This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infected PC (slow running, redirected web-pages, etc.)

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey there!

My name is Aleks. Recentely I have had problems with my computer concerning it's overall speed and performance. It seems like programs are running slow, internet pages get redirected to complete random web-ads and some other small issues.

I managed to get a DDS log with an attachment however I could not get an HJT log by any means. This is where the other problem concerns me. Strangely enough when I try to get a new anti-virus program like macfee or Avast installed on my computer and running, for some reason they decided to shut off. I tried to run HJT and as soon as it popped up it was gone. My only virus defender at this point is my Spyware Doctor and he isn't doing much to help. In any case, I really appreciate the help!

DSS Log


DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 22:05:18.44 on Sun 05/23/2010
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2559.1404 [GMT -4:00]

AV: Spyware Doctor with AntiVirus *On-access scanning enabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
AV: AVG 7.5.524 *On-access scanning enabled* (Outdated) {41564737-3200-1071-989B-0000E87B4FB1}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
C:\Program Files\Turbine\Turbine Download Manager\TurbineMessageService.exe
c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\Zune\ZuneNss.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Turbine\Turbine Download Manager\TurbineDownloadManagerIcon.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Me\Local Settings\Temporary Internet Files\Content.IE5\D1O5QZL5\dds[1].scr
C:\WINDOWS\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
BHO: {02478d38-c3f9-4efb-9b51-7695eca05670} - Yahoo! Toolbar Helper
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AIM Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - c:\program files\aim toolbar\aimtb.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll
uRun: [Steam] "c:\program files\valve\steam\steam.exe" -silent
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [RegistryMechanic] c:\program files\registry mechanic\RegMech.exe /H
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US ee://aol/imApp
mRun: [AVG7_CC] c:\progra~1\grisoft\avg7\avgcc.exe /STARTUP
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [PinnacleDriverCheck] c:\windows\system32\PSDrvCheck.exe -CheckReg
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [Ulead AutoDetector v2] c:\program files\common files\ulead systems\autodetector\monitor.exe
mRun: [USB2Check] RUNDLL32.EXE "c:\windows\system32\PCLECoInst.dll",CheckUSBController
mRun: [USBToolTip] "c:\program files\pinnacle\shared files\\programs\usbtip\USBTip.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Turbine Download Manager Tray Icon] "c:\program files\turbine\turbine download manager\TurbineDownloadManagerIcon.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe"
mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe"
dRun: [AVG7_Run] c:\progra~1\grisoft\avg7\avgw.exe /RUNONCE
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {0b83c99c-1efa-4259-858f-bcb33e007a5b} - {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.srtest.com/srl_bin/sysreqlab3.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab}
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1192098404078
DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} - hxxp://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1192098236312
DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: dfceadbfedb - c:\windows\system32\dfceadbfedb.dll
Notify: ebfaaeefbd - c:\windows\system32\ebfaaeefbd.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

============= SERVICES / DRIVERS ===============

R? abcaccadda;1c1257c6a231bc1264b422d2129a46aa
R? AVGEMS;AVG E-mail Scanner
R? icsak;icsak
R? LiveTurbineNetworkService;Turbine Network Service - Live
R? MSSQLServerADHelper100;SQL Active Directory Helper Service
R? RsFx0102;RsFx0102 Driver
R? SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS)
S? adbf;adbf
S? Avg7Alrt;AVG7 Alert Manager Server
S? Avg7Core;AVG7 Kernel
S? Avg7RsW;AVG7 Wrap Driver
S? Avg7RsXP;AVG7 Resident Driver XP
S? Avg7UpdSvc;AVG7 Update Service
S? AvgClean;AVG7 Clean Driver
S? AvgTdi;AVG Network Redirector
S? Browser Defender Update Service;Browser Defender Update Service
S? LiveTurbineMessageService;Turbine Message Service - Live
S? PCTCore;PCTools KDS
S? pctgntdi;pctgntdi
S? pctplsg;pctplsg
S? sdAuxService;PC Tools Auxiliary Service
S? sdCoreService;PC Tools Security Service
S? TfFsMon;TfFsMon
S? TfNetMon;TfNetMon
S? TfSysMon;TfSysMon
S? ThreatFire;ThreatFire
S? Viewpoint Manager Service;Viewpoint Manager Service

=============== Created Last 30 ================

2010-05-16 20:43:41 0 d—–w- c:\program files\YouTube Downloader

==================== Find3M ====================

2010-05-09 21:56:54 1984 —-a-w- c:\windows\system32\d3d9caps.dat
2010-04-18 21:38:42 165392 —-a-w- c:\windows\system32\9e15b39b2b92e9224ad80e6357daafe8.exe
2010-03-16 23:11:12 165392 —-a-w- c:\windows\system32\db41be6ef5c3a8885014702b7946246f.exe
2010-03-11 20:30:10 165392 —-a-w- c:\windows\system32\5cd2eec45cf72f7c8530a6ef0e8d3025.exe
2010-03-11 12:38:54 832512 —-a-w- c:\windows\system32\wininet.dll
2010-03-11 12:38:52 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:38:51 17408 —-a-w- c:\windows\system32\corpol.dll
2010-03-09 11:09:18 430080 —-a-w- c:\windows\system32\vbscript.dll
2009-05-01 19:51:41 32768 -csha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009050120090502\index.dat
2010-02-08 23:35:36 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\index.dat
2009-06-14 17:10:21 9451552 –sha-w- c:\windows\system32\drivers\fidbox.dat
2009-10-03 15:22:06 16384 –sha-w- c:\windows\temp\cookies\index.dat
2009-10-03 15:22:06 16384 –sha-w- c:\windows\temp\history\history.ie5\index.dat
2009-10-03 15:22:06 16384 –sha-w- c:\windows\temp\temporary internet files\content.ie5\index.dat

============= FINISH: 22:25:27.91 ===============



Thanks a bunch!
Hello Aleks and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!
Please be advised I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
This may cause a delay in response time, but I will do my best to keep it as short as possible.

I will post back shortly with instructions.
It appears you still have an old version of AVG on your machine. This version is no longer supported and not updating - thus providing no protection. In addition, having more than one anti-virus program on your machine can cause conflicts, including slowing down your machine and general poor performance. Before continuing on, please go to your Control Panel, choose Add/Remove Programs and uninstall AVG 7.5. If you are not prompted to do so, please reboot afterwards.

If you have CDEmulation drivers installed (such as Daemon Tools, Alcohol120) please follow the instructions below to run DeFogger prior to and after running GMER. If you do not have any CDEmulation drivers installed, you do not need to run DeFogger and you can go right to the instructions to run GMER.

Download DeFogger

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

Download and Run GMER

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hey, I just tried running gmer.exe and I had it running for about 5 hours when it seemed like it was practically done I stopped it so I can take that huge list of data and post it on here. But as soon as I tried to copy/paste the file my computer decided to have a crash so with that said I think I might run the program tomorrow early in the day so it finishes entirely without me stopping. Mainly, the reason its taking so long (in my opinion) is because its scanning everything in my C: drive and that particular drive has about 240Gb of used space so… Im not sure what to do about that. Let me know what you think I should do. Thank you!
It is important we get a GMER scan so we can make sure there is no rootkit activity on the machine.

Please make sure to Uncheck the following boxes when you run it:
  • IAT/EAT
  • Drives/Partition other than Systemdrive (typically C:\)
  • Show All (don't miss this one)
Please allow it to run until it has completed. Stopping the scan before it is finished will not give us accurate information to work with. When the scan has finished, it will produce a log file you can save and use to copy and paste into your next reply.
Hey. Here is the log GMER came up with

GMER LOG

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-25 20:41:54
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\Me\LOCALS~1\Temp\uwtdypow.sys


—- System - GMER 1.0.15 —-

SSDT TfSysMon.sys (ThreatFire System Monitor/PC Tools) ZwCreateKey [0xBA693A1C]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0xBA6B9CDE]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0xBA6B9ED0]
SSDT TfSysMon.sys (ThreatFire System Monitor/PC Tools) ZwDeleteKey [0xBA693C10]
SSDT TfSysMon.sys (ThreatFire System Monitor/PC Tools) ZwDeleteValueKey [0xBA693CB6]
SSDT TfSysMon.sys (ThreatFire System Monitor/PC Tools) ZwOpenKey [0xBA69390C]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwRenameKey [0xBA6D9D60]
SSDT TfSysMon.sys (ThreatFire System Monitor/PC Tools) ZwSetValueKey [0xBA693E52]
SSDT TfSysMon.sys (ThreatFire System Monitor/PC Tools) ZwTerminateProcess [0xBA695B30]

Code b75d9bbc831a627370592771d8e3ff8d.sys (ckmd/Noves Inc) ZwCreateKey [0xBA8DBC8E]
Code b75d9bbc831a627370592771d8e3ff8d.sys (ckmd/Noves Inc) ZwEnumerateKey [0xBA8DBD13]
Code b75d9bbc831a627370592771d8e3ff8d.sys (ckmd/Noves Inc) ZwOpenKey [0xBA8DBC10]
Code b75d9bbc831a627370592771d8e3ff8d.sys (ckmd/Noves Inc) ZwQueryDirectoryFile [0xBA8DB999]
Code b75d9bbc831a627370592771d8e3ff8d.sys (ckmd/Noves Inc) IoCreateFile
Code \WINDOWS\system32\ntkrnlpa.exe[PAGEVRFY] [80657088] pIofCallDriver
Code \WINDOWS\system32\ntkrnlpa.exe[PAGEVRFY] [8065771E] pIofCompleteRequest
Code b75d9bbc831a627370592771d8e3ff8d.sys (ckmd/Noves Inc) NtQueryDirectoryFile

—- Kernel code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB94DF360, 0x32DEFD, 0xE8000020]
? C:\WINDOWS\system32\adbf.sys The process cannot access the file because it is being used by another process.

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs TfFsMon.sys (ThreatFire Filesystem Monitor/PC Tools)
AttachedDevice \Driver\Tcpip \Device\Ip pctgntdi.sys (PC Tools Generic TDI Driver/PC Tools)
AttachedDevice \Driver\Tcpip \Device\Tcp pctgntdi.sys (PC Tools Generic TDI Driver/PC Tools)
AttachedDevice \Driver\Tcpip \Device\Udp pctgntdi.sys (PC Tools Generic TDI Driver/PC Tools)
AttachedDevice \Driver\Tcpip \Device\RawIp pctgntdi.sys (PC Tools Generic TDI Driver/PC Tools)

—- Services - GMER 1.0.15 —-

Service C:\WINDOWS\system32\b75d9bbc831a627370592771d8e3ff8d.sys (*** hidden *** ) [BOOT] b75d9bbc831a627370592771d8e3ff8d <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\b75d9bbc831a627370592771d8e3ff8d
Reg HKLM\SYSTEM\CurrentControlSet\Services\b75d9bbc831a627370592771d8e3ff8d@c ®istry_path=\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\b75d9bbc831a627370592771d8e3ff8d&download_period=846000&first_download_delay=180&version=2&ip_0=586742989&port_0=7000&max_fails_0=5&ip_1=704183501&port_1=8300&max_fails_1=5&ip_2=2241985741&port_2=9002&max_fails_2=2&ip_3=1512966353&port_3=11234&max_fails_3=2&ips_count=4&name=b75d9bbc831a627370592771d8e3ff8d&path=system32\b75d9bbc831a627370592771d8e3ff8d.sys&wmid=03003&idate=2009-12-14 19:28:34:734&last_download_time=2010-5-25 15:22:57.390&first_skip=1&last_update_ip_pos=1&fails_0=5&fails_1=4
Reg HKLM\SYSTEM\CurrentControlSet\Services\b75d9bbc831a627370592771d8e3ff8d@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\b75d9bbc831a627370592771d8e3ff8d@Start 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\b75d9bbc831a627370592771d8e3ff8d@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\b75d9bbc831a627370592771d8e3ff8d@Tag 6
Reg HKLM\SYSTEM\CurrentControlSet\Services\b75d9bbc831a627370592771d8e3ff8d@ImagePath system32\b75d9bbc831a627370592771d8e3ff8d.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\b75d9bbc831a627370592771d8e3ff8d@DisplayName b75d9bbc831a627370592771d8e3ff8d
Reg HKLM\SYSTEM\CurrentControlSet\Services\b75d9bbc831a627370592771d8e3ff8d@Group System Bus Extender
Reg HKLM\SYSTEM\CurrentControlSet\Services\b75d9bbc831a627370592771d8e3ff8d\Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\b75d9bbc831a627370592771d8e3ff8d\Security@Security 0x01 0x00 0x14 0x80 …
Reg HKLM\SYSTEM\ControlSet002\Services\adbf@DependOnGroup
Reg HKLM\SYSTEM\ControlSet002\Services\b75d9bbc831a627370592771d8e3ff8d (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\b75d9bbc831a627370592771d8e3ff8d@c ®istry_path=\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\b75d9bbc831a627370592771d8e3ff8d&download_period=846000&first_download_delay=180&version=2&ip_0=586742989&port_0=7000&max_fails_0=5&ip_1=704183501&port_1=8300&max_fails_1=5&ip_2=2241985741&port_2=9002&max_fails_2=2&ip_3=1512966353&port_3=11234&max_fails_3=2&ips_count=4&name=b75d9bbc831a627370592771d8e3ff8d&path=system32\b75d9bbc831a627370592771d8e3ff8d.sys&wmid=03003&idate=2009-12-14 19:28:34:734&last_download_time=2010-5-25 15:22:57.390&first_skip=1&last_update_ip_pos=1&fails_0=5&fails_1=4
Reg HKLM\SYSTEM\ControlSet002\Services\b75d9bbc831a627370592771d8e3ff8d@Type 1
Reg HKLM\SYSTEM\ControlSet002\Services\b75d9bbc831a627370592771d8e3ff8d@Start 0
Reg HKLM\SYSTEM\ControlSet002\Services\b75d9bbc831a627370592771d8e3ff8d@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet002\Services\b75d9bbc831a627370592771d8e3ff8d@Tag 6
Reg HKLM\SYSTEM\ControlSet002\Services\b75d9bbc831a627370592771d8e3ff8d@ImagePath system32\b75d9bbc831a627370592771d8e3ff8d.sys
Reg HKLM\SYSTEM\ControlSet002\Services\b75d9bbc831a627370592771d8e3ff8d@DisplayName b75d9bbc831a627370592771d8e3ff8d
Reg HKLM\SYSTEM\ControlSet002\Services\b75d9bbc831a627370592771d8e3ff8d@Group System Bus Extender
Reg HKLM\SYSTEM\ControlSet002\Services\b75d9bbc831a627370592771d8e3ff8d\Security (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\b75d9bbc831a627370592771d8e3ff8d\Security@Security 0x01 0x00 0x14 0x80 …
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xC8 0x28 0x51 0xAF …
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x6A 0x9C 0xD6 0x61 …
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0xFF 0x7C 0x85 0xE0 …
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x6B 0x65 0x49 0x6A …
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xF5 0x1D 0x4D 0x73 …
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xB0 0x18 0xED 0xA7 …
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0xFB 0xA7 0x78 0xE6 …
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x83 0x6C 0x56 0x8B …
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0x51 0xFA 0x6E 0x91 …
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0xB1 0xCD 0x45 0x5A …
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0x2A 0xB7 0xCC 0xB5 …
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F …

—- EOF - GMER 1.0.15 —-
Download Combofix and RE-NAME it BEFORE saving
  • Download Combofix from either of the links below. You must rename it to Aleks.exe before saving it.
  • Save it to your desktop. Change the ”save as file type” to ”all files”.
  • Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop.
  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools > Options > Main tab
  • Set to “Always ask me where to Save the files”
Link 1
Link 2
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause ”unpredictable results”.
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don’t know how to disable it, please ask.
  • NOTE: If ComboFix asks to install the Recovery Console, please ALLOW it to do so.
  • Double click on the renamed ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Hey there. My computer is running smoother now it seems but I'm not sure if it's 100% yet. I haven't tested out its random pop ups but it is doing a lot better than it did the other day so much appreciated :lol:

Here is the Combo Log

ComboFix 10-05-26.01 - Me 05/26/2010 16:10:53.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2559.2050 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Aleks.exe
AV: Spyware Doctor with AntiVirus *On-access scanning enabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\9g2234wesdf3dfgjf23
c:\windows\system32\adbf.sys
c:\windows\system32\PCLECoInst.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_adbf
——-\Service_adbf


((((((((((((((((((((((((( Files Created from 2010-04-26 to 2010-05-26 )))))))))))))))))))))))))))))))
.

2010-05-25 01:55 . 2010-05-25 01:55 ——– dc—-w- c:\documents and settings\All Users\Application Data\Avg7
2010-05-23 14:34 . 2010-05-23 14:34 ——– d—–w- c:\documents and settings\Me\Local Settings\Application Data\PCHealth
2010-05-16 20:43 . 2010-05-16 20:43 ——– d—–w- c:\program files\YouTube Downloader

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-26 20:31 . 2008-01-13 23:48 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-05-26 19:46 . 2009-01-04 17:23 ——– d—–w- c:\documents and settings\Me\Application Data\Hamachi
2010-05-26 19:36 . 2010-01-10 22:24 ——– d—–w- c:\program files\Spyware Doctor
2010-05-25 23:41 . 2010-05-25 23:41 503808 —-a-w- c:\documents and settings\Me\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-5230d71d-n\msvcp71.dll
2010-05-25 23:41 . 2010-05-25 23:41 499712 —-a-w- c:\documents and settings\Me\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-5230d71d-n\jmc.dll
2010-05-25 23:41 . 2010-05-25 23:41 348160 —-a-w- c:\documents and settings\Me\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-5230d71d-n\msvcr71.dll
2010-05-25 01:41 . 2008-10-02 23:06 ——– d—–w- c:\documents and settings\Me\Application Data\LimeWire
2010-05-24 00:49 . 2009-07-20 18:43 ——– d—–w- c:\documents and settings\Me\Application Data\Skype
2010-05-23 14:47 . 2009-10-25 15:41 1 —-a-w- c:\documents and settings\Me\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-05-22 20:10 . 2009-01-04 19:20 ——– d—–w- c:\documents and settings\Me\Application Data\skypePM
2010-05-09 21:56 . 2008-01-17 23:33 1984 —-a-w- c:\windows\system32\d3d9caps.dat
2010-05-02 19:09 . 2007-08-12 01:06 54888 —-a-w- c:\documents and settings\Me\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-19 16:18 . 2010-01-10 22:24 ——– dc—-w- c:\documents and settings\All Users\Application Data\PC Tools
2010-04-19 16:17 . 2008-04-24 23:54 ——– d—–w- c:\program files\Vstplugins
2010-04-19 16:16 . 2010-02-02 00:19 ——– d—–w- c:\program files\AviSynth 2.5
2010-04-19 15:55 . 2010-04-19 15:55 ——– dc—-w- c:\documents and settings\All Users\Application Data\XoftSpySE
2010-04-18 22:44 . 2008-12-29 19:08 ——– d—–w- c:\program files\World of Warcraft
2010-04-18 21:38 . 2010-04-18 21:38 165392 —-a-w- c:\windows\system32\9e15b39b2b92e9224ad80e6357daafe8.exe
2010-04-11 16:01 . 2009-09-09 23:46 ——– d—–w- c:\program files\Turbine
2010-03-31 18:37 . 2010-03-31 18:37 ——– d—–w- c:\program files\Common Files\Skype
2010-03-16 23:11 . 2010-03-16 23:11 165392 —-a-w- c:\windows\system32\db41be6ef5c3a8885014702b7946246f.exe
2010-03-11 20:30 . 2010-03-11 20:30 165392 —-a-w- c:\windows\system32\5cd2eec45cf72f7c8530a6ef0e8d3025.exe
2010-03-11 12:38 . 2006-03-04 03:33 832512 —-a-w- c:\windows\system32\wininet.dll
2010-03-11 12:38 . 2004-08-04 10:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:38 . 2004-08-04 10:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-03-09 11:09 . 2004-08-04 10:00 430080 —-a-w- c:\windows\system32\vbscript.dll
2009-06-14 17:10 . 2009-06-14 00:14 9451552 –sha-w- c:\windows\system32\drivers\fidbox.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\valve\steam\steam.exe" [2010-05-07 1238352]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-26 49968]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"PinnacleDriverCheck"="c:\windows\system32\PSDrvCheck.exe" [2004-03-11 406016]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"Ulead AutoDetector v2"="c:\program files\Common Files\Ulead Systems\AutoDetector\monitor.exe" [2004-11-26 90112]
"USBToolTip"="c:\program files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe" [2006-01-23 196608]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-22 14854144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016]
"Turbine Download Manager Tray Icon"="c:\program files\Turbine\Turbine Download Manager\TurbineDownloadManagerIcon.exe" [2010-02-02 472568]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-25 149280]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2010-01-07 158448]

c:\documents and settings\Me\Start Menu\Programs\Startup\
hamachi.lnk - c:\program files\Hamachi\hamachi.exe [2009-1-4 625952]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 22:43 69632 -c–a-w- c:\windows\ALCMTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-09-17 13:55 13574144 —-a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-09-17 13:55 86016 —-a-w- c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2008-09-17 13:55 1657376 —-a-w- c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2005-09-22 17:36 14854144 —-a-w- c:\windows\RTHDCPL.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Steam\\steamapps\\01468\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\RM.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\Studio.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\PMSRegisterFile.exe"=
"c:\\Program Files\\Pinnacle\\Shared Files\\Programs\\MediaManager\\PMSManager.exe"=
"c:\\Program Files\\Pinnacle\\Studio 10\\programs\\umi.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Documents and Settings\\Me\\Desktop\\Xfire\\xfire.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Steam\\steamapps\\01468\\source sdk base\\hl2.exe"=
"c:\\Program Files\\THQ\\Titan Quest Immortal Throne\\Tqit.exe"=
"c:\\Program Files\\THQ\\Titan Quest\\Titan Quest.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\Common Files\\Ulead Systems\\AutoDetector\\Monitor.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\jucheck.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-2.4.0-enUS-downloader.exe"=
"e:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Steam\\steamapps\\01468\\half-life\\hl.exe"=
"e:\\Documents and Settings\\randy marchant\\Desktop\\CrimeCraft\\ClientLauncher.exe"=
"e:\\Documents and Settings\\randy marchant\\Desktop\\CrimeCraft\\Binaries\\CrimeCraft.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Turbine\\Dungeons and Dragons Online - Eberron Unlimited\\TurbineInvoker.exe"=
"c:\\Program Files\\Turbine\\Dungeons and Dragons Online - Eberron Unlimited\\dndclient.exe"=
"c:\\Program Files\\Turbine\\Dungeons and Dragons Online - Eberron Unlimited\\dndlauncher.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Documents and Settings\\Me\\Desktop\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Documents and Settings\\Me\\Desktop\\Phone\\Skype.exe"=
"c:\\Program Files\\Turbine\\Turbine Download Manager\\TurbineMessageService.exe"=
"c:\\Program Files\\Turbine\\Turbine Download Manager\\TurbineNetworkService.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"56888:TCP"= 56888:TCP:Pando Media Booster
"56888:UDP"= 56888:UDP:Pando Media Booster

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [1/10/2010 6:25 PM 207792]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [4/19/2010 12:18 PM 51984]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [4/19/2010 12:18 PM 59664]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [1/10/2010 6:25 PM 233136]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [1/10/2010 6:27 PM 112592]
R2 LiveTurbineMessageService;Turbine Message Service - Live;c:\program files\Turbine\Turbine Download Manager\TurbineMessageService.exe [9/9/2009 7:46 PM 271856]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [10/9/2009 3:34 PM 24652]
S2 abcaccadda;1c1257c6a231bc1264b422d2129a46aa;c:\windows\abcaccadda.exe /s –> c:\windows\abcaccadda.exe [?]
S3 icsak;icsak;c:\windows\system32\drivers\icsak.sys [3/25/2009 1:24 PM 20472]
S3 LiveTurbineNetworkService;Turbine Network Service - Live;c:\program files\Turbine\Turbine Download Manager\TurbineNetworkService.exe [9/9/2009 7:46 PM 218608]
S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [1/10/2010 6:24 PM 70408]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [1/10/2010 6:24 PM 359624]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [4/19/2010 12:18 PM 33552]
S3 ThreatFire;ThreatFire;c:\program files\Spyware Doctor\TFEngine\TFService.exe service –> c:\program files\Spyware Doctor\TFEngine\TFService.exe service [?]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [7/10/2008 8:28 PM 47128]
S4 RsFx0102;RsFx0102 Driver;c:\windows\system32\drivers\RsFx0102.sys [7/10/2008 2:49 AM 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [7/10/2008 8:28 PM 369688]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-USB2Check - c:\windows\system32\PCLECoInst.dll
Notify-dfceadbfedb - c:\windows\system32\dfceadbfedb.dll
Notify-ebfaaeefbd - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-26 16:29
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\windows\system32\b75d9bbc831a627370592771d8e3ff8d.sys 39936 bytes executable

scan completed successfully
hidden files: 1

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\b75d9bbc831a627370592771d8e3ff8d]
"ImagePath"="system32\b75d9bbc831a627370592771d8e3ff8d.sys"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(736)
c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll

- - - - - - - > 'explorer.exe'(3196)
c:\windows\system32\WININET.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\ZuneBusEnum.exe
c:\program files\Zune\ZuneNss.exe
c:\windows\system32\wscntfy.exe
c:\program files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\AIM6\aolsoftware.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
c:\program files\Java\jre6\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2010-05-26 16:41:24 - machine was rebooted
ComboFix-quarantined-files.txt 2010-05-26 20:41
ComboFix2.txt 2009-05-23 02:45
ComboFix3.txt 2009-05-18 15:58
ComboFix4.txt 2009-05-04 18:14
ComboFix5.txt 2010-05-26 20:01

Pre-Run: 10,120,105,984 bytes free
Post-Run: 16,900,108,288 bytes free

- - End Of File - - ECB986DD1914E48002A3123707A117A9


Thanks!
We need some file informantion
  • Make sure to use Internet Explorer for this
  • Please go to: VirusTotal

    [external image: Posted Image]
  • Copy and paste the following file path, one at a time if more than file is listed, into the box next to "Browse" in the middle of the page:

    c:\windows\abcaccadda.exe
    c:\windows\system32\9e15b39b2b92e9224ad80e6357daafe8.exe
    c:\windows\system32\db41be6ef5c3a8885014702b7946246f.exe
    c:\windows\system32\5cd2eec45cf72f7c8530a6ef0e8d3025.exe
    C:\WINDOWS\system32\b75d9bbc831a627370592771d8e3ff8d.sys
  • Then click Send File
  • Please be patient while the file is scanned.
  • Please ensure the scan is complete and the results saved before submitting the next.
  • If a notice appears saying the file has been scanned already, please select Reanalyze now.
  • Once the Scan is completed, Copy and Paste the results of each scan into your next reply.
Hey. I just ran those scans and I'll just make a seperate post for each of the virus scans. For some reason I couldnt get a scan for "c:\windows\abcaccadda.exe". Whenever I tried to run a scan on this file it would bring me to an error page. I tried to browse for this particular file and couldn't find it either. The other scans ran just fine though. Thanks
c:\windows\system32\9e15b39b2b92e9224ad80e6357daafe8.exe

File 9e15b39b2b92e9224ad80e6357daafe8. received on 2010.05.27 20:01:56 (UTC)


Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.05.10 AdWare.Win32.BHO!IK
AhnLab-V3 2010.05.27.00 2010.05.27 Malware/Win32.Trojan Horse
AntiVir 8.2.1.242 2010.05.27 -
Antiy-AVL 2.0.3.7 2010.05.26 -
Authentium 5.2.0.5 2010.05.27 -
Avast 4.8.1351.0 2010.05.27 Win32:Malware-gen
Avast5 5.0.332.0 2010.05.27 Win32:Malware-gen
AVG 9.0.0.787 2010.05.27 SHeur3.ACT
BitDefender 7.2 2010.05.27 Trojan.Generic.3606033
CAT-QuickHeal 10.00 2010.05.27 -
ClamAV 0.96.0.3-git 2010.05.27 -
Comodo 4942 2010.05.25 TrojWare.Win32.Trojan.Agent.Gen
DrWeb 5.0.2.03300 2010.05.27 -
eSafe 7.0.17.0 2010.05.27 Win32.TrojanHorse
eTrust-Vet 35.2.7513 2010.05.27 -
F-Prot 4.6.0.103 2010.05.27 -
F-Secure 9.0.15370.0 2010.05.27 Trojan.Generic.3606033
Fortinet 4.1.133.0 2010.05.26 -
GData 21 2010.05.27 Trojan.Generic.3606033
Ikarus T3.1.1.84.0 2010.05.27 AdWare.Win32.BHO
Jiangmin 13.0.900 2010.05.27 -
Kaspersky 7.0.0.125 2010.05.27 -
McAfee 5.400.0.1158 2010.05.27 -
McAfee-GW-Edition 2010.1 2010.05.27 Heuristic.BehavesLike.Win32.Worm.H
Microsoft 1.5802 2010.05.27 -
NOD32 5151 2010.05.27 a variant of Win32/Agent.REH
Norman 6.04.12 2010.05.27 -
nProtect 2010-05-27.03 2010.05.27 Trojan.Generic.3606033
Panda 10.0.2.7 2010.05.27 Trj/CI.A
PCTools 7.0.3.5 2010.05.27 Trojan.Generic
Prevx 3.0 2010.05.27 Medium Risk Malware
Rising 22.49.03.04 2010.05.27 -
Sophos 4.53.0 2010.05.27 -
Sunbelt 6365 2010.05.27 Trojan.Win32.Generic!BT
Symantec 20101.1.0.89 2010.05.27 Trojan Horse
TheHacker 6.5.2.0.288 2010.05.27 -
TrendMicro 9.120.0.1004 2010.05.27 -
TrendMicro-HouseCall 9.120.0.1004 2010.05.27 -
VBA32 3.12.12.5 2010.05.27 -
ViRobot 2010.5.20.2326 2010.05.27 -
VirusBuster 5.0.27.0 2010.05.27 -

Additional information
File size: 165392 bytes
MD5…: bd72f6e7de0473465144e424d01af7a2
SHA1..: c0d10cdcc88002a3445e559aa8f5d1bf562e0992
SHA256: d9a02e7fb1a4c6ee9667f84e16d42687dea2f7fb3610690dcf3d8b2494c76abd
ssdeep: 3072:tCA4ZNaJ+d57pVKIaqfKaLRKsDwvv6rSEaZXwiqM+Y:7Id57pVKIaQRKJvv
6rSlH

PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0xb688
timedatestamp…..: 0x4b82e1c8 (Mon Feb 22 19:58:00 2010)
machinetype…….: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0xb97e 0xba00 5.98 f37cc3f7af185216830adb23de6935f9
.rdata 0xd000 0x41d4 0x4200 6.79 37e7f94e94c0a1f168f545654d8bf80e
.data 0x12000 0x12948 0x12a00 7.99 9e302302cc78919234df2e952a19fc4a
.rsrc 0x25000 0x5bc0 0x5c00 3.27 7d3c5d62c8aee552daa65585eb8e9299

( 7 imports )
> KERNEL32.dll: Sleep, GetVersionExW, LoadLibraryW, GetProcAddress, GetLastError, FreeLibrary, SetErrorMode, GetStartupInfoA, GetModuleHandleA, lstrlenA, FormatMessageW, LocalAlloc, LocalFree, MoveFileExW, SetFileAttributesW, GetFileSize, CloseHandle, WriteFile, ReadFile, IsDebuggerPresent, ExitProcess, GetSystemInfo, GetTempPathW, MultiByteToWideChar, WideCharToMultiByte, GetWindowsDirectoryW, GetSystemDirectoryW, GetModuleFileNameW, GetLocalTime, CreateFileW, lstrcpyW, GetFileTime, GetVolumeInformationW, GetCurrentDirectoryW, SetCurrentDirectoryW, GetShortPathNameW, WinExec, lstrcmpW, lstrcpynW, lstrlenW
> ADVAPI32.dll: CloseServiceHandle, RegSetValueExW, RegCloseKey, OpenSCManagerW, CreateServiceW, OpenServiceW, DeleteService, StartServiceW, RegCreateKeyExW
> WSOCK32.dll: -, -, -, -, -, -, -
> MSVCP60.dll: __1_Lockit@std@@QAE@XZ, __1_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAE@XZ, _assign@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAEAAV12@ABV12@II@Z, _npos@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@2IB, _append@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAEAAV12@PBDI@Z, _append@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAEAAV12@ID@Z, _assign@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAEAAV12@PBDI@Z, __Tidy@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@AAEX_N@Z, __C@_1___Nullstr@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@CAPBDXZ@4DB, __0_Lockit@std@@QAE@XZ
> MSVCRT.dll: exit, _XcptFilter, _exit, __1type_info@@UAE@XZ, free, _lrotl, _lrotr, __getmainargs, strlen, _CxxThrowException, memcpy, __2@YAPAXI@Z, memset, __CxxFrameHandler, _initterm, __setusermatherr, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, __dllonexit, _onexit, _except_handler3, _controlfp, _acmdln
> USER32.dll: wsprintfA, GetSystemMetrics, IsCharAlphaW, wsprintfW
> SHLWAPI.dll: StrChrW, StrRChrW, StrToIntW

( 0 exports )

RDS…: NSRL Reference Data Set
-
pdfid.: -
trid..: Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
http://info.prevx.com/aboutprogramtext.asp?PX5=A5A1C4B4104DD0FD868902BE8160E2000E7D18C6
sigcheck:
publisher….: Norms Inc.
copyright….: Norms Inc. © 2005-2006
product……:
description..: Norms Verifier
original name: vua.exe
internal name: nvua
file version.: 9, 2, 19, 123
comments…..: vua
signers……: -
signing date.: -
verified…..: Unsigned
c:\windows\system32\db41be6ef5c3a8885014702b7946246f.exe

File db41be6ef5c3a8885014702b7946246f. received on 2010.05.27 20:04:45 (UTC)


Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.05.10 AdWare.Win32.BHO!IK
AhnLab-V3 2010.05.27.00 2010.05.27 Malware/Win32.Trojan Horse
AntiVir 8.2.1.242 2010.05.27 -
Antiy-AVL 2.0.3.7 2010.05.26 -
Authentium 5.2.0.5 2010.05.27 -
Avast 4.8.1351.0 2010.05.27 Win32:Malware-gen
Avast5 5.0.332.0 2010.05.27 Win32:Malware-gen
AVG 9.0.0.787 2010.05.27 SHeur3.ACT
BitDefender 7.2 2010.05.27 Trojan.Generic.3606033
CAT-QuickHeal 10.00 2010.05.27 -
ClamAV 0.96.0.3-git 2010.05.27 -
Comodo 4942 2010.05.25 TrojWare.Win32.Trojan.Agent.Gen
DrWeb 5.0.2.03300 2010.05.27 -
eSafe 7.0.17.0 2010.05.27 Win32.TrojanHorse
eTrust-Vet 35.2.7513 2010.05.27 -
F-Prot 4.6.0.103 2010.05.27 -
F-Secure 9.0.15370.0 2010.05.27 Trojan.Generic.3606033
Fortinet 4.1.133.0 2010.05.26 -
GData 21 2010.05.27 Trojan.Generic.3606033
Ikarus T3.1.1.84.0 2010.05.27 AdWare.Win32.BHO
Jiangmin 13.0.900 2010.05.27 -
Kaspersky 7.0.0.125 2010.05.27 -
McAfee 5.400.0.1158 2010.05.27 -
McAfee-GW-Edition 2010.1 2010.05.27 Heuristic.BehavesLike.Win32.Worm.H
Microsoft 1.5802 2010.05.27 -
NOD32 5151 2010.05.27 a variant of Win32/Agent.REH
Norman 6.04.12 2010.05.27 -
nProtect 2010-05-27.03 2010.05.27 Trojan.Generic.3606033
Panda 10.0.2.7 2010.05.27 Trj/CI.A
PCTools 7.0.3.5 2010.05.27 Trojan.Generic
Prevx 3.0 2010.05.27 Medium Risk Malware
Rising 22.49.03.04 2010.05.27 -
Sophos 4.53.0 2010.05.27 -
Sunbelt 6365 2010.05.27 Trojan.Win32.Generic!BT
Symantec 20101.1.0.89 2010.05.27 Trojan Horse
TheHacker 6.5.2.0.288 2010.05.27 -
TrendMicro 9.120.0.1004 2010.05.27 -
TrendMicro-HouseCall 9.120.0.1004 2010.05.27 -
VBA32 3.12.12.5 2010.05.27 -
ViRobot 2010.5.20.2326 2010.05.27 -
VirusBuster 5.0.27.0 2010.05.27 -

Additional information
File size: 165392 bytes
MD5…: bd72f6e7de0473465144e424d01af7a2
SHA1..: c0d10cdcc88002a3445e559aa8f5d1bf562e0992
SHA256: d9a02e7fb1a4c6ee9667f84e16d42687dea2f7fb3610690dcf3d8b2494c76abd
ssdeep: 3072:tCA4ZNaJ+d57pVKIaqfKaLRKsDwvv6rSEaZXwiqM+Y:7Id57pVKIaQRKJvv
6rSlH

PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0xb688
timedatestamp…..: 0x4b82e1c8 (Mon Feb 22 19:58:00 2010)
machinetype…….: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0xb97e 0xba00 5.98 f37cc3f7af185216830adb23de6935f9
.rdata 0xd000 0x41d4 0x4200 6.79 37e7f94e94c0a1f168f545654d8bf80e
.data 0x12000 0x12948 0x12a00 7.99 9e302302cc78919234df2e952a19fc4a
.rsrc 0x25000 0x5bc0 0x5c00 3.27 7d3c5d62c8aee552daa65585eb8e9299

( 7 imports )
> KERNEL32.dll: Sleep, GetVersionExW, LoadLibraryW, GetProcAddress, GetLastError, FreeLibrary, SetErrorMode, GetStartupInfoA, GetModuleHandleA, lstrlenA, FormatMessageW, LocalAlloc, LocalFree, MoveFileExW, SetFileAttributesW, GetFileSize, CloseHandle, WriteFile, ReadFile, IsDebuggerPresent, ExitProcess, GetSystemInfo, GetTempPathW, MultiByteToWideChar, WideCharToMultiByte, GetWindowsDirectoryW, GetSystemDirectoryW, GetModuleFileNameW, GetLocalTime, CreateFileW, lstrcpyW, GetFileTime, GetVolumeInformationW, GetCurrentDirectoryW, SetCurrentDirectoryW, GetShortPathNameW, WinExec, lstrcmpW, lstrcpynW, lstrlenW
> ADVAPI32.dll: CloseServiceHandle, RegSetValueExW, RegCloseKey, OpenSCManagerW, CreateServiceW, OpenServiceW, DeleteService, StartServiceW, RegCreateKeyExW
> WSOCK32.dll: -, -, -, -, -, -, -
> MSVCP60.dll: __1_Lockit@std@@QAE@XZ, __1_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAE@XZ, _assign@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAEAAV12@ABV12@II@Z, _npos@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@2IB, _append@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAEAAV12@PBDI@Z, _append@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAEAAV12@ID@Z, _assign@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAEAAV12@PBDI@Z, __Tidy@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@AAEX_N@Z, __C@_1___Nullstr@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@CAPBDXZ@4DB, __0_Lockit@std@@QAE@XZ
> MSVCRT.dll: exit, _XcptFilter, _exit, __1type_info@@UAE@XZ, free, _lrotl, _lrotr, __getmainargs, strlen, _CxxThrowException, memcpy, __2@YAPAXI@Z, memset, __CxxFrameHandler, _initterm, __setusermatherr, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, __dllonexit, _onexit, _except_handler3, _controlfp, _acmdln
> USER32.dll: wsprintfA, GetSystemMetrics, IsCharAlphaW, wsprintfW
> SHLWAPI.dll: StrChrW, StrRChrW, StrToIntW

( 0 exports )

RDS…: NSRL Reference Data Set
-
pdfid.: -
trid..: Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
sigcheck:
publisher….: Norms Inc.
copyright….: Norms Inc. © 2005-2006
product……:
description..: Norms Verifier
original name: vua.exe
internal name: nvua
file version.: 9, 2, 19, 123
comments…..: vua
signers……: -
signing date.: -
verified…..: Unsigned

http://info.prevx.com/aboutprogramtext.asp?PX5=A5A1C4B4104DD0FD868902BE8160E2000E7D18C6
c:\windows\system32\5cd2eec45cf72f7c8530a6ef0e8d3025.exe

File 5cd2eec45cf72f7c8530a6ef0e8d3025. received on 2010.05.27 20:07:21 (UTC)


Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.05.10 AdWare.Win32.BHO!IK
AhnLab-V3 2010.05.27.00 2010.05.27 Malware/Win32.Trojan Horse
AntiVir 8.2.1.242 2010.05.27 -
Antiy-AVL 2.0.3.7 2010.05.26 -
Authentium 5.2.0.5 2010.05.27 -
Avast 4.8.1351.0 2010.05.27 Win32:Malware-gen
Avast5 5.0.332.0 2010.05.27 Win32:Malware-gen
AVG 9.0.0.787 2010.05.27 SHeur3.ACT
BitDefender 7.2 2010.05.27 Trojan.Generic.3606033
CAT-QuickHeal 10.00 2010.05.27 -
ClamAV 0.96.0.3-git 2010.05.27 -
Comodo 4942 2010.05.25 TrojWare.Win32.Trojan.Agent.Gen
DrWeb 5.0.2.03300 2010.05.27 -
eSafe 7.0.17.0 2010.05.27 Win32.TrojanHorse
eTrust-Vet 35.2.7513 2010.05.27 -
F-Prot 4.6.0.103 2010.05.27 -
F-Secure 9.0.15370.0 2010.05.27 Trojan.Generic.3606033
Fortinet 4.1.133.0 2010.05.26 -
GData 21 2010.05.27 Trojan.Generic.3606033
Ikarus T3.1.1.84.0 2010.05.27 AdWare.Win32.BHO
Jiangmin 13.0.900 2010.05.27 -
Kaspersky 7.0.0.125 2010.05.27 -
McAfee 5.400.0.1158 2010.05.27 -
McAfee-GW-Edition 2010.1 2010.05.27 Heuristic.BehavesLike.Win32.Worm.H
Microsoft 1.5802 2010.05.27 -
NOD32 5151 2010.05.27 a variant of Win32/Agent.REH
Norman 6.04.12 2010.05.27 -
nProtect 2010-05-27.03 2010.05.27 Trojan.Generic.3606033
Panda 10.0.2.7 2010.05.27 Trj/CI.A
PCTools 7.0.3.5 2010.05.27 Trojan.Generic
Prevx 3.0 2010.05.27 Medium Risk Malware
Rising 22.49.03.04 2010.05.27 -
Sophos 4.53.0 2010.05.27 -
Sunbelt 6365 2010.05.27 Trojan.Win32.Generic!BT
Symantec 20101.1.0.89 2010.05.27 Trojan Horse
TheHacker 6.5.2.0.288 2010.05.27 -
TrendMicro 9.120.0.1004 2010.05.27 -
TrendMicro-HouseCall 9.120.0.1004 2010.05.27 -
VBA32 3.12.12.5 2010.05.27 -
ViRobot 2010.5.20.2326 2010.05.27 -
VirusBuster 5.0.27.0 2010.05.27 -

Additional information
File size: 165392 bytes
MD5…: bd72f6e7de0473465144e424d01af7a2
SHA1..: c0d10cdcc88002a3445e559aa8f5d1bf562e0992
SHA256: d9a02e7fb1a4c6ee9667f84e16d42687dea2f7fb3610690dcf3d8b2494c76abd
ssdeep: 3072:tCA4ZNaJ+d57pVKIaqfKaLRKsDwvv6rSEaZXwiqM+Y:7Id57pVKIaQRKJvv
6rSlH

PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0xb688
timedatestamp…..: 0x4b82e1c8 (Mon Feb 22 19:58:00 2010)
machinetype…….: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0xb97e 0xba00 5.98 f37cc3f7af185216830adb23de6935f9
.rdata 0xd000 0x41d4 0x4200 6.79 37e7f94e94c0a1f168f545654d8bf80e
.data 0x12000 0x12948 0x12a00 7.99 9e302302cc78919234df2e952a19fc4a
.rsrc 0x25000 0x5bc0 0x5c00 3.27 7d3c5d62c8aee552daa65585eb8e9299

( 7 imports )
> KERNEL32.dll: Sleep, GetVersionExW, LoadLibraryW, GetProcAddress, GetLastError, FreeLibrary, SetErrorMode, GetStartupInfoA, GetModuleHandleA, lstrlenA, FormatMessageW, LocalAlloc, LocalFree, MoveFileExW, SetFileAttributesW, GetFileSize, CloseHandle, WriteFile, ReadFile, IsDebuggerPresent, ExitProcess, GetSystemInfo, GetTempPathW, MultiByteToWideChar, WideCharToMultiByte, GetWindowsDirectoryW, GetSystemDirectoryW, GetModuleFileNameW, GetLocalTime, CreateFileW, lstrcpyW, GetFileTime, GetVolumeInformationW, GetCurrentDirectoryW, SetCurrentDirectoryW, GetShortPathNameW, WinExec, lstrcmpW, lstrcpynW, lstrlenW
> ADVAPI32.dll: CloseServiceHandle, RegSetValueExW, RegCloseKey, OpenSCManagerW, CreateServiceW, OpenServiceW, DeleteService, StartServiceW, RegCreateKeyExW
> WSOCK32.dll: -, -, -, -, -, -, -
> MSVCP60.dll: __1_Lockit@std@@QAE@XZ, __1_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAE@XZ, _assign@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAEAAV12@ABV12@II@Z, _npos@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@2IB, _append@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAEAAV12@PBDI@Z, _append@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAEAAV12@ID@Z, _assign@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAEAAV12@PBDI@Z, __Tidy@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@AAEX_N@Z, __C@_1___Nullstr@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@CAPBDXZ@4DB, __0_Lockit@std@@QAE@XZ
> MSVCRT.dll: exit, _XcptFilter, _exit, __1type_info@@UAE@XZ, free, _lrotl, _lrotr, __getmainargs, strlen, _CxxThrowException, memcpy, __2@YAPAXI@Z, memset, __CxxFrameHandler, _initterm, __setusermatherr, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, __dllonexit, _onexit, _except_handler3, _controlfp, _acmdln
> USER32.dll: wsprintfA, GetSystemMetrics, IsCharAlphaW, wsprintfW
> SHLWAPI.dll: StrChrW, StrRChrW, StrToIntW

( 0 exports )

RDS…: NSRL Reference Data Set
-
pdfid.: -
trid..: Win32 Executable Generic (42.3%)
Win32 Dynamic Link Library (generic) (37.6%)
Generic Win/DOS Executable (9.9%)
DOS Executable Generic (9.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
http://info.prevx.com/aboutprogramtext.asp?PX5=A5A1C4B4104DD0FD868902BE8160E2000E7D18C6
sigcheck:
publisher….: Norms Inc.
copyright….: Norms Inc. © 2005-2006
product……:
description..: Norms Verifier
original name: vua.exe
internal name: nvua
file version.: 9, 2, 19, 123
comments…..: vua
signers……: -
signing date.: -
verified…..: Unsigned
C:\WINDOWS\system32\b75d9bbc831a627370592771d8e3ff8d.sys

File b75d9bbc831a627370592771d8e3ff8d. received on 2010.05.27 20:11:55 (UTC)


Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.05.10 Virus.Win32.Trojan!IK
AhnLab-V3 2010.05.27.00 2010.05.27 Win-Trojan/Rootkit.39936.C
AntiVir 8.2.1.242 2010.05.27 Rkit/Agent.39936
Antiy-AVL 2.0.3.7 2010.05.26 -
Authentium 5.2.0.5 2010.05.27 W32/Adware.AESR
Avast 4.8.1351.0 2010.05.27 Win32:Trojan-gen
Avast5 5.0.332.0 2010.05.27 Win32:Trojan-gen
AVG 9.0.0.787 2010.05.27 Generic12.BBZA
BitDefender 7.2 2010.05.27 Trojan.Downloader.Tdidrv.A
CAT-QuickHeal 10.00 2010.05.27 Trojan.Agent.WD
ClamAV 0.96.0.3-git 2010.05.27 -
Comodo 4942 2010.05.25 Win32.Rootkit.Small.~A
DrWeb 5.0.2.03300 2010.05.27 Trojan.NtRootKit.2686
eSafe 7.0.17.0 2010.05.27 Win32.MaliciousSoftw
eTrust-Vet 35.2.7513 2010.05.27 Win32/SillyDl.GQA
F-Prot 4.6.0.103 2010.05.27 W32/Adware.AESR
F-Secure 9.0.15370.0 2010.05.27 Rootkit:W32/Nockmd.A
Fortinet 4.1.133.0 2010.05.26 W32/Nockmd.A!tr.rkit
GData 21 2010.05.27 Trojan.Downloader.Tdidrv.A
Ikarus T3.1.1.84.0 2010.05.27 Virus.Win32.Trojan
Jiangmin 13.0.900 2010.05.27 -
Kaspersky 7.0.0.125 2010.05.27 -
McAfee 5.400.0.1158 2010.05.27 Generic Rootkit.d
McAfee-GW-Edition 2010.1 2010.05.27 Generic Rootkit.d
Microsoft 1.5802 2010.05.27 Adware:Win32/BHO.B
NOD32 5151 2010.05.27 Win32/Rootkit.Agent.NJF
Norman 6.04.12 2010.05.27 W32/Suspicious_Gen2.GXIZ
nProtect 2010-05-27.03 2010.05.27 Trojan/W32.Rootkit.39936.D
Panda 10.0.2.7 2010.05.27 Rootkit/Agent.LKN
PCTools 7.0.3.5 2010.05.27 Hacktool.Rootkit!sd6
Prevx 3.0 2010.05.27 High Risk Rootkit
Rising 22.49.03.04 2010.05.27 -
Sophos 4.53.0 2010.05.27 Troj/Rootkit-ES
Sunbelt 6365 2010.05.27 Trojan.Rootkit.GEN
Symantec 20101.1.0.89 2010.05.27 Hacktool.Rootkit
TheHacker 6.5.2.0.288 2010.05.27 -
TrendMicro 9.120.0.1004 2010.05.27 HKTL_BBZA
TrendMicro-HouseCall 9.120.0.1004 2010.05.27 HKTL_BBZA
VBA32 3.12.12.5 2010.05.27 Win32.Rootkit.Agent.NJF
ViRobot 2010.5.20.2326 2010.05.27 Trojan.Win32.RT-Agent.39936.D
VirusBuster 5.0.27.0 2010.05.27 Adware.BHO.STV

Additional information
File size: 39936 bytes
MD5…: 6c7234ec1cc778d45ffb265d026934a7
SHA1..: 850bb80105a1e96522af94ada769baa1fb502eed
SHA256: 67416fa252505ef418018db933e0a3e27b333055cf2711b4fab0ce2eff7907a4
ssdeep: 768:o2ZMWzKDw4nXOlf8WC52V4pCmJ3WVCEOMGcKCwgvALHeAYqHZJ8GO1Ja:lMW
mDMlfzCINoCOMGAM3Y6ZeGO14

PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x90d2
timedatestamp…..: 0x49496bef (Wed Dec 17 21:15:27 2008)
machinetype…….: 0x14c (I386)

( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x820e 0x8400 5.99 67d262ae775b005dde3a0732400f613c
.rdata 0xa000 0x794 0x800 5.06 7ef062e339f8e91b10903f8362de3944
.data 0xb000 0x254 0x200 3.82 98d31f417f4d5cb7878d147140cff210
.rsrc 0xc000 0x388 0x400 2.92 6dc20c7087d0a1afcca69a4c278d2f81
.reloc 0xd000 0x4ae 0x600 4.87 d1bae48ba3da4d38e1725518114336aa

( 1 imports )
> ntoskrnl.exe: KeInitializeTimerEx, PsCreateSystemThread, KeSetTimerEx, _allmul, ExFreePool, KeCancelTimer, memset, ExAllocatePoolWithTag, KeWaitForSingleObject, IoCreateFile, ZwClose, ZwDuplicateObject, MmIsAddressValid, ObOpenObjectByPointer, ZwQuerySystemInformation, ObReferenceObjectByHandle, ZwOpenThread, ObfReferenceObject, PsLookupProcessByProcessId, ObfDereferenceObject, wcscmp, KeInsertQueueApc, KeInitializeApc, KeUnstackDetachProcess, MmMapLockedPagesSpecifyCache, KeStackAttachProcess, IoFreeMdl, MmProbeAndLockPages, IoAllocateMdl, IoGetCurrentProcess, ZwCreateEvent, strncpy, memcpy, _except_handler3, ZwCreateFile, ZwWriteFile, ZwDeleteFile, KeServiceDescriptorTable, NtQueryDirectoryFile, memmove, wcslen, wcschr, RtlTimeToTimeFields, RtlTimeFieldsToTime, ExSystemTimeToLocalTime, KeQuerySystemTime, ZwQueryObject, ZwCreateKey, ZwSetValueKey, ZwQueryValueKey, KeSetEvent, RtlInitUnicodeString, KeInitializeEvent, RtlFreeUnicodeString, RtlCompareUnicodeString, RtlAnsiStringToUnicodeString, RtlUnicodeStringToAnsiString, RtlIntegerToUnicodeString, RtlUnicodeStringToInteger, RtlFreeAnsiString, IofCallDriver, IoBuildDeviceIoControlRequest, IoGetRelatedDeviceObject

( 0 exports )

RDS…: NSRL Reference Data Set
-
pdfid.: -
trid..: Generic Win/DOS Executable (49.9%)
DOS Executable Generic (49.8%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
sigcheck:
publisher….: Noves Inc
copyright….: Noves Inc © 2007
product……: Noves ckmd
description..: ckmd
original name: ckmd
internal name: lasd
file version.: 3, 35, 52, 123
comments…..:
signers……: -
signing date.: -
verified…..: Unsigned

ThreatExpert info: http://www.threatexpert.com/report.aspx?md5=6c7234ec1cc778d45ffb265d026934a7
http://info.prevx.com/aboutprogramtext.asp?PX5=E8C2E7CE00BB879A9C2B00D785FA2600772CBB09
We will be using Combofix again but will run it differently.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the all of the text in the code box below into the Notepad, (including the URL). Do Not copy the word CODE

http://forums.whatthetech.com/Infected_PC_slow_running_redirected_web_pages_etc_t112219.html

KillAll::

Collect::
c:\windows\abcaccadda.exe 
c:\windows\system32\9e15b39b2b92e9224ad80e6357daafe8.exe
c:\windows\system32\db41be6ef5c3a8885014702b7946246f.exe
c:\windows\system32\5cd2eec45cf72f7c8530a6ef0e8d3025.exe
C:\windows\system32\drivers\svchost.exe

Registry::
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\b75d9bbc831a627370592771d8e3ff8d]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\drivers\\svchost.exe"=-

Driver::
b75d9bbc831a627370592771d8e3ff8d
abcaccadda

Rootkit::
C:\WINDOWS\system32\b75d9bbc831a627370592771d8e3ff8d.sys

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save

Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.


Please post the Combofix log in your next reply and let me know how your machine is running now.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI