Dovenoir
Topic Starter
I've used AVG, Malware Bytes, Spybot and Adaware. Aside from removing a few cookies. I've had nothing come up. I was guided through Combofix by a friend of mine who does network administration, and he was unable to find anything wrong.
That being said, my ISP has shut me down until I either remove the virus or reformat all 3 machines. They have not given me any clues as to what the infection is except that there is a spambot working from my network sending email. I only use webmail, and do no have any mail client programs on my computer. They have not been able to give me any additional information.
I've been having difficulty running GMER outside safe mode.
The program either stops windows or causes a blue screen error. I haven't been able to see the screen long enough to identify which driver is causing the issue.
Per Microsoft Windows Error Reporting,
http://wer.microsoft.com/responses/Respons…e6-84f92108af5e
Blue screen error caused by a device or driver
You received this message because a hardware device, its driver, or related software has caused a blue screen error. This type of error means the computer has shut down abruptly to protect itself from potential data corruption or loss. In this case, we were unable to detect the specific device or driver that caused the problem.
The following troubleshooting steps might prevent the blue screen error from recurring. Try them in the order given. If one step does not solve the problem, then move on to the next one.
DDS and GMER (safe mode) posted below.
DDS (Ver_10-03-17.01) - NTFSx86 MINIMAL
Run by [removed] at 22:43:16.70 on Sat 04/17/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1677 [GMT -4:00]
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Lyz\My Documents\Downloads\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://search.digsby.com/
uInternet Connection Wizard,ShellNext = hxxp://picasa.google.com/support/bin/request.py?contact_type=uninstall&hl=en
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
uRun: [TOSCDSPD] "c:\program files\toshiba\toscdspd\toscdspd.exe"
uRun: [Sony Ericsson PC Suite] "c:\program files\sony ericsson\sony ericsson pc suite\SEPCSuite.exe" /systray /nologon
uRun: [SpybotSD TeaTimer] "c:\program files\spybot\TeaTimer.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [TFncKy] TFncKy.exe
mRun: [TDispVol] "TDispVol.exe"
mRun: [SynTPEnh] "c:\program files\synaptics\syntp\SynTPEnh.exe"
mRun: [ehTray] "c:\windows\ehome\ehtray.exe"
mRun: [THotkey] "c:\program files\toshiba\toshiba applet\thotkey.exe"
mRun: [SynTPLpr] "c:\program files\synaptics\syntp\SynTPLpr.exe"
mRun: [NDSTray.exe] NDSTray.exe
mRun: [Tvs] "c:\program files\toshiba\tvs\TvsTray.exe"
mRun: [TPSMain] "TPSMain.exe"
mRun: [SmoothView] "c:\program files\toshiba\toshiba zooming utility\SmoothView.exe"
mRun: [dla] "c:\windows\system32\dla\DLACTRLW.exe"
mRun: [Pinger] "c:\toshiba\ivp\ism\pinger.exe" /run
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
StartupFolder: c:\docume~1\lyz\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digsby.lnk - c:\program files\digsby\digsby.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ramasst.lnk - c:\windows\system32\RAMASST.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot\SDHelper.dll
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1268963137077
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://sslvpn.uc.edu/dana-cached/sc/JuniperSetupClient.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\lyz\applic~1\mozilla\firefox\profiles\zpvc12gr.default\
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npicaN.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-1-20 216200]
S1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-1-20 29512]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-1-20 242696]
S2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-3-13 308064]
S2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-3-23 38224]
S3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\drivers\s0017bus.sys [2010-3-13 86824]
S3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\drivers\s0017mdfl.sys [2010-3-13 15016]
S3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\drivers\s0017mdm.sys [2010-3-13 114600]
S3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0017mgmt.sys [2010-3-13 108328]
S3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\drivers\s0017nd5.sys [2010-3-13 26024]
S3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\drivers\s0017obex.sys [2010-3-13 104616]
S3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\drivers\s0017unic.sys [2010-3-13 109736]
S4 OMSI download service;Sony Ericsson OMSI download service;c:\program files\sony ericsson\sony ericsson pc suite\SupServ.exe [2010-3-13 90112]
============== File Associations ===============
.com=Gaussian.GaussView 5.0.Gaussian Input File
=============== Created Last 30 ================
2010-04-06 23:08:14 0 d—–w- c:\docume~1\alluse~1\applic~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-04 01:54:08 0 d-sha-r- C:\cmdcons
2010-04-04 01:53:19 98816 —-a-w- c:\windows\sed.exe
2010-04-04 01:53:19 77312 —-a-w- c:\windows\MBR.exe
2010-04-04 01:53:19 261632 —-a-w- c:\windows\PEV.exe
2010-04-04 01:53:19 161792 —-a-w- c:\windows\SWREG.exe
2010-04-01 02:08:54 0 d—–w- c:\program files\MSSOAP
2010-04-01 02:08:27 0 d—–w- c:\program files\Webroot
2010-04-01 02:07:57 164 —-a-w- c:\windows\install.dat
2010-03-30 19:27:13 0 d—–w- C:\g09w
2010-03-30 19:05:48 0 d—–w- c:\program files\Scratch
2010-03-30 19:05:37 0 d—–w- c:\program files\help
2010-03-30 19:05:32 336896 —-a-w- c:\program files\g09w.exe
2010-03-30 19:05:32 1611984 —-a-w- c:\program files\l1.exe
2010-03-30 19:05:32 0 d—–w- c:\program files\tests
2010-03-30 19:05:30 9798144 —-a-w- c:\program files\l913.exe
2010-03-30 19:05:29 7413248 —-a-w- c:\program files\l908.exe
2010-03-30 19:05:27 7874560 —-a-w- c:\program files\l906.exe
2010-03-30 19:05:27 259072 —-a-w- c:\program files\l905.exe
2010-03-30 19:05:25 945152 —-a-w- c:\program files\l902.exe
2010-03-30 19:05:25 8935424 —-a-w- c:\program files\l904.exe
2010-03-30 19:05:25 816640 —-a-w- c:\program files\l901.exe
2010-03-30 19:05:25 264192 —-a-w- c:\program files\l903.exe
2010-03-30 19:05:25 1659904 —-a-w- c:\program files\l811.exe
2010-03-30 19:05:23 7747584 —-a-w- c:\program files\l804.exe
2010-03-30 19:05:23 301568 —-a-w- c:\program files\l802.exe
2010-03-30 19:05:21 9468928 —-a-w- c:\program files\l801.exe
2010-03-30 19:05:20 10156544 —-a-w- c:\program files\l716.exe
2010-03-30 19:05:18 8127488 —-a-w- c:\program files\l703.exe
2010-03-30 19:05:18 1045504 —-a-w- c:\program files\l702.exe
2010-03-30 19:05:16 9735168 —-a-w- c:\program files\l701.exe
2010-03-30 19:05:14 6693888 —-a-w- c:\program files\l610.exe
2010-03-30 19:05:14 2395648 —-a-w- c:\program files\l609.exe
2010-03-30 19:05:13 7057920 —-a-w- c:\program files\l608.exe
2010-03-30 19:05:11 7537664 —-a-w- c:\program files\l607.exe
2010-03-30 19:05:11 1031168 —-a-w- c:\program files\l604.exe
2010-03-30 19:05:09 8812032 —-a-w- c:\program files\l602.exe
2010-03-30 19:05:07 9599488 —-a-w- c:\program files\l601.exe
2010-03-30 19:05:05 12791808 —-a-w- c:\program files\l510.exe
2010-03-30 19:05:03 9665536 —-a-w- c:\program files\l508.exe
2010-03-30 19:05:01 7275008 —-a-w- c:\program files\l506.exe
2010-03-30 19:05:01 1179648 —-a-w- c:\program files\l503.exe
2010-03-30 19:04:59 377856 —-a-w- c:\program files\l405.exe
2010-03-30 19:04:59 10930688 —-a-w- c:\program files\l502.exe
2010-03-30 19:04:57 11290624 —-a-w- c:\program files\l402.exe
2010-03-30 19:04:55 8733184 —-a-w- c:\program files\l401.exe
2010-03-30 19:04:53 6671872 —-a-w- c:\program files\l319.exe
2010-03-30 19:04:53 650752 —-a-w- c:\program files\l314.exe
2010-03-30 19:04:53 361472 —-a-w- c:\program files\l311.exe
2010-03-30 19:04:53 330240 —-a-w- c:\program files\l310.exe
2010-03-30 19:04:53 256000 —-a-w- c:\program files\l316.exe
2010-03-30 19:04:53 1052160 —-a-w- c:\program files\l318.exe
2010-03-30 19:04:51 6688768 —-a-w- c:\program files\l308.exe
2010-03-30 19:04:49 8733696 —-a-w- c:\program files\l303.exe
2010-03-30 19:04:47 8397824 —-a-w- c:\program files\l302.exe
2010-03-30 19:04:44 1223168 —-a-w- c:\program files\l202.exe
2010-03-30 19:04:44 11751424 —-a-w- c:\program files\l301.exe
2010-03-30 19:04:42 9291264 —-a-w- c:\program files\l124.exe
2010-03-30 19:04:42 1744896 —-a-w- c:\program files\l123.exe
2010-03-30 19:04:41 1064448 —-a-w- c:\program files\l122.exe
2010-03-30 19:04:40 7930368 —-a-w- c:\program files\l121.exe
2010-03-30 19:04:37 1440256 —-a-w- c:\program files\l118.exe
2010-03-30 19:04:37 10643456 —-a-w- c:\program files\l120.exe
2010-03-30 19:04:36 6884352 —-a-w- c:\program files\l117.exe
2010-03-30 19:04:33 9865216 —-a-w- c:\program files\l1112.exe
2010-03-30 19:04:33 304128 —-a-w- c:\program files\l116.exe
2010-03-30 19:04:33 1150464 —-a-w- c:\program files\l114.exe
2010-03-30 19:04:33 1146880 —-a-w- c:\program files\l113.exe
2010-03-30 19:04:33 1142784 —-a-w- c:\program files\l115.exe
2010-03-30 19:04:31 8138240 —-a-w- c:\program files\l1111.exe
2010-03-30 19:04:28 9956864 —-a-w- c:\program files\l1110.exe
2010-03-30 19:04:28 279040 —-a-w- c:\program files\l111.exe
2010-03-30 19:04:26 8638464 —-a-w- c:\program files\l1102.exe
2010-03-30 19:04:24 952320 —-a-w- c:\program files\l107.exe
2010-03-30 19:04:24 9010176 —-a-w- c:\program files\l1101.exe
2010-03-30 19:04:24 874496 —-a-w- c:\program files\l106.exe
2010-03-30 19:04:24 282624 —-a-w- c:\program files\l110.exe
2010-03-30 19:04:24 268800 —-a-w- c:\program files\l108.exe
2010-03-30 19:04:24 1127936 —-a-w- c:\program files\l109.exe
2010-03-30 19:04:24 1007104 —-a-w- c:\program files\l105.exe
2010-03-30 19:04:21 10782720 —-a-w- c:\program files\l103.exe
2010-03-30 19:04:18 9692160 —-a-w- c:\program files\l1014.exe
2010-03-30 19:04:18 279040 —-a-w- c:\program files\l102.exe
2010-03-30 19:04:16 8261120 —-a-w- c:\program files\l1003.exe
2010-03-30 19:04:16 2486414 —-a-w- c:\program files\l101.exe
2010-03-30 19:04:13 756224 —-a-w- c:\program files\gauoptl.exe
2010-03-30 19:04:13 737280 —-a-w- c:\program files\gauopt.exe
2010-03-30 19:04:13 299520 —-a-w- c:\program files\gautraj.exe
2010-03-30 19:04:13 253440 —-a-w- c:\program files\freqmem.exe
2010-03-30 19:04:13 250368 —-a-w- c:\program files\g09.exe
2010-03-30 19:04:13 248320 —-a-w- c:\program files\ham506.exe
2010-03-30 19:04:13 10354176 —-a-w- c:\program files\l1002.exe
2010-03-30 19:04:12 459264 —-a-w- c:\program files\formchk.exe
2010-03-30 19:04:12 287744 —-a-w- c:\program files\cubman.exe
2010-03-30 19:04:12 252416 —-a-w- c:\program files\demofc.exe
2010-03-30 19:04:12 2116096 —-a-w- c:\program files\freqchk.exe
2010-03-30 19:04:10 6821888 —-a-w- c:\program files\cubegen.exe
2010-03-30 19:04:10 406016 —-a-w- c:\program files\unfchk.exe
2010-03-30 19:04:10 344576 —-a-w- c:\program files\chkchk.exe
2010-03-30 19:04:10 337920 —-a-w- c:\program files\c8609.exe
2010-03-30 19:04:10 252928 —-a-w- c:\program files\copychk.exe
2010-03-30 19:04:09 2512896 —-a-w- c:\program files\testrt.exe
2010-03-30 19:04:09 249344 —-a-w- c:\program files\rwfdump.exe
2010-03-30 19:04:07 7741952 —-a-w- c:\program files\newzmat.exe
2010-03-30 19:04:05 10564096 —-a-w- c:\program files\mm.exe
2010-03-30 19:04:04 2479616 —-a-w- c:\program files\l9999.exe
2010-03-30 19:04:01 972288 —-a-w- c:\program files\l918.exe
2010-03-30 19:04:01 11876352 —-a-w- c:\program files\l923.exe
2010-03-30 19:03:58 9095680 —-a-w- c:\program files\l916.exe
2010-03-30 19:03:58 1062912 —-a-w- c:\program files\l915.exe
2010-03-30 19:03:51 10004992 —-a-w- c:\program files\l914.exe
2010-03-24 18:27:19 0 d—–w- c:\windows\pss
2010-03-24 00:56:39 0 d—–w- c:\program files\Spybot
2010-03-24 00:56:39 0 d—–w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-03-24 00:13:38 0 d—–w- c:\docume~1\lyz\applic~1\Malwarebytes
2010-03-24 00:13:33 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-24 00:13:32 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-24 00:13:32 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-24 00:13:32 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-03-19 16:36:54 274288 —-a-w- c:\windows\system32\mucltui.dll
2010-03-19 16:36:54 16736 —-a-w- c:\windows\system32\mucltui.dll.mui
==================== Find3M ====================
2010-03-30 19:06:01 148208 —-a-w- c:\program files\Uninst.isu
2010-03-30 19:05:57 136 —-a-w- c:\program files\G09W.INI
2010-03-13 18:43:42 242696 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-03-13 18:43:41 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-03-13 18:43:06 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-10 06:15:52 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-02-25 06:24:37 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11:07 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-19 23:47:50 3604480 —-a-w- c:\windows\system32\GPhotos.scr
2010-02-16 14:08:49 2146304 ——w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25:04 2024448 ——w- c:\windows\system32\ntkrnlpa.exe
2010-02-15 03:48:37 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-02-12 04:33:11 100864 —-a-w- c:\windows\system32\6to4svc.dll
2010-01-27 04:32:43 34160 —-a-w- c:\docume~1\lyz\applic~1\GDIPFONTCACHEV1.DAT
2009-06-12 20:51:22 255220 —-a-w- c:\program files\mm2.prm
2009-06-12 20:51:22 24716 —-a-w- c:\program files\oplsaa.prm
2009-06-12 20:51:22 20949 —-a-w- c:\program files\uff.prm
2009-06-12 20:51:20 5521 —-a-w- c:\program files\dreiding.prm
2009-06-12 20:51:20 31388 —-a-w- c:\program files\amber98.prm
2009-06-12 20:51:20 169617 —-a-w- c:\program files\dftba.prm
2009-06-12 20:51:20 15566 —-a-w- c:\program files\amber.prm
2009-05-12 18:03:44 4987 —-a-w- c:\program files\install.txt
2004-12-10 20:30:42 0 —-a-w- c:\program files\Default.r3
2004-12-10 19:31:08 28 —-a-w- c:\program files\Default.r2
2004-12-10 19:31:08 28 —-a-w- c:\program files\Default.r1
============= FINISH: 22:43:46.51 ===============
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-04-17 17:01:18
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\pgtcqpog.sys
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
—- EOF - GMER 1.0.15 —-
That being said, my ISP has shut me down until I either remove the virus or reformat all 3 machines. They have not given me any clues as to what the infection is except that there is a spambot working from my network sending email. I only use webmail, and do no have any mail client programs on my computer. They have not been able to give me any additional information.
I've been having difficulty running GMER outside safe mode.
The program either stops windows or causes a blue screen error. I haven't been able to see the screen long enough to identify which driver is causing the issue.
Per Microsoft Windows Error Reporting,
http://wer.microsoft.com/responses/Respons…e6-84f92108af5e
Blue screen error caused by a device or driver
You received this message because a hardware device, its driver, or related software has caused a blue screen error. This type of error means the computer has shut down abruptly to protect itself from potential data corruption or loss. In this case, we were unable to detect the specific device or driver that caused the problem.
The following troubleshooting steps might prevent the blue screen error from recurring. Try them in the order given. If one step does not solve the problem, then move on to the next one.
DDS and GMER (safe mode) posted below.
DDS (Ver_10-03-17.01) - NTFSx86 MINIMAL
Run by [removed] at 22:43:16.70 on Sat 04/17/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1677 [GMT -4:00]
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Lyz\My Documents\Downloads\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://search.digsby.com/
uInternet Connection Wizard,ShellNext = hxxp://picasa.google.com/support/bin/request.py?contact_type=uninstall&hl=en
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
uRun: [TOSCDSPD] "c:\program files\toshiba\toscdspd\toscdspd.exe"
uRun: [Sony Ericsson PC Suite] "c:\program files\sony ericsson\sony ericsson pc suite\SEPCSuite.exe" /systray /nologon
uRun: [SpybotSD TeaTimer] "c:\program files\spybot\TeaTimer.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [TFncKy] TFncKy.exe
mRun: [TDispVol] "TDispVol.exe"
mRun: [SynTPEnh] "c:\program files\synaptics\syntp\SynTPEnh.exe"
mRun: [ehTray] "c:\windows\ehome\ehtray.exe"
mRun: [THotkey] "c:\program files\toshiba\toshiba applet\thotkey.exe"
mRun: [SynTPLpr] "c:\program files\synaptics\syntp\SynTPLpr.exe"
mRun: [NDSTray.exe] NDSTray.exe
mRun: [Tvs] "c:\program files\toshiba\tvs\TvsTray.exe"
mRun: [TPSMain] "TPSMain.exe"
mRun: [SmoothView] "c:\program files\toshiba\toshiba zooming utility\SmoothView.exe"
mRun: [dla] "c:\windows\system32\dla\DLACTRLW.exe"
mRun: [Pinger] "c:\toshiba\ivp\ism\pinger.exe" /run
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
StartupFolder: c:\docume~1\lyz\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digsby.lnk - c:\program files\digsby\digsby.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ramasst.lnk - c:\windows\system32\RAMASST.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot\SDHelper.dll
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1268963137077
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://sslvpn.uc.edu/dana-cached/sc/JuniperSetupClient.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\lyz\applic~1\mozilla\firefox\profiles\zpvc12gr.default\
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npicaN.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-1-20 216200]
S1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-1-20 29512]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-1-20 242696]
S2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-3-13 308064]
S2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-3-23 38224]
S3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\drivers\s0017bus.sys [2010-3-13 86824]
S3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\drivers\s0017mdfl.sys [2010-3-13 15016]
S3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\drivers\s0017mdm.sys [2010-3-13 114600]
S3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0017mgmt.sys [2010-3-13 108328]
S3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\drivers\s0017nd5.sys [2010-3-13 26024]
S3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\drivers\s0017obex.sys [2010-3-13 104616]
S3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\drivers\s0017unic.sys [2010-3-13 109736]
S4 OMSI download service;Sony Ericsson OMSI download service;c:\program files\sony ericsson\sony ericsson pc suite\SupServ.exe [2010-3-13 90112]
============== File Associations ===============
.com=Gaussian.GaussView 5.0.Gaussian Input File
=============== Created Last 30 ================
2010-04-06 23:08:14 0 d—–w- c:\docume~1\alluse~1\applic~1\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-04 01:54:08 0 d-sha-r- C:\cmdcons
2010-04-04 01:53:19 98816 —-a-w- c:\windows\sed.exe
2010-04-04 01:53:19 77312 —-a-w- c:\windows\MBR.exe
2010-04-04 01:53:19 261632 —-a-w- c:\windows\PEV.exe
2010-04-04 01:53:19 161792 —-a-w- c:\windows\SWREG.exe
2010-04-01 02:08:54 0 d—–w- c:\program files\MSSOAP
2010-04-01 02:08:27 0 d—–w- c:\program files\Webroot
2010-04-01 02:07:57 164 —-a-w- c:\windows\install.dat
2010-03-30 19:27:13 0 d—–w- C:\g09w
2010-03-30 19:05:48 0 d—–w- c:\program files\Scratch
2010-03-30 19:05:37 0 d—–w- c:\program files\help
2010-03-30 19:05:32 336896 —-a-w- c:\program files\g09w.exe
2010-03-30 19:05:32 1611984 —-a-w- c:\program files\l1.exe
2010-03-30 19:05:32 0 d—–w- c:\program files\tests
2010-03-30 19:05:30 9798144 —-a-w- c:\program files\l913.exe
2010-03-30 19:05:29 7413248 —-a-w- c:\program files\l908.exe
2010-03-30 19:05:27 7874560 —-a-w- c:\program files\l906.exe
2010-03-30 19:05:27 259072 —-a-w- c:\program files\l905.exe
2010-03-30 19:05:25 945152 —-a-w- c:\program files\l902.exe
2010-03-30 19:05:25 8935424 —-a-w- c:\program files\l904.exe
2010-03-30 19:05:25 816640 —-a-w- c:\program files\l901.exe
2010-03-30 19:05:25 264192 —-a-w- c:\program files\l903.exe
2010-03-30 19:05:25 1659904 —-a-w- c:\program files\l811.exe
2010-03-30 19:05:23 7747584 —-a-w- c:\program files\l804.exe
2010-03-30 19:05:23 301568 —-a-w- c:\program files\l802.exe
2010-03-30 19:05:21 9468928 —-a-w- c:\program files\l801.exe
2010-03-30 19:05:20 10156544 —-a-w- c:\program files\l716.exe
2010-03-30 19:05:18 8127488 —-a-w- c:\program files\l703.exe
2010-03-30 19:05:18 1045504 —-a-w- c:\program files\l702.exe
2010-03-30 19:05:16 9735168 —-a-w- c:\program files\l701.exe
2010-03-30 19:05:14 6693888 —-a-w- c:\program files\l610.exe
2010-03-30 19:05:14 2395648 —-a-w- c:\program files\l609.exe
2010-03-30 19:05:13 7057920 —-a-w- c:\program files\l608.exe
2010-03-30 19:05:11 7537664 —-a-w- c:\program files\l607.exe
2010-03-30 19:05:11 1031168 —-a-w- c:\program files\l604.exe
2010-03-30 19:05:09 8812032 —-a-w- c:\program files\l602.exe
2010-03-30 19:05:07 9599488 —-a-w- c:\program files\l601.exe
2010-03-30 19:05:05 12791808 —-a-w- c:\program files\l510.exe
2010-03-30 19:05:03 9665536 —-a-w- c:\program files\l508.exe
2010-03-30 19:05:01 7275008 —-a-w- c:\program files\l506.exe
2010-03-30 19:05:01 1179648 —-a-w- c:\program files\l503.exe
2010-03-30 19:04:59 377856 —-a-w- c:\program files\l405.exe
2010-03-30 19:04:59 10930688 —-a-w- c:\program files\l502.exe
2010-03-30 19:04:57 11290624 —-a-w- c:\program files\l402.exe
2010-03-30 19:04:55 8733184 —-a-w- c:\program files\l401.exe
2010-03-30 19:04:53 6671872 —-a-w- c:\program files\l319.exe
2010-03-30 19:04:53 650752 —-a-w- c:\program files\l314.exe
2010-03-30 19:04:53 361472 —-a-w- c:\program files\l311.exe
2010-03-30 19:04:53 330240 —-a-w- c:\program files\l310.exe
2010-03-30 19:04:53 256000 —-a-w- c:\program files\l316.exe
2010-03-30 19:04:53 1052160 —-a-w- c:\program files\l318.exe
2010-03-30 19:04:51 6688768 —-a-w- c:\program files\l308.exe
2010-03-30 19:04:49 8733696 —-a-w- c:\program files\l303.exe
2010-03-30 19:04:47 8397824 —-a-w- c:\program files\l302.exe
2010-03-30 19:04:44 1223168 —-a-w- c:\program files\l202.exe
2010-03-30 19:04:44 11751424 —-a-w- c:\program files\l301.exe
2010-03-30 19:04:42 9291264 —-a-w- c:\program files\l124.exe
2010-03-30 19:04:42 1744896 —-a-w- c:\program files\l123.exe
2010-03-30 19:04:41 1064448 —-a-w- c:\program files\l122.exe
2010-03-30 19:04:40 7930368 —-a-w- c:\program files\l121.exe
2010-03-30 19:04:37 1440256 —-a-w- c:\program files\l118.exe
2010-03-30 19:04:37 10643456 —-a-w- c:\program files\l120.exe
2010-03-30 19:04:36 6884352 —-a-w- c:\program files\l117.exe
2010-03-30 19:04:33 9865216 —-a-w- c:\program files\l1112.exe
2010-03-30 19:04:33 304128 —-a-w- c:\program files\l116.exe
2010-03-30 19:04:33 1150464 —-a-w- c:\program files\l114.exe
2010-03-30 19:04:33 1146880 —-a-w- c:\program files\l113.exe
2010-03-30 19:04:33 1142784 —-a-w- c:\program files\l115.exe
2010-03-30 19:04:31 8138240 —-a-w- c:\program files\l1111.exe
2010-03-30 19:04:28 9956864 —-a-w- c:\program files\l1110.exe
2010-03-30 19:04:28 279040 —-a-w- c:\program files\l111.exe
2010-03-30 19:04:26 8638464 —-a-w- c:\program files\l1102.exe
2010-03-30 19:04:24 952320 —-a-w- c:\program files\l107.exe
2010-03-30 19:04:24 9010176 —-a-w- c:\program files\l1101.exe
2010-03-30 19:04:24 874496 —-a-w- c:\program files\l106.exe
2010-03-30 19:04:24 282624 —-a-w- c:\program files\l110.exe
2010-03-30 19:04:24 268800 —-a-w- c:\program files\l108.exe
2010-03-30 19:04:24 1127936 —-a-w- c:\program files\l109.exe
2010-03-30 19:04:24 1007104 —-a-w- c:\program files\l105.exe
2010-03-30 19:04:21 10782720 —-a-w- c:\program files\l103.exe
2010-03-30 19:04:18 9692160 —-a-w- c:\program files\l1014.exe
2010-03-30 19:04:18 279040 —-a-w- c:\program files\l102.exe
2010-03-30 19:04:16 8261120 —-a-w- c:\program files\l1003.exe
2010-03-30 19:04:16 2486414 —-a-w- c:\program files\l101.exe
2010-03-30 19:04:13 756224 —-a-w- c:\program files\gauoptl.exe
2010-03-30 19:04:13 737280 —-a-w- c:\program files\gauopt.exe
2010-03-30 19:04:13 299520 —-a-w- c:\program files\gautraj.exe
2010-03-30 19:04:13 253440 —-a-w- c:\program files\freqmem.exe
2010-03-30 19:04:13 250368 —-a-w- c:\program files\g09.exe
2010-03-30 19:04:13 248320 —-a-w- c:\program files\ham506.exe
2010-03-30 19:04:13 10354176 —-a-w- c:\program files\l1002.exe
2010-03-30 19:04:12 459264 —-a-w- c:\program files\formchk.exe
2010-03-30 19:04:12 287744 —-a-w- c:\program files\cubman.exe
2010-03-30 19:04:12 252416 —-a-w- c:\program files\demofc.exe
2010-03-30 19:04:12 2116096 —-a-w- c:\program files\freqchk.exe
2010-03-30 19:04:10 6821888 —-a-w- c:\program files\cubegen.exe
2010-03-30 19:04:10 406016 —-a-w- c:\program files\unfchk.exe
2010-03-30 19:04:10 344576 —-a-w- c:\program files\chkchk.exe
2010-03-30 19:04:10 337920 —-a-w- c:\program files\c8609.exe
2010-03-30 19:04:10 252928 —-a-w- c:\program files\copychk.exe
2010-03-30 19:04:09 2512896 —-a-w- c:\program files\testrt.exe
2010-03-30 19:04:09 249344 —-a-w- c:\program files\rwfdump.exe
2010-03-30 19:04:07 7741952 —-a-w- c:\program files\newzmat.exe
2010-03-30 19:04:05 10564096 —-a-w- c:\program files\mm.exe
2010-03-30 19:04:04 2479616 —-a-w- c:\program files\l9999.exe
2010-03-30 19:04:01 972288 —-a-w- c:\program files\l918.exe
2010-03-30 19:04:01 11876352 —-a-w- c:\program files\l923.exe
2010-03-30 19:03:58 9095680 —-a-w- c:\program files\l916.exe
2010-03-30 19:03:58 1062912 —-a-w- c:\program files\l915.exe
2010-03-30 19:03:51 10004992 —-a-w- c:\program files\l914.exe
2010-03-24 18:27:19 0 d—–w- c:\windows\pss
2010-03-24 00:56:39 0 d—–w- c:\program files\Spybot
2010-03-24 00:56:39 0 d—–w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-03-24 00:13:38 0 d—–w- c:\docume~1\lyz\applic~1\Malwarebytes
2010-03-24 00:13:33 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-24 00:13:32 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-24 00:13:32 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-24 00:13:32 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-03-19 16:36:54 274288 —-a-w- c:\windows\system32\mucltui.dll
2010-03-19 16:36:54 16736 —-a-w- c:\windows\system32\mucltui.dll.mui
==================== Find3M ====================
2010-03-30 19:06:01 148208 —-a-w- c:\program files\Uninst.isu
2010-03-30 19:05:57 136 —-a-w- c:\program files\G09W.INI
2010-03-13 18:43:42 242696 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-03-13 18:43:41 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-03-13 18:43:06 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-10 06:15:52 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-02-25 06:24:37 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11:07 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-19 23:47:50 3604480 —-a-w- c:\windows\system32\GPhotos.scr
2010-02-16 14:08:49 2146304 ——w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25:04 2024448 ——w- c:\windows\system32\ntkrnlpa.exe
2010-02-15 03:48:37 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-02-12 04:33:11 100864 —-a-w- c:\windows\system32\6to4svc.dll
2010-01-27 04:32:43 34160 —-a-w- c:\docume~1\lyz\applic~1\GDIPFONTCACHEV1.DAT
2009-06-12 20:51:22 255220 —-a-w- c:\program files\mm2.prm
2009-06-12 20:51:22 24716 —-a-w- c:\program files\oplsaa.prm
2009-06-12 20:51:22 20949 —-a-w- c:\program files\uff.prm
2009-06-12 20:51:20 5521 —-a-w- c:\program files\dreiding.prm
2009-06-12 20:51:20 31388 —-a-w- c:\program files\amber98.prm
2009-06-12 20:51:20 169617 —-a-w- c:\program files\dftba.prm
2009-06-12 20:51:20 15566 —-a-w- c:\program files\amber.prm
2009-05-12 18:03:44 4987 —-a-w- c:\program files\install.txt
2004-12-10 20:30:42 0 —-a-w- c:\program files\Default.r3
2004-12-10 19:31:08 28 —-a-w- c:\program files\Default.r2
2004-12-10 19:31:08 28 —-a-w- c:\program files\Default.r1
============= FINISH: 22:43:46.51 ===============
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-04-17 17:01:18
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\pgtcqpog.sys
—- Devices - GMER 1.0.15 —-
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
—- EOF - GMER 1.0.15 —-