This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

AntiMalware Doctor ---> Ruining my pc

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there, one day i was searching the web and all of the sudden my pc froze for like 2 minutes, after that it responded again and some new pop ups started emerging. My antivirus avast warned me that some trojan got in my pc, i clicked on delete but it seem it didnt do much cz now i have installed a program named antimalware doctor that every 2 minutes warns me that my pc its at risk and that some one is attacking my pc, plus it minimizes all my windows and freezes my pc for 15 seconds then it respondes again and tell me that i have to register to the program. Please Help its very annoying and it ruining my pc, crashes every while…


Here its my HTJ post:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:42:38 PM, on 7/14/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Athan\Athan.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\ZSSnp211.exe
C:\WINDOWS\Domino.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Paltalk Messenger\paltalk.exe
C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_wp.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\cmd.exe
C:\Documents and Settings\User\Application Data\BD330B408BD2353F1E08DE01BC703164\setup715newver0015.exe
C:\Documents and Settings\User\My Documents\HiJackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com.ve/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Athan] C:\Program Files\Athan\Athan.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe
O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
O4 - HKCU\..\Run: [setup715newver0015.exe] C:\Documents and Settings\User\Application Data\BD330B408BD2353F1E08DE01BC703164\setup715newver0015.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-1060284298-1715567821-1801674531-1008\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'ASPNET')
O4 - HKUS\S-1-5-18\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O4 - Startup: Antimalware Doctor.lnk = C:\Documents and Settings\User\Application Data\BD330B408BD2353F1E08DE01BC703164\setup715newver0015.exe
O4 - Startup: monipu32.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: PalTalk.lnk = C:\Program Files\Paltalk Messenger\paltalk.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} (PCMaticVer Class) - http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Microsoft ASPI Manager (aspimgr) - Unknown owner - C:\WINDOWS\system32\aspimgr.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Update Service (gupdate1ca630e917026fe) (gupdate1ca630e917026fe) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: WUSB54GCSVC - GEMTEKS - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 11447 bytes


Any help will be much appreciated….

Thanks a lot….
Hello Moe_J_AK and :welcome:

My name is JonTom.

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.


  • Please perform the following scan


    • Please download DDS from here and save it to your desktop.
    • Disable any script blocking protection (How to Disable your Security Programs)
    • Double click on the DDS icon to run the tool (may take up to 3 minutes to run).
    • When done, DDS.txt will open.
    • After a few moments, attach.txt will open in a second window.
    • Save both reports to your desktop.
    • Please post the contents of the DDS.txt and Attach.txt logs in your next reply.

  • DeFogger


    • Please download DeFogger to your desktop.
    • Click on DeFogger to run the tool.
    • The application window will appear.
    • Click the Disable button to disable your CD Emulation drivers.
    • Click Yes to continue.
    • A 'Finished!' message will appear.
    • Click OK.
    • DeFogger will now ask to reboot the machine - click OK.
      IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.
      Do not re-enable these drivers until otherwise instructed.

  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent.
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

      [external image: Posted Image]
      Click the image to enlarge it
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Please post the DDS logs and the GMER log in your next reply.

If you encounter any problems come back and let me know.
Hi there JonTon, first of all thanks a lot for helping me out…


1a)DDS log (DDS.txt):



DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 18:19:43.26 on Thu 07/15/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1407.908 [GMT -4.5:30]

AV: avast! antivirus 4.8.1351 [VPS 091124-0] *On-access scanning disabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Athan\Athan.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\ZSSnp211.exe
C:\WINDOWS\Domino.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\User\Application Data\BD330B408BD2353F1E08DE01BC703164\setup715newver0015.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Paltalk Messenger\paltalk.exe
C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe
svchost
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Documents and Settings\User\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://google.com.ve/
mWinlogon: SfcDisable=-99 (0xffffff9d)
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
EB: Groove Folder Synchronization: {2a541ae1-5bf6-4665-a8a3-cfa9672e4291} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
uRun: [AdobeUpdater] "c:\program files\common files\adobe\updater5\AdobeUpdater.exe"
uRun: [setup715newver0015.exe] c:\documents and settings\user\application data\bd330b408bd2353f1e08de01bc703164\setup715newver0015.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [Athan] c:\program files\athan\Athan.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [ZSSnp211] c:\windows\ZSSnp211.exe
mRun: [Domino] c:\windows\Domino.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [YSearchProtection] "c:\program files\yahoo!\search protection\SearchProtection.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
dRunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32
StartupFolder: c:\documents and settings\user\start menu\programs\startup\monipu32.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\paltalk.lnk - c:\program files\paltalk messenger\paltalk.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - c:\program files\paltalk messenger\Paltalk.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~1\office12\REFIEBAR.DLL
DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
LSA: Authentication Packages = msv1_0 nwprovau

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-8-2 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-8-2 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-8-2 138680]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-8-8 54752]
R3 S3GIGP;S3GIGP;c:\windows\system32\drivers\S3gIGPm.sys [2009-8-2 634880]
S2 aspimgr;Microsoft ASPI Manager;c:\windows\system32\aspimgr.exe –> c:\windows\system32\aspimgr.exe [?]
S2 gupdate1ca630e917026fe;Google Update Service (gupdate1ca630e917026fe);c:\program files\google\update\GoogleUpdate.exe [2009-11-11 133104]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-8-2 254040]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-8-2 352920]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 vvftav211;vvftav211;c:\windows\system32\drivers\vvftav211.sys [2009-8-12 480128]
S3 ZSMC30x;USB PC Camera Service ZSMC30x;c:\windows\system32\drivers\ZS211.sys [2009-8-12 1537024]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\pcpitstop\PCPitstopScheduleService.exe [2010-6-30 90296]

=============== Created Last 30 ================

2010-07-15 02:19:56 116 —-a-w- c:\windows\system32\fjhdyfhsn.bat
2010-07-15 02:19:54 0 d—–w- c:\docume~1\user\applic~1\BD330B408BD2353F1E08DE01BC703164
2010-07-15 02:19:23 4 —-a-w- c:\docume~1\user\applic~1\avdrn.dat
2010-07-14 00:44:08 744448 ——w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-11 03:27:34 3246 —-a-w- c:\windows\system32\wbem\Outlook_01cb20a900be367e.mof
2010-07-10 23:18:08 0 d–h–w- c:\windows\msdownld.tmp
2010-07-10 23:08:46 0 d—–w- c:\program files\directx
2010-07-10 23:08:46 0 —-a-w- c:\windows\DXT206.tmp
2010-07-10 23:08:46 0 —-a-w- c:\windows\DXT205.tmp
2010-07-10 23:08:46 0 —-a-w- c:\windows\DXT204.tmp
2010-07-10 23:08:46 0 —-a-w- c:\windows\DXT203.tmp
2010-07-10 23:05:06 0 d—–w- c:\program files\EACOM
2010-07-10 23:03:09 0 d—–w- c:\program files\EA SPORTS
2010-07-04 21:54:54 0 d—–w- C:\Games
2010-06-30 13:03:25 0 d—–w- c:\docume~1\alluse~1\applic~1\PCPitstop
2010-06-30 13:03:20 0 d—–w- c:\program files\PCPitstop
2010-06-28 18:46:14 285696 ——w- c:\windows\system32\dllcache\atmfd.dll
2010-06-28 18:46:05 226880 ——w- c:\windows\system32\dllcache\tcpip6.sys
2010-06-28 18:46:05 100864 ——w- c:\windows\system32\dllcache\6to4svc.dll
2010-06-28 18:45:22 691712 ——w- c:\windows\system32\dllcache\inetcomm.dll
2010-06-28 18:45:03 65536 ——w- c:\windows\system32\dllcache\asycfilt.dll
2010-06-28 18:39:35 456704 ——w- c:\windows\system32\dllcache\smtpsvc.dll
2010-06-28 18:23:50 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-28 18:09:02 178176 ——w- c:\windows\system32\dllcache\wintrust.dll
2010-06-28 18:08:34 86016 ——w- c:\windows\system32\dllcache\cabview.dll

==================== Find3M ====================

2010-06-02 09:25:30 74072 —-a-w- c:\windows\system32\XAPOFX1_5.dll
2010-06-02 09:25:30 527192 —-a-w- c:\windows\system32\XAudio2_7.dll
2010-06-02 09:25:30 239960 —-a-w- c:\windows\system32\xactengine3_7.dll
2010-05-26 16:11:02 470880 —-a-w- c:\windows\system32\d3dx10_43.dll
2010-05-26 16:11:02 248672 —-a-w- c:\windows\system32\d3dx11_43.dll
2010-05-26 16:11:02 2106216 —-a-w- c:\windows\system32\D3DCompiler_43.dll
2010-05-26 16:11:02 1998168 —-a-w- c:\windows\system32\D3DX9_43.dll
2010-05-26 16:11:02 1868128 —-a-w- c:\windows\system32\d3dcsx_43.dll
2010-05-05 13:30:57 173056 —-a-w- c:\windows\system32\dllcache\ie4uinit.exe
2010-05-02 16:34:16 1860352 —-a-w- c:\windows\system32\win32k.sys
2010-05-02 16:34:16 1860352 ——w- c:\windows\system32\dllcache\win32k.sys
2010-04-20 05:30:08 285696 —-a-w- c:\windows\system32\atmfd.dll
2009-08-03 00:09:51 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009080220090803\index.dat

============= FINISH: 18:19:53.56 ===============


1b) DDS Log (Attach.txt):



UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-03-17.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 8/2/2009 7:36:09 PM
System Uptime: 7/15/2010 6:05:17 PM (0 hours ago)

Motherboard: | | 4CoreDX90-VSTA
Processor: Genuine Intel® CPU 2160 @ 1.80GHz | CPUSocket | 1800/200mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 75 GiB total, 60.209 GiB free.
D: is CDROM ()
E: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: System Interrupt Controller
Device ID: PCI\VEN_1106&DEV_5364&SUBSYS_53641849&REV_00\3&267A616A&0&05
Manufacturer:
Name: System Interrupt Controller
PNP Device ID: PCI\VEN_1106&DEV_5364&SUBSYS_53641849&REV_00\3&267A616A&0&05
Service:

==== System Restore Points ===================

RP200: 4/17/2010 7:33:57 PM - System Checkpoint
RP201: 4/18/2010 8:05:18 PM - System Checkpoint
RP202: 4/19/2010 8:16:58 PM - System Checkpoint
RP203: 4/21/2010 9:45:22 PM - System Checkpoint
RP204: 4/24/2010 12:09:19 PM - System Checkpoint
RP205: 4/25/2010 12:09:43 PM - System Checkpoint
RP206: 4/26/2010 12:45:32 PM - System Checkpoint
RP207: 5/11/2010 10:35:55 AM - System Checkpoint
RP208: 5/12/2010 7:54:29 PM - System Checkpoint
RP209: 5/14/2010 12:11:52 PM - System Checkpoint
RP210: 5/15/2010 12:43:50 PM - System Checkpoint
RP211: 5/17/2010 8:36:39 AM - System Checkpoint
RP212: 5/18/2010 8:59:36 AM - System Checkpoint
RP213: 5/21/2010 9:52:28 PM - System Checkpoint
RP214: 5/24/2010 7:32:44 PM - System Checkpoint
RP215: 5/25/2010 7:40:18 PM - System Checkpoint
RP216: 5/26/2010 8:47:05 PM - System Checkpoint
RP217: 6/28/2010 2:07:39 PM - System Checkpoint
RP218: 6/29/2010 8:12:38 PM - Software Distribution Service 3.0
RP219: 6/30/2010 8:33:36 AM - Installed Microsoft Visual C++ 2005 Redistributable
RP220: 7/1/2010 10:09:29 PM - System Checkpoint
RP221: 7/3/2010 8:57:37 AM - System Checkpoint
RP222: 7/4/2010 11:14:51 AM - System Checkpoint
RP223: 7/5/2010 3:48:43 PM - System Checkpoint
RP224: 7/6/2010 7:15:54 PM - System Checkpoint
RP225: 7/7/2010 9:04:52 PM - System Checkpoint
RP226: 7/10/2010 9:05:44 AM - System Checkpoint
RP227: 7/10/2010 6:52:36 PM - Installed DirectX
RP228: 7/11/2010 7:51:38 PM - System Checkpoint
RP229: 7/12/2010 9:58:32 PM - System Checkpoint
RP230: 7/13/2010 7:55:51 PM - Software Distribution Service 3.0
RP231: 7/14/2010 8:31:16 PM - Software Distribution Service 3.0

==== Installed Programs ======================

Adobe Flash Player 10 ActiveX
Adobe Reader 8.1.0
AiO_Scan_CDA
AiOSoftwareNPI
Antimalware Doctor
Ask Toolbar
Athan Basic 3.7
avast! Antivirus
BufferChm
C3100
c3100_Help
Compact Wireless-G USB Adapter
Critical Update for Windows Media Player 11 (KB959772)
CustomerResearchQFolder
Destinations
DeviceManagementQFolder
DocProc
DocProcQFolder
EA.com Update
eSupportQFolder
Fax_CDA
Google Chrome
Google Earth
Google Toolbar for Internet Explorer
Google Update Helper
Half-Life
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
HP Customer Participation Program 7.0
HP Imaging Device Functions 7.0
HP Photosmart Essential
HP Photosmart, Officejet and Deskjet 7.0.A
HP Software Update
HP Solution Center 7.0
HPPhotoSmartExpress
HPProductAssistant
IIS 6.0 Resource Kit Tools
IIS6 Manager
InstantShareDevicesMFC
Junk Mail filter update
MarketResearch
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Live Add-in 1.3
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook Connector
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2005 Redistributable
MSVCRT
MSXML 4.0 SP2 (KB973688)
NewCopy_CDA
OCR Software by I.R.I.S 7.0
PaltalkScene
PanoStandAlone
PC Matic 1.0.0.16
ProductContextNPI
Protección de Yahoo! Búsquedas
Readme
RealPlayer
Realtek High Definition Audio Driver
RealUpgrade 1.0
Scan
ScannerCopy
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for 2007 Microsoft Office System (KB982312)
Security Update for 2007 Microsoft Office System (KB982331)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Excel 2007 (KB982308)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office Outlook 2007 (KB980376)
Security Update for Microsoft Office PowerPoint 2007 (KB982158)
Security Update for Microsoft Office Publisher 2007 (KB982124)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB982135)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB970483)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB976323)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Segoe UI
Sierra Utilities
SolutionCenter
Status
Toolbox
TrayApp
Unload
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Outlook 2007 Junk Email Filter (kb2202131)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows XP (KB955759)
Update for Windows XP (KB961503)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VIA/S3G Display Driver 6.14.10.0078
VideoLAN VLC media player 0.8.6d
WebFldrs XP
WebReg
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live Mail
Windows Live Messenger
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Toolbar
Windows Live Upload Tool
Windows Live Writer
WinRAR archiver
Yahoo! BrowserPlus
Yahoo! Messenger
Yahoo! Software Update
Yahoo! Toolbar
ZSMC USB PC Camera (ZS0211)

==== End Of File ===========================


2)The Defogger didnt ask me to restart the machine…

defogger_disable by jpshortstuff (23.02.10.1)
Log created at 18:21 on 15/07/2010 (User)

Checking for autostart values…
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers…


-=E.O.F=-


3) Gmer Log:


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-15 19:33:42
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\User\LOCALS~1\Temp\pwtdqpob.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB828E6B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xB828EA52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB828E14C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xB828E64E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB828E76E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB828E72E]

—- Kernel code sections - GMER 1.0.15 —-

.text ntoskrnl.exe!ZwYieldExecution + 17A 804E49D4 4 Bytes JMP D747B828

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\Explorer.EXE[3412] ntdll.dll!NtQueryDirectoryFile + 6 7C90D774 4 Bytes [90, 61, 08, 02] {NOP ; POPA ; OR [EDX], AL}
? C:\WINDOWS\system32\svchost.exe[3436] image checksum mismatch; time/date stamp mismatch;
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 15, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 15, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 15, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EB1A
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 15, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 15, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 15, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EB8B
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 15, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90ECB9
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 15, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 15, 00]
.text C:\Program Files\Google\Chrome\Application\chrome.exe[3908] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

—- EOF - GMER 1.0.15 —-


Once again thanks a lot….
Hello Moe_J_AK

Thank you for the logs.

Please do the following:


  • Download Combofix and RE-NAME it BEFORE saving


  • Download Combofix from either of the links below. You must rename it to moejak.exe before saving it.
  • Save it to your desktop. Change the "save as file type" to "all files".
  • Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop.


  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


Link 1
Link 2



  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.


  • NOTE: If ComboFix asks to install the Recovery Console, please ALLOW it to do so.


  • Double click on the renamed ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.
Hi JonTom,

here its the log you asked for:


ComboFix 10-07-15.05 - User 07/17/2010 1:37.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1407.833 [GMT -4.5:30]
Running from: c:\documents and settings\[removed]\Desktop\moejak.exe
AV: avast! antivirus 4.8.1351 [VPS 091124-0] *On-access scanning disabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\User\Application Data\avdrn.dat
c:\documents and settings\User\Application Data\BD330B408BD2353F1E08DE01BC703164
c:\documents and settings\User\Application Data\BD330B408BD2353F1E08DE01BC703164\enemies-names.txt
c:\documents and settings\User\Application Data\BD330B408BD2353F1E08DE01BC703164\local.ini
c:\documents and settings\User\Application Data\BD330B408BD2353F1E08DE01BC703164\lsrslt.ini
c:\documents and settings\User\Application Data\BD330B408BD2353F1E08DE01BC703164\setup715newver0015.exe
c:\documents and settings\User\Start Menu\Programs\Startup\monipu32.exe
c:\windows\system32\Cache
c:\windows\system32\fjhdyfhsn.bat
c:\windows\ws386.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_ASPIMGR
——-\Service_aspimgr


((((((((((((((((((((((((( Files Created from 2010-06-17 to 2010-07-17 )))))))))))))))))))))))))))))))
.

2010-07-17 06:12 . 2010-07-17 06:12 ——– d—–w- c:\windows\system32\xircom
2010-07-17 06:12 . 2010-07-17 06:12 ——– d—–w- c:\windows\system32\wbem\snmp
2010-07-17 06:12 . 2010-07-17 06:12 ——– d—–w- c:\program files\microsoft frontpage
2010-07-14 00:44 . 2010-06-14 14:31 744448 ——w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-10 23:08 . 2010-07-10 23:08 ——– d—–w- c:\program files\directx
2010-07-10 23:05 . 2010-07-10 23:05 ——– d—–w- c:\program files\EACOM
2010-07-10 23:03 . 2010-07-10 23:03 ——– d—–w- c:\program files\EA SPORTS
2010-07-07 02:05 . 2010-07-07 02:05 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2010-07-04 21:54 . 2010-07-04 23:07 ——– d—–w- C:\Games
2010-06-30 13:03 . 2010-06-30 13:04 ——– d—–w- c:\documents and settings\All Users\Application Data\PCPitstop
2010-06-30 13:03 . 2010-06-30 13:03 ——– d—–w- c:\program files\PCPitstop
2010-06-28 18:46 . 2010-04-20 05:30 285696 ——w- c:\windows\system32\dllcache\atmfd.dll
2010-06-28 18:46 . 2010-02-12 04:27 100864 ——w- c:\windows\system32\dllcache\6to4svc.dll
2010-06-28 18:46 . 2010-02-11 11:36 226880 ——w- c:\windows\system32\dllcache\tcpip6.sys
2010-06-28 18:45 . 2010-01-29 14:53 691712 ——w- c:\windows\system32\dllcache\inetcomm.dll
2010-06-28 18:45 . 2010-03-05 14:37 65536 ——w- c:\windows\system32\dllcache\asycfilt.dll
2010-06-28 18:39 . 2010-03-05 18:45 456704 ——w- c:\windows\system32\dllcache\smtpsvc.dll
2010-06-28 18:23 . 2010-05-06 10:41 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-28 18:09 . 2009-12-24 06:42 178176 ——w- c:\windows\system32\dllcache\wintrust.dll
2010-06-28 18:08 . 2010-01-13 14:01 86016 ——w- c:\windows\system32\dllcache\cabview.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-15 22:37 . 2010-07-15 22:37 16 —-a-w- c:\windows\system32\config\systemprofile\Application Data\hvyacl.dat
2010-07-15 01:04 . 2009-08-03 00:53 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-07-15 00:57 . 2009-08-09 03:23 ——– d—–w- c:\program files\Microsoft Silverlight
2010-07-10 23:08 . 2010-07-10 23:08 0 —-a-w- c:\windows\DXT206.tmp
2010-07-10 23:08 . 2010-07-10 23:08 0 —-a-w- c:\windows\DXT205.tmp
2010-07-10 23:08 . 2010-07-10 23:08 0 —-a-w- c:\windows\DXT204.tmp
2010-07-10 23:08 . 2010-07-10 23:08 0 —-a-w- c:\windows\DXT203.tmp
2010-07-10 23:05 . 2009-08-03 00:43 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-06-14 14:31 . 2009-08-03 00:02 744448 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-02 09:25 . 2010-07-10 23:22 74072 —-a-w- c:\windows\system32\XAPOFX1_5.dll
2010-06-02 09:25 . 2010-07-10 23:22 527192 —-a-w- c:\windows\system32\XAudio2_7.dll
2010-06-02 09:25 . 2010-07-10 23:22 239960 —-a-w- c:\windows\system32\xactengine3_7.dll
2010-05-26 16:11 . 2010-07-10 23:22 2106216 —-a-w- c:\windows\system32\D3DCompiler_43.dll
2010-05-26 16:11 . 2010-07-10 23:22 470880 —-a-w- c:\windows\system32\d3dx10_43.dll
2010-05-26 16:11 . 2010-07-10 23:22 248672 —-a-w- c:\windows\system32\d3dx11_43.dll
2010-05-26 16:11 . 2010-07-10 23:22 1868128 —-a-w- c:\windows\system32\d3dcsx_43.dll
2010-05-26 16:11 . 2010-07-10 23:22 1998168 —-a-w- c:\windows\system32\D3DX9_43.dll
2010-05-06 10:41 . 2008-10-16 19:38 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-02 16:34 . 2009-01-08 19:14 1860352 —-a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30 . 2008-04-14 04:39 285696 —-a-w- c:\windows\system32\atmfd.dll
.

——- Sigcheck ——-

[-] 2009-01-08 . 5AE1C2695F6523AD98B948F2887D8C5E . 361600 . . [5.1.2600.5649] . . c:\windows\system32\drivers\tcpip.sys

[-] 2009-01-08 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2009-01-02 18:06 365960 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-01-02 365960]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-01-02 365960]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-14 39408]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2009-11-10 5244216]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2009-08-10 2356088]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Athan"="c:\program files\Athan\Athan.exe" [2009-07-29 1114112]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"ZSSnp211"="c:\windows\ZSSnp211.exe" [2007-04-06 57344]
"Domino"="c:\windows\Domino.exe" [2006-08-18 49152]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-13 202256]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_2"="shell32" [X]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
PalTalk.lnk - c:\program files\Paltalk Messenger\paltalk.exe [2010-3-22 11554304]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-05-11 10:06 40048 —-a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-04 01:43 69632 —-a-r- c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 16:14 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-07-26 21:14 3883856 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2006-10-31 02:49 16269312 —-a-r- c:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\S3Trayp]
2006-10-10 12:14 176128 —-a-r- c:\windows\system32\S3Trayp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
2006-05-17 01:04 2879488 —-a-r- c:\windows\SkyTel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
2006-09-21 23:36 53248 —-a-r- c:\windows\system32\VTTimer.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"c:\\SIERRA\\Half-Life\\hl.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [8/2/2009 8:32 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8/2/2009 8:32 PM 20560]
S2 gupdate1ca630e917026fe;Google Update Service (gupdate1ca630e917026fe);c:\program files\Google\Update\GoogleUpdate.exe [11/11/2009 4:05 PM 133104]
S3 vvftav211;vvftav211;c:\windows\system32\drivers\vvftav211.sys [8/12/2009 12:26 AM 480128]
S3 ZSMC30x;USB PC Camera Service ZSMC30x;c:\windows\system32\drivers\ZS211.sys [8/12/2009 12:26 AM 1537024]
S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\PCPitstop\PCPitstopScheduleService.exe [6/30/2010 8:33 AM 90296]
.
Contents of the 'Scheduled Tasks' folder

2010-07-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-11 20:35]

2010-07-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-11 20:35]

2010-07-17 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1715567821-1801674531-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:39]

2010-07-17 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1715567821-1801674531-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:39]

2010-07-17 c:\windows\Tasks\User_Feed_Synchronization-{1AFE76CF-3904-45E9-AE5C-C2494D5800D6}.job
- c:\windows\system32\msfeedssync.exe [2009-01-08 09:01]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.com.ve/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-setup715newver0015.exe - c:\documents and settings\User\Application Data\BD330B408BD2353F1E08DE01BC703164\setup715newver0015.exe
AddRemove-VIA Chrome9 HC IGP Display - c:\progra~1\S3\UChromeP\s3minset.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-17 01:43
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(852)
c:\windows\system32\GTGina.dll

- - - - - - - > 'explorer.exe'(1952)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
c:\windows\system32\WgaTray.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\Yahoo!\Messenger\ymsgr_tray.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2010-07-17 01:49:41 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-17 06:19

Pre-Run: 64,444,473,344 bytes free
Post-Run: 64,652,431,360 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - FDA6B47AB2BB8F3ACD1FEC9198C937BC



Once again thanks a lot….

Attachments:

Hello Moe_J_AK

Thank you for the log.

Please work your way through the following steps:


  • MGADiag


    • Please download MGADiag by clicking here and save it to your desktop.
    • Double click the [external image: Posted Image] icon on your desktop.
    • Push [external image: Posted Image]
    • Push [external image: Posted Image]
    • Go to Start -> Run and type in "Notepad"
    • Go to Edit -> Paste in notepad.
    • "x" out all of the numbers and letters in the line beginning with "Windows Product Key:"
    • Copy and paste that log here.


    There are two files on your machine that need to be replaced. We will look for suitable replacements as part of the fix below:

  • Please work through the following steps


    • Open Notepad (Click on "Start", then on "Run" and type "notepad" (without quotations) in the Open field, then click on "OK").
    • NOTE: Do not Use Wordpad or any other text editor except Notepad or the script will fail.
    • Copy and Paste the text in the quotebox below into the open Notepad window:

      File::
      c:\windows\system32\config\systemprofile\Application Data\hvyacl.dat
      c:\windows\DXT206.tmp
      c:\windows\DXT205.tmp
      c:\windows\DXT204.tmp
      c:\windows\DXT203.tmp

      DirLook::
      c:\program files\directx

      SRPeek::
      c:\windows\system32\drivers\tcpip.sys
      c:\windows\system32\sfcfiles.dll

    • Save this as "CFScript.txt" (including the quotation marks), change the "Save as type" to "All Files" and save it to your desktop.
    • Close any open browsers.
    • Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Refering to the picture below, drag CFScript.txt into ComboFix.exe

      [external image: Posted Image]
    • When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
    • Once the log is produced, re-engage your resident anti virus.

    Please post the MGADiag log and the ComboFix log in your next reply.
Hello JonTom, Here you have both logs: 1) MGADiag.txt Diagnostic Report (1.9.0027.0): —————————————– Windows Validation Data–> Validation Status: Geographically blocked PID Validation Code: 13 Cached Validation Code: N/A Windows Product Key: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx Windows Product Key Hash: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx Windows Product ID: 55274-640-0054156-23907 Windows Product ID Type: 1 Windows License Type: Volume Windows OS version: 5.1.2600.2.00010100.3.0.pro ID: {35F35822-5EC8-4DEC-ABAE-3B57E8B42168}(3) Is Admin: Yes TestCab: 0x0 LegitcheckControl ActiveX: Registered, 1.8.31.9 Signed By: Microsoft Product Name: N/A Architecture: N/A Build lab: N/A TTS Error: N/A Validation Diagnostic: 025D1FF3-230-1 Resolution Status: N/A Vista WgaER Data–> ThreatID(s): N/A Version: N/A Windows XP Notifications Data–> Cached Result: 13 File Exists: Yes Version: 1.8.31.9 WgaTray.exe Signed By: Microsoft WgaLogon.dll Signed By: Microsoft OGA Notifications Data–> Cached Result: N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 OGAExec.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: N/A, hr = 0x80070002 OGA Data–> Office Status: 103 Blocked VLK Microsoft Office Enterprise 2007 - 103 Blocked VLK OGA Version: N/A, 0x80070002 Signed By: N/A, hr = 0x80070002 Office Diagnostics: 025D1FF3-230-1 Browser Data–> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32) Default Browser: C:\Program Files\Internet Explorer\IEXPLORE.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data–> Other data–> Office Details: {35F35822-5EC8-4DEC-ABAE-3B57E8B42168}1.9.0027.05.1.2600.2.00010100.3.0.prox32*****-*****-*****-*****-6XBFJ55274-640-0054156-239071S-1-5-21-1060284298-1715567821-1801674531To Be Filled By O.E.M.To Be Filled By O.E.M.American Megatrends Inc.P1.0020070412000000.000000+0008C0F37C70184207B04090409Venezuela Standard Time(GMT-04:30)03103 Licensing Data–> N/A Windows Activation Technologies–> N/A HWID Data–> N/A OEM Activation 1.0 Data–> BIOS string matches: yes Marker string from BIOS: 136C4:GENUINE C&C INC Marker string from OEMBIOS.DAT: N/A, hr = 0x80004005 OEM Activation 2.0 Data–> N/A 2)Combo log: ComboFix 10-07-15.05 - User 07/17/2010 15:08:29.2.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1407.991 [GMT -4.5:30] Running from: c:\documents and settings\[removed]\Desktop\moejak.exe Command switches used :: c:\documents and settings\User\Desktop\CFScript.txt AV: avast! antivirus 4.8.1351 [VPS 091124-0] *On-access scanning disabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D} FILE :: "c:\windows\DXT203.tmp" "c:\windows\DXT204.tmp" "c:\windows\DXT205.tmp" "c:\windows\DXT206.tmp" "c:\windows\system32\config\systemprofile\Application Data\hvyacl.dat" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\DXT203.tmp c:\windows\DXT204.tmp c:\windows\DXT205.tmp c:\windows\DXT206.tmp c:\windows\system32\config\systemprofile\Application Data\hvyacl.dat . ((((((((((((((((((((((((( Files Created from 2010-06-17 to 2010-07-17 ))))))))))))))))))))))))))))))) . 2010-07-17 19:27 . 2010-07-17 19:27 ——– d—–w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage 2010-07-17 06:12 . 2010-07-17 06:12 ——– d—–w- c:\windows\system32\xircom 2010-07-17 06:12 . 2010-07-17 06:12 ——– d—–w- c:\windows\system32\wbem\snmp 2010-07-17 06:12 . 2010-07-17 06:12 ——– d—–w- c:\program files\microsoft frontpage 2010-07-14 00:44 . 2010-06-14 14:31 744448 ——w- c:\windows\system32\dllcache\helpsvc.exe 2010-07-10 23:08 . 2010-07-10 23:08 ——– d—–w- c:\program files\directx 2010-07-10 23:05 . 2010-07-10 23:05 ——– d—–w- c:\program files\EACOM 2010-07-10 23:03 . 2010-07-10 23:03 ——– d—–w- c:\program files\EA SPORTS 2010-07-07 02:05 . 2010-07-07 02:05 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache 2010-07-04 21:54 . 2010-07-04 23:07 ——– d—–w- C:\Games 2010-06-30 13:03 . 2010-06-30 13:04 ——– d—–w- c:\documents and settings\All Users\Application Data\PCPitstop 2010-06-30 13:03 . 2010-06-30 13:03 ——– d—–w- c:\program files\PCPitstop 2010-06-28 18:46 . 2010-04-20 05:30 285696 ——w- c:\windows\system32\dllcache\atmfd.dll 2010-06-28 18:46 . 2010-02-12 04:27 100864 ——w- c:\windows\system32\dllcache\6to4svc.dll 2010-06-28 18:46 . 2010-02-11 11:36 226880 ——w- c:\windows\system32\dllcache\tcpip6.sys 2010-06-28 18:45 . 2010-01-29 14:53 691712 ——w- c:\windows\system32\dllcache\inetcomm.dll 2010-06-28 18:45 . 2010-03-05 14:37 65536 ——w- c:\windows\system32\dllcache\asycfilt.dll 2010-06-28 18:39 . 2010-03-05 18:45 456704 ——w- c:\windows\system32\dllcache\smtpsvc.dll 2010-06-28 18:23 . 2010-05-06 10:41 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll 2010-06-28 18:09 . 2009-12-24 06:42 178176 ——w- c:\windows\system32\dllcache\wintrust.dll 2010-06-28 18:08 . 2010-01-13 14:01 86016 ——w- c:\windows\system32\dllcache\cabview.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-07-15 01:04 . 2009-08-03 00:53 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help 2010-07-15 00:57 . 2009-08-09 03:23 ——– d—–w- c:\program files\Microsoft Silverlight 2010-07-10 23:05 . 2009-08-03 00:43 ——– d–h–w- c:\program files\InstallShield Installation Information 2010-06-14 14:31 . 2009-08-03 00:02 744448 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe 2010-06-02 09:25 . 2010-07-10 23:22 74072 —-a-w- c:\windows\system32\XAPOFX1_5.dll 2010-06-02 09:25 . 2010-07-10 23:22 527192 —-a-w- c:\windows\system32\XAudio2_7.dll 2010-06-02 09:25 . 2010-07-10 23:22 239960 —-a-w- c:\windows\system32\xactengine3_7.dll 2010-05-26 16:11 . 2010-07-10 23:22 2106216 —-a-w- c:\windows\system32\D3DCompiler_43.dll 2010-05-26 16:11 . 2010-07-10 23:22 470880 —-a-w- c:\windows\system32\d3dx10_43.dll 2010-05-26 16:11 . 2010-07-10 23:22 248672 —-a-w- c:\windows\system32\d3dx11_43.dll 2010-05-26 16:11 . 2010-07-10 23:22 1868128 —-a-w- c:\windows\system32\d3dcsx_43.dll 2010-05-26 16:11 . 2010-07-10 23:22 1998168 —-a-w- c:\windows\system32\D3DX9_43.dll 2010-05-06 10:41 . 2008-10-16 19:38 916480 —-a-w- c:\windows\system32\wininet.dll 2010-05-02 16:34 . 2009-01-08 19:14 1860352 —-a-w- c:\windows\system32\win32k.sys 2010-04-20 05:30 . 2008-04-14 04:39 285696 —-a-w- c:\windows\system32\atmfd.dll . (((((((((((((((((((((((((((((((((((((((((((( Look ))))))))))))))))))))))))))))))))))))))))))))))))))))))))) . —- Directory of c:\program files\directx —- (((((((((((((((((((((((((((((((((((((((((( SR_Search )))))))))))))))))))))))))))))))))))))))))))))))))))))))) . ——- Sigcheck ——- [-] 2009-01-08 . 5AE1C2695F6523AD98B948F2887D8C5E . 361600 . . [5.1.2600.5649] . . c:\windows\system32\drivers\tcpip.sys [-] 2009-01-08 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll . ((((((((((((((((((((((((((((( SnapShot@2010-07-17_06.13.38 ))))))))))))))))))))))))))))))))))))))))) . + 2009-12-27 03:22 . 2010-07-17 19:05 243812 c:\windows\system32\inetsrv\MetaBase.bin . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}] 2009-01-02 18:06 365960 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-01-02 365960] [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-01-02 365960] [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-14 39408] "Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2009-11-10 5244216] "Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856] "AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2009-08-10 2356088] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Athan"="c:\program files\Athan\Athan.exe" [2009-07-29 1114112] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152] "ZSSnp211"="c:\windows\ZSSnp211.exe" [2007-04-06 57344] "Domino"="c:\windows\Domino.exe" [2006-08-18 49152] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-13 202256] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "_nltide_2"="shell32" [X] c:\documents and settings\All Users\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472] PalTalk.lnk - c:\program files\Paltalk Messenger\paltalk.exe [2010-3-22 11554304] [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Authentication Packages REG_MULTI_SZ msv1_0 nwprovau [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2007-05-11 10:06 40048 —-a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr] 2005-05-04 01:43 69632 —-a-r- c:\windows\Alcmtr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor] 2008-10-25 16:14 31072 —-a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr] 2009-07-26 21:14 3883856 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL] 2006-10-31 02:49 16269312 —-a-r- c:\windows\RTHDCPL.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\S3Trayp] 2006-10-10 12:14 176128 —-a-r- c:\windows\system32\S3Trayp.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel] 2006-05-17 01:04 2879488 —-a-r- c:\windows\SkyTel.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer] 2006-09-21 23:36 53248 —-a-r- c:\windows\system32\VTTimer.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"= "c:\\SIERRA\\Half-Life\\hl.exe"= R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [8/2/2009 8:32 PM 114768] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8/2/2009 8:32 PM 20560] S2 gupdate1ca630e917026fe;Google Update Service (gupdate1ca630e917026fe);c:\program files\Google\Update\GoogleUpdate.exe [11/11/2009 4:05 PM 133104] S3 vvftav211;vvftav211;c:\windows\system32\drivers\vvftav211.sys [8/12/2009 12:26 AM 480128] S3 ZSMC30x;USB PC Camera Service ZSMC30x;c:\windows\system32\drivers\ZS211.sys [8/12/2009 12:26 AM 1537024] S4 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\PCPitstop\PCPitstopScheduleService.exe [6/30/2010 8:33 AM 90296] . Contents of the 'Scheduled Tasks' folder 2010-07-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-11-11 20:35] 2010-07-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-11-11 20:35] 2010-07-17 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1060284298-1715567821-1801674531-1003.job - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:39] 2010-07-17 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1060284298-1715567821-1801674531-1003.job - c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-25 02:39] 2010-07-17 c:\windows\Tasks\User_Feed_Synchronization-{1AFE76CF-3904-45E9-AE5C-C2494D5800D6}.job - c:\windows\system32\msfeedssync.exe [2009-01-08 09:01] . . ——- Supplementary Scan ——- . uStart Page = hxxp://google.com.ve/ IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html DPF: {A27C56D2-3F58-4ABB-AA31-1168EDA6636F} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab . ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'winlogon.exe'(848) c:\windows\system32\GTGina.dll . Completion time: 2010-07-17 15:15:09 ComboFix-quarantined-files.txt 2010-07-17 19:45 Pre-Run: 64,728,641,536 bytes free Post-Run: 64,716,304,384 bytes free - - End Of File - - E3B692265B35DC9921DA3F13CE64FF45 thank you…
Hello Moe_J_AK

It appears from the logs you have posted that you may have been the victim of software piracy. To resolve this issue you are advised to contact the location where you obtained your operating system (or contact MicroSoft directly).

Unless your operating system has been validated I cannot continue to give assistance.
Due to inactivity, this topic has been closed. If you are the topic starter and need this topic reopened, please PM a staff member (include the address of this thread in your request). Everyone else please start a new topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI