This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Audio clips, redorbit popups, clicking noise

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I started getting IE popups from RedOrbit. Those stopped and now I'm getting the "clicking" sound IE makes randomly. When I opened Yahoo Mesenger I started getting sound clips playing in the background. DDS (Ver_10-03-17.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume2 Install Date: 1/2/2004 7:32:58 PM System Uptime: 7/28/2010 5:16:01 PM (39 hours ago) Motherboard: Dell Computer Corp. | | 0N2828 Processor: Intel® Pentium® 4 CPU 2.66GHz | Microprocessor | 2660/533mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 38 GiB total, 3.186 GiB free. D: is FIXED (FAT32) - 19 GiB total, 1.721 GiB free. E: is Removable F: is CDROM (CDFS) ==== Disabled Device Manager Items ============= Class GUID: {4D36E968-E325-11CE-BFC1-08002BE10318} Description: Intel® 82865G Graphics Controller Device ID: PCI\VEN_8086&DEV_2572&SUBSYS_01741028&REV_02\3&172E68DD&0&10 Manufacturer: Intel Corporation Name: Intel® 82865G Graphics Controller PNP Device ID: PCI\VEN_8086&DEV_2572&SUBSYS_01741028&REV_02\3&172E68DD&0&10 Service: ialm ==== System Restore Points =================== RP1890: 6/5/2010 10:19:34 AM - System Checkpoint RP1891: 6/6/2010 5:37:48 PM - System Checkpoint RP1892: 6/7/2010 11:49:27 PM - System Checkpoint RP1893: 6/8/2010 11:51:27 PM - System Checkpoint RP1894: 6/10/2010 2:52:15 AM - System Checkpoint RP1895: 6/11/2010 3:07:11 AM - System Checkpoint RP1896: 6/12/2010 4:07:17 AM - System Checkpoint RP1897: 6/13/2010 5:07:08 AM - System Checkpoint RP1898: 6/13/2010 9:12:22 AM - Logitech QuickCam v11.70.1196 RP1899: 6/14/2010 1:10:36 PM - System Checkpoint RP1900: 6/16/2010 3:04:41 AM - System Checkpoint RP1901: 6/17/2010 3:30:29 AM - System Checkpoint RP1902: 6/18/2010 4:30:34 AM - System Checkpoint RP1903: 6/19/2010 5:30:35 AM - System Checkpoint RP1904: 6/20/2010 6:30:34 AM - System Checkpoint RP1905: 6/21/2010 7:30:33 AM - System Checkpoint RP1906: 6/22/2010 9:08:49 AM - System Checkpoint RP1907: 6/24/2010 1:14:39 AM - System Checkpoint RP1908: 6/25/2010 1:30:41 AM - System Checkpoint RP1909: 6/26/2010 2:30:34 AM - System Checkpoint RP1910: 6/27/2010 2:31:46 AM - System Checkpoint RP1911: 6/28/2010 3:30:33 AM - System Checkpoint RP1912: 6/29/2010 3:57:14 AM - System Checkpoint RP1913: 6/30/2010 4:30:40 AM - System Checkpoint RP1914: 7/1/2010 5:30:46 AM - System Checkpoint RP1915: 7/2/2010 6:30:44 AM - System Checkpoint RP1916: 7/3/2010 11:19:27 AM - System Checkpoint RP1917: 7/4/2010 11:30:38 AM - System Checkpoint RP1918: 7/6/2010 1:32:13 AM - System Checkpoint RP1919: 7/7/2010 2:30:46 AM - System Checkpoint RP1920: 7/8/2010 3:37:41 AM - System Checkpoint RP1921: 7/9/2010 3:42:04 AM - System Checkpoint RP1922: 7/10/2010 4:42:04 AM - System Checkpoint RP1923: 7/11/2010 5:42:09 AM - System Checkpoint RP1924: 7/12/2010 6:42:03 AM - System Checkpoint RP1925: 7/13/2010 7:42:09 AM - System Checkpoint RP1926: 7/14/2010 3:21:16 PM - System Checkpoint RP1927: 7/16/2010 1:23:28 AM - System Checkpoint RP1928: 7/17/2010 1:42:07 AM - System Checkpoint RP1929: 7/18/2010 2:26:53 AM - System Checkpoint RP1930: 7/19/2010 2:42:09 AM - System Checkpoint RP1931: 7/20/2010 3:42:14 AM - System Checkpoint RP1932: 7/21/2010 4:42:14 AM - System Checkpoint RP1933: 7/22/2010 5:42:15 AM - System Checkpoint RP1934: 7/23/2010 5:43:20 AM - System Checkpoint RP1935: 7/24/2010 6:42:17 AM - System Checkpoint RP1936: 7/25/2010 5:08:55 PM - System Checkpoint RP1937: 7/27/2010 5:54:23 AM - System Checkpoint RP1938: 7/28/2010 6:46:45 AM - System Checkpoint RP1939: 7/29/2010 8:20:02 AM - System Checkpoint ==== Installed Programs ====================== 7-Zip 4.32 ABBYY FineReader 5.0 Sprint Adobe Download Manager 1.2 (Remove Only) Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 8.1.3 Adobe Shockwave Player Azureus Vuze Banctec Service Agreement BCM V.92 56K Modem BitTorrent 3.3 CDDRV_Installer Combined Community Codec Pack 2007-07-22 Compatibility Pack for the 2007 Office system Complete Cleanup Trial DA920EN DAO Dell Digital Jukebox Driver Dell Networking Guide Dell Solution Center Dell Support Direct Show Ogg Vorbis Filter (remove only) DivX Content Uploader DivX Web Player DS21Patch Earthlink Installer - uninstall 'Earthlink 5.0' entry first if present ELNKInst ffdshow (remove only) FoneSync Google Chrome Google Talk Plugin Help and Support Customization Holowan_Plug-in ICQ ICQ6.5 Intel® Extreme Graphics Driver Intel® PRO Network Adapters and Drivers Intel® PROSet Internet Explorer Default Page J2SE Runtime Environment 5.0 Update 6 Jasc Paint Shop Photo Album Jasc Paint Shop Pro 8 Dell Edition Java 2 Runtime Environment, SE v1.4.2 Java™ 6 Update 14 Java™ 6 Update 7 KhalInstallWrapper Kotor Tool Logitech QuickCam Logitech QuickCam Driver Package Logitech SetPoint Malwarebytes' Anti-Malware Master of Orion II Matroska Pack - Lazy Man's MKV 0.94 (2004-11-11) Microsoft .NET Framework 1.1 Microsoft .NET Framework 2.0 Service Pack 1 Microsoft .NET Framework 3.0 Service Pack 1 Microsoft .NET Framework 3.5 Microsoft Encarta Encyclopedia Standard 2004 Microsoft Games for Windows - LIVE Microsoft Games for Windows - LIVE Redistributable Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft Office XP Professional Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Works 2001 Setup Launcher Microsoft Works 6.0 Microsoft Works Suite Add-in for Microsoft Word mIRC Modem Helper Mozilla Firefox (3.6.6) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 and SOAP Toolkit 3.0 MSXML 6.0 Parser (KB925673) MTX MUSICMATCH® Jukebox Netscape (7.1) Norton Internet Security NVIDIA Drivers Polymath 5.1 PowerDVD Privacy Guardian 3.2 RealPlayer RoadRunner Tech Install Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901190) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941693) Security Update for Windows XP (KB943055) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB943485) Security Update for Windows XP (KB944338) Security Update for Windows XP (KB944653) Security Update for Windows XP (KB945553) Security Update for Windows XP (KB946026) Security Update for Windows XP (KB948590) Security Update for Windows XP (KB950749) Security Update for Windows XP (KB950759) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB958644) Sentinel System Driver 5.41.1 (32-bit) Shockwave SimpleMU MUD Client Skype™ 4.2 Star Wars® Knights of the Old Republic® II: The Sith Lords™ Star Wars®: Knights of the Old Republic ™ Steam Sun Download Manager 2.0 (web) Survival Map 2.3 Survival Map Packs :Map Pack II v1.2 System Requirements Lab The Drawing Board The Drawing Board (C:\Program Files\The Drawing Board\) The Drawing Board v2 Beta The Drawing Board v2 Beta (C:\Program Files\The Drawing Board\) The Ur-Quan Masters 0.6.2 Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB930916) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update for Windows XP (KB942763) VC 9.0 Runtime Viewpoint Media Player (Remove Only) Warhammer 40,000: Dawn of War II - Beta WebFldrs XP Windows Imaging Component Windows Installer 3.1 (KB893803) Windows Media Encoder 9 Series Windows Media Format Runtime Windows Media Player 10 Windows Presentation Foundation Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885884 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 Windows XP Service Pack 2 WordPerfect Office 11 Works Suite OS Pack Works Synchronization XML Paper Specification Shared Components Pack 1.0 Yahoo! Messenger ZoneAlarm ==== Event Viewer Messages From Past Week ======== 7/29/2010 12:58:18 AM, error: Service Control Manager [7034] - The WebClient service terminated unexpectedly. It has done this 1 time(s). 7/29/2010 12:58:18 AM, error: Service Control Manager [7034] - The TCP/IP NetBIOS Helper service terminated unexpectedly. It has done this 1 time(s). 7/28/2010 5:12:24 PM, error: ipnathlp [32003] - The Network Address Translator (NAT) was unable to request an operation of the kernel-mode translation module. This may indicate misconfiguration, insufficient resources, or an internal error. The data is the error code. 7/28/2010 2:33:42 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Beep 7/28/2010 2:33:42 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the TrueVector Internet Monitor service to connect. 7/28/2010 2:33:42 PM, error: Service Control Manager [7000] - The Webroot Client Service service failed to start due to the following error: The system cannot find the path specified. 7/28/2010 2:33:42 PM, error: Service Control Manager [7000] - The TrueVector Internet Monitor service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 7/28/2010 2:33:42 PM, error: Service Control Manager [7000] - The LBeepKE service failed to start due to the following error: A device attached to the system is not functioning. ==== End Of File =========================== Originally, my research led me to download Bootkit Remover. remover.exe produced this: Bootkit Remover © 2009 eSage Lab www.esagelab.com Program version: 1.1.0.0 OS Version: Microsoft Windows XP Home Edition Service Pack 2 (build 2600) System volume is \\.\C: \\.\C: -> \\.\PhysicalDrive0 at offset 0x00000000`01f60800 Boot sector MD5 is: 2191ee473479383cb93df8a212a49962 Size Device Name MBR Status ——————————————– 38 GB \\.\PhysicalDrive0 Unknown boot code Unknown boot code has been found on some of your physical disks. To inspect the boot code manually, dump the master boot sector: remover.exe dump [output_file] To disinfect the master boot sector, use the following command: remover.exe fix Done; Press any key to quit… I then did as the demostration showed and created a fix.bat file containing @ECHO OFF START remover.exe fix \\.\PhysicalDrive0 EXIT The result was: Bootkit Remover © 2009 eSage Lab www.esagelab.com Program version: 1.1.0.0 OS Version: Microsoft Windows XP Home Edition Service Pack 2 (build 2600) CreateFile() ERROR 121 ERROR: Can't open physical disk device. Done; Press any key to quit…
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post
•Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
•This may cause a delay in response time, but I will do my best to keep it as short as possible.
•I will reply back shortly with instructions.
Please post the DDS.txt log you should have from when you ran the program,if you no longer have it,please re run DDS.

Next

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER won't run try with devices unchecked.If still no go try in safe mode.




Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
The DDS log is in the previous post, unless you need a different log.


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-07-30 08:40:34
Windows 5.1.2600 Service Pack 2
Running: gt6b0xo3.exe; Driver: C:\DOCUME~1\Thomas\LOCALS~1\Temp\kwliifog.sys


—- Devices - GMER 1.0.15 —-

Device A Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device A Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)

AttachedDevice A fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \Driver\Tcpip \Device\Ip vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\Tcpip \Device\Tcp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\Tcpip \Device\Udp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\Tcpip \Device\RawIp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

—- Processes - GMER 1.0.15 —-

Process C:\Program Files\Internet Explorer\iexplore.exe (*** hidden *** ) 3464

—- EOF - GMER 1.0.15 —-

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-30 08:45:55
Windows 5.1.2600 Service Pack 2
Running: gt6b0xo3.exe; Driver: C:\DOCUME~1\Thomas\LOCALS~1\Temp\kwliifog.sys


—- System - GMER 1.0.15 —-

SSDT 8A09DA10 ZwAlertResumeThread
SSDT 8A09DAF0 ZwAlertThread
SSDT 8A1A1BB8 ZwAllocateVirtualMemory
SSDT 8A1B9E90 ZwAssignProcessToJobObject
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwConnectPort [0xB5DBD534]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateFile [0xB5DB7782]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xB6604130]
SSDT 8A20DDC0 ZwCreateMutant
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreatePort [0xB5DBDCC0]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateProcess [0xB5DD0EB4]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateProcessEx [0xB5DD12A2]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateSection [0xB5DDA916]
SSDT 8A1B9CB0 ZwCreateSymbolicLinkObject
SSDT 8A20A2F8 ZwCreateThread
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateWaitablePort [0xB5DBDDF6]
SSDT 8A1B9F70 ZwDebugActiveProcess
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteFile [0xB5DB8398]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xB66043B0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xB6604910]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDuplicateObject [0xB5DCFDF0]
SSDT 8A25CBC0 ZwFreeVirtualMemory
SSDT 8A20DEB0 ZwImpersonateAnonymousToken
SSDT 8A20DF90 ZwImpersonateThread
SSDT 8A11F6C8 ZwLoadDriver
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKey [0xB5DD893C]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKey2 [0xB5DD8B44]
SSDT 8A25CAE0 ZwMapViewOfSection
SSDT 8A20DCE0 ZwOpenEvent
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwOpenFile [0xB5DB7FAA]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwOpenProcess [0xB5DD31CE]
SSDT 8A01B1F8 ZwOpenProcessToken
SSDT 8A20DB20 ZwOpenSection
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwOpenThread [0xB5DD2DF8]
SSDT 8A1B9DA0 ZwProtectVirtualMemory
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRenameKey [0xB5DD98D2]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwReplaceKey [0xB5DD9208]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRequestWaitReplyPort [0xB5DBD0F4]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRestoreKey [0xB5DDA2A4]
SSDT 8A26E1F0 ZwResumeThread
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSecureConnectPort [0xB5DBD7DC]
SSDT 8A21A868 ZwSetContextThread
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetInformationFile [0xB5DB875C]
SSDT 8A1EBAE0 ZwSetInformationProcess
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetSecurityObject [0xB5DD9E12]
SSDT 8A20D9D8 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xB6604B60]
SSDT 8A20DC00 ZwSuspendProcess
SSDT 8A09DBD0 ZwSuspendThread
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSystemDebugControl [0xB5DD1F0A]
SSDT \SystemRoot\System32\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwTerminateProcess [0xB5DD1C86]
SSDT 8A21A788 ZwTerminateThread
SSDT 8A1EBBD0 ZwUnmapViewOfSection
SSDT 8A1A1AE8 ZwWriteVirtualMemory

—- Devices - GMER 1.0.15 —-

Device A Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device A Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
Device \Driver\Tcpip \Device\Ip vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\Tcpip \Device\Tcp vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD)

AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

—- Processes - GMER 1.0.15 —-

Process C:\Program Files\Internet Explorer\iexplore.exe (*** hidden *** ) 3464

—- EOF - GMER 1.0.15 —-
When you run DDS it produces two logs,DDS.txt and Attach.txt.You only posted attach.txt,please run it again and post DDS.txt

Also,did you run MBRCheck,i need to see that log
MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Home Edition Windows Information: Service Pack 2 (build 2600) Logical Drives Mask: 0x0000003d Kernel Drivers (total 142): 0x804D7000 \WINDOWS\system32\ntoskrnl.exe 0x806EC000 \WINDOWS\system32\hal.dll 0xF7987000 \WINDOWS\system32\KDCOM.DLL 0xF7897000 \WINDOWS\system32\BOOTVID.dll 0xF75A8000 ACPI.sys 0xF7989000 \WINDOWS\System32\DRIVERS\WMILIB.SYS 0xF7597000 pci.sys 0xF75F7000 isapnp.sys 0xF7A4F000 pciide.sys 0xF7707000 \WINDOWS\System32\DRIVERS\PCIIDEX.SYS 0xF7607000 MountMgr.sys 0xF74D8000 ftdisk.sys 0xF770F000 PartMgr.sys 0xF7617000 VolSnap.sys 0xF74C0000 atapi.sys 0xF7627000 disk.sys 0xF7637000 \WINDOWS\System32\DRIVERS\CLASSPNP.SYS 0xF74A0000 fltmgr.sys 0xF748E000 sr.sys 0xF743F000 SYMEFA.SYS 0xF7428000 KSecDD.sys 0xF7B52000 Ntfs.sys 0xF786A000 NDIS.sys 0xF7414000 srescan.sys 0xF784F000 Mup.sys 0xF7647000 agp440.sys 0xF76F7000 \SystemRoot\System32\DRIVERS\intelppm.sys 0xF777F000 \SystemRoot\System32\DRIVERS\usbuhci.sys 0xBA04B000 \SystemRoot\System32\DRIVERS\USBPORT.SYS 0xF7787000 \SystemRoot\System32\DRIVERS\usbehci.sys 0xB98F8000 \SystemRoot\system32\DRIVERS\nv4_mini.sys 0xB98E4000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xB97D7000 \SystemRoot\System32\DRIVERS\BCMSM.sys 0xB97B4000 \SystemRoot\System32\DRIVERS\ks.sys 0xF778F000 \SystemRoot\System32\Drivers\Modem.SYS 0xB9790000 \SystemRoot\System32\DRIVERS\e100b325.sys 0xF7797000 \SystemRoot\System32\DRIVERS\fdc.sys 0xF7587000 \SystemRoot\System32\DRIVERS\i8042prt.sys 0xF793B000 \SystemRoot\system32\DRIVERS\L8042Kbd.sys 0xF779F000 \SystemRoot\System32\DRIVERS\kbdclass.sys 0xF7577000 \SystemRoot\system32\DRIVERS\L8042mou.Sys 0xB977E000 \SystemRoot\System32\DRIVERS\LMouKE.Sys 0xF77A7000 \SystemRoot\System32\DRIVERS\mouclass.sys 0xF7567000 \SystemRoot\System32\DRIVERS\serial.sys 0xF793F000 \SystemRoot\System32\DRIVERS\serenum.sys 0xB976A000 \SystemRoot\System32\DRIVERS\parport.sys 0xF77AF000 \SystemRoot\System32\Drivers\MxlW2k.SYS 0xF7557000 \SystemRoot\System32\DRIVERS\cdrom.sys 0xF7547000 \SystemRoot\System32\DRIVERS\redbook.sys 0xB96DC000 \SystemRoot\system32\drivers\smwdm.sys 0xB96B8000 \SystemRoot\system32\drivers\portcls.sys 0xF7527000 \SystemRoot\system32\drivers\drmk.sys 0xF79AB000 \SystemRoot\system32\drivers\aeaudio.sys 0xBA7E9000 \SystemRoot\System32\DRIVERS\audstub.sys 0xBACD0000 \SystemRoot\System32\DRIVERS\rasl2tp.sys 0xF7947000 \SystemRoot\System32\DRIVERS\ndistapi.sys 0xB9679000 \SystemRoot\System32\DRIVERS\ndiswan.sys 0xBACC0000 \SystemRoot\System32\DRIVERS\raspppoe.sys 0xBACB0000 \SystemRoot\System32\DRIVERS\raspptp.sys 0xF77B7000 \SystemRoot\System32\DRIVERS\TDI.SYS 0xB9668000 \SystemRoot\System32\DRIVERS\psched.sys 0xBACA0000 \SystemRoot\System32\DRIVERS\msgpc.sys 0xF77BF000 \SystemRoot\System32\DRIVERS\ptilink.sys 0xF77C7000 \SystemRoot\System32\DRIVERS\raspti.sys 0xBAC90000 \SystemRoot\System32\DRIVERS\termdd.sys 0xF77CF000 \SystemRoot\system32\DRIVERS\SymIM.sys 0xF79CF000 \SystemRoot\System32\DRIVERS\swenum.sys 0xB956F000 \SystemRoot\System32\DRIVERS\update.sys 0xF77D7000 \SystemRoot\System32\DRIVERS\omci.sys 0xBAFFC000 \SystemRoot\System32\DRIVERS\mssmbios.sys 0xBAC80000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xBAC70000 \SystemRoot\System32\DRIVERS\usbhub.sys 0xF79D3000 \SystemRoot\System32\DRIVERS\USBD.SYS 0xF77DF000 \SystemRoot\System32\DRIVERS\flpydisk.sys 0xF79D7000 \SystemRoot\System32\Drivers\i2omgmt.SYS 0xB73A4000 \SystemRoot\System32\Drivers\NIS\1008000.029\SRTSP.SYS 0xB7233000 \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS 0xF7667000 \SystemRoot\system32\drivers\NIS\1008000.029\SRTSPX.SYS 0xF79DB000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF77F7000 \SystemRoot\System32\DRIVERS\usbccgp.sys 0xF7AB5000 \SystemRoot\System32\Drivers\Null.SYS 0xF77FF000 \SystemRoot\System32\drivers\vga.sys 0xF7677000 \SystemRoot\system32\drivers\LVUSBSta.sys 0xF79DD000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xB6D8F000 \SystemRoot\system32\DRIVERS\lvuvc.sys 0xF79E1000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF7687000 \SystemRoot\system32\drivers\usbaudio.sys 0xF7807000 \SystemRoot\System32\Drivers\Msfs.SYS 0xB6CF7000 \SystemRoot\system32\DRIVERS\lvrs.sys 0xF780F000 \SystemRoot\System32\Drivers\Npfs.SYS 0xBAFA7000 \SystemRoot\System32\DRIVERS\rasacd.sys 0xB6CE4000 \SystemRoot\System32\DRIVERS\ipsec.sys 0xB6C8C000 \SystemRoot\System32\DRIVERS\tcpip.sys 0xB6C30000 \SystemRoot\System32\Drivers\NIS\1008000.029\SYMTDI.SYS 0xB6C0F000 \SystemRoot\System32\DRIVERS\ipnat.sys 0xF76A7000 \SystemRoot\System32\DRIVERS\wanarp.sys 0xF7817000 \SystemRoot\System32\Drivers\NIS\1008000.029\SYMNDIS.SYS 0xF781F000 \SystemRoot\System32\DRIVERS\HIDPARSE.SYS 0xB6BFA000 \SystemRoot\System32\Drivers\NIS\1008000.029\SYMFW.SYS 0xF772F000 \SystemRoot\System32\Drivers\NIS\1008000.029\SYMIDS.SYS 0xB6A62000 \SystemRoot\System32\DRIVERS\netbt.sys 0xB69E1000 \SystemRoot\System32\vsdatant.sys 0xB69BF000 \SystemRoot\System32\drivers\afd.sys 0xF76D7000 \SystemRoot\System32\DRIVERS\netbios.sys 0xB6994000 \SystemRoot\System32\DRIVERS\rdbss.sys 0xB6925000 \SystemRoot\System32\DRIVERS\mrxsmb.sys 0xF7507000 \SystemRoot\System32\Drivers\Fips.SYS 0xB6877000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 0xB685A000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 0xB67DF000 \SystemRoot\System32\Drivers\NIS\1008000.029\ccHPx86.sys 0xB679D000 \SystemRoot\System32\Drivers\NIS\1008000.029\BHDrvx86.sys 0xB6752000 \SystemRoot\System32\Drivers\Fastfat.SYS 0xBACE0000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xB673A000 \SystemRoot\System32\Drivers\dump_atapi.sys 0xF7995000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xB6C78000 \SystemRoot\System32\drivers\Dxapi.sys 0xB742F000 \SystemRoot\System32\watchdog.sys 0xBF9C3000 \SystemRoot\System32\drivers\dxg.sys 0xF7AA3000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF9D5000 \SystemRoot\System32\nv4_disp.dll 0xB6422000 \SystemRoot\System32\DRIVERS\ndisuio.sys 0xB60D6000 \SystemRoot\System32\DRIVERS\mrxdav.sys 0xF79CB000 \SystemRoot\System32\Drivers\ParVdm.SYS 0xB60C3000 \SystemRoot\System32\Drivers\SENTINEL.SYS 0xBFFA0000 \SystemRoot\System32\ATMFD.DLL 0xB5F96000 \SystemRoot\system32\drivers\wdmaud.sys 0xB6033000 \SystemRoot\system32\drivers\sysaudio.sys 0xB5D5C000 \SystemRoot\System32\DRIVERS\srv.sys 0xB743F000 \??\C:\WINDOWS\System32\drivers\symlcbrd.sys 0xB73F7000 \SystemRoot\system32\DRIVERS\LVPr2Mon.sys 0xB3469000 \SystemRoot\System32\DRIVERS\hidusb.sys 0xB4580000 \SystemRoot\System32\DRIVERS\HIDCLASS.SYS 0xB7437000 \SystemRoot\System32\DRIVERS\LHidFilt.Sys 0xB2BFD000 \SystemRoot\System32\DRIVERS\WDFLDR.SYS 0xB16F8000 \SystemRoot\System32\DRIVERS\Wdf01000.sys 0xB6C6C000 \SystemRoot\System32\DRIVERS\mouhid.sys 0xB7427000 \SystemRoot\System32\DRIVERS\LMouFilt.Sys 0xB01CA000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100812.022\NAVEX15.SYS 0xB01B6000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100812.022\NAVENG.SYS 0xB0161000 \??\C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20100809.001\IDSxpx86.sys 0x7C900000 \WINDOWS\SYSTEM32\ntdll.dll Processes (total 50): 0 System Idle Process 4 System 868 C:\WINDOWS\SYSTEM32\smss.exe 936 csrss.exe 960 C:\WINDOWS\SYSTEM32\winlogon.exe 1004 C:\WINDOWS\SYSTEM32\services.exe 1024 C:\WINDOWS\SYSTEM32\lsass.exe 1168 C:\WINDOWS\SYSTEM32\svchost.exe 1232 C:\WINDOWS\SYSTEM32\svchost.exe 1276 svchost.exe 1328 C:\WINDOWS\SYSTEM32\svchost.exe 1404 svchost.exe 1484 svchost.exe 1688 C:\WINDOWS\SYSTEM32\svchost.exe 1780 C:\WINDOWS\SYSTEM32\spoolsv.exe 1940 C:\Program Files\Common Files\Logishrd\LVCOMSER\LVComSer.exe 2032 C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe 180 C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe 396 C:\WINDOWS\explorer.exe 600 C:\WINDOWS\SYSTEM32\nvsvc32.exe 668 C:\WINDOWS\SYSTEM32\svchost.exe 752 wdfmgr.exe 1312 C:\WINDOWS\BCMSMMSG.exe 1528 C:\Program Files\Java\jre6\bin\jusched.exe 1636 C:\WINDOWS\SYSTEM32\rundll32.exe 2028 C:\Program Files\Common Files\Logishrd\LComMgr\Communications_Helper.exe 328 C:\Program Files\Logitech\QuickCam\Quickcam.exe 288 C:\Documents and Settings\Thomas\Local Settings\Application Data\Google\Update\GoogleUpdate.exe 140 C:\Documents and Settings\Thomas\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe 316 C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe 888 C:\Program Files\Logitech\SetPoint\SetPoint.exe 860 C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe 2596 C:\Program Files\Common Files\Logishrd\LVCOMSER\LVComSer.exe 2836 alg.exe 3160 C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe 3364 C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe 9496 C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe 1544 C:\WINDOWS\SYSTEM32\taskmgr.exe 7808 C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe 3308 C:\Program Files\Windows Media Player\wmplayer.exe 8428 C:\Documents and Settings\Thomas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe 1116 C:\Documents and Settings\Thomas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe 9968 C:\Documents and Settings\Thomas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe 6548 C:\Documents and Settings\Thomas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe 11616 C:\Documents and Settings\Thomas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe 12696 C:\Program Files\Java\jre6\launch4j-tmp\MegaMek.exe 8388 C:\Program Files\Common Files\Real\Update_OB\realsched.exe 16344 C:\Documents and Settings\Thomas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe 12384 wmiprvse.exe 14784 C:\Documents and Settings\Thomas\My Documents\Downloads\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`01f60800 (NTFS) \\.\D: –> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (FAT32) PhysicalDrive0 Model Number: Maxtor6E040L0, Rev: NAR61590 PhysicalDrive1 Model Number: ST320413A, Rev: 3.39 Size Device Name MBR Status ——————————————– 38 GB \\.\PhysicalDrive0 Known-bad MBR code detected (Whistler / Black Internet)! SHA1: 47055FAD2554A7035F16CE4EFCBE590BACF67C33 18 GB \\.\PhysicalDrive1 Known-bad MBR code detected (Whistler / Black Internet)! SHA1: 47055FAD2554A7035F16CE4EFCBE590BACF67C33 Found non-standard or infected MBR. Enter 'Y' and hit ENTER for more options, or 'N' to exit: Done! DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 6:04:55.61 on Fri 08/13/2010 Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_14 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1534.702 [GMT -5:00] FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe 4 svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe svchost.exe 4 C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\WINDOWS\BCMSMMSG.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\RunDLL32.exe C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe C:\Program Files\Logitech\QuickCam\Quickcam.exe C:\Documents and Settings\Thomas\Local Settings\Application Data\Google\Update\GoogleUpdate.exe C:\Documents and Settings\Thomas\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\taskmgr.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\Documents and Settings\Thomas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Thomas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Thomas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Thomas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Thomas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Program Files\Java\jre6\launch4j-tmp\MegaMek.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Documents and Settings\Thomas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Thomas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Thomas\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com uSearch Page = hxxp://www.google.com uDefault_Page_URL = uDefault_Search_URL = uSearch Bar = hxxp://www.google.com/ie uWindow Title = Road Runner High Speed Online mDefault_Search_URL = hxxp://www.google.com/ie mSearch Page = hxxp://www.google.com mStart Page = hxxp://www.google.com mSearch Bar = uCustomizeSearch = uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton internet security\engine\16.8.0.41\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton internet security\engine\16.8.0.41\IPSBHO.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton internet security\engine\16.8.0.41\coIEPlg.dll TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [Microsoft Works Update Detection] c:\program files\microsoft works\WkDetect.exe uRun: [Google Update] "c:\documents and settings\thomas\local settings\application data\google\update\GoogleUpdate.exe" /c mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE mRun: [BCMSMMSG] "c:\windows\BCMSMMSG.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe" mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~2.lnk - c:\program files\common files\microsoft shared\works shared\wkcalrem.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000 IE: {E59EB121-F339-4851-A3BA-FE49C35617C2} - c:\program files\icq6.5\ICQ.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton internet security\engine\16.8.0.41\CoIEPlg.dll Notify: igfxcui - igfxsrvc.dll Notify: LBTWlgn - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\thomas\applic~1\mozilla\firefox\profiles\jg9mleqz.default\ FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\coffplgn\components\coFFPlgn.dll FF - component: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\ipsffplgn\components\IPSFFPl.dll FF - component: c:\documents and settings\thomas\application data\mozilla\firefox\profiles\jg9mleqz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll FF - plugin: c:\documents and settings\thomas\application data\mozilla\plugins\npgoogletalk.dll FF - plugin: c:\documents and settings\thomas\local settings\application data\google\update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nis\1008000.029\SymEFA.sys [2010-2-2 310320] R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\nis\1008000.029\BHDrvx86.sys [2010-2-2 259632] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nis\1008000.029\cchpx86.sys [2010-2-2 482432] R1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20100809.001\IDSXpx86.sys [2010-8-12 331640] R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2004-4-18 532224] R2 Norton Internet Security;Norton Internet Security;c:\program files\norton internet security\engine\16.8.0.41\ccSvcHst.exe [2010-2-2 117640] R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service –> c:\windows\system32\zonelabs\vsmon.exe -service [?] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-6-12 102448] R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20100812.022\NAVENG.SYS [2010-8-12 85424] R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20100812.022\NAVEX15.SYS [2010-8-12 1362608] S2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2009-10-29 3712] S2 WRConsumerService;Webroot Client Service;"c:\program files\webroot\webrootsecurity\wrconsumerservice.exe" –> c:\program files\webroot\webrootsecurity\WRConsumerService.exe [?] S3 cdiskdun;cdiskdun;\??\c:\docume~1\thomas\locals~1\temp\cdiskdun.sys –> c:\docume~1\thomas\locals~1\temp\cdiskdun.sys [?] =============== Created Last 30 ================ 2010-08-02 23:52:00 0 d—–w- c:\program files\common files\Wise Installation Wizard 2010-07-29 22:53:04 0 d—–w- C:\4d5b36bb62f8f8ae7a6f361c383e ==================== Find3M ==================== 2010-08-03 18:39:19 0 —-a-w- c:\windows\system32\drivers\lvuvc.hs 2010-08-03 18:39:12 0 —-a-w- c:\windows\system32\drivers\logiflt.iad 2010-07-08 13:34:19 4212 —ha-w- c:\windows\system32\zllictbl.dat 2010-06-23 18:51:22 1238528 —-a-w- c:\windows\system32\zpeng25.dll 2008-11-06 02:50:31 15233 -c–a-w- c:\program files\common files\nycowek.ban 2008-11-06 02:50:31 10961 -c–a-w- c:\program files\common files\ivybujyk.bat 2008-11-06 02:50:30 19869 -c–a-w- c:\program files\common files\vimexanyb.dl 2008-11-06 02:50:30 18223 -c–a-w- c:\program files\common files\tacyliwi._dl 2008-11-06 02:50:30 16390 -c–a-w- c:\program files\common files\lopoq.db 2008-11-06 02:50:30 13137 -c–a-w- c:\program files\common files\zokif.sys 2008-11-06 02:50:30 10079 -c–a-w- c:\program files\common files\nalehuma.lib 2007-06-20 01:44:28 10007784 -c–a-w- c:\program files\Azureus_2.5.0.4a_Win32.setup.exe 2001-10-06 00:21:50 5331244 -c–a-w- c:\program files\icq2000b.exe ============= FINISH: 6:06:24.17 ===============
Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
The first time I ran combofix I accidentally denied internet access, without realizing that that was combofix. Combofix just kept running, so I've run it twice: once before installing the recovery console and once after. I am including both logs.


Without Recovery console:

ComboFix 10-08-15.01 - Thomas 08/15/2010 23:41:27.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1534.1184 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Thomas\Local Settings\Temporary Internet Files\sipip.sys
c:\documents and settings\Thomas\Local Settings\Temporary Internet Files\ubifix.vbs
C:\Install.exe
c:\windows\henasilyd.exe
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\windows\ubadiququ.scr
c:\windows\yjosivygu.dll

.
\\.\PhysicalDrive1 - Bootkit Whistler was found and disinfected
\\.\PhysicalDrive0 - Bootkit Whistler was found and disinfected
.
\\.\PhysicalDrive1 - Bootkit Whistler was found and disinfected
\\.\PhysicalDrive0 - Bootkit Whistler was found and disinfected
.
((((((((((((((((((((((((( Files Created from 2010-07-16 to 2010-08-16 )))))))))))))))))))))))))))))))
.

2010-08-03 18:35 . 2010-08-03 18:35 ——– d—–w- c:\documents and settings\Thomas\Local Settings\Application Data\Symantec
2010-08-02 23:52 . 2010-08-02 23:52 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-07-29 22:53 . 2010-07-30 02:59 ——– d—–w- C:\4d5b36bb62f8f8ae7a6f361c383e
2010-07-29 00:11 . 2010-07-29 00:13 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-16 04:57 . 2010-06-13 14:26 0 —-a-w- c:\windows\system32\drivers\lvuvc.hs
2010-08-16 04:57 . 2010-06-13 14:25 0 —-a-w- c:\windows\system32\drivers\logiflt.iad
2010-08-02 15:18 . 2004-01-03 01:33 65808 -c–a-w- c:\documents and settings\Thomas\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-29 06:57 . 2009-12-01 18:57 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-29 06:28 . 2004-05-18 03:35 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-07-29 03:41 . 2010-04-26 22:42 ——– d—–w- c:\program files\megamek-0.35.13-windows
2010-07-28 21:47 . 2010-02-25 04:10 ——– d—–w- c:\program files\megamek-dev-svn-20091208
2010-07-26 17:17 . 2009-01-31 20:40 ——– d—–w- c:\program files\Steam
2010-07-08 13:34 . 2004-01-18 23:21 4212 —ha-w- c:\windows\system32\zllictbl.dat
2010-06-23 18:51 . 2009-02-02 23:41 1238528 —-a-w- c:\windows\system32\zpeng25.dll
2010-06-23 18:51 . 2004-11-09 02:00 103936 —-a-w- c:\windows\system32\zlcommdb.dll
2010-06-23 18:51 . 2004-11-09 02:00 69120 —-a-w- c:\windows\system32\zlcomm.dll
2008-11-06 02:50 . 2008-11-06 02:50 15233 -c–a-w- c:\program files\Common Files\nycowek.ban
2008-11-06 02:50 . 2008-11-06 02:50 10961 -c–a-w- c:\program files\Common Files\ivybujyk.bat
2008-11-06 02:50 . 2008-11-06 02:50 19869 -c–a-w- c:\program files\Common Files\vimexanyb.dl
2008-11-06 02:50 . 2008-11-06 02:50 18223 -c–a-w- c:\program files\Common Files\tacyliwi._dl
2008-11-06 02:50 . 2008-11-06 02:50 16390 -c–a-w- c:\program files\Common Files\lopoq.db
2008-11-06 02:50 . 2008-11-06 02:50 13137 -c–a-w- c:\program files\Common Files\zokif.sys
2008-11-06 02:50 . 2008-11-06 02:50 10079 -c–a-w- c:\program files\Common Files\nalehuma.lib
2007-06-20 01:44 . 2007-06-20 01:43 10007784 -c–a-w- c:\program files\Azureus_2.5.0.4a_Win32.setup.exe
2001-10-06 00:21 . 2004-10-02 20:51 5331244 -c–a-w- c:\program files\icq2000b.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Thomas\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-01-11 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-08-04 180269]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"BCMSMMSG"="c:\windows\BCMSMMSG.exe" [2003-06-02 122880]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 148888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-26 8523776]
"nwiz"="nwiz.exe" [2007-12-26 1626112]
"NvMediaCenter"="NvMCTray.dll" [2007-12-26 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-02-13 564496]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-06-23 1043968]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-10-29 805392]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Microsoft Works Calendar Reminders.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2000-8-8 24633]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 08:42 72208 —-a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Documents and Settings\\Thomas\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\WINDOWS\\SYSTEM32\\ZoneLabs\\vsmon.exe"=

R0 SymEFA;Symantec Extended File Attributes;c:\windows\SYSTEM32\DRIVERS\NIS\1008000.029\SymEFA.sys [2/2/2010 11:55 PM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\SYSTEM32\DRIVERS\NIS\1008000.029\BHDrvx86.sys [2/2/2010 11:54 PM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\SYSTEM32\DRIVERS\NIS\1008000.029\cchpx86.sys [2/2/2010 11:54 PM 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100809.001\IDSXpx86.sys [8/12/2010 11:11 PM 331640]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe [2/2/2010 11:54 PM 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/12/2010 2:05 PM 102448]
S2 LBeepKE;LBeepKE;c:\windows\SYSTEM32\DRIVERS\LBeepKE.sys [10/29/2009 5:48 PM 3712]
S2 WRConsumerService;Webroot Client Service;"c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe" –> c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe [?]
S3 cdiskdun;cdiskdun;\??\c:\docume~1\Thomas\LOCALS~1\Temp\cdiskdun.sys –> c:\docume~1\Thomas\LOCALS~1\Temp\cdiskdun.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2010-07-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1577428371-2420907865-1656439345-1007Core.job
- c:\documents and settings\Thomas\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-01-11 01:54]

2010-07-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1577428371-2420907865-1656439345-1007UA.job
- c:\documents and settings\Thomas\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-01-11 01:54]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
uDefault_Search_URL =
mStart Page = hxxp://www.google.com
mSearch Bar =
uCustomizeSearch =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\jg9mleqz.default\
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - component: c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\jg9mleqz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\documents and settings\Thomas\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Thomas\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

Toolbar-SITEguard - (no file)
HKCU-Run-Microsoft Works Update Detection - c:\program files\Microsoft Works\WkDetect.exe
Notify-AtiExtEvent - (no file)
AddRemove-Survival Map - c:\program files\THQ\Dawn of War - Dark Crusade\DXP2\Data\uninst.exe
AddRemove-Survival Map Packs - c:\program files\THQ\Dawn of War - Dark Crusade\DXP2\Data\scenarios\mp\uninst.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-16 00:07
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.8.0.41\diMaster.dll\" /prefetch:1"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(964)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll

- - - - - - - > 'explorer.exe'(3872)
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\browselc.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\windows\system32\nvsvc32.exe
c:\windows\System32\wdfmgr.exe
c:\documents and settings\Thomas\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-08-16 00:18:06 - machine was rebooted
ComboFix-quarantined-files.txt 2010-08-16 05:17

Pre-Run: 3,048,099,840 bytes free
Post-Run: 5,674,676,224 bytes free

- - End Of File - - D89939278FD5A41D4B2FEE6971389709


With Recovery Console:


ComboFix 10-08-15.01 - Thomas 08/16/2010 0:30.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1534.895 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
\\.\PhysicalDrive1 - Bootkit Whistler was found and disinfected
\\.\PhysicalDrive0 - Bootkit Whistler was found and disinfected
.
((((((((((((((((((((((((( Files Created from 2010-07-16 to 2010-08-16 )))))))))))))))))))))))))))))))
.

2010-08-03 18:35 . 2010-08-03 18:35 ——– d—–w- c:\documents and settings\Thomas\Local Settings\Application Data\Symantec
2010-08-02 23:52 . 2010-08-02 23:52 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-07-29 22:53 . 2010-07-30 02:59 ——– d—–w- C:\4d5b36bb62f8f8ae7a6f361c383e
2010-07-29 00:11 . 2010-07-29 00:13 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-16 05:04 . 2005-03-15 19:30 5387014 —-a-w- c:\windows\Internet Logs\tvDebug.Zip
2010-08-16 04:57 . 2010-06-13 14:26 0 —-a-w- c:\windows\system32\drivers\lvuvc.hs
2010-08-16 04:57 . 2010-06-13 14:25 0 —-a-w- c:\windows\system32\drivers\logiflt.iad
2010-08-02 15:18 . 2004-01-03 01:33 65808 -c–a-w- c:\documents and settings\Thomas\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-29 06:57 . 2009-12-01 18:57 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-29 06:28 . 2004-05-18 03:35 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-07-29 03:41 . 2010-04-26 22:42 ——– d—–w- c:\program files\megamek-0.35.13-windows
2010-07-28 21:47 . 2010-02-25 04:10 ——– d—–w- c:\program files\megamek-dev-svn-20091208
2010-07-26 17:17 . 2009-01-31 20:40 ——– d—–w- c:\program files\Steam
2010-07-08 20:29 . 2010-07-08 20:29 503808 —-a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-21d73989-n\msvcp71.dll
2010-07-08 20:29 . 2010-07-08 20:29 499712 —-a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-21d73989-n\jmc.dll
2010-07-08 20:29 . 2010-07-08 20:29 348160 —-a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-21d73989-n\msvcr71.dll
2010-07-08 13:34 . 2004-01-18 23:21 4212 —ha-w- c:\windows\system32\zllictbl.dat
2010-07-08 13:33 . 2010-07-08 13:33 7423488 —-a-w- c:\windows\Internet Logs\xDB2C.tmp
2010-07-08 13:32 . 2010-07-08 13:33 7423488 —-a-w- c:\windows\Internet Logs\xDB2B.tmp
2010-06-23 18:51 . 2009-02-02 23:41 1238528 —-a-w- c:\windows\system32\zpeng25.dll
2010-06-23 18:51 . 2004-11-09 02:00 103936 —-a-w- c:\windows\system32\zlcommdb.dll
2010-06-23 18:51 . 2004-11-09 02:00 69120 —-a-w- c:\windows\system32\zlcomm.dll
2010-06-11 21:51 . 2010-06-11 21:51 3055600 —-a-w- c:\documents and settings\Thomas\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
2010-06-11 21:36 . 2010-06-11 21:36 275952 —-a-w- c:\documents and settings\Thomas\Application Data\Mozilla\plugins\npgoogletalk.dll
2008-11-06 02:50 . 2008-11-06 02:50 15233 -c–a-w- c:\program files\Common Files\nycowek.ban
2008-11-06 02:50 . 2008-11-06 02:50 10961 -c–a-w- c:\program files\Common Files\ivybujyk.bat
2008-11-06 02:50 . 2008-11-06 02:50 19869 -c–a-w- c:\program files\Common Files\vimexanyb.dl
2008-11-06 02:50 . 2008-11-06 02:50 18223 -c–a-w- c:\program files\Common Files\tacyliwi._dl
2008-11-06 02:50 . 2008-11-06 02:50 16390 -c–a-w- c:\program files\Common Files\lopoq.db
2008-11-06 02:50 . 2008-11-06 02:50 13137 -c–a-w- c:\program files\Common Files\zokif.sys
2008-11-06 02:50 . 2008-11-06 02:50 10079 -c–a-w- c:\program files\Common Files\nalehuma.lib
2007-06-20 01:44 . 2007-06-20 01:43 10007784 -c–a-w- c:\program files\Azureus_2.5.0.4a_Win32.setup.exe
2001-10-06 00:21 . 2004-10-02 20:51 5331244 -c–a-w- c:\program files\icq2000b.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Thomas\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-01-11 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-08-04 180269]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"BCMSMMSG"="c:\windows\BCMSMMSG.exe" [2003-06-02 122880]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 148888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-26 8523776]
"nwiz"="nwiz.exe" [2007-12-26 1626112]
"NvMediaCenter"="NvMCTray.dll" [2007-12-26 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-02-13 564496]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-06-23 1043968]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-10-29 805392]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Microsoft Works Calendar Reminders.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2000-8-8 24633]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 08:42 72208 —-a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Documents and Settings\\Thomas\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\WINDOWS\\SYSTEM32\\ZoneLabs\\vsmon.exe"=

R0 SymEFA;Symantec Extended File Attributes;c:\windows\SYSTEM32\DRIVERS\NIS\1008000.029\SymEFA.sys [2/2/2010 11:55 PM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\SYSTEM32\DRIVERS\NIS\1008000.029\BHDrvx86.sys [2/2/2010 11:54 PM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\SYSTEM32\DRIVERS\NIS\1008000.029\cchpx86.sys [2/2/2010 11:54 PM 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100809.001\IDSXpx86.sys [8/12/2010 11:11 PM 331640]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe [2/2/2010 11:54 PM 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/12/2010 2:05 PM 102448]
S2 LBeepKE;LBeepKE;c:\windows\SYSTEM32\DRIVERS\LBeepKE.sys [10/29/2009 5:48 PM 3712]
S2 WRConsumerService;Webroot Client Service;"c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe" –> c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe [?]
S3 cdiskdun;cdiskdun;\??\c:\docume~1\Thomas\LOCALS~1\Temp\cdiskdun.sys –> c:\docume~1\Thomas\LOCALS~1\Temp\cdiskdun.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2010-07-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1577428371-2420907865-1656439345-1007Core.job
- c:\documents and settings\Thomas\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-01-11 01:54]

2010-07-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1577428371-2420907865-1656439345-1007UA.job
- c:\documents and settings\Thomas\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-01-11 01:54]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
uDefault_Search_URL =
mStart Page = hxxp://www.google.com
mSearch Bar =
uCustomizeSearch =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\jg9mleqz.default\
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - component: c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\jg9mleqz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\documents and settings\Thomas\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Thomas\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-16 00:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.8.0.41\diMaster.dll\" /prefetch:1"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(964)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll

- - - - - - - > 'explorer.exe'(876)
c:\program files\Logitech\SetPoint\lgscroll.dll
.
Completion time: 2010-08-16 00:40:45
ComboFix-quarantined-files.txt 2010-08-16 05:40
ComboFix2.txt 2010-08-16 05:18

Pre-Run: 5,664,669,696 bytes free
Post-Run: 5,627,691,008 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

- - End Of File - - B53ED070033AF192C638E969F0F15B44
COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    http://forums.whatthetech.com/index.php?showtopic=113920
    
    Collect::
    c:\program files\Common Files\nycowek.ban
    c:\program files\Common Files\ivybujyk.bat
    c:\program files\Common Files\vimexanyb.dl
    c:\program files\Common Files\tacyliwi._dl
    c:\program files\Common Files\lopoq.db
    c:\program files\Common Files\zokif.sys
    c:\program files\Common Files\nalehuma.lib
    c:\docume~1\Thomas\LOCALS~1\Temp\cdiskdun.sys
    
    Driver:: 
    cdiskdun
    
    DirLook::
    C:\4d5b36bb62f8f8ae7a6f361c383e
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
ComboFix 10-08-15.01 - Thomas 08/16/2010 9:15.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1534.910 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Thomas\Desktop\CFScript.txt
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

file zipped: c:\program files\Common Files\ivybujyk.bat
file zipped: c:\program files\Common Files\lopoq.db
file zipped: c:\program files\Common Files\nalehuma.lib
file zipped: c:\program files\Common Files\nycowek.ban
file zipped: c:\program files\Common Files\tacyliwi._dl
file zipped: c:\program files\Common Files\vimexanyb.dl
file zipped: c:\program files\Common Files\zokif.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Common Files\ivybujyk.bat
c:\program files\Common Files\lopoq.db
c:\program files\Common Files\nalehuma.lib
c:\program files\Common Files\nycowek.ban
c:\program files\Common Files\tacyliwi._dl
c:\program files\Common Files\vimexanyb.dl
c:\program files\Common Files\zokif.sys

.
\\.\PhysicalDrive1 - Bootkit Whistler was found and disinfected
\\.\PhysicalDrive0 - Bootkit Whistler was found and disinfected
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_CDISKDUN
——-\Service_cdiskdun


((((((((((((((((((((((((( Files Created from 2010-07-16 to 2010-08-16 )))))))))))))))))))))))))))))))
.

2010-08-03 18:35 . 2010-08-03 18:35 ——– d—–w- c:\documents and settings\Thomas\Local Settings\Application Data\Symantec
2010-08-02 23:52 . 2010-08-02 23:52 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-07-29 22:53 . 2010-07-30 02:59 ——– d—–w- C:\4d5b36bb62f8f8ae7a6f361c383e
2010-07-29 00:11 . 2010-07-29 00:13 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-16 14:25 . 2010-06-13 14:26 0 —-a-w- c:\windows\system32\drivers\lvuvc.hs
2010-08-16 14:25 . 2010-06-13 14:25 0 —-a-w- c:\windows\system32\drivers\logiflt.iad
2010-08-16 05:04 . 2005-03-15 19:30 5387014 —-a-w- c:\windows\Internet Logs\tvDebug.Zip
2010-08-02 15:18 . 2004-01-03 01:33 65808 -c–a-w- c:\documents and settings\Thomas\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-29 06:57 . 2009-12-01 18:57 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-29 06:28 . 2004-05-18 03:35 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-07-29 03:41 . 2010-04-26 22:42 ——– d—–w- c:\program files\megamek-0.35.13-windows
2010-07-28 21:47 . 2010-02-25 04:10 ——– d—–w- c:\program files\megamek-dev-svn-20091208
2010-07-26 17:17 . 2009-01-31 20:40 ——– d—–w- c:\program files\Steam
2010-07-08 20:29 . 2010-07-08 20:29 503808 —-a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-21d73989-n\msvcp71.dll
2010-07-08 20:29 . 2010-07-08 20:29 499712 —-a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-21d73989-n\jmc.dll
2010-07-08 20:29 . 2010-07-08 20:29 348160 —-a-w- c:\documents and settings\Thomas\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-21d73989-n\msvcr71.dll
2010-07-08 13:34 . 2004-01-18 23:21 4212 —ha-w- c:\windows\system32\zllictbl.dat
2010-07-08 13:33 . 2010-07-08 13:33 7423488 —-a-w- c:\windows\Internet Logs\xDB2C.tmp
2010-07-08 13:32 . 2010-07-08 13:33 7423488 —-a-w- c:\windows\Internet Logs\xDB2B.tmp
2010-06-23 18:51 . 2009-02-02 23:41 1238528 —-a-w- c:\windows\system32\zpeng25.dll
2010-06-23 18:51 . 2004-11-09 02:00 103936 —-a-w- c:\windows\system32\zlcommdb.dll
2010-06-23 18:51 . 2004-11-09 02:00 69120 —-a-w- c:\windows\system32\zlcomm.dll
2010-06-11 21:51 . 2010-06-11 21:51 3055600 —-a-w- c:\documents and settings\Thomas\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
2010-06-11 21:36 . 2010-06-11 21:36 275952 —-a-w- c:\documents and settings\Thomas\Application Data\Mozilla\plugins\npgoogletalk.dll
2007-06-20 01:44 . 2007-06-20 01:43 10007784 -c–a-w- c:\program files\Azureus_2.5.0.4a_Win32.setup.exe
2001-10-06 00:21 . 2004-10-02 20:51 5331244 -c–a-w- c:\program files\icq2000b.exe
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of C:\4d5b36bb62f8f8ae7a6f361c383e —-

2010-07-02 17:39 . 2010-07-02 17:39 34045896 —-a-w- c:\4d5b36bb62f8f8ae7a6f361c383e\mrt.exe
2010-07-02 17:39 . 2010-07-02 17:39 58312 —-a-w- c:\4d5b36bb62f8f8ae7a6f361c383e\mrtstub.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Thomas\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-01-11 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-08-04 180269]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"BCMSMMSG"="c:\windows\BCMSMMSG.exe" [2003-06-02 122880]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 148888]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-26 8523776]
"nwiz"="nwiz.exe" [2007-12-26 1626112]
"NvMediaCenter"="NvMCTray.dll" [2007-12-26 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-02-13 564496]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-06-23 1043968]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-10-29 805392]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Microsoft Works Calendar Reminders.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2000-8-8 24633]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 08:42 72208 —-a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Documents and Settings\\Thomas\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\WINDOWS\\SYSTEM32\\ZoneLabs\\vsmon.exe"=

R0 SymEFA;Symantec Extended File Attributes;c:\windows\SYSTEM32\DRIVERS\NIS\1008000.029\SymEFA.sys [2/2/2010 11:55 PM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\SYSTEM32\DRIVERS\NIS\1008000.029\BHDrvx86.sys [2/2/2010 11:54 PM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\SYSTEM32\DRIVERS\NIS\1008000.029\cchpx86.sys [2/2/2010 11:54 PM 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100809.001\IDSXpx86.sys [8/12/2010 11:11 PM 331640]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe [2/2/2010 11:54 PM 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/12/2010 2:05 PM 102448]
S2 LBeepKE;LBeepKE;c:\windows\SYSTEM32\DRIVERS\LBeepKE.sys [10/29/2009 5:48 PM 3712]
S2 WRConsumerService;Webroot Client Service;"c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe" –> c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe [?]
.
Contents of the 'Scheduled Tasks' folder

2010-07-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1577428371-2420907865-1656439345-1007Core.job
- c:\documents and settings\Thomas\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-01-11 01:54]

2010-07-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1577428371-2420907865-1656439345-1007UA.job
- c:\documents and settings\Thomas\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-01-11 01:54]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
uDefault_Search_URL =
mStart Page = hxxp://www.google.com
mSearch Bar =
uCustomizeSearch =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\jg9mleqz.default\
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - component: c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\jg9mleqz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\documents and settings\Thomas\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Thomas\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-16 09:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.8.0.41\diMaster.dll\" /prefetch:1"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(944)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll

- - - - - - - > 'explorer.exe'(3976)
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\windows\system32\nvsvc32.exe
c:\windows\System32\wdfmgr.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RunDLL32.exe
c:\documents and settings\Thomas\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Completion time: 2010-08-16 09:36:58 - machine was rebooted
ComboFix-quarantined-files.txt 2010-08-16 14:36
ComboFix2.txt 2010-08-16 05:40
ComboFix3.txt 2010-08-16 05:18

Pre-Run: 5,645,115,392 bytes free
Post-Run: 5,528,416,256 bytes free

- - End Of File - - BF5C7B70755D929B1E01DC5BA06AB93D
Please do the following.

Save a copy of the MBR.

Re-run MBRCheck again.
When prompted, enter Y
Then enter 1 to dump the MBR to physical disk
Name the dumped file as Dump.dat

Enter -1 to exit

A log file named "dump.dat" will be located in the same folder as MBRCheck was saved, please zip it up and attach in your next reply.

Please do the following.

Save a copy of the MBR.


How? A web search on the subject just brings up various utility programs that will do it for you, but I'm not supposed to install new programs.
If you look carefully at my last post you will see Re-run MBRCheck again.
You already have that program installed.Follow the other instructions
I see. I mistook "Save a Copy of the MBR" as an instruction, rather than a section heading. My fault. I double clicked on MBRCheck.exe. It didn't prompt me for anything, it simply ran, then told me "press ENTER to exit" and produced a log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI