TYRONE
Topic Starter
Hello whatthetech,
I've come back from holiday to find my parent's laptop in a bit of a state. Unfortunately they fell for all of Antivirus XP's prompts to click here and click there and it's gotten a bit nasty.
I should have consulted people here first but I did download Malwarebytes anti Malware and Windows Defender (a little too late!) and for about a day there was no sign of Antivirus XP, it seems to come up very randomly and as I type it isn't giving me any bother, however the laptop remains VERY sluggish indeed.
I should also mention that after installing Windows updates, upon restarting the mousepad and keyboard are no longer functional. I don't know if this is related. Sorry I can't give anymore relevant information, my parents aren't the most tech savvy in the world!
Here are the logs and thankyou so so much in advance, I really would appreciate any help you can offer.
DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 18:52:09.10 on 23/04/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.222.21 [GMT 1:00]
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Documents and Settings\clive hutchison\Local Settings\Application Data\ave.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Documents and Settings\clive hutchison\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.msn.co.uk
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\toscdspd.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Toshiba Hotkey Utility] "c:\program files\toshiba\windows utilities\Hotkey.exe" /lang en
mRun: [TPSMain] TPSMain.exe
mRun: [NDSTray.exe] NDSTray.exe
mRun: [SmoothView] c:\program files\toshiba\toshiba zooming utility\SmoothView.exe
mRun: [PadTouch] c:\program files\toshiba\touch and launch\PadExe.exe
mRun: [DLCCCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLCCtime.dll,_RunDLLEntry@16
mRun: [dlccmon.exe] "c:\program files\dell photo aio printer 924\dlccmon.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
StartupFolder: c:\docume~1\cliveh~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office11\ONENOTEM.EXE
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
Notify: AtiExtEvent - Ati2evxx.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\cliveh~1\applic~1\mozilla\firefox\profiles\g9cnpr7o.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - component: c:\documents and settings\clive hutchison\application data\mozilla\firefox\profiles\g9cnpr7o.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
============== File Associations ===============
.exe=secfile
=============== Created Last 30 ================
2010-04-22 22:18:46 0 d—–w- c:\program files\MSECache
2010-04-22 18:47:59 0 d—–w- c:\windows\ie8updates
2010-04-22 18:31:43 353792 -c—-w- c:\windows\system32\dllcache\srv.sys
2010-04-22 18:19:37 1315328 -c—-w- c:\windows\system32\dllcache\msoe.dll
2010-04-22 18:18:16 81920 -c—-w- c:\windows\system32\dllcache\fontsub.dll
2010-04-22 18:18:15 119808 -c—-w- c:\windows\system32\dllcache\t2embed.dll
2010-04-22 18:16:00 594432 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2010-04-22 18:16:00 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-04-22 18:15:59 247808 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2010-04-22 18:15:59 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2010-04-22 18:15:54 1985536 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2010-04-22 18:13:42 337408 -c—-w- c:\windows\system32\dllcache\netapi32.dll
2010-04-22 17:53:17 0 d—–w- c:\docume~1\cliveh~1\applic~1\Malwarebytes
2010-04-22 17:52:59 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-22 17:52:56 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-04-22 17:52:50 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-22 17:52:50 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-20 16:39:15 181632 ——w- c:\windows\system32\MpSigStub.exe
2010-04-20 16:16:23 0 d—–w- c:\windows\system32\scripting
2010-04-20 16:16:21 0 d—–w- c:\windows\l2schemas
2010-04-20 16:16:20 0 d—–w- c:\windows\system32\en
2010-04-20 16:16:20 0 d—–w- c:\windows\system32\bits
2010-04-20 16:09:00 0 d—–w- c:\windows\network diagnostic
2010-04-20 15:47:33 21504 —-a-w- c:\windows\system32\hidserv.dll
2010-04-20 15:47:19 14592 —-a-w- c:\windows\system32\drivers\kbdhid.sys
2010-04-20 15:36:32 0 d-sh–w- c:\documents and settings\clive hutchison\IETldCache
2010-04-20 15:22:43 0 dc-h–w- c:\windows\ie8
2010-04-18 18:30:27 0 d—–w- c:\docume~1\alluse~1\applic~1\avG
2010-04-18 18:02:03 552 —-a-w- c:\windows\system32\d3d8caps.dat
2010-04-18 18:01:59 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-04-14 21:26:26 455680 -c—-w- c:\windows\system32\dllcache\mrxsmb.sys
2010-03-29 21:43:17 0 d—–w- c:\documents and settings\clive hutchison\Tracing
==================== Find3M ====================
2010-04-21 10:42:20 24576 —-a-w- c:\windows\system32\drivers\kbdclass.sys
2010-03-10 06:15:52 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-02-25 06:24:37 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11:07 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-17 08:10:28 2189952 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25:04 2066816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 10:03:03 293376 ——w- c:\windows\system32\browserchoice.exe
2010-02-12 04:33:11 100864 —-a-w- c:\windows\system32\6to4svc.dll
============= FINISH: 18:54:12.06 ===============
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-24 18:17:13
Windows 5.1.2600 Service Pack 3
Running: 1u9f7yu8.exe; Driver: C:\DOCUME~1\CLIVEH~1\LOCALS~1\Temp\kwaorpob.sys
—- Kernel code sections - GMER 1.0.15 —-
.rsrc C:\WINDOWS\system32\DRIVERS\kbdclass.sys entry point in ".rsrc" section [0xFA245E14]
—- User code sections - GMER 1.0.15 —-
.text C:\WINDOWS\System32\svchost.exe[972] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 006D000A
.text C:\WINDOWS\System32\svchost.exe[972] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 006E000A
.text C:\WINDOWS\System32\svchost.exe[972] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 006C000C
.text C:\WINDOWS\System32\svchost.exe[972] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 01DE000A
.text C:\WINDOWS\System32\svchost.exe[972] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 01D0000A
.text C:\WINDOWS\Explorer.EXE[1928] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B7000A
.text C:\WINDOWS\Explorer.EXE[1928] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00BD000A
.text C:\WINDOWS\Explorer.EXE[1928] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B6000C
.text C:\WINDOWS\system32\wuauclt.exe[2012] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0092000A
.text C:\WINDOWS\system32\wuauclt.exe[2012] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0093000A
.text C:\WINDOWS\system32\wuauclt.exe[2012] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0091000C
.text C:\Program Files\Mozilla Firefox\firefox.exe[3180] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0131000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3180] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0132000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3180] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0130000C
—- Devices - GMER 1.0.15 —-
Device -> \Driver\atapi \Device\Harddisk0\DR0 FFB0EAC8
—- Files - GMER 1.0.15 —-
File C:\WINDOWS\system32\DRIVERS\kbdclass.sys suspicious modification
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification
—- EOF - GMER 1.0.15 —-
THANKYOU!
Tyrone
I've come back from holiday to find my parent's laptop in a bit of a state. Unfortunately they fell for all of Antivirus XP's prompts to click here and click there and it's gotten a bit nasty.
I should have consulted people here first but I did download Malwarebytes anti Malware and Windows Defender (a little too late!) and for about a day there was no sign of Antivirus XP, it seems to come up very randomly and as I type it isn't giving me any bother, however the laptop remains VERY sluggish indeed.
I should also mention that after installing Windows updates, upon restarting the mousepad and keyboard are no longer functional. I don't know if this is related. Sorry I can't give anymore relevant information, my parents aren't the most tech savvy in the world!
Here are the logs and thankyou so so much in advance, I really would appreciate any help you can offer.
DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 18:52:09.10 on 23/04/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.222.21 [GMT 1:00]
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Documents and Settings\clive hutchison\Local Settings\Application Data\ave.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Documents and Settings\clive hutchison\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.msn.co.uk
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\toscdspd.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Toshiba Hotkey Utility] "c:\program files\toshiba\windows utilities\Hotkey.exe" /lang en
mRun: [TPSMain] TPSMain.exe
mRun: [NDSTray.exe] NDSTray.exe
mRun: [SmoothView] c:\program files\toshiba\toshiba zooming utility\SmoothView.exe
mRun: [PadTouch] c:\program files\toshiba\touch and launch\PadExe.exe
mRun: [DLCCCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLCCtime.dll,_RunDLLEntry@16
mRun: [dlccmon.exe] "c:\program files\dell photo aio printer 924\dlccmon.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
StartupFolder: c:\docume~1\cliveh~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office11\ONENOTEM.EXE
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
Notify: AtiExtEvent - Ati2evxx.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\cliveh~1\applic~1\mozilla\firefox\profiles\g9cnpr7o.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - component: c:\documents and settings\clive hutchison\application data\mozilla\firefox\profiles\g9cnpr7o.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
============== File Associations ===============
.exe=secfile
=============== Created Last 30 ================
2010-04-22 22:18:46 0 d—–w- c:\program files\MSECache
2010-04-22 18:47:59 0 d—–w- c:\windows\ie8updates
2010-04-22 18:31:43 353792 -c—-w- c:\windows\system32\dllcache\srv.sys
2010-04-22 18:19:37 1315328 -c—-w- c:\windows\system32\dllcache\msoe.dll
2010-04-22 18:18:16 81920 -c—-w- c:\windows\system32\dllcache\fontsub.dll
2010-04-22 18:18:15 119808 -c—-w- c:\windows\system32\dllcache\t2embed.dll
2010-04-22 18:16:00 594432 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2010-04-22 18:16:00 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-04-22 18:15:59 247808 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2010-04-22 18:15:59 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2010-04-22 18:15:54 1985536 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2010-04-22 18:13:42 337408 -c—-w- c:\windows\system32\dllcache\netapi32.dll
2010-04-22 17:53:17 0 d—–w- c:\docume~1\cliveh~1\applic~1\Malwarebytes
2010-04-22 17:52:59 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-22 17:52:56 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-04-22 17:52:50 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-22 17:52:50 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-20 16:39:15 181632 ——w- c:\windows\system32\MpSigStub.exe
2010-04-20 16:16:23 0 d—–w- c:\windows\system32\scripting
2010-04-20 16:16:21 0 d—–w- c:\windows\l2schemas
2010-04-20 16:16:20 0 d—–w- c:\windows\system32\en
2010-04-20 16:16:20 0 d—–w- c:\windows\system32\bits
2010-04-20 16:09:00 0 d—–w- c:\windows\network diagnostic
2010-04-20 15:47:33 21504 —-a-w- c:\windows\system32\hidserv.dll
2010-04-20 15:47:19 14592 —-a-w- c:\windows\system32\drivers\kbdhid.sys
2010-04-20 15:36:32 0 d-sh–w- c:\documents and settings\clive hutchison\IETldCache
2010-04-20 15:22:43 0 dc-h–w- c:\windows\ie8
2010-04-18 18:30:27 0 d—–w- c:\docume~1\alluse~1\applic~1\avG
2010-04-18 18:02:03 552 —-a-w- c:\windows\system32\d3d8caps.dat
2010-04-18 18:01:59 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-04-14 21:26:26 455680 -c—-w- c:\windows\system32\dllcache\mrxsmb.sys
2010-03-29 21:43:17 0 d—–w- c:\documents and settings\clive hutchison\Tracing
==================== Find3M ====================
2010-04-21 10:42:20 24576 —-a-w- c:\windows\system32\drivers\kbdclass.sys
2010-03-10 06:15:52 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-02-25 06:24:37 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11:07 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-17 08:10:28 2189952 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25:04 2066816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 10:03:03 293376 ——w- c:\windows\system32\browserchoice.exe
2010-02-12 04:33:11 100864 —-a-w- c:\windows\system32\6to4svc.dll
============= FINISH: 18:54:12.06 ===============
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-24 18:17:13
Windows 5.1.2600 Service Pack 3
Running: 1u9f7yu8.exe; Driver: C:\DOCUME~1\CLIVEH~1\LOCALS~1\Temp\kwaorpob.sys
—- Kernel code sections - GMER 1.0.15 —-
.rsrc C:\WINDOWS\system32\DRIVERS\kbdclass.sys entry point in ".rsrc" section [0xFA245E14]
—- User code sections - GMER 1.0.15 —-
.text C:\WINDOWS\System32\svchost.exe[972] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 006D000A
.text C:\WINDOWS\System32\svchost.exe[972] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 006E000A
.text C:\WINDOWS\System32\svchost.exe[972] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 006C000C
.text C:\WINDOWS\System32\svchost.exe[972] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 01DE000A
.text C:\WINDOWS\System32\svchost.exe[972] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 01D0000A
.text C:\WINDOWS\Explorer.EXE[1928] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B7000A
.text C:\WINDOWS\Explorer.EXE[1928] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00BD000A
.text C:\WINDOWS\Explorer.EXE[1928] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B6000C
.text C:\WINDOWS\system32\wuauclt.exe[2012] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0092000A
.text C:\WINDOWS\system32\wuauclt.exe[2012] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0093000A
.text C:\WINDOWS\system32\wuauclt.exe[2012] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0091000C
.text C:\Program Files\Mozilla Firefox\firefox.exe[3180] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0131000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3180] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0132000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3180] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0130000C
—- Devices - GMER 1.0.15 —-
Device -> \Driver\atapi \Device\Harddisk0\DR0 FFB0EAC8
—- Files - GMER 1.0.15 —-
File C:\WINDOWS\system32\DRIVERS\kbdclass.sys suspicious modification
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification
—- EOF - GMER 1.0.15 —-
THANKYOU!
Tyrone