Français, Deutsch
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe MPEG Encoder
Adobe Photoshop CS
Adobe Premiere 6.5
Adobe Reader 8
Age of Mythology
Age of Mythology - The Titans Expansion
Apple Software Update
Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
Canon CanoCraft CS-P 3.7
Canon iP4200
Canon Setup Utility 2.0
Canon Utilities Easy-PhotoPrint
Canon Utilities Easy-PrintToolBox
Cashflow Manager 3
CD-LabelPrint
Common-Use Signing Interface
Creative Mass Storage Drivers
Creative MediaSource
Creative System Information
Critical Update for Windows Media Player 11 (KB959772)
CyberLink PowerDirector
DivX Web Player
DVD Flick 1.3.0.7
DVD Shrink 3.2
Easy-WebPrint
Efficient Diary 1.76
Ewisoft Website Builder (include eCommerce Builder) Version 5
Fax Machine 4.33
Free DVD Ripper Version 2.25
Google Chrome
Google Earth
Google Update Helper
Google Updater
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Intel® Graphics Media Accelerator Driver
Java™ 6 Update 11
Kaiser Baas USB VIDEO TO DVD MAKER Device Driver
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office PowerPoint Viewer 2003
Microsoft Office XP Media Content
Microsoft Office XP Small Business
Microsoft Silverlight
Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Mirar
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
Nero 6 Ultra Edition
Norton AntiVirus
PhotoNow!
Platform
PowerDirector
PowerDVD
PowerProducer
QuickTime
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978706)
SMPlayer 0.6.7
Sony Media Manager 2.2
Sony Vegas 7.0
Sophos Anti-Rootkit 1.5.0
Spybot - Search & Destroy
Ulead Photo Express 2.0 SE
Ultra QuickTime Converter 3.2.0104
Uninstall 1.0.0.1
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB969497)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB898461)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VC80CRTRedist - 8.0.50727.762
VIA Platform Device Manager
VobSub v2.23 (Remove Only)
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live OneCare safety scanner
Windows Media Format 11 runtime
Windows Media Player 11
WinZip Self-Extractor
Xilisoft Video Converter Ultimate
Xvid 1.2.2 final uninstall

==== Event Viewer Messages From Past Week ========

4/04/2010 7:48:13 PM, error: atapi [9] - The device, \Device\Ide\IdePort2, did not respond within the timeout period.
4/04/2010 10:52:39 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000243' while processing the file 'SrtETmp' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
30/03/2010 7:55:08 AM, error: Dhcp [1002] - The IP address lease 192.168.1.100 for the Network Card with network address 0022156E075E has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
29/03/2010 11:27:53 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
2/04/2010 5:05:44 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
2/04/2010 5:05:44 PM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory.
2/04/2010 5:05:44 PM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver.

==== End Of File ===========================
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-05 10:08:17
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\User\LOCALS~1\Temp\axlyapob.sys


—- System - GMER 1.0.15 —-

SSDT 893471A8 ZwAlertResumeThread
SSDT 893479A8 ZwAlertThread
SSDT 893A8EF8 ZwAllocateVirtualMemory
SSDT 893AC0A8 ZwAssignProcessToJobObject
SSDT 89DB6F20 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xA8C26130]
SSDT 893A6150 ZwCreateMutant
SSDT 89331848 ZwCreateSymbolicLinkObject
SSDT 89331108 ZwCreateThread
SSDT 893AC168 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xA8C263B0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xA8C26910]
SSDT 893B80D8 ZwDuplicateObject
SSDT 89350F38 ZwFreeVirtualMemory
SSDT 893A6008 ZwImpersonateAnonymousToken
SSDT 893470E8 ZwImpersonateThread
SSDT 89CD84A8 ZwLoadDriver
SSDT 893A6790 ZwMapViewOfSection
SSDT 893A6090 ZwOpenEvent
SSDT 8934F008 ZwOpenProcess
SSDT 8934F058 ZwOpenProcessToken
SSDT 893A7130 ZwOpenSection
SSDT 8934F090 ZwOpenThread
SSDT 89331918 ZwProtectVirtualMemory
SSDT 893A4288 ZwResumeThread
SSDT 89347E78 ZwSetContextThread
SSDT 89347F38 ZwSetInformationProcess
SSDT 893AC008 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xA8C26B60]
SSDT 893A71F0 ZwSuspendProcess
SSDT 89347A68 ZwSuspendThread
SSDT 8934A6B8 ZwTerminateProcess
SSDT 89347B28 ZwTerminateThread
SSDT 893B8058 ZwUnmapViewOfSection
SSDT 893A8E28 ZwWriteVirtualMemory

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device -> \Driver\atapi \Device\Harddisk0\DR0 893FFAC8

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-
Hello

There are infections showing in your logs. To take care of these infections do the following.

Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.


Run Combofix:

Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode.
This allows us to more easily help you should your computer have a problem after an attempted removal of malware.
It is a simple procedure that will only take a few moments of your time.


Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.
Please continue as follows:

  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Click Yes to allow ComboFix to continue scanning for malware.

When the tool is finished, it will produce a report for you.

Please include the report in your next post:

C:\ComboFix.txt

"information and logs"

  • In your next post I need the following

  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
While running scan had nortons "tidserv request 2 blocked" even though nortons disabled
Data exclusion prevention - windows explorer . explorer not open
internet explorer make default pop up


ComboFix 10-04-03.02 - User 05/04/2010 13:29:38.1.4 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.2038.1444 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton AntiVirus *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\User\LOCALS~1\Temp\install_flash_player.exe
c:\documents and settings\User\Application Data\0200000099898b41600C.manifest
c:\documents and settings\User\Application Data\0200000099898b41600O.manifest
c:\documents and settings\User\Application Data\0200000099898b41600P.manifest
c:\documents and settings\User\Application Data\0200000099898b41600S.manifest
c:\documents and settings\User\Application Data\0200000099898b41665C.manifest
c:\documents and settings\User\Application Data\0200000099898b41665O.manifest
c:\documents and settings\User\Application Data\0200000099898b41665P.manifest
c:\documents and settings\User\Application Data\0200000099898b41665S.manifest
c:\documents and settings\User\Application Data\0200000099898b41821C.manifest
c:\documents and settings\User\Application Data\0200000099898b41821O.manifest
c:\documents and settings\User\Application Data\0200000099898b41821P.manifest
c:\documents and settings\User\Application Data\0200000099898b41821S.manifest
c:\documents and settings\User\Application Data\0200000099898b41867C.manifest
c:\documents and settings\User\Application Data\0200000099898b41867O.manifest
c:\documents and settings\User\Application Data\0200000099898b41867P.manifest
c:\documents and settings\User\Application Data\0200000099898b41867S.manifest
c:\documents and settings\User\Local Settings\Application Data\{31CFCDBC-11FD-4F87-9B55-78107CC179F8}
c:\documents and settings\User\Local Settings\Application Data\{31CFCDBC-11FD-4F87-9B55-78107CC179F8}\chrome.manifest
c:\documents and settings\User\Local Settings\Application Data\{31CFCDBC-11FD-4F87-9B55-78107CC179F8}\chrome\content\_cfg.js
c:\documents and settings\User\Local Settings\Application Data\{31CFCDBC-11FD-4F87-9B55-78107CC179F8}\chrome\content\overlay.xul
c:\documents and settings\User\Local Settings\Application Data\{31CFCDBC-11FD-4F87-9B55-78107CC179F8}\install.rdf
c:\windows\AppPatch\AcAdProc.dll
c:\windows\system32\707620946
c:\windows\system32\unrar.exe
C:\xcrashdump.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_FCI
——-\Legacy_ICF


((((((((((((((((((((((((( Files Created from 2010-03-05 to 2010-04-05 )))))))))))))))))))))))))))))))
.

2010-04-05 00:53 . 2010-02-03 09:00 84912 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100404.020\NAVENG.SYS
2010-04-05 00:53 . 2010-02-03 09:00 1324720 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100404.020\NAVEX15.SYS
2010-04-05 00:53 . 2009-10-25 18:32 177520 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100404.020\NAVENG32.DLL
2010-04-05 00:53 . 2009-10-25 18:32 1647984 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100404.020\NAVEX32A.DLL
2010-04-05 00:53 . 2009-12-09 09:00 2747440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100404.020\CCERASER.DLL
2010-04-05 00:53 . 2009-10-25 18:32 371248 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100404.020\EECTRL.SYS
2010-04-05 00:53 . 2009-10-25 18:32 259440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100404.020\ECMSVR32.DLL
2010-04-05 00:53 . 2009-10-25 18:32 102448 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100404.020\ERASER.SYS
2010-04-04 07:41 . 2010-04-04 07:41 ——– d—–w- c:\program files\Sophos
2010-04-03 08:33 . 2010-04-03 08:33 ——– d—–w- c:\documents and settings\LocalService\Application Data\AdobeUM
2010-04-03 08:33 . 2010-04-03 08:33 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-04-02 10:13 . 2010-04-02 10:13 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-04-02 10:13 . 2010-04-02 10:13 ——– d—–w- c:\documents and settings\NetworkService\Application Data\AdobeUM
2010-04-02 02:28 . 2010-04-03 20:45 120 —-a-w- c:\windows\Xbejinodu.dat
2010-04-02 02:28 . 2010-04-03 20:44 0 —-a-w- c:\windows\Mjimujoxumu.bin
2010-04-02 02:24 . 2010-04-02 02:24 45056 —-a-w- c:\windows\ftxa07573.exe
2010-03-26 08:42 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100326.001\IDSvix86.sys
2010-03-26 08:42 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100326.001\Scxpx86.dll
2010-03-26 08:42 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100326.001\IDSxpx86.dll
2010-03-26 08:42 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100326.001\IDSviA64.sys
2010-03-26 08:42 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100326.001\IDSXpx86.sys
2010-03-23 23:16 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100317.002\IDSvix86.sys
2010-03-23 23:16 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100317.002\IDSXpx86.sys
2010-03-23 23:16 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100317.002\Scxpx86.dll
2010-03-23 23:16 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100317.002\IDSxpx86.dll
2010-03-23 23:16 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100317.002\IDSviA64.sys
2010-03-21 21:46 . 2010-03-21 21:46 ——– d—–w- c:\program files\EwisoftWeb
2010-03-21 21:46 . 2010-03-21 21:46 ——– d—–w- c:\documents and settings\All Users\Application Data\EwisoftWeb
2010-03-10 21:48 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100310.001\IDSvix86.sys
2010-03-10 21:48 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100310.001\IDSXpx86.sys
2010-03-10 21:48 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100310.001\Scxpx86.dll
2010-03-10 21:48 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100310.001\IDSxpx86.dll
2010-03-10 21:48 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100310.001\IDSviA64.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-04 10:53 . 2009-01-23 07:06 ——– d—–w- c:\documents and settings\User\Application Data\LimeWire
2010-04-04 10:18 . 2009-05-21 03:39 ——– d—–w- c:\program files\Ultra QuickTime Converter
2010-04-04 01:25 . 2008-04-14 12:00 8832 —-a-w- c:\windows\system32\drivers\rasacd.sys
2010-04-03 23:39 . 2009-02-02 11:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-04-03 23:23 . 2009-02-02 11:49 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-04-02 06:15 . 2009-02-04 01:01 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-02 06:15 . 2009-06-01 10:11 5918776 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-03-30 10:00 . 2009-03-10 06:23 ——– d—–w- c:\documents and settings\User\Application Data\AdobeUM
2010-03-29 13:46 . 2009-02-04 01:01 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-29 13:45 . 2009-02-04 01:01 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-10 21:44 . 2009-11-11 08:00 79488 —-a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-26 23:26 . 2010-02-26 23:26 ——– d—–w- c:\documents and settings\User\Application Data\AVG8
2010-02-25 07:43 . 2010-02-25 07:43 ——– d—–w- c:\program files\Trymedia
2010-02-25 06:24 . 2008-04-14 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-11 11:08 . 2009-05-17 02:26 ——– d—–w- c:\program files\Google
2010-01-18 03:36 . 2009-01-19 10:15 86480 —-a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-04-13 14:10 . 2009-05-26 07:47 96512 —-a-w- c:\program files\atapi.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-17 39408]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-21 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-21 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-21 137752]
"HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2008-04-10 29757440]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-19 136600]
"Easy-PrintToolBox"="c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-14 409600]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"PE2CKFNT SE"="c:\program files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe" [1998-07-03 25088]

c:\documents and settings\User\Start Menu\Programs\Startup\
OCRAWARE.lnk - c:\oplimit\OCRAWARE.EXE [2009-3-8 51360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-10-24 217194]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-1-20 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Photo Express Calendar Checker SE.lnk - c:\program files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe [2009-3-8 55296]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0jixx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3etxx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3woxx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4mlxx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati5qpxx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati6ayxx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati7tcxx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati8xexx.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"e:\\programs\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\rmiregistry.exe"=

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1008000.029\SymEFA.sys [28/01/2010 10:22 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NAV\1008000.029\BHDrvx86.sys [28/01/2010 10:22 AM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1008000.029\cchpx86.sys [28/01/2010 10:21 AM 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100326.001\IDSXpx86.sys [26/03/2010 6:42 PM 329592]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe [28/01/2010 10:21 AM 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [26/08/2009 6:00 PM 102448]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [19/01/2009 2:15 PM 222976]
S0 ati0jixx;ati0jixx;c:\windows\system32\Drivers\ati0jixx.sys –> c:\windows\system32\Drivers\ati0jixx.sys [?]
S0 ati3etxx;ati3etxx;c:\windows\system32\Drivers\ati3etxx.sys –> c:\windows\system32\Drivers\ati3etxx.sys [?]
S0 ati3woxx;ati3woxx;c:\windows\system32\Drivers\ati3woxx.sys –> c:\windows\system32\Drivers\ati3woxx.sys [?]
S0 ati4mlxx;ati4mlxx;c:\windows\system32\Drivers\ati4mlxx.sys –> c:\windows\system32\Drivers\ati4mlxx.sys [?]
S0 ati5qpxx;ati5qpxx;c:\windows\system32\Drivers\ati5qpxx.sys –> c:\windows\system32\Drivers\ati5qpxx.sys [?]
S0 ati6ayxx;ati6ayxx;c:\windows\system32\Drivers\ati6ayxx.sys –> c:\windows\system32\Drivers\ati6ayxx.sys [?]
S0 ati7tcxx;ati7tcxx;c:\windows\system32\Drivers\ati7tcxx.sys –> c:\windows\system32\Drivers\ati7tcxx.sys [?]
S0 ati8xexx;ati8xexx;c:\windows\system32\Drivers\ati8xexx.sys –> c:\windows\system32\Drivers\ati8xexx.sys [?]
S2 gupdate1c9d697d19c9338;Google Update Service (gupdate1c9d697d19c9338);c:\program files\Google\Update\GoogleUpdate.exe [17/05/2009 12:32 PM 133104]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\aspi32.sys [21/05/2009 1:21 PM 16512]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\30.tmp –> c:\windows\system32\30.tmp [?]
S3 Winpnsem;Winpnsem; [x]
.
Contents of the 'Scheduled Tasks' folder

2010-02-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 01:34]

2010-04-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-17 02:26]

2010-04-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-17 02:32]

2010-04-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-17 02:32]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.abc.net.au/
mSearch Bar = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
HKCU-Run-DriverCure - c:\program files\ParetoLogic\DriverCure\DriverCure.exe
HKLM-Run-Fax Machine - (no file)
HKLM-Run-EfficientDiary - (no file)
Notify-dsmobkzx - dsmobkzx32.dll



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-05 13:41
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x89427AC8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba0ecf28
\Driver\ACPI -> ACPI.sys @ 0xb9f7fcb8
\Driver\atapi -> atapi.sys @ 0xb9f37852
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller -> SendCompleteHandler -> NDIS.sys @ 0xb9df4bb0
PacketIndicateHandler -> NDIS.sys @ 0xb9e01a21
SendHandler -> NDIS.sys @ 0xb9ddf87b
user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.8.0.41\diMaster.dll\" /prefetch:1"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\30.tmp"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(460)
c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(520)
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(2128)
c:\windows\system32\WININET.dll
c:\oplimit\oahook32.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\CTsvcCDA.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\system32\igfxsrvc.exe
c:\oplimit\ocrawr32.exe
.
**************************************************************************
.
Completion time: 2010-04-05 13:47:31 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-05 03:47

Pre-Run: 226,923,765,760 bytes free
Post-Run: 228,945,559,552 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 3389C5323C375361DDE1157C9DC6835F
Greetings

Here is what I would like you to do next

TDSSKiller:

  • Please Download TDSSKiller.zip and save it on your desktop.
  • extract (unzip) its contents to your Desktop.
  • double-click the TDSSKiller Folder on your desktop.
  • right-click on TDSSKiller.exe and click Copy then Paste it directly on to your Desktop.
  • Highlight and copy the text in the codebox below.
"%userprofile%\Desktop\TDSSKiller.exe" -v
  • Click Start, click Run… and paste the text above into the Open: line and click OK.
  • If malicious services or files have been detected, the utility will prompt to reboot the PC in order to complete the disinfection procedure. Please reboot when prompted.
  • After reboot, the driver will delete malicious registry keys and files as well as remove itself from the services list.
  • a log file should be created on your C: drive named something like TDSSKiller 2.1.1 Dec 20 2009 02:40:02
  • To find the log click Start then Computer then Vista ( C:).
  • Please post the contents of that log in your next reply

gringo
was not prompted to reboot?? 18:08:38:328 1900 TDSS rootkit removing tool [removed] Mar 22 2010 10:43:04 18:08:38:328 1900 ================================================================================ 18:08:38:328 1900 SystemInfo: 18:08:38:328 1900 OS Version: 5.1.2600 ServicePack: 3.0 18:08:38:328 1900 Product type: Workstation 18:08:38:328 1900 ComputerName: OWNER-92DFBD76A 18:08:38:328 1900 UserName: User 18:08:38:328 1900 Windows directory: C:\WINDOWS 18:08:38:328 1900 Processor architecture: Intel x86 18:08:38:328 1900 Number of processors: 4 18:08:38:328 1900 Page size: 0x1000 18:08:38:328 1900 Boot type: Normal boot 18:08:38:328 1900 ================================================================================ 18:08:38:328 1900 UnloadDriverW: NtUnloadDriver error 2 18:08:38:328 1900 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2 18:08:38:437 1900 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system 18:08:38:437 1900 wfopen_ex: MyNtCreateFileW error 32 (C0000043) 18:08:38:437 1900 wfopen_ex: Trying to KLMD file open 18:08:38:437 1900 wfopen_ex: File opened ok (Flags 2) 18:08:38:437 1900 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software 18:08:38:437 1900 wfopen_ex: MyNtCreateFileW error 32 (C0000043) 18:08:38:437 1900 wfopen_ex: Trying to KLMD file open 18:08:38:437 1900 wfopen_ex: File opened ok (Flags 2) 18:08:38:437 1900 Initialize success 18:08:38:437 1900 18:08:38:437 1900 Scanning Services … 18:08:38:796 1900 Raw services enum returned 347 services 18:08:38:812 1900 18:08:38:812 1900 Scanning Kernel memory … 18:08:38:812 1900 Devices to scan: 4 18:08:38:812 1900 18:08:38:812 1900 Driver Name: Disk 18:08:38:812 1900 IRP_MJ_CREATE : BA0EEBB0 18:08:38:812 1900 IRP_MJ_CREATE_NAMED_PIPE : 804F4562 18:08:38:812 1900 IRP_MJ_CLOSE : BA0EEBB0 18:08:38:812 1900 IRP_MJ_READ : BA0E8D1F 18:08:38:812 1900 IRP_MJ_WRITE : BA0E8D1F 18:08:38:812 1900 IRP_MJ_QUERY_INFORMATION : 804F4562 18:08:38:812 1900 IRP_MJ_SET_INFORMATION : 804F4562 18:08:38:812 1900 IRP_MJ_QUERY_EA : 804F4562 18:08:38:812 1900 IRP_MJ_SET_EA : 804F4562 18:08:38:812 1900 IRP_MJ_FLUSH_BUFFERS : BA0E92E2 18:08:38:812 1900 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562 18:08:38:812 1900 IRP_MJ_SET_VOLUME_INFORMATION : 804F4562 18:08:38:812 1900 IRP_MJ_DIRECTORY_CONTROL : 804F4562 18:08:38:812 1900 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562 18:08:38:812 1900 IRP_MJ_DEVICE_CONTROL : BA0E93BB 18:08:38:812 1900 IRP_MJ_INTERNAL_DEVICE_CONTROL : BA0ECF28 18:08:38:812 1900 IRP_MJ_SHUTDOWN : BA0E92E2 18:08:38:812 1900 IRP_MJ_LOCK_CONTROL : 804F4562 18:08:38:812 1900 IRP_MJ_CLEANUP : 804F4562 18:08:38:812 1900 IRP_MJ_CREATE_MAILSLOT : 804F4562 18:08:38:812 1900 IRP_MJ_QUERY_SECURITY : 804F4562 18:08:38:812 1900 IRP_MJ_SET_SECURITY : 804F4562 18:08:38:812 1900 IRP_MJ_POWER : BA0EAC82 18:08:38:812 1900 IRP_MJ_SYSTEM_CONTROL : BA0EF99E 18:08:38:812 1900 IRP_MJ_DEVICE_CHANGE : 804F4562 18:08:38:812 1900 IRP_MJ_QUERY_QUOTA : 804F4562 18:08:38:812 1900 IRP_MJ_SET_QUOTA : 804F4562 18:08:38:812 1900 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1 18:08:38:812 1900 18:08:38:812 1900 Driver Name: USBSTOR 18:08:38:812 1900 IRP_MJ_CREATE : BA3CD218 18:08:38:812 1900 IRP_MJ_CREATE_NAMED_PIPE : 804F4562 18:08:38:812 1900 IRP_MJ_CLOSE : BA3CD218 18:08:38:812 1900 IRP_MJ_READ : BA3CD23C 18:08:38:812 1900 IRP_MJ_WRITE : BA3CD23C 18:08:38:812 1900 IRP_MJ_QUERY_INFORMATION : 804F4562 18:08:38:812 1900 IRP_MJ_SET_INFORMATION : 804F4562 18:08:38:812 1900 IRP_MJ_QUERY_EA : 804F4562 18:08:38:812 1900 IRP_MJ_SET_EA : 804F4562 18:08:38:812 1900 IRP_MJ_FLUSH_BUFFERS : 804F4562 18:08:38:812 1900 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562 18:08:38:812 1900 IRP_MJ_SET_VOLUME_INFORMATION : 804F4562 18:08:38:812 1900 IRP_MJ_DIRECTORY_CONTROL : 804F4562 18:08:38:812 1900 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562 18:08:38:812 1900 IRP_MJ_DEVICE_CONTROL : BA3CD180 18:08:38:812 1900 IRP_MJ_INTERNAL_DEVICE_CONTROL : BA3C89E6 18:08:38:812 1900 IRP_MJ_SHUTDOWN : 804F4562 18:08:38:812 1900 IRP_MJ_LOCK_CONTROL : 804F4562 18:08:38:812 1900 IRP_MJ_CLEANUP : 804F4562 18:08:38:812 1900 IRP_MJ_CREATE_MAILSLOT : 804F4562 18:08:38:812 1900 IRP_MJ_QUERY_SECURITY : 804F4562 18:08:38:812 1900 IRP_MJ_SET_SECURITY : 804F4562 18:08:38:812 1900 IRP_MJ_POWER : BA3CC5F0 18:08:38:812 1900 IRP_MJ_SYSTEM_CONTROL : BA3CAA6E 18:08:38:812 1900 IRP_MJ_DEVICE_CHANGE : 804F4562 18:08:38:812 1900 IRP_MJ_QUERY_QUOTA : 804F4562 18:08:38:812 1900 IRP_MJ_SET_QUOTA : 804F4562 18:08:38:828 1900 C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: 1 18:08:38:828 1900 18:08:38:828 1900 Driver Name: Disk 18:08:38:828 1900 IRP_MJ_CREATE : BA0EEBB0 18:08:38:828 1900 IRP_MJ_CREATE_NAMED_PIPE : 804F4562 18:08:38:828 1900 IRP_MJ_CLOSE : BA0EEBB0 18:08:38:828 1900 IRP_MJ_READ : BA0E8D1F 18:08:38:828 1900 IRP_MJ_WRITE : BA0E8D1F 18:08:38:828 1900 IRP_MJ_QUERY_INFORMATION : 804F4562 18:08:38:828 1900 IRP_MJ_SET_INFORMATION : 804F4562 18:08:38:828 1900 IRP_MJ_QUERY_EA : 804F4562 18:08:38:828 1900 IRP_MJ_SET_EA : 804F4562 18:08:38:828 1900 IRP_MJ_FLUSH_BUFFERS : BA0E92E2 18:08:38:828 1900 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562 18:08:38:828 1900 IRP_MJ_SET_VOLUME_INFORMATION : 804F4562 18:08:38:828 1900 IRP_MJ_DIRECTORY_CONTROL : 804F4562 18:08:38:828 1900 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562 18:08:38:828 1900 IRP_MJ_DEVICE_CONTROL : BA0E93BB 18:08:38:828 1900 IRP_MJ_INTERNAL_DEVICE_CONTROL : BA0ECF28 18:08:38:828 1900 IRP_MJ_SHUTDOWN : BA0E92E2 18:08:38:828 1900 IRP_MJ_LOCK_CONTROL : 804F4562 18:08:38:828 1900 IRP_MJ_CLEANUP : 804F4562 18:08:38:828 1900 IRP_MJ_CREATE_MAILSLOT : 804F4562 18:08:38:828 1900 IRP_MJ_QUERY_SECURITY : 804F4562 18:08:38:828 1900 IRP_MJ_SET_SECURITY : 804F4562 18:08:38:828 1900 IRP_MJ_POWER : BA0EAC82 18:08:38:828 1900 IRP_MJ_SYSTEM_CONTROL : BA0EF99E 18:08:38:828 1900 IRP_MJ_DEVICE_CHANGE : 804F4562 18:08:38:828 1900 IRP_MJ_QUERY_QUOTA : 804F4562 18:08:38:828 1900 IRP_MJ_SET_QUOTA : 804F4562 18:08:38:828 1900 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1 18:08:38:828 1900 18:08:38:828 1900 Driver Name: atapi 18:08:38:828 1900 IRP_MJ_CREATE : 89427AC8 18:08:38:828 1900 IRP_MJ_CREATE_NAMED_PIPE : 89427AC8 18:08:38:828 1900 IRP_MJ_CLOSE : 89427AC8 18:08:38:828 1900 IRP_MJ_READ : 89427AC8 18:08:38:828 1900 IRP_MJ_WRITE : 89427AC8 18:08:38:828 1900 IRP_MJ_QUERY_INFORMATION : 89427AC8 18:08:38:828 1900 IRP_MJ_SET_INFORMATION : 89427AC8 18:08:38:828 1900 IRP_MJ_QUERY_EA : 89427AC8 18:08:38:828 1900 IRP_MJ_SET_EA : 89427AC8 18:08:38:828 1900 IRP_MJ_FLUSH_BUFFERS : 89427AC8 18:08:38:828 1900 IRP_MJ_QUERY_VOLUME_INFORMATION : 89427AC8 18:08:38:828 1900 IRP_MJ_SET_VOLUME_INFORMATION : 89427AC8 18:08:38:828 1900 IRP_MJ_DIRECTORY_CONTROL : 89427AC8 18:08:38:828 1900 IRP_MJ_FILE_SYSTEM_CONTROL : 89427AC8 18:08:38:828 1900 IRP_MJ_DEVICE_CONTROL : 89427AC8 18:08:38:828 1900 IRP_MJ_INTERNAL_DEVICE_CONTROL : 89427AC8 18:08:38:828 1900 IRP_MJ_SHUTDOWN : 89427AC8 18:08:38:828 1900 IRP_MJ_LOCK_CONTROL : 89427AC8 18:08:38:828 1900 IRP_MJ_CLEANUP : 89427AC8 18:08:38:828 1900 IRP_MJ_CREATE_MAILSLOT : 89427AC8 18:08:38:828 1900 IRP_MJ_QUERY_SECURITY : 89427AC8 18:08:38:828 1900 IRP_MJ_SET_SECURITY : 89427AC8 18:08:38:828 1900 IRP_MJ_POWER : 89427AC8 18:08:38:828 1900 IRP_MJ_SYSTEM_CONTROL : 89427AC8 18:08:38:828 1900 IRP_MJ_DEVICE_CHANGE : 89427AC8 18:08:38:828 1900 IRP_MJ_QUERY_QUOTA : 89427AC8 18:08:38:828 1900 IRP_MJ_SET_QUOTA : 89427AC8 18:08:38:828 1900 Driver "atapi" infected by TDSS rootkit! 18:08:38:843 1900 C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: 1 18:08:38:843 1900 File "C:\WINDOWS\system32\DRIVERS\atapi.sys" infected by TDSS rootkit … 18:08:38:843 1900 Processing driver file: C:\WINDOWS\system32\DRIVERS\atapi.sys 18:08:38:843 1900 ProcessDirEnumEx: FindFirstFile(C:\WINDOWS\system32\DriverStore\FileRepository\*) error 3 18:08:39:125 1900 vfvi6 18:08:39:187 1900 !dsvbh1 18:08:39:687 1900 dsvbh2 18:08:39:687 1900 fdfb2 18:08:39:687 1900 Backup copy found, using it.. 18:08:39:750 1900 will be cured on next reboot 18:08:39:750 1900 Reboot required for cure complete.. 18:08:39:781 1900 Cure on reboot scheduled successfully 18:08:39:781 1900 18:08:39:781 1900 Completed 18:08:39:781 1900 18:08:39:781 1900 Results: 18:08:39:781 1900 Memory objects infected / cured / cured on reboot: 1 / 0 / 0 18:08:39:781 1900 Registry objects infected / cured / cured on reboot: 0 / 0 / 0 18:08:39:781 1900 File objects infected / cured / cured on reboot: 1 / 0 / 1 18:08:39:781 1900 18:08:39:781 1900 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system 18:08:39:781 1900 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software 18:08:39:781 1900 UnloadDriverW: NtUnloadDriver error 1 18:08:39:781 1900 KLMD(ARK) unloaded successfully
Greetings

let me know how the computer is doing after the scan

:Run CFScript:

Open Notepad and copy/paste the text in the box into the window:

File::
c:\windows\Xbejinodu.dat
c:\windows\Mjimujoxumu.bin
c:\windows\ftxa07573.exe

Registry::
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati0jixx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3etxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3woxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati4mlxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati5qpxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati6ayxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati7tcxx.sys]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati8xexx.sys]

Driver::
ati0jixx
ati3etxx
ati3woxx
ati4mlxx
ati5qpxx
ati6ayxx
ati7tcxx
ati8xexx
Winpnsem


Save it to your desktop as CFScript.txt

Refering to the picture above, drag CFScript.txt into ComboFix.exe
[external image: Posted Image]
This will let ComboFix run again.
Restart if you have to.
Save the produced logfile to your desktop.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

"information and logs"

  • In your next post I need the following

  • log from combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
Still same problems

ComboFix 10-04-03.02 - User 05/04/2010 21:41:32.2.4 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.2038.1479 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\User\Desktop\CFScript.txt
AV: Norton AntiVirus *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}

FILE ::
"c:\windows\ftxa07573.exe"
"c:\windows\Mjimujoxumu.bin"
"c:\windows\Xbejinodu.dat"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\ftxa07573.exe
c:\windows\Mjimujoxumu.bin
c:\windows\Xbejinodu.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_ati0jixx
——-\Service_ati3etxx
——-\Service_ati3woxx
——-\Service_ati4mlxx
——-\Service_ati5qpxx
——-\Service_ati6ayxx
——-\Service_ati7tcxx
——-\Service_ati8xexx
——-\Service_Winpnsem


((((((((((((((((((((((((( Files Created from 2010-03-05 to 2010-04-05 )))))))))))))))))))))))))))))))
.

2010-04-05 00:53 . 2010-02-03 09:00 84912 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100404.020\NAVENG.SYS
2010-04-05 00:53 . 2010-02-03 09:00 1324720 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100404.020\NAVEX15.SYS
2010-04-05 00:53 . 2009-10-25 18:32 177520 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100404.020\NAVENG32.DLL
2010-04-05 00:53 . 2009-10-25 18:32 1647984 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100404.020\NAVEX32A.DLL
2010-04-05 00:53 . 2009-12-09 09:00 2747440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100404.020\CCERASER.DLL
2010-04-05 00:53 . 2009-10-25 18:32 371248 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100404.020\EECTRL.SYS
2010-04-05 00:53 . 2009-10-25 18:32 259440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100404.020\ECMSVR32.DLL
2010-04-05 00:53 . 2009-10-25 18:32 102448 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100404.020\ERASER.SYS
2010-04-04 07:41 . 2010-04-04 07:41 ——– d—–w- c:\program files\Sophos
2010-04-03 08:33 . 2010-04-03 08:33 ——– d—–w- c:\documents and settings\LocalService\Application Data\AdobeUM
2010-04-03 08:33 . 2010-04-03 08:33 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-04-02 10:13 . 2010-04-02 10:13 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-04-02 10:13 . 2010-04-02 10:13 ——– d—–w- c:\documents and settings\NetworkService\Application Data\AdobeUM
2010-03-26 08:42 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100326.001\IDSvix86.sys
2010-03-26 08:42 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100326.001\Scxpx86.dll
2010-03-26 08:42 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100326.001\IDSxpx86.dll
2010-03-26 08:42 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100326.001\IDSviA64.sys
2010-03-26 08:42 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100326.001\IDSXpx86.sys
2010-03-23 23:16 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100317.002\IDSvix86.sys
2010-03-23 23:16 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100317.002\IDSXpx86.sys
2010-03-23 23:16 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100317.002\Scxpx86.dll
2010-03-23 23:16 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100317.002\IDSxpx86.dll
2010-03-23 23:16 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100317.002\IDSviA64.sys
2010-03-21 21:46 . 2010-03-21 21:46 ——– d—–w- c:\program files\EwisoftWeb
2010-03-21 21:46 . 2010-03-21 21:46 ——– d—–w- c:\documents and settings\All Users\Application Data\EwisoftWeb
2010-03-10 21:48 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100310.001\IDSvix86.sys
2010-03-10 21:48 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100310.001\IDSXpx86.sys
2010-03-10 21:48 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100310.001\Scxpx86.dll
2010-03-10 21:48 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100310.001\IDSxpx86.dll
2010-03-10 21:48 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100310.001\IDSviA64.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-05 09:19 . 2008-04-14 12:00 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-04-04 10:53 . 2009-01-23 07:06 ——– d—–w- c:\documents and settings\User\Application Data\LimeWire
2010-04-04 10:18 . 2009-05-21 03:39 ——– d—–w- c:\program files\Ultra QuickTime Converter
2010-04-04 01:25 . 2008-04-14 12:00 8832 —-a-w- c:\windows\system32\drivers\rasacd.sys
2010-04-03 23:39 . 2009-02-02 11:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-04-03 23:23 . 2009-02-02 11:49 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-04-02 06:15 . 2009-02-04 01:01 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-02 06:15 . 2009-06-01 10:11 5918776 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-03-30 10:00 . 2009-03-10 06:23 ——– d—–w- c:\documents and settings\User\Application Data\AdobeUM
2010-03-29 13:46 . 2009-02-04 01:01 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-29 13:45 . 2009-02-04 01:01 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-10 21:44 . 2009-11-11 08:00 79488 —-a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-26 23:26 . 2010-02-26 23:26 ——– d—–w- c:\documents and settings\User\Application Data\AVG8
2010-02-25 07:43 . 2010-02-25 07:43 ——– d—–w- c:\program files\Trymedia
2010-02-25 06:24 . 2008-04-14 12:00 916480 ——w- c:\windows\system32\wininet.dll
2010-02-11 11:08 . 2009-05-17 02:26 ——– d—–w- c:\program files\Google
2010-01-18 03:36 . 2009-01-19 10:15 86480 —-a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-04-13 14:10 . 2009-05-26 07:47 96512 —-a-w- c:\program files\atapi.sys
.

((((((((((((((((((((((((((((( SnapShot@2010-04-05_03.41.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-04-05 11:50 . 2010-04-05 11:50 16384 c:\windows\Temp\Perflib_Perfdata_780.dat
+ 2010-04-05 11:50 . 2010-04-05 11:50 16384 c:\windows\Temp\Perflib_Perfdata_728.dat
+ 2008-04-14 12:00 . 2010-04-05 09:24 75452 c:\windows\system32\perfc009.dat
- 2008-04-14 12:00 . 2010-04-05 00:31 75452 c:\windows\system32\perfc009.dat
+ 2008-04-14 12:00 . 2010-04-05 09:24 450960 c:\windows\system32\perfh009.dat
- 2008-04-14 12:00 . 2010-04-05 00:31 450960 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-17 39408]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-21 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-21 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-21 137752]
"HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2008-04-10 29757440]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-19 136600]
"Easy-PrintToolBox"="c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-14 409600]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"PE2CKFNT SE"="c:\program files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe" [1998-07-03 25088]

c:\documents and settings\User\Start Menu\Programs\Startup\
OCRAWARE.lnk - c:\oplimit\OCRAWARE.EXE [2009-3-8 51360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-10-24 217194]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-1-20 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Photo Express Calendar Checker SE.lnk - c:\program files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe [2009-3-8 55296]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"e:\\programs\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\rmiregistry.exe"=

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1008000.029\SymEFA.sys [28/01/2010 10:22 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NAV\1008000.029\BHDrvx86.sys [28/01/2010 10:22 AM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1008000.029\cchpx86.sys [28/01/2010 10:21 AM 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100326.001\IDSXpx86.sys [26/03/2010 6:42 PM 329592]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe [28/01/2010 10:21 AM 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [26/08/2009 6:00 PM 102448]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [19/01/2009 2:15 PM 222976]
S2 gupdate1c9d697d19c9338;Google Update Service (gupdate1c9d697d19c9338);c:\program files\Google\Update\GoogleUpdate.exe [17/05/2009 12:32 PM 133104]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\aspi32.sys [21/05/2009 1:21 PM 16512]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\30.tmp –> c:\windows\system32\30.tmp [?]
.
Contents of the 'Scheduled Tasks' folder

2010-02-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 01:34]

2010-04-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-17 02:26]

2010-04-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-17 02:32]

2010-04-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-17 02:32]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.abc.net.au/
mSearch Bar = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-klmdb.sys



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-05 21:50
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x892D4AC8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba0ecf28
\Driver\ACPI -> ACPI.sys @ 0xb9f7fcb8
\Driver\atapi -> atapi.sys @ 0xb9f37852
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller -> SendCompleteHandler -> NDIS.sys @ 0xb9df4bb0
PacketIndicateHandler -> NDIS.sys @ 0xb9e01a21
SendHandler -> NDIS.sys @ 0xb9ddf87b
user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.8.0.41\diMaster.dll\" /prefetch:1"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\30.tmp"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(452)
c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(512)
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(3292)
c:\windows\system32\WININET.dll
c:\oplimit\oahook32.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\CTsvcCDA.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\system32\igfxsrvc.exe
c:\oplimit\ocrawr32.exe
.
**************************************************************************
.
Completion time: 2010-04-05 21:56:19 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-05 11:56
ComboFix2.txt 2010-04-05 03:47

Pre-Run: 228,989,784,064 bytes free
Post-Run: 228,951,154,688 bytes free

- - End Of File - - EC9AEF20ABFEEF815CCF9306CD747C34
Greetings

"Still same problems" - please tell me more about the problems

I woulde like you to rerun TDDSkiller then run a new scan for me

TDSSKiller:

  • double-click the TDSSKiller Folder on your desktop.
  • right-click on TDSSKiller.exe and click Copy then Paste it directly on to your Desktop.
  • Highlight and copy the text in the codebox below.
"%userprofile%\Desktop\TDSSKiller.exe" -v
  • Click Start, click Run… and paste the text above into the Open: line and click OK.
  • If malicious services or files have been detected, the utility will prompt to reboot the PC in order to complete the disinfection procedure. Please reboot when prompted.
  • After reboot, the driver will delete malicious registry keys and files as well as remove itself from the services list.
  • a log file should be created on your C: drive named something like TDSSKiller 2.1.1 Dec 20 2009 02:40:02
  • To find the log click Start then Computer then Vista ( C:).
  • Please post the contents of that log in your next reply


Download and run OTL:

Download OTL by Old Timer and save it to your Desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in
    • netsvcs
      %SYSTEMDRIVE%\*.exe
      /md5start
      eventlog.dll
      scecli.dll
      netlogon.dll
      cngaudit.dll
      sceclt.dll
      ntelogon.dll
      logevent.dll
      iaStor.sys
      nvstor.sys
      atapi.sys
      IdeChnDr.sys
      viasraid.sys
      AGP440.sys
      vaxscsi.sys
      nvatabus.sys
      viamraid.sys
      nvata.sys
      nvgts.sys
      iastorv.sys
      ViPrt.sys
      eNetHook.dll
      ahcix86.sys
      KR10N.sys
      nvstor32.sys
      ahcix86s.sys
      nvrd32.sys
      symmpi.sys
      adp3132.sys
      mv61xx.sys
      /md5stop
      %systemroot%\*. /mp /s
      CREATERESTOREPOINT
      %systemroot%\system32\*.dll /lockedfiles
      %systemroot%\Tasks\*.job /lockedfiles
      %systemroot%\system32\drivers\*.sys /lockedfiles
      %systemroot%\System32\config\*.sav
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them if you need to start a new topic.

"information and logs"

  • In your next post I need the following

  • new log from TDDskiller
  • log from OTL
  • please give me more details of your problems
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
Still getting nortons warning - tidserv reqest 2 blocked
still getting browser redirected

08:15:50:078 3348 TDSS rootkit removing tool [removed] Mar 22 2010 10:43:04
08:15:50:093 3348 ================================================================================
08:15:50:093 3348 SystemInfo:

08:15:50:093 3348 OS Version: 5.1.2600 ServicePack: 3.0
08:15:50:093 3348 Product type: Workstation
08:15:50:093 3348 ComputerName: OWNER-92DFBD76A
08:15:50:093 3348 UserName: User
08:15:50:093 3348 Windows directory: C:\WINDOWS
08:15:50:093 3348 Processor architecture: Intel x86
08:15:50:093 3348 Number of processors: 4
08:15:50:093 3348 Page size: 0x1000
08:15:50:093 3348 Boot type: Normal boot
08:15:50:093 3348 ================================================================================
08:15:50:093 3348 UnloadDriverW: NtUnloadDriver error 1
08:15:50:093 3348 ForceUnloadDriverW: UnloadDriverW(klmd21) error 1
08:15:50:140 3348 LoadDriverW: Driver already loaded
08:15:50:140 3348 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
08:15:50:140 3348 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
08:15:50:140 3348 wfopen_ex: Trying to KLMD file open
08:15:50:140 3348 wfopen_ex: File opened ok (Flags 2)
08:15:50:140 3348 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
08:15:50:140 3348 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
08:15:50:140 3348 wfopen_ex: Trying to KLMD file open
08:15:50:140 3348 wfopen_ex: File opened ok (Flags 2)
08:15:50:140 3348 Initialize success
08:15:50:140 3348
08:15:50:140 3348 Scanning Services …
08:15:50:609 3348 Raw services enum returned 339 services
08:15:50:609 3348
08:15:50:609 3348 Scanning Kernel memory …
08:15:50:609 3348 Devices to scan: 2
08:15:50:609 3348
08:15:50:609 3348 Driver Name: Disk
08:15:50:609 3348 IRP_MJ_CREATE : BA0EEBB0
08:15:50:609 3348 IRP_MJ_CREATE_NAMED_PIPE : 804F4562
08:15:50:609 3348 IRP_MJ_CLOSE : BA0EEBB0
08:15:50:609 3348 IRP_MJ_READ : BA0E8D1F
08:15:50:609 3348 IRP_MJ_WRITE : BA0E8D1F
08:15:50:609 3348 IRP_MJ_QUERY_INFORMATION : 804F4562
08:15:50:609 3348 IRP_MJ_SET_INFORMATION : 804F4562
08:15:50:609 3348 IRP_MJ_QUERY_EA : 804F4562
08:15:50:609 3348 IRP_MJ_SET_EA : 804F4562
08:15:50:609 3348 IRP_MJ_FLUSH_BUFFERS : BA0E92E2
08:15:50:609 3348 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4562
08:15:50:609 3348 IRP_MJ_SET_VOLUME_INFORMATION : 804F4562
08:15:50:609 3348 IRP_MJ_DIRECTORY_CONTROL : 804F4562
08:15:50:609 3348 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4562
08:15:50:609 3348 IRP_MJ_DEVICE_CONTROL : BA0E93BB
08:15:50:609 3348 IRP_MJ_INTERNAL_DEVICE_CONTROL : BA0ECF28
08:15:50:609 3348 IRP_MJ_SHUTDOWN : BA0E92E2
08:15:50:609 3348 IRP_MJ_LOCK_CONTROL : 804F4562
08:15:50:609 3348 IRP_MJ_CLEANUP : 804F4562
08:15:50:609 3348 IRP_MJ_CREATE_MAILSLOT : 804F4562
08:15:50:609 3348 IRP_MJ_QUERY_SECURITY : 804F4562
08:15:50:609 3348 IRP_MJ_SET_SECURITY : 804F4562
08:15:50:609 3348 IRP_MJ_POWER : BA0EAC82
08:15:50:609 3348 IRP_MJ_SYSTEM_CONTROL : BA0EF99E
08:15:50:609 3348 IRP_MJ_DEVICE_CHANGE : 804F4562
08:15:50:609 3348 IRP_MJ_QUERY_QUOTA : 804F4562
08:15:50:609 3348 IRP_MJ_SET_QUOTA : 804F4562
08:15:50:625 3348 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
08:15:50:625 3348
08:15:50:625 3348 Driver Name: atapi
08:15:50:625 3348 IRP_MJ_CREATE : 890FBAC8
08:15:50:625 3348 IRP_MJ_CREATE_NAMED_PIPE : 890FBAC8
08:15:50:625 3348 IRP_MJ_CLOSE : 890FBAC8
08:15:50:625 3348 IRP_MJ_READ : 890FBAC8
08:15:50:625 3348 IRP_MJ_WRITE : 890FBAC8
08:15:50:625 3348 IRP_MJ_QUERY_INFORMATION : 890FBAC8
08:15:50:625 3348 IRP_MJ_SET_INFORMATION : 890FBAC8
08:15:50:625 3348 IRP_MJ_QUERY_EA : 890FBAC8
08:15:50:625 3348 IRP_MJ_SET_EA : 890FBAC8
08:15:50:625 3348 IRP_MJ_FLUSH_BUFFERS : 890FBAC8
08:15:50:625 3348 IRP_MJ_QUERY_VOLUME_INFORMATION : 890FBAC8
08:15:50:625 3348 IRP_MJ_SET_VOLUME_INFORMATION : 890FBAC8
08:15:50:625 3348 IRP_MJ_DIRECTORY_CONTROL : 890FBAC8
08:15:50:625 3348 IRP_MJ_FILE_SYSTEM_CONTROL : 890FBAC8
08:15:50:625 3348 IRP_MJ_DEVICE_CONTROL : 890FBAC8
08:15:50:625 3348 IRP_MJ_INTERNAL_DEVICE_CONTROL : 890FBAC8
08:15:50:625 3348 IRP_MJ_SHUTDOWN : 890FBAC8
08:15:50:625 3348 IRP_MJ_LOCK_CONTROL : 890FBAC8
08:15:50:625 3348 IRP_MJ_CLEANUP : 890FBAC8
08:15:50:625 3348 IRP_MJ_CREATE_MAILSLOT : 890FBAC8
08:15:50:625 3348 IRP_MJ_QUERY_SECURITY : 890FBAC8
08:15:50:625 3348 IRP_MJ_SET_SECURITY : 890FBAC8
08:15:50:625 3348 IRP_MJ_POWER : 890FBAC8
08:15:50:625 3348 IRP_MJ_SYSTEM_CONTROL : 890FBAC8
08:15:50:625 3348 IRP_MJ_DEVICE_CHANGE : 890FBAC8
08:15:50:625 3348 IRP_MJ_QUERY_QUOTA : 890FBAC8
08:15:50:625 3348 IRP_MJ_SET_QUOTA : 890FBAC8
08:15:50:625 3348 Driver "atapi" infected by TDSS rootkit!
08:15:50:625 3348 C:\WINDOWS\system32\drivers\tsk7.tmp - Verdict: 3
08:15:50:625 3348
08:15:50:625 3348 Completed
08:15:50:625 3348
08:15:50:625 3348 Results:
08:15:50:625 3348 Memory objects infected / cured / cured on reboot: 1 / 0 / 0
08:15:50:640 3348 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
08:15:50:640 3348 File objects infected / cured / cured on reboot: 0 / 0 / 0
08:15:50:640 3348
08:15:50:640 3348 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
08:15:50:640 3348 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
08:15:50:640 3348 UnloadDriverW: NtUnloadDriver error 1
08:15:50:640 3348 KLMD(ARK) unloaded successfully
OTL Extras logfile created on: 6/04/2010 8:26:48 AM - Run 1
OTL by OldTimer - Version 3.2.1.0 Folder = C:\Documents and Settings\User\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 67.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 213.24 Gb Free Space | 71.54% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OWNER-92DFBD76A
Current User Name: User
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"E:\programs\LimeWire\LimeWire.exe" = E:\programs\LimeWire\LimeWire.exe:*:Enabled:LimeWire – File not found
"C:\Program Files\Java\jre6\bin\rmiregistry.exe" = C:\Program Files\Java\jre6\bin\rmiregistry.exe:*:Disabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{110E7958-3EE1-4684-9168-CD5D73A2CDDD}" = Mirar
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{251C3815-7A55-4607-A82D-C3B98F0FBAB8}" = Sony Vegas 7.0
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{2E0C1913-886B-4C5C-8DAF-D1E649CE5FCC}" = Creative MediaSource
"{2EAF7E61-068E-11DF-953C-005056806466}" = Google Earth
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{5AE91C01-5906-11D5-A50C-006067797177}" = Cashflow Manager 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{71A41426-C7A4-4DCF-A9ED-C5B4B105ED1D}" = Sony Media Manager 2.2
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90300409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Media Content
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{91130409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Small Business
"{9811A185-3D3D-11D6-9E14-00036D172B00}" = Adobe MPEG Encoder
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-1033-F400-7760-000000000001}" = Adobe Acrobat 6.0.1 Professional - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-A80000000002}" = Adobe Reader 8
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B7A0CE06-068E-11D6-97FD-0050BACBF861}" = PowerProducer
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{FB3BE405-6BF0-490A-84B3-00611385EA0D}" = Common-Use Signing Interface
"4Videosoft DVD to QuickTime Converter_is1" = 4Videosoft DVD to QuickTime Converter
"Adobe Atmosphere Player" = Adobe Atmosphere Player for Acrobat and Adobe Reader
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Premiere 6.5" = Adobe Premiere 6.5
"Age of Mythology 1.0" = Age of Mythology
"Age of Mythology Expansion Pack 1.0" = Age of Mythology - The Titans Expansion
"CanoCraft CS-P 3.7" = Canon CanoCraft CS-P 3.7
"Canon Setup Utility 2.0" = Canon Setup Utility 2.0
"CANONBJ_Deinstall_CNMCP78.DLL" = Canon iP4200
"Common-Use Signing Interface" = Common-Use Signing Interface
"Creative Mass Storage Drivers" = Creative Mass Storage Drivers
"DVD Flick_is1" = DVD Flick 1.3.0.7
"DVD Shrink_is1" = DVD Shrink 3.2
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-PrintToolBox" = Canon Utilities Easy-PrintToolBox
"Easy-WebPrint" = Easy-WebPrint
"Efficient Diary_is1" = Efficient Diary 1.76
"Ewisoft Website Builder (include eCommerce Builder)_is1" = Ewisoft Website Builder (include eCommerce Builder) Version 5
"Fax Machine_is1" = Fax Machine 4.33
"Free DVD Ripper 2.25_is1" = Free DVD Ripper Version 2.25
"Google Chrome" = Google Chrome
"Google Updater" = Google Updater
"HDMI" = Intel® Graphics Media Accelerator Driver
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaNavigation.CDLabelPrint" = CD-LabelPrint
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MuVo Driver" = Creative Mass Storage Drivers
"NAV" = Norton AntiVirus
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"SMPlayer" = SMPlayer 0.6.7
"Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.0
"SysInfo" = Creative System Information
"TVEpaDrv" = Kaiser Baas USB VIDEO TO DVD MAKER Device Driver
"Ulead Photo Express 2.0 SE" = Ulead Photo Express 2.0 SE
"Ultra QuickTime Converter_is1" = Ultra QuickTime Converter 3.2.0104
"Uninstall_is1" = Uninstall 1.0.0.1
"VobSub" = VobSub v2.23 (Remove Only)
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinZip Self-Extractor" = WinZip Self-Extractor
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xilisoft Video Converter Ultimate" = Xilisoft Video Converter Ultimate
"Xvid_is1" = Xvid 1.2.2 final uninstall

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/04/2010 7:23:06 PM | Computer Name = OWNER-92DFBD76A | Source = Application Error | ID = 1000
Description = Faulting application spybotsd.exe, version 1.6.2.46, faulting module
spybotsd.exe, version 1.6.2.46, fault address 0x00001941.

Error - 4/04/2010 2:59:25 AM | Computer Name = OWNER-92DFBD76A | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

Error - 4/04/2010 5:31:54 PM | Computer Name = OWNER-92DFBD76A | Source = Application Error | ID = 1004
Description = Faulting application svchost.exe, version 0.0.0.0, faulting module
unknown, version 0.0.0.0, fault address 0x00000000.

Error - 4/04/2010 5:38:37 PM | Computer Name = OWNER-92DFBD76A | Source = Application Error | ID = 1000
Description = Faulting application , version 0.0.0.0, faulting module unknown, version
0.0.0.0, fault address 0x00000000.

Error - 4/04/2010 5:40:20 PM | Computer Name = OWNER-92DFBD76A | Source = Application Error | ID = 1000
Description = Faulting application chrome.exe, version 0.0.0.0, faulting module
chrome.dll, version 4.1.249.1045, fault address 0x0001b1a1.

Error - 4/04/2010 5:42:23 PM | Computer Name = OWNER-92DFBD76A | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 4/04/2010 5:42:23 PM | Computer Name = OWNER-92DFBD76A | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 4/04/2010 5:42:26 PM | Computer Name = OWNER-92DFBD76A | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 4/04/2010 6:13:05 PM | Computer Name = OWNER-92DFBD76A | Source = Application Error | ID = 1004
Description = Faulting application svchost.exe, version 0.0.0.0, faulting module
unknown, version 0.0.0.0, fault address 0x00000000.

Error - 4/04/2010 11:31:54 PM | Computer Name = OWNER-92DFBD76A | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.5512, faulting
module unknown, version 0.0.0.0, fault address 0x715b9e59.

[ System Events ]
Error - 5/04/2010 7:50:41 AM | Computer Name = OWNER-92DFBD76A | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 5/04/2010 5:19:28 PM | Computer Name = OWNER-92DFBD76A | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 5/04/2010 5:19:28 PM | Computer Name = OWNER-92DFBD76A | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 5/04/2010 5:20:35 PM | Computer Name = OWNER-92DFBD76A | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.100 for the Network Card with network
address 0022156E075E has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).

Error - 5/04/2010 5:20:41 PM | Computer Name = OWNER-92DFBD76A | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 5/04/2010 5:20:41 PM | Computer Name = OWNER-92DFBD76A | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 5/04/2010 6:09:04 PM | Computer Name = OWNER-92DFBD76A | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000001'
while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring
the volume.

Error - 5/04/2010 6:09:04 PM | Computer Name = OWNER-92DFBD76A | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.

Error - 5/04/2010 6:09:04 PM | Computer Name = OWNER-92DFBD76A | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.

Error - 5/04/2010 6:09:21 PM | Computer Name = OWNER-92DFBD76A | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
i8042prt


< End of report >
OTL logfile created on: 6/04/2010 8:26:48 AM - Run 1
OTL by OldTimer - Version 3.2.1.0 Folder = C:\Documents and Settings\User\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 67.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.08 Gb Total Space | 213.24 Gb Free Space | 71.54% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OWNER-92DFBD76A
Current User Name: User
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/04/06 08:17:04 | 000,561,664 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
PRC - [2009/08/22 16:37:15 | 000,117,640 | R— | M] (Symantec Corporation) – C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe
PRC - [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) – C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008/04/14 22:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/04/14 22:00:00 | 000,420,864 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\ntvdm.exe
PRC - [2008/04/14 22:00:00 | 000,060,416 | —- | M] (Microsoft Corporation) – C:\Program Files\Outlook Express\msimn.exe
PRC - [2004/12/02 18:23:34 | 000,102,400 | —- | M] (Creative Technology Ltd) – C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
PRC - [2003/10/24 14:37:56 | 000,217,194 | —- | M] (Adobe Systems Inc.) – C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
PRC - [1998/07/08 12:01:28 | 000,055,296 | —- | M] (Ulead Systems, Inc.) – C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
PRC - [1998/03/19 14:22:02 | 000,041,984 | —- | M] (Caere Corporation) – C:\OPLIMIT\OCRAWR32.EXE


========== Modules (SafeList) ==========

MOD - [2010/04/06 08:17:04 | 000,561,664 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
MOD - [1998/07/11 13:34:52 | 000,135,680 | —- | M] (Caere Corporation) – C:\OPLIMIT\OAHOOK32.DLL


========== Win32 Services (SafeList) ==========

SRV - [2009/08/22 16:37:15 | 000,117,640 | R— | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe – (Norton AntiVirus)
SRV - [2002/12/17 16:26:22 | 007,520,337 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe – (MSSQL$SONY_MEDIAMGR)
SRV - [2002/12/17 16:23:30 | 000,311,872 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE – (SQLAgent$SONY_MEDIAMGR)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.abc.net.au/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 7E 57 48 04 18 2D 1A 49 98 97 19 51 ED E3 F9 AF [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


[2010/04/02 16:02:15 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/04/05 21:50:35 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O4 - HKLM..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [PE2CKFNT SE] C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe ()
O4 - HKCU..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Photo Express Calendar Checker SE.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe (Ulead Systems, Inc.)
O4 - Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE (Caere Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/19 14:07:40 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/01/19 23:45:43 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17746478449557504)

========== Files/Folders - Created Within 14 Days ==========

[2010/04/06 08:16:59 | 000,561,664 | —- | C] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2010/04/06 08:15:03 | 000,000,000 | —D | C] – C:\tds old log
[2010/04/06 08:09:38 | 000,036,488 | —- | C] (Kaspersky Lab, SLA) – C:\WINDOWS\System32\drivers\klmdb.sys
[2010/04/05 13:27:18 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/04/05 13:24:50 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/04/05 13:24:50 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/04/05 13:24:50 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/04/05 13:24:50 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/04/05 13:24:17 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/04/05 13:20:18 | 000,000,000 | —D | C] – C:\Qoobox
[2010/04/04 17:41:55 | 000,000,000 | —D | C] – C:\Program Files\Sophos
[2010/04/04 09:19:44 | 016,409,960 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\User\Desktop\spybotsd162.exe
[2010/04/03 18:33:04 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\AdobeUM
[2010/04/03 18:33:03 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2010/04/03 18:32:44 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/04/02 20:48:24 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/04/02 20:13:02 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\AdobeUM
[2010/04/02 20:13:02 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/04/02 20:12:52 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/04/02 16:37:42 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/04/02 14:16:54 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/04/02 14:10:55 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Sun
[2010/04/02 12:37:41 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/04/02 12:30:07 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/02/27 09:44:19 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/02/27 09:44:19 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/01/19 10:30:30 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\CyberLink
[2009/05/26 17:47:17 | 000,096,512 | —- | C] (Microsoft Corporation) – C:\Program Files\atapi.sys
[2009/05/18 06:58:57 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/05/17 12:33:13 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2009/03/12 06:57:00 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\Documents and Settings\User\Application Data\*.tmp files -> C:\Documents and Settings\User\Application Data\*.tmp -> ]

========== Files - Modified Within 14 Days ==========

[2010/04/06 08:17:04 | 000,561,664 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2010/04/06 08:13:16 | 000,535,230 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/04/06 08:13:16 | 000,450,960 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/04/06 08:13:16 | 000,075,452 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/04/06 08:09:38 | 000,036,488 | —- | M] (Kaspersky Lab, SLA) – C:\WINDOWS\System32\drivers\klmdb.sys
[2010/04/06 08:09:13 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/04/06 08:09:11 | 000,000,394 | —- | M] () – C:\WINDOWS\ULEAD32.INI
[2010/04/06 08:08:53 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/04/06 08:08:48 | 000,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/04/06 08:08:47 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/04/06 08:08:42 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/04/06 08:07:25 | 008,912,896 | —- | M] () – C:\Documents and Settings\User\ntuser.dat
[2010/04/06 08:07:25 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\User\ntuser.ini
[2010/04/06 08:07:20 | 000,000,757 | —- | M] () – C:\WINDOWS\oplimit.ini
[2010/04/06 07:29:03 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/04/05 21:51:23 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/04/05 21:50:35 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2010/04/05 18:40:09 | 003,174,328 | -H– | M] () – C:\Documents and Settings\User\Local Settings\Application Data\IconCache.db
[2010/04/05 18:15:08 | 000,019,968 | —- | M] () – C:\Documents and Settings\User\Desktop\TDSS rootkit removing tool.doc
[2010/04/05 17:55:39 | 000,154,469 | —- | M] () – C:\Documents and Settings\User\Desktop\tdsskiller.zip
[2010/04/05 13:27:28 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/04/05 13:19:59 | 003,907,280 | R— | M] () – C:\Documents and Settings\User\Desktop\ComboFix.exe
[2010/04/05 08:16:27 | 000,284,915 | —- | M] () – C:\Documents and Settings\User\Desktop\gmer.zip
[2010/04/05 07:55:55 | 000,525,824 | —- | M] () – C:\Documents and Settings\User\Desktop\dds.scr
[2010/04/05 07:49:17 | 000,050,477 | —- | M] () – C:\Documents and Settings\User\Desktop\Defogger.exe
[2010/04/04 20:18:15 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/04/04 20:18:14 | 000,000,108 | —- | M] () – C:\WINDOWS\System32\temp_0000_30437.aok
[2010/04/04 18:56:11 | 000,231,390 | —- | M] () – C:\Documents and Settings\User\Desktop\RootkitRevealer.zip
[2010/04/04 17:41:49 | 001,339,288 | —- | M] () – C:\Documents and Settings\User\Desktop\sar_15_sfx.exe
[2010/04/04 09:50:14 | 000,000,154 | —- | M] () – C:\WINDOWS\wininit.ini
[2010/04/04 09:21:13 | 000,000,933 | —- | M] () – C:\Documents and Settings\User\Desktop\Spybot - Search & Destroy.lnk
[2010/04/04 09:19:58 | 016,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\User\Desktop\spybotsd162.exe
[2010/04/04 08:30:52 | 000,220,160 | —- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/02 16:24:53 | 000,533,691 | —- | M] () – C:\Documents and Settings\User\Desktop\Main News - The Northern Rivers Echo Newspaper, Lismore.mht
[2010/04/01 07:30:01 | 000,001,813 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2010/03/30 19:00:39 | 000,001,186 | -HS- | M] () – C:\WINDOWS\System32\1213155173
[2010/03/29 23:46:30 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/29 23:45:52 | 000,020,824 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\Documents and Settings\User\Application Data\*.tmp files -> C:\Documents and Settings\User\Application Data\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/04/05 18:15:08 | 000,019,968 | —- | C] () – C:\Documents and Settings\User\Desktop\TDSS rootkit removing tool.doc
[2010/04/05 17:55:38 | 000,154,469 | —- | C] () – C:\Documents and Settings\User\Desktop\tdsskiller.zip
[2010/04/05 13:27:27 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/04/05 13:27:21 | 000,260,272 | —- | C] () – C:\cmldr
[2010/04/05 13:24:50 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/04/05 13:24:50 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/04/05 13:24:50 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/04/05 13:24:50 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/04/05 13:24:50 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/04/05 13:18:33 | 003,907,280 | R— | C] () – C:\Documents and Settings\User\Desktop\ComboFix.exe
[2010/04/05 08:16:22 | 000,284,915 | —- | C] () – C:\Documents and Settings\User\Desktop\gmer.zip
[2010/04/05 07:51:51 | 000,525,824 | —- | C] () – C:\Documents and Settings\User\Desktop\dds.scr
[2010/04/05 07:49:06 | 000,050,477 | —- | C] () – C:\Documents and Settings\User\Desktop\Defogger.exe
[2010/04/04 20:18:14 | 000,000,108 | —- | C] () – C:\WINDOWS\System32\temp_0000_30437.aok
[2010/04/04 18:56:10 | 000,231,390 | —- | C] () – C:\Documents and Settings\User\Desktop\RootkitRevealer.zip
[2010/04/04 17:41:43 | 001,339,288 | —- | C] () – C:\Documents and Settings\User\Desktop\sar_15_sfx.exe
[2010/04/04 09:21:13 | 000,000,933 | —- | C] () – C:\Documents and Settings\User\Desktop\Spybot - Search & Destroy.lnk
[2010/04/02 16:24:52 | 000,533,691 | —- | C] () – C:\Documents and Settings\User\Desktop\Main News - The Northern Rivers Echo Newspaper, Lismore.mht
[2010/01/26 19:32:07 | 002,255,360 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2010/01/26 19:32:07 | 000,395,776 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2010/01/26 19:32:07 | 000,262,144 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010/01/26 19:32:07 | 000,112,640 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2010/01/18 12:57:41 | 000,001,606 | —- | C] () – C:\WINDOWS\TVEpaDrv.ini
[2010/01/18 12:57:22 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\PsisDecd.dll
[2009/09/11 08:20:12 | 000,012,288 | —- | C] () – C:\Documents and Settings\User\Application Data\plugcach.fon
[2009/05/27 17:15:58 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\mdmparm.dll
[2009/05/27 17:15:58 | 000,006,144 | —- | C] () – C:\WINDOWS\System32\ClassXps.dll
[2009/05/21 13:39:30 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\AVEQT.dll
[2009/05/21 13:33:36 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\DVDIFOFilter.dll
[2009/05/21 13:21:17 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2009/05/21 13:21:17 | 000,819,200 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/05/21 13:21:17 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/04/13 12:58:56 | 000,000,067 | —- | C] () – C:\WINDOWS\AVIConverter.INI
[2009/03/08 12:43:46 | 000,000,604 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2009/03/08 12:43:46 | 000,000,047 | —- | C] () – C:\WINDOWS\OPLEInst.ini
[2009/03/08 12:43:07 | 000,000,757 | —- | C] () – C:\WINDOWS\oplimit.ini
[2009/03/08 12:42:06 | 000,000,394 | —- | C] () – C:\WINDOWS\ULEAD32.INI
[2009/03/08 11:32:52 | 000,015,488 | —- | C] () – C:\WINDOWS\System32\drivers\ScFBPNT2.sys
[2009/02/28 16:52:45 | 000,000,035 | —- | C] () – C:\WINDOWS\A5W.INI
[2009/02/04 10:50:07 | 000,000,154 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/02/02 12:52:33 | 000,000,551 | —- | C] () – C:\Documents and Settings\User\Application Data\AutoGK.ini
[2009/01/24 13:03:05 | 008,912,896 | —- | C] () – C:\Documents and Settings\User\ntuser.dat
[2009/01/23 11:03:04 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS78.DLL
[2009/01/20 08:50:47 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2009/01/19 20:22:52 | 000,220,160 | —- | C] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/19 20:22:52 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2009/01/19 14:14:30 | 000,147,456 | R— | C] () – C:\WINDOWS\System32\igfxCoIn_v4935.dll
[2009/01/19 14:11:55 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2009/01/19 14:11:54 | 000,013,195 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2009/01/19 14:11:47 | 000,012,536 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2009/01/19 14:11:09 | 000,000,278 | -HS- | C] () – C:\Documents and Settings\User\ntuser.ini
[2009/01/19 14:11:08 | 000,001,024 | -H– | C] () – C:\Documents and Settings\User\ntuser.dat.LOG
[2006/02/09 13:46:30 | 000,106,496 | —- | C] () – C:\WINDOWS\System32\VSHP1020.DLL
[2002/10/16 08:54:04 | 000,153,088 | —- | C] () – C:\WINDOWS\System32\unrar.dll

========== LOP Check ==========

[2009/05/05 08:56:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2009/11/15 16:56:24 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2009/02/24 19:44:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverCure
[2010/03/22 07:46:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EwisoftWeb
[2009/01/20 08:29:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\New Folder
[2009/02/16 09:20:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/09/11 07:58:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2009/01/20 16:32:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2009/07/14 13:14:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/02/18 12:56:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2009/02/22 15:40:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZipSE
[2009/08/20 13:32:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{4C0DBD62-F011-4A41-B11D-BE5CFA6DEDD7}
[2009/05/21 17:57:58 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Azureus
[2009/02/22 15:48:28 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\DriverCure
[2009/11/15 09:34:12 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Efficient Diary
[2009/05/21 13:39:15 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\GetRightToGo
[2010/04/04 20:53:26 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\LimeWire
[2009/02/04 19:18:59 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Netscape
[2009/01/20 16:39:22 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Publish Providers
[2010/01/03 11:43:29 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\SmartDraw
[2009/01/20 16:39:10 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Sony
[2009/01/20 15:11:08 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Sony Setup
[2009/02/20 18:19:11 | 000,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Xilisoft Corporation

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008/04/14 22:00:00 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys

< MD5 for: ATAPI.SYS >
[2008/04/14 22:00:00 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\Program Files\atapi.sys
[2010/04/05 19:19:20 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\dllcache\atapi.sys
[2010/04/06 08:08:04 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2008/04/14 22:00:00 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/14 22:00:00 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/14 22:00:00 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2008/04/14 22:00:00 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2007/01/12 21:30:08 | 000,007,216 | —- | M] () MD5=C2A279A458A06DE2C83D842AA042B5A8 – C:\Program Files\CyberLink\PowerDirector\EventLog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/14 22:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/14 22:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\dllcache\netlogon.dll
[2008/04/14 22:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2008/04/14 22:00:00 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/14 22:00:00 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\dllcache\scecli.dll
[2008/04/14 22:00:00 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2009/03/08 04:31:44 | 000,348,160 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtmsft.dll
[2009/03/08 04:31:38 | 000,216,064 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtrans.dll
[2008/04/14 22:00:00 | 000,068,768 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\mmsystem.dll
[2008/04/14 22:00:00 | 000,005,120 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\shell.dll
[2008/04/14 22:00:00 | 000,013,888 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\toolhelp.dll
[9 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >
[1 C:\WINDOWS\system32\drivers\*.tmp files -> C:\WINDOWS\system32\drivers\*.tmp -> ]

< %systemroot%\System32\config\*.sav >
[2009/01/19 23:49:01 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/01/19 23:49:01 | 001,064,960 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/01/19 23:49:01 | 000,905,216 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< End of report >
also started recieving error - iexplore.exe-application error the instruction at "0x03b37778"refered memory at 0x6bf54c08 the memory could not be read. click OK to terminate program
GMER:

I would like you to rerun gmer please

  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan..
[external image: Posted Image]
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "ark.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

please send me the report that it makes


gringo
after running GMER recieved following
- generic host process for win32 services has encountered a problem needs to close
- the instruction at 0x03b37776 refered memory at 0x6bf54c08 the memory could not be read
- desktop toolbar changed apperance
- could not open internet explorer or email
- had to restart computer

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-06 20:05:31
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\User\LOCALS~1\Temp\axlyapob.sys


—- System - GMER 1.0.15 —-

SSDT 89D7FEF8 ZwAlertResumeThread
SSDT 89D04468 ZwAlertThread
SSDT 89316CE8 ZwAllocateVirtualMemory
SSDT 89CF03A0 ZwAssignProcessToJobObject
SSDT 89DB6768 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xA84E6130]
SSDT 89BC4C10 ZwCreateMutant
SSDT 89B33DC0 ZwCreateSymbolicLinkObject
SSDT 893148E8 ZwCreateThread
SSDT 89CFFA50 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xA84E63B0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xA84E6910]
SSDT 89316FC0 ZwDuplicateObject
SSDT 8920E370 ZwFreeVirtualMemory
SSDT 89D80B28 ZwImpersonateAnonymousToken
SSDT 89D87C88 ZwImpersonateThread
SSDT 89B39E30 ZwLoadDriver
SSDT 89D89A80 ZwMapViewOfSection
SSDT 89D07EF8 ZwOpenEvent
SSDT 89A28D38 ZwOpenProcess
SSDT 89B1C400 ZwOpenProcessToken
SSDT 89CF6558 ZwOpenSection
SSDT 89A1CE38 ZwOpenThread
SSDT 895638F0 ZwProtectVirtualMemory
SSDT 892FA248 ZwResumeThread
SSDT 8955E220 ZwSetContextThread
SSDT 89210838 ZwSetInformationProcess
SSDT 89D7F6E0 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xA84E6B60]
SSDT 89CF6830 ZwSuspendProcess
SSDT 89D6BAE0 ZwSuspendThread
SSDT 8930A8E8 ZwTerminateProcess
SSDT 893128C0 ZwTerminateThread
SSDT 89B9FD38 ZwUnmapViewOfSection
SSDT 89A2FAB8 ZwWriteVirtualMemory

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device -> \Driver\atapi \Device\Harddisk0\DR0 890C5AC8

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-
Greetings

please read this post completly before you start and if you have any questions please ask. after you have read this post please print them out for easy reference

Create and Run Batch File

Open Notepad and copy/paste the entire contents of the codebox below, into Notepad:
@echo off
copy /y C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys c:\
del %0
Save the file to your DESKTOP as "fix.bat". Make sure to save it with the quotes.
Choose to Save type as - All Files and where to save - Desktop - then close the Notepad file.
It should look like this: 🖼Click to load external image (Posted Image)
Double-click on fix.bat to run it.

Print out these instructions to use while in the Recovery Console: (This is for XP only)
  • Restart your computer.
  • Before Windows loads, you will be prompted to choose which Operating System to start.
  • Use the up and down arrow key to select Microsoft Windows Recovery Console
  • You must enter which Windows installation to log onto. Type 1 and press 'Enter'.
  • At the C:\Windows prompt, type the following bolded entries, and press 'Enter' (note the spaces):

    cd c:\windows\system32\drivers
    ren atapi.sys atapi.old
    copy c:\atapi.sys c:\windows\system32\drivers
    exit


    You should see a message '1 file copied'. If you did not see that message, try again and ensure there is a space after the word copy and another space between the file paths.

    NOTE**(if you do not see 1 file copied on the screen, even after ensuring the commands are correct, rename the file back to it's original name by typing the following command then hitting Enter.
    ren atapi.old atapi.sys
    you should NOT be prompted to overwrite an existing file, but if you are, select No then type exit to restart and notify me of your results)

  • Type exit and press 'Enter'. Your computer should reboot.

now I would like you to run GMER again and send me the report

Gringo

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI