This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Stubborn Infection?

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello I picked up a nasty which seems to resist all attempts by MBAM to remove. Please see latest MBAM log below. Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Database version: 3965 Windows 5.1.2600 Service Pack 2 Internet Explorer 7.0.5730.13 07/04/2010 17:25:48 mbam-log-2010-04-07 (17-25-48).txt Scan type: Quick scan Objects scanned: 97890 Time elapsed: 2 minute(s), 3 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\uid (Malware.Trace) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Can anybody help me get rid of the infected item ?(despite what is said it has NOT been quarantined and removed - it reappears on subsequent MBAM scans) Thanks
Hello there, nelclaret

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

Please bear with me, I will post back to you as soon as I can.

IMPORTANT NOTE : Please do not delete anything unless instructed to.

**In any case where you happen to be busy or unable to give us a reply, we would be more than grateful if you keep us informed in advance and we will be more than happy to wait. :)
Hi,

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
===================================================

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries

===================================================

On your next reply please post :
OTL log
GMER log

Good Day!
Hello Conspire,

Thank you for looking at this problem.

Here are the logs as requested.

OTL logfile created on: 09/04/2010 09:28:24 - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\PC-User1\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,023.00 Mb Total Physical Memory | 663.00 Mb Available Physical Memory | 65.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 95.37 Gb Free Space | 85.32% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOME-PC
Current User Name: PC-User1
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\PC-User1\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe (Crawler.com)
PRC - C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe (Acronis)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ASUS\AASP\1.00.12\aaCenter.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\PC-User1\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\rsaenh.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\wsock32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (aswUpdSv) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (sp_rssrv) – C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)


========== Driver Services (SafeList) ==========

DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (aswMon2) – C:\WINDOWS\system32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswSP) – C:\WINDOWS\system32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\WINDOWS\system32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (aswTdi) – C:\WINDOWS\system32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswRdr) – C:\WINDOWS\system32\drivers\aswRdr.sys (ALWIL Software)
DRV - (Aavmker4) – C:\WINDOWS\system32\drivers\aavmker4.sys (ALWIL Software)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (sp_rsdrv2) – C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ()
DRV - (timounter) – C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (snapman) – C:\WINDOWS\system32\DRIVERS\snapman.sys (Acronis)
DRV - (tifsfilter) – C:\WINDOWS\system32\drivers\tifsfilt.sys (Acronis)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (AsIO) – C:\WINDOWS\system32\drivers\AsIO.sys ()
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (ZD1211U(Cable & Wireless)) Cable & Wireless 802.11g Series Wireless LAN USB(Cable & Wireless) – C:\WINDOWS\system32\drivers\ZD1211U.sys (ZyDAS Technology Corporation)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (bkn50USB) – C:\WINDOWS\system32\drivers\rt2500usb.sys (Ralink Technology Inc.)
DRV - (ZDPNDIS5) – C:\WINDOWS\system32\ZDPNDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (alcan5wn) SpeedTouch USB ADSL PPP Networking Driver (NDISWAN) – C:\WINDOWS\system32\drivers\alcan5wn.sys (THOMSON)
DRV - (alcaudsl) – C:\WINDOWS\system32\drivers\alcaudsl.sys (THOMSON)
DRV - (GT680x) – C:\WINDOWS\system32\drivers\GT680X.sys ( )


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.co.uk/
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://en-GB.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official"

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/08/12 22:23:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/06/21 13:54:58 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/06/21 13:54:58 | 000,000,000 | —D | M]

[2008/06/08 00:03:43 | 000,000,000 | —D | M] – C:\Documents and Settings\PC-User1\Application Data\Mozilla\Firefox\Profiles\7dha7iw5.default\extensions
[2008/02/10 22:51:02 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\PC-User1\Application Data\Mozilla\Firefox\Profiles\7dha7iw5.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2008/01/13 20:25:21 | 000,000,000 | —D | M] – C:\Documents and Settings\PC-User1\Application Data\Mozilla\Firefox\Profiles\7dha7iw5.default\extensions\[removed]
[2008/06/08 00:03:43 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2008/01/12 21:10:47 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2007/11/28 20:31:59 | 000,067,696 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\jar50.dll
[2007/11/28 20:31:59 | 000,054,376 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\jsd3250.dll
[2007/11/28 20:31:59 | 000,034,952 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\myspell.dll
[2007/11/28 20:31:59 | 000,046,720 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\spellchk.dll
[2007/11/28 20:31:59 | 000,172,144 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\xpinstal.dll
[2008/03/24 20:21:00 | 002,889,088 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll
[2006/06/15 11:24:15 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2006/06/15 11:24:15 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2006/06/15 11:24:15 | 000,001,077 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2006/09/11 15:39:34 | 000,000,831 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/04/07 16:30:49 | 000,000,000 | —- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [Acronis True Image Monitor] C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [AsusServiceProvider] C:\Program Files\ASUS\AASP\1.00.12\aaCenter.exe ()
O4 - HKLM..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.12\AsRunHelp.exe ()
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [SpywareTerminator] C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe (Crawler.com)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableProfileQuota = 1
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O8 - Extra context menu item: Search with Wanadoo - C:\WINDOWS\System32\WSBar.dll ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll (Sun Microsystems, Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/Facebo…toUploader5.cab (Facebook Photo Uploader 5)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} http://upload.facebook.com/controls/Facebo…Uploader4_5.cab (Facebook Photo Uploader 4)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx2.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\localsys64.exe) - C:\WINDOWS\localsys64.exe File not found
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O27 - HKLM IFEO\RapportMgmtService.exe: Debugger - ZASRAKOMONDOHUI31338.EXE File not found
O27 - HKLM IFEO\RapportService.exe: Debugger - ZASRAKOMONDOHUI31338.EXE File not found
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/01/12 18:47:47 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{aa431c24-e7ed-11dc-8122-000e50918fa0}\Shell - "" = AutoRun
O33 - MountPoints2\{aa431c24-e7ed-11dc-8122-000e50918fa0}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{aa431c24-e7ed-11dc-8122-000e50918fa0}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O33 - MountPoints2\{af35984c-fb52-11dc-8181-000e50918fa0}\Shell - "" = AutoRun
O33 - MountPoints2\{af35984c-fb52-11dc-8181-000e50918fa0}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{af35984c-fb52-11dc-8181-000e50918fa0}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2008/01/12 18:47:22 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

========== Files/Folders - Created Within 30 Days ==========

[2010/04/09 09:26:40 | 000,561,664 | —- | C] (OldTimer Tools) – C:\Documents and Settings\PC-User1\Desktop\OTL.exe
[2010/04/08 19:42:09 | 000,000,000 | RH-D | C] – C:\Documents and Settings\PC-User1\Recent
[2010/03/08 17:45:50 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/02/06 09:57:05 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/02/06 09:52:38 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2008/05/25 14:59:49 | 000,017,504 | R— | C] ( ) – C:\WINDOWS\System32\drivers\GT680X.sys
[2008/03/25 22:10:46 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Help
[2008/03/25 22:10:46 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Help
[2008/01/12 21:54:50 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2008/01/12 18:50:18 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2008/01/12 18:47:39 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/04/09 09:26:46 | 000,561,664 | —- | M] (OldTimer Tools) – C:\Documents and Settings\PC-User1\Desktop\OTL.exe
[2010/04/09 09:24:27 | 000,000,309 | —- | M] () – C:\WINDOWS\LEXSTAT.INI
[2010/04/09 09:07:49 | 000,356,120 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/04/09 09:07:49 | 000,311,934 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/04/09 09:07:49 | 000,040,196 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/04/09 09:07:03 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/04/09 09:07:00 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/04/09 09:03:55 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/04/09 09:03:42 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/04/09 09:03:35 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/04/08 19:45:36 | 005,242,880 | —- | M] () – C:\Documents and Settings\PC-User1\ntuser.dat
[2010/04/08 19:45:36 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\PC-User1\ntuser.ini
[2010/04/08 19:45:29 | 005,328,334 | -H– | M] () – C:\Documents and Settings\PC-User1\Local Settings\Application Data\IconCache.db
[2010/04/07 20:59:05 | 000,000,603 | —- | M] () – C:\WINDOWS\ULEAD32.INI
[2010/04/03 12:09:19 | 000,000,133 | —- | M] () – C:\Documents and Settings\PC-User1\default.pls
[2010/04/03 12:06:26 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/04/03 12:05:58 | 000,107,008 | —- | M] () – C:\Documents and Settings\PC-User1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/31 13:48:51 | 000,037,256 | —- | M] () – C:\Documents and Settings\PC-User1\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/03/30 00:46:30 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/30 00:45:52 | 000,020,824 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/29 11:57:03 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/03/28 21:06:00 | 000,068,608 | —- | M] () – C:\Documents and Settings\PC-User1\My Documents\Nursery meeting 29.3.10.doc
[2010/03/25 23:18:50 | 000,168,304 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/03/11 13:38:54 | 001,168,384 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\urlmon.dll
[2010/03/11 13:38:54 | 000,832,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wininet.dll
[2010/03/11 13:38:54 | 000,233,472 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\webcheck.dll
[2010/03/11 13:38:53 | 003,599,872 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtml.dll
[2010/03/11 13:38:53 | 000,671,232 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mstime.dll
[2010/03/11 13:38:53 | 000,671,232 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mstime.dll
[2010/03/11 13:38:53 | 000,477,696 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshtmled.dll
[2010/03/11 13:38:53 | 000,459,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeeds.dll
[2010/03/11 13:38:53 | 000,459,264 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2010/03/11 13:38:53 | 000,193,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msrating.dll
[2010/03/11 13:38:53 | 000,193,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msrating.dll
[2010/03/11 13:38:53 | 000,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\url.dll
[2010/03/11 13:38:53 | 000,105,984 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\url.dll
[2010/03/11 13:38:53 | 000,102,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\occache.dll
[2010/03/11 13:38:53 | 000,052,224 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\msfeedsbs.dll
[2010/03/11 13:38:53 | 000,052,224 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2010/03/11 13:38:53 | 000,044,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\pngfilt.dll
[2010/03/11 13:38:53 | 000,044,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pngfilt.dll
[2010/03/11 13:38:52 | 006,067,200 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2010/03/11 13:38:52 | 001,830,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\inetcpl.cpl
[2010/03/11 13:38:52 | 001,830,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetcpl.cpl
[2010/03/11 13:38:52 | 000,268,288 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2010/03/11 13:38:52 | 000,192,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iepeers.dll
[2010/03/11 13:38:52 | 000,192,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iepeers.dll
[2010/03/11 13:38:52 | 000,078,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieencode.dll
[2010/03/11 13:38:52 | 000,078,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieencode.dll
[2010/03/11 13:38:52 | 000,044,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iernonce.dll
[2010/03/11 13:38:52 | 000,044,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iernonce.dll
[2010/03/11 13:38:52 | 000,027,648 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\jsproxy.dll
[2010/03/11 13:38:52 | 000,027,648 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\jsproxy.dll
[2010/03/11 13:38:51 | 000,385,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\iedkcs32.dll
[2010/03/11 13:38:51 | 000,385,024 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iedkcs32.dll
[2010/03/11 13:38:51 | 000,380,928 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieapfltr.dll
[2010/03/11 13:38:51 | 000,380,928 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieapfltr.dll
[2010/03/11 13:38:51 | 000,347,136 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dxtmsft.dll
[2010/03/11 13:38:51 | 000,347,136 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dxtmsft.dll
[2010/03/11 13:38:51 | 000,230,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieaksie.dll
[2010/03/11 13:38:51 | 000,230,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieaksie.dll
[2010/03/11 13:38:51 | 000,214,528 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dxtrans.dll
[2010/03/11 13:38:51 | 000,214,528 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dxtrans.dll
[2010/03/11 13:38:51 | 000,153,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieakeng.dll
[2010/03/11 13:38:51 | 000,153,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieakeng.dll
[2010/03/11 13:38:51 | 000,133,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\extmgr.dll
[2010/03/11 13:38:51 | 000,124,928 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advpack.dll
[2010/03/11 13:38:51 | 000,063,488 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icardie.dll
[2010/03/11 13:38:51 | 000,017,408 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\corpol.dll
[2010/03/11 13:38:51 | 000,017,408 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\corpol.dll
[2010/03/10 14:18:46 | 000,389,120 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\html.iec
[2010/03/10 14:18:21 | 000,013,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ieudinit.exe
[2010/03/10 14:18:21 | 000,013,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieudinit.exe
[2010/03/10 14:18:20 | 000,070,656 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\ie4uinit.exe
[2010/03/10 14:18:20 | 000,070,656 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ie4uinit.exe
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/03/28 21:05:59 | 000,068,608 | —- | C] () – C:\Documents and Settings\PC-User1\My Documents\Nursery meeting 29.3.10.doc
[2010/03/08 21:53:56 | 000,010,250 | -HS- | C] () – C:\Documents and Settings\PC-User1\Local Settings\Application Data\N40fDO82
[2010/03/06 08:30:09 | 000,012,582 | -HS- | C] () – C:\Documents and Settings\PC-User1\Local Settings\Application Data\fXsMq7BWv
[2009/09/10 09:22:54 | 005,242,880 | —- | C] () – C:\Documents and Settings\PC-User1\ntuser.dat
[2009/06/21 13:54:58 | 000,000,031 | -H– | C] () – C:\WINDOWS\UKCpInfo.sys
[2008/07/13 08:00:58 | 000,008,701 | —- | C] () – C:\Documents and Settings\PC-User1\scan.log
[2008/05/25 16:00:49 | 000,000,073 | —- | C] () – C:\WINDOWS\WinInit.Ini
[2008/05/25 14:59:49 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\MKCoInstaller.dll
[2008/05/25 14:20:50 | 000,000,000 | —- | C] () – C:\WINDOWS\ui.INI
[2008/05/25 14:15:56 | 000,000,603 | —- | C] () – C:\WINDOWS\ULEAD32.INI
[2008/05/25 14:12:55 | 000,000,492 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2008/02/18 22:30:48 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2008/02/10 21:09:56 | 000,271,264 | —- | C] () – C:\WINDOWS\System32\VBRUN100.DLL
[2008/02/10 21:09:56 | 000,000,010 | —- | C] () – C:\WINDOWS\BestSol.ini
[2008/02/10 14:17:45 | 000,005,606 | —- | C] () – C:\WINDOWS\System32\stci.dll
[2008/02/10 12:31:07 | 000,000,133 | —- | C] () – C:\Documents and Settings\PC-User1\default.pls
[2008/02/10 12:30:51 | 000,107,008 | —- | C] () – C:\Documents and Settings\PC-User1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/10 12:30:36 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/02/10 11:37:32 | 000,000,309 | —- | C] () – C:\WINDOWS\LEXSTAT.INI
[2008/02/10 11:01:37 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\WSBar.dll
[2008/02/02 20:40:04 | 000,037,888 | —- | C] () – C:\WINDOWS\System32\setupnt.dll
[2008/01/27 20:55:28 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\InsDrvZD.dll
[2008/01/12 21:30:53 | 000,141,312 | —- | C] () – C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2008/01/12 20:56:49 | 000,024,576 | R— | C] () – C:\WINDOWS\System32\AsIO.dll
[2008/01/12 20:56:49 | 000,005,685 | R— | C] () – C:\WINDOWS\System32\drivers\AsIO.sys
[2008/01/12 20:56:17 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\vuins32.dll
[2008/01/12 20:53:02 | 000,016,174 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2008/01/12 20:53:00 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2008/01/12 20:52:57 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008/01/12 18:51:30 | 000,001,024 | -H– | C] () – C:\Documents and Settings\PC-User1\ntuser.dat.LOG
[2008/01/12 18:51:30 | 000,000,178 | -HS- | C] () – C:\Documents and Settings\PC-User1\ntuser.ini
[2007/03/27 10:45:22 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\sysres.dll

========== LOP Check ==========

[2008/01/13 20:37:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2010/03/09 17:02:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spyware Terminator
[2008/07/16 08:40:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/06/22 11:54:25 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2008/02/10 21:40:31 | 000,000,000 | —D | M] – C:\Documents and Settings\PC-User1\Application Data\123 Free Solitaire
[2008/02/02 20:44:15 | 000,000,000 | —D | M] – C:\Documents and Settings\PC-User1\Application Data\Acronis
[2010/03/24 13:32:08 | 000,000,000 | —D | M] – C:\Documents and Settings\PC-User1\Application Data\Spyware Terminator
[2010/03/29 11:57:03 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2006/02/28 13:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/04/13 19:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\agp440.sys
[2004/08/03 23:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\system32\dllcache\agp440.sys

< MD5 for: ATAPI.SYS >
[2006/02/28 13:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/04/13 19:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\atapi.sys
[2006/02/28 13:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\dllcache\atapi.sys
[2006/02/28 13:00:00 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/14 01:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\eventlog.dll
[2006/02/28 13:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2006/02/28 13:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/14 01:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\netlogon.dll
[2009/02/06 19:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 19:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2006/02/28 13:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\dllcache\netlogon.dll
[2006/02/28 13:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2006/02/28 13:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\dllcache\scecli.dll
[2006/02/28 13:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\scecli.dll
[2008/04/14 01:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2010/03/11 13:38:51 | 000,347,136 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtmsft.dll
[2010/03/11 13:38:51 | 000,214,528 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\dxtrans.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2008/01/12 18:35:19 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2008/01/12 18:35:19 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2008/01/12 18:35:19 | 000,905,216 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< >

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
OTL Extras logfile created on: 09/04/2010 09:28:24 - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\PC-User1\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,023.00 Mb Total Physical Memory | 663.00 Mb Available Physical Memory | 65.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 95.37 Gb Free Space | 85.32% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOME-PC
Current User Name: PC-User1
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" = C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger – File not found
"C:\Program Files\Windows Live\Messenger\livecall.exe" = C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone) – File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0EE11800-A1BD-11D3-BFEB-005004AF2D32}" = Risk II
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{31DABA20-10A1-4746-9D9F-57955B8DFF66}" = Free Games Offer, Desktop Shortcut
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{587178E7-B1DF-494E-9838-FA4DD36E873C}" = AsusUpdate
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{83C03FBE-4492-4133-BBAB-421CD88ADA32}" = OpenOffice.org 2.3
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA9768AA-FF0B-4C66-A085-31E934F77841}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{BD1DC860-2B0A-11D4-BD2E-00500480A380}" = Combat Mission
"{C151CE54-E7EA-4804-854B-F515368B0798}" = Athlon 64 Processor Driver
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{D41FAAA9-8048-4906-86B2-9AADEA1FA0B7}" = SpeedTouch USB Software
"{D9B4D7EE-481C-4C36-86AB-A8F7417725FF}" = LightScribe 1.6.43.1
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F61DD673-0030-4BB2-A382-7E57E97F1033}" = Nero 7 Essentials
"{F7338FA3-DAB5-49B2-900D-0AFB5760C166}" = PC Probe II
"123 Free Solitaire" = 123 Free Solitaire
"ABBYY FineReader 4.0 Sprint" = ABBYY FineReader 4.0 Sprint
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"avast!" = avast! Antivirus
"CCleaner" = CCleaner (remove only)
"CodeStuff Starter" = CodeStuff Starter
"Combat Mission 2" = Combat Mission 2
"Combat Mission 3 Afrika Korps" = Combat Mission 3 Afrika Korps
"Driver Genius Professional Edition_is1" = Driver Genius Professional Edition
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"Lexmark Z600 Series" = Lexmark Z600 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (2.0.0.11)" = Mozilla Firefox (2.0.0.11)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Patience_is1" = Patience 1.5 beta
"PC Pitstop Driver Alert_is1" = PC Pitstop Driver Alert 1.0
"RealAlt_is1" = Real Alternative 1.7.5
"RealPlayer 6.0" = RealPlayer
"Revo Uninstaller" = Revo Uninstaller 1.71
"Spyware Terminator_is1" = Spyware Terminator
"TrueImage" = Acronis True Image
"Ulead Photo Express 3.0 SE" = Ulead Photo Express 3.0 SE
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast Ethernet Adapter
"Wanadoo" = Wanadoo Search Toolbar
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Toolbar" = Yahoo! Toolbar
"YInstHelper" = Yahoo! Install Manager

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 03/08/2009 04:40:03 | Computer Name = HOME-PC | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\DCIM\100C3045\DSCI0228.JPG failed, 0000001E.

[ Application Events ]
Error - 25/03/2010 17:07:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =

Error - 26/03/2010 06:50:07 | Computer Name = HOME-PC | Source = Application Hang | ID = 1002
Description = Hanging application SUPERAntiSpyware.exe, version 4.34.0.1000, hang
module hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 28/03/2010 16:07:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =

Error - 28/03/2010 17:07:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =

Error - 29/03/2010 06:59:27 | Computer Name = HOME-PC | Source = Application Hang | ID = 1002
Description = Hanging application soffice.bin, version 2.3.9215.500, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 29/03/2010 11:07:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =

Error - 31/03/2010 05:07:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =

Error - 06/04/2010 11:07:07 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =

Error - 07/04/2010 11:07:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =

Error - 07/04/2010 13:07:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =

[ Application Events ]
Error - 25/03/2010 17:07:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =

Error - 26/03/2010 06:50:07 | Computer Name = HOME-PC | Source = Application Hang | ID = 1002
Description = Hanging application SUPERAntiSpyware.exe, version 4.34.0.1000, hang
module hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 28/03/2010 16:07:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =

Error - 28/03/2010 17:07:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =

Error - 29/03/2010 06:59:27 | Computer Name = HOME-PC | Source = Application Hang | ID = 1002
Description = Hanging application soffice.bin, version 2.3.9215.500, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 29/03/2010 11:07:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =

Error - 31/03/2010 05:07:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =

Error - 06/04/2010 11:07:07 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =

Error - 07/04/2010 11:07:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =

Error - 07/04/2010 13:07:05 | Computer Name = HOME-PC | Source = Google Update | ID = 20
Description =

[ System Events ]
Error - 07/04/2010 12:00:28 | Computer Name = HOME-PC | Source = Service Control Manager | ID = 7000
Description = The SASDIFSV service failed to start due to the following error: %%183


< End of report >GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-09 09:41:37
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\PC-User1\LOCALS~1\Temp\kxtdipow.sys


—- System - GMER 1.0.15 —-

SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwClose [0xAE222606]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateFile [0xAE22205A]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateKey [0xAE221D3C]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateSection [0xAE223652]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteKey [0xAE221E46]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteValueKey [0xAE221F30]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xAE12514C]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwLoadDriver [0xAE2228CC]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwOpenFile [0xAE222362]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xAE12564E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xAE12508C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xAE1250F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xAE12576E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xAE12572E]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwSetValueKey [0xAE221BBA]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwTerminateProcess [0xAE222814]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwWriteFile [0xAE222494]

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 snapman.sys (Acronis Snapshot API/Acronis)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\localsys64.exe 575592 bytes executable
File C:\WINDOWS\winmain32 0 bytes
File C:\WINDOWS\winmain32\windisi.nls 175711 bytes
File C:\WINDOWS\winmain32\winsys.nls 0 bytes

—- EOF - GMER 1.0.15 —-

Thank you and Good Day yourself!
Hello there,

***Read through this entire procedure and if you have any questions, please ask them before you begin. Then either print out, or copy this page to Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.

Please read through these instructions to familarize yourself with what to expect when this tool runs


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Good Monning.

Here is the combofix log as requested.

ComboFix 10-04-10.02 - PC-User1 11/04/2010 6:56.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1023.554 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100410-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\PC-User1\Start Menu\Programs\Download programs.url
c:\documents and settings\PC-User1\Start Menu\Programs\Games.url
c:\documents and settings\PC-User1\Start Menu\Programs\Translator.url
c:\documents and settings\PC-User1\Start Menu\Programs\Videos.url
c:\program files\Mozilla Firefox\components\npclntax.xpt

c:\windows\system32\proquota.exe . . . is missing!!

.
((((((((((((((((((((((((( Files Created from 2010-03-11 to 2010-04-11 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-28 19:31 . 2008-01-12 20:10 67696 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2007-11-28 19:31 . 2008-01-12 20:10 54376 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2007-11-28 19:31 . 2008-01-12 20:10 34952 —-a-w- c:\program files\mozilla firefox\components\myspell.dll
2007-11-28 19:31 . 2008-01-12 20:10 46720 —-a-w- c:\program files\mozilla firefox\components\spellchk.dll
2007-11-28 19:31 . 2008-01-12 20:10 172144 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-02-10 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-05-02 1817600]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2008-02-02 90112]
"Acronis True Image Monitor"="c:\program files\Acronis\TrueImage\TrueImageMonitor.exe" [2008-02-02 423258]
"AsusServiceProvider"="c:\program files\ASUS\AASP\1.00.12\aaCenter.exe" [2006-10-22 593920]
"AsusStartupHelp"="c:\program files\ASUS\AASP\1.00.12\AsRunHelp.exe" [2006-10-29 362496]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,c:\windows\localsys64.exe,"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-24 15:43 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=


R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 135664]
R3 bkn50USB;Belkin 54Mbps Wireless USB Network Adapter;c:\windows\system32\DRIVERS\rt2500usb.sys [2004-07-16 140416]
R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-03-01 1029456]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2010-03-08 12872]
R3 ZD1211U(Cable & Wireless);Cable & Wireless 802.11g Series Wireless LAN USB(Cable & Wireless);c:\windows\system32\DRIVERS\zd1211u.sys [2004-12-22 259584]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-06-22 64160]
S1 aswSP;avast! Self Protection; [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-03-08 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2010-03-08 66632]
S1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2008-05-02 141312]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-11-24 20560]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-04-19 13:23 452136 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-03-29 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 11:58]

2010-04-11 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-02-10 10:13]

2010-04-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 08:52]

2010-04-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 08:52]
.
.
——- Supplementary Scan ——-
.
uStart Page = www.google.co.uk/
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Search with Wanadoo - c:\windows\system32\WSBar.dll/VSearch.htm
FF - ProfilePath - c:\documents and settings\PC-User1\Application Data\Mozilla\Firefox\Profiles\7dha7iw5.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-GB.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-11 07:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\windows\localsys64.exe 575592 bytes executable
c:\windows\winmain32
c:\docume~1\PC-User1\LOCALS~1\Temp\Perflib_Perfdata_edc.dat 16384 bytes

scan completed successfully
hidden files: 3

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(548)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(604)
c:\windows\system32\wininet.dll
.
Completion time: 2010-04-11 07:03:47
ComboFix-quarantined-files.txt 2010-04-11 06:03

Pre-Run: 102,347,964,416 bytes free
Post-Run: 102,312,636,416 bytes free

Current=2 Default=2 Failed=1 LastKnownGood=3 Sets=1,2,3,6,7,8
- - End Of File - - B50A4AB3C4B4B51A2BD40F07F4DA5B50

Thanks.
Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

SRPeek::
C:\Windows\System32\proquota.exe

Rootkit::
C:\WINDOWS\localsys64.exe
C:\WINDOWS\winmain32

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\\windows\\system32\\userinit.exe,"

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

===================================================

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    proquota.*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Hello Actioned as per instructions. (Note: I am not altogether clear from your instructions whether you wanted to see the ComboFix log as well as the SystemLook. I am posting both.) ComboFix 10-04-10.02 - PC-User1 12/04/2010 20:39:44.3.1 - x86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1023.669 [GMT 1:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\PC-User1\Desktop\CFScript.txt AV: avast! antivirus 4.8.1368 [VPS 100412-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\proquota.exe . . . is missing!! . ((((((((((((((((((((((((( Files Created from 2010-03-12 to 2010-04-12 ))))))))))))))))))))))))))))))) . No new files created in this timespan . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-11-28 19:31 . 2008-01-12 20:10 67696 —-a-w- c:\program files\mozilla firefox\components\jar50.dll 2007-11-28 19:31 . 2008-01-12 20:10 54376 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll 2007-11-28 19:31 . 2008-01-12 20:10 34952 —-a-w- c:\program files\mozilla firefox\components\myspell.dll 2007-11-28 19:31 . 2008-01-12 20:10 46720 —-a-w- c:\program files\mozilla firefox\components\spellchk.dll 2007-11-28 19:31 . 2008-01-12 20:10 172144 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll . (((((((((((((((((((((((((((((((((((((((((( SR_Search )))))))))))))))))))))))))))))))))))))))))))))))))))))))) . ((((((((((((((((((((((((((((( SnapShot@2010-04-11_06.01.33 ))))))))))))))))))))))))))))))))))))))))) . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-02-10 68856] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000] "SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-05-02 1817600] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696] "Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2008-02-02 90112] "Acronis True Image Monitor"="c:\program files\Acronis\TrueImage\TrueImageMonitor.exe" [2008-02-02 423258] "AsusServiceProvider"="c:\program files\ASUS\AASP\1.00.12\aaCenter.exe" [2006-10-22 593920] "AsusStartupHelp"="c:\program files\ASUS\AASP\1.00.12\AsRunHelp.exe" [2006-10-29 362496] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="c:\windows\system32\userinit.exe,c:\windows\localsys64.exe," [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-24 15:43 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" SystemLook v1.0 by jpshortstuff (11.01.10) Log created at 20:53 on 12/04/2010 by PC-User1 (Administrator - Elevation successful) ========== filefind ========== Searching for "proquota.*" C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\proquota.exe –a— 50176 bytes [09:34 14/10/2008] [00:12 14/04/2008] F6465A2EEF75468988A4FCF124148FA8 -=End Of File=- [HKEY_LOCAL_MACHINE\software\microsoft\security center] Thank you
ComboFix 10-04-10.02 - PC-User1 12/04/2010 20:39:44.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1023.669 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\PC-User1\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100412-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\proquota.exe . . . is missing!!

.
((((((((((((((((((((((((( Files Created from 2010-03-12 to 2010-04-12 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-28 19:31 . 2008-01-12 20:10 67696 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2007-11-28 19:31 . 2008-01-12 20:10 54376 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2007-11-28 19:31 . 2008-01-12 20:10 34952 —-a-w- c:\program files\mozilla firefox\components\myspell.dll
2007-11-28 19:31 . 2008-01-12 20:10 46720 —-a-w- c:\program files\mozilla firefox\components\spellchk.dll
2007-11-28 19:31 . 2008-01-12 20:10 172144 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.

(((((((((((((((((((((((((((((((((((((((((( SR_Search ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
((((((((((((((((((((((((((((( SnapShot@2010-04-11_06.01.33 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-02-10 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-05-02 1817600]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2008-02-02 90112]
"Acronis True Image Monitor"="c:\program files\Acronis\TrueImage\TrueImageMonitor.exe" [2008-02-02 423258]
"AsusServiceProvider"="c:\program files\ASUS\AASP\1.00.12\aaCenter.exe" [2006-10-22 593920]
"AsusStartupHelp"="c:\program files\ASUS\AASP\1.00.12\AsRunHelp.exe" [2006-10-29 362496]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,c:\windows\localsys64.exe,"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-24 15:43 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=


R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 135664]
R3 bkn50USB;Belkin 54Mbps Wireless USB Network Adapter;c:\windows\system32\DRIVERS\rt2500usb.sys [2004-07-16 140416]
R3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-03-01 1029456]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2010-03-08 12872]
R3 ZD1211U(Cable & Wireless);Cable & Wireless 802.11g Series Wireless LAN USB(Cable & Wireless);c:\windows\system32\DRIVERS\zd1211u.sys [2004-12-22 259584]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-06-22 64160]
S1 aswSP;avast! Self Protection; [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-03-08 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2010-03-08 66632]
S1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2008-05-02 141312]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-11-24 20560]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-04-19 13:23 452136 —-a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-03-29 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 11:58]

2010-04-12 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-02-10 10:13]

2010-04-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 08:52]

2010-04-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-06 08:52]
.
.
——- Supplementary Scan ——-
.
uStart Page = www.google.co.uk/
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Search with Wanadoo - c:\windows\system32\WSBar.dll/VSearch.htm
FF - ProfilePath - c:\documents and settings\PC-User1\Application Data\Mozilla\Firefox\Profiles\7dha7iw5.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-GB.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-12 20:45
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\windows\localsys64.exe 575592 bytes executable
c:\windows\winmain32

scan completed successfully
hidden files: 2

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(556)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(612)
c:\windows\system32\wininet.dll

- - - - - - - > 'explorer.exe'(3496)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-04-12 20:47:57
ComboFix-quarantined-files.txt 2010-04-12 19:47
ComboFix2.txt 2010-04-11 06:03

Pre-Run: 102,279,495,680 bytes free
Post-Run: 102,240,862,208 bytes free

Current=2 Default=2 Failed=1 LastKnownGood=3 Sets=1,2,3,6,7,8
- - End Of File - - 8F94B15C9E582DB4051AF9C0B3DB3F07



Is this Ok?
Please do this:
  • Copy the contents of the Code Box below to Notepad.
  • Name the file as fix.reg
  • Change the Save as Type to All Files
  • and Save it on the desktop
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\\windows\\system32\\userinit.exe,"
Make sure there are NO blank lines before REGEDIT4

===================================================

1. Please download The Avenger2 by Swandog46 to your Desktop.
  • Right click on the Avenger.zip folder and select "Extract All…"
  • Follow the prompts and extract the avenger folder to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Begin copying here:
Files to delete:
C:\WINDOWS\localsys64.exe

Folders to delete:
C:\WINDOWS\winmain32

Programs to launch on reboot:
c:\documents and settings\PC-User1\Desktop\fix.reg

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, open the avenger folder and start The Avenger program by clicking on its icon.
  • Right click on the window under Input script here:, and select Paste.
  • You can also Paste the text copied to the clipboard into this window by pressing (Ctrl+V), or click on the third button under the menu to paste it from the clipboard.
  • Click on Execute
  • Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete" or "Drivers to Disable", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply.

===================================================

Please re-run OTL and post the log in your next reply.

===================================================

On your next reply please post :
Avenger log
OTL log

Good Day!
Hello Conspire

here are the logs as per instructions.

Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

File "C:\WINDOWS\localsys64.exe" deleted successfully.
Folder "C:\WINDOWS\winmain32" deleted successfully.
Program "c:\documents and settings\PC-User1\Desktop\fix.reg" successfully queued to run on reboot.

Completed script processing.

*******************

Finished! Terminate.OTL logfile created on: 15/04/2010 17:49:56 - Run 2
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\PC-User1\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1,023.00 Mb Total Physical Memory | 611.00 Mb Available Physical Memory | 60.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 94.96 Gb Free Space | 84.96% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HOME-PC
Current User Name: PC-User1
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\PC-User1\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe (Crawler.com)
PRC - C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe (Acronis)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ASUS\AASP\1.00.12\aaCenter.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\PC-User1\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (aswUpdSv) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (sp_rssrv) – C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)


========== Driver Services (SafeList) ==========

DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (aswMon2) – C:\WINDOWS\system32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswSP) – C:\WINDOWS\system32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\WINDOWS\system32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (aswTdi) – C:\WINDOWS\system32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswRdr) – C:\WINDOWS\system32\drivers\aswRdr.sys (ALWIL Software)
DRV - (Aavmker4) – C:\WINDOWS\system32\drivers\aavmker4.sys (ALWIL Software)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (sp_rsdrv2) – C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ()
DRV - (timounter) – C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (snapman) – C:\WINDOWS\system32\DRIVERS\snapman.sys (Acronis)
DRV - (tifsfilter) – C:\WINDOWS\system32\drivers\tifsfilt.sys (Acronis)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (AsIO) – C:\WINDOWS\system32\drivers\AsIO.sys ()
DRV - (AmdK8) – C:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (ZD1211U(Cable & Wireless)) Cable & Wireless 802.11g Series Wireless LAN USB(Cable & Wireless) – C:\WINDOWS\system32\drivers\ZD1211U.sys (ZyDAS Technology Corporation)
DRV - (MTsensor) – C:\WINDOWS\system32\drivers\ASACPI.sys ()
DRV - (bkn50USB) – C:\WINDOWS\system32\drivers\rt2500usb.sys (Ralink Technology Inc.)
DRV - (ZDPNDIS5) – C:\WINDOWS\system32\ZDPNDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (alcan5wn) SpeedTouch USB ADSL PPP Networking Driver (NDISWAN) – C:\WINDOWS\system32\drivers\alcan5wn.sys (THOMSON)
DRV - (alcaudsl) – C:\WINDOWS\system32\drivers\alcaudsl.sys (THOMSON)
DRV - (GT680x) – C:\WINDOWS\system32\drivers\GT680X.sys ( )


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.co.uk/
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://en-GB.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-GB:official"

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/08/12 22:23:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/11 07:00:56 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/06/21 13:54:58 | 000,000,000 | —D | M]

[2008/06/08 00:03:43 | 000,000,000 | —D | M] – C:\Documents and Settings\PC-User1\Application Data\Mozilla\Firefox\Profiles\7dha7iw5.default\extensions
[2008/02/10 22:51:02 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\PC-User1\Application Data\Mozilla\Firefox\Profiles\7dha7iw5.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2008/01/13 20:25:21 | 000,000,000 | —D | M] – C:\Documents and Settings\PC-User1\Application Data\Mozilla\Firefox\Profiles\7dha7iw5.default\extensions\[removed]
[2008/06/08 00:03:43 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2008/01/12 21:10:47 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2007/11/28 20:31:59 | 000,067,696 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\jar50.dll
[2007/11/28 20:31:59 | 000,054,376 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\jsd3250.dll
[2007/11/28 20:31:59 | 000,034,952 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\myspell.dll
[2007/11/28 20:31:59 | 000,046,720 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\spellchk.dll
[2007/11/28 20:31:59 | 000,172,144 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\xpinstal.dll
[2008/03/24 20:21:00 | 002,889,088 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll
[2006/06/15 11:24:15 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2006/06/15 11:24:15 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2006/06/15 11:24:15 | 000,001,077 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2006/09/11 15:39:34 | 000,000,831 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/04/07 16:30:49 | 000,000,000 | —- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [Acronis True Image Monitor] C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [AsusServiceProvider] C:\Program Files\ASUS\AASP\1.00.12\aaCenter.exe ()
O4 - HKLM..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.12\AsRunHelp.exe ()
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [SpywareTerminator] C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe (Crawler.com)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O8 - Extra context menu item: Search with Wanadoo - C:\WINDOWS\System32\WSBar.dll ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll (Sun Microsystems, Inc.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/Facebo…toUploader5.cab (Facebook Photo Uploader 5)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} http://upload.facebook.com/controls/Facebo…Uploader4_5.cab (Facebook Photo Uploader 4)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} http://gfx2.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/01/12 18:47:47 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found

========== Files/Folders - Created Within 30 Days ==========

[2010/04/15 17:45:03 | 000,000,000 | —D | C] – C:\Avenger
[2010/04/15 17:39:07 | 000,000,000 | —D | C] – C:\Documents and Settings\PC-User1\Desktop\avenger
[2010/04/15 17:00:01 | 000,000,000 | RH-D | C] – C:\Documents and Settings\PC-User1\Recent
[2010/04/12 21:19:26 | 000,000,000 | —D | C] – C:\Documents and Settings\PC-User1\Desktop\logs
[2010/04/12 21:19:15 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/04/11 06:55:17 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/04/11 06:55:17 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/04/11 06:55:17 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/04/11 06:55:17 | 000,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/04/11 06:54:47 | 000,000,000 | —D | C] – C:\Qoobox
[2010/04/09 09:26:40 | 000,561,664 | —- | C] (OldTimer Tools) – C:\Documents and Settings\PC-User1\Desktop\OTL.exe
[2010/03/08 17:45:50 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/02/06 09:57:05 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/02/06 09:52:38 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2008/05/25 14:59:49 | 000,017,504 | R— | C] ( ) – C:\WINDOWS\System32\drivers\GT680X.sys
[2008/03/25 22:10:46 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Help
[2008/03/25 22:10:46 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Help
[2008/01/12 21:54:50 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2008/01/12 18:50:18 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2008/01/12 18:47:39 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/04/15 17:49:44 | 000,356,120 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/04/15 17:49:44 | 000,311,934 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/04/15 17:49:44 | 000,040,196 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/04/15 17:45:48 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/04/15 17:45:38 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/04/15 17:45:35 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/04/15 17:45:25 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/04/15 17:44:22 | 005,242,880 | —- | M] () – C:\Documents and Settings\PC-User1\ntuser.dat
[2010/04/15 17:44:22 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\PC-User1\ntuser.ini
[2010/04/15 17:44:18 | 005,330,472 | -H– | M] () – C:\Documents and Settings\PC-User1\Local Settings\Application Data\IconCache.db
[2010/04/15 17:38:28 | 000,724,952 | —- | M] () – C:\Documents and Settings\PC-User1\Desktop\avenger.zip
[2010/04/15 17:37:07 | 000,000,137 | —- | M] () – C:\Documents and Settings\PC-User1\Desktop\fix.reg
[2010/04/15 09:07:03 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/04/13 19:09:30 | 000,000,603 | —- | M] () – C:\WINDOWS\ULEAD32.INI
[2010/04/13 17:33:20 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/04/12 20:51:51 | 000,100,908 | —- | M] () – C:\Documents and Settings\PC-User1\Desktop\SystemLook.exe
[2010/04/12 20:45:24 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/04/12 20:02:35 | 000,000,309 | —- | M] () – C:\WINDOWS\LEXSTAT.INI
[2010/04/11 06:51:55 | 003,911,676 | R— | M] () – C:\Documents and Settings\PC-User1\Desktop\ComboFix.exe
[2010/04/09 09:35:52 | 000,293,376 | —- | M] () – C:\Documents and Settings\PC-User1\Desktop\gmer.exe
[2010/04/09 09:34:28 | 000,284,915 | —- | M] () – C:\Documents and Settings\PC-User1\Desktop\gmer.zip
[2010/04/09 09:26:46 | 000,561,664 | —- | M] (OldTimer Tools) – C:\Documents and Settings\PC-User1\Desktop\OTL.exe
[2010/04/03 12:09:19 | 000,000,133 | —- | M] () – C:\Documents and Settings\PC-User1\default.pls
[2010/04/03 12:05:58 | 000,107,008 | —- | M] () – C:\Documents and Settings\PC-User1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/31 13:48:51 | 000,037,256 | —- | M] () – C:\Documents and Settings\PC-User1\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/03/30 00:46:30 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/30 00:45:52 | 000,020,824 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/29 11:57:03 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/03/28 21:06:00 | 000,068,608 | —- | M] () – C:\Documents and Settings\PC-User1\My Documents\Nursery meeting 29.3.10.doc
[2010/03/25 23:18:50 | 000,168,304 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/04/15 17:38:27 | 000,724,952 | —- | C] () – C:\Documents and Settings\PC-User1\Desktop\avenger.zip
[2010/04/15 17:37:07 | 000,000,137 | —- | C] () – C:\Documents and Settings\PC-User1\Desktop\fix.reg
[2010/04/12 20:51:50 | 000,100,908 | —- | C] () – C:\Documents and Settings\PC-User1\Desktop\SystemLook.exe
[2010/04/11 06:55:17 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/04/11 06:55:17 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/04/11 06:55:17 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/04/11 06:55:17 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/04/11 06:55:17 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/04/11 06:51:55 | 003,911,676 | R— | C] () – C:\Documents and Settings\PC-User1\Desktop\ComboFix.exe
[2010/04/09 09:34:26 | 000,284,915 | —- | C] () – C:\Documents and Settings\PC-User1\Desktop\gmer.zip
[2010/03/28 21:05:59 | 000,068,608 | —- | C] () – C:\Documents and Settings\PC-User1\My Documents\Nursery meeting 29.3.10.doc
[2010/03/08 21:53:56 | 000,010,250 | -HS- | C] () – C:\Documents and Settings\PC-User1\Local Settings\Application Data\N40fDO82
[2010/03/06 08:30:09 | 000,012,582 | -HS- | C] () – C:\Documents and Settings\PC-User1\Local Settings\Application Data\fXsMq7BWv
[2009/09/10 09:22:54 | 005,242,880 | —- | C] () – C:\Documents and Settings\PC-User1\ntuser.dat
[2009/06/21 13:54:58 | 000,000,031 | -H– | C] () – C:\WINDOWS\UKCpInfo.sys
[2008/07/13 08:00:58 | 000,008,701 | —- | C] () – C:\Documents and Settings\PC-User1\scan.log
[2008/05/25 16:00:49 | 000,000,073 | —- | C] () – C:\WINDOWS\WinInit.Ini
[2008/05/25 14:59:49 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\MKCoInstaller.dll
[2008/05/25 14:20:50 | 000,000,000 | —- | C] () – C:\WINDOWS\ui.INI
[2008/05/25 14:15:56 | 000,000,603 | —- | C] () – C:\WINDOWS\ULEAD32.INI
[2008/05/25 14:12:55 | 000,000,492 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2008/02/18 22:30:48 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2008/02/10 21:09:56 | 000,271,264 | —- | C] () – C:\WINDOWS\System32\VBRUN100.DLL
[2008/02/10 21:09:56 | 000,000,010 | —- | C] () – C:\WINDOWS\BestSol.ini
[2008/02/10 14:17:45 | 000,005,606 | —- | C] () – C:\WINDOWS\System32\stci.dll
[2008/02/10 12:31:07 | 000,000,133 | —- | C] () – C:\Documents and Settings\PC-User1\default.pls
[2008/02/10 12:30:51 | 000,107,008 | —- | C] () – C:\Documents and Settings\PC-User1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/10 12:30:36 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/02/10 11:37:32 | 000,000,309 | —- | C] () – C:\WINDOWS\LEXSTAT.INI
[2008/02/10 11:01:37 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\WSBar.dll
[2008/02/02 20:40:04 | 000,037,888 | —- | C] () – C:\WINDOWS\System32\setupnt.dll
[2008/01/27 20:55:28 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\InsDrvZD.dll
[2008/01/12 21:30:53 | 000,141,312 | —- | C] () – C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2008/01/12 20:56:49 | 000,024,576 | R— | C] () – C:\WINDOWS\System32\AsIO.dll
[2008/01/12 20:56:49 | 000,005,685 | R— | C] () – C:\WINDOWS\System32\drivers\AsIO.sys
[2008/01/12 20:56:17 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\vuins32.dll
[2008/01/12 20:53:02 | 000,016,174 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2008/01/12 20:53:00 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2008/01/12 20:52:57 | 000,005,824 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008/01/12 18:51:30 | 000,001,024 | -H– | C] () – C:\Documents and Settings\PC-User1\ntuser.dat.LOG
[2008/01/12 18:51:30 | 000,000,178 | -HS- | C] () – C:\Documents and Settings\PC-User1\ntuser.ini
[2007/03/27 10:45:22 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\sysres.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >

Good day to you.
Hi,

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :file
    C:\Documents and Settings\PC-User1\Local Settings\Application Data\fXsMq7BWv
    C:\Documents and Settings\PC-User1\Local Settings\Application Data\N40fDO82
    
    :filefind
    proquota.*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

===================================================

I need some information on some unidentified files. We will use Virustotal Please submit these files for analysis

To submit a file to virustotal, please click on this link

Http://www.virustotal.com

copy and paste the following into the upload a file box (one at a time if more than one file is listed)


C:\Documents and Settings\PC-User1\Local Settings\Application Data\fXsMq7BWv
C:\Documents and Settings\PC-User1\Local Settings\Application Data\N40fDO82


scroll down a bit and click "send file", wait for the results and post them in your next reply.

If it says already scanned – click "reanalyze now"

Please note that sometimes the scans take a few minutes. Please ensure that the scan has completed and the results are complete before submitting the next sample. Also please make sure each result is clearly identified as to which sample they belong to.

===================================================

On your next reply please post :
SystemLook log
VirusTotal log

Good Day!
Hello. Systemlook result: SystemLook v1.0 by jpshortstuff (11.01.10) Log created at 17:41 on 17/04/2010 by PC-User1 (Administrator - Elevation successful) No Context: file No Context: C:\Documents and Settings\PC-User1\Local Settings\Application Data\fXsMq7BWv No Context: C:\Documents and Settings\PC-User1\Local Settings\Application Data\N40fDO82 ========== filefind ========== Searching for "proquota.*" C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\proquota.exe –a— 50176 bytes [09:34 14/10/2008] [00:12 14/04/2008] F6465A2EEF75468988A4FCF124148FA8 -=End Of File=- virustotal results; (I hope this is how you want them!) File fXsMq7BWv received on 2010.04.17 16:44:13 (UTC) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 0/40 (0%) Loading server information… Your file is queued in position: 3. Estimated start time is between 56 and 80 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result a-squared 4.5.0.50 2010.04.17 - AhnLab-V3 5.0.0.2 2010.04.17 - AntiVir 7.10.6.115 2010.04.16 - Antiy-AVL 2.0.3.7 2010.04.16 - Authentium 5.2.0.5 2010.04.16 - Avast 4.8.1351.0 2010.04.17 - Avast5 5.0.332.0 2010.04.17 - AVG 9.0.0.787 2010.04.17 - BitDefender 7.2 2010.04.17 - CAT-QuickHeal 10.00 2010.04.17 - ClamAV 0.96.0.3-git 2010.04.17 - Comodo 4626 2010.04.17 - DrWeb 5.0.2.03300 2010.04.17 - eSafe 7.0.17.0 2010.04.15 - eTrust-Vet 35.2.7431 2010.04.17 - F-Prot 4.5.1.85 2010.04.17 - F-Secure 9.0.15370.0 2010.04.16 - Fortinet 4.0.14.0 2010.04.17 - GData 19 2010.04.17 - Ikarus T3.1.1.80.0 2010.04.17 - Jiangmin 13.0.900 2010.04.17 - Kaspersky 7.0.0.125 2010.04.17 - McAfee 5.400.0.1158 2010.04.17 - McAfee-GW-Edition 6.8.5 2010.04.17 - Microsoft 1.5605 2010.04.17 - NOD32 5036 2010.04.17 - Norman 6.04.11 2010.04.16 - nProtect 2010-04-17.01 2010.04.17 - Panda 10.0.2.7 2010.04.17 - PCTools 7.0.3.5 2010.04.17 - Prevx 3.0 2010.04.17 - Rising 22.43.05.03 2010.04.17 - Sophos 4.52.0 2010.04.17 - Sunbelt 6188 2010.04.17 - Symantec 20091.2.0.41 2010.04.17 - TheHacker 6.5.2.0.263 2010.04.16 - TrendMicro 9.120.0.1004 2010.04.15 - VBA32 3.12.12.4 2010.04.15 - ViRobot 2010.4.17.2282 2010.04.17 - VirusBuster 5.0.27.0 2010.04.17 - Additional information File size: 12582 bytes MD5…: 1fa3c11da42f1cbf8af96e9e0868eff3 SHA1..: 118d6bc5ee4fab1cdeebfe4a90429165471c1d93 SHA256: 58b5610d5f71f6f676fae2e1ac891268c7a97d13a45e1f3eb9e2f492e2614bae ssdeep: 384:xYf3AScmBiDmRLJAt7sbVtUo0abxIsUac:xCQxYiDauoZ2o0nsU5 PEiD..: - PEInfo: - RDS…: NSRL Reference Data Set - pdfid.: - trid..: Unknown! sigcheck: publisher….: n/a copyright….: n/a product……: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments…..: n/a signers……: - signing date.: - verified…..: Unsigned and the second virustotal result: File N40fDO82 received on 2010.04.17 16:50:54 (UTC) Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED Result: 0/40 (0%) Loading server information… Your file is queued in position: 1. Estimated start time is between 42 and 60 seconds. Do not close the window until scan is complete. The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result. If you are waiting for more than five minutes you have to resend your file. Your file is being scanned by VirusTotal in this moment, results will be shown as they're generated. Compact Print results Your file has expired or does not exists. Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email: Antivirus Version Last Update Result a-squared 4.5.0.50 2010.04.17 - AhnLab-V3 5.0.0.2 2010.04.17 - AntiVir 7.10.6.115 2010.04.16 - Antiy-AVL 2.0.3.7 2010.04.16 - Authentium 5.2.0.5 2010.04.16 - Avast 4.8.1351.0 2010.04.17 - Avast5 5.0.332.0 2010.04.17 - AVG 9.0.0.787 2010.04.17 - BitDefender 7.2 2010.04.17 - CAT-QuickHeal 10.00 2010.04.17 - ClamAV 0.96.0.3-git 2010.04.17 - Comodo 4626 2010.04.17 - DrWeb 5.0.2.03300 2010.04.17 - eSafe 7.0.17.0 2010.04.15 - eTrust-Vet 35.2.7431 2010.04.17 - F-Prot 4.5.1.85 2010.04.17 - F-Secure 9.0.15370.0 2010.04.16 - Fortinet 4.0.14.0 2010.04.17 - GData 19 2010.04.17 - Ikarus T3.1.1.80.0 2010.04.17 - Jiangmin 13.0.900 2010.04.17 - Kaspersky 7.0.0.125 2010.04.17 - McAfee 5.400.0.1158 2010.04.17 - McAfee-GW-Edition 6.8.5 2010.04.17 - Microsoft 1.5605 2010.04.17 - NOD32 5036 2010.04.17 - Norman 6.04.11 2010.04.16 - nProtect 2010-04-17.01 2010.04.17 - Panda 10.0.2.7 2010.04.17 - PCTools 7.0.3.5 2010.04.17 - Prevx 3.0 2010.04.17 - Rising 22.43.05.03 2010.04.17 - Sophos 4.52.0 2010.04.17 - Sunbelt 6188 2010.04.17 - Symantec 20091.2.0.41 2010.04.17 - TheHacker 6.5.2.0.263 2010.04.16 - TrendMicro 9.120.0.1004 2010.04.15 - VBA32 3.12.12.4 2010.04.15 - ViRobot 2010.4.17.2282 2010.04.17 - VirusBuster 5.0.27.0 2010.04.17 - Additional information File size: 10250 bytes MD5…: a486bb370457af7ed5ac3b50582565ae SHA1..: 5bf4235671dbf215c6a3d86fd10767c22a4c8ff6 SHA256: 9c4bc70fa6c4be8277c6de0588bb642411f61c9ad9d2b745c7b7cb04bec70178 ssdeep: 192:hDd6y+ewnMYd9Rw5TOIsx9HAFEPR4Rkl0E2jsBiR9oyjxV1+fAwdmBNJu+KN 7:X6yjwM15TOB0Q0SBc+yjfYSuv PEiD..: - PEInfo: - RDS…: NSRL Reference Data Set - pdfid.: - trid..: Unknown! sigcheck: publisher….: n/a copyright….: n/a product……: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments…..: n/a signers……: - signing date.: - verified…..: Unsigned By the way - my MBAM results are now clear (see original post). I realise that this does not necessarily mean evrything is OK but I thought I would let you know as I am pleased! Good afternoon.
Hmm I spoke too soon, methinks. Whilst on internet this morning I was hit by one of those fake XP Antivirus things. I MBAM-ed and got the following log: Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Database version: 3994 Windows 5.1.2600 Service Pack 2 Internet Explorer 7.0.5730.13 18/04/2010 10:03:02 mbam-log-2010-04-18 (10-03-02).txt Scan type: Quick scan Objects scanned: 99538 Time elapsed: 3 minute(s), 0 second(s) Memory Processes Infected: 1 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 2 Registry Data Items Infected: 7 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: C:\Documents and Settings\PC-User1\Local Settings\Application Data\ave.exe (Rogue.MultipleAV) -> Unloaded process successfully. Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_CLASSES_ROOT\.exe\shell\open\command\(default) (Hijack.ExeFile) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\secfile\shell\open\command\(default) (Rogue.MultipleAV) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\PC-User1\Local Settings\Application Data\ave.exe" /START "firefox.exe") Good: (firefox.exe) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\PC-User1\Local Settings\Application Data\ave.exe" /START "C:\Program Files\Internet Explorer\IEXPLORE.EXE") Good: (iexplore.exe) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\PC-User1\Local Settings\Application Data\ave.exe" /START "firefox.exe -safe-mode") Good: (firefox.exe -safe-mode) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\.exe\(default) (Hijacked.exeFile) -> Bad: (secfile) Good: (exefile) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: C:\Documents and Settings\PC-User1\Local Settings\Application Data\ave.exe (Rogue.MultipleAV) -> Quarantined and deleted successfully. Two subsequent MBAM scans have come up clear. I thought I would mention it.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI