This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan generator changed internet speed

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

clicked a file and thought it was something else, turns out it was Windows defragmenter, and it would not go away,
finally after Using AVG, Malwarebytes, Spyware Doctor, and SuperAntispyware, Even in safemode, got rid of it,
but then stuff started acting bogged down, and im still detecting trojans each time I scan! Even tried online scanner!
Internet Exploer doesn't work.
Mozilla is slow to load or I have to keep hitting retry to go to a page!
Google Chrome works for awile before giving me the blue screen of death!
Im using "The world Browser right now, and it acts alittle better but it gets a broken connection too allot of the time!
And I have High speed internet, so something has changed, so im using Hyjackthis, in hopes someone has had this experience
im at my witts end, help please,
ill post my computer processes first, followed by my startup log.
Thank you in advance,


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:42:47 PM, on 10/22/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2900.5508)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\a\My Documents\runme\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: Shell=explorer.exe
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Foxit Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [Ppumijegohewateb] rundll32.exe "C:\WINDOWS\efaqeluwe.dll",Startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\a\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: ZDWLan Utility.lnk = C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1287643598401
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1287643966791
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Browser Defender Update Service - Unknown owner - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NIHardwareService - Native Instruments GmbH - C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

–
End of file - 6309 bytes




StartupList report, 10/23/2010, 1:53:43 AM
StartupList version: 1.52.2
Started from : C:\Documents and Settings\a\My Documents\runme\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 (6.00.2900.5508)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\TheWorld 2.0\TheWorld.exe
C:\Documents and Settings\a\My Documents\runme\HijackThis.exe

————————————————–

Listing of startup folders:

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
ZDWLan Utility.lnk = C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

SoundMAXPnP = C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
SoundMAX = "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
ATIPTA = C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
SynTPLpr = C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
SynTPEnh = C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
Zune Launcher = "C:\Program Files\Zune\ZuneLauncher.exe"
DivXUpdate = "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
Malwarebytes' Anti-Malware = "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
Ppumijegohewateb = rundll32.exe "C:\WINDOWS\efaqeluwe.dll",Startup

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
cdloader = "C:\Documents and Settings\a\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
swg = "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
SUPERAntiSpyware = C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–


Enumerating Task Scheduler jobs:

GoogleUpdateTaskMachineCore.job
GoogleUpdateTaskMachineUA.job
GoogleUpdateTaskUserS-1-5-21-299502267-854245398-1343024091-1003Core.job
GoogleUpdateTaskUserS-1-5-21-299502267-854245398-1343024091-1003UA.job
Updater.job

————————————————–

Enumerating Download Program Files:

[Macromedia Authorware Web Player Control]
InProcServer32 = C:\WINDOWS\system32\macromed\authorwa\awswax.ocx
CODEBASE = http://fpdownload.macromedia.com/get/shock…are/awswaxd.cab

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\Adobe\Director\SwDir.dll
CODEBASE = http://download.macromedia.com/pub/shockwa…director/sw.cab

[WUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\wuweb.dll
CODEBASE = http://update.microsoft.com/windowsupdate/…b?1287643598401

[DivXBrowserPlugin Object]
InProcServer32 = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CODEBASE = http://download.divx.com/player/DivXBrowserPlugin.cab

[MUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\muweb.dll
CODEBASE = http://www.update.microsoft.com/microsoftu…b?1287643966791

[GMNRev Class]
InProcServer32 = C:\Program Files\HP\Common\HPGMNRev.dll
CODEBASE = http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab

[{E2883E8F-472F-4FB0-9522-AC9BF37916A7}]
CODEBASE = http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: %system%\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll
WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll
UPnPMonitor: C:\WINDOWS\system32\upnpui.dll

————————————————–
End of report, 6,839 bytes
Report generated in 0.040 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Hi

Please do the following:



Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.



NEXT



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



NEXT


Scan With RootKitUnHooker

  • Please Download Rootkit Unhooker and save it to your desktop.
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"
Thank you for your quick response, ill post these reports, My Mbr report__________ MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Professional Windows Information: Service Pack 2 (build 2600) Logical Drives Mask: 0x0000000c Kernel Drivers (total 148): 0x804D7000 \WINDOWS\system32\ntoskrnl.exe 0x806EC000 \WINDOWS\system32\hal.dll 0xF7D2D000 \WINDOWS\system32\KDCOM.DLL 0xF7C3D000 \WINDOWS\system32\BOOTVID.dll 0xF77DE000 ACPI.sys 0xF7D2F000 \WINDOWS\System32\DRIVERS\WMILIB.SYS 0xF77BE000 fltmgr.sys 0xF77AD000 pci.sys 0xF782D000 isapnp.sys 0xF76DA000 goxlwt.sys 0xF7C41000 compbatt.sys 0xF7C45000 \WINDOWS\System32\DRIVERS\BATTC.SYS 0xF7DF5000 pciide.sys 0xF7AAD000 \WINDOWS\System32\DRIVERS\PCIIDEX.SYS 0xF7D31000 intelide.sys 0xF76BC000 pcmcia.sys 0xF783D000 MountMgr.sys 0xF769D000 ftdisk.sys 0xF7D33000 dmload.sys 0xF7677000 dmio.sys 0xF7C49000 ACPIEC.sys 0xF7DF6000 \WINDOWS\System32\DRIVERS\OPRGHDLR.SYS 0xF7AB5000 PartMgr.sys 0xF784D000 VolSnap.sys 0xF765F000 atapi.sys 0xF785D000 disk.sys 0xF786D000 \WINDOWS\System32\DRIVERS\CLASSPNP.SYS 0xF7628000 PCTCore.sys 0xF787D000 PxHelp20.sys 0xF7611000 KSecDD.sys 0xF7584000 Ntfs.sys 0xF7557000 NDIS.sys 0xF753C000 Mup.sys 0xF788D000 agp440.sys 0xF7518000 \SystemRoot\System32\DRIVERS\tunmp.sys 0xF6DF7000 \SystemRoot\System32\DRIVERS\intelppm.sys 0xF6CF0000 \SystemRoot\System32\DRIVERS\ati2mtag.sys 0xF6CDC000 \SystemRoot\System32\DRIVERS\VIDEOPRT.SYS 0xF7B7D000 \SystemRoot\System32\DRIVERS\usbuhci.sys 0xF6CB9000 \SystemRoot\System32\DRIVERS\USBPORT.SYS 0xF7B85000 \SystemRoot\System32\DRIVERS\usbehci.sys 0xF7D77000 \SystemRoot\system32\drivers\MbxStby.sys 0xF6C19000 \SystemRoot\system32\drivers\o2mmb.sys 0xF6DE7000 \SystemRoot\System32\DRIVERS\serial.sys 0xF7504000 \SystemRoot\System32\DRIVERS\serenum.sys 0xF7B8D000 \SystemRoot\System32\DRIVERS\fdc.sys 0xF6C05000 \SystemRoot\System32\DRIVERS\parport.sys 0xF6DD7000 \SystemRoot\System32\DRIVERS\i8042prt.sys 0xF7B95000 \SystemRoot\System32\DRIVERS\kbdclass.sys 0xF6BD7000 \SystemRoot\System32\DRIVERS\SynTP.sys 0xF7D79000 \SystemRoot\System32\DRIVERS\USBD.SYS 0xF7B9D000 \SystemRoot\System32\DRIVERS\mouclass.sys 0xF6DC7000 \SystemRoot\System32\DRIVERS\imapi.sys 0xF6DB7000 \SystemRoot\System32\DRIVERS\cdrom.sys 0xF78CD000 \SystemRoot\System32\DRIVERS\redbook.sys 0xF6BB4000 \SystemRoot\System32\DRIVERS\ks.sys 0xF6B74000 \SystemRoot\system32\drivers\smwdm.sys 0xF6B50000 \SystemRoot\system32\drivers\portcls.sys 0xF78DD000 \SystemRoot\system32\drivers\drmk.sys 0xF6B30000 \SystemRoot\system32\drivers\aeaudio.sys 0xF6A2B000 \SystemRoot\System32\DRIVERS\AGRSM.sys 0xF7BA5000 \SystemRoot\System32\Drivers\Modem.SYS 0xF7412000 \SystemRoot\System32\DRIVERS\CmBatt.sys 0xF740E000 \SystemRoot\System32\DRIVERS\wmiacpi.sys 0xF7F6E000 \SystemRoot\System32\DRIVERS\audstub.sys 0xF7BAD000 \SystemRoot\System32\DRIVERS\rasirda.sys 0xF7BB5000 \SystemRoot\System32\DRIVERS\TDI.SYS 0xF78ED000 \SystemRoot\System32\DRIVERS\rasl2tp.sys 0xF7406000 \SystemRoot\System32\DRIVERS\ndistapi.sys 0xF69EC000 \SystemRoot\System32\DRIVERS\ndiswan.sys 0xF78FD000 \SystemRoot\System32\DRIVERS\raspppoe.sys 0xF790D000 \SystemRoot\System32\DRIVERS\raspptp.sys 0xF69C0000 \SystemRoot\System32\DRIVERS\psched.sys 0xF791D000 \SystemRoot\System32\DRIVERS\msgpc.sys 0xF7BC5000 \SystemRoot\System32\DRIVERS\ptilink.sys 0xF7BCD000 \SystemRoot\System32\DRIVERS\raspti.sys 0xF698F000 \SystemRoot\System32\DRIVERS\rdpdr.sys 0xF792D000 \SystemRoot\System32\DRIVERS\termdd.sys 0xF7D83000 \SystemRoot\System32\DRIVERS\swenum.sys 0xF6936000 \SystemRoot\System32\DRIVERS\update.sys 0xF73EE000 \SystemRoot\System32\DRIVERS\mssmbios.sys 0xF793D000 \SystemRoot\system32\DRIVERS\zumbus.sys 0xF794D000 \SystemRoot\system32\DRIVERS\WDFLDR.SYS 0xF68C5000 \SystemRoot\System32\Drivers\wdf01000.sys 0xF796D000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xF799D000 \SystemRoot\System32\DRIVERS\usbhub.sys 0xF7D99000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF7E64000 \SystemRoot\System32\Drivers\Null.SYS 0xF7D9B000 \SystemRoot\System32\Drivers\Beep.SYS 0xF7BED000 \SystemRoot\System32\drivers\vga.sys 0xF7D9D000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF7D9F000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF7BF5000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF7BFD000 \SystemRoot\System32\Drivers\Npfs.SYS 0xF7D1D000 \SystemRoot\System32\DRIVERS\rasacd.sys 0xAAFA5000 \SystemRoot\System32\DRIVERS\ipsec.sys 0xAAF4D000 \SystemRoot\System32\DRIVERS\tcpip.sys 0xAAF15000 \SystemRoot\System32\DRIVERS\tcpip6.sys 0xAAEFC000 \SystemRoot\System32\Drivers\avgtdix.sys 0xAAED4000 \SystemRoot\System32\DRIVERS\netbt.sys 0xF7D25000 \SystemRoot\System32\drivers\ws2ifsl.sys 0xAAEB2000 \SystemRoot\System32\drivers\afd.sys 0xF79ED000 \SystemRoot\System32\DRIVERS\netbios.sys 0xAADF0000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 0xF7C05000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 0xAADC5000 \SystemRoot\System32\DRIVERS\rdbss.sys 0xAAD56000 \SystemRoot\System32\DRIVERS\mrxsmb.sys 0xF7A0D000 \SystemRoot\System32\Drivers\Fips.SYS 0xAAD35000 \SystemRoot\System32\DRIVERS\ipnat.sys 0xF7C0D000 \SystemRoot\system32\drivers\ip6fw.sys 0xF7A1D000 \SystemRoot\System32\DRIVERS\wanarp.sys 0xF7C1D000 \SystemRoot\System32\Drivers\avgmfx86.sys 0xAACBC000 \SystemRoot\System32\Drivers\avgldx86.sys 0xAAC47000 \SystemRoot\system32\DRIVERS\zd1211Bu.sys 0xF7A5D000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xAAC2F000 \SystemRoot\System32\Drivers\dump_atapi.sys 0xF7DE3000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xAAFDC000 \SystemRoot\System32\drivers\Dxapi.sys 0xF7B0D000 \SystemRoot\System32\watchdog.sys 0xBF9C3000 \SystemRoot\System32\drivers\dxg.sys 0xF7EC3000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF9D5000 \SystemRoot\System32\ati2dvag.dll 0xBFA0B000 \SystemRoot\System32\ati2cqag.dll 0xBFA43000 \SystemRoot\System32\ati3duag.dll 0xBFC11000 \SystemRoot\System32\ativvaxx.dll 0xBFFA0000 \SystemRoot\System32\ATMFD.DLL 0xF7CD1000 \??\C:\WINDOWS\system32\drivers\mbam.sys 0xAAAD8000 \SystemRoot\system32\DRIVERS\WudfPf.sys 0xAAC23000 \SystemRoot\system32\DRIVERS\AegisP.sys 0xAA95A000 \SystemRoot\System32\DRIVERS\irda.sys 0xAA944000 \SystemRoot\System32\DRIVERS\nwlnkipx.sys 0xAABB7000 \SystemRoot\System32\DRIVERS\nwlnknb.sys 0xAA9DC000 \SystemRoot\System32\DRIVERS\ndisuio.sys 0xAA7DC000 \SystemRoot\System32\DRIVERS\nwrdr.sys 0xAA788000 \SystemRoot\System32\DRIVERS\mrxdav.sys 0xAA74B000 \SystemRoot\system32\drivers\wdmaud.sys 0xAAE92000 \SystemRoot\system32\drivers\sysaudio.sys 0xF7B65000 \SystemRoot\System32\Drivers\TDTCP.SYS 0xAA51A000 \SystemRoot\System32\Drivers\RDPWD.SYS 0xF7DC7000 \SystemRoot\System32\Drivers\ParVdm.SYS 0xAA400000 \SystemRoot\System32\DRIVERS\srv.sys 0xAA6C8000 \SystemRoot\System32\DRIVERS\nwlnkspx.sys 0xA9BEF000 \SystemRoot\System32\Drivers\HTTP.sys 0xF7B1D000 \SystemRoot\System32\Drivers\ZDPSp50.sys 0xA98AC000 \SystemRoot\system32\DRIVERS\ar5211.sys 0xA97C3000 \SystemRoot\system32\drivers\kmixer.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 38): 0 System Idle Process 4 System 812 C:\WINDOWS\system32\smss.exe 876 csrss.exe 900 C:\WINDOWS\system32\winlogon.exe 944 C:\WINDOWS\system32\services.exe 964 C:\WINDOWS\system32\lsass.exe 1112 C:\WINDOWS\system32\ati2evxx.exe 1128 C:\WINDOWS\system32\svchost.exe 1184 svchost.exe 1240 C:\WINDOWS\system32\svchost.exe 1364 C:\WINDOWS\system32\svchost.exe 1592 svchost.exe 1624 svchost.exe 2008 C:\WINDOWS\system32\spoolsv.exe 252 svchost.exe 864 C:\WINDOWS\system32\ati2evxx.exe 1944 C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe 648 C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe 2136 C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe 2160 C:\WINDOWS\system32\ZuneBusEnum.exe 2264 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe 2568 C:\WINDOWS\system32\ctfmon.exe 3048 C:\WINDOWS\system32\svchost.exe 3068 C:\WINDOWS\system32\svchost.exe 1152 alg.exe 3976 C:\Program Files\AVG\AVG8\avgrsx.exe 1140 C:\WINDOWS\explorer.exe 788 C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe 2628 C:\Program Files\TheWorld 2.0\TheWorld.exe 2736 C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe 3608 C:\Program Files\AVG\AVG8\avgrsx.exe 2932 C:\PROGRA~1\AVG\AVG8\avgemc.exe 2140 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe 540 C:\WINDOWS\system32\searchindexer.exe 3396 C:\Program Files\AVG\AVG8\avgcsrvx.exe 2368 C:\PROGRA~1\AVG\AVG8\avgnsx.exe 744 C:\Documents and Settings\a\Desktop\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) PhysicalDrive0 Model Number: HTS548040M9AT00, Rev: MG2OA56A Size Device Name MBR Status ——————————————– 37 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A Done! My DDS report_________________- DDS (Ver_10-10-21.02) - NTFSx86 Run by [removed] at 19:12:21.75 on Sat 10/23/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_16 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.552 [GMT -4:00] AV: Spyware Doctor with AntiVirus *On-access scanning enabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6} AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe c:\WINDOWS\system32\ZuneBusEnum.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\WINDOWS\system32\ctfmon.exe "C:\WINDOWS\System32\svchost.exe" "C:\WINDOWS\System32\svchost.exe" C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\WINDOWS\explorer.exe C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe C:\Program Files\TheWorld 2.0\TheWorld.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\WINDOWS\system32\SearchIndexer.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Documents and Settings\a\Desktop\dds.com ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie mDefault_Search_URL = hxxp://www.google.com/ie uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie mWinlogon: Shell=explorer.exe TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Foxit Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [cdloader] "c:\documents and settings\a\application data\mjusbsp\cdloader2.exe" MAGICJACK uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe mRun: [SoundMAX] "c:\program files\analog devices\soundmax\Smax4.exe" /tray mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe" mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray mRun: [Ppumijegohewateb] rundll32.exe "c:\windows\efaqeluwe.dll",Startup StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\zdwlan~1.lnk - c:\program files\zydas technology corporation\zydas_802.11g_utility\ZDWlan.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {15B782AF-55D8-11D1-B477-006097098764} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/authorware/awswaxd.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1287643598401 DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1287643966791 DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL Notify: AtiExtEvent - Ati2evxx.dll Notify: avgrsstarter - avgrsstx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL LSA: Authentication Packages = msv1_0 nwprovau ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\a\applic~1\mozilla\firefox\profiles\6f7ycyq1.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - component: c:\documents and settings\a\application data\mozilla\firefox\profiles\6f7ycyq1.default\extensions\[removed]\components\coolirisstub.dll FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll FF - plugin: c:\documents and settings\a\application data\mozilla\firefox\profiles\6f7ycyq1.default\extensions\[removed]\plugins\npcoolirisplugin.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: XULRunner: {D2988324-5122-474F-B0A6-9FA708FFB083} - c:\documents and settings\a\local settings\application data\{D2988324-5122-474F-B0A6-9FA708FFB083} FF - HiddenExtension: XULRunner: {E164FA15-A38E-49B3-9F6E-7C6E1E9E9FFA} - c:\documents and settings\newone\local settings\application data\{e164fa15-a38e-49b3-9f6e-7c6e1e9e9ffa}\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} —- FIREFOX POLICIES —- FF - user.js: network.cookie.cookieBehavior - 0 FF - user.js: privacy.clearOnShutdown.cookies - false FF - user.js: security.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); ============= SERVICES / DRIVERS =============== R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-3-11 207280] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-3-11 335240] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-3-11 27784] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-3-11 108552] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2010-3-11 908056] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2010-3-11 297752] R2 NIHardwareService;NIHardwareService;c:\program files\common files\native instruments\hardware\NIHardwareService.exe [2010-2-26 3623424] R3 CONAN;CONAN;c:\windows\system32\drivers\o2mmb.sys [2006-8-4 182101] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-10-20 20952] R3 MbxStby;MbxStby;c:\windows\system32\drivers\MbxStby.sys [2006-8-4 5689] R3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service;c:\windows\system32\drivers\ar5211.sys [2009-9-2 468768] S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\spyware doctor\bdt\BDTUpdateService.exe [2010-3-11 112592] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-5-12 136176] S2 Ias;MicroSoft Production Manager;c:\windows\system32\svchost.exe -k netsvcs [2003-7-16 14336] S2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-10-20 304464] S3 BRGSp50;BRGSp50 NDIS Protocol Driver;c:\windows\system32\drivers\BRGSp50.sys [2010-9-15 20608] S3 rig3avs;rig3avs;c:\windows\system32\drivers\rig3avs.sys [2009-10-18 35216] S3 rig3usb;rig3usb;c:\windows\system32\drivers\rig3usb.sys [2009-10-18 210064] S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2010-3-11 365280] S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2010-3-11 1141712] S3 WPC300N;Linksys Wireless Notebook Adapter WPC300N Driver;c:\windows\system32\drivers\WPC300Nv1.SYS [2006-12-1 610816] S4 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2010-3-11 233136] S4 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [2010-3-11 70408] =============== Created Last 30 ================ 2010-10-23 07:22:00 ——– d—–w- C:\ZyDAS Technology Corporation 2010-10-22 13:29:12 221184 —-a-w- c:\windows\system32\wmpns.dll 2010-10-22 11:53:01 ——– d—–w- c:\docume~1\a\locals~1\applic~1\G DATA 2010-10-22 11:41:19 189520 —-a-w- c:\windows\system32\drivers\tmcomm.sys 2010-10-21 06:47:10 15064 —-a-w- c:\windows\system32\wuapi.dll.mui 2010-10-21 05:20:03 ——– d—–w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com 2010-10-21 05:20:03 ——– d—–w- c:\docume~1\a\applic~1\SUPERAntiSpyware.com 2010-10-21 05:19:42 ——– d—–w- c:\program files\SUPERAntiSpyware 2010-10-20 06:50:55 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-10-20 06:50:54 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-10-20 06:50:54 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-10-20 01:42:15 ——– d—–w- C:\WINDOWS2 2010-10-20 01:00:32 16384 —-a-w- c:\program files\internet explorer\connection wizard\isignup.exe 2010-10-20 00:58:09 33792 —-a-w- c:\program files\messenger\custsat.dll 2010-10-20 00:57:47 86016 —-a-w- c:\program files\msn\msncorefiles\oobe\obepopc.dll 2010-10-20 00:57:47 77824 —-a-w- c:\program files\msn\msncorefiles\oobe\obemtllc.dll 2010-10-20 00:57:46 966656 —-a-w- c:\program files\msn\msncorefiles\oobe\obemetal.dll 2010-10-20 00:57:46 229376 —-a-w- c:\program files\msn\msncorefiles\oobe\obelog.dll 2010-10-20 00:57:43 884712 —-a-w- c:\program files\msn\msncorefiles\install\msn9components\Digcore.exe 2010-10-20 00:57:38 11053008 —-a-w- c:\program files\msn\msncorefiles\install\msn9components\Msncli.exe 2010-10-20 00:57:37 1327320 —-a-w- c:\program files\msn\msncorefiles\install\msnsusii.exe 2010-10-18 16:23:39 ——– d—–w- c:\docume~1\a\applic~1\Malwarebytes 2010-10-18 16:23:20 ——– d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-10-18 07:41:26 0 —-a-w- c:\windows\Bgatedesuvar.bin 2010-10-18 07:41:17 ——– d—–w- c:\docume~1\a\locals~1\applic~1\{D2988324-5122-474F-B0A6-9FA708FFB083} 2010-10-18 07:39:38 843776 —-a-w- c:\windows\system32\drivers\goxlwt.sys 2010-10-18 07:39:26 184 —-a-w- c:\docume~1\a\applic~1\23560.bat 2010-10-18 07:39:17 ——– d—–w- c:\docume~1\alluse~1\applic~1\Update 2010-10-18 07:39:08 ——– d—–w- c:\docume~1\a\applic~1\Ixciol 2010-10-18 07:39:08 ——– d—–w- c:\docume~1\a\applic~1\Biiki 2010-10-18 06:53:44 ——– d—–w- c:\program files\DownloadToolz 2010-10-18 05:45:26 730240 —-a-w- c:\windows\system32\drivers\rt2870.sys 2010-10-18 02:14:04 ——– d—–w- c:\program files\CommViewWiFi 2010-10-17 19:49:15 ——– d—–w- c:\program files\Network Stumbler 2010-10-16 20:09:45 74072 —-a-w- c:\windows\system32\XAPOFX1_5.dll 2010-10-16 20:09:45 527192 —-a-w- c:\windows\system32\XAudio2_7.dll 2010-10-16 20:09:44 239960 —-a-w- c:\windows\system32\xactengine3_7.dll 2010-10-16 20:09:44 1868128 —-a-w- c:\windows\system32\d3dcsx_43.dll 2010-10-16 20:09:43 248672 —-a-w- c:\windows\system32\d3dx11_43.dll 2010-10-16 20:09:41 470880 —-a-w- c:\windows\system32\d3dx10_43.dll 2010-10-15 07:22:11 ——– d—–w- c:\docume~1\alluse~1\applic~1\DivX 2010-10-09 04:58:22 ——– d—–w- c:\docume~1\a\locals~1\applic~1\Song_ini_Generator 2010-09-28 17:28:30 ——– d—–w- c:\program files\MixMeister BPM Analyzer 2010-09-28 08:21:51 ——– d—–w- c:\program files\Audacity ==================== Find3M ==================== ============= FINISH: 19:13:13.08 =============== ive zipped the attatched report in a zip file and included it!, And here is my Rootkitunhooker report_____________________ RkU Version: 3.8.388.590, Type LE (SR2) ============================================== OS Name: Windows XP Version 5.1.2600 (Service Pack 2) Number of processors #1 ============================================== >Drivers ============================================== 0x804D7000 C:\WINDOWS\system32\ntoskrnl.exe 2180480 bytes (Microsoft Corporation, NT Kernel & System) 0x804D7000 PnpManager 2180480 bytes 0x804D7000 RAW 2180480 bytes 0x804D7000 WMIxWDM 2180480 bytes 0xBFA43000 C:\WINDOWS\System32\ati3duag.dll 1892352 bytes (ATI Technologies Inc. , ati3duag.dll) 0xBF800000 Win32k 1847296 bytes 0xBF800000 C:\WINDOWS\System32\win32k.sys 1847296 bytes (Microsoft Corporation, Multi-User Win32 Driver) 0xF6A2B000 C:\WINDOWS\System32\DRIVERS\AGRSM.sys 1069056 bytes (Agere Systems, SoftModem Device Driver) 0xF76DA000 goxlwt.sys 864256 bytes 0xF6CF0000 C:\WINDOWS\System32\DRIVERS\ati2mtag.sys 815104 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Miniport Driver) 0xF7584000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver) 0xBFC11000 C:\WINDOWS\System32\ativvaxx.dll 520192 bytes (ATI Technologies Inc. , Radeon Video Acceleration Universal Driver) 0xAAC47000 C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys 479232 bytes (ZyDAS Technology Corporation, ZD1211B 802.11 b+g USB LAN Driver) 0xA98AC000 C:\WINDOWS\system32\DRIVERS\ar5211.sys 471040 bytes (Atheros Communications, Inc., Driver for Atheros AR5001 Wireless Network Adapter) 0xF68C5000 C:\WINDOWS\System32\Drivers\wdf01000.sys 462848 bytes (Microsoft Corporation, Kernel Mode Driver Framework Runtime) 0xAAD56000 C:\WINDOWS\System32\DRIVERS\mrxsmb.sys 454656 bytes (Microsoft Corporation, Windows NT SMB Minirdr) 0xF6936000 C:\WINDOWS\System32\DRIVERS\update.sys 364544 bytes (Microsoft Corporation, Update Driver) 0xAAF4D000 C:\WINDOWS\System32\DRIVERS\tcpip.sys 360448 bytes (Microsoft Corporation, TCP/IP Protocol Driver) 0xAA400000 C:\WINDOWS\System32\DRIVERS\srv.sys 335872 bytes (Microsoft Corporation, Server driver) 0xAACBC000 C:\WINDOWS\System32\Drivers\avgldx86.sys 331776 bytes (AVG Technologies CZ, s.r.o., AVG AVI Loader Driver) 0xBFFA0000 C:\WINDOWS\System32\ATMFD.DLL 286720 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver) 0xA9BEF000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack) 0xF6B74000 C:\WINDOWS\system32\drivers\smwdm.sys 262144 bytes (Analog Devices, Inc., SoundMAX Integrated Digital Audio ) 0xBFA0B000 C:\WINDOWS\System32\ati2cqag.dll 229376 bytes (ATI Technologies Inc., Central Memory Manager / Queue Server Module) 0xAAF15000 C:\WINDOWS\System32\DRIVERS\tcpip6.sys 229376 bytes (Microsoft Corporation, IPv6 driver) 0xF7628000 PCTCore.sys 225280 bytes (PC Tools, PC Tools KDS Core Driver) 0xBF9D5000 C:\WINDOWS\System32\ati2dvag.dll 221184 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Display Driver) 0xF698F000 C:\WINDOWS\System32\DRIVERS\rdpdr.sys 200704 bytes (Microsoft Corporation, Microsoft RDP Device redirector) 0xF77DE000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT) 0xF6BD7000 C:\WINDOWS\System32\DRIVERS\SynTP.sys 188416 bytes (Synaptics, Inc., Synaptics Touchpad Driver) 0xF7557000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver) 0xF6C19000 C:\WINDOWS\system32\drivers\o2mmb.sys 184320 bytes (O2 Micro , o2mmb) 0xAA788000 C:\WINDOWS\System32\DRIVERS\mrxdav.sys 180224 bytes (Microsoft Corporation, Windows NT WebDav Minirdr) 0xAADC5000 C:\WINDOWS\System32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver) 0xAAED4000 C:\WINDOWS\System32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver) 0xAA7DC000 C:\WINDOWS\System32\DRIVERS\nwrdr.sys 163840 bytes (Microsoft Corporation, NetWare Redirector File System Driver) 0xF7677000 dmio.sys 155648 bytes (Microsoft Corp., Veritas Software, NT Disk Manager I/O Driver) 0xF6B50000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices)) 0xF6BB4000 C:\WINDOWS\System32\DRIVERS\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library) 0xAA51A000 C:\WINDOWS\System32\Drivers\RDPWD.SYS 143360 bytes (Microsoft Corporation, RDP Terminal Stack Driver (US/Canada Only, Not for Export)) 0xF6CB9000 C:\WINDOWS\System32\DRIVERS\USBPORT.SYS 143360 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver) 0xAAEB2000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock) 0xAADF0000 C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 139264 bytes (SUPERAdBlocker.com and SUPERAntiSpyware.com, SASKUTIL.SYS) 0xAAD35000 C:\WINDOWS\System32\DRIVERS\ipnat.sys 135168 bytes (Microsoft Corporation, IP Network Address Translator) 0xF6B30000 C:\WINDOWS\system32\drivers\aeaudio.sys 131072 bytes (Andrea Electronics Corporation, Andrea Audio Noise Cancellation Driver) 0xF77BE000 fltmgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager) 0xF769D000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver) 0xF76BC000 pcmcia.sys 122880 bytes (Microsoft Corporation, PCMCIA Bus Driver) 0xF753C000 Mup.sys 110592 bytes (Microsoft Corporation, Multiple UNC Provider driver) 0xAAEFC000 C:\WINDOWS\System32\Drivers\avgtdix.sys 102400 bytes (AVG Technologies CZ, s.r.o., AVG Network connection watcher) 0xF765F000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver) 0xAAC2F000 C:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes 0xF7611000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface) 0xF69EC000 C:\WINDOWS\System32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption)) 0xAAAD8000 C:\WINDOWS\system32\DRIVERS\WudfPf.sys 94208 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver) 0xAA95A000 C:\WINDOWS\System32\DRIVERS\irda.sys 90112 bytes (Microsoft Corporation, IRDA Protocol Driver) 0xAA944000 C:\WINDOWS\System32\DRIVERS\nwlnkipx.sys 90112 bytes (Microsoft Corporation, NWLINK2 IPX Protocol Driver) 0xAA74B000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper) 0xF6C05000 C:\WINDOWS\System32\DRIVERS\parport.sys 81920 bytes (Microsoft Corporation, Parallel Port Driver) 0xF6CDC000 C:\WINDOWS\System32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver) 0x806EC000 ACPI_HAL 81280 bytes 0x806EC000 C:\WINDOWS\system32\hal.dll 81280 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL) 0xAAFA5000 C:\WINDOWS\System32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver) 0xBF9C3000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver) 0xF77AD000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator) 0xF69C0000 C:\WINDOWS\System32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler) 0xF7A5D000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver) 0xF6DB7000 C:\WINDOWS\System32\DRIVERS\cdrom.sys 65536 bytes (Microsoft Corporation, SCSI CD-ROM Driver) 0xAABB7000 C:\WINDOWS\System32\DRIVERS\nwlnknb.sys 65536 bytes (Microsoft Corporation, NWLINK2 IPX Netbios Protocol Driver) 0xF6DE7000 C:\WINDOWS\System32\DRIVERS\serial.sys 65536 bytes (Microsoft Corporation, Serial Device Driver) 0xF78DD000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter) 0xF78CD000 C:\WINDOWS\System32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver) 0xAAE92000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter) 0xF799D000 C:\WINDOWS\System32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB) 0xAA6C8000 C:\WINDOWS\System32\DRIVERS\nwlnkspx.sys 57344 bytes (Microsoft Corporation, NWLINK2 SPX Protocol Driver) 0xF794D000 C:\WINDOWS\system32\DRIVERS\WDFLDR.SYS 57344 bytes (Microsoft Corporation, Kernel Mode Driver Framework Loader) 0xF786D000 C:\WINDOWS\System32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll) 0xF6DD7000 C:\WINDOWS\System32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver) 0xF78ED000 C:\WINDOWS\System32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver) 0xF784D000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver) 0xF790D000 C:\WINDOWS\System32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol) 0xF788D000 agp440.sys 45056 bytes (Microsoft Corporation, 440 NT AGP Filter) 0xF6DC7000 C:\WINDOWS\System32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver) 0xF783D000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager) 0xF78FD000 C:\WINDOWS\System32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver) 0xF796D000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy) 0xF787D000 PxHelp20.sys 40960 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP) 0xF792D000 C:\WINDOWS\System32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver) 0xF793D000 C:\WINDOWS\system32\DRIVERS\zumbus.sys 40960 bytes (Microsoft Corporation, Zune User-Mode Bus Enumerator) 0xF785D000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver) 0xF7A0D000 C:\WINDOWS\System32\Drivers\Fips.SYS 36864 bytes (Microsoft Corporation, FIPS Crypto Driver) 0xF6DF7000 C:\WINDOWS\System32\DRIVERS\intelppm.sys 36864 bytes (Microsoft Corporation, Processor Device Driver) 0xF782D000 isapnp.sys 36864 bytes (Microsoft Corporation, PNP ISA Bus Driver) 0xF791D000 C:\WINDOWS\System32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier) 0xF79ED000 C:\WINDOWS\System32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver) 0xAA1E8000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver) 0xF7A1D000 C:\WINDOWS\System32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver) 0xF7C0D000 C:\WINDOWS\system32\drivers\ip6fw.sys 32768 bytes (Microsoft Corporation, IPv6 Windows Firewall Driver) 0xF7BA5000 C:\WINDOWS\System32\Drivers\Modem.SYS 32768 bytes (Microsoft Corporation, Modem Device Driver) 0xF7BFD000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver) 0xF7B8D000 C:\WINDOWS\System32\DRIVERS\fdc.sys 28672 bytes (Microsoft Corporation, Floppy Disk Controller Driver) 0xF7AAD000 C:\WINDOWS\System32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension) 0xF7B85000 C:\WINDOWS\System32\DRIVERS\usbehci.sys 28672 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver) 0xF7C1D000 C:\WINDOWS\System32\Drivers\avgmfx86.sys 24576 bytes (AVG Technologies CZ, s.r.o., AVG Resident Shield Minifilter Driver) 0xF7B95000 C:\WINDOWS\System32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver) 0xF7B9D000 C:\WINDOWS\System32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver) 0xF7C05000 C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 24576 bytes (SUPERAdBlocker.com and SUPERAntiSpyware.com, SASDIFSV.SYS) 0xF7B65000 C:\WINDOWS\System32\Drivers\TDTCP.SYS 24576 bytes (Microsoft Corporation, TCP Transport Driver) 0xF7BED000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver) 0xF7BF5000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver) 0xF7AB5000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager) 0xF7BC5000 C:\WINDOWS\System32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library) 0xF7BAD000 C:\WINDOWS\System32\DRIVERS\rasirda.sys 20480 bytes (Microsoft Corporation, IrDA WAN Miniport Driver) 0xF7BCD000 C:\WINDOWS\System32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver) 0xF7BB5000 C:\WINDOWS\System32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper) 0xF7B7D000 C:\WINDOWS\System32\DRIVERS\usbuhci.sys 20480 bytes (Microsoft Corporation, UHCI USB Miniport Driver) 0xF7B0D000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver) 0xF7B1D000 C:\WINDOWS\System32\Drivers\ZDPSp50.sys 20480 bytes (Printing Communications Assoc., Inc. (PCAUSA), PCAUSA NDIS 5.0 SPR Protocol Driver) 0xAAC23000 C:\WINDOWS\system32\DRIVERS\AegisP.sys 16384 bytes (Meetinghouse Data Communications, IEEE 802.1X Protocol Driver) 0xF7C45000 C:\WINDOWS\System32\DRIVERS\BATTC.SYS 16384 bytes (Microsoft Corporation, Battery Class Driver) 0xF7412000 C:\WINDOWS\System32\DRIVERS\CmBatt.sys 16384 bytes (Microsoft Corporation, Control Method Battery Driver) 0xF7CD1000 C:\WINDOWS\system32\drivers\mbam.sys 16384 bytes (Malwarebytes Corporation, Malwarebytes' Anti-Malware) 0xF73EE000 C:\WINDOWS\System32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver) 0xAA9DC000 C:\WINDOWS\System32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver) 0xF7504000 C:\WINDOWS\System32\DRIVERS\serenum.sys 16384 bytes (Microsoft Corporation, Serial Port Enumerator) 0xF7518000 C:\WINDOWS\System32\DRIVERS\tunmp.sys 16384 bytes (Microsoft Corporation, Microsoft Tunnel Interface Driver) 0xF7C49000 ACPIEC.sys 12288 bytes (Microsoft Corporation, ACPI Embedded Controller Driver) 0xF7C3D000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver) 0xF7C41000 compbatt.sys 12288 bytes (Microsoft Corporation, Composite Battery Driver) 0xAAFDC000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver) 0xF7406000 C:\WINDOWS\System32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver) 0xF7D1D000 C:\WINDOWS\System32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver) 0xF740E000 C:\WINDOWS\System32\DRIVERS\wmiacpi.sys 12288 bytes (Microsoft Corporation, Windows Management Interface for ACPI) 0xF7D25000 C:\WINDOWS\System32\drivers\ws2ifsl.sys 12288 bytes (Microsoft Corporation, Winsock2 IFS Layer) 0xF7D9B000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver) 0xF7D33000 dmload.sys 8192 bytes (Microsoft Corp., Veritas Software., NT Disk Manager Startup Driver) 0xF7DE3000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes 0xF7D99000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver) 0xF7D31000 intelide.sys 8192 bytes (Microsoft Corporation, Intel PCI IDE Driver) 0xF7D2D000 C:\WINDOWS\system32\KDCOM.DLL 8192 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL) 0xF7D77000 C:\WINDOWS\system32\drivers\MbxStby.sys 8192 bytes (O2 Micro, O2Micro MemoryCardBus Slot Manager) 0xF7D9D000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator) 0xF7DC7000 C:\WINDOWS\System32\Drivers\ParVdm.SYS 8192 bytes (Microsoft Corporation, VDM Parallel Driver) 0xF7D9F000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport) 0xF7D83000 C:\WINDOWS\System32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator) 0xF7D79000 C:\WINDOWS\System32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver) 0xF7D2F000 C:\WINDOWS\System32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll) 0xF7F6E000 C:\WINDOWS\System32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver) 0xF7EC3000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk) 0xF7E64000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver) 0xF7DF6000 C:\WINDOWS\System32\DRIVERS\OPRGHDLR.SYS 4096 bytes (Microsoft Corporation, ACPI Operation Registration Driver) 0xF7DF5000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver) 0x86193838 unknown_irp_handler 1992 bytes 0x866D6E00 unknown_irp_handler 512 bytes ============================================== >Stealth ============================================== WARNING: File locked for read access [C:\WINDOWS\system32\drivers\goxlwt.sys] There we go, I gotta say this last file above the locked file "goxlwt.sys", when ever i try to load google chrome and it runs for awhile ived noticed that it will crash my system and give me the blue screen of death, and that sys file is listed, I don't know what to do with it, ill leave it and won't delete anything, mabe this is the cause? I'll wait for further instructions, thank you for your quick response and great diagnostic tools!

Attachments:

  • [attachment removed: Attach.zip]
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Wow, what ever that did for me, all my browsers have been restored to there rightful surfing speed, and everything!
Thank you so much, but to be sure here is a copy of my report log incase there is something missing or wrong.

Report________

ComboFix 10-10-23.01 - a 10/24/2010 0:33.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.546 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\a\Local Settings\Application Data\{D2988324-5122-474F-B0A6-9FA708FFB083}
c:\documents and settings\a\Local Settings\Application Data\{D2988324-5122-474F-B0A6-9FA708FFB083}\chrome.manifest
c:\documents and settings\a\Local Settings\Application Data\{D2988324-5122-474F-B0A6-9FA708FFB083}\chrome\content\_cfg.js
c:\documents and settings\a\Local Settings\Application Data\{D2988324-5122-474F-B0A6-9FA708FFB083}\chrome\content\overlay.xul
c:\documents and settings\a\Local Settings\Application Data\{D2988324-5122-474F-B0A6-9FA708FFB083}\install.rdf
c:\documents and settings\newone\Local Settings\Application Data\{E164FA15-A38E-49B3-9F6E-7C6E1E9E9FFA}
c:\documents and settings\newone\Local Settings\Application Data\{E164FA15-A38E-49B3-9F6E-7C6E1E9E9FFA}\chrome.manifest
c:\documents and settings\newone\Local Settings\Application Data\{E164FA15-A38E-49B3-9F6E-7C6E1E9E9FFA}\chrome\content\_cfg.js
c:\documents and settings\newone\Local Settings\Application Data\{E164FA15-A38E-49B3-9F6E-7C6E1E9E9FFA}\chrome\content\overlay.xul
c:\documents and settings\newone\Local Settings\Application Data\{E164FA15-A38E-49B3-9F6E-7C6E1E9E9FFA}\install.rdf
c:\program files\Mozilla Firefox\searchplugins\google_search.xml
c:\windows\efaqeluwe.dll
c:\windows\system32\drivers\goxlwt.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_IAS
——-\Service_Ias
——-\Legacy_goxlwt
——-\Service_goxlwt


((((((((((((((((((((((((( Files Created from 2010-09-24 to 2010-10-24 )))))))))))))))))))))))))))))))
.

2010-10-23 07:22 . 2010-10-23 07:22 ——– d—–w- C:\ZyDAS Technology Corporation
2010-10-22 13:29 . 2008-05-03 12:00 221184 —-a-w- c:\windows\system32\wmpns.dll
2010-10-22 13:28 . 2010-10-22 13:29 ——– d—–w- c:\documents and settings\newone
2010-10-22 11:53 . 2010-10-22 11:53 ——– d—–w- c:\documents and settings\a\Local Settings\Application Data\G DATA
2010-10-22 11:41 . 2010-09-06 09:26 189520 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2010-10-21 06:47 . 2009-08-06 23:24 15064 —-a-w- c:\windows\system32\wuapi.dll.mui
2010-10-21 05:20 . 2010-10-21 05:20 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-10-21 05:20 . 2010-10-21 05:20 ——– d—–w- c:\documents and settings\a\Application Data\SUPERAntiSpyware.com
2010-10-21 05:19 . 2010-10-21 05:20 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-10-20 06:50 . 2010-04-29 19:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-20 06:50 . 2010-10-20 06:50 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-10-20 06:50 . 2010-04-29 19:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-10-20 01:46 . 2010-10-24 04:26 ——– d–h–w- c:\documents and settings\Default User.WINDOWS2
2010-10-20 01:46 . 2010-10-20 01:01 ——– d—–w- c:\documents and settings\All Users.WINDOWS2
2010-10-20 01:42 . 2010-10-23 23:42 ——– d—–w- C:\WINDOWS2
2010-10-20 01:05 . 2010-10-23 23:43 ——– d—–w- c:\documents and settings\Administrator
2010-10-20 01:05 . 2010-10-20 01:05 ——– d-sh–w- c:\documents and settings\LocalService.NT AUTHORITY
2010-10-20 01:05 . 2010-10-20 01:05 ——– d-sh–w- c:\documents and settings\NetworkService.NT AUTHORITY
2010-10-20 01:00 . 2008-05-03 12:00 16384 —-a-w- c:\program files\Internet Explorer\Connection Wizard\isignup.exe
2010-10-20 00:58 . 2008-05-03 12:00 33792 —-a-w- c:\program files\Messenger\custsat.dll
2010-10-20 00:57 . 2008-05-03 12:00 86016 —-a-w- c:\program files\MSN\MSNCoreFiles\OOBE\obepopc.dll
2010-10-20 00:57 . 2008-05-03 12:00 77824 —-a-w- c:\program files\MSN\MSNCoreFiles\OOBE\obemtllc.dll
2010-10-20 00:57 . 2008-05-03 12:00 966656 —-a-w- c:\program files\MSN\MSNCoreFiles\OOBE\obemetal.dll
2010-10-20 00:57 . 2008-05-03 12:00 229376 —-a-w- c:\program files\MSN\MSNCoreFiles\OOBE\obelog.dll
2010-10-20 00:57 . 2008-05-03 12:00 884712 —-a-w- c:\program files\MSN\MSNCoreFiles\Install\MSN9Components\Digcore.exe
2010-10-20 00:57 . 2008-05-03 12:00 11053008 —-a-w- c:\program files\MSN\MSNCoreFiles\Install\MSN9Components\Msncli.exe
2010-10-20 00:57 . 2008-05-03 12:00 1327320 —-a-w- c:\program files\MSN\MSNCoreFiles\Install\msnsusii.exe
2010-10-19 04:50 . 2010-10-19 04:50 ——– d-sh–w- c:\documents and settings\LocalService\PrivacIE
2010-10-18 16:23 . 2010-10-18 16:23 ——– d—–w- c:\documents and settings\a\Application Data\Malwarebytes
2010-10-18 16:23 . 2010-10-18 16:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-10-18 07:50 . 2010-10-18 07:50 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-10-18 07:41 . 2010-10-23 05:47 0 —-a-w- c:\windows\Bgatedesuvar.bin
2010-10-18 07:39 . 2010-10-18 07:39 184 —-a-w- c:\documents and settings\a\Application Data\23560.bat
2010-10-18 07:39 . 2010-10-19 03:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Update
2010-10-18 07:39 . 2010-10-19 03:48 ——– d—–w- c:\documents and settings\a\Application Data\Biiki
2010-10-18 07:39 . 2010-10-18 07:56 ——– d—–w- c:\documents and settings\a\Application Data\Ixciol
2010-10-18 06:53 . 2010-10-18 06:53 ——– d—–w- c:\program files\DownloadToolz
2010-10-18 05:45 . 2010-04-02 14:40 730240 —-a-w- c:\windows\system32\drivers\rt2870.sys
2010-10-18 02:14 . 2010-10-19 06:08 ——– d—–w- c:\program files\CommViewWiFi
2010-10-17 19:49 . 2010-10-17 19:49 ——– d—–w- c:\program files\Network Stumbler
2010-10-16 20:09 . 2010-06-02 08:55 74072 —-a-w- c:\windows\system32\XAPOFX1_5.dll
2010-10-16 20:09 . 2010-06-02 08:55 527192 —-a-w- c:\windows\system32\XAudio2_7.dll
2010-10-16 20:09 . 2010-06-02 08:55 239960 —-a-w- c:\windows\system32\xactengine3_7.dll
2010-10-16 20:09 . 2010-05-26 15:41 1868128 —-a-w- c:\windows\system32\d3dcsx_43.dll
2010-10-16 20:09 . 2010-05-26 15:41 248672 —-a-w- c:\windows\system32\d3dx11_43.dll
2010-10-16 20:09 . 2010-05-26 15:41 470880 —-a-w- c:\windows\system32\d3dx10_43.dll
2010-10-15 07:22 . 2010-10-15 07:27 ——– d—–w- c:\documents and settings\All Users\Application Data\DivX
2010-10-09 04:58 . 2010-10-09 04:58 ——– d—–w- c:\documents and settings\a\Local Settings\Application Data\Song_ini_Generator
2010-09-28 17:28 . 2010-09-28 17:28 ——– d—–w- c:\program files\MixMeister BPM Analyzer
2010-09-28 08:21 . 2010-09-28 08:21 ——– d—–w- c:\program files\Audacity

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.

——- Sigcheck ——-

[7] 2009-03-08 . B60DDDD2D63CE41CB8C487FCFBB6419E . 638816 . . [8.00.6001.18702] . . c:\windows\system32\dllcache\iexplore.exe
[-] 2008-04-14 . 55794B97A7FAABD2910873C85274F409 . 93184 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\iexplore.exe
[7] 2004-08-04 . E7484514C0464642BE7B4DC2689354C8 . 93184 . . [6.00.2900.2180] . . c:\windows\ie8\iexplore.exe
[7] 2004-08-04 . E7484514C0464642BE7B4DC2689354C8 . 93184 . . [6.00.2900.2180] . . c:\windows\ServicePackFiles\i386\iexplore.exe
[-] 2003-07-16 . 418D301C3B1FA94B19584AEEB3D65166 . 91136 . . [6.00.2800.1106] . . c:\windows\$NtServicePackUninstall$\iexplore.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-18 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="c:\documents and settings\a\Application Data\mjusbsp\cdloader2.exe" [2010-10-08 50592]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-10 39408]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-09-28 2424560]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-16 335872]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 688218]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2010-01-07 158448]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-16 1164584]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
ZDWLan Utility.lnk - c:\program files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe [2010-9-15 487424]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-27 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-11 18:48 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
2005-04-19 17:03 88209 —-a-w- c:\windows\AGRSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
2010-07-08 15:34 2048352 —-a-w- c:\progra~1\AVG\AVG8\avgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 18:50 155648 —-a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-09-15 21:25 149280 —-a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-09-10 19:14 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"IntuitUpdateService"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\XBMC\\XBMC.exe"=
"c:\\Documents and Settings\\a\\Application Data\\mjusbsp\\magicJack.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [3/11/2010 5:36 AM 207280]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/11/2010 2:36 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/11/2010 2:36 PM 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 2:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 2:41 PM 67656]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [3/11/2010 2:36 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/11/2010 2:36 PM 297752]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [3/11/2010 5:45 AM 112592]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [10/20/2010 2:50 AM 304464]
R2 NIHardwareService;NIHardwareService;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [2/26/2010 12:19 PM 3623424]
R3 CONAN;CONAN;c:\windows\system32\drivers\o2mmb.sys [8/4/2006 1:40 PM 182101]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [10/20/2010 2:50 AM 20952]
R3 MbxStby;MbxStby;c:\windows\system32\drivers\MbxStby.sys [8/4/2006 1:40 PM 5689]
R3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service;c:\windows\system32\drivers\ar5211.sys [9/2/2009 3:59 PM 468768]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/12/2010 12:37 AM 136176]
S3 rig3avs;rig3avs;c:\windows\system32\drivers\rig3avs.sys [10/18/2009 1:57 AM 35216]
S3 rig3usb;rig3usb;c:\windows\system32\drivers\rig3usb.sys [10/18/2009 1:57 AM 210064]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [3/11/2010 5:36 AM 365280]
S3 WPC300N;Linksys Wireless Notebook Adapter WPC300N Driver;c:\windows\system32\drivers\WPC300Nv1.SYS [12/1/2006 2:54 AM 610816]
S4 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [3/11/2010 5:36 AM 233136]
S4 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [3/11/2010 5:36 AM 70408]
.
Contents of the 'Scheduled Tasks' folder

2010-10-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-12 04:36]

2010-10-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-12 04:36]

2010-10-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299502267-854245398-1343024091-1003Core.job
- c:\documents and settings\a\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-10-20 19:51]

2010-10-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299502267-854245398-1343024091-1003UA.job
- c:\documents and settings\a\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-10-20 19:51]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
FF - ProfilePath - c:\documents and settings\a\Application Data\Mozilla\Firefox\Profiles\6f7ycyq1.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\documents and settings\a\Application Data\Mozilla\Firefox\Profiles\6f7ycyq1.default\extensions\[removed]\components\coolirisstub.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\a\Application Data\Mozilla\Firefox\Profiles\6f7ycyq1.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

Toolbar-Locked - (no file)
HKLM-Run-Ppumijegohewateb - c:\windows\efaqeluwe.dll
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-Ppumijegohewateb - c:\windows\efaqeluwe.dll



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-24 00:47
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(892)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(948)
c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll

- - - - - - - > 'explorer.exe'(3476)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\ZuneBusEnum.exe
c:\windows\system32\wscntfy.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
.
**************************************************************************
.
Completion time: 2010-10-24 00:51:41 - machine was rebooted
ComboFix-quarantined-files.txt 2010-10-24 04:51

Pre-Run: 21,546,676,224 bytes free
Post-Run: 21,674,090,496 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS2
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS2="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

- - End Of File - - FBC0ADE49F8308CDF9E2785E34BC87EA
Hi

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/index.php?showtopic=115194&view=findpost&p=690470

Collect::
c:\documents and settings\a\Application Data\23560.bat

DirLook::
c:\documents and settings\All Users\Application Data\Update
c:\documents and settings\a\Application Data\Biiki
c:\documents and settings\a\Application Data\Ixciol

File::
c:\windows\Bgatedesuvar.bin

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT



  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
in order

Combofix report______________

ComboFix 10-10-23.02 - a 10/24/2010 15:12:51.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.567 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\a\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}

FILE ::
"c:\windows\Bgatedesuvar.bin"

file zipped: c:\documents and settings\a\Application Data\23560.bat
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\a\Application Data\23560.bat
c:\windows\Bgatedesuvar.bin

.
((((((((((((((((((((((((( Files Created from 2010-09-24 to 2010-10-24 )))))))))))))))))))))))))))))))
.

2010-10-23 07:22 . 2010-10-23 07:22 ——– d—–w- C:\ZyDAS Technology Corporation
2010-10-22 13:29 . 2008-05-03 12:00 221184 —-a-w- c:\windows\system32\wmpns.dll
2010-10-22 13:28 . 2010-10-22 13:29 ——– d—–w- c:\documents and settings\newone
2010-10-22 11:53 . 2010-10-22 11:53 ——– d—–w- c:\documents and settings\a\Local Settings\Application Data\G DATA
2010-10-22 11:41 . 2010-09-06 09:26 189520 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2010-10-21 06:47 . 2009-08-06 23:24 15064 —-a-w- c:\windows\system32\wuapi.dll.mui
2010-10-21 05:20 . 2010-10-21 05:20 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-10-21 05:20 . 2010-10-21 05:20 ——– d—–w- c:\documents and settings\a\Application Data\SUPERAntiSpyware.com
2010-10-21 05:19 . 2010-10-21 05:20 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-10-20 06:50 . 2010-04-29 19:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-20 06:50 . 2010-10-20 06:50 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-10-20 06:50 . 2010-04-29 19:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-10-20 01:46 . 2010-10-24 04:26 ——– d–h–w- c:\documents and settings\Default User.WINDOWS2
2010-10-20 01:46 . 2010-10-20 01:01 ——– d—–w- c:\documents and settings\All Users.WINDOWS2
2010-10-20 01:42 . 2010-10-23 23:42 ——– d—–w- C:\WINDOWS2
2010-10-20 01:05 . 2010-10-23 23:43 ——– d—–w- c:\documents and settings\Administrator
2010-10-20 01:05 . 2010-10-20 01:05 ——– d-sh–w- c:\documents and settings\LocalService.NT AUTHORITY
2010-10-20 01:05 . 2010-10-20 01:05 ——– d-sh–w- c:\documents and settings\NetworkService.NT AUTHORITY
2010-10-20 01:00 . 2008-05-03 12:00 16384 —-a-w- c:\program files\Internet Explorer\Connection Wizard\isignup.exe
2010-10-20 00:58 . 2008-05-03 12:00 33792 —-a-w- c:\program files\Messenger\custsat.dll
2010-10-20 00:57 . 2008-05-03 12:00 86016 —-a-w- c:\program files\MSN\MSNCoreFiles\OOBE\obepopc.dll
2010-10-20 00:57 . 2008-05-03 12:00 77824 —-a-w- c:\program files\MSN\MSNCoreFiles\OOBE\obemtllc.dll
2010-10-20 00:57 . 2008-05-03 12:00 966656 —-a-w- c:\program files\MSN\MSNCoreFiles\OOBE\obemetal.dll
2010-10-20 00:57 . 2008-05-03 12:00 229376 —-a-w- c:\program files\MSN\MSNCoreFiles\OOBE\obelog.dll
2010-10-20 00:57 . 2008-05-03 12:00 884712 —-a-w- c:\program files\MSN\MSNCoreFiles\Install\MSN9Components\Digcore.exe
2010-10-20 00:57 . 2008-05-03 12:00 11053008 —-a-w- c:\program files\MSN\MSNCoreFiles\Install\MSN9Components\Msncli.exe
2010-10-20 00:57 . 2008-05-03 12:00 1327320 —-a-w- c:\program files\MSN\MSNCoreFiles\Install\msnsusii.exe
2010-10-19 04:50 . 2010-10-19 04:50 ——– d-sh–w- c:\documents and settings\LocalService\PrivacIE
2010-10-18 16:23 . 2010-10-18 16:23 ——– d—–w- c:\documents and settings\a\Application Data\Malwarebytes
2010-10-18 16:23 . 2010-10-18 16:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-10-18 07:50 . 2010-10-18 07:50 ——– d-sh–w- c:\documents and settings\NetworkService\IETldCache
2010-10-18 07:39 . 2010-10-19 03:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Update
2010-10-18 07:39 . 2010-10-19 03:48 ——– d—–w- c:\documents and settings\a\Application Data\Biiki
2010-10-18 07:39 . 2010-10-18 07:56 ——– d—–w- c:\documents and settings\a\Application Data\Ixciol
2010-10-18 06:53 . 2010-10-18 06:53 ——– d—–w- c:\program files\DownloadToolz
2010-10-18 05:45 . 2010-04-02 14:40 730240 —-a-w- c:\windows\system32\drivers\rt2870.sys
2010-10-18 02:14 . 2010-10-19 06:08 ——– d—–w- c:\program files\CommViewWiFi
2010-10-17 19:49 . 2010-10-17 19:49 ——– d—–w- c:\program files\Network Stumbler
2010-10-16 20:09 . 2010-06-02 08:55 74072 —-a-w- c:\windows\system32\XAPOFX1_5.dll
2010-10-16 20:09 . 2010-06-02 08:55 527192 —-a-w- c:\windows\system32\XAudio2_7.dll
2010-10-16 20:09 . 2010-06-02 08:55 239960 —-a-w- c:\windows\system32\xactengine3_7.dll
2010-10-16 20:09 . 2010-05-26 15:41 1868128 —-a-w- c:\windows\system32\d3dcsx_43.dll
2010-10-16 20:09 . 2010-05-26 15:41 248672 —-a-w- c:\windows\system32\d3dx11_43.dll
2010-10-16 20:09 . 2010-05-26 15:41 470880 —-a-w- c:\windows\system32\d3dx10_43.dll
2010-10-15 07:22 . 2010-10-15 07:27 ——– d—–w- c:\documents and settings\All Users\Application Data\DivX
2010-10-09 04:58 . 2010-10-09 04:58 ——– d—–w- c:\documents and settings\a\Local Settings\Application Data\Song_ini_Generator
2010-09-28 17:28 . 2010-09-28 17:28 ——– d—–w- c:\program files\MixMeister BPM Analyzer
2010-09-28 08:21 . 2010-09-28 08:21 ——– d—–w- c:\program files\Audacity

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\documents and settings\a\Application Data\Biiki —-


—- Directory of c:\documents and settings\a\Application Data\Ixciol —-


—- Directory of c:\documents and settings\All Users\Application Data\Update —-



——- Sigcheck ——-

[7] 2009-03-08 . B60DDDD2D63CE41CB8C487FCFBB6419E . 638816 . . [8.00.6001.18702] . . c:\windows\system32\dllcache\iexplore.exe
[-] 2008-04-14 . 55794B97A7FAABD2910873C85274F409 . 93184 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\iexplore.exe
[7] 2004-08-04 . E7484514C0464642BE7B4DC2689354C8 . 93184 . . [6.00.2900.2180] . . c:\windows\ie8\iexplore.exe
[7] 2004-08-04 . E7484514C0464642BE7B4DC2689354C8 . 93184 . . [6.00.2900.2180] . . c:\windows\ServicePackFiles\i386\iexplore.exe
[-] 2003-07-16 . 418D301C3B1FA94B19584AEEB3D65166 . 91136 . . [6.00.2800.1106] . . c:\windows\$NtServicePackUninstall$\iexplore.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-18 333192]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="c:\documents and settings\a\Application Data\mjusbsp\cdloader2.exe" [2010-10-08 50592]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-10 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-16 335872]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 688218]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2010-01-07 158448]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-09-16 1164584]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
ZDWLan Utility.lnk - c:\program files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe [2010-9-15 487424]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-27 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-11 18:48 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
2005-04-19 17:03 88209 —-a-w- c:\windows\AGRSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
2010-07-08 15:34 2048352 —-a-w- c:\progra~1\AVG\AVG8\avgtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 18:50 155648 —-a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-09-15 21:25 149280 —-a-w- c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-09-10 19:14 39408 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"IntuitUpdateService"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\XBMC\\XBMC.exe"=
"c:\\Documents and Settings\\a\\Application Data\\mjusbsp\\magicJack.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [3/11/2010 5:36 AM 207280]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/11/2010 2:36 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/11/2010 2:36 PM 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 2:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 2:41 PM 67656]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [3/11/2010 2:36 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/11/2010 2:36 PM 297752]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [3/11/2010 5:45 AM 112592]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [10/20/2010 2:50 AM 304464]
R2 NIHardwareService;NIHardwareService;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [2/26/2010 12:19 PM 3623424]
R3 CONAN;CONAN;c:\windows\system32\drivers\o2mmb.sys [8/4/2006 1:40 PM 182101]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [10/20/2010 2:50 AM 20952]
R3 MbxStby;MbxStby;c:\windows\system32\drivers\MbxStby.sys [8/4/2006 1:40 PM 5689]
R3 WLAN_400_500_SERVICE;HP WLAN W400/W500 Wireless Network Adapter Service;c:\windows\system32\drivers\ar5211.sys [9/2/2009 3:59 PM 468768]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/12/2010 12:37 AM 136176]
S3 rig3avs;rig3avs;c:\windows\system32\drivers\rig3avs.sys [10/18/2009 1:57 AM 35216]
S3 rig3usb;rig3usb;c:\windows\system32\drivers\rig3usb.sys [10/18/2009 1:57 AM 210064]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [3/11/2010 5:36 AM 365280]
S3 WPC300N;Linksys Wireless Notebook Adapter WPC300N Driver;c:\windows\system32\drivers\WPC300Nv1.SYS [12/1/2006 2:54 AM 610816]
S4 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [3/11/2010 5:36 AM 233136]
S4 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [3/11/2010 5:36 AM 70408]
.
Contents of the 'Scheduled Tasks' folder

2010-10-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-12 04:36]

2010-10-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-12 04:36]

2010-10-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299502267-854245398-1343024091-1003Core.job
- c:\documents and settings\a\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-10-20 19:51]

2010-10-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-299502267-854245398-1343024091-1003UA.job
- c:\documents and settings\a\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-10-20 19:51]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
FF - ProfilePath - c:\documents and settings\a\Application Data\Mozilla\Firefox\Profiles\6f7ycyq1.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\documents and settings\a\Application Data\Mozilla\Firefox\Profiles\6f7ycyq1.default\extensions\[removed]\components\coolirisstub.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\a\Application Data\Mozilla\Firefox\Profiles\6f7ycyq1.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-24 15:21
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(652)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(708)
c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
.
Completion time: 2010-10-24 15:24:09
ComboFix-quarantined-files.txt 2010-10-24 19:23
ComboFix2.txt 2010-10-24 04:51

Pre-Run: 21,492,088,832 bytes free
Post-Run: 21,490,372,608 bytes free

- - End Of File - - CE63CE99727EB01AD0CDBEC1E031328F
Upload was successful


Malwarebytes Scan Report__________________

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4938

Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702

10/24/2010 3:36:18 PM
mbam-log-2010-10-24 (15-36-18).txt

Scan type: Quick scan
Objects scanned: 181733
Time elapsed: 6 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Online Scan Report_____________________

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Monday, October 25, 2010
Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Sunday, October 24, 2010 15:41:26
Records in database: 4175354
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Objects scanned: 145353
Threats found: 8
Infected objects found: 8
Suspicious objects found: 0
Scan duration: 03:45:36


File name / Threat / Threats count
C:\Documents and Settings\a\My Documents\Downloads\WinAircrackPack\WinAircrackPack\aircrack.exe Infected: not-a-virus:PSWTool.Win32.AirCrack.a 1
C:\Documents and Settings\a\My Documents\Downloads\WinAircrackPack\WinAircrackPack\airodump.exe Infected: not-a-virus:PSWTool.Win32.AirCrack.f 1
C:\Emulators\Dolphin\Plugins\Plugin_DSP_HLE.dll Infected: not-a-virus:AdWare.Win32.AdMedia.lf 1
C:\Emulators\Dolphin\Plugins\Plugin_DSP_LLE.dll Infected: not-a-virus:AdWare.Win32.AdMedia.lg 1
C:\Emulators\Dolphin\Plugins\Plugin_nJoy_SDL.dll Infected: not-a-virus:AdWare.Win32.AdMedia.ld 1
C:\Emulators\Dolphin\Plugins\Plugin_VideoDX9.dll Infected: not-a-virus:AdWare.Win32.AdMedia.le 1
C:\Emulators\Dolphin\Plugins\Plugin_Wiimote.dll Infected: not-a-virus:AdWare.Win32.AdMedia.lh 1
C:\Qoobox\Quarantine\C\Program Files\Mozilla Firefox\searchplugins\google_search.xml.vir Infected: Trojan.Win32.Clicker.hd 1

Selected area has been scanned.
Kaspersky is showing these items to be adware, so if you are not needing them, I would delete these files.

The other items are in quarantine already, which we will clean up shortly.

C:\Emulators\Dolphin\Plugins\Plugin_DSP_HLE.dll Infected: not-a-virus:AdWare.Win32.AdMedia.lf 1
C:\Emulators\Dolphin\Plugins\Plugin_DSP_LLE.dll Infected: not-a-virus:AdWare.Win32.AdMedia.lg 1
C:\Emulators\Dolphin\Plugins\Plugin_nJoy_SDL.dll Infected: not-a-virus:AdWare.Win32.AdMedia.ld 1
C:\Emulators\Dolphin\Plugins\Plugin_VideoDX9.dll Infected: not-a-virus:AdWare.Win32.AdMedia.le 1
C:\Emulators\Dolphin\Plugins\Plugin_Wiimote.dll Infected: not-a-virus:AdWare.Win32.AdMedia.lh 1



NEXT



You need to update your computer to SP3 as SP2 is no longer supported by Microsoft.


http://www.microsoft.com/downloads/en/deta…;displaylang=en



NEXT



[external image: Posted Image] Your Java is out of date.
Java™ 6 Update 16 can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.
An update should begin; > follow the prompts.


Clear Java cache

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup) If you do not see the icon, look to your left and click 'Switch to Classic View'.
  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT



Please advise how the computer is running now and if there are any outstanding issues.
Undertow76

Why do you have this hacking tool on your machine?

WinAircrackPack




WTT does not condone hacking, cracking or using pirated programs, stealing WiFi or any other illegal activity.
My computer is running Great!! at full speed…. Thank you so much. As for the program, I didn't know what I was getting into when I downloaded that, I was researching things like net stumbler and the like because i have a yagi antenna, and wanted one program to manage free wifi signals that comes into range! I imagine that is the thing that caused this whole mess, that and downloading things from rapidshare. Come to think of it, I was watching some instructional youtube video's "cheaply made" and clicked on a download link! I won't be doing that anymore! May this post be a lesson to everybody, Watch what you download off the video links of "Youtube" especially if they are from a rapidshare account, and research what you are downloading on google before you do download it! I didn't know that was a hacking program, I am deleting it after i post this, I have no use for that. Thank you again CatByte, it is truly amazing what you people do here, and im really greatful
OK, fair enough,

just some housekeeping to do now

please do the following:

You can delete the MBRCheck, DDS and RKU logs and programs from your desktop.


NEXT


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


If there are any logs/tools remaining > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Very good Articles, I can definately relate to them, and will be using your advice, Put WOT on all my browsers, Updated Windows, i havent did that in awhile, I'll be doing that more often now I know the importance of it. And did a registry backup, and put it on a usb key! I also after all the updates, did a driver backup of all my drivers and put them on my usb key also. Thank you again for helping me, this has been insightful, and I will be telling my friends of this forum and the Brilliant dedicated people here. Thank you for your help CatByte, :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI