This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

computer freezes using firefox, "SVCHOST.EXE and WUAUCLT.EXE"

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Topics can be closed if you don't reply within 3 days.

Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.



Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • It doesn't take long to run, once it is finished move onto the next step

Next:

Please read carefully and follow these steps.
please post the contents of that log TDSSKiller and GooredFix log.
GooredFix by jpshortstuff (03.07.10.1) Log created at 09:50 on 29/08/2010 (Administrator) Firefox version 3.6.8 (en-US) ========== GooredScan ========== ========== GooredLog ========== C:\Program Files\Mozilla Firefox\extensions\ {972ce4c6-7e08-4474-a285-3208198ce6fd} [02:32 16/07/2005] {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} [03:06 26/07/2009] C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\crovfnbd.default\extensions\ {73a6fe31-595d-460b-a920-fcc0f8843232} [11:14 25/11/2005] C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\uhgh87ld.Default User\extensions\ temp [16:00 24/10/2007] {73a6fe31-595d-460b-a920-fcc0f8843232} [01:43 21/08/2010] {e4a8a97b-f2ed-450b-b12d-ee082ba24781} [03:12 17/04/2010] {5F4EC95A-FFA8-11DE-898C-667D55D89593} [15:12 12/02/2010] [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "[removed]"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [03:06 26/07/2009] -=E.O.F=- NEXT scan result is no threat found , log below attached 2010/08/29 09:52:52.0511 TDSS rootkit removing tool 2.4.1.3 Aug 27 2010 08:53:42 2010/08/29 09:52:52.0511 ================================================================================ 2010/08/29 09:52:52.0511 SystemInfo: 2010/08/29 09:52:52.0511 2010/08/29 09:52:52.0511 OS Version: 5.1.2600 ServicePack: 2.0 2010/08/29 09:52:52.0511 Product type: Workstation 2010/08/29 09:52:52.0511 ComputerName: (DEL my me) 2010/08/29 09:52:52.0511 UserName: Administrator 2010/08/29 09:52:52.0511 Windows directory: C:\WINDOWS 2010/08/29 09:52:52.0511 System windows directory: C:\WINDOWS 2010/08/29 09:52:52.0511 Processor architecture: Intel x86 2010/08/29 09:52:52.0511 Number of processors: 1 2010/08/29 09:52:52.0511 Page size: 0x1000 2010/08/29 09:52:52.0511 Boot type: Normal boot 2010/08/29 09:52:52.0511 ================================================================================ 2010/08/29 09:52:53.0603 Initialize success 2010/08/29 09:53:08.0625 ================================================================================ 2010/08/29 09:53:08.0625 Scan started 2010/08/29 09:53:08.0625 Mode: Manual; 2010/08/29 09:53:08.0625 ================================================================================ 2010/08/29 09:53:09.0356 61883 (86d7b1e70661d754685b9ac6d749aae5) C:\WINDOWS\system32\DRIVERS\61883.sys 2010/08/29 09:53:10.0017 ac97intc (0f2d66d5f08ebe2f77bb904288dcf6f0) C:\WINDOWS\system32\drivers\ac97intc.sys 2010/08/29 09:53:10.0247 ACPI (2e76d0847098458b6f6776323d36a6fa) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2010/08/29 09:53:10.0417 ACPIEC (619410be0b33801f0fa0ad994b153cb4) C:\WINDOWS\system32\drivers\ACPIEC.sys 2010/08/29 09:53:10.0948 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys 2010/08/29 09:53:11.0118 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys 2010/08/29 09:53:11.0389 agp440 (2c428fa0c3e3a01ed93c9b2a27d8d4bb) C:\WINDOWS\system32\DRIVERS\agp440.sys 2010/08/29 09:53:13.0121 Arp1394 (f0d692b0bffb46e30eb3cea168bbc49f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 2010/08/29 09:53:13.0982 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2010/08/29 09:53:14.0183 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys 2010/08/29 09:53:14.0583 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2010/08/29 09:53:14.0784 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2010/08/29 09:53:14.0964 Avc (87c223adb8f7596b31caae3c67b16ddd) C:\WINDOWS\system32\DRIVERS\avc.sys 2010/08/29 09:53:15.0104 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2010/08/29 09:53:15.0314 Bridge (e4e6a0922e3d983728c9ad4e8d466954) C:\WINDOWS\system32\DRIVERS\bridge.sys 2010/08/29 09:53:15.0364 BridgeMP (e4e6a0922e3d983728c9ad4e8d466954) C:\WINDOWS\system32\DRIVERS\bridge.sys 2010/08/29 09:53:15.0515 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2010/08/29 09:53:15.0915 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2010/08/29 09:53:16.0055 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys 2010/08/29 09:53:16.0186 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2010/08/29 09:53:16.0626 CmBatt (4266be808f85826aedf3c64c1e240203) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 2010/08/29 09:53:17.0027 Compbatt (df1b1a24bf52d0ebc01ed4ece8979f50) C:\WINDOWS\system32\DRIVERS\compbatt.sys 2010/08/29 09:53:17.0588 d347bus (5776322f93cdb91086111f5ffbfda2a0) C:\WINDOWS\system32\DRIVERS\d347bus.sys 2010/08/29 09:53:17.0848 d347prt (b49f79ace459763f4e0380071be9cb45) C:\WINDOWS\system32\Drivers\d347prt.sys 2010/08/29 09:53:18.0469 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys 2010/08/29 09:53:18.0699 dmboot (48fa74a11fc3da495b9b546d640f8950) C:\WINDOWS\system32\drivers\dmboot.sys 2010/08/29 09:53:18.0929 dmio (b99078c1719a26bfe2ca9aa2a50e0b10) C:\WINDOWS\system32\drivers\dmio.sys 2010/08/29 09:53:18.0970 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2010/08/29 09:53:19.0150 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys 2010/08/29 09:53:19.0530 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys 2010/08/29 09:53:19.0721 E100B (00f73b6b7b8e1783516360de6f4360e4) C:\WINDOWS\system32\DRIVERS\e100b325.sys 2010/08/29 09:53:19.0881 ENUM1394 (80d1b490b60e74e002dc116ec5d41748) C:\WINDOWS\system32\DRIVERS\enum1394.sys 2010/08/29 09:53:20.0031 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys 2010/08/29 09:53:20.0221 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\drivers\Fdc.sys 2010/08/29 09:53:20.0321 Fips (baac25464472a8112e7703e7eb38f603) C:\WINDOWS\system32\drivers\Fips.sys 2010/08/29 09:53:20.0432 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\drivers\Flpydisk.sys 2010/08/29 09:53:20.0642 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS\system32\drivers\fltmgr.sys 2010/08/29 09:53:20.0872 FsVga (10a80a866a41490a43fdcccfeef0dce4) C:\WINDOWS\system32\DRIVERS\fsvga.sys 2010/08/29 09:53:20.0952 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2010/08/29 09:53:21.0022 Ftdisk (de92525813b461317e95221a2a0d49ca) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2010/08/29 09:53:21.0433 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2010/08/29 09:53:21.0744 hardlock (f3e34776d8b8ab665d051a8674fdf4cc) C:\WINDOWS\system32\drivers\hardlock.sys 2010/08/29 09:53:22.0064 Haspnt (2dd25f060dc9f79b5cdf33d90ed93669) C:\WINDOWS\system32\drivers\Haspnt.sys 2010/08/29 09:53:22.0274 hidusb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2010/08/29 09:53:22.0975 HTTP (cb77bb47e67e84deb17ba29632501730) C:\WINDOWS\system32\Drivers\HTTP.sys 2010/08/29 09:53:23.0626 i8042prt (5f07dcfd005e94d54d99d881cef962cc) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2010/08/29 09:53:23.0756 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys 2010/08/29 09:53:24.0197 IntelIde (abbd1814791a011613ca1395e1344b7e) C:\WINDOWS\system32\DRIVERS\intelide.sys 2010/08/29 09:53:24.0367 intelppm (00273ace71b53cf8c006ed6574feeeb4) C:\WINDOWS\system32\DRIVERS\intelppm.sys 2010/08/29 09:53:24.0588 ip6fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\drivers\ip6fw.sys 2010/08/29 09:53:24.0758 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2010/08/29 09:53:24.0888 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2010/08/29 09:53:25.0038 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2010/08/29 09:53:25.0249 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2010/08/29 09:53:25.0459 irda (86c204836feec22510d434982d4221b8) C:\WINDOWS\system32\DRIVERS\irda.sys 2010/08/29 09:53:25.0669 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys 2010/08/29 09:53:25.0819 isapnp (691914b157afb302d6831484d8e0d9d3) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2010/08/29 09:53:26.0090 k750bus (fe8300320281d658a7854d5cfc02a63f) C:\WINDOWS\system32\DRIVERS\k750bus.sys 2010/08/29 09:53:26.0390 k750mdfl (f44521f63c0c00364fa3d59db980de6a) C:\WINDOWS\system32\DRIVERS\k750mdfl.sys 2010/08/29 09:53:26.0661 k750mdm (e93323c3ed5e8923a177740a973c27b2) C:\WINDOWS\system32\DRIVERS\k750mdm.sys 2010/08/29 09:53:26.0901 k750mgmt (9d5f5a70ca0b7c428efcd73db50e6ac7) C:\WINDOWS\system32\DRIVERS\k750mgmt.sys 2010/08/29 09:53:27.0221 k750obex (81ca2d57b2c14f76f4ba80846784bb3d) C:\WINDOWS\system32\DRIVERS\k750obex.sys 2010/08/29 09:53:27.0392 Kbdclass (8ccdd51821bbacd3dba1afa5e7c4d756) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2010/08/29 09:53:27.0592 kbdhid (dae14daa133386f4258a40d8a4db58b7) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 2010/08/29 09:53:27.0872 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys 2010/08/29 09:53:28.0203 KSecDD (674d3e5a593475915dc6643317192403) C:\WINDOWS\system32\drivers\KSecDD.sys 2010/08/29 09:53:28.0683 mcdbus (8fd868e32459ece2a1bb0169f513d31e) C:\WINDOWS\system32\DRIVERS\mcdbus.sys 2010/08/29 09:53:28.0914 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2010/08/29 09:53:29.0004 Modem (746a1a3d73a648c57398c9cb8af315ed) C:\WINDOWS\system32\drivers\Modem.sys 2010/08/29 09:53:29.0064 Mouclass (c145c60f25efe006b9a22a046ce5883f) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2010/08/29 09:53:29.0284 mouhid (44cacbcea57a1a1dc44f1454d033178c) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2010/08/29 09:53:29.0405 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys 2010/08/29 09:53:29.0815 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2010/08/29 09:53:30.0126 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2010/08/29 09:53:30.0306 MSDV (6dd721dfd2648f3f6d5808b5ba6cb095) C:\WINDOWS\system32\DRIVERS\msdv.sys 2010/08/29 09:53:30.0446 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys 2010/08/29 09:53:30.0546 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2010/08/29 09:53:30.0706 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2010/08/29 09:53:30.0777 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys 2010/08/29 09:53:30.0987 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2010/08/29 09:53:31.0097 MSTEE (bf13612142995096ab084f2db7f40f77) C:\WINDOWS\system32\drivers\MSTEE.sys 2010/08/29 09:53:31.0247 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys 2010/08/29 09:53:31.0337 NABTSFEC (5c8dc6429c43dc6177c1fa5b76290d1a) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 2010/08/29 09:53:31.0838 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys 2010/08/29 09:53:31.0948 NdisIP (520ce427a8b298f54112857bcf6bde15) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 2010/08/29 09:53:32.0108 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2010/08/29 09:53:32.0249 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2010/08/29 09:53:32.0439 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2010/08/29 09:53:32.0589 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys 2010/08/29 09:53:32.0709 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys 2010/08/29 09:53:32.0880 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys 2010/08/29 09:53:33.0060 NIC1394 (5c5c53db4fef16cf87b9911c7e8c6fbc) C:\WINDOWS\system32\DRIVERS\nic1394.sys 2010/08/29 09:53:33.0260 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys 2010/08/29 09:53:33.0550 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\WINDOWS\system32\drivers\Ntfs.sys 2010/08/29 09:53:33.0761 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2010/08/29 09:53:33.0961 nv (25663bead605630a691715348c0d4b06) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 2010/08/29 09:53:34.0191 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2010/08/29 09:53:34.0322 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2010/08/29 09:53:34.0452 ohci1394 (0951db8e5823ea366b0e408d71e1ba2a) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 2010/08/29 09:53:34.0612 Parport (25e7306d56ddd7177f8197a008961757) C:\WINDOWS\system32\drivers\Parport.sys 2010/08/29 09:53:34.0722 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys 2010/08/29 09:53:34.0902 ParVdm (3d531ced44f72ef076ff795c001aa9f8) C:\WINDOWS\system32\drivers\ParVdm.sys 2010/08/29 09:53:35.0193 PCI (ada684c2be7064411d092efdc090faa3) C:\WINDOWS\system32\DRIVERS\pci.sys 2010/08/29 09:53:35.0824 pciSm (a8f5589799f403672a5734d2ebdcc619) C:\WINDOWS\system32\DRIVERS\tossmpci.sys 2010/08/29 09:53:36.0084 Pcmcia (59f94f258b7935b4d921ba5b9b01d0aa) C:\WINDOWS\system32\DRIVERS\pcmcia.sys 2010/08/29 09:53:37.0927 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2010/08/29 09:53:38.0257 Processor (ddf210181ee4b9bd8b327d71bd304d8e) C:\WINDOWS\system32\DRIVERS\processr.sys 2010/08/29 09:53:38.0558 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys 2010/08/29 09:53:38.0628 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2010/08/29 09:53:40.0190 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2010/08/29 09:53:40.0410 Rasirda (0207d26ddf796a193ccd9f83047bb5fc) C:\WINDOWS\system32\DRIVERS\rasirda.sys 2010/08/29 09:53:40.0681 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2010/08/29 09:53:41.0041 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2010/08/29 09:53:41.0141 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2010/08/29 09:53:41.0282 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2010/08/29 09:53:41.0362 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2010/08/29 09:53:41.0742 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 2010/08/29 09:53:42.0013 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys 2010/08/29 09:53:42.0363 redbook (8bf05f5f9408a097f86113829def844b) C:\WINDOWS\system32\DRIVERS\redbook.sys 2010/08/29 09:53:42.0684 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 2010/08/29 09:53:42.0994 SAVRT (3d2eb85b0a130cba0cd08bcdd2b2e485) C:\Program Files\Norton AntiVirus\SAVRT.SYS 2010/08/29 09:53:43.0284 SAVRTPEL (a5d09f85b8717bbf67520b1cc71d641f) C:\Program Files\Norton AntiVirus\SAVRTPEL.SYS 2010/08/29 09:53:43.0505 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2010/08/29 09:53:43.0815 Serial (58670ee2faf94fd65d19bb3e7927b485) C:\WINDOWS\system32\drivers\Serial.sys 2010/08/29 09:53:44.0106 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\DRIVERS\sfloppy.sys 2010/08/29 09:53:44.0626 SLIP (5caeed86821fa2c6139e32e9e05ccdc9) C:\WINDOWS\system32\DRIVERS\SLIP.sys 2010/08/29 09:53:44.0787 SMCIRDA (9951b523fe6820f29ef010680cb692d2) C:\WINDOWS\system32\DRIVERS\smcirda.sys 2010/08/29 09:53:45.0087 SOFTXG (183d5938362668021c0195eed4c91820) C:\WINDOWS\system32\drivers\sxgxgwdm.sys 2010/08/29 09:53:45.0428 SONYPVU1 (a1eceeaa5c5e74b2499eb51d38185b84) C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS 2010/08/29 09:53:45.0878 SPBBCDrv (924e82d6dec26f82036e69b8d3f04216) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys 2010/08/29 09:53:46.0199 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys 2010/08/29 09:53:46.0479 sr (272f4bba833ef3553734eb02d6164f2b) C:\WINDOWS\system32\DRIVERS\sr.sys 2010/08/29 09:53:46.0850 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys 2010/08/29 09:53:47.0160 streamip (284c57df5dc7abca656bc2b96a667afb) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 2010/08/29 09:53:47.0471 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys 2010/08/29 09:53:47.0671 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys 2010/08/29 09:53:48.0482 SYMDNS (1f0a3f93fecba6e873e75ac34538708b) C:\WINDOWS\System32\Drivers\SYMDNS.SYS 2010/08/29 09:53:48.0702 SymEvent (c9b8f325b2a22cda1bda7b25181b1389) C:\Program Files\Symantec\SYMEVENT.SYS 2010/08/29 09:53:49.0023 SYMFW (ca212638c07f7a1736667319589f416e) C:\WINDOWS\System32\Drivers\SYMFW.SYS 2010/08/29 09:53:49.0283 SYMIDS (83a0415ab669afe9f2b7fccc52f23153) C:\WINDOWS\System32\Drivers\SYMIDS.SYS 2010/08/29 09:53:49.0594 SYMIDSCO (14316306984f8ae6b6090b29a5f097b6) C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\IDS-DI~1\20100826.001\symidsco.sys 2010/08/29 09:53:49.0874 symlcbrd (6596892dd5abbe48f5876a551867a166) C:\WINDOWS\system32\drivers\symlcbrd.sys 2010/08/29 09:53:50.0164 SYMNDIS (2a8ebb694d702d91d8046b31c3da2220) C:\WINDOWS\System32\Drivers\SYMNDIS.SYS 2010/08/29 09:53:50.0505 SYMREDRV (7c73b65f1bdfab9052a5076c0ca622de) C:\WINDOWS\System32\Drivers\SYMREDRV.SYS 2010/08/29 09:53:50.0795 SYMTDI (b4562798891dca27ed67ca07acbadbd9) C:\WINDOWS\System32\Drivers\SYMTDI.SYS 2010/08/29 09:53:51.0506 SynTP (9dc35e8fa6172edfbd151727b5bb26db) C:\WINDOWS\system32\DRIVERS\SynTP.sys 2010/08/29 09:53:51.0787 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys 2010/08/29 09:53:52.0137 Tcpip (01d5eaaff224415a7ff513e4c882be30) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2010/08/29 09:53:52.0448 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys 2010/08/29 09:53:52.0698 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys 2010/08/29 09:53:52.0958 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys 2010/08/29 09:53:53.0299 TOSHIBASoftModem (fb978ef3d4f53382ee4ee7c2293ae1c5) C:\WINDOWS\system32\DRIVERS\LTSM.sys 2010/08/29 09:53:53.0830 tsdhd (a226ed7f4583616a65930cb361eb2a55) C:\WINDOWS\system32\DRIVERS\tsdhd.sys 2010/08/29 09:53:53.0980 TVALD (20b6be2a69c7547a09f67c3e67a2bdd5) C:\WINDOWS\system32\DRIVERS\TVALD.SYS 2010/08/29 09:53:54.0110 TVALDX (9287b10b79042d8399067f7fa76ae6b4) C:\WINDOWS\system32\DRIVERS\TVALDX.SYS 2010/08/29 09:53:54.0370 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys 2010/08/29 09:53:54.0981 Update (ced744117e91bdc0beb810f7d8608183) C:\WINDOWS\system32\DRIVERS\update.sys 2010/08/29 09:53:55.0292 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 2010/08/29 09:53:55.0612 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2010/08/29 09:53:55.0873 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys 2010/08/29 09:53:56.0133 usbstor (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2010/08/29 09:53:56.0493 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2010/08/29 09:53:56.0714 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys 2010/08/29 09:53:57.0275 VolSnap (a3105e8b54eab87a0ad0031aa02084b3) C:\WINDOWS\system32\drivers\VolSnap.sys 2010/08/29 09:53:57.0555 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2010/08/29 09:53:57.0946 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys 2010/08/29 09:53:58.0216 WDM_YAMAHAAC97 (a464e61160475be47a0c2c91e73691ff) C:\WINDOWS\system32\drivers\yacxg.sys 2010/08/29 09:53:58.0687 WSTCODEC (d5842484f05e12121c511aa93f6439ec) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 2010/08/29 09:53:58.0927 ================================================================================ 2010/08/29 09:53:58.0927 Scan finished 2010/08/29 09:53:58.0927 ================================================================================
I don't think you're having a Malware issue but lets try another tool.



Print out these instructions as we may need to close every window that is open later in the fix.


It is possible that the infection you are trying to remove will not allow you to download files on the infected computer. If this is the case, then you will need to download the files requested in this guide on another computer and then transfer them to the infected computer. You can transfer the files via a CD/DVD, external drive, or USB flash drive.

Do not reboot your computer after running rkill as the malware programs will start again.

Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 5 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click and choose Run as Admin
You only need to get one of them to run, not all of them.
  • rkill.exe
  • rkill.com
  • rkill.scr
  • WiNlOgOn.exe
  • uSeRiNiT.exe

Do not reboot your computer after running rkill as the malware programs will start again.

Next:
Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste". .
RKILL completed very quick, log below: This log file is located at C:\rkill.log. Please post this only if requested to by the person helping you. Otherwise you can close this log when you wish. Ran as Administrator on /08/30 ๆ˜ŸๆœŸไธ€ at 18:50:00. Processes terminated by Rkill or while it was running: C:\Documents and Settings\Administrator\ๆกŒ้ข\rkill.exe Rkill completed on /08/30 ๆ˜ŸๆœŸไธ€ at 18:50:08. โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€“ for malware scanner , i experience same errors in the last time i mentioned :: except i noted down the error file at the time of freezes 1) during scan, error prompt " EBAM_ERROR_ADD_TO_RESULTS(0,6) appears , and at the same time the file infected count becomes 1. I click OK(?) and the scan continued. After a few sec, the file under scan is like HKEY_CLASSES_ROOT\CLSID 2) windows application error appears when scanning c:\\windows\system32\asctrls.ocx then the malware sacnner freezes and windows prompt me to close it. I closed it. Windows also promt drwtsn32.exe also errored and need to be closed. I also closed it.
Do not reboot your computer after running rkill as the malware programs will start again.
Run rkill again followed by:

Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.If Vista or Windows 7, skip the Recovery Console part
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you โ€“ please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
ComboFix 10-08-30.02 - Administrator /08/31 ๆ˜ŸๆœŸไบŒ 20:24:34.4.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.[removed].18.511.291 [GMT 8:00]
ๅŸท่กŒไฝ็ฝฎ: c:\documents and settings\Administrator\ๆกŒ้ข\ComboFix.exe
AV: Norton AntiVirus 2005 *On-access scanning disabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.

((((((((((((((((((((((((((((((((((((((( ่ขซๅˆช้™ค็š„ๆช”ๆกˆ )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Thumbs.db
c:\windows\daemon.dll
c:\windows\system32\UACmpqjadwjfj.db

.
((((((((((((((((((((((((( 2010-07-28 ่‡ณ 2010-08-31 ็š„ๆ–ฐ็š„ๆช”ๆกˆ )))))))))))))))))))))))))))))))
.

2010-08-22 07:14 . 2010-08-22 07:15 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\eMule
2010-08-21 02:25 . 1997-11-06 06:53 27648 โ€”-a-w- c:\windows\system32\ir50_lcs.dll
2010-08-20 14:24 . 2010-08-20 14:24 โ€”โ€”โ€“ dโ€”โ€“w- C:\FOUND.001
2010-08-20 14:06 . 2010-04-29 07:39 38224 โ€”-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-20 13:53 . 2010-04-29 07:39 20952 โ€”-a-w- c:\windows\system32\drivers\mbam.sys
2010-08-20 13:28 . 2010-08-20 13:28 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\Malwarebytes' Anti-Malware
2010-08-14 11:08 . 2010-08-14 11:08 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\MagicDisc

.
(((((((((((((((((((((((((((((((((((((((( ๅœจไธ‰ๅ€‹ๆœˆๅ…ง่ขซไฟฎๆ”น็š„ๆช”ๆกˆ ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-24 02:38 . 2010-07-24 02:37 144696 โ€”-a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-07-24 02:23 . 2010-07-24 02:08 57344 โ€”-a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-07-24 02:20 . 2010-07-24 02:20 โ€”โ€”โ€“ dโ€”โ€“w- c:\program files\DivX
2010-07-24 02:00 . 2010-07-24 02:00 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\Administrator\Application Data\DivX
2010-07-24 01:50 . 2010-07-24 01:50 โ€”โ€”โ€“ dโ€”โ€“w- c:\documents and settings\All Users\Application Data\DivX
2010-07-06 19:35 . 2010-07-06 19:35 2396 โ€”-a-w- c:\windows\system32\PerfStringBackup.TMP
2010-07-06 19:35 . 2001-09-17 04:00 68308 โ€”-a-w- c:\windows\system32\prfc0404.dat
2010-07-06 19:35 . 2001-09-17 04:00 222718 โ€”-a-w- c:\windows\system32\prfh0404.dat
2005-07-06 17:25 . 2005-07-06 17:25 56 โ€“shโ€“r- c:\windows\system32\D782B1A6B6.sys
.

โ€”โ€”- Sigcheck โ€”โ€”-

[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[-] 2008-06-20 . 01D5EAAFF224415A7FF513E4C882BE30 . 360320 . . [5.1.2600.3394] . . c:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394] . . c:\windows\system32\dllcache\tcpip.sys
[7] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[-] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\5a805edbaa54f0da2a0bf62909893538\tcpip.sys
[7] 2007-10-30 . 90CAFF4B094573449A0872A0F919B178 . 360064 . . [5.1.2600.3244] . . c:\windows\$NtUninstallKB951748$\tcpip.sys
[7] 2007-10-30 . 64798ECFA43D78C7178375FCDD16D8C8 . 360832 . . [5.1.2600.3244] . . c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[7] 2006-04-20 . B2220C618B42A2212A59D91EBD6FC4B4 . 360576 . . [5.1.2600.2892] . . c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
[7] 2006-04-20 . 1DBF125862891817F374F407626967F4 . 359808 . . [5.1.2600.2892] . . c:\windows\$NtUninstallKB941644$\tcpip.sys
[7] 2006-01-13 . 5562CC0A47B2AEF06D3417B733F3C195 . 360448 . . [5.1.2600.2827] . . c:\windows\$hf_mig$\KB913446\SP2QFE\tcpip.sys
[7] 2006-01-13 . 583E063FDC888CA30D05C2724B0D7EF4 . 359808 . . [5.1.2600.2827] . . c:\windows\$NtUninstallKB917953$\tcpip.sys
[7] 2005-05-25 . 63FDFEA54EB53DE2D863EE454937CE1E . 359936 . . [5.1.2600.2685] . . c:\windows\$hf_mig$\KB893066\SP2QFE\tcpip.sys
[7] 2005-05-25 . 88763A98A4C26C409741B4AA162720C9 . 359808 . . [5.1.2600.2685] . . c:\windows\$NtUninstallKB913446$\tcpip.sys
[7] 2004-08-04 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB893066$\tcpip.sys
[7] 2004-08-04 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\ServicePackFiles\i386\tcpip.sys
[-] 2001-09-17 . E7774698BB0D14B0710A9A31E209F9B6 . 327168 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\tcpip.sys

[-] 2008-04-15 . F1A48452D018059538CD66E76261C2F4 . 247296 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\5a805edbaa54f0da2a0bf62909893538\tapisrv.dll
[-] 2007-06-18 . E1E074DB9C0C158736A04EC9B6144B3F . 246784 . . [5.1.2600.3158] . . c:\windows\$hf_mig$\KB938828\SP2QFE\tapisrv.dll
[-] 2007-06-18 . 0C78C3605A7830262AAEEE153D2CC913 . 246784 . . [5.1.2600.3158] . . c:\windows\system32\tapisrv.dll
[-] 2007-06-18 . 0C78C3605A7830262AAEEE153D2CC913 . 246784 . . [5.1.2600.3158] . . c:\windows\system32\dllcache\tapisrv.dll
[7] 2005-07-08 . 5BAB8AB739453DD356A5C137F48159F1 . 246784 . . [5.1.2600.2716] . . c:\windows\$hf_mig$\KB893756\SP2QFE\tapisrv.dll
[7] 2005-07-08 . FCF84F606E86557FD0FCD2CE21F4D245 . 246784 . . [5.1.2600.2716] . . c:\windows\$NtUninstallKB938828$\tapisrv.dll
[7] 2004-08-12 . B33207375E2B018409286E9477A1B517 . 243712 . . [5.1.2600.2180] . . c:\windows\ServicePackFiles\i386\tapisrv.dll
[7] 2004-08-12 . B33207375E2B018409286E9477A1B517 . 243712 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB893756$\tapisrv.dll
[-] 2001-09-17 . CE5CECC3EEBCEE1CE39928F9718095C7 . 233984 . . [5.1.2600.0] . . c:\windows\$NtServicePackUninstall$\tapisrv.dll

[-] 2008-04-15 . 88057E7B74236C11098E4D4EEAC7DF5E . 978432 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\5a805edbaa54f0da2a0bf62909893538\explorer.exe
[-] 2007-06-18 . D1822278F43E2850E03EF36D29686D4F . 977920 . . [6.00.2900.3158] . . c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
[-] 2007-06-18 . 3DDB98936B29019549C6FBABD86846E7 . 977920 . . [6.00.2900.3158] . . c:\windows\explorer.exe
[-] 2007-06-18 . 3DDB98936B29019549C6FBABD86846E7 . 977920 . . [6.00.2900.3158] . . c:\windows\system32\dllcache\explorer.exe
[7] 2004-08-12 . 211358AE74733075C22142B3AC519A19 . 976896 . . [6.00.2900.2180] . . c:\windows\ServicePackFiles\i386\explorer.exe
[7] 2004-08-12 . 211358AE74733075C22142B3AC519A19 . 976896 . . [6.00.2900.2180] . . c:\windows\$NtUninstallKB938828$\explorer.exe
[-] 2001-09-17 . EE2156A747C0038FA3453DE33F081878 . 1000960 . . [6.00.2600.0000] . . c:\windows\$NtServicePackUninstall$\explorer.exe
.
((((((((((((((((((((((((((((((((((((( ้‡่ฆ็™ปๅ…ฅ้ปž ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*ๆณจๆ„* ็ฉบ็™ฝ่ˆ‡ๅˆๆณ•็ผบ็œ็™ป้Œ„ๅฐ‡ไธๆœƒ่ขซ้กฏ็คบ
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RealPlayer"="c:\program files\Real\RealOne Player\realplay.exe" [2006-06-06 1003520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" [X]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-12 455168]
"PHIME2002A"="c:\windows\System32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-12 455168]
"00THotkey"="c:\windows\System32\00THotkey.exe" [2002-01-08 245760]
"000StTHK"="000StTHK.exe" [2001-06-23 24576]
"Tpwrtray"="TPWRTRAY.EXE" [2002-01-25 196608]
"TFncKy"="TFncKy.exe" [BU]
"SxgTkBar"="SxgTkBar.exe" [2001-07-11 53248]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2001-08-16 94208]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2001-08-16 376832]
"TosHKCW.exe"="c:\program files\TOSHIBA\Wireless Hotkey\TosHKCW.exe" [2002-01-22 49152]
"TFNF5"="TFNF5.exe" [2001-08-03 73728]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2002-10-17 151597]
"LWBMOUSE"="c:\program files\Browser Mouse\Browser Mouse\1.0\lwbwheel.exe" [2001-03-26 429568]
"gcasServ"="c:\program files\Microsoft AntiSpyware\gcasServ.exe" [2005-11-15 473928]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-05-19 59040]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2006-01-12 100056]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-26 148888]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\System32\ctfmon.exe" [2004-08-12 15360]

c:\documents and settings\Administrator\ใ€Œ้–‹ๅง‹ใ€ๅŠŸ่ƒฝ่กจ\็จ‹ๅผ้›†\ๅ•Ÿๅ‹•\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2010-8-14 576000]

c:\documents and settings\All Users\ใ€Œ้–‹ๅง‹ใ€ๅŠŸ่ƒฝ่กจ\็จ‹ๅผ้›†\ๅ•Ÿๅ‹•\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 1942\\bf1942.exe"=
"c:\\Program Files\\Messenger\\MSMSGS.EXE"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\System32\\dpvsetup.exe"=
"c:\\Documents and Settings\\Administrator\\ๆกŒ้ข\\้ญ”?1.07\\Warcraft III.exe"=
"g:\\CQ Design Institute\\GEO\\้ญ”?1.07\\Warcraft III.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\NextLink\\GOGOBOX\\gfscagent.exe"=
"c:\\Program Files\\NextLink\\GOGOBOX\\gogobox.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\WINDOWS\\System32\\dplaysvr.exe"=
"c:\\Program Files\\eMule\\emule.exe"=

R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [2005/7/1 ไธ‹ๅˆ 12:55 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [2005/7/1 ไธ‹ๅˆ 12:55 5248]
R0 pciSm;pciSm;c:\windows\system32\drivers\tossmpci.sys [2002/7/31 ไธŠๅˆ 11:47 45803]
R0 TVALDX;Toshiba ACPI-Based Value Added Logical Device Extension Driver;c:\windows\system32\drivers\TVALDX.SYS [2002/7/31 ไธŠๅˆ 11:43 6082]
R2 ่‡ชๅ‹• LiveUpdate ๆŽ’็จ‹ๅ™จ;่‡ชๅ‹• LiveUpdate ๆŽ’็จ‹ๅ™จ;c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe [2006/12/29 ไธ‹ๅˆ 11:13 100032]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010/8/20 ไธ‹ๅˆ 10:06 38224]
R3 SOFTXG;YAMAHA XG WDM SoftSynthesizer;c:\windows\system32\drivers\sxgxgwdm.sys [2002/7/31 ไธŠๅˆ 11:51 966784]

โ€” Other Services/Drivers In Memory โ€”

*NewlyCreated* - MBAMSWISSARMY
.
โ€˜่จˆๅŠƒไปปๅ‹™โ€™ ๆ–‡ไปถๅคพ ่ฃก็š„ๅ…งๅฎน

2010-08-27 c:\windows\Tasks\Norton AntiVirus - ๆŽƒๆๆˆ‘็š„้›ป่…ฆ - Administrator.job
- c:\progra~1\NORTON~1\Navw32.exe [2004-09-01 10:36]

2010-08-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 04:34]
.
.
โ€”โ€”- ่€Œๅค–็š„ๆŽƒๆ โ€”โ€”-
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = iexplore
IE: ๅŒฏๅ‡บ่‡ณ Microsoft Excel(&X) - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: {9B69C40C-4719-4BCA-85F7-49A8AFC67880} = 218.102.32.208 205.252.144.126
DPF: Microsoft XML Parser for Java
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\uhgh87ld.Default User\
FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/accounts/ServiceLogin?service=mail&passive=true&rm=false&continue=https%3A%2F%2Fmail.google.com%2Fmail%2F%3Fnsr%3D1%26ui%3Dhtml%26zy%3Dl FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprpjplug.dll

โ€”- ็ซ็‹้…็ฝฎๆ–‡ไปถ โ€”-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xnโ€“mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xnโ€“mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
.
โ€”โ€”- ๆ–‡ไปถ้กžๅž‹ โ€”โ€”-
.
.scr=AutoCADScript
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-31 20:31
Windows 5.1.2600 Service Pack 2 FAT NTAPI

ๆŽƒๆ่ขซ้šฑ่—็š„้€ฒ็จ‹ โ€ฆ

ๆŽƒๆ่ขซ้šฑ่—็š„ๅ•Ÿๅ‹•็ต„ โ€ฆ

ๆŽƒๆ่ขซ้šฑ่—็š„ๆ–‡ไปถ โ€ฆ

ๆŽƒๆๅฎŒๆˆ
่ขซ้šฑ่—็š„ๆช”ๆกˆ: 0

**************************************************************************
Binary file temp00 matches
.
โ€”โ€”โ€”โ€”โ€”โ€”โ€” LOCKED REGISTRY KEYS โ€”โ€”โ€”โ€”โ€”โ€”โ€”

[HKEY_USERS\.Default\AppEvents\Schemes\Apps\Conf\ๆ‘ธๅ—ฟ*๎“ฃQ\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"

[HKEY_USERS\LocalService\AppEvents\Schemes\Apps\Conf\ๆ‘ธๅ—ฟ*๎“ฃQ\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"

[HKEY_USERS\S-1-5-20\AppEvents\Schemes\Apps\Conf\ๆ‘ธๅ—ฟ*๎“ฃQ\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"

[HKEY_USERS\S-1-5-21-1605616401-71594873-1131426265-500\AppEvents\Schemes\Apps\Conf\ๆ‘ธๅ—ฟ*๎“ฃQ\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"

[HKEY_USERS\S-1-5-21-1605616401-71594873-1131426265-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\ N_*8n_*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"Order"=hex:08,00,00,00,02,00,00,00,da,01,00,00,01,00,00,00,04,00,00,00,74,00,
00,00,00,00,00,00,66,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,54,00,32,\

[HKEY_USERS\S-1-5-21-1605616401-71594873-1131426265-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\wc๎”‡ *-* * *D๎ ฅ\ๆฐ”(u z_]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1605616401-71594873-1131426265-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\nndto@Y,n3*"{E`3U]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"Order"=hex:08,00,00,00,02,00,00,00,14,01,00,00,01,00,00,00,02,00,00,00,86,00,
00,00,00,00,00,00,78,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,66,00,36,\

[HKEY_USERS\S-1-5-21-1605616401-71594873-1131426265-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\้‹จRโ‚ฌl๎กฉ_5*๎“ธ๏Œก^tX]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"Order"=hex:08,00,00,00,02,00,00,00,0c,00,00,00,01,00,00,00,00,00,00,00

[HKEY_USERS\S-1-5-21-1605616401-71594873-1131426265-500\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\At|๎‘Ÿ?\3*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"Order"=hex:08,00,00,00,02,00,00,00,0c,00,00,00,01,00,00,00,00,00,00,00

[HKEY_USERS\S-1-5-21-299502267-1606980848-854245398-500_Classes\O*v*e*r*t*u*r*e* *j\๏“ท
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-299502267-1606980848-854245398-500_Classes\O*v*e*r*t*u*r*e* *j\๏“ถDefaultIcon]
@=expand:"%APPDATA%\\Microsoft\\Installer\\{50ADDF79-3249-4679-B527-3FB8C5EA99E5}\\_294823.exe,0"

[HKEY_USERS\S-1-5-21-299502267-1606980848-854245398-500_Classes\O*v*e*r*t*u*r*e* *j\๏“ถshell]
@="open"

[HKEY_USERS\S-1-5-21-299502267-1606980848-854245398-500_Classes\O*v*e*r*t*u*r*e* *j\๏“ถshell\open]
@="้–‹ๅ•Ÿ(&O)"

[HKEY_USERS\S-1-5-21-299502267-1606980848-854245398-500_Classes\O*v*e*r*t*u*r*e* *j\๏“ถshell\open\command]
@="\"c:\\Program Files\\Overture 4.0 ็น้ซ”ไธญๆ–‡็‰ˆ\\Overture.exe\" \"%1\""
"command"=multi:"%_(xAdi9`=RGK6dXKNlr>?%)duR)D9Xu~OSIW`PT- \"%1\"\00\00"

[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*CQ่ญธ\CLSID]
@="{809B6661-94C4-49E6-B6EC-3F0F862215AA}"

[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*CQ่ญธ\CurVer]
@="BDATuner.ๅ…ƒไปถ.1"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\้‹จRโ‚ฌl๎กฉ_5*๎“ธ๏Œก^tX]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,00,40,10,
3f,a7,97,c6,01,18,00,00,00,43,00,3a,00,5c,00,47,00,54,00,41,00,20,00,56,00,\
"Changed"=dword:00000000

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Print\Printers\?ๆ‚ A N Y O N E - 3 D C F 4 6 2 0
N๏ƒ… H P D e s k J e t 9 3 0 C / 9 3 2 C / 9 3 5 C \DsDriver]
"printBinNames"=multi:"่‡ชๅ‹•้ธๅ–\00ไธŠๆ–น็ด™ๅŒฃ\00ๆ‰‹ๅ‹•้€็ด™\00ไฟกๅฐ, ๆ‰‹ๅ‹•้€็ด™\00\00"
"printCollate"=hex:01
"printColor"=hex:01
"printDuplexSupported"=hex:00
"printStaplingSupported"=hex:00
"printMaxXExtent"=dword:0000086f
"printMaxYExtent"=dword:00000de4
"printMinXExtent"=dword:000003e8
"printMinYExtent"=dword:000005b4
"printMediaSupported"=multi:"Letter\00Legal\00Executive\00A4\00A5\00B5 (JIS)\00Envelope #10\00Envelope DL\00Envelope C6\00Japanese Postcard\00A6\00Envelope A2\00US Index Card 4x6\00US Index Card 5x8\00\00"
"printMediaReady"=multi:"A4\00\00"
"printNumberUp"=dword:00000006
"printOrientationsSupported"=multi:"PORTRAIT\00LANDSCAPE\00\00"
"printMaxResolutionSupported"=dword:000004b0
"printLanguage"=multi:"PCL\00\00"
"printRate"=dword:00000009
"printRateUnit"="PagesPerMinute"
"printPagesPerMinute"=dword:00000009
"driverVersion"=dword:00000401

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Print\Printers\?ๆ‚ A N Y O N E - 3 D C F 4 6 2 0
N๏ƒ… H P D e s k J e t 9 3 0 C / 9 3 2 C / 9 3 5 C \DsSpooler]
"description"=""
"driverName"="HP DeskJet 930C/932C/935C"
"location"=""
"portName"=multi:"\\\\ANYONE-3DCF4620\\ๆ‰“ๅฐๆœบ\00\00"
"printStartTime"=dword:00000000
"printEndTime"=dword:00000000
"printerName"="่‡ชๅ‹• ANYONE-3DCF4620 ไธŠ็š„ HP DeskJet 930C/932C/935C"
"printKeepPrintedJobs"=hex:00
"printSeparatorFile"=""
"printShareName"=""
"printSpooling"="PrintWhileSpooling"
"priority"=dword:00000001
"uNCName"="\\\\LEE-YV2R7VX5FBM\\่‡ชๅ‹• ANYONE-3DCF4620 ไธŠ็š„ HP DeskJet 930C/932C/935C"
"versionNumber"=dword:00000004
"serverName"="LEE-YV2R7VX5FBM"
"shortServerName"="LEE-YV2R7VX5FBM"
"flags"=dword:00000000

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Print\Printers\?ๆ‚ A N Y O N E - 3 D C F 4 6 2 0
N๏ƒ… H P D e s k J e t 9 3 0 C / 9 3 2 C / 9 3 5 C \PrinterDriverData]
"InitDriverVersion"=dword:00000500
"Model"="HP DeskJet 930C/932C/935C"
"PrinterDataSize"=dword:00000230
"PrinterData"=hex:00,05,30,02,81,08,00,00,80,1a,06,00,00,00,00,00,00,00,00,00,
64,00,58,02,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,f4,0c,86,d1,01,\
"FeatureKeywordSize"=dword:0000001d
"FeatureKeyword"=hex:48,50,44,75,70,6c,65,78,55,6e,69,74,00,4e,6f,74,49,6e,73,
74,61,6c,6c,65,64,00,0a,00,00
"Forms?"=dword:d1860cf4

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\?ๆ‚ *L*i*v*e*U*p*d*a*t*e* *๎–จ zhV\Security]
"Security"=hex:01,00,14,80,90,00,00,00,9c,00,00,00,14,00,00,00,30,00,00,00,02,
00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
.
ๅฎŒๆˆๆ™‚้–“: 2010-08-31 20:34:16
ComboFix-quarantined-files.txt 2010-08-31 12:34

Pre-Run: 361,971,712 ไฝๅ…ƒ็ต„ๅฏ็”จ
Post-Run: 330,448,896 ไฝๅ…ƒ็ต„ๅฏ็”จ

Current=2 Default=2 Failed=3 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 02D46F5EDBC7E282BE867C20202064F1



nth strange in computerโ€ฆbut need to cut connection and reconnect to internet to load this page

1) during scan, error prompt " EBAM_ERROR_ADD_TO_RESULTS(0,6) appears , and at the same time the file infected count becomes 1. I click OK(?) and the scan continued. After a few sec, the file under scan is like HKEY_CLASSES_ROOT\CLSID

2) windows application error appears when scanning c:\\windows\system32\asctrls.ocx
then the malware sacnner freezes and windows prompt me to close it. I closed it.
Windows also promt drwtsn32.exe also errored and need to be closed. I also closed it.



Do you still have that?

1) during scan, error prompt " EBAM_ERROR_ADD_TO_RESULTS(0,6) appears , and at the same time the file infected count becomes 1. I click OK(?) and the scan continued. After a few sec, the file under scan is like HKEY_CLASSES_ROOT\CLSID

2) windows application error appears when scanning c:\\windows\system32\asctrls.ocx
then the malware sacnner freezes and windows prompt me to close it. I closed it.
Windows also promt drwtsn32.exe also errored and need to be closed. I also closed it.



Do you still have that?



strange enough

part1) no longer happen

but part 2) still happens

I'd uninstall MBAM and download a new copy and try that.



just did that
same error at the same file when scanning c:\\windows\system32\asctrls.ocx

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI