This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Do I have virus / malware - HijackThis log

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:50:40, on 13/08/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames2.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Avira AntiVir Programador (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Dispositivo Celular da Apple (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Serviço do Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

–
End of file - 3871 bytes
Hi

Please do the following:



Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.



NEXT



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



NEXT


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hello Catbyte! Thank you. Here are the logs. MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows 7 Home Premium Edition Windows Information: (build 7600), 32-bit Base Board Manufacturer: ASUSTeK Computer INC. BIOS Manufacturer: American Megatrends Inc. System Manufacturer: System manufacturer System Product Name: System Product Name Logical Drives Mask: 0x0000003c Kernel Drivers (total 196): 0x82E1D000 \SystemRoot\system32\ntkrnlpa.exe 0x8322D000 \SystemRoot\system32\halmacpi.dll 0x80BAE000 \SystemRoot\system32\kdcom.dll 0x88A11000 \SystemRoot\system32\mcupdate_AuthenticAMD.dll 0x88A1C000 \SystemRoot\system32\PSHED.dll 0x88A2D000 \SystemRoot\system32\BOOTVID.dll 0x88A35000 \SystemRoot\system32\CLFS.SYS 0x88A77000 \SystemRoot\system32\CI.dll 0x88B22000 \SystemRoot\system32\drivers\Wdf01000.sys 0x88B93000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x88C12000 \SystemRoot\System32\Drivers\sphp.sys 0x88D05000 \SystemRoot\System32\Drivers\WMILIB.SYS 0x88D0E000 \SystemRoot\System32\Drivers\SCSIPORT.SYS 0x88D34000 \SystemRoot\system32\DRIVERS\ACPI.sys 0x88D7C000 \SystemRoot\system32\DRIVERS\msisadrv.sys 0x88D84000 \SystemRoot\system32\DRIVERS\vdrvroot.sys 0x88D8F000 \SystemRoot\system32\DRIVERS\pci.sys 0x88DB9000 \SystemRoot\System32\drivers\partmgr.sys 0x88DCA000 \SystemRoot\system32\DRIVERS\volmgr.sys 0x88BA1000 \SystemRoot\System32\drivers\volmgrx.sys 0x88DDA000 \SystemRoot\system32\DRIVERS\pciide.sys 0x88DE1000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS 0x88E23000 \SystemRoot\System32\drivers\mountmgr.sys 0x88E39000 \SystemRoot\system32\DRIVERS\atapi.sys 0x88E42000 \SystemRoot\system32\DRIVERS\ataport.SYS 0x88E65000 \SystemRoot\system32\DRIVERS\amdxata.sys 0x88E6E000 \SystemRoot\system32\drivers\fltmgr.sys 0x88EA2000 \SystemRoot\system32\drivers\fileinfo.sys 0x88EB3000 \SystemRoot\System32\Drivers\Ntfs.sys 0x8902C000 \SystemRoot\System32\Drivers\msrpc.sys 0x89057000 \SystemRoot\System32\Drivers\ksecdd.sys 0x8906A000 \SystemRoot\System32\Drivers\cng.sys 0x890C7000 \SystemRoot\System32\drivers\pcw.sys 0x890D5000 \SystemRoot\System32\Drivers\Fs_Rec.sys 0x890DE000 \SystemRoot\system32\drivers\ndis.sys 0x89195000 \SystemRoot\system32\drivers\NETIO.SYS 0x891D3000 \SystemRoot\System32\Drivers\ksecpkg.sys 0x8920A000 \SystemRoot\System32\drivers\tcpip.sys 0x89353000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x89384000 \SystemRoot\system32\DRIVERS\volsnap.sys 0x893C3000 \SystemRoot\System32\Drivers\spldr.sys 0x893CB000 \SystemRoot\System32\drivers\rdyboost.sys 0x89000000 \SystemRoot\System32\Drivers\mup.sys 0x893F8000 \SystemRoot\System32\drivers\hwpolicy.sys 0x8942C000 \SystemRoot\System32\DRIVERS\fvevol.sys 0x8945E000 \SystemRoot\system32\DRIVERS\disk.sys 0x8946F000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS 0x89494000 \SystemRoot\system32\DRIVERS\AtiPcie.sys 0x894CE000 \SystemRoot\system32\DRIVERS\cdrom.sys 0x894ED000 \SystemRoot\System32\Drivers\Null.SYS 0x894F4000 \SystemRoot\System32\Drivers\Beep.SYS 0x894FB000 \SystemRoot\System32\drivers\vga.sys 0x89507000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x89528000 \SystemRoot\System32\drivers\watchdog.sys 0x89535000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x8953D000 \SystemRoot\system32\drivers\rdpencdd.sys 0x89545000 \SystemRoot\system32\drivers\rdprefmp.sys 0x8954D000 \SystemRoot\System32\Drivers\Msfs.SYS 0x89558000 \SystemRoot\System32\Drivers\Npfs.SYS 0x89566000 \SystemRoot\system32\DRIVERS\tdx.sys 0x8957D000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x89588000 \SystemRoot\system32\drivers\afd.sys 0x8DC3D000 \SystemRoot\System32\DRIVERS\netbt.sys 0x8DC6F000 \SystemRoot\system32\DRIVERS\wfplwf.sys 0x8DC76000 \SystemRoot\system32\DRIVERS\pacer.sys 0x8DC95000 \SystemRoot\system32\DRIVERS\vwififlt.sys 0x8DCA6000 \SystemRoot\system32\DRIVERS\netbios.sys 0x8DCB4000 \SystemRoot\system32\DRIVERS\serial.sys 0x8DCCE000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x8DCE1000 \SystemRoot\system32\DRIVERS\termdd.sys 0x8DCF1000 \SystemRoot\system32\DRIVERS\ssmdrv.sys 0x8DCF7000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x8DD38000 \SystemRoot\system32\drivers\nsiproxy.sys 0x8DD42000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0x8DD4C000 \SystemRoot\System32\drivers\discache.sys 0x8DD58000 \SystemRoot\System32\Drivers\dfsc.sys 0x8DD70000 \SystemRoot\system32\DRIVERS\blbdrive.sys 0x8DD7E000 \SystemRoot\system32\DRIVERS\avipbb.sys 0x8DD9A000 \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys 0x8DD9C000 \SystemRoot\system32\drivers\AsUpIO.sys 0x8DD9E000 \SystemRoot\system32\drivers\AsIO.sys 0x8DD9F000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x8DDC0000 \SystemRoot\system32\DRIVERS\amdppm.sys 0x8DC00000 \SystemRoot\system32\DRIVERS\atikmpag.sys 0x8E800000 \SystemRoot\system32\DRIVERS\atikmdag.sys 0x93025000 \SystemRoot\System32\drivers\dxgkrnl.sys 0x930DC000 \SystemRoot\System32\drivers\dxgmms1.sys 0x93115000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0x93134000 \SystemRoot\system32\DRIVERS\Rt86win7.sys 0x93173000 \SystemRoot\system32\DRIVERS\usbohci.sys 0x9317D000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0x931C8000 \SystemRoot\system32\DRIVERS\usbehci.sys 0x931D7000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys 0x931DD000 \SystemRoot\system32\DRIVERS\parport.sys 0x931F5000 \SystemRoot\system32\DRIVERS\ASACPI.sys 0x93000000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0x93018000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x8EDEB000 \SystemRoot\system32\DRIVERS\serenum.sys 0x93612000 \SystemRoot\System32\Drivers\ab780mj3.SYS 0x9364B000 \SystemRoot\system32\DRIVERS\wmiacpi.sys 0x93654000 \SystemRoot\system32\DRIVERS\CompositeBus.sys 0x93661000 \SystemRoot\system32\DRIVERS\AgileVpn.sys 0x93673000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x9368B000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x93696000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x936B8000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x936D0000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x936E7000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x936FE000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x9370B000 \SystemRoot\system32\DRIVERS\swenum.sys 0x9370D000 \SystemRoot\system32\DRIVERS\ks.sys 0x93741000 \SystemRoot\system32\DRIVERS\umbus.sys 0x9374F000 \SystemRoot\system32\DRIVERS\usbhub.sys 0x93793000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x937A4000 \SystemRoot\system32\drivers\AtiHdmi.sys 0x937C2000 \SystemRoot\system32\drivers\portcls.sys 0x8DDD1000 \SystemRoot\system32\drivers\drmk.sys 0x94802000 \SystemRoot\system32\drivers\HdAudio.sys 0x94F30000 \SystemRoot\System32\win32k.sys 0x94852000 \SystemRoot\System32\drivers\Dxapi.sys 0x9485C000 \SystemRoot\system32\DRIVERS\netr73.sys 0x948EA000 \SystemRoot\system32\DRIVERS\vwifibus.sys 0x948F4000 \SystemRoot\system32\DRIVERS\hidusb.sys 0x948FF000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0x94912000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0x94919000 \SystemRoot\system32\DRIVERS\USBD.SYS 0x9491B000 \SystemRoot\system32\DRIVERS\mouhid.sys 0x94926000 \SystemRoot\System32\Drivers\crashdmp.sys 0x94933000 \SystemRoot\System32\Drivers\dump_dumpata.sys 0x9493E000 \SystemRoot\System32\Drivers\dump_atapi.sys 0x94947000 \SystemRoot\System32\Drivers\dump_dumpfve.sys 0x94958000 \SystemRoot\system32\DRIVERS\monitor.sys 0x95190000 \SystemRoot\System32\TSDDD.dll 0x951C0000 \SystemRoot\System32\cdd.dll 0x94963000 \SystemRoot\system32\drivers\luafv.sys 0x9497E000 \SystemRoot\system32\DRIVERS\avgntflt.sys 0x94992000 \SystemRoot\system32\drivers\WudfPf.sys 0x949AC000 \SystemRoot\system32\DRIVERS\lltdio.sys 0x9380F000 \SystemRoot\system32\DRIVERS\nwifi.sys 0x93855000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0x93865000 \SystemRoot\system32\DRIVERS\rspndr.sys 0x93878000 \SystemRoot\system32\drivers\HTTP.sys 0x938FD000 \SystemRoot\system32\DRIVERS\bowser.sys 0x93916000 \SystemRoot\System32\drivers\mpsdrv.sys 0x93928000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0x9394B000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0x93986000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0x939A1000 \SystemRoot\system32\DRIVERS\parvdm.sys 0x9DE2F000 \SystemRoot\system32\drivers\peauth.sys 0x9DEC6000 \SystemRoot\System32\Drivers\secdrv.SYS 0x9DED0000 \SystemRoot\System32\DRIVERS\srvnet.sys 0x9DEF1000 \SystemRoot\System32\drivers\tcpipreg.sys 0x9DEFE000 \SystemRoot\System32\DRIVERS\srv2.sys 0x9DF4D000 \SystemRoot\System32\DRIVERS\srv.sys 0xA4A09000 \SystemRoot\system32\drivers\spsys.sys 0xA4A73000 \SystemRoot\system32\DRIVERS\asyncmac.sys 0x775D0000 \Windows\System32\ntdll.dll 0x477D0000 \Windows\System32\smss.exe 0x77810000 \Windows\System32\apisetschema.dll 0x00830000 \Windows\System32\autochk.exe 0x10000000 \Program Files\DAEMON Tools Lite\Engine.dll 0x777F0000 \Windows\System32\psapi.dll 0x77470000 \Windows\System32\ole32.dll 0x772D0000 \Windows\System32\setupapi.dll 0x77750000 \Windows\System32\advapi32.dll 0x77740000 \Windows\System32\lpk.dll 0x77720000 \Windows\System32\imm32.dll 0x77290000 \Windows\System32\ws2_32.dll 0x77230000 \Windows\System32\difxapi.dll 0x771B0000 \Windows\System32\comdlg32.dll 0x77070000 \Windows\System32\urlmon.dll 0x77710000 \Windows\System32\nsi.dll 0x77010000 \Windows\System32\shlwapi.dll 0x76F80000 \Windows\System32\oleaut32.dll 0x76EA0000 \Windows\System32\kernel32.dll 0x76E00000 \Windows\System32\usp10.dll 0x76D70000 \Windows\System32\clbcatq.dll 0x76CC0000 \Windows\System32\rpcrt4.dll 0x76BF0000 \Windows\System32\msctf.dll 0x75FA0000 \Windows\System32\shell32.dll 0x75EA0000 \Windows\System32\wininet.dll 0x75DD0000 \Windows\System32\user32.dll 0x75D20000 \Windows\System32\msvcrt.dll 0x75D10000 \Windows\System32\normaliz.dll 0x75CC0000 \Windows\System32\gdi32.dll 0x75CA0000 \Windows\System32\sechost.dll 0x75C70000 \Windows\System32\imagehlp.dll 0x75C20000 \Windows\System32\Wldap32.dll 0x75A20000 \Windows\System32\iertutil.dll 0x75900000 \Windows\System32\crypt32.dll 0x758E0000 \Windows\System32\devobj.dll 0x75890000 \Windows\System32\KernelBase.dll 0x75860000 \Windows\System32\wintrust.dll 0x757D0000 \Windows\System32\comctl32.dll 0x757A0000 \Windows\System32\cfgmgr32.dll 0x75790000 \Windows\System32\msasn1.dll Processes (total 56): 0 System Idle Process 4 System 288 C:\Windows\System32\smss.exe 380 csrss.exe 460 C:\Windows\System32\wininit.exe 468 csrss.exe 508 C:\Windows\System32\services.exe 532 C:\Windows\System32\lsass.exe 540 C:\Windows\System32\lsm.exe 604 C:\Windows\System32\winlogon.exe 700 C:\Windows\System32\svchost.exe 816 C:\Windows\System32\svchost.exe 880 C:\Windows\System32\atiesrxx.exe 940 C:\Windows\System32\svchost.exe 976 C:\Windows\System32\svchost.exe 1024 C:\Windows\System32\svchost.exe 1120 C:\Windows\System32\audiodg.exe 1164 C:\Windows\System32\svchost.exe 1216 C:\Windows\System32\atieclxx.exe 1368 C:\Windows\System32\svchost.exe 1524 C:\Windows\System32\spoolsv.exe 1552 C:\Program Files\Avira\AntiVir Desktop\sched.exe 1572 C:\Windows\System32\svchost.exe 1676 C:\Program Files\Avira\AntiVir Desktop\avguard.exe 1700 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 1720 C:\Program Files\Bonjour\mDNSResponder.exe 1768 C:\Windows\System32\svchost.exe 1816 C:\Windows\System32\svchost.exe 2196 C:\Windows\System32\svchost.exe 2372 C:\Windows\System32\taskhost.exe 2448 C:\Windows\System32\taskeng.exe 2484 C:\Windows\System32\dwm.exe 2544 C:\Windows\explorer.exe 2576 C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe 2680 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe 2692 C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe 2736 C:\Program Files\iTunes\iTunesHelper.exe 2760 C:\Program Files\Common Files\Java\Java Update\jusched.exe 2808 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe 2968 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe 3116 C:\Program Files\iPod\bin\iPodService.exe 3272 C:\Windows\System32\SearchIndexer.exe 3376 C:\Program Files\Windows Media Player\wmpnetwk.exe 3516 C:\Windows\System32\SearchProtocolHost.exe 3704 C:\Windows\System32\svchost.exe 3796 WmiPrvSE.exe 4040 C:\Program Files\Mozilla Firefox\firefox.exe 3788 C:\Program Files\Mozilla Firefox\plugin-container.exe 2068 C:\Windows\System32\sppsvc.exe 2072 C:\Windows\System32\svchost.exe 2168 WmiPrvSE.exe 2532 C:\Windows\servicing\TrustedInstaller.exe 3596 C:\Windows\System32\SearchFilterHost.exe 2884 C:\Users\Sala\Desktop\MBRCheck.exe 2964 C:\Windows\System32\conhost.exe 2436 C:\Windows\System32\dllhost.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`06500000 (NTFS) \\.\D: –> \\.\PhysicalDrive1 at offset 0x00000000`00100000 (NTFS) PhysicalDrive0 Model Number: SAMSUNGHD080HJ, Rev: ZH100-41 PhysicalDrive1 Model Number: WDCWD5000AADS-00S9B0, Rev: 01.00A01 Size Device Name MBR Status ——————————————– 74 GB \\.\PhysicalDrive0 Windows 7 MBR code detected SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79 465 GB \\.\PhysicalDrive1 Windows 7 MBR code detected SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79 Done! DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 11:45:20,18 on 15/08/2010 Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_21 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.55.1046.18.2047.1185 [GMT -3:00] ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\AUDIODG.EXE C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\atieclxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\taskhost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Windows\system32\sppsvc.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\NOTEPAD.EXE C:\Windows\system32\svchost.exe -k SDRSVC C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Sala\Desktop\dds.com C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = about:blank uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL ================= FIREFOX =================== FF - ProfilePath - c:\users\sala\appdata\roaming\mozilla\firefox\profiles\t3wyycgc.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q= FF - component: c:\program files\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [2010-3-5 11448] R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-3-5 11608] R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-7-6 176128] R2 AntiVirSchedulerService;Avira AntiVir Programador;c:\program files\avira\antivir desktop\sched.exe [2010-3-5 108289] R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-3-5 185089] R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-3-5 56816] R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2010-7-6 5882368] R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2010-7-6 210944] R3 netr73;RT73 USB Wireless LAN Card Driver for Vista;c:\windows\system32\drivers\netr73.sys [2009-6-10 545792] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-12-19 249888] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888] S3 WatAdminSvc;Serviço de Tecnologias de Ativação do Windows;c:\windows\system32\wat\WatAdminSvc.exe [2010-3-6 1343400] =============== Created Last 30 ================ 2010-08-15 00:52:00 0 d—–w- c:\programdata\EA Core 2010-08-15 00:51:47 0 d—–w- c:\programdata\Electronic Arts 2010-08-15 00:51:30 100720 —ha-w- c:\windows\system32\mlfcache.dat 2010-08-11 20:06:18 1286016 —-a-w- c:\windows\system32\drivers\tcpip.sys 2010-08-11 20:06:05 82944 —-a-w- c:\windows\system32\iccvid.dll 2010-08-11 20:06:05 197632 —-a-w- c:\windows\system32\ir32_32.dll 2010-08-11 20:06:03 37376 —-a-w- c:\windows\system32\rtutils.dll 2010-08-11 20:06:03 1233920 —-a-w- c:\windows\system32\msxml3.dll 2010-08-11 20:06:01 3955080 —-a-w- c:\windows\system32\ntkrnlpa.exe 2010-08-11 20:06:01 3899784 —-a-w- c:\windows\system32\ntoskrnl.exe 2010-08-11 20:06:01 310784 —-a-w- c:\windows\system32\drivers\srv.sys 2010-08-11 20:06:01 307200 —-a-w- c:\windows\system32\drivers\srv2.sys 2010-08-11 20:06:01 113664 —-a-w- c:\windows\system32\drivers\srvnet.sys 2010-08-11 20:03:25 0 d—–w- c:\program files\Trend Micro 2010-08-02 15:47:23 0 d—–w- c:\program files\CCleaner 2010-08-02 13:18:10 20480 —-a-w- c:\users\sala\count.exe 2010-07-31 02:15:15 0 d—–w- c:\programdata\ATI 2010-07-27 10:01:01 0 d—–w- c:\programdata\Blizzard Entertainment 2010-07-27 10:01:01 0 d—–w- c:\program files\common files\Blizzard Entertainment ==================== Find3M ==================== 2010-07-17 08:00:04 423656 —-a-w- c:\windows\system32\deployJava1.dll 2010-07-16 10:11:09 654272 —-a-w- c:\windows\system32\prfh0416.dat 2010-07-16 10:11:09 124724 —-a-w- c:\windows\system32\prfc0416.dat 2010-07-07 02:29:16 5882368 —-a-w- c:\windows\system32\drivers\atikmdag.sys 2010-07-07 01:55:08 15461888 —-a-w- c:\windows\system32\atioglxx.dll 2010-07-07 01:54:16 143360 —-a-w- c:\windows\system32\atiapfxx.exe 2010-07-07 01:54:08 513024 —-a-w- c:\windows\system32\aticfx32.dll 2010-07-07 01:51:30 446464 —-a-w- c:\windows\system32\ATIDEMGX.dll 2010-07-07 01:51:10 380928 —-a-w- c:\windows\system32\atieclxx.exe 2010-07-07 01:50:42 176128 —-a-w- c:\windows\system32\atiesrxx.exe 2010-07-07 01:49:42 159744 —-a-w- c:\windows\system32\atitmmxx.dll 2010-07-07 01:49:28 356352 —-a-w- c:\windows\system32\atipdlxx.dll 2010-07-07 01:49:18 278528 —-a-w- c:\windows\system32\Oemdspif.dll 2010-07-07 01:49:12 11776 —-a-w- c:\windows\system32\atimuixx.dll 2010-07-07 01:49:06 43520 —-a-w- c:\windows\system32\ati2edxx.dll 2010-07-07 01:46:26 3826688 —-a-w- c:\windows\system32\atidxx32.dll 2010-07-07 01:29:24 46080 —-a-w- c:\windows\system32\aticalrt.dll 2010-07-07 01:29:14 44032 —-a-w- c:\windows\system32\aticalcl.dll 2010-07-07 01:28:20 3975680 —-a-w- c:\windows\system32\atiumdag.dll 2010-07-07 01:27:58 4323840 —-a-w- c:\windows\system32\aticaldd.dll 2010-07-07 01:24:32 50176 —-a-w- c:\windows\system32\coinst.dll 2010-07-07 01:23:14 3058688 —-a-w- c:\windows\system32\atiumdva.dll 2010-07-07 01:16:00 237568 —-a-w- c:\windows\system32\atiadlxx.dll 2010-07-07 01:15:50 12800 —-a-w- c:\windows\system32\atiglpxx.dll 2010-07-07 01:15:46 16896 —-a-w- c:\windows\system32\atigktxx.dll 2010-07-07 01:15:24 210944 —-a-w- c:\windows\system32\drivers\atikmpag.sys 2010-07-07 01:14:58 30208 —-a-w- c:\windows\system32\atiuxpag.dll 2010-07-07 01:14:44 22528 —-a-w- c:\windows\system32\atiu9pag.dll 2010-07-07 01:14:16 53248 —-a-w- c:\windows\system32\drivers\ati2erec.dll 2010-07-07 01:11:06 52736 —-a-w- c:\windows\system32\atimpc32.dll 2010-07-07 01:11:06 52736 —-a-w- c:\windows\system32\amdpcom32.dll 2010-06-30 06:25:31 978432 —-a-w- c:\windows\system32\wininet.dll 2010-06-19 04:07:18 2326016 —-a-w- c:\windows\system32\win32k.sys 2010-06-16 05:48:35 224256 —-a-w- c:\windows\system32\schannel.dll 2010-06-15 22:28:58 2857 —-a-w- c:\windows\system32\atipblag.dat 2010-05-27 07:24:13 34304 —-a-w- c:\windows\system32\atmlib.dll 2010-05-27 03:49:37 293888 —-a-w- c:\windows\system32\atmfd.dll 2010-05-21 17:14:28 221568 ——w- c:\windows\system32\MpSigStub.exe 2009-07-14 08:30:56 38536 —-a-w- c:\windows\inf\perflib\0416\perfd.dat 2009-07-14 08:30:56 38536 —-a-w- c:\windows\inf\perflib\0416\perfc.dat 2009-07-14 08:30:56 323154 —-a-w- c:\windows\inf\perflib\0416\perfi.dat 2009-07-14 08:30:56 323154 —-a-w- c:\windows\inf\perflib\0416\perfh.dat 2009-07-14 04:41:57 174 –sha-w- c:\program files\desktop.ini 2009-07-14 00:34:40 291294 —-a-w- c:\windows\inf\perflib\0000\perfi.dat 2009-07-14 00:34:40 291294 —-a-w- c:\windows\inf\perflib\0000\perfh.dat 2009-07-14 00:34:38 31548 —-a-w- c:\windows\inf\perflib\0000\perfd.dat 2009-07-14 00:34:38 31548 —-a-w- c:\windows\inf\perflib\0000\perfc.dat 2009-06-10 21:26:35 9633792 –sha-r- c:\windows\fonts\StaticCache.dat 2009-07-14 01:14:45 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe ============= FINISH: 11:45:46,32 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-03-17.01) Microsoft Windows 7 Home Premium Boot Device: \Device\HarddiskVolume1 Install Date: 05/03/2010 16:02:55 System Uptime: 15/08/2010 11:38:55 (0 hours ago) Motherboard: ASUSTeK Computer INC. | | M4A785-M Processor: AMD Athlon™ II X4 620 Processor | AM2 | 2600/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 74 GiB total, 53,712 GiB free. D: is FIXED (NTFS) - 466 GiB total, 375,506 GiB free. E: is CDROM () F: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP125: 06/08/2010 09:55:17 - Windows Update RP126: 09/08/2010 13:05:44 - Windows Update RP127: 12/08/2010 00:41:57 - Windows Update RP128: 13/08/2010 10:56:22 - Windows Update RP129: 13/08/2010 20:47:00 - Installed HiJackThis ==== Installed Programs ====================== Acrobat.com Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.3.3 AMD Drag and Drop Transcoding Apple Application Support Apple Mobile Device Support Apple Software Update ASUSUpdate ATI Catalyst Install Manager µTorrent Avira AntiVir Personal - Free Antivirus Bonjour Catalyst Control Center - Branding Catalyst Control Center Graphics Previews Common Catalyst Control Center Graphics Previews Vista Catalyst Control Center InstallProxy ccc-core-static ccc-utility CCC Help English CCleaner Company of Heroes Cool & Quiet Deus Ex: Game of the Year Edition EA Download Manager UI EPU-4 Engine EVEREST Ultimate Edition v5.30 Football Manager 2009 GameSpy Arcade Gerenciador de Downloads da EA HiJackThis IRPF2010 - Declaração de Ajuste Anual e Final de Espólio iTunes Java Auto Updater Java™ 6 Update 21 League of Legends Mass Effect Mass Effect 2 Microsoft Application Error Reporting Microsoft Choice Guard Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Mozilla Firefox (3.6.8) MSVCRT MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML4 Parser NVIDIA PhysX OpenOffice.org 3.2 Pando Media Booster Portal QuickTime Realtek Ethernet Controller Driver For Windows Vista and Later Realtek High Definition Audio Driver Receitanet Java 2010.02a SimCity 4 Deluxe Skype Toolbars Skype™ 4.2 Starcraft StarCraft II Steam System Requirements Lab Warcraft III Warcraft III: All Products Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Messenger Windows Live Photo Gallery Windows Live Sign-in Assistant Windows Live Sync Windows Live Upload Tool Windows Media Player Firefox Plugin WinRAR archiver ==== End Of File ===========================
If you are having trouble with the GMER scan, please try running it in safe mode with just "sections" and the "c:\" drive checked (to enter safe mode > reboot > tap F8 repeatedly upon boot up until an advanced menu appears > arrow up to safe mode)
Forgot!



GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-15 11:52:27
Windows 6.1.7600
Running: 3d8ux9sh.exe; Driver: C:\Users\Sala\AppData\Local\Temp\kxldypow.sys


—- System - GMER 1.0.15 —-

SSDT 805E8C54 ZwCreateThread
SSDT 805E8C40 ZwOpenProcess
SSDT 805E8C45 ZwOpenThread
SSDT 805E8C4F ZwTerminateProcess

INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83247AF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83247104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 832473F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 832302D8
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8322F898
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 832471DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83247958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 832476F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83247F2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 832481A8

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82E60599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82E84F52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, …] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!RtlSidHashLookup + 34C 82E8C85C 4 Bytes [54, 8C, 5E, 80] {PUSH ESP; MOV WORD [ESI-0x80], DS}
.text ntkrnlpa.exe!RtlSidHashLookup + 4E8 82E8C9F8 4 Bytes [40, 8C, 5E, 80] {INC EAX; MOV WORD [ESI-0x80], DS}
.text ntkrnlpa.exe!RtlSidHashLookup + 508 82E8CA18 4 Bytes [45, 8C, 5E, 80] {INC EBP; MOV WORD [ESI-0x80], DS}
.text ntkrnlpa.exe!RtlSidHashLookup + 7B8 82E8CCC8 4 Bytes [4F, 8C, 5E, 80] {DEC EDI; MOV WORD [ESI-0x80], DS}
? System32\Drivers\sphp.sys O sistema não pode encontrar o caminho especificado. !
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8E801000, 0x31BA76, 0xE8000020]
.text USBPORT.SYS!DllUnload 931A1CA0 5 Bytes JMP 85E384E0
.text ab780mj3.SYS 93613000 12 Bytes [44, 28, 23, 83, EE, 26, 23, …] {INC ESP; SUB [EBX], AH; SUB ESI, 0x26; AND EAX, [EBX-0x7cdcf860]}
.text ab780mj3.SYS 9361300D 9 Bytes [07, 23, 83, 48, 2B, 23, 83, …] {POP ES; AND EAX, [EBX-0x7cdcd4b8]; ADD [EAX], AL}
.text ab780mj3.SYS 93613017 170 Bytes [00, DE, 07, D1, 88, E6, 05, …]
.text ab780mj3.SYS 936130C3 8 Bytes [00, 00, 00, 00, 00, 00, 00, …] {ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL}
.text ab780mj3.SYS 936130CE 4 Bytes [00, 00, 00, 00] {ADD [EAX], AL; ADD [EAX], AL}
.text …
.text peauth.sys 9DE34C9D 28 Bytes [D5, 92, 15, 34, 63, C4, 2D, …]
.text peauth.sys 9DE34CC1 28 Bytes [D5, 92, 15, 34, 63, C4, 2D, …]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Mozilla Firefox\plugin-container.exe[3788] USER32.dll!TrackPopupMenu 75E04B3B 5 Bytes JMP 64B1721D C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[4040] ntdll.dll!LdrLoadDll 7762F625 5 Bytes JMP 009813F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 84C751F8
Device \Driver\volmgr \Device\VolMgrControl 84C711F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{EEEF5E34-A6E7-4D2A-81DA-335042205C97} 85DB01F8
Device \Driver\usbohci \Device\USBPDO-0 85E531F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{6C7A2390-724A-4FBA-B803-04C03070529B} 85DB01F8
Device \Driver\usbohci \Device\USBPDO-1 85E531F8
Device \Driver\usbehci \Device\USBPDO-2 85E541F8
Device \Driver\usbohci \Device\USBPDO-3 85E531F8
Device \Driver\usbohci \Device\USBPDO-4 85E531F8
Device \Driver\PCI_PNP1424 \Device\00000055 sphp.sys
Device \Driver\usbehci \Device\USBPDO-5 85E541F8
Device \Driver\usbohci \Device\USBPDO-6 85E531F8
Device \Driver\volmgr \Device\HarddiskVolume1 84C711F8

AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)

Device \Driver\volmgr \Device\HarddiskVolume2 84C711F8

AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)

Device \Driver\cdrom \Device\CdRom0 85D4F1F8
Device \Driver\cdrom \Device\CdRom1 85D4F1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 84C731F8
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-2 84C731F8
Device \Driver\atapi \Device\Ide\IdePort0 84C731F8
Device \Driver\atapi \Device\Ide\IdePort1 84C731F8
Device \Driver\atapi \Device\Ide\IdePort2 84C731F8
Device \Driver\atapi \Device\Ide\IdePort3 84C731F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-4 84C731F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 85DB01F8
Device \Driver\ACPI_HAL \Device\0000004a halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
Device \Driver\usbohci \Device\USBFDO-0 85E531F8
Device \Driver\usbohci \Device\USBFDO-1 85E531F8
Device \Driver\usbehci \Device\USBFDO-2 85E541F8
Device \Driver\usbohci \Device\USBFDO-3 85E531F8
Device \Driver\usbohci \Device\USBFDO-4 85E531F8
Device \Driver\usbehci \Device\USBFDO-5 85E541F8
Device \Driver\usbohci \Device\USBFDO-6 85E531F8
Device \Driver\sptd \Device\2542937430 sphp.sys
Device \Driver\ab780mj3 \Device\Scsi\ab780mj31Port4Path0Target0Lun0 85ED21F8
Device \Driver\ab780mj3 \Device\Scsi\ab780mj31 85ED21F8

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x92 0x0A 0x70 0xD3 …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x90 0xD7 0x0C 0xEB …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x8C 0x42 0x73 0x08 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x92 0x0A 0x70 0xD3 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x90 0xD7 0x0C 0xEB …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x8C 0x42 0x73 0x08 …

—- EOF - GMER 1.0.15 —-
I'm not seeing any obvious signs of malware in any of those logs, what symptoms are you experiencing that make you believe you are infected?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI