This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Can't RUN AV or AntiMalware Programs

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Within the last 48 hours I am no longer able to run certain AV or AntiMalware programs, specifically SpyBot S&D and Malwarebytes' AntiMalware!! I decided to uninstall both (via the 'uninst.exe' option or 'Unlocker') and then reinstall. During the uninstall(s) there were several popup consoles advising that Windows (Explorer) had encountered errors! The reinstalls seemed to be successful but upon inspection, some of the files necessary were missing!! e.g. in SpyBot S&D both the "SpybotSD.exe" and the "SDUpdate.exe" were not resident. The net result was that both reinstalls were still not capable of being run correctly/successfully. I ran several AV and AntiMalware scans (e.g. AVG, IOBit and STINGER to name a few) and the scans showed no infection!! Many of my other AV and AntiMalware programs/applications seem unaffected by this issue. I am hoping that the learned members can suggest a resolution to my problem!! Thanks in advance for any and all assistance with this issue. jmac0408 P.S I cannot seem to attach the generated HijackThis log file - keep getting the disclaimer that "You are not permitted to upload this type of file"!! ????
how many AV's do you have installed?

You should only have one, more than one can cause system slowdowns, conflicts and crashes

Please do the following:




Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.



NEXT



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



NEXT


Scan With RootKitUnHooker

  • Please Download Rootkit Unhooker and save it to your desktop.
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"
Good Mornng, CatByte: First, thank you for responding to my issue. I apologize for the delay in replying but I've been out of the country for several days. I will try and follow your instructions correctly below: MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Home Edition Windows Information: Service Pack 3 (build 2600) Logical Drives Mask: 0x0000003d Kernel Drivers (total 164): 0x804D7000 \WINDOWS\system32\ntoskrnl.exe 0x806FF000 \WINDOWS\system32\hal.dll 0xF7B6E000 \WINDOWS\system32\KDCOM.DLL 0xF7A7E000 \WINDOWS\system32\BOOTVID.dll 0xF7550000 spny.sys 0xF7B70000 \WINDOWS\System32\Drivers\WMILIB.SYS 0xF7538000 \WINDOWS\System32\Drivers\SCSIPORT.SYS 0xF750A000 ACPI.sys 0xF74F9000 pci.sys 0xF766E000 isapnp.sys 0xF7B72000 viaide.sys 0xF78EE000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xF767E000 MountMgr.sys 0xF74DA000 ftdisk.sys 0xF78F6000 PartMgr.sys 0xF768E000 VolSnap.sys 0xF748E000 atapi.sys 0xF76AE000 disk.sys 0xF76BE000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xF746E000 fltmgr.sys 0xF7458000 PQV2i.sys 0xF76CE000 PxHelp20.sys 0xF7441000 KSecDD.sys 0xF742E000 WudfPf.sys 0xF73A1000 Ntfs.sys 0xF7374000 NDIS.sys 0xF7309000 timntr.sys 0xF76DE000 uagp35.sys 0xF72B0000 tdrpman.sys 0xF729C000 srescan.sys 0xF7B74000 speedfan.sys 0xF727D000 snapman.sys 0xF76EE000 RVSYSTEM.sys 0xF7A82000 RVSDISK.sys 0xF7263000 Mup.sys 0xF78FE000 hotcore3.sys 0xF7C36000 giveio.sys 0xF774E000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xF6FD5000 \SystemRoot\system32\DRIVERS\ati2mtag.sys 0xF6FC1000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xF6F66000 \SystemRoot\system32\DRIVERS\bcmwl5.sys 0xF775E000 \SystemRoot\system32\DRIVERS\imapi.sys 0xF776E000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xF777E000 \SystemRoot\system32\DRIVERS\redbook.sys 0xF6F43000 \SystemRoot\system32\DRIVERS\ks.sys 0xF793E000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys 0xF794E000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0xF6F1F000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xF7B78000 \SystemRoot\System32\Drivers\vulfnth.sys 0xF7956000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xF7966000 \SystemRoot\system32\DRIVERS\fdc.sys 0xF6F0B000 \SystemRoot\system32\DRIVERS\parport.sys 0xF7B7C000 \SystemRoot\system32\DRIVERS\ASACPI.sys 0xF778E000 \SystemRoot\system32\DRIVERS\serial.sys 0xF71C7000 \SystemRoot\system32\DRIVERS\serenum.sys 0xF779E000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0xF7976000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xF6EC9000 \SystemRoot\system32\drivers\smwdm.sys 0xF6EA5000 \SystemRoot\system32\drivers\portcls.sys 0xF77AE000 \SystemRoot\system32\drivers\drmk.sys 0xF6E89000 \SystemRoot\system32\drivers\aeaudio.sys 0xF6E2B000 \SystemRoot\system32\drivers\senfilt.sys 0xF6E14000 \SystemRoot\System32\Drivers\ezplay.sys 0xF77BE000 \SystemRoot\system32\drivers\srs_sscfilter.sys 0xF79A6000 \SystemRoot\system32\drivers\wowhd_kern_i386.sys 0xF77CE000 \SystemRoot\system32\drivers\csiidecoder_kern_i386.sys 0xF77DE000 \SystemRoot\system32\drivers\surroundhp_kern_i386.sys 0xF77EE000 \SystemRoot\system32\drivers\tshd4_kern_i386.sys 0xF79B6000 \SystemRoot\system32\drivers\DsAudioDevice_286.sys 0xF7DC4000 \SystemRoot\system32\DRIVERS\audstub.sys 0xF7B84000 \SystemRoot\System32\Drivers\RootMdm.sys 0xF79C6000 \SystemRoot\System32\Drivers\Modem.SYS 0xF77FE000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xF71B7000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xF6D5D000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xF780E000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xF781E000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xF79E6000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xF6D4C000 \SystemRoot\system32\DRIVERS\psched.sys 0xF782E000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xF79FE000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xF7A0E000 \SystemRoot\system32\DRIVERS\raspti.sys 0xF785E000 \SystemRoot\System32\Drivers\pcouffin.sys 0xF786E000 \SystemRoot\system32\DRIVERS\termdd.sys 0xF7A16000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xF6D37000 \SystemRoot\system32\DRIVERS\StarPortLite.sys 0xF7B94000 \SystemRoot\system32\DRIVERS\swenum.sys 0xF6CD9000 \SystemRoot\system32\DRIVERS\update.sys 0xF7193000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xF7A2E000 \SystemRoot\system32\DRIVERS\UimBus.sys 0xF6C80000 \SystemRoot\System32\Drivers\Uim_IM.sys 0xF6C44000 \SystemRoot\System32\Drivers\UimFIO.SYS 0xF788E000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xF716B000 \SystemRoot\System32\Drivers\vulfntr.sys 0xF78BE000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xF7B9C000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xF7A66000 \SystemRoot\system32\DRIVERS\flpydisk.sys 0xF7BA0000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF7D06000 \SystemRoot\System32\Drivers\Null.SYS 0xF7BA4000 \SystemRoot\System32\Drivers\Beep.SYS 0xF792E000 \SystemRoot\System32\drivers\vga.sys 0xF7BA8000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF7BAC000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF7946000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF796E000 \SystemRoot\System32\Drivers\Npfs.SYS 0xF71DF000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xBA7A5000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xBA74C000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xBA726000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xBA6EC000 \SystemRoot\System32\Drivers\avgtdix.sys 0xF78DE000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xBA6C4000 \SystemRoot\system32\DRIVERS\netbt.sys 0xBA684000 \SystemRoot\System32\Drivers\SYMTDI.SYS 0xBA604000 \SystemRoot\System32\vsdatant.sys 0xF71AF000 \SystemRoot\system32\DRIVERS\hidusb.sys 0xF769E000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0xF79EE000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xF71A3000 \SystemRoot\system32\DRIVERS\mouhid.sys 0xF6DA4000 \SystemRoot\system32\DRIVERS\point32.sys 0xF6D94000 \SystemRoot\system32\DRIVERS\WDFLDR.SYS 0xBA593000 \SystemRoot\System32\Drivers\wdf01000.sys 0xF6D84000 \??\C:\WINDOWS\system32\Drivers\pssdk42.sys 0xBA549000 \SystemRoot\System32\drivers\afd.sys 0xF6D74000 \SystemRoot\system32\DRIVERS\netbios.sys 0xF6B90000 \SystemRoot\System32\Drivers\FileDisk.sys 0xBA47E000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xBA42D000 \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys 0xF7A26000 \??\C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\19917\RapportCerberus_19917.sys 0xF783E000 \SystemRoot\System32\Drivers\PQIMount.SYS 0xBA36D000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xBA577000 \??\C:\Program Files\HWiNFO32\HWiNFO32.SYS 0xF79D6000 \??\C:\WINDOWS\system32\drivers\HFCore.sys 0xF784E000 \SystemRoot\System32\Drivers\Fips.SYS 0xF7DA9000 \SystemRoot\System32\Drivers\BANTExt.sys 0xF7A06000 \SystemRoot\System32\Drivers\avgmfx86.sys 0xBA339000 \SystemRoot\System32\Drivers\avgldx86.sys 0xF7C04000 \SystemRoot\system32\drivers\AsIO.sys 0xF6DB4000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xBA311000 \SystemRoot\System32\drivers\Dxapi.sys 0xF7A76000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xF7C90000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF012000 \SystemRoot\System32\ati2dvag.dll 0xBF054000 \SystemRoot\System32\ati2cqag.dll 0xBF093000 \SystemRoot\System32\atikvmag.dll 0xBF0C9000 \SystemRoot\System32\ati3duag.dll 0xBF34D000 \SystemRoot\System32\ativvaxx.dll 0xBFFA0000 \SystemRoot\System32\ATMFD.DLL 0xB5A60000 \SystemRoot\system32\DRIVERS\tifsfilt.sys 0xB58E8000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xF795E000 \SystemRoot\system32\DRIVERS\pnarp.sys 0xF7A3E000 \SystemRoot\system32\DRIVERS\purendis.sys 0xB549B000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xF7C1A000 \SystemRoot\System32\Drivers\ParVdm.SYS 0xB5AE8000 \??\C:\Program Files\ASTRA32\ASTRA32.sys 0xB5342000 \SystemRoot\System32\Drivers\HTTP.sys 0xB5256000 \SystemRoot\System32\Drivers\Fastfat.SYS 0xB506F000 \SystemRoot\system32\DRIVERS\srv.sys 0xB4FCB000 \??\C:\WINDOWS\system32\drivers\tmcomm.sys 0xB4926000 \SystemRoot\system32\drivers\wdmaud.sys 0xB548B000 \SystemRoot\system32\drivers\sysaudio.sys 0xB3B67000 \SystemRoot\system32\drivers\kmixer.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 56): 0 System Idle Process 4 System 884 C:\WINDOWS\system32\smss.exe 1000 csrss.exe 1028 C:\WINDOWS\system32\winlogon.exe 1072 C:\WINDOWS\system32\services.exe 1084 C:\WINDOWS\system32\lsass.exe 1252 C:\Program Files\USB Safely Remove\USBSRService.exe 1264 C:\WINDOWS\system32\ati2evxx.exe 1292 C:\WINDOWS\system32\svchost.exe 1412 svchost.exe 1452 C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe 1484 C:\WINDOWS\system32\svchost.exe 1536 C:\WINDOWS\system32\svchost.exe 1560 C:\Program Files\AVG\AVG9\avgchsvx.exe 1568 C:\Program Files\AVG\AVG9\avgrsx.exe 1756 svchost.exe 1796 C:\Program Files\AVG\AVG9\avgcsrvx.exe 1832 svchost.exe 592 C:\WINDOWS\system32\spoolsv.exe 660 svchost.exe 876 C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe 1624 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 1192 C:\Program Files\AVG\AVG9\avgwdsvc.exe 1860 C:\Program Files\Bonjour\mDNSResponder.exe 2072 C:\WINDOWS\system32\gearsec.exe 2236 C:\WINDOWS\system32\svchost.exe 2252 C:\Program Files\Google\Update\GoogleUpdate.exe 2328 C:\Program Files\IObit\IObit Security 360\is360srv.exe 2332 C:\Program Files\AVG\AVG9\avgnsx.exe 2488 C:\Program Files\Java\jre6\bin\jqs.exe 2556 C:\WINDOWS\system32\HPZipm12.exe 2896 C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe 3036 C:\WINDOWS\system32\svchost.exe 3304 C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe 3360 C:\Program Files\AVG\AVG9\avgemc.exe 3416 C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe 3484 C:\Program Files\AVG\AVG9\avgcsrvx.exe 3556 wmpnetwk.exe 3764 alg.exe 2688 C:\WINDOWS\system32\ati2evxx.exe 3152 C:\Program Files\Trusteer\Rapport\bin\RapportService.exe 1408 C:\WINDOWS\explorer.exe 2600 C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe 3700 C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe 392 C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe 2612 C:\PROGRA~1\AVG\AVG9\avgtray.exe 2516 C:\Program Files\Microsoft IntelliPoint\ipoint.exe 556 C:\Program Files\Weather Watcher\ww.exe 2132 C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe 3000 C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe 4536 C:\WINDOWS\system32\wuauclt.exe 5568 C:\Program Files\Internet Explorer\iexplore.exe 5804 C:\Program Files\Internet Explorer\iexplore.exe 4268 C:\Program Files\Internet Explorer\iexplore.exe 6064 C:\Documents and Settings\John\desktop\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) \\.\D: –> \\.\PhysicalDrive1 at offset 0x00000000`00007e00 (NTFS) PhysicalDrive0 Model Number: WDCWD1600JB-00REA0, Rev: 20.00K20 PhysicalDrive1 Model Number: Maxtor6Y160P0, Rev: YAR41BW0 Size Device Name MBR Status ——————————————– 149 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A 152 GB \\.\PhysicalDrive1 Unknown MBR code SHA1: 77FAC0B8A12A8FA01F9977882D41261898FB36E7 Found non-standard or infected MBR. Enter 'Y' and hit ENTER for more options, or 'N' to exit: Done! DDS (Ver_10-10-10.03) - NTFSx86 Run by [removed] at 5:34:19.20 on 13/10/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Home Edition 5.1.2600.3.1252.2.1033.18.1023.264 [GMT -4:00] AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} FW: ZoneAlarm Pro Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B} ============== Running Processes =============== C:\Program Files\USB Safely Remove\USBSRService.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe svchost.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\System32\GEARSec.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Google\Update\GoogleUpdate.exe C:\Program Files\IObit\IObit Security 360\IS360srv.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe C:\Program Files\AVG\AVG9\avgemc.exe C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Trusteer\Rapport\bin\RapportService.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe C:\PROGRA~1\AVG\AVG9\avgtray.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files\Weather Watcher\ww.exe C:\Program Files\Atomic Alarm Clock\AtomicAlarmClock.exe C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Documents and Settings\John\Desktop\dds.com ============== Pseudo HJT Report =============== uStart Page = hxxp://www.cbc.ca uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8 uDefault_Search_URL = hxxp://www.google.com/ie uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie mSearchAssistant = hxxp://www.google.com/ie uURLSearchHooks: _URLHandler: {23a6f4c1-32ea-40af-b42b-e0a99e2a74a6} - c:\progra~1\romeob~2\ROMEOS~1.DLL BHO: IE7Pro BHO: {00011268-e188-40df-a514-835fcd78b1bf} - c:\program files\ie7pro\iepro\iepro.dll BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: QuickStores-Toolbar: {10edb994-47f8-43f7-ae96-f2ea63e9f90f} - mscoree.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll BHO: SearchGT: {684b7df7-51de-4852-acf8-7ba3934d9bd1} - c:\program files\searchgt\SearchGTShell.dll BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: CGreenPrintPDF Object: {df96ba30-57f6-4700-8065-910ec3be9e3b} - c:\program files\greenprint technologies\greenprint world\GPIEPlugin.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: Ziptionary BHO: {f9ff8423-50f2-4f80-a31d-d1a03dbe9d86} - c:\program files\ziptionary\ziptionary.dll TB: &RoboForm;: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll TB: Grab Pro: {c55bbcd6-41ad-48ad-9953-3609c48eacc7} - c:\program files\ie7pro\iepro\IEProRecorder.dll TB: QuickStores-Toolbar: {10edb994-47f8-43f7-ae96-f2ea63e9f90f} - mscoree.dll TB: &Google; Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File EB: {6F480F82-C3A6-4D35-96F7-B297AD49FBE8} - No File EB: Ziptionary Band Panel: {2579475b-a3d7-43ad-b95a-b88830e15e29} - c:\program files\ziptionary\ziptionary.dll EB: SearchGT: {502bf9b7-3bf4-444d-98c5-545fd8247924} - c:\program files\searchgt\SearchGTShell.dll uRun: [WeatherWatcher] c:\program files\weather watcher\ww.exe uRun: [SkinClock] c:\program files\atomic alarm clock\AtomicAlarmClock.exe uRun: [DriverMax_RESTART] uRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe" mRun: [WinPatrol] c:\program files\winpatrol\winpatrol.exe -expressboot mRun: [Acronis Scheduler2 Service] "c:\program files\common files\acronis\schedule2\schedhlp.exe" mRun: [ZoneAlarm Client] "c:\program files\zonealarm\zlclient.exe" mRun: [TrueImageMonitor.exe] c:\program files\acronis\trueimagehome\TrueImageMonitor.exe mRun: [AcronisTimounterMonitor] c:\program files\acronis\trueimagehome\TimounterMonitor.exe mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe mRun: [] mRun: [Eraser] mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe" dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\john\startm~1\programs\startup\cleanc~1.lnk - c:\program files\cleancache 3.0\CleanCache.exe StartupFolder: c:\docume~1\john\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\sentinel.lnk - c:\program files\sentinel2\sentinel2\Sentinel.exe IE: &Clean; Traces - c:\program files\downloadacceleratorplus (dap)\privacy package\dapcleanerie.htm IE: &Compress; Image Using Image Compressor 2008 - c:\program files\image compressor 2008 pro\imcieex_compress.html IE: &Download; with &DAP; - c:\program files\downloadacceleratorplus (dap)\dapextie.htm IE: >Search in Linkman - file://c:\documents and settings\john\my documents\linkman\iescript_search.htm IE: Add to EverNote - c:\program files\evernote\evernote\enbar.dll/2000 IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200 IE: Add to Linkman - file://c:\documents and settings\john\my documents\linkman\iescript_add.htm IE: Add to Linkman and Edit - file://c:\documents and settings\john\my documents\linkman\iescript_edit.htm IE: Capture image with GKB - IE: Capture web page with GKB - IE: Customize Menu - file://c:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html IE: Download &all; with DAP - c:\program files\downloadacceleratorplus (dap)\dapextie2.htm IE: Enqueue current page with Bulk Image Downloader - file://c:\program files\bulk image downloader\iemenu\iebidqueue.htm IE: Enqueue link target with Bulk Image Downloader - file://c:\program files\bulk image downloader\iemenu\iebidlinkqueue.htm IE: Fill Forms - file://c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: Free YouTube to Mp3 Converter - c:\documents and settings\john\application data\dvdvideosoftiehelpers\youtubetomp3.htm IE: Open current page with Bulk Image Downloader - file://c:\program files\bulk image downloader\iemenu\iebid.htm IE: Open link target with Bulk Image Downloader - file://c:\program files\bulk image downloader\iemenu\iebidlink.htm IE: RoboForm Toolbar - file://c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: Save Forms - file://c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: Save YouTube Video as MP3 - c:\program files\common files\dvdvideosoft\dll\IEContextMenuY.dll/scriptY2MP3.htm IE: Show Linkman - file://c:\documents and settings\john\my documents\linkman\iescript_show.htm IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: {DF96BA30-57F6-4700-8065-910EC3BE9E3B} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583}\SOFTWARE IE: {e2e2dd38-d088-4134-82b7-f2ba38496583}\SOFTWARE\Classes IE: {e2e2dd38-d088-4134-82b7-f2ba38496583}\SOFTWARE\Classes\CLSID IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583}\ProgID IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {000002a3-84fe-43f1-b958-f2c3ca804f1a} - {CD275D4E-791A-4993-9D4D-6A071EDD2709} - c:\program files\ie7pro\iepro\iepro.dll IE: {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - {B119EB0C-C021-46CF-85B0-34A760E0D5FE} - c:\program files\ie7pro\iepro\iepro.dll IE: {554099FE-3856-4d93-86B5-0024AEF63BC7} - {DF96BA30-57F6-4700-8065-910EC3BE9E3B} - c:\program files\greenprint technologies\greenprint world\GPIEPlugin.dll IE: {A5ABA0BB-F195-40d8-A5E9-0801153E6597} - {2151DA8C-C5B6-4B4F-86AB-BDA449BF8747} - c:\program files\evernote\evernote\enbar.dll DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://pcpitstop.com/betapit/PCPitStop.CAB DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} - hxxp://www.kaspersky.com/kos/english/kavwebscan_unicode.cab DPF: {16F67783-7E72-4C39-99C4-4780A8335484} - hxxp://www.syncmyride.com/Own/Modules/UploadDownload/applets/sync.cab DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/9/b/d/9bdc68ef-6a9f-4505-8fb8-d0d2d160e512/LegitCheckControl.cab DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.2.cab DPF: {4B48D5DF-9021-45F7-A240-60304302A215} - hxxp://download.microsoft.com/download/5/c/2/5c2fc4b7-3875-4eec-946b-ffe15472cabc/WebCleaner.cab DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} - hxxp://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} - hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1233307740348 DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1179870376303 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1179870328597 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {99FE5072-78AA-4FEE-89BA-69A5FA55343F} - hxxp://download.microsoft.com/download/B/3/A/B3A2EA73-793D-4ABE-992D-C81140384044/igdtoolx.cab DPF: {A5A76EA0-7B92-4707-9DBF-6F6FE56A6800} - hxxp://scan.networkmagic.com/nmscan/download/WebDiag.4.5.8056.1-ship-WD.V1.cab DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://driveragent.com/files/driveragent.cab DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} - hxxp://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326 DPF: {FC6703A7-5B7E-4f58-BE6D-2693AA3906AE} - hxxp://h30155.www3.hp.com/ediags/hpna/66/install/gtdownhp.cab?1,0,0,94 DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\platform\puresp3.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: avgrsstarter - avgrsstx.dll Notify: System Safety Monitor - SSMWinlogonEx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: {1214FBE7-4464-4A7E-9958-B5851A7A30A3} - No File LSA: Authentication Packages = msv1_0 relog_ap Hosts: 127.0.0.1 www.spywareinfo.com ============= SERVICES / DRIVERS =============== R0 hotcore3;hc3ServiceName;c:\windows\system32\drivers\hotcore3.sys [2009-8-29 40560] R0 PQV2i;PQV2i;c:\windows\system32\drivers\PQV2i.sys [2004-2-25 138118] R0 RVSDISK;RVSDISK;c:\windows\system32\drivers\RVSDISK.sys [2008-12-26 11904] R0 RVSYSTEM;RVSYSTEM;c:\windows\system32\drivers\RVSYSTEM.sys [2008-12-26 38272] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-7-8 216400] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-7-8 29584] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-7-8 243024] R1 HFCore;HFCore;c:\windows\system32\drivers\HFCore.sys [2006-5-30 18816] R1 HWiNFO32;HWiNFO32 Kernel Driver;c:\program files\hwinfo32\HWiNFO32.SYS [2009-12-23 20088] R1 PQIMount;PQIMount;c:\windows\system32\drivers\PQIMount.sys [2004-2-25 46773] R1 PSSDK42;PSSDK42;c:\windows\system32\drivers\pssdk42.sys [2009-8-7 38976] R1 RapportCerberus_19917;RapportCerberus_19917;c:\documents and settings\all users\application data\trusteer\rapport\store\exts\rapportcerberus\19917\RapportCerberus_19917.sys [2010-10-3 34792] R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2010-10-3 169320] R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\drivers\StarPortLite.sys [2007-10-3 85760] R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2006-4-18 528128] R2 ASTRA32;ASTRA32 Kernel Driver 5.2.1.0;c:\program files\astra32\astra32.sys [2007-2-22 30864] R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-7-16 921952] R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-7-16 308136] R2 IS360service;IS360service;c:\program files\iobit\iobit security 360\is360srv.exe [2009-9-17 305936] R2 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2010-10-3 767208] R2 USBSafelyRemoveService;USB Safely Remove Assistant;c:\program files\usb safely remove\USBSRService.exe [2009-8-20 213776] R3 DsAudioDevice_286;DsAudioDevice_286;c:\windows\system32\drivers\DsAudioDevice_286.sys [2008-12-24 16640] S0 safemon;System Safety Monitor 2.0 Core Engine;c:\windows\system32\drivers\safemon.sys [2007-1-29 216144] S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\tffsmon.sys –> c:\windows\system32\drivers\TfFsMon.sys [?] S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\tfsysmon.sys –> c:\windows\system32\drivers\TfSysMon.sys [?] S2 aawservice;Lavasoft Ad-Aware Service;"c:\program files\lavasoft\ad-aware\aawservice.exe" –> c:\program files\lavasoft\ad-aware\aawservice.exe [?] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-9-28 133104] S2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service –> c:\windows\system32\zonelabs\vsmon.exe -service [?] S3 DfSdkS;Defragmentation-Service;c:\program files\ashampoo\ashampoo winoptimizer 6\DfSdkS.exe [2010-7-23 406016] S3 GVTDrv;GVTDrv;c:\windows\system32\drivers\GVTDrv.sys [2006-4-9 23524] S3 SliceDisk5;SliceDisk5;c:\program files\partition find and mount\slicedisk.sys [2008-10-8 10240] S3 Systemometer;Systemometer;c:\program files\systemometer\sysmetersrvc.exe [2008-3-22 253952] S3 TfNetMon;TfNetMon; [x] S3 ultradfg;ultradfg;c:\windows\system32\drivers\ultradfg.sys [2008-11-13 24576] S3 VNic;ULan Network Driver Module;c:\windows\system32\drivers\vnic.sys –> c:\windows\system32\drivers\VNic.sys [?] S4 Fix-It Utilities 10 Essentials Task Manager;Fix-It Utilities 10 Essentials Task Manager;c:\progra~1\avanqu~1\fix-it\mxtask.exe -service –> c:\progra~1\avanqu~1\fix-it\mxtask.exe -Service [?] S4 Paragon System Backup Service;Paragon System Backup Service;d:\dottech\paragon system backup 9.5\program\dbhservice.exe [2010-5-6 150096] =============== Created Last 30 ================ 2010-10-07 15:55:22 1885464 —-a-w- c:\windows\system32\AutoPartNt.exe 2010-10-07 15:32:30 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-10-07 15:32:29 ——– d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-10-07 15:32:27 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-10-07 15:02:51 ——– d—–w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy 2010-10-06 20:55:43 239104 —-a-w- c:\windows\Ptimya.exe 2010-10-04 03:43:44 59240 —-a-w- c:\windows\system32\drivers\RapportKELL.sys 2010-09-27 20:57:44 2826240 —-a-w- c:\windows\system32\GPhotos.scr 2010-09-22 22:10:52 103864 —-a-w- c:\program files\internet explorer\plugins\nppdf32.dll 2010-09-17 10:19:10 ——– d—–w- c:\program files\Microsoft IntelliType Pro 2010-09-16 20:46:09 16928 ——w- c:\windows\system32\spmsgXP_2k3.dll 2010-09-16 20:45:39 40848 —-a-w- c:\windows\system32\drivers\point32.sys 2010-09-16 20:45:39 1461992 —-a-w- c:\windows\system32\wdfcoinstaller01009.dll 2010-09-16 11:22:48 ——– d—–w- c:\program files\Paragon Drive Copy 10 (Personal Special Edition) ==================== Find3M ==================== 2010-08-22 18:48:54 114176 —-a-w- c:\windows\system32\PCWizard.cpl 2010-08-17 13:17:06 58880 —-a-w- c:\windows\system32\spoolsv.exe 2010-08-01 11:15:18 22 –sha-w- c:\windows\Sys3390 SettingsCollection.bin 2010-07-22 15:49:15 590848 —-a-w- c:\windows\system32\rpcrt4.dll 2010-07-22 05:57:20 5120 —-a-w- c:\windows\system32\xpsp4res.dll 2010-07-21 01:22:46 1238528 —-a-w- c:\windows\system32\zpeng25.dll 2010-07-16 10:28:58 12536 —-a-w- c:\windows\system32\avgrsstx.dll 2008-08-08 11:51:28 225 -c–a-w- c:\program files\2JK6FJR4.bat 2006-05-03 09:06:54 163328 –sh–r- c:\windows\system32\flvDX.dll 2007-02-21 10:47:16 31232 –sh–r- c:\windows\system32\msfDX.dll ============= FINISH: 5:36:58.46 =============== RkU Version: 3.8.388.590, Type LE (SR2) ============================================== OS Name: Windows XP Version 5.1.2600 (Service Pack 3) Number of processors #2 ============================================== >Drivers ============================================== 0xBF0C9000 C:\WINDOWS\System32\ati3duag.dll 2637824 bytes (ATI Technologies Inc. , ati3duag.dll) 0x804D7000 C:\WINDOWS\system32\ntoskrnl.exe 2260992 bytes (Microsoft Corporation, NT Kernel & System) 0x804D7000 PnpManager 2260992 bytes 0x804D7000 RAW 2260992 bytes 0x804D7000 WMIxWDM 2260992 bytes 0xBF800000 Win32k 1855488 bytes 0xBF800000 C:\WINDOWS\System32\win32k.sys 1855488 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0xF6FD5000 C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 1564672 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Miniport Driver) 0xF7550000 PCI_PNP1564 1036288 bytes 0xF7550000 spny.sys 1036288 bytes 0xF7550000 sptd 1036288 bytes 0xBF34D000 C:\WINDOWS\System32\ativvaxx.dll 864256 bytes (ATI Technologies Inc. , Radeon Video Acceleration Universal Driver) 0xF73A1000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver) 0xBA604000 C:\WINDOWS\System32\vsdatant.sys 524288 bytes (Check Point Software Technologies LTD, ZoneAlarm Firewalling Driver) 0xBA593000 C:\WINDOWS\System32\Drivers\wdf01000.sys 462848 bytes (Microsoft Corporation, Kernel Mode Driver Framework Runtime) 0xBA36D000 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 458752 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0xF7309000 timntr.sys 438272 bytes (Acronis, Acronis True Image Backup Archive Explorer) 0xF6E2B000 C:\WINDOWS\system32\drivers\senfilt.sys 385024 bytes (Sensaura, Sensaura WDM 3D Audio Driver) 0xF6CD9000 C:\WINDOWS\system32\DRIVERS\update.sys 385024 bytes (Microsoft Corporation, Update Driver) 0xF6F66000 C:\WINDOWS\system32\DRIVERS\bcmwl5.sys 372736 bytes (Broadcom Corporation, Broadcom 802.11 Network Adapter wireless driver) 0xBA74C000 C:\WINDOWS\system32\DRIVERS\tcpip.sys 364544 bytes (Microsoft Corporation, TCP/IP Protocol Driver) 0xF72B0000 tdrpman.sys 364544 bytes (Acronis, Acronis Try&Decide; and Restore Points Volume Filter Driver) 0xF6C80000 C:\WINDOWS\System32\Drivers\Uim_IM.sys 364544 bytes (Paragon, Image Mounter) 0xB506F000 C:\WINDOWS\system32\DRIVERS\srv.sys 356352 bytes (Microsoft Corporation, Server driver) 0xBFFA0000 C:\WINDOWS\System32\ATMFD.DLL 286720 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver) 0xBF012000 C:\WINDOWS\System32\ati2dvag.dll 270336 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Display Driver) 0xF6EC9000 C:\WINDOWS\system32\drivers\smwdm.sys 270336 bytes (Analog Devices, Inc., SoundMAX Integrated Digital Audio ) 0xB5342000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack) 0xBA684000 C:\WINDOWS\System32\Drivers\SYMTDI.SYS 262144 bytes (Symantec Corporation, Network Dispatch Driver) 0xBF054000 C:\WINDOWS\System32\ati2cqag.dll 258048 bytes (ATI Technologies Inc., Central Memory Manager / Queue Server Module) 0xF6C44000 C:\WINDOWS\System32\Drivers\UimFIO.SYS 245760 bytes (Paragon, Image Mounter File I/O) 0xBA6EC000 C:\WINDOWS\System32\Drivers\avgtdix.sys 237568 bytes (AVG Technologies CZ, s.r.o., AVG Network connection watcher) 0xBF093000 C:\WINDOWS\System32\atikvmag.dll 221184 bytes (ATI Technologies Inc., Virtual Command And Memory Manager) 0xBA339000 C:\WINDOWS\System32\Drivers\avgldx86.sys 212992 bytes (AVG Technologies CZ, s.r.o., AVG AVI Loader Driver) 0xF750A000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT) 0xB549B000 C:\WINDOWS\system32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0xF7374000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver) 0xB4FCB000 C:\WINDOWS\system32\drivers\tmcomm.sys 180224 bytes (Trend Micro Inc., TrendMicro Common Module) 0xB3B67000 C:\WINDOWS\system32\drivers\kmixer.sys 176128 bytes (Microsoft Corporation, Kernel Mode Audio Mixer) 0xBA47E000 C:\WINDOWS\system32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0xBA42D000 C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys 167936 bytes (Trusteer Ltd., RapportPG) 0xBA6C4000 C:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver) 0xBA726000 C:\WINDOWS\system32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator) 0xB5256000 C:\WINDOWS\System32\Drivers\Fastfat.SYS 147456 bytes (Microsoft Corporation, Fast FAT File System Driver) 0xF6EA5000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0xF6F1F000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 147456 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0xF6F43000 C:\WINDOWS\system32\DRIVERS\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library) 0xBA549000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0x806FF000 ACPI_HAL 134400 bytes 0x806FF000 C:\WINDOWS\system32\hal.dll 134400 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0xF746E000 fltmgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0xF74DA000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver) 0xF727D000 snapman.sys 126976 bytes (Acronis, Acronis Snapshot API) 0xF6E89000 C:\WINDOWS\system32\drivers\aeaudio.sys 114688 bytes (Andrea Electronics Corporation, Andrea Audio Noise Cancellation Driver) 0xF7263000 Mup.sys 106496 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0xF748E000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver) 0xF7538000 C:\WINDOWS\System32\Drivers\SCSIPORT.SYS 98304 bytes (Microsoft Corporation, SCSI Port Driver) 0xF6E14000 C:\WINDOWS\System32\Drivers\ezplay.sys 94208 bytes (VSO Software, Helper driver to facilitate play of cd backups) 0xF7441000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0xF6D5D000 C:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0xF7458000 PQV2i.sys 90112 bytes (StorageCraft, StorageCraft Volume Snap-Shot) 0xF6D37000 C:\WINDOWS\system32\DRIVERS\StarPortLite.sys 86016 bytes (Rocket Division Software, StarPort Storage Controller Lite) 0xB4926000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper) 0xF6F0B000 C:\WINDOWS\system32\DRIVERS\parport.sys 81920 bytes (Microsoft Corporation, Parallel Port Driver) 0xF729C000 srescan.sys 81920 bytes 0xF6FC1000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver) 0xBA7A5000 C:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver) 0xF742E000 WudfPf.sys 77824 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver) 0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver) 0xF74F9000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0xF6D4C000 C:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler) 0xF6DB4000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver) 0xF776E000 C:\WINDOWS\system32\DRIVERS\cdrom.sys 65536 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0xF778E000 C:\WINDOWS\system32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver) 0xF77AE000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0xF777E000 C:\WINDOWS\system32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver) 0xB548B000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter) 0xF78BE000 C:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB) 0xF6D94000 C:\WINDOWS\system32\DRIVERS\WDFLDR.SYS 57344 bytes (Microsoft Corporation, Kernel Mode Driver Framework Loader) 0xF76BE000 C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll) 0xF779E000 C:\WINDOWS\system32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver) 0xF77FE000 C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0xF768E000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0xF785E000 C:\WINDOWS\System32\Drivers\pcouffin.sys 49152 bytes (VSO Software, low level access layer for CD/DVD/BD devices) 0xF6D84000 C:\WINDOWS\system32\Drivers\pssdk42.sys 49152 bytes (microOLAP Technologies LTD, PSSDK Driver Protocol v4.2 32bit) 0xF781E000 C:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0xF77EE000 C:\WINDOWS\system32\drivers\tshd4_kern_i386.sys 49152 bytes (-, SRS Labs TruSurround HD 4 kernel DLL) 0xF784E000 C:\WINDOWS\System32\Drivers\Fips.SYS 45056 bytes (Microsoft Corporation, FIPS Crypto Driver) 0xF775E000 C:\WINDOWS\system32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver) 0xF767E000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager) 0xF780E000 C:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0xF77DE000 C:\WINDOWS\system32\drivers\surroundhp_kern_i386.sys 45056 bytes (-, SRS Labs Surround HD kernel DLL) 0xF76DE000 uagp35.sys 45056 bytes (Microsoft Corporation, MS AGPv3.5 Filter) 0xF77CE000 C:\WINDOWS\system32\drivers\csiidecoder_kern_i386.sys 40960 bytes (-, SRS Labs CSII Decoder Kernel DLL) 0xF766E000 isapnp.sys 40960 bytes (Microsoft Corporation, PNP ISA Bus Driver) 0xF788E000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy) 0xF76EE000 RVSYSTEM.sys 40960 bytes (Returnil SIA, Returnil Virtual System 2008) 0xF786E000 C:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver) 0xB5A60000 C:\WINDOWS\system32\DRIVERS\tifsfilt.sys 40960 bytes (Acronis, Acronis True Image File System Filter) 0xF76AE000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver) 0xF769E000 C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS 36864 bytes (Microsoft Corporation, Hid Class Library) 0xF774E000 C:\WINDOWS\system32\DRIVERS\intelppm.sys 36864 bytes (Microsoft Corporation, Processor Device Driver) 0xF782E000 C:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier) 0xF6D74000 C:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver) 0xB3CD2000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver) 0xF6DA4000 C:\WINDOWS\system32\DRIVERS\point32.sys 36864 bytes (Microsoft Corporation, Point32k.sys) 0xF783E000 C:\WINDOWS\System32\Drivers\PQIMount.SYS 36864 bytes (PowerQuest Corporation, PQIMount.sys - PQI Image Mounting Device Driver) 0xF76CE000 PxHelp20.sys 36864 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP) 0xF77BE000 C:\WINDOWS\system32\drivers\srs_sscfilter.sys 36864 bytes (-, SRS WOW HD, TSXT, CSII, Mobile HD Standalone driver) 0xF78DE000 C:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0xF79C6000 C:\WINDOWS\System32\Drivers\Modem.SYS 32768 bytes (Microsoft Corporation, Modem Device Driver) 0xF796E000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver) 0xF7A26000 C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\19917\RapportCerberus_19917.sys 32768 bytes (Trusteer Ltd., RapportCerberus) 0xF7956000 C:\WINDOWS\system32\DRIVERS\usbehci.sys 32768 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0xF79A6000 C:\WINDOWS\system32\drivers\wowhd_kern_i386.sys 32768 bytes (SRS Labs, Inc., WOW HD kernel mode DLL for Windows) 0xF7966000 C:\WINDOWS\system32\DRIVERS\fdc.sys 28672 bytes (Microsoft Corporation, Floppy Disk Controller Driver) 0xF79EE000 C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS 28672 bytes (Microsoft Corporation, Hid Parsing Library) 0xF78EE000 C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0xF7A2E000 C:\WINDOWS\system32\DRIVERS\UimBus.sys 28672 bytes (Windows ® 2000 DDK provider, Image Mounter SCSI Port Driver) 0xF7A06000 C:\WINDOWS\System32\Drivers\avgmfx86.sys 24576 bytes (AVG Technologies CZ, s.r.o., AVG Resident Shield Minifilter Driver) 0xF793E000 C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 24576 bytes (GEAR Software Inc., CD DVD Filter) 0xF7976000 C:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver) 0xF7A16000 C:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver) 0xF794E000 C:\WINDOWS\system32\DRIVERS\usbuhci.sys 24576 bytes (Microsoft Corporation, UHCI USB Miniport Driver) 0xF792E000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0xB5AE8000 C:\Program Files\ASTRA32\ASTRA32.sys 20480 bytes (Licensed for Sysinfo Lab, Astra Generic Device Driver) 0xF79B6000 C:\WINDOWS\system32\drivers\DsAudioDevice_286.sys 20480 bytes (Wondershare, Wondershare Virtual Audio Device) 0xF7A66000 C:\WINDOWS\system32\DRIVERS\flpydisk.sys 20480 bytes (Microsoft Corporation, Floppy Driver) 0xF79D6000 C:\WINDOWS\system32\drivers\HFCore.sys 20480 bytes 0xF78FE000 hotcore3.sys 20480 bytes (Paragon Software Group, A part of Paragon System Utilities) 0xF7946000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver) 0xF78F6000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager) 0xF795E000 C:\WINDOWS\system32\DRIVERS\pnarp.sys 20480 bytes (Pure Networks, Inc., Address Resolution Protocol Driver) 0xF79FE000 C:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library) 0xF7A3E000 C:\WINDOWS\system32\DRIVERS\purendis.sys 20480 bytes (Pure Networks, Inc., NDIS Relay Driver) 0xF7A0E000 C:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver) 0xF79E6000 C:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper) 0xF7A76000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver) 0xBA577000 C:\Program Files\HWiNFO32\HWiNFO32.SYS 16384 bytes (REALiX™, HWiNFO32 Kernel Driver) 0xF7193000 C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver) 0xB58E8000 C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver) 0xF71C7000 C:\WINDOWS\system32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator) 0xF7A7E000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver) 0xBA311000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver) 0xF6B90000 C:\WINDOWS\System32\Drivers\FileDisk.sys 12288 bytes (Bo Brantén, FileDisk Virtual Disk Driver) 0xF71AF000 C:\WINDOWS\system32\DRIVERS\hidusb.sys 12288 bytes (Microsoft Corporation, USB Miniport Driver for Input Devices) 0xF71A3000 C:\WINDOWS\system32\DRIVERS\mouhid.sys 12288 bytes (Microsoft Corporation, HID Mouse Filter Driver) 0xF71B7000 C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0xF71DF000 C:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0xF7A82000 RVSDISK.sys 12288 bytes 0xF716B000 C:\WINDOWS\System32\Drivers\vulfntr.sys 12288 bytes (VIA Technologies, Inc., VIA USB Roothub Lower Filter Driver) 0xF7B7C000 C:\WINDOWS\system32\DRIVERS\ASACPI.sys 8192 bytes (-, ATK0110 ACPI Utility) 0xF7C04000 C:\WINDOWS\system32\drivers\AsIO.sys 8192 bytes 0xF7BA4000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver) 0xF7BA0000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver) 0xF7B6E000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0xF7BA8000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator) 0xF7C1A000 C:\WINDOWS\System32\Drivers\ParVdm.SYS 8192 bytes (Microsoft Corporation, VDM Parallel Driver) 0xF7BAC000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport) 0xF7B84000 C:\WINDOWS\System32\Drivers\RootMdm.sys 8192 bytes (Microsoft Corporation, Legacy Non-Pnp Modem Device Driver) 0xF7B74000 speedfan.sys 8192 bytes 0xF7B94000 C:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0xF7B9C000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) 0xF7B72000 viaide.sys 8192 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver) 0xF7B78000 C:\WINDOWS\System32\Drivers\vulfnth.sys 8192 bytes (VIA Technologies, Inc., VIA USB Host Controller Lower Filter Driver) 0xF7B70000 C:\WINDOWS\System32\Drivers\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0xF7DC4000 C:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver) 0xF7DA9000 C:\WINDOWS\System32\Drivers\BANTExt.sys 4096 bytes 0xF7C90000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk) 0xF7C36000 giveio.sys 4096 bytes 0xF7D06000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver) 0x873641F8 unknown_irp_handler 3592 bytes 0x85FED1F8 unknown_irp_handler 3592 bytes 0x873661F8 unknown_irp_handler 3592 bytes 0x8713A1F8 unknown_irp_handler 3592 bytes 0x872631F8 unknown_irp_handler 3592 bytes 0x868971F8 unknown_irp_handler 3592 bytes 0x87150500 unknown_irp_handler 2816 bytes 0x872E9500 unknown_irp_handler 2816 bytes 0x868EC500 unknown_irp_handler 2816 bytes !!!!!!!!!!!Hidden driver: 0x86E57AEA ?_empty_? 1302 bytes !!!!!!!!!!!Hidden driver: 0x8733EA10 ?_empty_? 0 bytes ============================================== >Stealth ============================================== 0xF748E000 WARNING: suspicious driver modification [atapi.sys::0x86E57AEA] WARNING: Virus alike driver modification [AsInsHelp32.sys] WARNING: Virus alike driver modification [symdns.sys] WARNING: Virus alike driver modification [cpqdap01.sys] WARNING: Virus alike driver modification [AsInsHelp64.sys] WARNING: Virus alike driver modification [nikedrv.sys] WARNING: Virus alike driver modification [rio8drv.sys] WARNING: Virus alike driver modification [riodrv.sys] WARNING: Virus alike driver modification [ws2ifsl.sys] WARNING: Virus alike driver modification [fsvga.sys] WARNING: Virus alike driver modification [SYMEVENT.SYS] WARNING: Virus alike driver modification [imagesrv.sys] WARNING: Virus alike driver modification [smclib.sys] WARNING: Virus alike driver modification [symfw.sys] WARNING: Virus alike driver modification [tsbvcap.sys] WARNING: Virus alike driver modification [cinemst2.sys] WARNING: Virus alike driver modification [atmepvc.sys] WARNING: Virus alike driver modification [rawwan.sys] WARNING: Virus alike driver modification [atmuni.sys] WARNING: Virus alike driver modification [symids.sys] WARNING: Virus alike driver modification [wpdusb.sys] WARNING: File locked for read access [C:\WINDOWS\system32\drivers\sptd.sys] WARNING: Virus alike driver modification [ASUSHWIO.SYS] WARNING: Virus alike driver modification [imagedrv.sys] WARNING: Virus alike driver modification [nwlnknb.sys] WARNING: Virus alike driver modification [mcd.sys] Hopefully this is what you'll need? jmac0408

Attachments:

Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
CatByte: I disabled WinPatrol, ZoneAlarm and AVG Free 9 and then downloaded/saved ComboFix to the desktop as per your instruction. I double-clicked on the ComboFix.exe icon on my desktop and clicked the "Run" button and then nothing!! No activity whatsoever. I waited about 5-7 minutes and then deleted the desktop icon for ComboFix.exe and tried the process again only this time using the "Link 2" option. Again, the exact same ocurred, i.e. NOTHING! What should I do now? Thanks for all your help! jmac0408
Hi

please delete the copy of combofix that you have on your desktop and download a fresh copy, but rename it to Combo.com before saving it to your desktop and try running it again

if it will not run, then try running it in sfae mode

make sure your file extensions are showing or you will end up with combo.com.exe

  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Clear "Hide file extensions for known file types."
  • Click Apply, and then click OK.

To enter into safe mode reboot > tap F8 repeatedly upon startup until an option menu appears > arrow up to safe mode.
Hi

Please do the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Good Morning, CatByte: I did not start your latest set of instructions until early this morning. At startup/boot this morning (after running ComboFix the night before and then posting and shutting down for the night), I noticed several "different"/unusual ocurrences: 1. WinPatrol advised that there had been a change in the IE search engine from Google to IE search (for which I selected YES) ???? 2. WinPatrol advised/alerted that there had been a File Type Change Alert! = .URL. Program Currently associated is: Run a DLL as an APP. C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ieframe.dll, OpenURL %1. A change was made to use the following program for this file type: RUN a DLL as an APP. rundll32.exe ieframe.dll, OpenURL %1. (I selected YES) ???? There was also an IE icon/shortcut on my Desktop!!??? (which had previously not been present!). CONTINUED: (@ ~ 3:45 pm): As I mentioned previously, I had uninstalled both SpyBot S&D 1.6.2 and Malwarebytes AntiMalware 1.46 because I "assumed" they were corrupted/infected. So, I d/l Malwarebytes AntiMalware 1.46 successfully and updated it successfully. I ran the scan and hopefully have saved the generated "log.txt. I then ran the Kaspersky Online Scan which required EIGHT HOURS and TWENTY minutes FORTY ONE SECONDS to complete successfully!!! (Isn't that an inordinately long time for the scan????) None the less, please find the results for your inspection. Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4820 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 14/10/2010 6:09:56 AM mbam-log-2010-10-14 (06-09-56).txt Scan type: Quick scan Objects scanned: 138727 Time elapsed: 6 minute(s), 4 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\Ptimya.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Thursday, October 14, 2010 Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Thursday, October 14, 2010 00:15:22 Records in database: 4199346 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ F:\ Scan statistics: Objects scanned: 165643 Threats found: 11 Infected objects found: 14 Suspicious objects found: 0 Scan duration: 08:20:41 File name / Threat / Threats count C:\Documents and Settings\John\My Documents\My Pictures\InboxScreensaver.exe Infected: not-a-virus:AdWare.Win32.WebSearch.bv 1 C:\Program Files\Axence\NetTools\3.1\agents\nvagentinstall.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.c 1 C:\Program Files\Icon Commander\Setup.exe Infected: Constructor.Win32.Downldr.ns 1 C:\Program Files\PDF to Text\pdf2text.exe Infected: Trojan.Win32.Vilsel.aban 1 C:\Program Files\VideoCacheView\VideoCacheView.exe Infected: not-a-virus:PSWTool.Win32.NetPass.on 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\UimBus.sys.vir Infected: Virus.Win32.TDSS.b 1 C:\System Volume Information\_restore{708D6B8D-067D-40DC-9D19-3056ED47A3FC}\RP1\A0000062.sys Infected: Virus.Win32.TDSS.b 1 C:\UBCD4Win\plugin\Disk\Partition\MbrFix\MbrFix.exe Infected: not-a-virus:RiskTool.Win32.MBRFix.a 1 C:\UBCD4Win\plugin\Network\CrossLoop\files\VNCHooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b 1 C:\UBCD4Win\plugin\Network\CrossLoop\files\winvnc.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.h 1 C:\UBCD4Win\plugin\Network\ultravnc\files\sfx\winvnc.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.ac 1 C:\UBCD4Win\plugin\Network\ultravnc\files\winvnc.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.ac 1 C:\UBCD4Win\plugin\Network\VNCServer\vncconfig.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.ad 1 C:\UBCD4Win\plugin\Network\VNCServer\winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.ad 1 Selected area has been scanned.
Hi,

Please do the following:
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

File::
C:\Documents and Settings\John\My Documents\My Pictures\InboxScreensaver.exe 
C:\Program Files\Icon Commander\Setup.exe 
C:\Program Files\PDF to Text\pdf2text.exe

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]

  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT


Please advise how the computer is running and if there are any outstanding issues.

ComboFix does reset a number of different default items, the IE icon being one of them.
CatByte: Here is the real-time Report log fromComboFix: 10-10-12.03 - John 14/10/2010 17:05:10.2.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.2.1033.18.1023.581 [GMT -4:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\John\Desktop\CFScript.txt AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} FW: ZoneAlarm Pro Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B} FILE :: "c:\documents and settings\John\My Documents\My Pictures\InboxScreensaver.exe" "c:\program files\Icon Commander\Setup.exe" "c:\program files\PDF to Text\pdf2text.exe" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\John\My Documents\My Pictures\InboxScreensaver.exe c:\program files\Icon Commander\Setup.exe c:\program files\PDF to Text\pdf2text.exe . ((((((((((((((((((((((((( Files Created from 2010-09-14 to 2010-10-14 ))))))))))))))))))))))))))))))) . 2010-10-14 20:10 . 2010-10-14 20:15 ——– d—–w- c:\program files\Spybot - Search & Destroy 2010-10-14 10:00 . 2010-10-14 20:01 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-09-22 22:10 . 2010-09-22 22:10 103864 —-a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll 2010-09-17 10:19 . 2010-09-17 10:19 ——– d—–w- c:\program files\Microsoft IntelliType Pro 2010-09-16 20:46 . 2008-11-07 22:55 16928 ——w- c:\windows\system32\spmsgXP_2k3.dll 2010-09-16 20:45 . 2010-07-21 20:52 40848 —-a-w- c:\windows\system32\drivers\point32.sys 2010-09-16 20:45 . 2010-07-21 20:52 1461992 —-a-w- c:\windows\system32\wdfcoinstaller01009.dll 2010-09-16 11:22 . 2010-09-16 12:00 ——– d—–w- c:\program files\Paragon Drive Copy 10 (Personal Special Edition) . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2006-05-03 09:06 163328 –sh–r- c:\windows\system32\flvDX.dll 2007-02-21 10:47 31232 –sh–r- c:\windows\system32\msfDX.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WeatherWatcher"="c:\program files\Weather Watcher\ww.exe" [2009-07-08 1110016] "SkinClock"="c:\program files\Atomic Alarm Clock\AtomicAlarmClock.exe" [2008-09-23 1739264] "RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2010-06-24 160328] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WinPatrol"="c:\program files\WinPatrol\winpatrol.exe" [2010-05-31 323976] "Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2009-10-27 365560] "ZoneAlarm Client"="c:\program files\ZoneAlarm\zlclient.exe" [2010-07-21 1038848] "TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2008-04-10 2595792] "AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2008-04-10 909208] "AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-10-05 2067808] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2010-07-21 1797008] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] c:\documents and settings\John\Start Menu\Programs\Startup\ CleanCache3StartupExit.lnk - c:\program files\CleanCache 3.0\CleanCache.exe [2006-6-6 655360] ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Sentinel.lnk - c:\program files\Sentinel2\Sentinel2\Sentinel.exe [2006-4-20 1060893] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2010-07-16 10:28 12536 —-a-w- c:\windows\system32\avgrsstx.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\System Safety Monitor] 2007-01-29 15:59 51152 —-a-w- c:\windows\system32\SSMWinlogonEx.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe "WinPatrol System Monitor"=c:\program files\WinPatrol\WinPatrol.exe "Cute Organizer"=c:\program files\Cute Organizer\Organizer.exe "WiTS"="c:\program files\Windows Inspection Tool Set\wits.exe" -iconify "eReminder TopBar"="c:\program files\eTimeInc\eReminder 2008\Bin\eTopBar.exe" "Linkman"= "Advanced SystemCare 3"= "Eraser"=c:\program files\Eraser\eraser.exe -hide "SpybotSD TeaTimer"= [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "NeroFilterCheck"=c:\windows\system32\NeroCheck.exe "Acronis True Image Monitor"= "Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" "UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" "NeroCheck"=c:\windows\system32\NeroCheck.exe "SunJavaUpdateSched"= "itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" "nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash "MuralPixAgent"=c:\program files\MuralPix\MpAgent.exe /r "Adobe Reader Speed Launcher"= "SmartToDo"="c:\program files\Smart To-Do\SmartToDo.exe" minimize "GPPrinterNotify"="c:\program files\GreenPrint Technologies\GreenPrint World\GPPrinterNotify.exe" "nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" "ZoneAlarm Client"="c:\program files\ZoneAlarm\zlclient.exe" "Rvsystem"=c:\progra~1\Returnil\Returnil.exe "ProcessLassoManagementConsole"=c:\program files\Process Lasso\processlasso.exe "ProcessGovernor"=c:\program files\Process Lasso\processgovernor.exe "adm_tray.exe"=c:\program files\Acronis\DriveMonitor\adm_tray.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\WINDOWS\\system32\\usmt\\migwiz.exe"= "c:\\Program Files\\GigaByte\\VGA Utility Manager\\G-vga.exe"= "c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"= "c:\\Program Files\\LimeWire\\LimeWire.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Axence\\NetTools\\3.1\\nVision.exe"= "c:\\Program Files\\MailStore Home\\MailStoreDesktopServices.exe"= "c:\\Program Files\\IEPro\\MiniDM.exe"= "c:\\Program Files\\eMule\\emule.exe"= "c:\\Program Files\\IE7Pro\\IEPro\\MiniDM.exe"= "c:\\Program Files\\AVG\\AVG9\\avgemc.exe"= "c:\\Program Files\\AVG\\AVG9\\avgupd.exe"= "c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "67:UDP"= 67:UDP:DHCP Discovery Service "4434:TCP"= 4434:TCP:nVision Agent Data Server R0 hotcore3;hc3ServiceName;c:\windows\system32\drivers\hotcore3.sys [29/08/2009 6:00 AM 40560] R0 PQV2i;PQV2i;c:\windows\system32\drivers\PQV2i.sys [25/02/2004 2:19 PM 138118] R0 RVSDISK;RVSDISK;c:\windows\system32\drivers\RVSDISK.sys [26/12/2008 5:00 AM 11904] R0 RVSYSTEM;RVSYSTEM;c:\windows\system32\drivers\RVSYSTEM.sys [26/12/2008 5:00 AM 38272] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [08/07/2009 2:49 PM 216400] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [08/07/2009 2:49 PM 243024] R1 HFCore;HFCore;c:\windows\system32\drivers\HFCore.sys [30/05/2006 7:46 AM 18816] R1 HWiNFO32;HWiNFO32 Kernel Driver;c:\program files\HWiNFO32\HWiNFO32.SYS [23/12/2009 6:35 PM 20088] R1 PQIMount;PQIMount;c:\windows\system32\drivers\PQIMount.sys [25/02/2004 2:19 PM 46773] R1 PSSDK42;PSSDK42;c:\windows\system32\drivers\pssdk42.sys [07/08/2009 5:59 AM 38976] R1 RapportCerberus_19917;RapportCerberus_19917;c:\documents and settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\19917\RapportCerberus_19917.sys [03/10/2010 11:54 PM 34792] R1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [03/10/2010 11:43 PM 169320] R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\drivers\StarPortLite.sys [03/10/2007 8:00 AM 85760] R2 ASTRA32;ASTRA32 Kernel Driver 5.2.1.0;c:\program files\ASTRA32\astra32.sys [22/02/2007 11:28 AM 30864] R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [16/07/2010 6:28 AM 921952] R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [16/07/2010 6:28 AM 308136] R2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [17/09/2009 2:55 PM 305936] R2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [03/10/2010 11:43 PM 767208] R2 USBSafelyRemoveService;USB Safely Remove Assistant;c:\program files\USB Safely Remove\USBSRService.exe [20/08/2009 8:06 AM 213776] R3 DsAudioDevice_286;DsAudioDevice_286;c:\windows\system32\drivers\DsAudioDevice_286.sys [24/12/2008 8:31 PM 16640] S0 safemon;System Safety Monitor 2.0 Core Engine;c:\windows\system32\drivers\safemon.sys [29/01/2007 11:58 AM 216144] S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys –> c:\windows\system32\drivers\TfFsMon.sys [?] S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys –> c:\windows\system32\drivers\TfSysMon.sys [?] S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [28/09/2009 3:27 PM 133104] S3 DfSdkS;Defragmentation-Service;c:\program files\Ashampoo\Ashampoo WinOptimizer 6\DfSdkS.exe [23/07/2010 6:47 AM 406016] S3 GVTDrv;GVTDrv;c:\windows\system32\drivers\GVTDrv.sys [09/04/2006 12:15 AM 23524] S3 SliceDisk5;SliceDisk5;c:\program files\Partition Find and Mount\slicedisk.sys [08/10/2008 4:58 AM 10240] S3 Systemometer;Systemometer;c:\program files\Systemometer\sysmetersrvc.exe [22/03/2008 11:30 PM 253952] S3 TfNetMon;TfNetMon; [x] S3 ultradfg;ultradfg;c:\windows\system32\drivers\ultradfg.sys [13/11/2008 5:52 AM 24576] S3 VNic;ULan Network Driver Module;c:\windows\system32\DRIVERS\VNic.sys –> c:\windows\system32\DRIVERS\VNic.sys [?] S4 Fix-It Utilities 10 Essentials Task Manager;Fix-It Utilities 10 Essentials Task Manager;c:\progra~1\AVANQU~1\Fix-It\mxtask.exe -Service –> c:\progra~1\AVANQU~1\Fix-It\mxtask.exe -Service [?] S4 Paragon System Backup Service;Paragon System Backup Service;d:\dottech\Paragon System Backup 9.5\program\dbhservice.exe [06/05/2010 3:05 PM 150096] S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [03/10/2007 8:00 AM 716272] . Contents of the 'Scheduled Tasks' folder 2010-05-13 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:50] 2010-09-16 c:\windows\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job - c:\program files\Microsoft IntelliPoint\ipoint.exe [2010-07-21 20:52] 2010-09-17 c:\windows\Tasks\Microsoft_Hardware_Launch_IType_exe.job - c:\program files\Microsoft IntelliType Pro\itype.exe [2010-07-21 21:07] 2010-10-14 c:\windows\Tasks\User_Feed_Synchronization-{25356BFB-3FF3-4E3A-98E3-EAEAF7903AAC}.job - c:\windows\system32\msfeedssync.exe [2006-10-17 09:31] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.cbc.ca uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8 uDefault_Search_URL = hxxp://www.google.com/ie uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie IE: &Clean; Traces - c:\program files\DownloadAcceleratorPlus (DAP)\Privacy Package\dapcleanerie.htm IE: &Compress; Image Using Image Compressor 2008 - c:\program files\Image Compressor 2008 Pro\imcieex_compress.html IE: &Download; with &DAP; - c:\program files\DownloadAcceleratorPlus (DAP)\dapextie.htm IE: >Search in Linkman - file://c:\documents and settings\John\My Documents\Linkman\iescript_search.htm IE: Add to EverNote - c:\program files\EverNote\EverNote\enbar.dll/2000 IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200 IE: Add to Linkman - file://c:\documents and settings\John\My Documents\Linkman\iescript_add.htm IE: Add to Linkman and Edit - file://c:\documents and settings\John\My Documents\Linkman\iescript_edit.htm IE: Capture image with GKB - IE: Capture web page with GKB - IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html IE: Download &all; with DAP - c:\program files\DownloadAcceleratorPlus (DAP)\dapextie2.htm IE: Enqueue current page with Bulk Image Downloader - file://c:\program files\Bulk Image Downloader\iemenu\iebidqueue.htm IE: Enqueue link target with Bulk Image Downloader - file://c:\program files\Bulk Image Downloader\iemenu\iebidlinkqueue.htm IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html IE: Free YouTube to Mp3 Converter - c:\documents and settings\John\Application Data\DVDVideoSoftIEHelpers\youtubetomp3.htm IE: Open current page with Bulk Image Downloader - file://c:\program files\Bulk Image Downloader\iemenu\iebid.htm IE: Open link target with Bulk Image Downloader - file://c:\program files\Bulk Image Downloader\iemenu\iebidlink.htm IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html IE: Save YouTube Video as MP3 - c:\program files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm IE: Show Linkman - file://c:\documents and settings\John\My Documents\Linkman\iescript_show.htm DPF: {16F67783-7E72-4C39-99C4-4780A8335484} - hxxp://www.syncmyride.com/Own/Modules/UploadDownload/applets/sync.cab DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab DPF: {A5A76EA0-7B92-4707-9DBF-6F6FE56A6800} - hxxp://scan.networkmagic.com/nmscan/download/WebDiag.4.5.8056.1-ship-WD.V1.cab . . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" [HKEY_LOCAL_MACHINE\software\Microsoft\EncryptionInterface*] "l_encryption_d"="585A4A574A5F" [HKEY_LOCAL_MACHINE\software\Xanthic\{EAC0842F-9764-03DD-A0B6-5FFFB48AD6EB}*_] "fr"="0781794A535D5F" "lr"="0781675E585D5F" . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'winlogon.exe'(1024) c:\windows\system32\Ati2evxx.dll c:\windows\system32\SSMWinlogonEx.dll - - - - - - - > 'lsass.exe'(1080) c:\windows\system32\relog_ap.dll . Completion time: 2010-10-14 17:16:51 ComboFix-quarantined-files.txt 2010-10-14 21:16 ComboFix2.txt 2010-10-14 02:34 Pre-Run: 124,301,180,928 bytes free Post-Run: 124,278,779,904 bytes free - - End Of File - - 4A732D56DD9B5EE3644ABA9C61F442DA ComboFix.exe My system seems to be running more "normally" at present - I have been able to reinstall and successfully run/scan/update both Malwarebytes AntiMalware and SpyBot S&D.; I appreciate your adding the comment about changes such as the IE icon on the desktop via ComboFix. I truly appreciate all your detailed assistance, patience and knowledge in the attempted resolution of my ISSUE!! Best Regards and HUMBLE THANKS. jmac0408
Hi

Just some housekeeping to do now, please do the following:



P2P - I see you have P2P software LimeWire 5.4.6 installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It may be contributing to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall this now. You can do so via Control Panel >> Add or Remove Programs.


NEXT



Visit ADOBEand download the latest version of Acrobat Reader (version 9.4)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT

[external image: Posted Image]Your Java is out of date.
Java™ 6 Update 21 can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.
An update should begin; > follow the prompts.


Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup) If you do not see the icon, look to your left and click 'Switch to Classic View'.
  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • There are two options in the window to clear the cache - Leave BOTH Checked
  • Applications and Applets
    Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT


You can delete the MBRCheck, DDS and RKU folders from your desktop.


NEXT

Follow these steps to uninstall Combofix
Make sure your security programs are totally disabled.
Click START then RUN
Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.


[external image: Posted Image]


If there are any logs/tools remaining > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
  • Strong passwords: How to create and use them Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/

    This will ensure your computer has always the latest security updates available installed on your computer.


  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.


  • DownloadTFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    • It's normal after running TFC cleaner that the PC will be slower to boot the first time.


  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Greento go
    • Yellow for caution
    • Red to stop
    • WOT has an addon available for both Firefox and IE


  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
  • Think Prevention.
  • PC Safety and Security–What Do I Need?.

**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Hi CatByte:

So, I've uninstalled LimeWire 5.4.6 (although I should mention that I ALWAYS scanned any d/l files from the program with 2 or more AV/Anti-/Malware apps/utilities for any possible infection(s)).

I updated my Adobe Reader 9.4.0 and JRE 6 to Update 22.

I deleted MBRCheck, DDS and RKU.

I could not, however, uninstall ComboFix via Start/Run with "Combofix /Uninstall" !!! {See attached screenshot.} Can I simply delete the shortcut/executable via a Right-Click??

I followed and performed all your suggestions re Internet Explorer and d/l and ran TFC.

I will do my best to follow your suggestions re Passwords but admittedly this will be a tough one to adhere to a regimen of frequent changing of same!!

I will assess and Review WOT and most likely install it on my system! I already had ERUNT installed on C:\. I do weekly backups of my system via Acronis True Image and save them to an external HD.
Hi

Please download a fresh copy of combofix to your desktop then uninstall it via the run command Combofix /uninstall

it performs important cleanup routines when uninstalling;

thanks

Link 1

(if you still have the icon on your desktop > right click and delete it, before downloading the fresh one)
Still no luck with uninstalling ComboFix via Start/Run and the command "combofix /uninstall"!! Any further instruction?/suggestions? jmac0408

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI