PLEASE HELP!
hi i understand u come across this issues 100times a day but its quite pain in the a** for business users like us…
1. I m using Kaspersky Internet Security 2010 AFTER i was infected by worm/virus/trojan i dont even know exactly what or maybe all of them… I have updated KIS 2010 databases to current day!
2. The problems i m having are …
a) when i goto google/hotmail,etc it redirects me to some fake google site…
i cannot even open www.hotmail.com AND recieve """500 Error - Web Site is Temporarily Unavailable
The server is temporarily unable to service your request due to maintenance downtime or capacity problems.Please try again later""".
c) most of the time MSN>ALK messenger dont work i cannot sign-in (yahoo msnger works though)… in short my basic internet browsing is AFFECTED a lot.
3. i cannot download avz.exe from your link. in the save dialogue it tries to save it as error500.html ONLY.
4. my internet speed comes down to 2kb/sec and it is very very difficult to update kaspersky in normal mode.
i have updated it in safemode with networking MODE.
5. i have scanned and rescanned by FULL COMPUTER SCAN after every update…till now it has cleaned about 15-20 different THREATS but the problem still persists.
MY SYSTEMINFO LOG LINK:
http://www.getsysteminfo.com/read.php?file…56380fc98bf2ab5
YOUR HELP WILL BE GREATLY APPRECIATED
THANKS!!
Hi
Please do the following:
Please download MBRCheck.exe to your desktop.
Be sure to disable your security programs Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt) A window will open on your desktop if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice. If nothing unusual is found just press Enter A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop. Please post the contents of that file.
NEXT
Please download
DDS from either of these links
LINK 1
LINK 2
and save it to your
desktop.
Disable any script blocking protection Double click dds.pif to run the tool. When done, two DDS.txt's will open. Save both reports to your desktop. —————————————————
Please include the contents of the following in your next reply:
DDS.txt
Attach.txt .
NEXT
Download
GMER Rootkit Scanner from
here to your desktop. It will be a randomly named executable.
Double click the exe file. If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO , then use the following settings for a more complete scan.
[external image: Posted Image]
Click the image to enlarge it
In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked IAT/EAT Drives/Partition other than Systemdrive (typically C:\) Show All (don't miss this one) Then click the Scan button & wait for it to finish. Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and attach it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hiii CatByte.. as per ur instructions..
1. mbrchk.. and 2. ddr worked fine .. i m attaching both the logs below… but the 3.gmer rootkit scanner got me a BLUESCREEN 3 times as per your given settings… so i didnt get the logfile for GMER. Let me konw what to do.
thanks!!!!!!!!!!!!!
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
xxxx
MBRCheck, version 1.1.1
© 2010, AD
\\.\C: –> \\.\PhysicalDrive0
\\.\D: –> \\.\PhysicalDrive0
Size Device Name MBR Status
——————————————–
111 GB \\.\PhysicalDrive0 Windows Vista MBR code detected
Done! Press ENTER to exit…
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
x
DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 18:10:27.86 on Fri 07/23/2010
Internet Explorer: 7.0.6000.16982
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.2046.968 [GMT 5.5:30]
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: Kaspersky Internet Security *disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\System32\bcmwltry.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Windows\system32\PnkBstrA.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Windows\System32\tcpsvcs.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k iissvcs
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\ZSSnp211.exe
C:\Windows\Domino.exe
C:\Program Files\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe
C:\Windows\sttray.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\My Lockbox\flockbox.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Intuwave\Shared\mRouterRuntime\mRouterRuntime.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Symbian\Shared\SYMBIA~1\SYMBIA~1.EXE
C:\PROGRA~1\Symbian\Shared\SYMBIA~1\SCBAL.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\R-Crypto\EDisk.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
C:\Windows\system32\conime.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\pbs\Desktop\dds.com
============== Pseudo HJT Report ===============
uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
uStart Page = about:blank
uWindow Title = Internet Explorer provided by Dell
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
mStart Page = hxxp://www.yahoo.com/
mDefault_Page_URL = hxxp://www.yahoo.com/
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2010\ievkbd.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.5126.1836\swg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [mRouterConfig] "c:\program files\intuwave\shared\mrouterruntime\mRouterConfig.exe"
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: []
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [ZSSnp211] c:\windows\ZSSnp211.exe
mRun: [Domino] c:\windows\Domino.exe
mRun: [PC Suite for Smartphones] "c:\program files\sony ericsson\mobile4\application launcher\Application Launcher.exe" /startoptions
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [SigmatelSysTrayApp] sttray.exe
mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start
mRun: [flockbox] c:\program files\my lockbox\flockbox.exe /a
mRun: [R-Crypto] c:\program files\r-crypto\EDiskCall.exe Startup
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\windows\installer\{53a01cc6-14b0-4512-a2e7-10d39bf83dc4}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe
IE: &Clean Traces - c:\program files\dap\privacy package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\dap\dapextie.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download &all with DAP - c:\program files\dap\dapextie2.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Translate with &Babylon - c:\program files\babylon\babylon-pro\utils\BabylonIEPI.dll/Translate.htm
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\npjpi160.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
Trusted Zone: yahoo%20messenger
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w2/resources/VistaMSNPUplden-in.cab
DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} - hxxp://www.systemrequirementslab.com/sysreqlab2.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: {DBA345A4-E55A-4C76-BBC0-224D78F9ACBC} = 61.1.96.71,61.1.96.69
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~3\office12\GR99D3~1.DLL
Notify: klogon - c:\windows\system32\klogon.dll
AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll,c:\progra~1\kasper~1\kasper~1\kloehk.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\users\pbs\appdata\roaming\mozilla\firefox\profiles\3zs08xny.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage -
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - component: c:\program files\mozilla firefox\extensions\[removed]\components\KavLinkFilter.dll
FF - component: c:\users\pbs\appdata\roaming\mozilla\firefox\profiles\3zs08xny.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
FF - plugin: c:\users\pbs\appdata\local\yahoo!\browserplus\2.5.1\plugins\npybrowserplus_2.5.1.dll
FF - plugin: c:\users\pbs\program files\dna\plugins\npbtdna.dll
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-14 36880]
R0 MPRIFL;MPRIFL;c:\windows\system32\drivers\mprifl.sys [2010-3-9 17264]
R1 EDiskDrv;EDiskDrv;c:\windows\system32\drivers\EDiskDrv.sys [2009-6-25 26416]
R1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\elrawdsk.sys [2008-10-2 12800]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\drivers\klim6.sys [2009-9-14 21520]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-10-2 19472]
S2 AVP;Kaspersky Internet Security;c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe [2009-10-20 340456]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-29 135664]
S3 HDDirect;Hard Disk Direct Control;c:\windows\system32\drivers\hddirect.sys [2010-7-21 12552]
S3 W35UNDW;W89C35 802.11bg WLAN USB Adapter Driver;c:\windows\system32\drivers\W35UNDW.SYS [2010-3-5 134656]
============== File Associations ===============
JSEFile=NOTEPAD.EXE %1
regfile=NOTEPAD.EXE %1
scrfile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.scr=AutoCADScriptFile
=============== Created Last 30 ================
2010-07-21 08:19:23 0 d–h–w- c:\windows\PIF
2010-07-21 08:09:58 12552 —-a-w- c:\windows\system32\drivers\hddirect.sys
2010-07-20 18:40:38 0 d—–w- C:\antiboot
2010-07-20 12:46:40 97549 —-a-w- c:\windows\system32\drivers\klick.dat
2010-07-20 12:46:40 113933 —-a-w- c:\windows\system32\drivers\klin.dat
2010-07-20 12:45:03 0 d—–w- c:\program files\Kaspersky Lab
2010-07-20 12:40:25 0 d—–w- c:\programdata\Kaspersky Lab Setup Files
2010-07-20 11:08:30 0 d—–w- c:\programdata\Kaspersky Lab
2010-07-18 18:56:33 156672 —-a-w- c:\windows\system32\t2embed.dll
2010-07-18 18:56:32 72704 —-a-w- c:\windows\system32\fontsub.dll
2010-07-18 18:56:32 34304 —-a-w- c:\windows\system32\atmlib.dll
2010-07-18 18:56:32 289792 —-a-w- c:\windows\system32\atmfd.dll
2010-07-18 18:56:32 24064 —-a-w- c:\windows\system32\lpk.dll
2010-07-18 18:56:32 10240 —-a-w- c:\windows\system32\dciman32.dll
2010-07-18 18:55:53 61440 —-a-w- c:\windows\system32\winipsec.dll
2010-07-18 18:55:53 361984 —-a-w- c:\windows\system32\IPSECSVC.DLL
2010-07-18 18:55:53 28672 —-a-w- c:\windows\system32\FwRemoteSvr.dll
2010-07-18 18:55:53 272896 —-a-w- c:\windows\system32\polstore.dll
2010-07-18 18:55:18 84992 —-a-w- c:\windows\system32\drivers\srvnet.sys
2010-07-18 18:55:17 306688 —-a-w- c:\windows\system32\drivers\srv.sys
2010-07-18 18:54:13 9728 —-a-w- c:\windows\system32\TCPSVCS.EXE
2010-07-18 18:54:13 8704 —-a-w- c:\windows\system32\HOSTNAME.EXE
2010-07-18 18:54:13 15360 —-a-w- c:\windows\system32\netevent.dll
2010-07-18 18:54:13 11264 —-a-w- c:\windows\system32\MRINFO.EXE
2010-07-18 18:54:13 103936 —-a-w- c:\windows\system32\netiohlp.dll
2010-07-18 18:54:13 10240 —-a-w- c:\windows\system32\finger.exe
2010-07-18 18:54:12 27136 —-a-w- c:\windows\system32\NETSTAT.EXE
2010-07-18 18:54:12 19968 —-a-w- c:\windows\system32\ARP.EXE
2010-07-18 18:54:12 17920 —-a-w- c:\windows\system32\ROUTE.EXE
2010-07-18 18:53:00 1657350 —-a-w- c:\windows\system32\wlan.tmf
2010-07-18 18:53:00 123904 —-a-w- c:\windows\system32\L2SecHC.dll
2010-07-18 18:52:59 67584 —-a-w- c:\windows\system32\wlanhlp.dll
2010-07-18 18:52:59 502272 —-a-w- c:\windows\system32\wlansvc.dll
2010-07-18 18:52:59 47104 —-a-w- c:\windows\system32\wlanapi.dll
2010-07-18 18:52:59 297984 —-a-w- c:\windows\system32\wlansec.dll
2010-07-18 18:52:59 290816 —-a-w- c:\windows\system32\wlanmsm.dll
2010-07-18 18:52:11 1260032 —-a-w- c:\windows\system32\msxml3.dll
2010-07-18 18:52:10 2048 —-a-w- c:\windows\system32\msxml6r.dll
2010-07-18 18:52:10 2048 —-a-w- c:\windows\system32\msxml3r.dll
2010-07-18 18:52:10 1406464 —-a-w- c:\windows\system32\msxml6.dll
2010-07-18 18:50:52 7680 —-a-w- c:\windows\system32\lsass.exe
2010-07-18 18:50:52 72704 —-a-w- c:\windows\system32\secur32.dll
2010-07-18 18:50:52 408136 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2010-07-18 18:50:52 216576 —-a-w- c:\windows\system32\msv1_0.dll
2010-07-18 18:50:52 175104 —-a-w- c:\windows\system32\wdigest.dll
2010-07-18 18:50:52 1233920 —-a-w- c:\windows\system32\lsasrv.dll
2010-07-18 18:49:22 211968 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-07-18 18:49:21 58368 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-07-18 18:49:21 102400 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-07-18 18:48:45 98816 —-a-w- c:\windows\system32\mfps.dll
2010-07-18 18:48:45 52736 —-a-w- c:\windows\system32\rrinstaller.exe
2010-07-18 18:48:45 2855424 —-a-w- c:\windows\system32\mf.dll
2010-07-18 18:48:45 2048 —-a-w- c:\windows\system32\mferror.dll
2010-07-18 18:48:44 24576 —-a-w- c:\windows\system32\mfpmp.exe
2010-07-18 18:47:56 3502480 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-07-18 18:47:56 3468168 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-07-18 18:47:21 376832 —-a-w- c:\windows\system32\winhttp.dll
2010-07-18 18:46:53 434176 —-a-w- c:\windows\system32\vbscript.dll
2010-07-18 18:45:36 500736 —-a-w- c:\windows\system32\msdtcprx.dll
2010-07-18 18:45:36 30208 —-a-w- c:\windows\system32\xolehlp.dll
2010-07-18 18:45:07 156160 —-a-w- c:\windows\system32\wkssvc.dll
2010-07-18 18:44:34 36352 —-a-w- c:\windows\system32\tsgqec.dll
2010-07-18 18:44:34 1871872 —-a-w- c:\windows\system32\mstscax.dll
2010-07-18 18:44:34 116736 —-a-w- c:\windows\system32\aaclient.dll
2010-07-18 18:29:46 171520 —-a-w- c:\windows\system32\wintrust.dll
2010-07-18 18:25:43 549888 —-a-w- c:\windows\system32\rpcss.dll
2010-07-18 18:25:40 654336 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2010-07-18 18:25:40 247296 —-a-w- c:\windows\system32\wbem\WmiPrvSE.exe
2010-07-18 18:25:40 24576 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2010-07-18 18:25:40 130560 —-a-w- c:\windows\system32\wbem\WmiDcPrv.dll
2010-07-18 18:25:39 614912 —-a-w- c:\windows\system32\wbem\fastprox.dll
2010-07-18 18:25:39 501760 —-a-w- c:\windows\system32\wbem\WmiPrvSD.dll
2010-07-18 18:25:38 97280 —-a-w- c:\windows\system32\iasrecst.dll
2010-07-18 18:25:38 53248 —-a-w- c:\windows\system32\iasads.dll
2010-07-18 18:25:38 37888 —-a-w- c:\windows\system32\iasdatastore.dll
2010-07-18 18:25:38 158720 —-a-w- c:\windows\system32\sdohlp.dll
2010-07-18 18:24:49 220672 —-a-w- c:\windows\system32\l3codecp.acm
2010-07-18 18:24:48 62464 —-a-w- c:\windows\system32\l3codeca.acm
2010-07-18 18:24:04 25088 —-a-w- c:\windows\system32\drivers\tunnel.sys
2010-07-18 18:24:04 179712 —-a-w- c:\windows\system32\iphlpsvc.dll
2010-07-18 18:24:04 15360 —-a-w- c:\windows\system32\drivers\TUNMP.SYS
2010-07-18 18:24:03 815104 —-a-w- c:\windows\system32\drivers\tcpip.sys
2010-07-18 18:24:03 22016 —-a-w- c:\windows\system32\netiougc.exe
2010-07-18 18:24:03 213592 —-a-w- c:\windows\system32\drivers\netio.sys
2010-07-18 18:24:03 167424 —-a-w- c:\windows\system32\tcpipcfg.dll
2010-07-18 18:23:16 97792 —-a-w- c:\windows\system32\cabview.dll
2010-07-18 18:21:32 312320 —-a-w- c:\windows\system32\msdrm.dll
2010-07-18 18:21:30 435712 —-a-w- c:\windows\system32\RMActivate_ssp.exe
2010-07-18 18:21:29 154112 —-a-w- c:\windows\system32\secproc_ssp.dll
2010-07-18 18:21:25 154624 —-a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-07-18 18:21:24 431104 —-a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-07-18 18:21:18 472576 —-a-w- c:\windows\system32\secproc.dll
2010-07-18 18:21:15 515584 —-a-w- c:\windows\system32\RMActivate.exe
2010-07-18 18:21:06 523776 —-a-w- c:\windows\system32\RMActivate_isv.exe
2010-07-18 18:21:04 473088 —-a-w- c:\windows\system32\secproc_isv.dll
2010-07-18 18:16:06 84480 —-a-w- c:\windows\system32\INETRES.dll
2010-07-18 18:16:05 737792 —-a-w- c:\windows\system32\inetcomm.dll
2010-07-18 18:14:10 51200 —-a-w- c:\windows\system32\admwprox.dll
2010-07-18 18:14:10 148480 —-a-w- c:\windows\system32\iisRtl.dll
2010-07-18 18:14:10 10752 —-a-w- c:\windows\system32\wamregps.dll
2010-07-18 18:14:09 14848 —-a-w- c:\windows\system32\iisreset.exe
2010-07-18 18:14:08 8192 —-a-w- c:\windows\system32\iisrstap.dll
2010-07-18 18:14:04 396800 —-a-w- c:\windows\system32\drivers\http.sys
2010-07-18 18:14:04 31232 —-a-w- c:\windows\system32\httpapi.dll
2010-07-18 18:14:03 24064 —-a-w- c:\windows\system32\nshhttp.dll
2010-07-18 18:11:10 321536 —-a-w- c:\windows\system32\WSDApi.dll
2010-07-18 18:09:25 50176 —-a-w- c:\windows\system32\iyuv_32.dll
2010-07-18 18:09:25 22528 —-a-w- c:\windows\system32\msyuv.dll
2010-07-18 18:09:25 11776 —-a-w- c:\windows\system32\tsbyuv.dll
2010-07-18 18:09:24 1327616 —-a-w- c:\windows\system32\quartz.dll
2010-07-18 18:09:23 88576 —-a-w- c:\windows\system32\avifil32.dll
2010-07-18 18:09:23 82944 —-a-w- c:\windows\system32\mciavi32.dll
2010-07-18 18:09:23 65024 —-a-w- c:\windows\system32\avicap32.dll
2010-07-18 18:09:23 31232 —-a-w- c:\windows\system32\msvidc32.dll
2010-07-18 18:09:23 13312 —-a-w- c:\windows\system32\msrle32.dll
2010-07-18 18:09:23 123904 —-a-w- c:\windows\system32\msvfw32.dll
2010-07-17 15:13:20 65536 –sha-w- c:\users\pbs\ntuser.dat{4697803e-91b5-11df-a0b2-00197dfde212}.TM.blf
2010-07-17 15:13:20 524288 –sha-w- c:\users\pbs\ntuser.dat{4697803e-91b5-11df-a0b2-00197dfde212}.TMContainer00000000000000000002.regtrans-ms
2010-07-17 15:13:20 524288 –sha-w- c:\users\pbs\ntuser.dat{4697803e-91b5-11df-a0b2-00197dfde212}.TMContainer00000000000000000001.regtrans-ms
==================== Find3M ====================
2010-07-22 17:17:19 6604 —-a-w- c:\windows\bthservsdp.dat
2010-07-20 12:45:59 86016 —-a-w- c:\windows\inf\infstor.dat
2010-07-20 12:45:59 51200 —-a-w- c:\windows\inf\infpub.dat
2010-07-20 12:45:58 143360 —-a-w- c:\windows\inf\infstrng.dat
2010-07-20 12:23:34 88587 —-a-w- c:\users\pbs\appdata\roaming\nvModes.dat
2010-07-18 19:39:20 665600 —-a-w- c:\windows\inf\drvindex.dat
2010-06-03 02:41:44 3600384 —-a-w- c:\windows\system32\GPhotos.scr
2010-05-21 08:44:28 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-05-21 08:36:46 622080 —-a-w- c:\windows\system32\icardagt.exe
2010-05-21 08:36:46 11264 —-a-w- c:\windows\system32\icardres.dll
2010-05-21 08:36:45 97800 —-a-w- c:\windows\system32\infocardapi.dll
2010-05-21 08:36:31 105016 —-a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2010-05-21 08:36:29 326160 —-a-w- c:\windows\system32\PresentationHost.exe
2010-05-21 08:36:28 781344 —-a-w- c:\windows\system32\PresentationNative_v0300.dll
2010-05-21 08:36:28 43544 —-a-w- c:\windows\system32\PresentationHostProxy.dll
2010-05-21 08:12:27 96760 —-a-w- c:\windows\system32\dfshim.dll
2010-05-21 08:12:26 41984 —-a-w- c:\windows\system32\netfxperf.dll
2010-05-21 08:12:19 282112 —-a-w- c:\windows\system32\mscoree.dll
2010-05-21 08:12:18 158720 —-a-w- c:\windows\system32\mscorier.dll
2010-05-21 08:12:17 83968 —-a-w- c:\windows\system32\mscories.dll
2009-12-15 07:12:15 174 –sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2010-04-22 02:03:40 16384 –sha-w- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2010-04-22 02:03:40 49152 –sha-w- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2010-04-22 02:03:40 16384 –sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\cookies\index.dat
2007-03-18 01:57:40 8192 –sha-w- c:\windows\users\default\NTUSER.DAT
============= FINISH: 18:10:43.35 ===============
Hi
Please try running GMER in safe mode with just "sections" and the "C:\" drive checked.
Due to inactivity this topic will be closed.
If you need help please start a new thread.
New members follow the instructions here
http://forums.whatthetech.com/you_Infected_t106388.html and start a new topic