This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Backdoor.Tidserv.I!inf

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello again blackdog

Did this happen recently or is this from the same infection?

Somethings to remember while we are working together.

1.Please do not run any other tool untill instructed to do so!
2.Please reply to this thread, do not start another!
3.Please tell me about any problems that have occurred during the fix.
4.Please tell me of any other symptoms you may be having as these can help also.
5.Please try as much as possible not to run anything while executing a fix.

If you follow these instructions, everything should go smoothly.

Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe.

I would like to get a better look at your system, please do the following so I can get some more detailed logs.


DeFogger:

  • Please download DeFogger to your desktop.

    Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger may ask you to reboot the machine, if it does - click OK
Do not re-enable these drivers until otherwise instructed.
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Download DDS:

  • Please download DDS by sUBs from one of the links below and save it to your desktop:

    [external image: Posted Image]
    Download DDS and save it to your desktop

    Link1
    Link2
    Link3

    Please disable any anti-malware program that will block scripts from running before running DDS.

    • Double-Click on dds.scr and a command window will appear. This is normal.
    • Shortly after two logs will appear:
    • DDS.txt
    • Attach.txt
  • A window will open instructing you save & post the logs
  • Save the logs to a convenient place such as your desktop
  • Copy the contents of both logs & post in your next reply

Gmer

Download GMER Rootkit Scanner from here.
  • Double click the .exe file. If asked to allow gmer.sys driver to load, please consent
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO

    🖼Click to load external image (Posted Image)
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file
  • Save it where you can easily find it, such as your desktop, and post it in reply
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Note: Do not run any programs while Gmer is running.


information and logs:

In your next post I need the following

1.logs from DDS
2.log from GMER
3.let me know of any problems you may have had

Gringo
Hello Gringo,
I was'nt expecting to need help again so soon.
I am assuming this is a new virus as I have had no problems.
I got the nortons message "Backdoor.Tidserv.I!inf needs to be removed manually"
Win Patrol then started picking up

Currently assigned
Run a dll as an application
Microsoft
rundll32.exeieframe.dll,open URL%I
Change to
Run a dll as an application
c:\windows\system32\rundll32.exe.c\windows\system32\ieframe.dll,open url %I

I click no
this keeps popping up regularily although it has'nt happenen for a few hours - other than that computor running O.K maybe a little slow
I also didnt realise I had win patrol running while doing your scans I hope thats OK


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 19/01/2009 3:08:52 PM
System Uptime: 27/04/2010 7:08:56 AM (15 hours ago)

Motherboard: ASUSTeK Computer INC. | | P5KPL-CM
Processor: Intel® Core™2 Quad CPU Q6600 @ 2.40GHz | Socket 775 | 2399/266mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 298 GiB total, 209.803 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4D36E96B-E325-11CE-BFC1-08002BE10318}
Description: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
Device ID: ACPI\PNP0303\4&2C575ACB&0
Manufacturer: (Standard keyboards)
Name: Standard 101/102-Key or Microsoft Natural PS/2 Keyboard
PNP Device ID: ACPI\PNP0303\4&2C575ACB&0
Service: i8042prt

Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318}
Description: Microsoft PS/2 Mouse
Device ID: ACPI\PNP0F03\4&2C575ACB&0
Manufacturer: Microsoft
Name: Microsoft PS/2 Mouse
PNP Device ID: ACPI\PNP0F03\4&2C575ACB&0
Service: i8042prt

==== System Restore Points ===================

RP1: 27/04/2010 5:49:45 PM - System Checkpoint

==== Installed Programs ======================

4Videosoft DVD to QuickTime Converter
Adobe Acrobat - Reader 6.0.2 Update
Adobe Acrobat 6.0.1 Professional - English, Français, Deutsch
Adobe Acrobat and Reader 6.0.3 Update
Adobe Acrobat and Reader 6.0.4 Update
Adobe Acrobat and Reader 6.0.5 Update
Adobe Acrobat and Reader 6.0.6 Update
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe MPEG Encoder
Adobe Photoshop CS
Adobe Premiere 6.5
Adobe Reader 8
Age of Mythology
Age of Mythology - The Titans Expansion
Apple Application Support
Apple Software Update
Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
Canon CanoCraft CS-P 3.7
Canon iP4200
Canon Setup Utility 2.0
Canon Utilities Easy-PhotoPrint
Canon Utilities Easy-PrintToolBox
Cashflow Manager 3
CD-LabelPrint
Common-Use Signing Interface
Creative Mass Storage Drivers
Creative MediaSource
Creative System Information
Critical Update for Windows Media Player 11 (KB959772)
CyberLink PowerDirector
DivX Web Player
DVD Flick 1.3.0.7
DVD Shrink 3.2
Easy-WebPrint
Efficient Diary 1.76
ESET Online Scanner v3
Ewisoft Website Builder (include eCommerce Builder) Version 5
Fax Machine 4.33
Free DVD Ripper Version 2.25
Google Chrome
Google Earth
Google Update Helper
Google Updater
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Intel® Graphics Media Accelerator Driver
Java™ 6 Update 11
Kaiser Baas USB VIDEO TO DVD MAKER Device Driver
LimeWire 5.5.8
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office PowerPoint Viewer 2003
Microsoft Office XP Media Content
Microsoft Office XP Small Business
Microsoft Silverlight
Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Mirar
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
Nero 6 Ultra Edition
Norton AntiVirus
PersonalWebKit
PhotoNow!
Platform
PowerDirector
PowerDVD
PowerProducer
QuickTime
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980232)
SMPlayer 0.6.7
Sony Media Manager 2.2
Sony Vegas 7.0
Sophos Anti-Rootkit 1.5.0
SpywareBlaster 4.2
Ulead Photo Express 2.0 SE
Ultra QuickTime Converter 3.2.0104
Uninstall 1.0.0.1
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB969497)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB898461)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VC80CRTRedist - 8.0.50727.762
VIA Platform Device Manager
VobSub v2.23 (Remove Only)
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live OneCare safety scanner
Windows Media Format 11 runtime
Windows Media Player 11
WinPatrol 2009
WinZip Self-Extractor
Xilisoft Video Converter Ultimate
Xvid 1.2.2 final uninstall

==== End Of File ===========================

DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 22:21:29.01 on Tue 27/04/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.2038.1362 [GMT 10:00]

AV: Norton AntiVirus *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe
C:\OPLIMIT\ocrawr32.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\User\Desktop\virus removal tools\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.abc.net.au/
mSearch Bar = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\acrobat\activex\AcroIEHelper.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\engine\16.8.0.41\IPSBHO.DLL
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [Creative Detector] c:\program files\creative\mediasource\detector\CTDetect.exe /R
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [HDAudDeck] c:\program files\via\viaudioi\hdadeck\HDeck.exe 1
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Easy-PrintToolBox] c:\program files\canon\easy-printtoolbox\BJPSMAIN.EXE /logon
mRun: [PE2CKFNT SE] c:\program files\ulead systems\ulead photo express 2 se\ChkFont.exe
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
StartupFolder: c:\docume~1\user\startm~1\programs\startup\ocraware.lnk - c:\oplimit\OCRAWARE.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\acrobat 6.0\distillr\acrotray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\reader 8.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~2.lnk - c:\program files\adobe\reader 8.0\reader\AdobeCollabSync.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\photoe~1.lnk - c:\program files\ulead systems\ulead photo express 2 se\CalCheck.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\canon\easy-webprint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\canon\easy-webprint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\canon\easy-webprint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\canon\easy-webprint\Resource.dll/RC_Print.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/buxus/docs/OnlineScanner.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

============= SERVICES / DRIVERS ===============

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1008000.029\SymEFA.sys [2010-1-28 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nav\1008000.029\BHDrvx86.sys [2010-1-28 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nav\1008000.029\cchpx86.sys [2010-1-28 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20100422.002\IDSXpx86.sys [2010-4-27 329592]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\norton antivirus\engine\16.8.0.41\ccSvcHst.exe [2010-1-28 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-4-23 102448]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20100426.039\NAVENG.SYS [2010-4-27 84912]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20100426.039\NAVEX15.SYS [2010-4-27 1324720]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-1-19 222976]
S2 gupdate1c9d697d19c9338;Google Update Service (gupdate1c9d697d19c9338);c:\program files\google\update\GoogleUpdate.exe [2009-5-17 133104]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\aspi32.sys [2009-5-21 16512]
S3 cpuz132;cpuz132;\??\c:\docume~1\user\locals~1\temp\cpuz132\cpuz132_x32.sys –> c:\docume~1\user\locals~1\temp\cpuz132\cpuz132_x32.sys [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\30.tmp –> c:\windows\system32\30.tmp [?]

=============== Created Last 30 ================

2010-04-27 12:20:44 0 —-a-w- c:\documents and settings\user\defogger_reenable
2010-04-26 09:01:09 0 d—–w- c:\program files\LimeWire
2010-04-16 08:49:39 0 d—–w- c:\docume~1\user\applic~1\Nvu
2010-04-14 02:38:15 0 d—–w- c:\docume~1\alluse~1\applic~1\Driver Whiz
2010-04-13 05:52:17 286720 —-a-w- c:\windows\iun507.exe
2010-04-13 05:51:55 0 d—–w- c:\program files\PersonalWebKit3
2010-04-11 07:52:56 0 d—–w- c:\program files\SpywareBlaster
2010-04-11 07:50:51 0 d—–w- c:\docume~1\user\applic~1\WinPatrol
2010-04-11 07:50:40 0 d—–w- c:\program files\BillP Studios
2010-04-11 03:30:48 0 d—–w- c:\program files\ESET
2010-04-10 23:24:58 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-10 23:24:54 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-10 08:14:14 8832 —-a-w- c:\windows\system32\drivers\rasacd.sys
2010-04-10 08:14:14 8832 —-a-w- C:\rasacd.sys
2010-04-06 22:11:47 96512 -c–a-w- c:\windows\system32\dllcache\atapi.sys
2010-04-06 22:11:47 96512 —-a-w- C:\atapi.sys
2010-04-06 22:11:47 96512 ——w- c:\windows\system32\drivers\ATAPI.SYS
2010-04-05 22:15:03 0 d—–w- C:\tds old log
2010-04-05 03:27:18 0 d-sha-r- C:\cmdcons
2010-04-04 10:18:14 108 —-a-w- c:\windows\system32\temp_0000_30437.aok
2010-04-04 07:41:55 0 d—–w- c:\program files\Sophos

==================== Find3M ====================

2010-04-21 02:26:40 86480 —-a-w- c:\docume~1\user\applic~1\GDIPFONTCACHEV1.DAT
2010-04-11 06:31:25 114825 —-a-w- c:\windows\fonts\AdobeFnt07.lst
2010-04-07 23:22:20 8832 —-a-w- c:\windows\system32\drivers\rasacd.old
2010-04-06 04:27:25 96512 —-a-w- c:\windows\system32\drivers\atapi.old
2010-03-10 06:15:52 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-02-25 06:24:37 916480 ——w- c:\windows\system32\wininet.dll
2010-02-16 14:08:49 2146304 ——w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25:04 2024448 ——w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33:11 100864 —-a-w- c:\windows\system32\6to4svc.dll
2008-04-13 14:10:32 96512 —-a-w- c:\program files\atapi.sys

============= FINISH: 22:21:48.93 ===============
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-28 12:04:04
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\User\LOCALS~1\Temp\axlyapob.sys


—- System - GMER 1.0.15 —-

SSDT 89402E48 ZwAlertResumeThread
SSDT 89402F08 ZwAlertThread
SSDT 893FFE30 ZwAllocateVirtualMemory
SSDT 893DEE90 ZwAssignProcessToJobObject
SSDT 89456658 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xA899B130]
SSDT 893A7C90 ZwCreateMutant
SSDT 893DC100 ZwCreateSymbolicLinkObject
SSDT 893E1D18 ZwCreateThread
SSDT 893DEF70 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xA899B3B0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xA899B910]
SSDT 893FFFC0 ZwDuplicateObject
SSDT 893E1E68 ZwFreeVirtualMemory
SSDT 893FCAE0 ZwImpersonateAnonymousToken
SSDT 893FCBA0 ZwImpersonateThread
SSDT 89CA0008 ZwLoadDriver
SSDT 893AD668 ZwMapViewOfSection
SSDT 893FCA20 ZwOpenEvent
SSDT 893E6AF8 ZwOpenProcess
SSDT 893FFF00 ZwOpenProcessToken
SSDT 893FDDD8 ZwOpenSection
SSDT 893E6A28 ZwOpenThread
SSDT 893DC1D0 ZwProtectVirtualMemory
SSDT 89401918 ZwResumeThread
SSDT 893A4AB8 ZwSetContextThread
SSDT 893E4E38 ZwSetInformationProcess
SSDT 893FDCB0 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xA899BB60]
SSDT 893A7B48 ZwSuspendProcess
SSDT 893A4978 ZwSuspendThread
SSDT 894064A8 ZwTerminateProcess
SSDT 893A49F8 ZwTerminateThread
SSDT 893E4F08 ZwUnmapViewOfSection
SSDT 893E1F38 ZwWriteVirtualMemory

—- Kernel code sections - GMER 1.0.15 —-

? SYMEFA.SYS The system cannot find the file specified. !
init C:\WINDOWS\system32\drivers\monfilt.sys entry point in "init" section [0xA8C3B280]

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

—- EOF - GMER 1.0.15 —-
Greetings Blackdog

well it is the same virus just a different driver so it was a reinfection.

I had win patrol running while doing your scans I hope thats OK - that is ok it didn't hurt anything - but durring the fixes it will need to be turned off - let me know if you don't know how to do this

.:P2P Warning!:

IMPORTANT I notice there are signs of one or more P2P (Person to Person) File Sharing Programs on your computer.

LimeWire 5.5.8

Please note that as long as you are using any form of Peer-to-Peer networking and downloading files from non-documented sources, you can expect infestations of malware to occur
Once upon a time, P2P file sharing was fairly safe. That is no longer true. , please keep in mind that this practice may be the source of your current malware infestation

Please read these short reports on the dangers of peer-2-peer programs and file sharing.

Cyber Education Letter
File sharing infects 500,000 computers
USAToday

After you have uninstalled limewire please continue below.

:run combofix:

Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode.
This allows us to more easily help you should your computer have a problem after an attempted removal of malware.
It is a simple procedure that will only take a few moments of your time.


Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.
Please continue as follows:

  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Click Yes to allow ComboFix to continue scanning for malware.

When the tool is finished, it will produce a report for you.

Please include the report in your next post:

C:\ComboFix.txt

"information and logs"

  • In your next post I need the following

  • log from combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
How do you turn off win patrol and I am a bit confused about the windows recovery console. I have printed instructions for combo fix is that part of those instructions or are we taliking about starting in safe mode ?
Hello Blackdog

the recovery console was installed the first time so don't worry about that.

:Disable Winpatrol:

  • Some programs can Interfere with the fix

  • Right click on the Scotty Dog near the clock and select Options…. A window will open.
  • Select the Options tab.
  • Uncheck (untick) this box: Automatically run Winpatrol when computer starts.
  • Close the Winpatrol window.
  • Right click on the Scotty Dog again and select Exit Program.

please re-enable winpatrol when we finish the fix.

gringo
ComboFix 10-04-26.05 - User 28/04/2010 15:29:23.4.4 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.2038.1368 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton AntiVirus *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\User\System
c:\documents and settings\User\System\win_qs8.jqx

.
((((((((((((((((((((((((( Files Created from 2010-03-28 to 2010-04-28 )))))))))))))))))))))))))))))))
.

2010-04-28 03:40 . 2010-02-03 09:00 84912 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100427.022\NAVENG.SYS
2010-04-28 03:40 . 2010-02-03 09:00 1324720 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100427.022\NAVEX15.SYS
2010-04-28 03:40 . 2009-12-09 09:00 2747440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100427.022\CCERASER.DLL
2010-04-28 03:40 . 2009-10-25 18:32 371248 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100427.022\EECTRL.SYS
2010-04-28 03:40 . 2009-10-25 18:32 259440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100427.022\ECMSVR32.DLL
2010-04-28 03:40 . 2009-10-25 18:32 177520 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100427.022\NAVENG32.DLL
2010-04-28 03:40 . 2009-10-25 18:32 1647984 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100427.022\NAVEX32A.DLL
2010-04-28 03:40 . 2009-10-25 18:32 102448 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100427.022\ERASER.SYS
2010-04-27 00:43 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100422.002\IDSvix86.sys
2010-04-27 00:43 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100422.002\IDSXpx86.sys
2010-04-27 00:43 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100422.002\Scxpx86.dll
2010-04-27 00:43 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100422.002\IDSxpx86.dll
2010-04-27 00:43 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100422.002\IDSviA64.sys
2010-04-21 22:02 . 2010-04-21 22:02 ——– d—–w- c:\program files\Common Files\Apple
2010-04-21 22:02 . 2010-04-21 22:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-04-16 21:45 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100415.001\Scxpx86.dll
2010-04-16 21:45 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100415.001\IDSvix86.sys
2010-04-16 21:45 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100415.001\IDSXpx86.sys
2010-04-16 21:45 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100415.001\IDSxpx86.dll
2010-04-16 21:45 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100415.001\IDSviA64.sys
2010-04-16 08:49 . 2010-04-16 08:49 ——– d—–w- c:\documents and settings\User\Application Data\Nvu
2010-04-14 02:38 . 2010-04-14 02:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Driver Whiz
2010-04-13 05:52 . 2010-04-13 05:51 286720 —-a-w- c:\windows\iun507.exe
2010-04-13 05:51 . 2010-04-13 05:58 ——– d—–w- c:\program files\PersonalWebKit3
2010-04-11 07:53 . 2010-04-27 07:48 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-11 07:52 . 2010-04-27 07:47 ——– d—–w- c:\program files\SpywareBlaster
2010-04-11 07:50 . 2010-04-11 07:50 ——– d—–w- c:\documents and settings\User\Application Data\WinPatrol
2010-04-11 07:50 . 2009-01-19 04:07 0 —-a-w- c:\documents and settings\User\Application Data\WinPatrol\Config.sys
2010-04-11 07:50 . 2009-01-19 04:07 0 —-a-w- c:\documents and settings\User\Application Data\WinPatrol\Autoexec.bat
2010-04-11 07:50 . 2010-04-11 07:50 ——– d—–w- c:\program files\BillP Studios
2010-04-11 03:30 . 2010-04-11 03:30 ——– d—–w- c:\program files\ESET
2010-04-10 23:24 . 2010-03-29 14:46 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-10 23:24 . 2010-03-29 14:45 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-10 08:14 . 2010-04-07 23:22 8832 —-a-w- c:\windows\system32\drivers\rasacd.sys
2010-04-10 08:14 . 2010-04-07 23:22 8832 —-a-w- C:\rasacd.sys
2010-04-06 22:11 . 2008-04-14 12:00 96512 -c–a-w- c:\windows\system32\dllcache\atapi.sys
2010-04-06 22:11 . 2008-04-14 12:00 96512 —-a-w- C:\atapi.sys
2010-04-06 22:11 . 2008-04-14 12:00 96512 ——w- c:\windows\system32\drivers\ATAPI.SYS
2010-04-05 22:15 . 2010-04-05 22:15 ——– d—–w- C:\tds old log
2010-04-04 07:41 . 2010-04-04 07:41 ——– d—–w- c:\program files\Sophos
2010-04-03 08:33 . 2010-04-03 08:33 ——– d—–w- c:\documents and settings\LocalService\Application Data\AdobeUM
2010-04-03 08:33 . 2010-04-03 08:33 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-04-02 10:13 . 2010-04-02 10:13 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-04-02 10:13 . 2010-04-02 10:13 ——– d—–w- c:\documents and settings\NetworkService\Application Data\AdobeUM

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-22 12:26 . 2009-03-10 06:23 ——– d—–w- c:\documents and settings\User\Application Data\AdobeUM
2010-04-21 22:02 . 2009-01-21 11:13 ——– d—–w- c:\program files\QuickTime
2010-04-14 22:44 . 2009-11-11 08:00 79488 —-a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-04-14 02:38 . 2009-01-19 10:15 86480 —-a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-13 10:37 . 2009-05-17 02:26 ——– d—–w- c:\program files\Google
2010-04-09 09:59 . 2009-02-02 11:49 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-04-09 09:58 . 2009-02-02 11:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-04-07 23:22 . 2008-04-14 12:00 8832 —-a-w- c:\windows\system32\drivers\rasacd.old
2010-04-06 04:27 . 2008-04-14 12:00 96512 —-a-w- c:\windows\system32\drivers\atapi.old
2010-04-04 10:18 . 2009-05-21 03:39 ——– d—–w- c:\program files\Ultra QuickTime Converter
2010-03-21 21:46 . 2010-03-21 21:46 ——– d—–w- c:\program files\EwisoftWeb
2010-03-21 21:46 . 2010-03-21 21:46 ——– d—–w- c:\documents and settings\All Users\Application Data\EwisoftWeb
2010-03-10 06:15 . 2008-04-14 12:00 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-02-25 06:24 . 2008-04-14 12:00 916480 ——w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2008-04-14 12:00 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-16 14:08 . 2008-04-14 12:00 2146304 ——w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2008-04-14 00:01 2024448 ——w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33 . 2008-04-14 12:00 100864 —-a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2008-04-14 12:00 226880 —-a-w- c:\windows\system32\drivers\tcpip6.sys
2008-04-13 14:10 . 2009-05-26 07:47 96512 —-a-w- c:\program files\atapi.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-17 39408]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-21 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-21 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-21 137752]
"HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2008-04-10 29757440]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-19 136600]
"Easy-PrintToolBox"="c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-14 409600]
"PE2CKFNT SE"="c:\program files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe" [1998-07-03 25088]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-17 421888]

c:\documents and settings\User\Start Menu\Programs\Startup\
OCRAWARE.lnk - c:\oplimit\OCRAWARE.EXE [2009-3-8 51360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-10-24 217194]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-1-20 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Photo Express Calendar Checker SE.lnk - c:\program files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe [2009-3-8 55296]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"e:\\programs\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\rmiregistry.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1233:UDP"= 1233:UDP:Windows Media Format SDK (svchost.exe)
"1232:UDP"= 1232:UDP:Windows Media Format SDK (svchost.exe)

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1008000.029\SymEFA.sys [28/01/2010 10:22 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NAV\1008000.029\BHDrvx86.sys [28/01/2010 10:22 AM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1008000.029\cchpx86.sys [28/01/2010 10:21 AM 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100422.002\IDSXpx86.sys [27/04/2010 10:43 AM 329592]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe [28/01/2010 10:21 AM 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [23/04/2010 11:25 AM 102448]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [19/01/2009 2:15 PM 222976]
S2 gupdate1c9d697d19c9338;Google Update Service (gupdate1c9d697d19c9338);c:\program files\Google\Update\GoogleUpdate.exe [17/05/2009 12:32 PM 133104]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\aspi32.sys [21/05/2009 1:21 PM 16512]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\30.tmp –> c:\windows\system32\30.tmp [?]
.
Contents of the 'Scheduled Tasks' folder

2010-04-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 01:34]

2010-04-28 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-17 02:26]

2010-04-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-17 02:32]

2010-04-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-17 02:32]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.abc.net.au/
mSearch Bar = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-klmdb.sys



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-28 15:32
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.8.0.41\diMaster.dll\" /prefetch:1"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\30.tmp"
.
Completion time: 2010-04-28 15:33:52
ComboFix-quarantined-files.txt 2010-04-28 05:33

Pre-Run: 225,537,400,832 bytes free
Post-Run: 226,196,549,632 bytes free

- - End Of File - - 993BB5D286129FE57F6EAF844CA3EAE4
Hello blackdog

How are things doing?

please run GMER again and please note the options I have listed.

Gmer

Download GMER Rootkit Scanner from here.
  • Double click the .exe file. If asked to allow gmer.sys driver to load, please consent
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO

    🖼Click to load external image (Posted Image)
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file
  • Save it where you can easily find it, such as your desktop, and post it in reply
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Note: Do not run any programs while Gmer is running.


let me have this log

ill be back in about 1 hour


gringo
When I run Gmer it shuts down and I get this error report. When I run second time it completes scan and freezes when I try to save it. Keep trying ?

#
# An unexpected error has been detected by Java Runtime Environment:
#
# EXCEPTION_ACCESS_VIOLATION (0xc0000005) at pc=0x6d7a8d76, pid=3452, tid=1676
#
# Java VM: Java HotSpot™ Client VM (11.0-b16 mixed mode windows-x86)
# Problematic frame:
# C [unpack.dll+0x8d76]
#
# If you would like to submit a bug report, please visit:
# http://java.sun.com/webapps/bugreport/crash.jsp
# The crash happened outside the Java Virtual Machine in native code.
# See problematic frame for where to report the bug.
#

————— T H R E A D —————

Current thread (0x0afff000): JavaThread "thread applet-Show.class-1" [_thread_in_native, id=1676, stack(0x0c3b0000,0x0c400000)]

siginfo: ExceptionCode=0xc0000005, writing address 0x19fc0000

Registers:
EAX=0x00000005, EBX=0x00000005, ECX=0x19fc0000, EDX=0x000000aa
ESP=0x0c3fe9c0, EBP=0x0c3fe9dc, ESI=0x1a5cf008, EDI=0x19fbf490
EIP=0x6d7a8d76, EFLAGS=0x00010283

Top of Stack: (sp=0x0c3fe9c0)
0x0c3fe9c0: 00000000 1a5cf008 0afff114 00000003
0x0c3fe9d0: 00000000 0000007a 053fea08 0c3fea08
0x0c3fe9e0: 6d7a93dc 00000000 1a5cf008 6d7a9438
0x0c3fe9f0: 6d7a27bd 00000000 00000000 0afff000
0x0c3fea00: 071a20a8 071a20a8 0c3fea58 0091a372
0x0c3fea10: 0afff114 0c3fea74 00000000 00000000
0x0c3fea20: 00000000 071a2739 0c3fea74 0c3fea30
0x0c3fea30: 0afff005 06983318 0c3fea30 071a20a8

Instructions: (pc=0x6d7a8d76)
0x6d7a8d66: 49 88 5d ff 8d 3c cf 7e 1a 8b cf eb 03 8a 5d ff
0x6d7a8d76: 88 19 8b 5d f8 ff 45 f8 89 59 08 83 c1 18 39 55


Stack: [0x0c3b0000,0x0c400000], sp=0x0c3fe9c0, free space=314k
Native frames: (J=compiled Java code, j=interpreted, Vv=VM code, C=native code)
C [unpack.dll+0x8d76]
C [unpack.dll+0x93dc]
j com.sun.java.util.jar.pack.NativeUnpack.start(Ljava/nio/ByteBuffer;J)J+0
j com.sun.java.util.jar.pack.NativeUnpack.run(Ljava/io/InputStream;Ljava/util/jar/JarOutputStream;Ljava/nio/ByteBuffer;)V+93
j com.sun.java.util.jar.pack.NativeUnpack.run(Ljava/io/InputStream;Ljava/util/jar/JarOutputStream;)V+4
j com.sun.java.util.jar.pack.UnpackerImpl.unpack(Ljava/io/InputStream;Ljava/util/jar/JarOutputStream;)V+173
j com.sun.deploy.net.DownloadEngine.getJarFileWithoutCache(Ljava/net/URL;Ljava/lang/String;Ljava/lang/String;Lcom/sun/deploy/net/DownloadEngine$DownloadDelegate;I)Ljava/io/File;+289
j com.sun.deploy.net.DownloadEngine.downloadJarWithoutCache(Ljava/net/URL;Ljava/lang/String;Ljava/lang/String;Lcom/sun/deploy/net/DownloadEngine$DownloadDelegate;I)Ljava/io/File;+9
j sun.plugin.PluginURLJarFileCallBack$2.run()Ljava/lang/Object;+222
v ~StubRoutines::call_stub

Java frames: (J=compiled Java code, j=interpreted, Vv=VM code)
j com.sun.java.util.jar.pack.NativeUnpack.start(Ljava/nio/ByteBuffer;J)J+0
j com.sun.java.util.jar.pack.NativeUnpack.run(Ljava/io/InputStream;Ljava/util/jar/JarOutputStream;Ljava/nio/ByteBuffer;)V+93
j com.sun.java.util.jar.pack.NativeUnpack.run(Ljava/io/InputStream;Ljava/util/jar/JarOutputStream;)V+4
j com.sun.java.util.jar.pack.UnpackerImpl.unpack(Ljava/io/InputStream;Ljava/util/jar/JarOutputStream;)V+173
j com.sun.deploy.net.DownloadEngine.getJarFileWithoutCache(Ljava/net/URL;Ljava/lang/String;Ljava/lang/String;Lcom/sun/deploy/net/DownloadEngine$DownloadDelegate;I)Ljava/io/File;+289
j com.sun.deploy.net.DownloadEngine.downloadJarWithoutCache(Ljava/net/URL;Ljava/lang/String;Ljava/lang/String;Lcom/sun/deploy/net/DownloadEngine$DownloadDelegate;I)Ljava/io/File;+9
j sun.plugin.PluginURLJarFileCallBack$2.run()Ljava/lang/Object;+222
v ~StubRoutines::call_stub
j java.security.AccessController.doPrivileged(Ljava/security/PrivilegedExceptionAction;)Ljava/lang/Object;+0
j sun.plugin.PluginURLJarFileCallBack.retrieve(Ljava/net/URL;)Ljava/util/jar/JarFile;+73
j sun.net.www.protocol.jar.URLJarFile.retrieve(Ljava/net/URL;Lsun/net/www/protocol/jar/URLJarFile$URLJarFileCloseController;)Ljava/util/jar/JarFile;+10
j sun.net.www.protocol.jar.URLJarFile.getJarFile(Ljava/net/URL;Lsun/net/www/protocol/jar/URLJarFile$URLJarFileCloseController;)Ljava/util/jar/JarFile;+19
j sun.net.www.protocol.jar.JarFileFactory.get(Ljava/net/URL;Z)Ljava/util/jar/JarFile;+192
j sun.net.www.protocol.jar.JarURLConnection.connect()V+19
j sun.plugin.net.protocol.jar.CachedJarURLConnection.connect()V+98
j sun.plugin.net.protocol.jar.CachedJarURLConnection.getInputStream()Ljava/io/InputStream;+1
j sun.misc.URLClassPath$Loader.getResource(Ljava/lang/String;Z)Lsun/misc/Resource;+48
j sun.misc.URLClassPath.getResource(Ljava/lang/String;Z)Lsun/misc/Resource;+53
j java.net.URLClassLoader$1.run()Ljava/lang/Object;+26
v ~StubRoutines::call_stub
j java.security.AccessController.doPrivileged(Ljava/security/PrivilegedExceptionAction;Ljava/security/AccessControlContext;)Ljava/lang/Object;+0
j java.net.URLClassLoader.findClass(Ljava/lang/String;)Ljava/lang/Class;+13
j java.lang.ClassLoader.loadClass(Ljava/lang/String;Z)Ljava/lang/Class;+43
j java.net.FactoryURLClassLoader.loadClass(Ljava/lang/String;Z)Ljava/lang/Class;+36
j java.lang.ClassLoader.loadClass(Ljava/lang/String;)Ljava/lang/Class;+3
j java.lang.ClassLoader.loadClassInternal(Ljava/lang/String;)Ljava/lang/Class;+2
v ~StubRoutines::call_stub
j java.lang.Class.forName0(Ljava/lang/String;ZLjava/lang/ClassLoader;)Ljava/lang/Class;+0
j java.lang.Class.forName(Ljava/lang/String;ZLjava/lang/ClassLoader;)Ljava/lang/Class;+32
j Show.init()V+47
j sun.plugin2.applet.Plugin2Manager$AppletExecutionRunnable.run()V+837
j java.lang.Thread.run()V+11
v ~StubRoutines::call_stub

————— P R O C E S S —————

Java Threads: ( => current thread )
0x0b007800 JavaThread "Thread-10" [_thread_blocked, id=3592, stack(0x0c450000,0x0c4a0000)]
=>0x0afff000 JavaThread "thread applet-Show.class-1" [_thread_in_native, id=1676, stack(0x0c3b0000,0x0c400000)]
0x0afe8c00 JavaThread "AWT-EventQueue-2" [_thread_blocked, id=1756, stack(0x0c310000,0x0c360000)]
0x0afe8000 JavaThread "Applet 1 LiveConnect Worker Thread" [_thread_blocked, id=3516, stack(0x0b4a0000,0x0b4f0000)]
0x0afeb800 JavaThread "Browser Side Object Cleanup Thread" [_thread_blocked, id=3440, stack(0x0c2c0000,0x0c310000)]
0x0afcf000 JavaThread "Windows Tray Icon Thread" [_thread_in_native, id=3436, stack(0x0ba40000,0x0ba90000)]
0x0afcbc00 JavaThread "CacheCleanUpThread" daemon [_thread_blocked, id=3432, stack(0x0b9f0000,0x0ba40000)]
0x0afd7800 JavaThread "CacheMemoryCleanUpThread" daemon [_thread_blocked, id=3428, stack(0x0b590000,0x0b5e0000)]
0x0afb1800 JavaThread "AWT-EventQueue-0" [_thread_blocked, id=3540, stack(0x0b540000,0x0b590000)]
0x0afb0000 JavaThread "Java Plug-In Heartbeat Thread" [_thread_blocked, id=3536, stack(0x0b4f0000,0x0b540000)]
0x0afad000 JavaThread "AWT-Windows" daemon [_thread_in_native, id=3528, stack(0x0b3d0000,0x0b420000)]
0x0afa7400 JavaThread "AWT-Shutdown" [_thread_blocked, id=3524, stack(0x0b380000,0x0b3d0000)]
0x0afab800 JavaThread "Java2D Disposer" daemon [_thread_blocked, id=3520, stack(0x0b330000,0x0b380000)]
0x0af7e000 JavaThread "Java Plug-In Pipe Worker Thread (Client-Side)" [_thread_in_native, id=3500, stack(0x0b290000,0x0b2e0000)]
0x0af81c00 JavaThread "traceMsgQueueThread" daemon [_thread_blocked, id=3424, stack(0x0b1a0000,0x0b1f0000)]
0x0af73000 JavaThread "Timer-0" [_thread_blocked, id=592, stack(0x0b150000,0x0b1a0000)]
0x0aac4800 JavaThread "Low Memory Detector" daemon [_thread_blocked, id=144, stack(0x0ad10000,0x0ad60000)]
0x0aabe800 JavaThread "CompilerThread0" daemon [_thread_blocked, id=3480, stack(0x0acc0000,0x0ad10000)]
0x0aabd000 JavaThread "Attach Listener" daemon [_thread_blocked, id=3492, stack(0x0ac70000,0x0acc0000)]
0x0aabbc00 JavaThread "Signal Dispatcher" daemon [_thread_blocked, id=3304, stack(0x0ac20000,0x0ac70000)]
0x0aaa8c00 JavaThread "Finalizer" daemon [_thread_blocked, id=1252, stack(0x0abd0000,0x0ac20000)]
0x0aaa7800 JavaThread "Reference Handler" daemon [_thread_blocked, id=3132, stack(0x0ab80000,0x0abd0000)]
0x002b6800 JavaThread "main" [_thread_blocked, id=3472, stack(0x008c0000,0x00910000)]

Other Threads:
0x0aaa2800 VMThread [stack: 0x0ab30000,0x0ab80000] [id=1408]
0x0aac6c00 WatcherThread [stack: 0x0ad60000,0x0adb0000] [id=196]

VM state:not at safepoint (normal execution)

VM Mutex/Monitor currently owned by a thread: None

Heap
def new generation total 4544K, used 4544K [0x02990000, 0x02e70000, 0x02e70000)
eden space 4096K, 100% used [0x02990000, 0x02d90000, 0x02d90000)
from space 448K, 100% used [0x02d90000, 0x02e00000, 0x02e00000)
to space 448K, 0% used [0x02e00000, 0x02e00000, 0x02e70000)
tenured generation total 60544K, used 60518K [0x02e70000, 0x06990000, 0x06990000)
the space 60544K, 99% used [0x02e70000, 0x06989990, 0x06989a00, 0x06990000)
compacting perm gen total 12288K, used 8274K [0x06990000, 0x07590000, 0x0a990000)
the space 12288K, 67% used [0x06990000, 0x071a4b28, 0x071a4c00, 0x07590000)
No shared spaces configured.

Dynamic libraries:
0x00400000 - 0x00424000 C:\Program Files\Java\jre6\bin\java.exe
0x7c900000 - 0x7c9b2000 C:\WINDOWS\system32\ntdll.dll
0x7c800000 - 0x7c8f6000 C:\WINDOWS\system32\kernel32.dll
0x77dd0000 - 0x77e6b000 C:\WINDOWS\system32\ADVAPI32.dll
0x77e70000 - 0x77f02000 C:\WINDOWS\system32\RPCRT4.dll
0x77fe0000 - 0x77ff1000 C:\WINDOWS\system32\Secur32.dll
0x7c340000 - 0x7c396000 C:\Program Files\Java\jre6\bin\msvcr71.dll
0x6d800000 - 0x6da56000 C:\Program Files\Java\jre6\bin\client\jvm.dll
0x7e410000 - 0x7e4a1000 C:\WINDOWS\system32\USER32.dll
0x77f10000 - 0x77f59000 C:\WINDOWS\system32\GDI32.dll
0x76b40000 - 0x76b6d000 C:\WINDOWS\system32\WINMM.dll
0x76390000 - 0x763ad000 C:\WINDOWS\system32\IMM32.DLL
0x6d280000 - 0x6d288000 C:\Program Files\Java\jre6\bin\hpi.dll
0x76bf0000 - 0x76bfb000 C:\WINDOWS\system32\PSAPI.DLL
0x6d7b0000 - 0x6d7bc000 C:\Program Files\Java\jre6\bin\verify.dll
0x6d320000 - 0x6d33f000 C:\Program Files\Java\jre6\bin\java.dll
0x6d7f0000 - 0x6d7ff000 C:\Program Files\Java\jre6\bin\zip.dll
0x6d430000 - 0x6d436000 C:\Program Files\Java\jre6\bin\jp2native.dll
0x6d1c0000 - 0x6d1d3000 C:\Program Files\Java\jre6\bin\deploy.dll
0x77a80000 - 0x77b15000 C:\WINDOWS\system32\CRYPT32.dll
0x77b20000 - 0x77b32000 C:\WINDOWS\system32\MSASN1.dll
0x77c10000 - 0x77c68000 C:\WINDOWS\system32\msvcrt.dll
0x7c9c0000 - 0x7d1d7000 C:\WINDOWS\system32\SHELL32.dll
0x77f60000 - 0x77fd6000 C:\WINDOWS\system32\SHLWAPI.dll
0x774e0000 - 0x7761d000 C:\WINDOWS\system32\ole32.dll
0x77120000 - 0x771ab000 C:\WINDOWS\system32\OLEAUT32.dll
0x3d930000 - 0x3da16000 C:\WINDOWS\system32\WININET.dll
0x003f0000 - 0x003f9000 C:\WINDOWS\system32\Normaliz.dll
0x78130000 - 0x78262000 C:\WINDOWS\system32\urlmon.dll
0x3dfd0000 - 0x3e1b8000 C:\WINDOWS\system32\iertutil.dll
0x773d0000 - 0x774d3000 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
0x6d6b0000 - 0x6d6f2000 C:\Program Files\Java\jre6\bin\regutils.dll
0x77c00000 - 0x77c08000 C:\WINDOWS\system32\VERSION.dll
0x7d1e0000 - 0x7d49c000 C:\WINDOWS\system32\msi.dll
0x6d610000 - 0x6d623000 C:\Program Files\Java\jre6\bin\net.dll
0x71ab0000 - 0x71ac7000 C:\WINDOWS\system32\WS2_32.dll
0x71aa0000 - 0x71aa8000 C:\WINDOWS\system32\WS2HELP.dll
0x6d630000 - 0x6d639000 C:\Program Files\Java\jre6\bin\nio.dll
0x6d000000 - 0x6d138000 C:\Program Files\Java\jre6\bin\awt.dll
0x73000000 - 0x73026000 C:\WINDOWS\system32\WINSPOOL.DRV
0x5ad70000 - 0x5ada8000 C:\WINDOWS\system32\uxtheme.dll
0x74720000 - 0x7476c000 C:\WINDOWS\system32\MSCTF.dll
0x10000000 - 0x10027000 C:\OPLIMIT\oahook32.dll
0x77b40000 - 0x77b62000 C:\WINDOWS\system32\apphelp.dll
0x755c0000 - 0x755ee000 C:\WINDOWS\system32\msctfime.ime
0x6d220000 - 0x6d274000 C:\Program Files\Java\jre6\bin\fontmanager.dll
0x6d190000 - 0x6d1b3000 C:\Program Files\Java\jre6\bin\dcpr.dll
0x71a50000 - 0x71a8f000 C:\WINDOWS\System32\mswsock.dll
0x76f20000 - 0x76f47000 C:\WINDOWS\system32\DNSAPI.dll
0x76fb0000 - 0x76fb8000 C:\WINDOWS\System32\winrnr.dll
0x76f60000 - 0x76f8c000 C:\WINDOWS\system32\WLDAP32.dll
0x76fc0000 - 0x76fc6000 C:\WINDOWS\system32\rasadhlp.dll
0x662b0000 - 0x66308000 C:\WINDOWS\system32\hnetcfg.dll
0x71a90000 - 0x71a98000 C:\WINDOWS\System32\wshtcpip.dll
0x68000000 - 0x68036000 C:\WINDOWS\system32\rsaenh.dll
0x769c0000 - 0x76a74000 C:\WINDOWS\system32\USERENV.dll
0x5b860000 - 0x5b8b5000 C:\WINDOWS\system32\netapi32.dll
0x6d7a0000 - 0x6d7af000 C:\Program Files\Java\jre6\bin\unpack.dll

VM Arguments:
jvm_args: -D__jvm_launched=1185656751 -Xbootclasspath/a:C:\PROGRA~1\Java\jre6\lib\deploy.jar;C:\PROGRA~1\Java\jre6\lib\javaws.jar;C:\PROGRA~1\Java\jre6\lib\plugin.jar
java_command: sun.plugin2.main.client.PluginMain write_pipe_name=jpi2_pid2456_pipe3,read_pipe_name=jpi2_pid2456_pipe2
Launcher Type: SUN_STANDARD

Environment Variables:
PATH=C:\Program Files\Internet Explorer;;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Common-Use Signing Interface\JRE\bin
USERNAME=User
OS=Windows_NT
PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 11, GenuineIntel



————— S Y S T E M —————

OS: Windows XP Build 2600 Service Pack 3

CPU:total 4 (4 cores per cpu, 1 threads per core) family 6 model 15 stepping 11, cmov, cx8, fxsr, mmx, sse, sse2, sse3, ssse3

Memory: 4k page, physical 2087020k(1260152k free), swap 4025388k(3351560k free)

vm_info: Java HotSpot™ Client VM (11.0-b16) for windows-x86 JRE (1.6.0_11-b03), built on Nov 10 2008 02:15:12 by "java_re" with MS VC++ 7.1

time: Tue Aug 25 12:10:08 2009
elapsed time: 11 seconds
Hello

Run it in safe mode.


Boot into Safe Mode

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.


Gringo
While running Gmer in safe mode computor restarted itself on restart there was microsoft error report BCCode : 1000007f BCP1 : 0000000D BCP2 : 00000000 BCP3 : 00000000 BCP4 : 00000000 OSVer : 5_1_2600 SP : 3_0 Product : 768_1 Keep trying ?
success

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-29 19:34:24
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\User\LOCALS~1\Temp\axlyapob.sys


—- Kernel code sections - GMER 1.0.15 —-

? SYMEFA.SYS The system cannot find the file specified. !

—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 sector 01: copy of MBR
Disk \Device\Harddisk0\DR0 sector 02: copy of MBR
Disk \Device\Harddisk0\DR0 sector 03: copy of MBR
Disk \Device\Harddisk0\DR0 sector 04: copy of MBR
Disk \Device\Harddisk0\DR0 sector 05: copy of MBR
Disk \Device\Harddisk0\DR0 sector 06: copy of MBR
Disk \Device\Harddisk0\DR0 sector 07: copy of MBR
Disk \Device\Harddisk0\DR0 sector 08: copy of MBR
Disk \Device\Harddisk0\DR0 sector 09: copy of MBR
Disk \Device\Harddisk0\DR0 sector 10: copy of MBR
Disk \Device\Harddisk0\DR0 sector 11: copy of MBR
Disk \Device\Harddisk0\DR0 sector 12: copy of MBR
Disk \Device\Harddisk0\DR0 sector 13: copy of MBR
Disk \Device\Harddisk0\DR0 sector 14: copy of MBR
Disk \Device\Harddisk0\DR0 sector 15: copy of MBR
Disk \Device\Harddisk0\DR0 sector 16: copy of MBR
Disk \Device\Harddisk0\DR0 sector 17: copy of MBR
Disk \Device\Harddisk0\DR0 sector 18: copy of MBR
Disk \Device\Harddisk0\DR0 sector 19: copy of MBR
Disk \Device\Harddisk0\DR0 sector 20: copy of MBR
Disk \Device\Harddisk0\DR0 sector 21: copy of MBR
Disk \Device\Harddisk0\DR0 sector 22: copy of MBR
Disk \Device\Harddisk0\DR0 sector 23: copy of MBR
Disk \Device\Harddisk0\DR0 sector 24: copy of MBR
Disk \Device\Harddisk0\DR0 sector 25: copy of MBR
Disk \Device\Harddisk0\DR0 sector 26: copy of MBR
Disk \Device\Harddisk0\DR0 sector 27: copy of MBR
Disk \Device\Harddisk0\DR0 sector 28: copy of MBR
Disk \Device\Harddisk0\DR0 sector 29: copy of MBR
Disk \Device\Harddisk0\DR0 sector 30: copy of MBR
Disk \Device\Harddisk0\DR0 sector 31: copy of MBR
Disk \Device\Harddisk0\DR0 sector 32: rootkit-like behavior; copy of MBR
Disk \Device\Harddisk0\DR0 sector 33: copy of MBR
Disk \Device\Harddisk0\DR0 sector 34: copy of MBR
Disk \Device\Harddisk0\DR0 sector 35: copy of MBR
Disk \Device\Harddisk0\DR0 sector 36: copy of MBR
Disk \Device\Harddisk0\DR0 sector 37: copy of MBR
Disk \Device\Harddisk0\DR0 sector 38: copy of MBR
Disk \Device\Harddisk0\DR0 sector 39: copy of MBR
Disk \Device\Harddisk0\DR0 sector 40: copy of MBR
Disk \Device\Harddisk0\DR0 sector 41: copy of MBR
Disk \Device\Harddisk0\DR0 sector 42: copy of MBR
Disk \Device\Harddisk0\DR0 sector 43: copy of MBR
Disk \Device\Harddisk0\DR0 sector 44: copy of MBR
Disk \Device\Harddisk0\DR0 sector 45: copy of MBR
Disk \Device\Harddisk0\DR0 sector 46: copy of MBR
Disk \Device\Harddisk0\DR0 sector 47: copy of MBR
Disk \Device\Harddisk0\DR0 sector 48: copy of MBR
Disk \Device\Harddisk0\DR0 sector 49: copy of MBR
Disk \Device\Harddisk0\DR0 sector 50: copy of MBR
Disk \Device\Harddisk0\DR0 sector 51: copy of MBR
Disk \Device\Harddisk0\DR0 sector 52: copy of MBR
Disk \Device\Harddisk0\DR0 sector 53: copy of MBR
Disk \Device\Harddisk0\DR0 sector 54: copy of MBR
Disk \Device\Harddisk0\DR0 sector 55: copy of MBR
Disk \Device\Harddisk0\DR0 sector 56: copy of MBR
Disk \Device\Harddisk0\DR0 sector 57: copy of MBR
Disk \Device\Harddisk0\DR0 sector 58: copy of MBR
Disk \Device\Harddisk0\DR0 sector 59: copy of MBR
Disk \Device\Harddisk0\DR0 sector 60: copy of MBR
Disk \Device\Harddisk0\DR0 sector 61: copy of MBR
Disk \Device\Harddisk0\DR0 sector 62: copy of MBR
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior; copy of MBR

—- EOF - GMER 1.0.15 —-
Hello Blackdog

How is the computer doing now? does it still redirect?


Please print out these instructions, or copy them to a Notepad file. It will make it easier for you to follow the instructions and complete all of the necessary steps..


uninstall some programs

1. click on start
2. then go to settings
3. after that you need control panel
4. look for the icon add/remove programs
click on the following programs

Adobe Reader 8
Mirar


and click on remove

Update Adobe Reader

Recently there have been vunerabilities detected in older versions of Adobe Reader. It is strongly suggested that you update to the current version.

You can download it from http://www.adobe.com/products/acrobat/readstep2.html
After installing the latest Adobe Reader, uninstall all previous versions.
If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

If you don't like Adobe Reader (33.5 MB), you can download Foxit PDF Reader(3.5MB) from here. It's a much smaller file to download and uses a lot less resources than Adobe Reader.

Note: When installing FoxitReader, be carefull not to install anything to do with AskBar.

Your Java is out of date.

It can be updated by the Java control panel
  • click on Start-> Control Panel (Classic View)-> Java (looks like a coffee cup) -> Update Tab -> Update Now.
  • An update should begin;
  • follow the prompts
  • After the update is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.

TFC(Temp File Cleaner):

  • Please download TFC to your desktop,
  • Save any unsaved work. TFC will close all open application windows.
  • Double-click TFC.exe to run the program.
  • If prompted, click "Yes" to reboot.
Note: Save your work. TFC will automatically close any open programs, let it run uninterrupted. It shouldn't take longer take a couple of minutes, and may only take a few seconds. Only if needed will you be prompted to reboot.

: Malwarebytes' Anti-Malware :

  • Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to
    • Update Malwarebytes' Anti-Malware
    • and Launch Malwarebytes' Anti-Malware
  • then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is Checked (ticked) except items in the C:\System Volume Information folder and click on Remove Selected.
  • When completed, a log will open in Notepad. please copy and paste the log into your next reply
    • If you accidently close it, the log file is saved here and will be named like this:
    • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.


:Kaspersky scan:

  • Please go to Kaspersky website and perform an online antivirus scan.

    • Read through the requirements and privacy statement and click on Accept button.
    • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    • When the downloads have finished, click on Settings.
    • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button: Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

"information and logs"

  • In your next post I need the following

  • Log From MBAM
  • Log From Kaspersky
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
I dont get redirects I get win patrol warning all the time. I get a blank window titled Mirar unistall but nothing happens I have malware bytes on my computor already it OK to use that one I also have adobe professional 6.0.1 do I need to lose that aswell

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI