This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help ..Email sending Spam... [Solved]

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey Guys, I have Yahoo Email as a 2nd email client and it is sending out spam email. I have Outlook at primary and it is not sending the spam. The System is Windows Vista, Thanks for any Help with this..!
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:52:21 PM, on 1/12/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\ASUS\AI Direct Link\AsCmd.exe
C:\Program Files\ASUS\AASP\1.00.59\aaCenter.exe
C:\Program Files\ASUS\AI Direct Link\AsShare.exe
C:\Windows\System32\fpplock.exe
C:\Program Files\Logitech\G35\G35.exe
C:\Program Files\Logitech\Gaming Software\LWEMon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Bluebeam Software\Brewery\V45\Printer Support\BBPrint.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Users\TheMadMan\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [Warning: do not remove it!] fpplock.exe
O4 - HKLM\..\Run: [Logitech G35] C:\Program Files\Logitech\G35\G35.exe
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKLM\..\Run: [Live Update 5] C:\Program Files\MSI\Live Update 5\LU5.exe /reminder
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [BbInstallUser] C:\Program Files\Bluebeam Software\Pushbutton PDF\Bluebeam Admin User.exe
O4 - HKLM\..\Run: [BbPrintMonitor] C:\Program Files\Common Files\Bluebeam Software\Brewery\V45\Printer Support\BBPrint.exe
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [Launch Direct Link] "C:\Program Files\ASUS\AI Direct Link\AsShare.exe"
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
O4 - HKLM\..\Run: [Bonus.SSR.FR10] "C:\Program Files\ABBYY FineReader 10\Bonus.ScreenshotReader.exe" /autorun
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe startup
O4 - HKLM\..\Run: [Launch As Cmd Runner] "C:\Program Files\ASUS\AI Direct Link\AsCmd.exe" -reg
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [HLBackupScheduler] C:\Program Files\Verizon V CAST Media Manager\V CAST Backup Scheduler.exe
O4 - HKCU\..\Run: [InstallIQUpdater] "C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe" /silent /autorun
O4 - HKUS\S-1-5-18\..\Run: [DevconDefaultDB] C:\Windows\system32\READREG /SILENT /FAIL=1 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DevconDefaultDB] C:\Windows\system32\READREG /SILENT /FAIL=1 (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: ABBYY FineReader 10 PE Licensing Service (ABBYY.Licensing.FineReader.Professional.10.0) - ABBYY - C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: iRacing.com Helper Service (iRacingService) - iRacing.com Motorsport Simulations, LLC
Bedford, MA 01730 - C:\Program Files\iRacing\iRacingService.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP4\RpcAgentSrv.exe

–
End of file - 9899 bytes
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———-

First we need to make all files and folders VISIBLE:

  • Go to Start >> Control Panel >> Folder Options >> View
  • Choose to "show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with ok
———-

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Right-click and Run as Administrator dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt

Attach.txt
———-

Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Right-click and Run as Administrator GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
.
———-

In your next reply please post the logs created by DDS and aswMBR. :)
DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 Run by [removed] at 20:26:05 on 2012-01-15 Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.3070.1647 [GMT -5:00] . AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files\Creative\Shared Files\CTAudSvc.exe C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\atieclxx.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Windows\System32\fpplock.exe C:\Program Files\Logitech\G35\G35.exe C:\Program Files\Logitech\Gaming Software\LWEMon.exe C:\Program Files\ASUS\AI Direct Link\AsCmd.exe C:\Program Files\ASUS\AASP\1.00.59\aaCenter.exe C:\Program Files\ASUS\AI Direct Link\AsShare.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Bluebeam Software\Brewery\V45\Printer Support\BBPrint.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Verizon V CAST Media Manager\V CAST Backup Scheduler.exe C:\Program Files\W3i\InstallIQUpdater\InstallIQUpdater.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k hpdevmgmt C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe C:\Program Files\iRacing\iRacingService.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\PSIService.exe C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\mobsync.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe C:\Windows\system32\Macromed\Flash\FlashUtil11e_ActiveX.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.yahoo.com/ uInternet Settings,ProxyOverride = *.local BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn3\YTSingleInstance.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter uRun: [HLBackupScheduler] c:\program files\verizon v cast media manager\V CAST Backup Scheduler.exe uRun: [InstallIQUpdater] "c:\program files\w3i\installiqupdater\InstallIQUpdater.exe" /silent /autorun mRun: [Warning: do not remove it!] fpplock.exe mRun: [Logitech G35] c:\program files\logitech\g35\G35.exe mRun: [Start WingMan Profiler] c:\program files\logitech\gaming software\LWEMon.exe /noui mRun: [Live Update 5] c:\program files\msi\live update 5\LU5.exe /reminder mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [BbInstallUser] c:\program files\bluebeam software\pushbutton pdf\Bluebeam Admin User.exe mRun: [BbPrintMonitor] c:\program files\common files\bluebeam software\brewery\v45\printer support\BBPrint.exe mRun: [AudioDrvEmulator] "c:\program files\creative\shared files\module loader\dllml.exe" -1 audiodrvemulator "c:\program files\creative\shared files\module loader\audio emulator\AudDrvEm.dll" mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume mRun: [Launch Direct Link] "c:\program files\asus\ai direct link\AsShare.exe" mRun: [ASUS Camera ScreenSaver] c:\windows\ASScrProlog.exe mRun: [Bonus.SSR.FR10] "c:\program files\abbyy finereader 10\Bonus.ScreenshotReader.exe" /autorun mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [Intuit SyncManager] c:\program files\common files\intuit\sync\IntuitSyncManager.exe startup mRun: [Launch As Cmd Runner] "c:\program files\asus\ai direct link\AsCmd.exe" -reg mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey dRun: [DevconDefaultDB] c:\windows\system32\READREG /SILENT /FAIL=1 StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL Trusted Zone: real.com\rhap-app-4-0 Trusted Zone: real.com\rhapreg Trusted Zone: rhapsody.com\rhap-app-4-0 Trusted Zone: rhapsody.com\rhapreg DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab TCP: DhcpNameServer = 192.168.1.254 TCP: Interfaces\{2D7BE3E5-D0BF-4915-8AAF-C541E24FA1D8} : DhcpNameServer = 192.168.1.254 TCP: Interfaces\{36242DD6-25FC-4EF5-9207-88608F78F6D6} : DhcpNameServer = 192.168.1.254 Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\intuit\quickbooks 2009\HelpAsyncPluggableProtocol.dll Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll . ============= SERVICES / DRIVERS =============== . R0 bmpanapi;bmpanapi;c:\windows\system32\drivers\bmpanapi.sys [2008-1-20 44544] R1 CLBStor;InstantBurn Storage Helper Driver;c:\windows\system32\drivers\CLBStor.sys [2009-1-22 16048] R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165648] R2 ABBYY.Licensing.FineReader.Professional.10.0;ABBYY FineReader 10 PE Licensing Service;c:\program files\common files\abbyy\finereader\10.00\licensing\pe\NetworkLicenseServer.exe [2009-12-22 814344] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-7-7 176128] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504] R2 iRacingService;iRacing.com Helper Service;c:\program files\iracing\iRacingService.exe [2010-2-17 476840] R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2011-7-7 8312832] R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2011-7-7 244736] R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdLH3.sys [2011-3-30 97808] R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [2009-6-23 99352] R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [2009-6-23 555032] R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [2009-6-23 566296] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-12-9 136176] S3 ACSSCR;ACR38 Smart Card Reader;c:\windows\system32\drivers\a38usb.sys [2009-10-30 36736] S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [2009-6-23 99352] S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files\common files\creative labs shared\service\AL6Licensing.exe [2010-2-17 79360] S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2010-2-17 79360] S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [2009-6-23 555032] S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [2009-6-23 100888] S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [2009-6-23 100888] S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [2009-6-23 566296] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-12-9 136176] S3 LachesisFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [2009-10-30 12032] S3 LADF_DHP2;G35 DHP2 Filter Driver;c:\windows\system32\drivers\ladfDHP2i386.sys [2010-9-29 53976] S3 LADF_SBVM;G35 SBVM Filter Driver;c:\windows\system32\drivers\ladfSBVMi386.sys [2010-9-29 335064] S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392] S3 MSI_MSIBIOS_010507;MSI_MSIBIOS_010507;c:\program files\msi\live update 5\msibios32_100507.sys [2011-8-3 25912] S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 65024] S3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2011-4-27 208944] S3 NTIOLib_1_0_4;NTIOLib_1_0_4;c:\program files\msi\live update 5\NTIOLib.sys [2011-8-3 7680] S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\sisoftware\sisoftware sandra lite 2009.sp4\RpcAgentSrv.exe [2009-10-28 99176] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2012-01-15 14:24:37 56200 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{1bb22742-2477-4939-92fe-849f59c7b6ee}\offreg.dll 2012-01-15 14:24:36 6823496 —-a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{1bb22742-2477-4939-92fe-849f59c7b6ee}\mpengine.dll 2012-01-12 22:35:19 703824 ——w- c:\programdata\microsoft\microsoft antimalware\definition updates\{e1e6901f-5fb5-4a12-8c21-6d811a2db4cd}\gapaengine.dll 2012-01-11 23:08:07 23552 —-a-w- c:\windows\system32\mciseq.dll 2012-01-11 23:08:07 189952 —-a-w- c:\windows\system32\winmm.dll 2012-01-11 23:08:07 1205064 —-a-w- c:\windows\system32\ntdll.dll 2012-01-11 23:08:06 66560 —-a-w- c:\windows\system32\packager.dll 2012-01-11 23:08:06 376320 —-a-w- c:\windows\system32\winsrv.dll 2012-01-11 23:08:06 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat 2012-01-11 23:08:02 497152 —-a-w- c:\windows\system32\qdvd.dll 2012-01-11 23:08:02 1314816 —-a-w- c:\windows\system32\quartz.dll 2011-12-21 01:05:17 42 —-a-w- c:\users\themadman\appdata\roaming\redline2stapler.tmp 2011-12-19 18:27:02 ——– d—–w- c:\users\themadman\appdata\roaming\Foxit Software . ==================== Find3M ==================== . 2011-12-13 13:27:09 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-12-11 04:45:24 544656 —-a-w- c:\windows\system32\deployJava1.dll 2011-12-11 04:00:31 6647808 —-a-w- c:\windows\system32\devaxrip.exe 2011-12-11 04:00:30 1273856 —-a-w- c:\windows\system32\cpyervid.dll 2011-12-10 20:24:06 20464 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-11-23 13:37:27 2043904 —-a-w- c:\windows\system32\win32k.sys 2011-11-08 14:42:19 2048 —-a-w- c:\windows\system32\tzres.dll 2011-11-03 22:47:42 1798144 —-a-w- c:\windows\system32\jscript9.dll 2011-11-03 22:40:21 1427456 —-a-w- c:\windows\system32\inetcpl.cpl 2011-11-03 22:39:47 1127424 —-a-w- c:\windows\system32\wininet.dll 2011-11-03 22:31:57 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2011-10-27 08:01:53 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe 2011-10-27 08:01:53 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe 2011-10-25 15:56:04 49152 —-a-w- c:\windows\system32\csrsrv.dll 2011-10-24 19:29:02 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx 2011-10-24 19:29:02 69632 —-a-w- c:\windows\system32\QuickTime.qts 2011-10-24 15:16:42 602112 —-a-w- c:\windows\system32\xvid.dll 2003-12-07 02:12:54 121856 –sha-w- c:\windows\system32\fpplock.exe . ============= FINISH: 20:26:19.99 ===============
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-01-15 21:09:19
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 Intel___ rev.1.0.
Running: gmer.exe; Driver: C:\Users\THEMAD~1\AppData\Local\Temp\uwryyuob.sys


—- Kernel code sections - GMER 1.0.15 —-

.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x91010000, 0x396C95, 0xE8000020]
? C:\Users\THEMAD~1\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Internet Explorer\iexplore.exe[4372] USER32.dll!EnableWindow 7654CD8B 5 Bytes JMP 6FB59A14 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4372] USER32.dll!DialogBoxParamW 765710B0 5 Bytes JMP 6FAB170B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4372] USER32.dll!DialogBoxIndirectParamW 76572EF5 5 Bytes JMP 6FCA62BE C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4372] USER32.dll!DialogBoxParamA 76588152 5 Bytes JMP 6FCA6259 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4372] USER32.dll!DialogBoxIndirectParamA 7658847D 5 Bytes JMP 6FCA6323 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4372] USER32.dll!MessageBoxIndirectA 7659D4D9 5 Bytes JMP 6FCA61E0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4372] USER32.dll!MessageBoxIndirectW 7659D5D3 5 Bytes JMP 6FCA6167 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4372] USER32.dll!MessageBoxExA 7659D639 5 Bytes JMP 6FCA6103 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4372] USER32.dll!MessageBoxExW 7659D65D 5 Bytes JMP 6FCA609F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] kernel32.dll!CreateThread 75A1CB2E 5 Bytes JMP 6FB17303 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!CreateDialogParamW 765472A2 5 Bytes JMP 6FCA6628 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!GetAsyncKeyState 7654863C 5 Bytes JMP 6FAFDD8D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!SetWindowsHookExW 765487AD 5 Bytes JMP 6FB52194 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!CallNextHookEx 76548E3B 5 Bytes JMP 6FB77BB7 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!UnhookWindowsHookEx 765498DB 5 Bytes JMP 6FB9EB74 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!EnableWindow 7654CD8B 5 Bytes JMP 6FB59A14 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!DefWindowProcA 7654DB88 7 Bytes JMP 6FB1952D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!CreateWindowExA 7654DC2A 5 Bytes JMP 6FB23363 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!CreateWindowExW 76551305 5 Bytes JMP 6FB7FF8F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!GetKeyState 76558CB1 5 Bytes JMP 6FAFDC67 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!DefWindowProcW 765603B4 7 Bytes JMP 6FB77C1A C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!IsDialogMessageW 76560745 5 Bytes JMP 6FCA6D82 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!CreateDialogParamA 765617AA 5 Bytes JMP 6FCA65F0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!IsDialogMessage 76561847 2 Bytes JMP 6FCA6D5A C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!IsDialogMessage + 3 7656184A 2 Bytes [74, F9] {JZ 0xfffffffffffffffb}
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!CreateDialogIndirectParamA 765626F1 5 Bytes JMP 6FCA6660 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!CreateDialogIndirectParamW 76569A62 5 Bytes JMP 6FCA6698 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!SetKeyboardState 76570987 5 Bytes JMP 6FCA7649 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!DialogBoxParamW 765710B0 5 Bytes JMP 6FAB170B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!DialogBoxIndirectParamW 76572EF5 5 Bytes JMP 6FCA62BE C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!SendInput 76572F75 5 Bytes JMP 6FCA75F1 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!EndDialog 7657326E 5 Bytes JMP 6FCA702E C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!SetCursorPos 76586FB2 5 Bytes JMP 6FCA76CA C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!DialogBoxParamA 76588152 5 Bytes JMP 6FCA6259 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!DialogBoxIndirectParamA 7658847D 5 Bytes JMP 6FCA6323 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!MessageBoxIndirectA 7659D4D9 5 Bytes JMP 6FCA61E0 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!MessageBoxIndirectW 7659D5D3 5 Bytes JMP 6FCA6167 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!MessageBoxExA 7659D639 5 Bytes JMP 6FCA6103 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!MessageBoxExW 7659D65D 5 Bytes JMP 6FCA609F C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] USER32.dll!keybd_event 7659D972 5 Bytes JMP 6FCA75AE C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] SHELL32.dll!SHRestricted + D95 768589A8 4 Bytes [CF, 01, 07, 73]
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] SHELL32.dll!SHRestricted + D9D 768589B0 8 Bytes [E0, 61, 06, 73, 79, F7, 06, …]
.text C:\Program Files\Internet Explorer\iexplore.exe[5804] ole32.dll!OleLoadFromStream 76181E80 5 Bytes JMP 6FCA6A8C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

—- Files - GMER 1.0.15 —-

File C:\Windows\System32\subenurl 0 bytes
File C:\Windows\System32\subenurl\F3B5DEB31DAC517E155356A4CA33AB9F20AEDBCF.fox 13410189 bytes
File C:\Windows\System32\subenurl\F50BCAD368DF00146B7144B7C77F481298A307A2.fox 1338526 bytes
File C:\Windows\System32\subenurl\F51827670556C9F3580CCCC0AEE9BAF3C90BFDCB.fox 4049799 bytes
File C:\Windows\System32\subenurl\F5AF8166EF515CA4F95E74236ED41775DE404E6F.fox 281972 bytes
File C:\Windows\System32\subenurl\F6689385D213A0B7F8FA022D4F51EDEE49532F58.fox 10445491 bytes
File C:\Windows\System32\subenurl\F6E2B1D9567B1985F3DB3240D9724E097678CFC4.fox 6673375 bytes
File C:\Windows\System32\subenurl\F78B2DC823FF16A8688D1FB171014E4569A68411.fox 1799078 bytes
File C:\Windows\System32\subenurl\2DBD7AAFE7500424A5A08F0C127CD2202ABF24F0.fox 6491513 bytes
File C:\Windows\System32\subenurl\2F07C810656319F7C9D6E1BE20D2AD7694738666.fox 9980617 bytes
File C:\Windows\System32\subenurl\33470BA7800826410E60CF34CFE2FC0C0896731C.fox 14509324 bytes
File C:\Windows\System32\subenurl\3424E4CCF1F1E7FEB4A87B2038F68333D743F285.fox 4609746 bytes
File C:\Windows\System32\subenurl\6891890A9C415F12F994EFF6FAC259534095913C.fox 1276273 bytes
File C:\Windows\System32\subenurl\6D03B4BC7451C27A4F1C1E4E662E9CA86C319D34.fox 6072371 bytes
File C:\Windows\System32\subenurl\4E0BA40DB3F35C47346D075C6DD3BF720DF50C0F.fox 4618535 bytes
File C:\Windows\System32\subenurl\503CC6DE00D37A7260FED83EE54B34726FFB6DC1.fox 3173634 bytes
File C:\Windows\System32\subenurl\5284DB6503CCD4C96C19D085DBBAF32AF577D966.fox 4326160 bytes
File C:\Windows\System32\subenurl\547572FC7F4D40D8D7E2DD8B9F8DF197C4F0BBDE.fox 5678122 bytes
File C:\Windows\System32\subenurl\58450714D196BD08265AD10E3CDE5667551FD1F1.fox 1259287 bytes
File C:\Windows\System32\subenurl\599D0DF07ABF0387AC38F5D2F59958DEC1D5F7C1.fox 830622 bytes
File C:\Windows\System32\subenurl\5A80DBC2A01EA21E23BF9F6AEE132DF5C5080F50.fox 554730 bytes
File C:\Windows\System32\subenurl\5DAE373C4B160130E14509815234BFF4ED520812.fox 206149 bytes
File C:\Windows\System32\subenurl\5F2161ACCC264CC744955059EAFC4FBEB15F457F.fox 412299 bytes
File C:\Windows\System32\subenurl\62196BCFE2D36A298468F607EA03E1FC4A63E757.fox 8552564 bytes
File C:\Windows\System32\subenurl\FD79F8E2AB21F5DF6E613019C8DB5F5FE0F2463F.fox 7881838 bytes
File C:\Windows\System32\subenurl\weburdev.ocx 546513 bytes
File C:\Windows\System32\subenurl\98B4FA3266A427AB5CEF8143EDAB9F781047ECFC.fox 1009654 bytes
File C:\Windows\System32\subenurl\99484AD5599E9C6528ED5F65B2E9836F8E2DC77D.fox 983275 bytes
File C:\Windows\System32\subenurl\99B86D2BC54D8AC2DE8001D9B1735E3F995A6539.fox 767390 bytes
File C:\Windows\System32\subenurl\9E25FB5F097A0414F3EC1C298FC10914EEA4D59A.fox 255491 bytes
File C:\Windows\System32\subenurl\62D28391CEAD169D18A20A17A317F8B1666B7912.fox 274640 bytes
File C:\Windows\System32\subenurl\638E3DDA0A13F71AF81C7EAEA4A0726D41816B9B.fox 7361610 bytes
File C:\Windows\System32\subenurl\658A2A4A9585FA4F96BB891C3208208914B99715.fox 7370100 bytes
File C:\Windows\System32\subenurl\662B12ED0F2B3D6E40ED51AE357BB13457741011.fox 6459402 bytes
File C:\Windows\System32\subenurl\E47705F05A3E06189E38AACBD50D1073F50DF827.fox 3643368 bytes
File C:\Windows\System32\subenurl\E7889C2ACA0657C2E9E847CC745F4F9E497E8F89.fox 92472 bytes
File C:\Windows\System32\subenurl\EA0637529118B8C2D8A05F3D506C4B631B41FDA6.fox 4682364 bytes
File C:\Windows\System32\subenurl\EA79FA7304B27990D82E307820A51BB089FDC1A8.fox 155653 bytes
File C:\Windows\System32\subenurl\EB29746DDB53F3BF07C832970666CD4D9CC866BA.fox 672798 bytes
File C:\Windows\System32\subenurl\EF6665EA0400EE11D85E345B30D75E26B4FD2BBE.fox 3701719 bytes
File C:\Windows\System32\subenurl\4970B2123AD877267933412C22D7BD716AAD03C5.fox 13709210 bytes
File C:\Windows\System32\subenurl\49844024417C982C1217FD27D28E4096C6263B68.fox 2780911 bytes
File C:\Windows\System32\subenurl\4D95BEE9634FA2DC56D86DDEF76C3DE527A9F5C1.fox 2870760 bytes
File C:\Windows\System32\subenurl\4DA1F5F7AA03A0172BB03D8F03B70E2FFF24C8FC.fox 13057286 bytes
File C:\Windows\System32\subenurl\D4F73F0D5767FB26B06CE7EFBD0231DFB467FF3D.fox 3193026 bytes
File C:\Windows\System32\subenurl\D68F09C83F58996919A77D2F6A6A406B829A1B14.fox 8358164 bytes
File C:\Windows\System32\subenurl\D7BDE1EAFF3A7DA6AFA317173383745CF495CFDD.fox 10577389 bytes
File C:\Windows\System32\subenurl\D8247B35B5C51562EB9424080F2DE19ED442A47A.fox 2180561 bytes
File C:\Windows\System32\subenurl\D888E0C1A9913F1DF20101F95635274230145C8E.fox 226177 bytes
File C:\Windows\System32\subenurl\DA292800252FEA1602965E0D5403EEE5013EBCC7.fox 1774322 bytes
File C:\Windows\System32\subenurl\0293CB3213747AFFC9A2A524B03ED91A6B51CBC0.fox 444963 bytes
File C:\Windows\System32\subenurl\03FC1211B73F7FB324E8C6A06142C634BD7901A4.fox 170668 bytes
File C:\Windows\System32\subenurl\0A9D23D820EE42BAAE17D51FE481DE887AC6AC20.fox 1493204 bytes
File C:\Windows\System32\subenurl\0AF1509DA87EC034829211AD8B3AAE3EAEB8BAE4.fox 7182115 bytes
File C:\Windows\System32\subenurl\0E8BEFBE9C0F88D2BA5AE49C45B3DDF8E32D82C7.fox 182273 bytes
File C:\Windows\System32\subenurl\0F2C20EDFE879912F4F80DE32D94E709884F7119.fox 83832 bytes
File C:\Windows\System32\subenurl\10892029B92A5079226231C68B0CB4A96B292182.fox 10583328 bytes
File C:\Windows\System32\subenurl\140312FB97CF7013A5E2D8B31B6BA96B8620387A.fox 500061 bytes
File C:\Windows\System32\subenurl\15D0F9F5565CDDC8E9498AF1311A22F770EBFE62.fox 870989 bytes
File C:\Windows\System32\subenurl\16917B6DFCEE9EA9FB0F661DDA3640990EEAF225.fox 607185 bytes
File C:\Windows\System32\subenurl\17C08023803FBAAFC15BCEF648AFFA8B2569BACA.fox 5882 bytes
File C:\Windows\System32\subenurl\E1FB55212AAF78FFC13FE701239EEAD9C0B3A10B.fox 9967886 bytes
File C:\Windows\System32\subenurl\B3C21237BEE4498A5D2CF677D7E893433A8F8686.fox 10312756 bytes
File C:\Windows\System32\subenurl\B95B7E06559E50260D31F98119F63E063F278621.fox 4336712 bytes
File C:\Windows\System32\subenurl\B9729B2707C759F0C528F2D574609B34AF3A983E.fox 13731697 bytes
File C:\Windows\System32\subenurl\BC56FF3E9C7EBF82936887876B657A0FED60104A.fox 11308230 bytes
File C:\Windows\System32\subenurl\BE1F1C18996B1957DDB3ED320C23D94FFA737AB9.fox 4063715 bytes
File C:\Windows\System32\subenurl\C008BDD55C301499E06C70C14D5114CE396CCD7E.fox 4815234 bytes
File C:\Windows\System32\subenurl\C131ECF504E336356F86F0A96BCF115CC1F9026D.fox 1159217 bytes
File C:\Windows\System32\subenurl\C2BA2049773CEDF235BFD66123FF96C6872E83FE.fox 13749749 bytes
File C:\Windows\System32\subenurl\73F06F90929E1C1E6A8816ED0486786DDF58A199.fox 87905 bytes
File C:\Windows\System32\subenurl\77AA8A3B9295D5F20F16F573392D3E0CCEAD0DA1.fox 12173652 bytes
File C:\Windows\System32\subenurl\798EED2CB6B02CE24D9CDDE57619D4BD030D313D.fox 4842961 bytes
File C:\Windows\System32\subenurl\79ED574F40678155387859390703890203D46245.fox 1498581 bytes
File C:\Windows\System32\subenurl\7D4E8660D156363ACC0EB4F670FD83801A333AD5.fox 10965567 bytes
File C:\Windows\System32\subenurl\8036B8F5D51CBA7C6002AEB5391F66F9E972E511.fox 1109770 bytes
File C:\Windows\System32\subenurl\80BC15A4170DB8952409B0ECA6C79DEE79B8DC2B.fox 69399 bytes
File C:\Windows\System32\subenurl\817679B47AA68DAB55D36F702EC2AE4C04783E6F.fox 82886 bytes
File C:\Windows\System32\subenurl\855CB12ECBB6670F97218A213836689D95C600C9.fox 2526 bytes
File C:\Windows\System32\subenurl\010E99FD19A34AC064B9DE7F1220B560A0F13093.fox 10503880 bytes
File C:\Windows\System32\subenurl\012311B47C6C4899F1BC29C8334226FAA51AD5F1.fox 1738329 bytes
File C:\Windows\System32\subenurl\01C960F4AE3AF54D6BB70A089749C3D39EA77ED4.fox 5165001 bytes
File C:\Windows\System32\subenurl\027B6F7E53B7F6D70E235DDDC0E9F727956FEB77.fox 59283 bytes
File C:\Windows\System32\subenurl\A45A458EBA8BB534D0C5FA48884A34A70E7DB255.fox 4391509 bytes
File C:\Windows\System32\subenurl\A67B7B42B171A3F4C864ED16ACAE05ACB1C77F80.fox 1869861 bytes
File C:\Windows\System32\subenurl\A9D08AD2B4410E0BA1F49BE974E31A2424A20987.fox 11181622 bytes
File C:\Windows\System32\subenurl\AAA53FE6E352FE1939AB5FE9294AB9050A90C53C.fox 4513543 bytes
File C:\Windows\System32\subenurl\ABF77E0246F4E2959EBC8DDF659A744D2AE34ABF.fox 943098 bytes
File C:\Windows\System32\subenurl\AC70DF8F73161C01D79256B2DA3652E1B5C4B5A7.fox 6435737 bytes
File C:\Windows\System32\subenurl\AE23338C515A8F90148A95F2DB0E765547934B58.fox 335553 bytes
File C:\Windows\System32\subenurl\AE59798A15D3B96E16985094B8033D221B982ACC.fox 10280061 bytes
File C:\Windows\System32\subenurl\B31FABDE998E4A54784D99E9C078B23677D0E45B.fox 976587 bytes
File C:\Windows\System32\subenurl\1D342A31C0982001E9C9BC4F6134AB349D93FEC0.fox 1465713 bytes
File C:\Windows\System32\subenurl\1DDC5F8CEFE25F5A75B7AFDD6A0A616FE040EEC0.fox 12303721 bytes
File C:\Windows\System32\subenurl\22381DAD0CCDF4693CD0ABE20979612000542CD9.fox 11605485 bytes
File C:\Windows\System32\subenurl\24F61AC3CB88DFC4B572BB5CB8B05DE65796A473.fox 1312609 bytes
File C:\Windows\System32\subenurl\2627ED4DB5045AF315FBAF8CD51B68D8B23761A9.fox 10073163 bytes
File C:\Windows\System32\subenurl\2ABDAB4B02234507A58CB0BD55F1B118E7E6386F.fox 2115910 bytes
File C:\Windows\System32\subenurl\2CC0BC587579FEDA406960865ED00087A44E8695.fox 864 bytes
File C:\Windows\System32\subenurl\86ED4DE791D7682CF0F7F60EB10C13C16EE7AE12.fox 1421239 bytes
File C:\Windows\System32\subenurl\89DCFF1C718D9CC18496A45211CE23A64E138491.fox 2248900 bytes
File C:\Windows\System32\subenurl\8DB350455EFF7D9AC83CB54400E8C82F920AE23D.fox 318034 bytes
File C:\Windows\System32\subenurl\8E3AC18BF326084D0C2E0EEABCCFA6C0230855D6.fox 2512280 bytes
File C:\Windows\System32\subenurl\8E8A9010C3514552A0354ABF7CF914F9D6081B9E.fox 5236143 bytes
File C:\Windows\System32\subenurl\92D43E700387D5E4E53F83D296D7B48D5F48EA61.fox 3573762 bytes
File C:\Windows\System32\subenurl\97477B9AB4B3AB667ABFC02209EFC691DE2732DA.fox 2140 bytes
File C:\Windows\System32\subenurl\C61BADA040E1B43861011C788788DD98A9D9B83B.fox 2955770 bytes
File C:\Windows\System32\subenurl\C7976B3745DB66369233F5C5F8D22F25F9C8180E.fox 917935 bytes
File C:\Windows\System32\subenurl\C916D85A8E7327F56D5C4967782F8E1B61327B9E.fox 1131239 bytes
File C:\Windows\System32\subenurl\CC3E062CA41A836311AA1099917A9101367D44FF.fox 5552634 bytes
File C:\Windows\System32\subenurl\CDB3BD0A8D074095D51ECB9C97CA7F6725D91FE6.fox 13233523 bytes
File C:\Windows\System32\subenurl\CDC7D187CB7CA5236073CD2F72D731F1A01C4781.fox 13255881 bytes
File C:\Windows\System32\subenurl\CE880C2F58E66647E9EC90A5100A08D1EF742D98.fox 2387523 bytes
File C:\Windows\System32\subenurl\D3239AD626563185CB79A51C1CAEDCB6FBF2F75E.fox 2444381 bytes
File C:\Windows\System32\subenurl\D36CE86FD9D823ED151C67A5A072F680D75AE608.fox 6180175 bytes
File C:\Windows\System32\subenurl\D42139DCAA444751B5BF5805D07A385BDA374571.fox 1264704 bytes
File C:\Windows\System32\subenurl\386BE3732EF06D3D828EDC0626C4D0C08A19B8BF.fox 281146 bytes
File C:\Windows\System32\subenurl\3C45B0AD48B41D7B4BDC3E805DD4C0B07A7A753E.fox 13269591 bytes
File C:\Windows\System32\subenurl\412759878EB4F60D48A1CC1927AC5AEE06140790.fox 5159689 bytes
File C:\Windows\System32\subenurl\42797D5F36EAE8AD37B15186CA51C76530BDD722.fox 736448 bytes
File C:\Windows\System32\subenurl\4377B896C8E882D01861B38A8EA110BAEE0229DE.fox 1718225 bytes
File C:\Windows\System32\subenurl\4420FE52731D734A9364CBC85E724619BA054709.fox 6770117 bytes
File C:\Windows\System32\subenurl\44D97F543903847C21AF895DB9408FBB7D11F616.fox 7400505 bytes
File C:\Windows\System32\subenurl\4723ECE461DB9402467F863D481ADB670FC6BFA2.fox 187463 bytes
File C:\Windows\System32\subenurl\endulsnd 0 bytes

—- EOF - GMER 1.0.15 —-
aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software Run date: 2012-01-14 01:10:31 —————————– 01:10:31.623 OS Version: Windows 6.0.6002 Service Pack 2 01:10:31.623 Number of processors: 4 586 0x1707 01:10:31.623 ComputerName: THEMADMAN-PC UserName: TheMadMan 01:10:32.419 Initialize success 01:10:35.024 AVAST engine defs: 12011301 01:10:46.693 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 01:10:46.693 Disk 0 Vendor: Intel___ 1.0. Size: 286173MB BusType: 8 01:10:46.709 Disk 0 MBR read successfully 01:10:46.709 Disk 0 MBR scan 01:10:46.709 Disk 0 Windows VISTA default MBR code 01:10:46.709 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 286171 MB offset 2048 01:10:46.724 Disk 0 scanning sectors +586080256 01:10:46.755 Disk 0 scanning C:\Windows\system32\drivers 01:10:52.871 Service scanning 01:10:53.495 Service MpNWMon C:\Windows\system32\DRIVERS\MpNWMon.sys **LOCKED** 32 01:10:54.087 Modules scanning 01:10:57.410 Disk 0 trace - called modules: 01:10:57.426 ntkrnlpa.exe CLASSPNP.SYS disk.sys iastor.sys hal.dll 01:10:57.426 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x899e43b0] 01:10:57.441 3 CLASSPNP.SYS[8d5cd8b3] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x88d6f028] 01:10:58.206 AVAST engine scan C:\Windows 01:11:03.026 AVAST engine scan C:\Windows\system32 01:12:25.207 AVAST engine scan C:\Windows\system32\drivers 01:12:32.773 AVAST engine scan C:\Users\TheMadMan 01:25:20.979 AVAST engine scan C:\ProgramData 01:27:05.453 Scan finished successfully 10:06:40.730 Disk 0 MBR has been saved successfully to "C:\Users\TheMadMan\Desktop\MBR.dat" 10:06:40.730 The log file has been saved successfully to "C:\Users\TheMadMan\Desktop\aswMBR.txt"
Hi Bobby,

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
———-
ComboFix 12-01-15.01 - TheMadMan 01/15/2012 22:01:04.3.4 - x86
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.3070.1352 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\TheMadMan\AppData\Roaming\redline2stapler.tmp
.
.
((((((((((((((((((((((((( Files Created from 2011-12-16 to 2012-01-16 )))))))))))))))))))))))))))))))
.
.
2012-01-16 03:05 . 2012-01-16 03:06 ——– d—–w- c:\users\TheMadMan\AppData\Local\temp
2012-01-16 03:05 . 2012-01-16 03:05 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2012-01-16 03:05 . 2012-01-16 03:05 ——– d—–w- c:\users\Public\AppData\Local\temp
2012-01-16 03:05 . 2012-01-16 03:05 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-01-15 14:24 . 2012-01-15 14:24 56200 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1BB22742-2477-4939-92FE-849F59C7B6EE}\offreg.dll
2012-01-15 14:24 . 2011-11-21 07:47 6823496 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1BB22742-2477-4939-92FE-849F59C7B6EE}\mpengine.dll
2012-01-12 22:35 . 2011-12-10 03:00 703824 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E1E6901F-5FB5-4A12-8C21-6D811A2DB4CD}\gapaengine.dll
2012-01-11 23:08 . 2011-11-18 20:23 1205064 —-a-w- c:\windows\system32\ntdll.dll
2012-01-11 23:08 . 2011-10-14 16:03 189952 —-a-w- c:\windows\system32\winmm.dll
2012-01-11 23:08 . 2011-10-14 16:00 23552 —-a-w- c:\windows\system32\mciseq.dll
2012-01-11 23:08 . 2011-12-01 15:21 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2012-01-11 23:08 . 2011-11-25 15:59 376320 —-a-w- c:\windows\system32\winsrv.dll
2012-01-11 23:08 . 2011-11-18 17:47 66560 —-a-w- c:\windows\system32\packager.dll
2012-01-11 23:08 . 2011-10-25 15:58 1314816 —-a-w- c:\windows\system32\quartz.dll
2012-01-11 23:08 . 2011-10-25 15:58 497152 —-a-w- c:\windows\system32\qdvd.dll
2012-01-06 04:03 . 2012-01-06 04:03 ——– d—–w- c:\program files\7-Zip
2011-12-19 18:27 . 2011-12-19 18:27 ——– d—–w- c:\users\TheMadMan\AppData\Roaming\Foxit Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-13 13:27 . 2011-12-13 13:27 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-11 04:45 . 2010-10-24 22:22 544656 —-a-w- c:\windows\system32\deployJava1.dll
2011-12-10 20:24 . 2011-12-10 09:34 20464 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-12-10 03:00 . 2011-12-10 03:00 703824 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\gapaengine.dll
2011-12-10 03:00 . 2011-08-12 00:25 703824 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2011-11-23 13:37 . 2011-12-14 14:27 2043904 —-a-w- c:\windows\system32\win32k.sys
2011-11-21 10:47 . 2011-12-09 06:15 6823496 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1691F84F-6263-40A9-923C-C65351F899C5}\mpengine.dll
2011-11-21 07:47 . 2011-12-11 06:22 6823496 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-11-21 07:47 . 2011-05-26 01:22 6823496 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-11-08 14:42 . 2011-12-14 14:26 2048 —-a-w- c:\windows\system32\tzres.dll
2011-11-03 22:47 . 2011-12-15 14:30 1798144 —-a-w- c:\windows\system32\jscript9.dll
2011-11-03 22:40 . 2011-12-15 14:30 1427456 —-a-w- c:\windows\system32\inetcpl.cpl
2011-11-03 22:39 . 2011-12-15 14:30 1127424 —-a-w- c:\windows\system32\wininet.dll
2011-11-03 22:31 . 2011-12-15 14:30 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2011-10-27 08:01 . 2011-12-14 14:27 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-27 08:01 . 2011-12-14 14:27 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 15:56 . 2011-12-14 14:26 49152 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-24 19:29 . 2011-10-24 19:29 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 19:29 . 2011-10-24 19:29 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-10-24 15:16 . 2011-10-24 15:16 602112 —-a-w- c:\windows\system32\xvid.dll
2003-12-07 02:12 121856 –sha-w- c:\windows\System32\fpplock.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-14 39408]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2011-11-24 6497592]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"HLBackupScheduler"="c:\program files\Verizon V CAST Media Manager\V CAST Backup Scheduler.exe" [2011-10-23 5013128]
"InstallIQUpdater"="c:\program files\W3i\InstallIQUpdater\InstallIQUpdater.exe" [2011-10-11 1179648]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Warning: do not remove it!"="fpplock.exe" [2003-12-07 121856]
"Logitech G35"="c:\program files\Logitech\G35\G35.exe" [2010-10-05 1811800]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 153672]
"Live Update 5"="c:\program files\MSI\Live Update 5\LU5.exe" [2011-07-15 1752376]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-07-08 336384]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-12-24 981680]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-11-13 421736]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"BbInstallUser"="c:\program files\Bluebeam Software\Pushbutton PDF\Bluebeam Admin User.exe" [2008-11-25 49824]
"BbPrintMonitor"="c:\program files\Common Files\Bluebeam Software\Brewery\V45\Printer Support\BBPrint.exe" [2008-04-16 156320]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2007-07-23 57344]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
"Launch Direct Link"="c:\program files\ASUS\AI Direct Link\AsShare.exe" [2007-11-16 1209856]
"ASUS Camera ScreenSaver"="c:\windows\ASScrProlog.exe" [2009-01-28 37232]
"Bonus.SSR.FR10"="c:\program files\ABBYY FineReader 10\Bonus.ScreenshotReader.exe" [2010-01-29 941320]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2009-12-22 1092872]
"Launch As Cmd Runner"="c:\program files\ASUS\AI Direct Link\AsCmd.exe" [2007-04-11 376832]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-05-04 252136]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DevconDefaultDB"="c:\windows\system32\READREG" [X]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2010-2-2 984352]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux6"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R3 ACSSCR;ACR38 Smart Card Reader;c:\windows\system32\DRIVERS\a38usb.sys [2009-01-23 36736]
S2 ABBYY.Licensing.FineReader.Professional.10.0;ABBYY FineReader 10 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe [2009-12-22 814344]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - UWRYYUOB
*Deregistered* - pctgntdi
*Deregistered* - uwryyuob
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-15 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-26 14:59]
.
2012-01-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-12-10 02:24]
.
2012-01-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-12-10 02:24]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
Trusted Zone: rhapsody.com\rhap-app-4-0
Trusted Zone: rhapsody.com\rhapreg
TCP: DhcpNameServer = 192.168.1.254
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Octoshape add-in for Adobe Flash Player - c:\users\TheMadMan\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-15 22:06
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
.
c:\windows\system32\subenurl
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-4246842962-803938559-1680518877-1000\Software\SecuROM\License information*]
"datasecu"=hex:05,aa,d9,65,a8,cd,1a,f6,3f,66,77,9d,8f,29,77,fd,8d,a2,fc,73,7b,
90,33,27,5a,a4,2d,c4,a0,3e,b4,ad,e6,7c,6f,7b,88,7a,12,c8,dd,a9,d8,4d,2b,68,\
"rkeysecu"=hex:25,87,2e,7f,ad,f4,1a,66,3b,ba,b3,17,ee,91,a3,2c
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2012-01-15 22:07:43
ComboFix-quarantined-files.txt 2012-01-16 03:07
.
Pre-Run: 180,583,174,144 bytes free
Post-Run: 180,217,741,312 bytes free
.
- - End Of File - - 3B68517429514DCDFDFCB5DB4BCE5365
Hi Bobby,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    DDS::
    TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
    TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    Trusted Zone: real.com\rhap-app-4-0
    Trusted Zone: real.com\rhapreg
    Trusted Zone: rhapsody.com\rhap-app-4-0
    Trusted Zone: rhapsody.com\rhapreg
    
    File::
    c:\windows\system32\drivers\bmpanapi.sys
    c:\windows\system32\devaxrip.exe
    c:\windows\system32\cpyervid.dll
    
    RegLock::
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    
    RegNull::
    [HKEY_USERS\S-1-5-21-4246842962-803938559-1680518877-1000\Software\SecuROM\License information*]
    
    Driver::
    bmpanapi
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
ComboFix 12-01-16.02 - TheMadMan 01/16/2012 8:36.4.4 - x86
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.3070.1890 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\TheMadMan\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\system32\cpyervid.dll"
"c:\windows\system32\devaxrip.exe"
"c:\windows\system32\drivers\bmpanapi.sys"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\cpyervid.dll
c:\windows\system32\devaxrip.exe
c:\windows\system32\drivers\bmpanapi.sys
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_BMPANAPI
——-\Service_bmpanapi
.
.
((((((((((((((((((((((((( Files Created from 2011-12-16 to 2012-01-16 )))))))))))))))))))))))))))))))
.
.
2012-01-16 13:40 . 2012-01-16 13:44 ——– d—–w- c:\users\TheMadMan\AppData\Local\temp
2012-01-16 13:40 . 2012-01-16 13:40 ——– d—–w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2012-01-16 13:40 . 2012-01-16 13:40 ——– d—–w- c:\users\Public\AppData\Local\temp
2012-01-16 13:40 . 2012-01-16 13:40 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-01-15 14:24 . 2011-11-21 07:47 6823496 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{1BB22742-2477-4939-92FE-849F59C7B6EE}\mpengine.dll
2012-01-12 22:35 . 2011-12-10 03:00 703824 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E1E6901F-5FB5-4A12-8C21-6D811A2DB4CD}\gapaengine.dll
2012-01-11 23:08 . 2011-11-18 20:23 1205064 —-a-w- c:\windows\system32\ntdll.dll
2012-01-11 23:08 . 2011-10-14 16:03 189952 —-a-w- c:\windows\system32\winmm.dll
2012-01-11 23:08 . 2011-10-14 16:00 23552 —-a-w- c:\windows\system32\mciseq.dll
2012-01-11 23:08 . 2011-12-01 15:21 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2012-01-11 23:08 . 2011-11-25 15:59 376320 —-a-w- c:\windows\system32\winsrv.dll
2012-01-11 23:08 . 2011-11-18 17:47 66560 —-a-w- c:\windows\system32\packager.dll
2012-01-11 23:08 . 2011-10-25 15:58 1314816 —-a-w- c:\windows\system32\quartz.dll
2012-01-11 23:08 . 2011-10-25 15:58 497152 —-a-w- c:\windows\system32\qdvd.dll
2012-01-06 04:03 . 2012-01-06 04:03 ——– d—–w- c:\program files\7-Zip
2011-12-19 18:27 . 2011-12-19 18:27 ——– d—–w- c:\users\TheMadMan\AppData\Roaming\Foxit Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-13 13:27 . 2011-12-13 13:27 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-11 04:45 . 2010-10-24 22:22 544656 —-a-w- c:\windows\system32\deployJava1.dll
2011-12-10 20:24 . 2011-12-10 09:34 20464 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-12-10 03:00 . 2011-12-10 03:00 703824 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\gapaengine.dll
2011-12-10 03:00 . 2011-08-12 00:25 703824 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2011-11-23 13:37 . 2011-12-14 14:27 2043904 —-a-w- c:\windows\system32\win32k.sys
2011-11-21 10:47 . 2011-12-09 06:15 6823496 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1691F84F-6263-40A9-923C-C65351F899C5}\mpengine.dll
2011-11-21 07:47 . 2011-12-11 06:22 6823496 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Updates\mpengine.dll
2011-11-21 07:47 . 2011-05-26 01:22 6823496 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-11-08 14:42 . 2011-12-14 14:26 2048 —-a-w- c:\windows\system32\tzres.dll
2011-11-03 22:47 . 2011-12-15 14:30 1798144 —-a-w- c:\windows\system32\jscript9.dll
2011-11-03 22:40 . 2011-12-15 14:30 1427456 —-a-w- c:\windows\system32\inetcpl.cpl
2011-11-03 22:39 . 2011-12-15 14:30 1127424 —-a-w- c:\windows\system32\wininet.dll
2011-11-03 22:31 . 2011-12-15 14:30 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2011-10-27 08:01 . 2011-12-14 14:27 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-27 08:01 . 2011-12-14 14:27 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 15:56 . 2011-12-14 14:26 49152 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-24 19:29 . 2011-10-24 19:29 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 19:29 . 2011-10-24 19:29 69632 —-a-w- c:\windows\system32\QuickTime.qts
2011-10-24 15:16 . 2011-10-24 15:16 602112 —-a-w- c:\windows\system32\xvid.dll
2003-12-07 02:12 121856 –sha-w- c:\windows\System32\fpplock.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-14 39408]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2011-11-24 6497592]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"WindowsWelcomeCenter"="oobefldr.dll" [2009-04-11 2153472]
"HLBackupScheduler"="c:\program files\Verizon V CAST Media Manager\V CAST Backup Scheduler.exe" [2011-10-23 5013128]
"InstallIQUpdater"="c:\program files\W3i\InstallIQUpdater\InstallIQUpdater.exe" [2011-10-11 1179648]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Warning: do not remove it!"="fpplock.exe" [2003-12-07 121856]
"Logitech G35"="c:\program files\Logitech\G35\G35.exe" [2010-10-05 1811800]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 153672]
"Live Update 5"="c:\program files\MSI\Live Update 5\LU5.exe" [2011-07-15 1752376]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-07-08 336384]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-12-24 981680]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-11-13 421736]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"BbInstallUser"="c:\program files\Bluebeam Software\Pushbutton PDF\Bluebeam Admin User.exe" [2008-11-25 49824]
"BbPrintMonitor"="c:\program files\Common Files\Bluebeam Software\Brewery\V45\Printer Support\BBPrint.exe" [2008-04-16 156320]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2007-07-23 57344]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
"Launch Direct Link"="c:\program files\ASUS\AI Direct Link\AsShare.exe" [2007-11-16 1209856]
"ASUS Camera ScreenSaver"="c:\windows\ASScrProlog.exe" [2009-01-28 37232]
"Bonus.SSR.FR10"="c:\program files\ABBYY FineReader 10\Bonus.ScreenshotReader.exe" [2010-01-29 941320]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2009-12-22 1092872]
"Launch As Cmd Runner"="c:\program files\ASUS\AI Direct Link\AsCmd.exe" [2007-04-11 376832]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-05-04 252136]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DevconDefaultDB"="c:\windows\system32\READREG" [X]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2010-2-2 984352]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux6"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R3 ACSSCR;ACR38 Smart Card Reader;c:\windows\system32\DRIVERS\a38usb.sys [2009-01-23 36736]
S2 ABBYY.Licensing.FineReader.Professional.10.0;ABBYY FineReader 10 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe [2009-12-22 814344]
.
.
— Other Services/Drivers In Memory —
.
*Deregistered* - pctgntdi
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-15 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-26 14:59]
.
2012-01-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-12-10 02:24]
.
2012-01-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-12-10 02:24]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.1.254
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-16 08:43
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\windows\system32\atiesrxx.exe
c:\program files\Creative\Shared Files\CTAudSvc.exe
c:\windows\system32\atieclxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\iRacing\iRacingService.exe
c:\windows\system32\PSIService.exe
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\windows\system32\WUDFHost.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\ASUS\AASP\1.00.59\aaCenter.exe
c:\windows\System32\fpplock.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\Yahoo!\Messenger\ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2012-01-16 08:45:40 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-16 13:45
ComboFix2.txt 2012-01-16 03:07
.
Pre-Run: 181,463,519,232 bytes free
Post-Run: 181,049,200,640 bytes free
.
- - End Of File - - 9B5A3FA4D8580949D42B4485E6EC6717
After running the program the system rebooted & gave me the log I could not open Internet exployer. Error ( Illegal operation attempted on a registry key that has been marked for deletion ) I rebooted and works now..
Hi Bobby,

After running the program the system rebooted & gave me the log I could not open Internet exployer. Error ( Illegal operation attempted on a registry key that has been marked for deletion ) I rebooted and works now..

Yes sometimes that will happen but it is not a problem. I would have had you reboot your system anyway and that is what clears that up. :thumbup:

I will be back after reviewing your logs.
Hi,

Malwarebytes

I see that you have Malwarebytes on your system. Please open Malwarebytes, update it and then run a Quick Scan. Please save the log that is created for your next reply.
———-

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.



As a Vista/Win7 user you will need to right click your browser icon and select "Run as Administrator" in order to run this scan.
  • Do not use this instance of your browser for anything besides doing this scan
  • When the scan is complete and the results saved, close that instance of your browser
  • Open a new one the usual way and post the results in this topic.


  • Right-click and Run as Administartor on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
http://www.eset.com/onlinescan/
———-

In your next reply please post the logs that are created by Malwarebytes and ESET online scanner. :)
Malwarebytes Anti-Malware 1.60.0.1800 www.malwarebytes.org Database version: v2012.01.16.01 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 TheMadMan :: THEMADMAN-PC [administrator] 1/16/2012 9:30:56 AM mbam-log-2012-01-16 (09-30-56).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 178384 Time elapsed: 2 minute(s), 41 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI