This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trouble removing stubborn infections

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'll start with the TL;DR (summary)

  • Recurring rootkits under AVG Root-kit free
  • Recurring Downloader.agent.ggt on AVG Anti spyware
  • Recurring random number executable that is blocked by AVG
  • Recurring issue with svchost.exe process that creates many connections successfully if left unattended.

Detailed explanation.

I'm getting two root-kits detected in AVG Root-kit free, labeled as hidden driver files they reside in $windows$\system32\drivers\ and are named a random 8 letter (sometimes containing numbers) every time they are removed. Program wont scan in safe mode.

Downloader.agent.ggt high risk is found with AVG Anti-Spyware, attempted quarantine and delete in both safe mode and normal boot.

I have no idea what is making the random number executable, it is made in the $windows$\temp\ folder, the warning didn't come up on this reboot but i do not think the issue is cleared.

One of the svchost.exe in the process list starts making multiple (at least 5) connections some time after the reboot (or reconnect to the internet) on its own. Even if there are no other programs running at the time. I currently control it by noting when it starts to happen and closing it, as the CPU usage gives it out. Also it appears on the AVG Spyware Analysis under connections. Upon closing it all the connections cease. I currently do not recall if the process starts up on its own again.

Related to the above, apparently on every session in the event viewer security area i get a maximum tcp connections warning. I am not using torrents or p2p so i shouldn't be making such connections. I am worried about the tcpip entries in HiJackThis, im sure these are not normal as ive seen a few other logs, but if everything is being routed through certain IP's i might loose internet access to post here upon forceful removal.

I'm aware i have a lot of odd things related to games, if one isn't recognizable i probably do recognize it.

This is the current HijackThis log, I avoided posting other logs as the sticky said to post the HijackThis one.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:40:21 PM, on 2/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
F:\rc-warhammer\setaffinity\setaffinity_service.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\GRISOFT\AVG Anti-Rootkit Free\avgarkt.exe
C:\Program Files\GRISOFT\AVG Anti-Rootkit Free\6Kf0ki.exe
C:\Program Files\Trend Micro\HijackThis\nohidingplease.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:81
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=userinit.exe,C:\WINDOWS\system32\ntos.exe,
O1 - Hosts: 206.255.16.159 L2authd.lineage2.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [SoundMax] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" /automount
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CBF7EDC-17EC-442C-8AE9-5E804707B6CA} (NeffyClient Class) - http://dist.cdnetworks.co.jp/cdndist/neffy/Neffy.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1159060709606
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1159060656684
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {7C5D062A-7A1E-4A46-A02B-A928084CBD66} (MLauncherNew Class) - http://legendofares.netgame.com/download/MusaLauncherNew.cab
O16 - DPF: {8E9089E1-0461-4F60-8150-1E334629ABB7} (CNeopleInstallAXCtlJap6 Object) - http://down.hangame.co.jp/jp/pudn/pubarad/…er/arad_dis.cab
O16 - DPF: {B905F63D-7489-4B3D-9B62-49A1B8647E2A} (HgPluginJP21 Class) - http://down.hangame.co.jp/jp/dist/hgstart/HGPluginJP21.cab
O16 - DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} (HanSetupCtrl1008 Class) - http://cdn.hangame.com/hangame/hansetup/HanSetup1008.cab
O16 - DPF: {D0FD5E32-CABD-4A6E-BD0F-94ACE89CCE03} (HGPluginJP23 Class) - http://down.hangame.co.jp/jp/dist/hgstart/HGPluginJP23.cab
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - http://d-fighter.nefficient.co.kr/samsungd…Crypt/npkcx.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.2.1.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6E02604C-F26B-45B7-AA4F-2C0AF39E0D7D}: NameServer = 81.169.172.219,81.169.141.30
O17 - HKLM\System\CCS\Services\Tcpip\..\{7A5C0129-65C4-4628-B978-0933FA95C95E}: NameServer = 85.255.116.149,85.255.112.14
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
O17 - HKLM\System\CS5\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
O17 - HKLM\System\CS6\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
O17 - HKLM\System\CS7\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
O17 - HKLM\System\CS8\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
O17 - HKLM\System\CS9\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
O17 - HKLM\System\CS10\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
O17 - HKLM\System\CS11\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
O17 - HKLM\System\CS12\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
O17 - HKLM\System\CS13\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\wicsvc.dll (file missing)
O20 - Winlogon Notify: LogCrypt - LogCrypt.dll (file missing)
O20 - Winlogon Notify: ShellServiceObjectDelayLoad - C:\WINDOWS\system32\degeng.dll (file missing)
O20 - Winlogon Notify: Syncmgr - C:\WINDOWS\system32\h80qlid5180.dll (file missing)
O20 - Winlogon Notify: WLCtrl32 - C:\WINDOWS\SYSTEM32\WLCtrl32.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\system32\npkcsvc.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: Remote Plugin Service - Unknown owner - C:\WINDOWS\system32\lsyss.exe (file missing)
O23 - Service: setaffinity - Unknown owner - F:\rc-warhammer\setaffinity\\setaffinity_service.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 10240 bytes
Hello Scrangos and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem.


A. Please download FixWareout from the following site:
http://download.bleepingcomputer.com/lonny/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts.
You will be asked to reboot your computer; please do so.
Your system may take longer than usual to load; this is normal.
Please post the text that will open (report.txt).


B. We need to temporarily disable some of your security tools so that they do not interfere with our tools:

AVG ANTI-SPYWARE
  • Launch AVG Anti-Spyware.
  • From the "Status" menu, select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'.
  • Then right click on AVG Anti-Spyware in the system tray and uncheck "Start with Windows".



C. Please download ComboFix by sUBs from HERE or HERE directly to your Desktop.

Note: If you already have ComboFix on your machine, please DELETE it from your desktop before downloading the newest version.

Go to [external image: Posted Image] -> Run -> copy/paste the following single line command in the runbox & click OK

"%userprofile%\desktop\combofix.exe" /killall

[external image: Posted Image]
  • ComboFix will automatically start. Any monitoring programs will be shut down like your antivirus, antispyware programs for example.
  • ComboFix may restart your computer, this is normal.
  • When finished, it will produce a log, ComboFix.txt.
  • Please post ComboFix.txt in your next reply along with a new HijackThis log and the report.txt from FixWareOut.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Thank you for your assistance Trevuren. Sorry for the delay, I did not expect such a prompt response which all the traffic in the forum. I have done as instructed with two things to point out.

  • During the combofix stages one of the executables that start with lex asked for internet access, i died it although im fairly certain these are just remnants from an old printer installation.
  • Upon booting up, midway through the combo fix log creation AVG Anti-Virus came up with an alert over a numbered executable, as to not disturb combofix i just let the timer run out.

I would like to point out looking at combofix's log that "F:\rc-warhammer\setaffinity\createproc_hook.dll" is part of a program called setaffinity I use to automatically or forcefully set the processor affinity on a process using a multicore computer. Seems clean, fairly popular among people running programs with compatibility issues regarding multicore processors.


Here are the logs

Fixwareout:

Username "Scrangos" - 02/25/2008 18:12:30 [Fixwareout edited 9/01/2007]

~~~~~ Prerun check


HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
"nameserver"="85.255.116.149 85.255.112.14" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{7A5C0129-65C4-4628-B978-0933FA95C95E}
"nameserver"="85.255.116.149,85.255.112.14" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{04D3759A-5810-424C-B1CD-5E23799CE692}
"DhcpNameServer"="[removed],[removed]" HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{7A5C0129-65C4-4628-B978-0933FA95C95E}
"DhcpNameServer"="[removed],[removed]"
Successfully flushed the DNS Resolver Cache.
System was rebooted successfully.

~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "System"=""
….
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "0mdm" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls "1mdm" Deleted
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion "smksc" Value deleted
HKCR\CLSID\{133B4572-A795-4239-BDDF-7D758A56B99E}\_h\4 Deleted.
….
~~~~~ Misc files.
….
~~~~~ Checking for older varients.
….

~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"amd_dc_opt"="C:\\Program Files\\AMD\\Dual-Core Optimizer\\amd_dc_opt.exe"
"SoundMax"="\"C:\\Program Files\\Analog Devices\\SoundMAX\\Smax4.exe\" /tray"
"SoundMAXPnP"="C:\\Program Files\\Analog Devices\\Core\\smax4pnp.exe"
"IntelliPoint"="\"c:\\Program Files\\Microsoft IntelliPoint\\ipoint.exe\""
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"AtiPTA"="atiptaxx.exe"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"DAEMON Tools Lite"="\"C:\\Program Files\\DAEMON Tools Lite\\daemon.exe\""
"AlcoholAutomount"="\"C:\\Program Files\\Alcohol Soft\\Alcohol 52\\axcmd.exe\" /automount"
….
Hosts file was reset, If you use a custom hosts file please replace it…
~~~~~ End report ~~~~~

Combofix

ComboFix 08-02-25.3 - Scrangos 2008-02-25 18:18:29.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.615 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\desktop\combofix.exe
Command switches used :: /killall

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
The following files were disabled during the run:
F:\rc-warhammer\setaffinity\createproc_hook.dll


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Documents and Settings\Scrangos\Application Data\macromedia\Flash Player\#SharedObjects\TQ4R8SW5\www.broadcaster.com
C:\Documents and Settings\Scrangos\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\WINDOWS\keyboard1.dat
C:\WINDOWS\system32\_004221_.tmp.dll
C:\WINDOWS\system32\_004222_.tmp.dll
C:\WINDOWS\system32\_004223_.tmp.dll
C:\WINDOWS\system32\_004224_.tmp.dll
C:\WINDOWS\system32\3_exception.nls
C:\WINDOWS\system32\drivers\Ubi63.sys
C:\WINDOWS\system32\guard.tmp
C:\WINDOWS\system32\wsnpoem
C:\WINDOWS\system32\wsnpoem\audio.dll
C:\WINDOWS\system32\wsnpoem\audio.dll.cla
C:\WINDOWS\system32\wsnpoem\video.dll
C:\WINDOWS\Temp\152109.exe

—– BITS: Possible infected sites —–

hxxp://laeaberrpatch.everquest2.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CMDSERVICE
——-\LEGACY_NETWORK_MONITOR
——-\LEGACY_SMTPDRV
——-\LEGACY_UBI63
——-\cmdService
——-\Ubi63


((((((((((((((((((((((((( Files Created from 2008-01-25 to 2008-02-25 )))))))))))))))))))))))))))))))
.

2008-02-25 18:12 . 2008-02-25 18:15 d——– C:\fixwareout
2008-02-25 16:22 . 2008-02-25 16:22 d——– C:\Program Files\Trend Micro
2008-02-25 15:50 . 2008-02-25 15:50 d——– C:\Deckard
2008-02-25 15:47 . 2008-02-25 15:49 d——– C:\Program Files\EULAlyzer
2008-02-25 15:34 . 2008-02-25 15:34 30,601 –a—— C:\Documents and Settings\Scrangos\x.exe
2008-02-25 13:48 . 2008-02-25 16:00 7,168 –a—— C:\WINDOWS\system32\WLCtrl32.dll
2008-02-24 23:21 . 2007-09-28 21:05 593,920 ——— C:\WINDOWS\system32\ati2sgag.exe
2008-02-24 12:17 . 2008-02-24 12:17 d——– C:\Documents and Settings\Scrangos\Application Data\Grisoft
2008-02-24 12:17 . 2007-05-30 08:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-24 12:00 . 2008-02-25 06:25 d——– C:\Documents and Settings\Scrangos\Application Data\AVG7
2008-02-24 11:59 . 2008-02-24 11:59 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-24 11:59 . 2008-02-24 12:17 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-24 11:59 . 2008-02-24 12:29 d——– C:\Documents and Settings\All Users\Application Data\avg7
2008-02-24 11:25 . 2007-01-18 08:00 3,968 –a—— C:\WINDOWS\system32\drivers\AvgArCln.sys
2008-02-24 03:27 . 2008-02-24 04:07 d——– C:\Documents and Settings\Administrator\.housecall6.6
2008-02-23 20:32 . 2008-02-23 20:28 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-02-23 20:28 . 2008-02-23 21:41 d——– C:\Documents and Settings\Scrangos\.housecall6.6
2008-02-19 23:01 . 2006-01-31 16:27 126,464 –a—— C:\WINDOWS\system32\madCHook.dll
2008-02-19 19:26 . 2008-02-19 19:27 d——– C:\Program Files\Dofus
2008-02-18 23:05 . 2008-02-18 23:09 d——– C:\Program Files\OpenVPN
2008-02-18 22:30 . 2008-02-18 22:30 d——– C:\Program Files\Your Freedom
2008-02-18 17:39 . 2008-02-18 17:40 d——– C:\Program Files\AutoTunnel GG
2008-02-18 13:19 . 2008-02-18 13:19 d——– C:\Documents and Settings\Scrangos\Builds
2008-02-18 13:12 . 2008-02-18 13:19 d——– C:\Documents and Settings\All Users\Application Data\Outspark
2008-02-17 19:01 . 2008-02-25 16:59 141,612 –a—— C:\WINDOWS\system32\drivers\dump_wmimmc.sys
2008-02-17 17:22 . 2008-02-17 17:22 d——– C:\Program Files\MaxOn Soft
2008-02-17 10:59 . 2008-02-17 11:40 d——– C:\Program Files\SealOnline
2008-02-17 05:15 . 2008-02-17 05:47 d——– C:\Program Files\Neffy
2008-02-14 22:13 . 2007-09-18 23:41 258,352 –a—— C:\WINDOWS\system32\unicows.dll
2008-02-13 18:03 . 2008-02-13 18:03 d——– C:\mGame
2008-02-13 08:11 . 2008-02-13 08:11 d——– C:\Program Files\Common Files\INCA Shared
2008-02-09 15:35 . 2008-02-09 15:35 d——– C:\Program Files\Lavasoft
2008-02-09 15:35 . 2008-02-25 16:14 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-09 01:11 . 2008-02-09 01:11 118,784 –a—— C:\WINDOWS\system32\sbcrreag.dll
2008-02-09 00:00 . 2008-02-09 00:00 d——– C:\Documents and Settings\Scrangos\Application Data\ProxyCap
2008-02-08 23:26 . 2008-02-08 23:47 d——– C:\Program Files\HTTP-Tunnel
2008-02-08 21:02 . 2008-02-08 23:47 d——– C:\Program Files\ProxyWay
2008-02-02 02:05 . 2008-02-02 02:08 d——– C:\Program Files\eVer-Craft
2008-01-30 22:02 . 2008-01-30 22:02 54,608 –a—— C:\WINDOWS\system32\xfcodec.dll
2008-01-30 14:08 . 2008-01-30 14:14 70,656 –a—— C:\WINDOWS\ScUnin.exe
2008-01-30 14:08 . 2008-01-30 14:14 32,653 –a—— C:\WINDOWS\scunin.dat
2008-01-30 14:08 . 2008-01-30 14:14 967 –a—— C:\WINDOWS\ScUnin.pif
2008-01-29 20:41 . 2008-01-29 20:41 25,216 –a—— C:\WINDOWS\system32\drivers\tap0901.sys
2008-01-26 21:28 . 2008-01-26 21:28 d——– C:\Program Files\Microsoft IntelliPoint
2008-01-26 21:28 . 2007-08-21 01:13 21,760 –a—— C:\WINDOWS\system32\drivers\point32.sys
2008-01-26 21:27 . 2008-01-26 21:27 d——– C:\Program Files\MSXML 6.0
2008-01-26 00:28 . 2008-01-26 00:28 d——– C:\Documents and Settings\Scrangos\Application Data\atitray
2008-01-26 00:28 . 2006-02-21 21:05 136,272 –a—— C:\WINDOWS\system32\atmenuxx.hlp
2008-01-26 00:28 . 2006-02-21 21:05 40,651 –a—— C:\WINDOWS\system32\attenuxx.hlp
2008-01-26 00:28 . 2006-02-21 21:05 23,224 –a—— C:\WINDOWS\system32\atfenuxx.hlp
2008-01-26 00:20 . 2008-02-24 22:28 d——– C:\Program Files\Radeon Omega Drivers
2008-01-26 00:20 . 2008-02-24 22:37 d——– C:\Program Files\MultiRes
2008-01-26 00:20 . 2008-01-26 00:20 472,576 –a—— C:\WINDOWS\Radeon Omega Drivers v4.8.442 Uninstall.exe
2008-01-25 22:15 . 2008-01-25 22:19 139,264 –a—— C:\WINDOWS\War3Unin.exe
2008-01-25 22:15 . 2008-02-06 20:41 76,254 –a—— C:\WINDOWS\War3Unin.dat
2008-01-25 22:15 . 2008-01-25 22:19 2,829 –a—— C:\WINDOWS\War3Unin.pif
2008-01-25 21:36 . 2008-01-25 21:34 51,472 –a–c— C:\WINDOWS\system32\dllcache\imagecfg.exe
2008-01-25 21:35 . 2008-01-25 21:34 51,472 –a—— C:\WINDOWS\system32\imagecfg.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-25 22:26 17,788,960 –sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-02-25 22:24 212,624 –sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-02-25 22:12 ——— d—–w C:\Program Files\Trillian
2008-02-25 20:14 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-25 19:52 ——— d—–w C:\Program Files\SpywareBlaster
2008-02-25 19:34 ——— d—–w C:\Program Files\VisualRoute
2008-02-24 22:16 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\MegauploadToolbar
2008-02-24 21:07 ——— d—–w C:\Program Files\Game Elements PC Recoil Pad
2008-02-24 16:21 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\Free Download Manager
2008-02-23 01:37 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-22 18:41 ——— d—–w C:\Program Files\Granado Espada
2008-02-20 23:13 ——— d—–w C:\Program Files\mIRC
2008-02-17 14:58 65,536 —-a-w C:\WINDOWS\IFinst27.exe
2008-02-17 03:40 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\Xfire
2008-02-16 13:15 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\IGN_DLM
2008-02-09 19:13 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\Lavasoft
2008-02-07 19:58 107,888 —-a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-02-01 07:28 ——— d—–w C:\Program Files\World of Warcraft
2008-01-27 19:52 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\ATI
2008-01-27 19:40 13,824 —-a-w C:\WINDOWS\Internet Logs\xDB4.tmp
2008-01-27 19:40 1,893,376 —-a-w C:\WINDOWS\Internet Logs\xDB5.tmp
2008-01-27 19:39 2,464,256 —-a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2008-01-27 19:39 1,893,376 —-a-w C:\WINDOWS\Internet Logs\xDB3.tmp
2008-01-26 23:53 ——— d—–w C:\Program Files\Warkeys
2008-01-22 21:27 ——— d—–w C:\Program Files\Codec Pack - All In 1
2008-01-22 21:25 737,280 —-a-w C:\WINDOWS\iun6002.exe
2008-01-18 00:44 ——— d—–w C:\Program Files\Analog Devices
2008-01-15 19:46 3,521,897 —-a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2008-01-15 00:16 ——— d—–w C:\Program Files\Sims2Pack Clean Installer
2008-01-15 00:16 ——— d—–w C:\Program Files\SimPE
2008-01-12 22:06 ——— d—–w C:\Program Files\EA GAMES
2008-01-12 03:08 ——— d—–w C:\Program Files\Alcohol Soft
2008-01-07 20:11 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\Sonic
2008-01-07 20:07 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\Leadertech
2008-01-07 20:04 ——— d—–w C:\Program Files\Sonic
2008-01-06 17:10 ——— d—–w C:\Program Files\Microsoft ActiveSync
2008-01-06 17:10 ——— d—–w C:\Program Files\Common Files\L&H;
2008-01-06 17:09 ——— d—–w C:\Program Files\Microsoft Works
2008-01-06 17:08 ——— d—–w C:\Program Files\Microsoft.NET
2008-01-05 12:45 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\OpenOffice.org2
2008-01-04 22:41 ——— d—–w C:\Program Files\Black Isle
2008-01-04 22:29 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\DAEMON Tools
2008-01-04 22:27 ——— d—–w C:\Program Files\DAEMON Tools Lite
2008-01-03 21:01 715,248 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-01-03 21:01 ——— d—–w C:\Program Files\DAEMON Tools Pro
2008-01-03 10:43 21,760 —-a-w C:\WINDOWS\system32\drivers\Cjp28.sys
2007-12-28 12:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Insight Software Solutions
2007-12-28 12:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Insight Software
2007-12-21 02:24 46,080 —-a-w C:\WINDOWS\system32\amdpcom32.dll
2007-12-15 04:53 2,541,056 —-a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2007-12-05 03:05 368,640 —-a-w C:\WINDOWS\system32\ATIDEMGX.dll
2007-12-05 03:04 269,312 —-a-w C:\WINDOWS\system32\ati2dvag.dll
2007-12-05 02:56 147,456 —-a-w C:\WINDOWS\system32\atipdlxx.dll
2007-12-05 02:55 43,520 —-a-w C:\WINDOWS\system32\ati2edxx.dll
2007-12-05 02:55 26,112 —-a-w C:\WINDOWS\system32\Ati2mdxx.exe
2007-12-05 02:55 122,880 —-a-w C:\WINDOWS\system32\Oemdspif.dll
2007-12-05 02:55 122,880 —-a-w C:\WINDOWS\system32\ati2evxx.dll
2007-12-05 02:53 53,248 —-a-w C:\WINDOWS\system32\ATIDDC.DLL
2007-12-05 02:53 495,616 —-a-w C:\WINDOWS\system32\ati2evxx.exe
2007-12-05 02:48 9,535,488 —-a-w C:\WINDOWS\system32\atioglx2.dll
2007-12-05 02:44 3,175,584 —-a-w C:\WINDOWS\system32\ati3duag.dll
2007-12-05 02:33 1,640,192 —-a-w C:\WINDOWS\system32\ativvaxx.dll
2007-12-05 02:19 5,435,392 —-a-w C:\WINDOWS\system32\atioglxx.dll
2007-12-05 02:19 385,024 —-a-w C:\WINDOWS\system32\atikvmag.dll
2007-12-05 02:17 17,408 —-a-w C:\WINDOWS\system32\atitvo32.dll
2007-12-05 02:14 180,224 —-a-w C:\WINDOWS\system32\atiok3x2.dll
2007-12-05 02:11 499,712 —-a-w C:\WINDOWS\system32\ati2cqag.dll
2007-04-19 22:42 205,778 —-a-w C:\Program Files\CustomKeys.txt
2006-11-20 07:54 202,277,175 —-a-w C:\Program Files\se.ipf
2006-10-05 17:58 1,134,282,010 —-a-w C:\Documents and Settings\Scrangos\RAG_SETUP0711.exe
2004-07-18 02:55 460,728 —-a-w C:\WINDOWS\Fonts\SET4C2.tmp
2004-07-18 02:55 383,140 —-a-w C:\WINDOWS\Fonts\SET4C1.tmp
2004-07-18 02:55 355,436 —-a-w C:\WINDOWS\Fonts\SET4C0.tmp
2004-07-17 15:39 409,280 —-a-w C:\WINDOWS\Fonts\SET4BF.tmp
2004-07-17 15:39 398,372 —-a-w C:\WINDOWS\Fonts\SET4BE.tmp
2004-07-17 15:39 367,112 —-a-w C:\WINDOWS\Fonts\SET4C6.tmp
2004-07-17 15:39 352,224 —-a-w C:\WINDOWS\Fonts\SET4C5.tmp
2004-07-17 15:39 171,792 —-a-w C:\WINDOWS\Fonts\SET4BC.tmp
2004-07-17 15:39 155,068 —-a-w C:\WINDOWS\Fonts\SET4C3.tmp
2004-07-17 15:39 134,108 —-a-w C:\WINDOWS\Fonts\SET4BD.tmp
2004-07-17 15:39 127,596 —-a-w C:\WINDOWS\Fonts\SET4C4.tmp
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-01-03 09:54 486856]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" [2007-12-22 03:09 221056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14 919016]
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14 919016]
"amd_dc_opt"="C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2006-11-17 16:49 77824]
"SoundMax"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2006-05-18 14:26 729088]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-05-18 14:22 843776]
"IntelliPoint"="c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 12:01 1037736]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-24 11:59 579072]
"AtiPTA"="atiptaxx.exe" [2006-02-21 21:05 344064 C:\WINDOWS\system32\atiptaxx.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-24 11:59 219136]

C:\Documents and Settings\test17\Start Menu\Programs\Startup\
OpenOffice.org 2.0.lnk - C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe [2006-07-14 21:26:34 393216]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LogCrypt]
LogCrypt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WLCtrl32]
WLCtrl32.dll 2008-02-25 16:00 7168 C:\WINDOWS\system32\WLCtrl32.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.exe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TabUserW.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TabUserW.exe.lnk
backup=C:\WINDOWS\pss\TabUserW.exe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Scrangos^Start Menu^Programs^Startup^hamachi.lnk]
path=C:\Documents and Settings\Scrangos\Start Menu\Programs\Startup\hamachi.lnk
backup=C:\WINDOWS\pss\hamachi.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ANIWZCS2Service]
–a—— 2004-08-16 16:45 45056 C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\D-Link AirPlus G]
–a—— 2004-08-18 11:47 1249280 C:\Program Files\D-Link\AirPlus G\AirGCFG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
C:\Program Files\DAEMON Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\defender]
C:\\dfndrff_e21.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
–a—— 2007-03-05 17:57 1103480 C:\Program Files\Download Manager\DLM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMEKRMIG6.1]
–a—— 2001-08-23 18:00 44032 C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
–a—— 2004-08-03 22:32 208952 C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
–a—— 2005-08-11 15:30 249856 C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
–a—— 2005-08-11 15:30 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\keyboard]
C:\\kybrdff_e21.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 3100 Series]
–a—— 2003-07-28 18:50 106496 C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXBRKsk]
–a—— 2003-06-13 14:57 294912 C:\PROGRA~1\LEXMAR~1\LXBRKsk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
–a—— 2004-08-03 22:31 59392 C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\newname]
C:\\nwnmff_e21.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
–a—— 2004-08-03 22:32 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
–a—— 2004-08-03 22:32 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
–a—— 2004-11-02 20:24 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
–a—— 2006-05-18 14:26 729088 C:\Program Files\Analog Devices\SoundMAX\Smax4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
–a—— 2006-05-18 14:22 843776 C:\Program Files\Analog Devices\Core\smax4pnp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
–a—— 2004-05-12 01:03 1038336 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2005-11-10 13:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"ANIWZCS2Service"=C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
"newname"=C:\\nwnmff_e21.exe
"MSPY2002"=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
"IMEKRMIG6.1"=C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"F:\\Program Files\\Flagship Studios\\Hellgate London\\Launcher.exe"=
"F:\\Program Files\\Flagship Studios\\Mythos\\bin\\Mythos.exe"=
"C:\\Program Files\\GRISOFT\\AVG7\\avginet.exe"=
"C:\\Program Files\\GRISOFT\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\GRISOFT\\AVG7\\avgcc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9842:TCP"= 9842:TCP:*:Disabled:SolidNetworkManager
"9842:UDP"= 9842:UDP:*:Disabled:SolidNetworkManager
"10737:TCP"= 10737:TCP:*:Disabled:SolidNetworkManager
"10737:UDP"= 10737:UDP:*:Disabled:SolidNetworkManager
"12623:TCP"= 12623:TCP:*:Disabled:SolidNetworkManager
"12623:UDP"= 12623:UDP:*:Disabled:SolidNetworkManager

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{de76d8ed-c53c-11dc-bd14-001731cadcc1}]
\shell\Setup\command - E:\setup.exe

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-25 18:26:06
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
F:\rc-warhammer\setaffinity\setaffinity_service.exe
c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
.
**************************************************************************
.
Completion time: 2008-02-25 18:30:47 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-25 22:30:43

HijackThis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:35, on 2008-02-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
F:\rc-warhammer\setaffinity\setaffinity_service.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\hopeful.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:81
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [SoundMax] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" /automount
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CBF7EDC-17EC-442C-8AE9-5E804707B6CA} (NeffyClient Class) - http://dist.cdnetworks.co.jp/cdndist/neffy/Neffy.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1159060709606
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1159060656684
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {7C5D062A-7A1E-4A46-A02B-A928084CBD66} (MLauncherNew Class) - http://legendofares.netgame.com/download/MusaLauncherNew.cab
O16 - DPF: {8E9089E1-0461-4F60-8150-1E334629ABB7} (CNeopleInstallAXCtlJap6 Object) - http://down.hangame.co.jp/jp/pudn/pubarad/…er/arad_dis.cab
O16 - DPF: {B905F63D-7489-4B3D-9B62-49A1B8647E2A} (HgPluginJP21 Class) - http://down.hangame.co.jp/jp/dist/hgstart/HGPluginJP21.cab
O16 - DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} (HanSetupCtrl1008 Class) - http://cdn.hangame.com/hangame/hansetup/HanSetup1008.cab
O16 - DPF: {D0FD5E32-CABD-4A6E-BD0F-94ACE89CCE03} (HGPluginJP23 Class) - http://down.hangame.co.jp/jp/dist/hgstart/HGPluginJP23.cab
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - http://d-fighter.nefficient.co.kr/samsungd…Crypt/npkcx.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.2.1.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6E02604C-F26B-45B7-AA4F-2C0AF39E0D7D}: NameServer = 81.169.172.219,81.169.141.30
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
O17 - HKLM\System\CS5\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
O17 - HKLM\System\CS6\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
O17 - HKLM\System\CS7\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
O17 - HKLM\System\CS8\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
O17 - HKLM\System\CS9\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
O17 - HKLM\System\CS10\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
O17 - HKLM\System\CS11\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
O20 - Winlogon Notify: LogCrypt - LogCrypt.dll (file missing)
O20 - Winlogon Notify: WLCtrl32 - C:\WINDOWS\SYSTEM32\WLCtrl32.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\system32\npkcsvc.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: Remote Plugin Service - Unknown owner - C:\WINDOWS\system32\lsyss.exe (file missing)
O23 - Service: setaffinity - Unknown owner - F:\rc-warhammer\setaffinity\\setaffinity_service.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 8908 bytes
A. Please make sure that all security programs remain disabled.


B. Please RUN HijackThis
  • Click the SCAN button to produce a log.

  • Place a check mark beside each one of the following items:

    O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
    O16 - DPF: {8E9089E1-0461-4F60-8150-1E334629ABB7} (CNeopleInstallAXCtlJap6 Object) - http://down.hangame.co.jp/jp/pudn/pubarad/…er/arad_dis.cab
    O16 - DPF: {B905F63D-7489-4B3D-9B62-49A1B8647E2A} (HgPluginJP21 Class) - http://down.hangame.co.jp/jp/dist/hgstart/HGPluginJP21.cab
    O16 - DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} (HanSetupCtrl1008 Class) - http://cdn.hangame.com/hangame/hansetup/HanSetup1008.cab
    O16 - DPF: {D0FD5E32-CABD-4A6E-BD0F-94ACE89CCE03} (HGPluginJP23 Class) - http://down.hangame.co.jp/jp/dist/hgstart/HGPluginJP23.cab
    O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - http://d-fighter.nefficient.co.kr/samsungd…Crypt/npkcx.cab
    O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.2.1.cab
    O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
    O17 - HKLM\System\CS5\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
    O17 - HKLM\System\CS6\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
    O17 - HKLM\System\CS7\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
    O17 - HKLM\System\CS8\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
    O17 - HKLM\System\CS9\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
    O17 - HKLM\System\CS10\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14
    O17 - HKLM\System\CS11\Services\Tcpip\Parameters: NameServer = 85.255.116.149 85.255.112.14


  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.


C. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\fixwareout
C:\Program Files\EULAlyzer
C:\WINDOWS\Fonts\SET4C2.tmp
C:\WINDOWS\Fonts\SET4C1.tmp
C:\WINDOWS\Fonts\SET4C0.tmp
C:\WINDOWS\Fonts\SET4BF.tmp
C:\WINDOWS\Fonts\SET4BE.tmp
C:\WINDOWS\Fonts\SET4C6.tmp
C:\WINDOWS\Fonts\SET4C5.tmp
C:\WINDOWS\Fonts\SET4BC.tmp
C:\WINDOWS\Fonts\SET4C3.tmp
C:\WINDOWS\Fonts\SET4BD.tmp
C:\WINDOWS\Fonts\SET4C4.tmp
C:\WINDOWS\system32\WLCtrl32.dll
C:\WINDOWS\system32\madCHook.dll
C:\WINDOWS\system32\drivers\dump_wmimmc.sys
C:\WINDOWS\Internet Logs\xDB4.tmp
C:\WINDOWS\Internet Logs\xDB5.tmp
C:\WINDOWS\Internet Logs\xDB2.tmp
C:\WINDOWS\Internet Logs\xDB3.tmp
C:\WINDOWS\Internet Logs\xDB1.tmp
C:\WINDOWS\system32\drivers\Cjp28.sys
C:\WINDOWS\IFinst27.exe
E:\setup.exe

DirLook::
C:\mGame

Driver::
Remote Plugin Service

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LogCrypt]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WLCtrl32]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{de76d8ed-c53c-11dc-bd14-001731cadcc1}]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\defender]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\keyboard]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\newname]
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

5. All your monitoring programs (Antivirus/Antispyware, Guards and Shields) will be stopped.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.



D. Using Internet Explorer, please do a Kaspersky Online Scan

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will provide a report if your system is infected. It does not provide an option to clean/disinfect. We only require a report from it.

    [external image: Posted Image]

  • Click the Save as Text button to save the file to your desktop and post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan
Hello, sorry for the delays. The karpersky scan took a long time as I have too many files on the computer.

During the combofix run an svchost crashed (gave the usual window to send a report) and then got a blue screen (This was an odd blue screen however, not filled with the usual information, said Hard Stop and a code that was around 0x00000a2c, i regret not writing it down but it has probably nothing to do with the issue). Since combo fix was running under a set of instructions I figured it would be safe to run it again, however the log of the successful completion might not be as complete as it should be.

As tempted as i was to go on a witch hunt with the kapersky log I have only done as instructed and I'm awaiting further action.

Edit: Ack i just went over the instructions for ComboFix and i made a blunder, i left my pendrive connected and a setup file was deleted @.@ My fault for leaving it in.

Things I'd like to point out from the logs and actions:
  • mGame folder contains an ini for a game called Holic (the usa version), asian programmed games sometimes install in weird ways. It seems safe, would be odd for larger companies to risk malware.
  • I'm both shocked and confused that the mirc installer (the one in rc-warhammer) contains a virus, since i downloaded it from an official source. Unless that not-a-virus is just a warning as an exception by the mirc programmers or Kapersky and not a clever joke of the virus programmer…
  • While i did as instructed I'd like to point out that d-fighter.nefficient.co.kr and down.hangame.co.jp urls are related to games that have to start their main program by logging in and clicking a link on the main webpage. Both are the same game, one in japanese (Arado Senki) and one in korean (Dungeon & Fighter). Again, two fairly large companies.


Here are the logs:

Combofix

ComboFix 08-02-25.3 - Scrangos 2008-02-25 20:24:33.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.659 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Scrangos\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\fixwareout
C:\Program Files\EULAlyzer
C:\WINDOWS\Fonts\SET4BC.tmp
C:\WINDOWS\Fonts\SET4BD.tmp
C:\WINDOWS\Fonts\SET4BE.tmp
C:\WINDOWS\Fonts\SET4BF.tmp
C:\WINDOWS\Fonts\SET4C0.tmp
C:\WINDOWS\Fonts\SET4C1.tmp
C:\WINDOWS\Fonts\SET4C2.tmp
C:\WINDOWS\Fonts\SET4C3.tmp
C:\WINDOWS\Fonts\SET4C4.tmp
C:\WINDOWS\Fonts\SET4C5.tmp
C:\WINDOWS\Fonts\SET4C6.tmp
C:\WINDOWS\IFinst27.exe
C:\WINDOWS\Internet Logs\xDB1.tmp
C:\WINDOWS\Internet Logs\xDB2.tmp
C:\WINDOWS\Internet Logs\xDB3.tmp
C:\WINDOWS\Internet Logs\xDB4.tmp
C:\WINDOWS\Internet Logs\xDB5.tmp
C:\WINDOWS\system32\drivers\Cjp28.sys
C:\WINDOWS\system32\drivers\dump_wmimmc.sys
C:\WINDOWS\system32\madCHook.dll
C:\WINDOWS\system32\WLCtrl32.dll
E:\setup.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\drivers\Cjp28.sys
.
—- Previous Run ——-
.
C:\WINDOWS\Fonts\SET4BC.tmp
C:\WINDOWS\Fonts\SET4BD.tmp
C:\WINDOWS\Fonts\SET4BE.tmp
C:\WINDOWS\Fonts\SET4BF.tmp
C:\WINDOWS\Fonts\SET4C0.tmp
C:\WINDOWS\Fonts\SET4C1.tmp
C:\WINDOWS\Fonts\SET4C2.tmp
C:\WINDOWS\Fonts\SET4C3.tmp
C:\WINDOWS\Fonts\SET4C4.tmp
C:\WINDOWS\Fonts\SET4C5.tmp
C:\WINDOWS\Fonts\SET4C6.tmp
C:\WINDOWS\IFinst27.exe
C:\WINDOWS\Internet Logs\xDB1.tmp
C:\WINDOWS\Internet Logs\xDB2.tmp
C:\WINDOWS\Internet Logs\xDB3.tmp
C:\WINDOWS\Internet Logs\xDB4.tmp
C:\WINDOWS\Internet Logs\xDB5.tmp
C:\WINDOWS\system32\8_exception.nls
C:\WINDOWS\system32\drivers\dump_wmimmc.sys
C:\WINDOWS\system32\madCHook.dll
C:\WINDOWS\system32\WLCtrl32.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_REMOTE_PLUGIN_SERVICE
——-\Remote Plugin Service


——-\LEGACY_REMOTE_PLUGIN_SERVICE
——-\Remote Plugin Service


((((((((((((((((((((((((( Files Created from 2008-01-26 to 2008-02-26 )))))))))))))))))))))))))))))))
.

2008-02-25 18:12 . 2008-02-25 18:15 d——– C:\fixwareout
2008-02-25 16:22 . 2008-02-25 16:22 d——– C:\Program Files\Trend Micro
2008-02-25 15:50 . 2008-02-25 15:50 d——– C:\Deckard
2008-02-25 15:47 . 2008-02-25 15:49 d——– C:\Program Files\EULAlyzer
2008-02-25 15:34 . 2008-02-25 15:34 30,601 –a—— C:\Documents and Settings\Scrangos\x.exe
2008-02-24 23:21 . 2007-09-28 21:05 593,920 ——— C:\WINDOWS\system32\ati2sgag.exe
2008-02-24 12:17 . 2008-02-24 12:17 d——– C:\Documents and Settings\Scrangos\Application Data\Grisoft
2008-02-24 12:17 . 2007-05-30 08:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-24 12:00 . 2008-02-25 06:25 d——– C:\Documents and Settings\Scrangos\Application Data\AVG7
2008-02-24 11:59 . 2008-02-24 11:59 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-24 11:59 . 2008-02-24 12:17 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-24 11:59 . 2008-02-24 12:29 d——– C:\Documents and Settings\All Users\Application Data\avg7
2008-02-24 11:25 . 2007-01-18 08:00 3,968 –a—— C:\WINDOWS\system32\drivers\AvgArCln.sys
2008-02-24 03:27 . 2008-02-24 04:07 d——– C:\Documents and Settings\Administrator\.housecall6.6
2008-02-23 20:32 . 2008-02-23 20:28 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-02-23 20:28 . 2008-02-23 21:41 d——– C:\Documents and Settings\Scrangos\.housecall6.6
2008-02-19 19:26 . 2008-02-19 19:27 d——– C:\Program Files\Dofus
2008-02-18 23:05 . 2008-02-18 23:09 d——– C:\Program Files\OpenVPN
2008-02-18 22:30 . 2008-02-18 22:30 d——– C:\Program Files\Your Freedom
2008-02-18 17:39 . 2008-02-18 17:40 d——– C:\Program Files\AutoTunnel GG
2008-02-18 13:19 . 2008-02-18 13:19 d——– C:\Documents and Settings\Scrangos\Builds
2008-02-18 13:12 . 2008-02-18 13:19 d——– C:\Documents and Settings\All Users\Application Data\Outspark
2008-02-17 17:22 . 2008-02-17 17:22 d——– C:\Program Files\MaxOn Soft
2008-02-17 10:59 . 2008-02-17 11:40 d——– C:\Program Files\SealOnline
2008-02-17 05:15 . 2008-02-17 05:47 d——– C:\Program Files\Neffy
2008-02-14 22:13 . 2007-09-18 23:41 258,352 –a—— C:\WINDOWS\system32\unicows.dll
2008-02-13 18:03 . 2008-02-13 18:03 d——– C:\mGame
2008-02-13 08:11 . 2008-02-13 08:11 d——– C:\Program Files\Common Files\INCA Shared
2008-02-09 15:35 . 2008-02-09 15:35 d——– C:\Program Files\Lavasoft
2008-02-09 15:35 . 2008-02-25 16:14 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-09 01:11 . 2008-02-09 01:11 118,784 –a—— C:\WINDOWS\system32\sbcrreag.dll
2008-02-09 00:00 . 2008-02-09 00:00 d——– C:\Documents and Settings\Scrangos\Application Data\ProxyCap
2008-02-08 23:26 . 2008-02-08 23:47 d——– C:\Program Files\HTTP-Tunnel
2008-02-08 21:02 . 2008-02-08 23:47 d——– C:\Program Files\ProxyWay
2008-02-02 02:05 . 2008-02-02 02:08 d——– C:\Program Files\eVer-Craft
2008-01-30 22:02 . 2008-01-30 22:02 54,608 –a—— C:\WINDOWS\system32\xfcodec.dll
2008-01-30 14:08 . 2008-01-30 14:14 70,656 –a—— C:\WINDOWS\ScUnin.exe
2008-01-30 14:08 . 2008-01-30 14:14 32,653 –a—— C:\WINDOWS\scunin.dat
2008-01-30 14:08 . 2008-01-30 14:14 967 –a—— C:\WINDOWS\ScUnin.pif
2008-01-29 20:41 . 2008-01-29 20:41 25,216 –a—— C:\WINDOWS\system32\drivers\tap0901.sys
2008-01-26 21:28 . 2008-01-26 21:28 d——– C:\Program Files\Microsoft IntelliPoint
2008-01-26 21:28 . 2007-08-21 01:13 21,760 –a—— C:\WINDOWS\system32\drivers\point32.sys
2008-01-26 21:27 . 2008-01-26 21:27 d——– C:\Program Files\MSXML 6.0
2008-01-26 00:28 . 2008-01-26 00:28 d——– C:\Documents and Settings\Scrangos\Application Data\atitray
2008-01-26 00:28 . 2006-02-21 21:05 136,272 –a—— C:\WINDOWS\system32\atmenuxx.hlp
2008-01-26 00:28 . 2006-02-21 21:05 40,651 –a—— C:\WINDOWS\system32\attenuxx.hlp
2008-01-26 00:28 . 2006-02-21 21:05 23,224 –a—— C:\WINDOWS\system32\atfenuxx.hlp
2008-01-26 00:20 . 2008-02-24 22:28 d——– C:\Program Files\Radeon Omega Drivers
2008-01-26 00:20 . 2008-02-24 22:37 d——– C:\Program Files\MultiRes
2008-01-26 00:20 . 2008-01-26 00:20 472,576 –a—— C:\WINDOWS\Radeon Omega Drivers v4.8.442 Uninstall.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-26 00:29 213,008 –sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-02-26 00:29 17,838,112 –sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-02-26 00:19 5,521,896 —-a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2008-02-26 00:03 ——— d—–w C:\Program Files\Trillian
2008-02-25 20:14 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-25 19:52 ——— d—–w C:\Program Files\SpywareBlaster
2008-02-25 19:34 ——— d—–w C:\Program Files\VisualRoute
2008-02-24 22:16 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\MegauploadToolbar
2008-02-24 21:07 ——— d—–w C:\Program Files\Game Elements PC Recoil Pad
2008-02-24 16:21 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\Free Download Manager
2008-02-23 01:37 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-22 18:41 ——— d—–w C:\Program Files\Granado Espada
2008-02-20 23:13 ——— d—–w C:\Program Files\mIRC
2008-02-17 03:40 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\Xfire
2008-02-16 13:15 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\IGN_DLM
2008-02-09 19:13 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\Lavasoft
2008-02-07 19:58 107,888 —-a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-02-01 07:28 ——— d—–w C:\Program Files\World of Warcraft
2008-01-27 19:52 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\ATI
2008-01-26 23:53 ——— d—–w C:\Program Files\Warkeys
2008-01-26 02:19 139,264 —-a-w C:\WINDOWS\War3Unin.exe
2008-01-26 01:34 51,472 —-a-w C:\WINDOWS\system32\imagecfg.exe
2008-01-22 21:27 ——— d—–w C:\Program Files\Codec Pack - All In 1
2008-01-22 21:25 737,280 —-a-w C:\WINDOWS\iun6002.exe
2008-01-18 00:44 ——— d—–w C:\Program Files\Analog Devices
2008-01-15 00:16 ——— d—–w C:\Program Files\Sims2Pack Clean Installer
2008-01-15 00:16 ——— d—–w C:\Program Files\SimPE
2008-01-12 22:06 ——— d—–w C:\Program Files\EA GAMES
2008-01-12 03:08 ——— d—–w C:\Program Files\Alcohol Soft
2008-01-07 20:11 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\Sonic
2008-01-07 20:07 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\Leadertech
2008-01-07 20:04 ——— d—–w C:\Program Files\Sonic
2008-01-06 17:10 ——— d—–w C:\Program Files\Microsoft ActiveSync
2008-01-06 17:10 ——— d—–w C:\Program Files\Common Files\L&H;
2008-01-06 17:09 ——— d—–w C:\Program Files\Microsoft Works
2008-01-06 17:08 ——— d—–w C:\Program Files\Microsoft.NET
2008-01-05 12:45 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\OpenOffice.org2
2008-01-04 22:41 ——— d—–w C:\Program Files\Black Isle
2008-01-04 22:29 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\DAEMON Tools
2008-01-04 22:27 ——— d—–w C:\Program Files\DAEMON Tools Lite
2008-01-03 21:01 715,248 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-01-03 21:01 ——— d—–w C:\Program Files\DAEMON Tools Pro
2007-12-28 12:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Insight Software Solutions
2007-12-28 12:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Insight Software
2007-12-21 02:24 46,080 —-a-w C:\WINDOWS\system32\amdpcom32.dll
2007-12-05 03:05 368,640 —-a-w C:\WINDOWS\system32\ATIDEMGX.dll
2007-12-05 03:04 269,312 —-a-w C:\WINDOWS\system32\ati2dvag.dll
2007-12-05 02:56 147,456 —-a-w C:\WINDOWS\system32\atipdlxx.dll
2007-12-05 02:55 43,520 —-a-w C:\WINDOWS\system32\ati2edxx.dll
2007-12-05 02:55 26,112 —-a-w C:\WINDOWS\system32\Ati2mdxx.exe
2007-12-05 02:55 122,880 —-a-w C:\WINDOWS\system32\Oemdspif.dll
2007-12-05 02:55 122,880 —-a-w C:\WINDOWS\system32\ati2evxx.dll
2007-12-05 02:53 53,248 —-a-w C:\WINDOWS\system32\ATIDDC.DLL
2007-12-05 02:53 495,616 —-a-w C:\WINDOWS\system32\ati2evxx.exe
2007-12-05 02:48 9,535,488 —-a-w C:\WINDOWS\system32\atioglx2.dll
2007-12-05 02:44 3,175,584 —-a-w C:\WINDOWS\system32\ati3duag.dll
2007-12-05 02:33 1,640,192 —-a-w C:\WINDOWS\system32\ativvaxx.dll
2007-12-05 02:19 5,435,392 —-a-w C:\WINDOWS\system32\atioglxx.dll
2007-12-05 02:19 385,024 —-a-w C:\WINDOWS\system32\atikvmag.dll
2007-12-05 02:17 17,408 —-a-w C:\WINDOWS\system32\atitvo32.dll
2007-12-05 02:14 180,224 —-a-w C:\WINDOWS\system32\atiok3x2.dll
2007-12-05 02:11 499,712 —-a-w C:\WINDOWS\system32\ati2cqag.dll
2007-04-19 22:42 205,778 —-a-w C:\Program Files\CustomKeys.txt
2006-11-20 07:54 202,277,175 —-a-w C:\Program Files\se.ipf
2006-10-05 17:58 1,134,282,010 —-a-w C:\Documents and Settings\Scrangos\RAG_SETUP0711.exe
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

—- Directory of C:\mGame —-

2008-02-13 18:03 173 –a—— C:\mGame\Common\HolicUSA.ini


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-01-03 09:54 486856]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" [2007-12-22 03:09 221056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14 919016]
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14 919016]
"amd_dc_opt"="C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2006-11-17 16:49 77824]
"SoundMax"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2006-05-18 14:26 729088]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-05-18 14:22 843776]
"IntelliPoint"="c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 12:01 1037736]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-24 11:59 579072]
"AtiPTA"="atiptaxx.exe" [2006-02-21 21:05 344064 C:\WINDOWS\system32\atiptaxx.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-24 11:59 219136]

C:\Documents and Settings\test17\Start Menu\Programs\Startup\
OpenOffice.org 2.0.lnk - C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe [2006-07-14 21:26:34 393216]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.exe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TabUserW.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TabUserW.exe.lnk
backup=C:\WINDOWS\pss\TabUserW.exe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Scrangos^Start Menu^Programs^Startup^hamachi.lnk]
path=C:\Documents and Settings\Scrangos\Start Menu\Programs\Startup\hamachi.lnk
backup=C:\WINDOWS\pss\hamachi.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ANIWZCS2Service]
–a—— 2004-08-16 16:45 45056 C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\D-Link AirPlus G]
–a—— 2004-08-18 11:47 1249280 C:\Program Files\D-Link\AirPlus G\AirGCFG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
–a—— 2007-03-05 17:57 1103480 C:\Program Files\Download Manager\DLM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMEKRMIG6.1]
–a—— 2001-08-23 18:00 44032 C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
–a—— 2004-08-03 22:32 208952 C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
–a—— 2005-08-11 15:30 249856 C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
–a—— 2005-08-11 15:30 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 3100 Series]
–a—— 2003-07-28 18:50 106496 C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXBRKsk]
–a—— 2003-06-13 14:57 294912 C:\PROGRA~1\LEXMAR~1\LXBRKsk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
–a—— 2004-08-03 22:31 59392 C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
–a—— 2004-08-03 22:32 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
–a—— 2004-08-03 22:32 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
–a—— 2004-11-02 20:24 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
–a—— 2006-05-18 14:26 729088 C:\Program Files\Analog Devices\SoundMAX\Smax4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
–a—— 2006-05-18 14:22 843776 C:\Program Files\Analog Devices\Core\smax4pnp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
–a—— 2004-05-12 01:03 1038336 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2005-11-10 13:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"ANIWZCS2Service"=C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
"newname"=C:\\nwnmff_e21.exe
"MSPY2002"=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
"IMEKRMIG6.1"=C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"F:\\Program Files\\Flagship Studios\\Hellgate London\\Launcher.exe"=
"F:\\Program Files\\Flagship Studios\\Mythos\\bin\\Mythos.exe"=
"C:\\Program Files\\GRISOFT\\AVG7\\avginet.exe"=
"C:\\Program Files\\GRISOFT\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\GRISOFT\\AVG7\\avgcc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9842:TCP"= 9842:TCP:*:Disabled:SolidNetworkManager
"9842:UDP"= 9842:UDP:*:Disabled:SolidNetworkManager
"10737:TCP"= 10737:TCP:*:Disabled:SolidNetworkManager
"10737:UDP"= 10737:UDP:*:Disabled:SolidNetworkManager
"12623:TCP"= 12623:TCP:*:Disabled:SolidNetworkManager
"12623:UDP"= 12623:UDP:*:Disabled:SolidNetworkManager

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-25 20:30:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
.
**************************************************************************
.
Completion time: 2008-02-25 20:36:22 - machine was rebooted [Scrangos]
ComboFix-quarantined-files.txt 2008-02-26 00:36:19
ComboFix2.txt 2008-02-25 22:30:48


Kapersky

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
2008-02-26 14:46
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 26/02/2008
Kaspersky Anti-Virus database records: 581658
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\

Scan Statistics:
Total number of scanned objects: 302139
Number of viruses found: 9
Number of infected objects: 16
Number of suspicious objects: 2
Duration of the scan process: 05:12:39

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC3.zip/drsmartload.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC3.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Scrangos\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Scrangos\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Scrangos\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Scrangos\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Scrangos\Local Settings\History\History.IE5\MSHist012008022620080227\index.dat Object is locked skipped
C:\Documents and Settings\Scrangos\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Scrangos\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Scrangos\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Scrangos\UserData\index.dat Object is locked skipped
C:\Program Files\mIRC\backups\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\WLCtrl32.dll.vir Infected: Trojan.Win32.Small.agv skipped
C:\QooBox\Quarantine\catchme2008-02-25_182517.32.zip/Ubi63.sys Infected: Email-Worm.Win32.Agent.e skipped
C:\QooBox\Quarantine\catchme2008-02-25_182517.32.zip ZIP: infected - 1 skipped
C:\RECYCLER\S-1-5-21-507921405-1844237615-725345543-500\Dc2.exe Infected: not-a-virus:AdWare.Win32.AdURL.c skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{1FC5C793-610E-46A4-8691-E209EB8984D3}\RP2\A0000084.dll Infected: Trojan.Win32.Small.agv skipped
C:\System Volume Information\_restore{1FC5C793-610E-46A4-8691-E209EB8984D3}\RP3\A0001125.exe/file02 Infected: not-a-virus:AdWare.Win32.Lop.bo skipped
C:\System Volume Information\_restore{1FC5C793-610E-46A4-8691-E209EB8984D3}\RP3\A0001125.exe/file13 Infected: Trojan.Win32.Obfuscated.en skipped
C:\System Volume Information\_restore{1FC5C793-610E-46A4-8691-E209EB8984D3}\RP3\A0001125.exe Inno: infected - 2 skipped
C:\System Volume Information\_restore{1FC5C793-610E-46A4-8691-E209EB8984D3}\RP3\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\MIMI.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\system32\config\sam Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\security Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\i Infected: Trojan-Downloader.BAT.Ftp.ab skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\TEMP\ZLT01a15.TMP Object is locked skipped
C:\WINDOWS\TEMP\ZLT0359f.TMP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
F:\rc-warhammer\mirc631.exe/stream/data0001/stream/data0014 Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped
F:\rc-warhammer\mirc631.exe/stream/data0001/stream Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped
F:\rc-warhammer\mirc631.exe/stream/data0001 Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped
F:\rc-warhammer\mirc631.exe/stream Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped
F:\rc-warhammer\mirc631.exe NSIS: infected - 4 skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\_restore{1FC5C793-610E-46A4-8691-E209EB8984D3}\RP3\change.log Object is locked skipped

Scan process completed.

HijackThis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:48, on 2008-02-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Trend Micro\HijackThis\hopefulsecond.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:81
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [SoundMax] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" /automount
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-507921405-1844237615-725345543-1005\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User '?')
O4 - HKUS\S-1-5-21-507921405-1844237615-725345543-1006\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User '?')
O4 - HKUS\S-1-5-21-507921405-1844237615-725345543-1008\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User '?')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CBF7EDC-17EC-442C-8AE9-5E804707B6CA} (NeffyClient Class) - http://dist.cdnetworks.co.jp/cdndist/neffy/Neffy.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1159060709606
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1159060656684
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {7C5D062A-7A1E-4A46-A02B-A928084CBD66} (MLauncherNew Class) - http://legendofares.netgame.com/download/MusaLauncherNew.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6E02604C-F26B-45B7-AA4F-2C0AF39E0D7D}: NameServer = 81.169.172.219,81.169.141.30
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\system32\npkcsvc.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: setaffinity - Unknown owner - F:\rc-warhammer\setaffinity\\setaffinity_service.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 7436 bytes
A. Kaspersky and mIRC: It is in fact a False Positive. It is signalled out by Kaspersky because Kas is set to run with advanced heuristics and with instructions to flag potentially dangerous programs. Most of our tools are flagged on a regular basis. mIRC is flagged because it is an IRC program and these programs are one of the biggest facilitators for infection transmission just due to their nature.

B. All your game DPFs/ActiveX entries will return as soon as you visit the site again. A bit of a pain but better remove an unknown than to leave a rootkit.


C. Please ensure that are your security programs are still disabled.

D. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC3.zip
C:\WINDOWS\system32\i

Folder::
C:\fixwareout
C:\WINDOWS\system32\i
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

5. All your monitoring programs (Antivirus/Antispyware, Guards and Shields) will be stopped.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


E. Now, please tell me how your system is running. If the next series of logs come out negative, and all is OH with your system, we will proceed with the final cleanup procedures.
The system is running considerably better. All issues are fixed except one, although this might be a false positive if nothing else has detected it.
  • Success Recurring Downloader.agent.ggt on AVG Anti spyware
  • Success Recurring random number executable that is blocked by AVG
  • Success Recurring issue with svchost.exe process that creates many connections successfully if left unattended.

However the root-kits with AVG Root-kit Free continue to appear. They appear as hidden driver files. Possible causes of this could be a virtual drive made with daemon-tools. Also in the past I have hidden said drives from prying software using software that modifies the registry, however backups for this have long since been restored and the drives unhidden.

Here is an image with the results, as i know its always easier to understand whats going on when you see it.

[external image: Posted Image]

I will attempt to remove it using AVG Root-kit Free and edit right here to see if I'm successful or not. The various removals in the last few cycles might have been what was causing them to reappear.

Edit: They continue to appear, they are now called al40vz7m.SYS and asgan0tj.SYS

As for the logs:

Combofix

ComboFix 08-02-25.3 - Scrangos 2008-02-26 21:29:58.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.621 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Scrangos\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC3.zip
C:\WINDOWS\system32\i
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC3.zip
C:\fixwareout
C:\fixwareout\dnsbak.reg
C:\fixwareout\FindT\clsid.bak
C:\fixwareout\FindT\dumphive.exe
C:\fixwareout\FindT\FixWareOut.reg
C:\fixwareout\FindT\nircmd.exe
C:\fixwareout\FindT\patterns.txt
C:\fixwareout\FindT\rbot.bat
C:\fixwareout\FindT\RestartIt.exe
C:\fixwareout\FindT\runback.txt
C:\fixwareout\FindT\runs.vbs
C:\fixwareout\FindT\swreg.exe
C:\fixwareout\FindT\vfind.exe
C:\fixwareout\FindT\XP-2K2.cmd
C:\fixwareout\FixIt.BAT
C:\fixwareout\report.txt
C:\WINDOWS\system32\i
C:\WINDOWS\system32\i\

.
((((((((((((((((((((((((( Files Created from 2008-01-27 to 2008-02-27 )))))))))))))))))))))))))))))))
.

2008-02-25 21:58 . 2008-02-26 15:32 141,612 –a—— C:\WINDOWS\system32\drivers\dump_wmimmc.sys
2008-02-25 20:40 . 2008-02-25 20:40 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-02-25 20:40 . 2008-02-25 20:40 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-25 16:22 . 2008-02-25 16:22 d——– C:\Program Files\Trend Micro
2008-02-25 15:50 . 2008-02-25 15:50 d——– C:\Deckard
2008-02-25 15:47 . 2008-02-25 15:49 d——– C:\Program Files\EULAlyzer
2008-02-25 15:34 . 2008-02-25 15:34 30,601 –a—— C:\Documents and Settings\Scrangos\x.exe
2008-02-24 23:21 . 2007-09-28 21:05 593,920 ——— C:\WINDOWS\system32\ati2sgag.exe
2008-02-24 12:17 . 2008-02-24 12:17 d——– C:\Documents and Settings\Scrangos\Application Data\Grisoft
2008-02-24 12:17 . 2007-05-30 08:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-24 12:00 . 2008-02-26 14:44 d——– C:\Documents and Settings\Scrangos\Application Data\AVG7
2008-02-24 11:59 . 2008-02-24 11:59 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-24 11:59 . 2008-02-24 12:17 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-24 11:59 . 2008-02-24 12:29 d——– C:\Documents and Settings\All Users\Application Data\avg7
2008-02-24 11:25 . 2007-01-18 08:00 3,968 –a—— C:\WINDOWS\system32\drivers\AvgArCln.sys
2008-02-24 03:27 . 2008-02-24 04:07 d——– C:\Documents and Settings\Administrator\.housecall6.6
2008-02-23 20:32 . 2008-02-23 20:28 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-02-23 20:28 . 2008-02-23 21:41 d——– C:\Documents and Settings\Scrangos\.housecall6.6
2008-02-19 19:26 . 2008-02-19 19:27 d——– C:\Program Files\Dofus
2008-02-18 23:05 . 2008-02-18 23:09 d——– C:\Program Files\OpenVPN
2008-02-18 22:30 . 2008-02-18 22:30 d——– C:\Program Files\Your Freedom
2008-02-18 17:39 . 2008-02-18 17:40 d——– C:\Program Files\AutoTunnel GG
2008-02-18 13:19 . 2008-02-18 13:19 d——– C:\Documents and Settings\Scrangos\Builds
2008-02-18 13:12 . 2008-02-18 13:19 d——– C:\Documents and Settings\All Users\Application Data\Outspark
2008-02-17 17:22 . 2008-02-17 17:22 d——– C:\Program Files\MaxOn Soft
2008-02-17 10:59 . 2008-02-17 11:40 d——– C:\Program Files\SealOnline
2008-02-17 05:15 . 2008-02-17 05:47 d——– C:\Program Files\Neffy
2008-02-14 22:13 . 2007-09-18 23:41 258,352 –a—— C:\WINDOWS\system32\unicows.dll
2008-02-13 18:03 . 2008-02-13 18:03 d——– C:\mGame
2008-02-13 08:11 . 2008-02-13 08:11 d——– C:\Program Files\Common Files\INCA Shared
2008-02-09 15:35 . 2008-02-09 15:35 d——– C:\Program Files\Lavasoft
2008-02-09 15:35 . 2008-02-25 16:14 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-09 01:11 . 2008-02-09 01:11 118,784 –a—— C:\WINDOWS\system32\sbcrreag.dll
2008-02-09 00:00 . 2008-02-09 00:00 d——– C:\Documents and Settings\Scrangos\Application Data\ProxyCap
2008-02-08 23:26 . 2008-02-08 23:47 d——– C:\Program Files\HTTP-Tunnel
2008-02-08 21:02 . 2008-02-08 23:47 d——– C:\Program Files\ProxyWay
2008-02-02 02:05 . 2008-02-02 02:08 d——– C:\Program Files\eVer-Craft
2008-01-30 22:02 . 2008-01-30 22:02 54,608 –a—— C:\WINDOWS\system32\xfcodec.dll
2008-01-30 14:08 . 2008-01-30 14:14 70,656 –a—— C:\WINDOWS\ScUnin.exe
2008-01-30 14:08 . 2008-01-30 14:14 32,653 –a—— C:\WINDOWS\scunin.dat
2008-01-30 14:08 . 2008-01-30 14:14 967 –a—— C:\WINDOWS\ScUnin.pif
2008-01-29 20:41 . 2008-01-29 20:41 25,216 –a—— C:\WINDOWS\system32\drivers\tap0901.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-27 01:37 20,496,416 –sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-02-27 01:35 244,352 –sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-02-27 01:28 ——— d—–w C:\Program Files\Trillian
2008-02-26 11:46 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\MegauploadToolbar
2008-02-26 00:19 5,521,896 —-a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2008-02-25 20:14 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-25 19:52 ——— d—–w C:\Program Files\SpywareBlaster
2008-02-25 19:34 ——— d—–w C:\Program Files\VisualRoute
2008-02-25 02:37 ——— d—–w C:\Program Files\MultiRes
2008-02-25 02:28 ——— d—–w C:\Program Files\Radeon Omega Drivers
2008-02-24 21:07 ——— d—–w C:\Program Files\Game Elements PC Recoil Pad
2008-02-24 16:21 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\Free Download Manager
2008-02-23 01:37 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-22 18:41 ——— d—–w C:\Program Files\Granado Espada
2008-02-20 23:13 ——— d—–w C:\Program Files\mIRC
2008-02-17 03:40 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\Xfire
2008-02-16 13:15 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\IGN_DLM
2008-02-09 19:13 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\Lavasoft
2008-02-07 19:58 107,888 —-a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-02-01 07:28 ——— d—–w C:\Program Files\World of Warcraft
2008-01-27 19:52 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\ATI
2008-01-27 01:28 ——— d—–w C:\Program Files\Microsoft IntelliPoint
2008-01-27 01:27 ——— d—–w C:\Program Files\MSXML 6.0
2008-01-26 23:53 ——— d—–w C:\Program Files\Warkeys
2008-01-26 04:28 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\atitray
2008-01-26 04:20 472,576 —-a-w C:\WINDOWS\Radeon Omega Drivers v4.8.442 Uninstall.exe
2008-01-26 02:19 139,264 —-a-w C:\WINDOWS\War3Unin.exe
2008-01-26 01:34 51,472 —-a-w C:\WINDOWS\system32\imagecfg.exe
2008-01-22 21:27 ——— d—–w C:\Program Files\Codec Pack - All In 1
2008-01-22 21:25 737,280 —-a-w C:\WINDOWS\iun6002.exe
2008-01-18 00:44 ——— d—–w C:\Program Files\Analog Devices
2008-01-15 00:16 ——— d—–w C:\Program Files\Sims2Pack Clean Installer
2008-01-15 00:16 ——— d—–w C:\Program Files\SimPE
2008-01-12 22:06 ——— d—–w C:\Program Files\EA GAMES
2008-01-12 03:08 ——— d—–w C:\Program Files\Alcohol Soft
2008-01-07 20:11 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\Sonic
2008-01-07 20:07 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\Leadertech
2008-01-07 20:04 ——— d—–w C:\Program Files\Sonic
2008-01-06 17:10 ——— d—–w C:\Program Files\Microsoft ActiveSync
2008-01-06 17:10 ——— d—–w C:\Program Files\Common Files\L&H;
2008-01-06 17:09 ——— d—–w C:\Program Files\Microsoft Works
2008-01-06 17:08 ——— d—–w C:\Program Files\Microsoft.NET
2008-01-05 12:45 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\OpenOffice.org2
2008-01-04 22:41 ——— d—–w C:\Program Files\Black Isle
2008-01-04 22:29 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\DAEMON Tools
2008-01-04 22:27 ——— d—–w C:\Program Files\DAEMON Tools Lite
2008-01-03 21:01 715,248 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-01-03 21:01 ——— d—–w C:\Program Files\DAEMON Tools Pro
2007-12-28 12:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Insight Software Solutions
2007-12-28 12:21 ——— d—–w C:\Documents and Settings\All Users\Application Data\Insight Software
2007-12-21 02:24 46,080 —-a-w C:\WINDOWS\system32\amdpcom32.dll
2007-12-05 03:05 368,640 —-a-w C:\WINDOWS\system32\ATIDEMGX.dll
2007-12-05 03:04 269,312 —-a-w C:\WINDOWS\system32\ati2dvag.dll
2007-12-05 02:56 147,456 —-a-w C:\WINDOWS\system32\atipdlxx.dll
2007-12-05 02:55 43,520 —-a-w C:\WINDOWS\system32\ati2edxx.dll
2007-12-05 02:55 26,112 —-a-w C:\WINDOWS\system32\Ati2mdxx.exe
2007-12-05 02:55 122,880 —-a-w C:\WINDOWS\system32\Oemdspif.dll
2007-12-05 02:55 122,880 —-a-w C:\WINDOWS\system32\ati2evxx.dll
2007-12-05 02:53 53,248 —-a-w C:\WINDOWS\system32\ATIDDC.DLL
2007-12-05 02:53 495,616 —-a-w C:\WINDOWS\system32\ati2evxx.exe
2007-12-05 02:48 9,535,488 —-a-w C:\WINDOWS\system32\atioglx2.dll
2007-12-05 02:44 3,175,584 —-a-w C:\WINDOWS\system32\ati3duag.dll
2007-12-05 02:33 1,640,192 —-a-w C:\WINDOWS\system32\ativvaxx.dll
2007-12-05 02:19 5,435,392 —-a-w C:\WINDOWS\system32\atioglxx.dll
2007-12-05 02:19 385,024 —-a-w C:\WINDOWS\system32\atikvmag.dll
2007-12-05 02:17 17,408 —-a-w C:\WINDOWS\system32\atitvo32.dll
2007-12-05 02:14 180,224 —-a-w C:\WINDOWS\system32\atiok3x2.dll
2007-12-05 02:11 499,712 —-a-w C:\WINDOWS\system32\ati2cqag.dll
2007-04-19 22:42 205,778 —-a-w C:\Program Files\CustomKeys.txt
2006-11-20 07:54 202,277,175 —-a-w C:\Program Files\se.ipf
2006-10-05 17:58 1,134,282,010 —-a-w C:\Documents and Settings\Scrangos\RAG_SETUP0711.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-01-03 09:54 486856]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" [2007-12-22 03:09 221056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14 919016]
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14 919016]
"amd_dc_opt"="C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2006-11-17 16:49 77824]
"SoundMax"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2006-05-18 14:26 729088]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-05-18 14:22 843776]
"IntelliPoint"="c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 12:01 1037736]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-24 11:59 579072]
"AtiPTA"="atiptaxx.exe" [2006-02-21 21:05 344064 C:\WINDOWS\system32\atiptaxx.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-24 11:59 219136]

C:\Documents and Settings\test17\Start Menu\Programs\Startup\
OpenOffice.org 2.0.lnk - C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe [2006-07-14 21:26:34 393216]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.exe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TabUserW.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TabUserW.exe.lnk
backup=C:\WINDOWS\pss\TabUserW.exe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Scrangos^Start Menu^Programs^Startup^hamachi.lnk]
path=C:\Documents and Settings\Scrangos\Start Menu\Programs\Startup\hamachi.lnk
backup=C:\WINDOWS\pss\hamachi.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ANIWZCS2Service]
–a—— 2004-08-16 16:45 45056 C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\D-Link AirPlus G]
–a—— 2004-08-18 11:47 1249280 C:\Program Files\D-Link\AirPlus G\AirGCFG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
–a—— 2007-03-05 17:57 1103480 C:\Program Files\Download Manager\DLM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMEKRMIG6.1]
–a—— 2001-08-23 18:00 44032 C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
–a—— 2004-08-03 22:32 208952 C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
–a—— 2005-08-11 15:30 249856 C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
–a—— 2005-08-11 15:30 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 3100 Series]
–a—— 2003-07-28 18:50 106496 C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXBRKsk]
–a—— 2003-06-13 14:57 294912 C:\PROGRA~1\LEXMAR~1\LXBRKsk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
–a—— 2004-08-03 22:31 59392 C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
–a—— 2004-08-03 22:32 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
–a—— 2004-08-03 22:32 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
–a—— 2004-11-02 20:24 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
–a—— 2006-05-18 14:26 729088 C:\Program Files\Analog Devices\SoundMAX\Smax4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
–a—— 2006-05-18 14:22 843776 C:\Program Files\Analog Devices\Core\smax4pnp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
–a—— 2004-05-12 01:03 1038336 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2005-11-10 13:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"ANIWZCS2Service"=C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
"newname"=C:\\nwnmff_e21.exe
"MSPY2002"=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
"IMEKRMIG6.1"=C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"F:\\Program Files\\Flagship Studios\\Hellgate London\\Launcher.exe"=
"F:\\Program Files\\Flagship Studios\\Mythos\\bin\\Mythos.exe"=
"C:\\Program Files\\GRISOFT\\AVG7\\avginet.exe"=
"C:\\Program Files\\GRISOFT\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\GRISOFT\\AVG7\\avgcc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9842:TCP"= 9842:TCP:*:Disabled:SolidNetworkManager
"9842:UDP"= 9842:UDP:*:Disabled:SolidNetworkManager
"10737:TCP"= 10737:TCP:*:Disabled:SolidNetworkManager
"10737:UDP"= 10737:UDP:*:Disabled:SolidNetworkManager
"12623:TCP"= 12623:TCP:*:Disabled:SolidNetworkManager
"12623:UDP"= 12623:UDP:*:Disabled:SolidNetworkManager

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-26 21:37:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.2180]
-> C:\Program Files\WinRAR\rarext.dll
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
.
**************************************************************************
.
Completion time: 2008-02-26 21:42:38 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-27 01:42:35
ComboFix2.txt 2008-02-26 00:36:22
ComboFix3.txt 2008-02-25 22:30:48

Hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:45, on 2008-02-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\microtrend\thisjackhi\canthidefromthis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:81
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [SoundMax] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" /automount
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CBF7EDC-17EC-442C-8AE9-5E804707B6CA} (NeffyClient Class) - http://dist.cdnetworks.co.jp/cdndist/neffy/Neffy.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1159060709606
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1159060656684
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {7C5D062A-7A1E-4A46-A02B-A928084CBD66} (MLauncherNew Class) - http://legendofares.netgame.com/download/MusaLauncherNew.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6E02604C-F26B-45B7-AA4F-2C0AF39E0D7D}: NameServer = 81.169.172.219,81.169.141.30
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\system32\npkcsvc.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: setaffinity - Unknown owner - F:\rc-warhammer\setaffinity\\setaffinity_service.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 7103 bytes
Download Gmer
  • Disconnect from internet and close running programs.
  • There is a small chance this application may crash your computer so save any work you have open.
  • Double click gmer.exe
  • Let the gmer.sys driver load if asked.
  • If it gives you a warning at program start about rootkit activity and asks if you want to run scan…say Ok.
  • If no warning….
  • Click "Rootkit" tab and click "Scan"
  • Once done, click "Copy"
  • Open Notepad and hit "ctrl+v" to paste the log.
  • Reconnect to the internet and post the log back to this thread please.
Here is the GMER log.


GMER 1.0.14.14116 - http://www.gmer.net
Rootkit scan 2008-02-27 07:55:17
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.14 —-

SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwConnectPort [0xAE6B3EB0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreateFile [0xAE6B0870]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreateKey [0xAE6BB720]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreatePort [0xAE6B4270]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreateProcess [0xAE6BA520]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreateProcessEx [0xAE6BA750]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreateSection [0xAE6BE0B0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwCreateWaitablePort [0xAE6B4360]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwDeleteFile [0xAE6B0EF0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwDeleteKey [0xAE6BC740]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwDeleteValueKey [0xAE6BC380]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwDuplicateObject [0xAE6BA290]
SSDT spyk.sys ZwEnumerateKey [0xF74E2CA2]
SSDT spyk.sys ZwEnumerateValueKey [0xF74E3030]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwLoadKey [0xAE6BCA80]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwOpenFile [0xAE6B0D40]
SSDT spyk.sys ZwOpenKey [0xF74C50C0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwOpenProcess [0xAE6B9FE0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwOpenThread [0xAE6B9E00]
SSDT spyk.sys ZwQueryKey [0xF74E3108]
SSDT spyk.sys ZwQueryValueKey [0xF74E2F88]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwRenameKey [0xAE6BD1F0]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwReplaceKey [0xAE6BCD70]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwRequestWaitReplyPort [0xAE6B3B50]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwRestoreKey [0xAE6BD020]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwSecureConnectPort [0xAE6B4060]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwSetInformationFile [0xAE6B1060]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwSetValueKey [0xAE6BBEF7]
SSDT \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC) ZwTerminateProcess [0xAE6BA980]

INT 0x01 \SystemRoot\system32\DRIVERS\ati2mtag.sys F64EF4F6
INT 0x03 \SystemRoot\system32\DRIVERS\ati2mtag.sys F64EF59C

—- Kernel code sections - GMER 1.0.14 —-

.text ntoskrnl.exe!ZwYieldExecution + 12E 804E4968 12 Bytes [ 70, 42, 6B, AE, 20, A5, 6B, … ]
? spyk.sys The system cannot find the file specified. !
? srescan.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload F681B62C 5 Bytes JMP 871604E0
.text apq4r13t.SYS F62FD384 1 Byte [ 20 ]
.text apq4r13t.SYS F62FD386 35 Bytes [ 00, 68, 00, 00, 00, 00, 00, … ]
.text apq4r13t.SYS F62FD3AA 24 Bytes [ 00, 00, 20, 00, 00, E0, 00, … ]
.text apq4r13t.SYS F62FD3C4 3 Bytes [ 00, 00, 00 ]
.text apq4r13t.SYS F62FD3C9 1 Byte [ 00 ]
.text …
.text al7jgyyt.SYS F6298384 1 Byte [ 20 ]
.text al7jgyyt.SYS F6298386 35 Bytes [ 00, 68, 00, 00, 00, 00, 00, … ]
.text al7jgyyt.SYS F62983AA 24 Bytes [ 00, 00, 20, 00, 00, E0, 00, … ]
.text al7jgyyt.SYS F62983C4 3 Bytes [ 00, 00, 00 ]
.text al7jgyyt.SYS F62983C9 1 Byte [ 00 ]
.text …

—- User code sections - GMER 1.0.14 —-

.text C:\WINDOWS\system32\svchost.exe[1184] SHELL32.dll!SHCreateLocalServerRunDll + 1BD85 7CB76BEF 1 Byte [ 8B ]
.text C:\WINDOWS\System32\svchost.exe[1372] USER32.dll!UserRegisterWowHandlers + 17F 77D835E7 1 Byte [ C7 ]

—- Kernel IAT/EAT - GMER 1.0.14 —-

IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 873544B8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F74EB6D0] spyk.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F74EF708] spyk.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F74C6046] spyk.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F74C6142] spyk.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74C60C4] spyk.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74C67CE] spyk.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74C66A4] spyk.sys
IAT \SystemRoot\System32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 871605E0
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!RtlInitUnicodeString] DD000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!swprintf] 74000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!KeSetEvent] 1F000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoCreateSymbolicLink] 4B000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoGetConfigurationInformation] BD000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoDeleteSymbolicLink] 8B000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!MmFreeMappingAddress] 8A000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoFreeErrorLogEntry] 70000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoDisconnectInterrupt] 3E000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!MmUnmapIoSpace] B5000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!ObReferenceObjectByPointer] 66000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IofCompleteRequest] 48000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!RtlCompareUnicodeString] 03000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IofCallDriver] F6000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!MmAllocateMappingAddress] 0E000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoAllocateErrorLogEntry] 61000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoConnectInterrupt] 35000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoDetachDevice] 57000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!KeWaitForSingleObject] B9000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!KeInitializeEvent] 86000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!RtlAnsiStringToUnicodeString] C1000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!RtlInitAnsiString] 1D000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoBuildDeviceIoControlRequest] 9E000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoQueueWorkItem] E1000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!MmMapIoSpace] F8000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoInvalidateDeviceRelations] 98000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoReportDetectedDevice] 11000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoReportResourceForDetection] 69000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!RtlxAnsiStringToUnicodeSize] D9000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!NlsMbCodePageTag] 8E000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!PoRequestPowerIrp] 94000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!KeInsertByKeyDeviceQueue] 9B000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!PoRegisterDeviceForIdleDetection] 1E000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!sprintf] 87000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!MmMapLockedPagesSpecifyCache] E9000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!ObfDereferenceObject] CE000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoGetAttachedDeviceReference] 55000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoInvalidateDeviceState] 28000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!ZwClose] DF000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!ObReferenceObjectByHandle] 8C000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!ZwCreateDirectoryObject] A1000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoBuildSynchronousFsdRequest] 89000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!PoStartNextPowerIrp] 0D000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!PoCallDriver] [BF000000] \SystemRoot\System32\drivers\dxg.sys (DirectX Graphics Driver/Microsoft Corporation)
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoCreateDevice] E6000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoAllocateDriverObjectExtension] 42000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!RtlQueryRegistryValues] 68000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!ZwOpenKey] 41000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!RtlFreeUnicodeString] 99000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoStartTimer] 2D000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!KeInitializeTimer] 0F000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoInitializeTimer] B0000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!KeInitializeDpc] 54000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!KeInitializeSpinLock] BB000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoInitializeIrp] 16000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!ZwCreateKey] 00000052
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!RtlAppendUnicodeStringToString] 00000009
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!RtlIntegerToUnicodeString] 0000006A
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!ZwSetValueKey] 000000D5
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!KeInsertQueueDpc] 00000030
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!KefAcquireSpinLockAtDpcLevel] 00000036
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoStartPacket] 000000A5
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!KefReleaseSpinLockFromDpcLevel] 00000038
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoBuildAsynchronousFsdRequest] 000000BF
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoFreeMdl] 00000040
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!MmUnlockPages] 000000A3
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoWriteErrorLogEntry] 0000009E
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!KeRemoveByKeyDeviceQueue] 00000081
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!MmMapLockedPagesWithReservedMapping] 000000F3
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!MmUnmapReservedMapping] 000000D7
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!KeSynchronizeExecution] 000000FB
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoStartNextPacket] 0000007C
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!KeBugCheckEx] 000000E3
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!KeRemoveDeviceQueue] 00000039
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!KeSetTimer] 00000082
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!KeCancelTimer] 0000009B
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!_allmul] 0000002F
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!MmProbeAndLockPages] 000000FF
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!_except_handler3] 00000087
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!PoSetPowerState] 00000034
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoOpenDeviceRegistryKey] 0000008E
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!RtlWriteRegistryValue] 00000043
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!_aulldiv] 00000044
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!strstr] 000000C4
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!_strupr] 000000DE
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!KeQuerySystemTime] 000000E9
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoWMIRegistrationControl] 000000CB
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!KeTickCount] 00000054
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoAttachDeviceToDeviceStack] 0000007B
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoDeleteDevice] 00000094
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!ExAllocatePoolWithTag] 00000032
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoAllocateWorkItem] 000000A6
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoAllocateIrp] 000000C2
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoAllocateMdl] 00000023
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!MmBuildMdlForNonPagedPool] 0000003D
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!MmLockPagableDataSection] 000000EE
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoGetDriverObjectExtension] 0000004C
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!MmUnlockPagableImageSection] 00000095
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!ExFreePoolWithTag] 0000000B
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoFreeIrp] 00000042
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!IoFreeWorkItem] 000000FA
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!InitSafeBootMode] 000000C3
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!RtlCompareMemory] 0000004E
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!RtlCopyUnicodeString] 00000008
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!memmove] 0000002E
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[ntoskrnl.exe!MmHighestUserAddress] 000000A1
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[HAL.dll!KfAcquireSpinLock] 6C000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[HAL.dll!READ_PORT_UCHAR] 56000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[HAL.dll!KeGetCurrentIrql] F4000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[HAL.dll!KfRaiseIrql] EA000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[HAL.dll!KfLowerIrql] 65000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[HAL.dll!HalGetInterruptVector] 7A000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[HAL.dll!HalTranslateBusAddress] AE000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[HAL.dll!KeStallExecutionProcessor] 08000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[HAL.dll!KfReleaseSpinLock] BA000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 78000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[HAL.dll!READ_PORT_USHORT] 25000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 2E000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[HAL.dll!WRITE_PORT_UCHAR] 1C000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[WMILIB.SYS!WmiSystemControl] B4000000
IAT \SystemRoot\System32\Drivers\apq4r13t.SYS[WMILIB.SYS!WmiCompleteRequest] C6000000
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!RtlInitUnicodeString] 9252D2DB
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!swprintf] [804FC5C0] \WINDOWS\system32\ntoskrnl.exe (NT Kernel & System/Microsoft Corporation)
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!KeSetEvent] 8E44C8C9
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoCreateSymbolicLink] A475EBF6
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoGetConfigurationInformation] AA7EE6FF
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoDeleteSymbolicLink] B863F1E4
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!MmFreeMappingAddress] B668FCED
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoFreeErrorLogEntry] 0CB1670A
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoDisconnectInterrupt] 02BA6A03
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!MmUnmapIoSpace] 10A77D18
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!ObReferenceObjectByPointer] 1EAC7011
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IofCompleteRequest] 349D532E
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!RtlCompareUnicodeString] 3A965E27
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IofCallDriver] 288B493C
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!MmAllocateMappingAddress] 26804435
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoAllocateErrorLogEntry] 7CE90F42
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoConnectInterrupt] 72E2024B
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoDetachDevice] 60FF1550
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!KeWaitForSingleObject] 6EF41859
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!KeInitializeEvent] 44C53B66
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!RtlAnsiStringToUnicodeString] 4ACE366F
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!RtlInitAnsiString] 58D32174
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoBuildDeviceIoControlRequest] 56D82C7D
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoQueueWorkItem] 377A0CA1
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!MmMapIoSpace] 397101A8
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoInvalidateDeviceRelations] 2B6C16B3
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoReportDetectedDevice] 25671BBA
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoReportResourceForDetection] 0F563885
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!RtlxAnsiStringToUnicodeSize] 015D358C
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!NlsMbCodePageTag] 13402297
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!PoRequestPowerIrp] 1D4B2F9E
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!KeInsertByKeyDeviceQueue] 472264E9
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!PoRegisterDeviceForIdleDetection] 492969E0
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!sprintf] 5B347EFB
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!MmMapLockedPagesSpecifyCache] 553F73F2
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!ObfDereferenceObject] 7F0E50CD
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoGetAttachedDeviceReference] 71055DC4
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoInvalidateDeviceState] 63184ADF
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!ZwClose] 6D1347D6
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!ObReferenceObjectByHandle] D7CADC31
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!ZwCreateDirectoryObject] D9C1D138
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoBuildSynchronousFsdRequest] CBDCC623
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!PoStartNextPowerIrp] C5D7CB2A
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!PoCallDriver] EFE6E815
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoCreateDevice] E1EDE51C
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoAllocateDriverObjectExtension] F3F0F207
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!RtlQueryRegistryValues] FDFBFF0E
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!ZwOpenKey] A792B479
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!RtlFreeUnicodeString] A999B970
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoStartTimer] BB84AE6B
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!KeInitializeTimer] B58FA362
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoInitializeTimer] 9FBE805D
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!KeInitializeDpc] 91B58D54
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!KeInitializeSpinLock] 83A89A4F
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoInitializeIrp] 8DA39746
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!ZwCreateKey] 00000063
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!RtlAppendUnicodeStringToString] 0000007C
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!RtlIntegerToUnicodeString] 00000077
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!ZwSetValueKey] 0000007B
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!KeInsertQueueDpc] 000000F2
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!KefAcquireSpinLockAtDpcLevel] 0000006B
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoStartPacket] 0000006F
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!KefReleaseSpinLockFromDpcLevel] 000000C5
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoBuildAsynchronousFsdRequest] 00000030
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoFreeMdl] 00000001
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!MmUnlockPages] 00000067
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoWriteErrorLogEntry] 0000002B
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!KeRemoveByKeyDeviceQueue] 000000FE
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!MmMapLockedPagesWithReservedMapping] 000000D7
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!MmUnmapReservedMapping] 000000AB
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!KeSynchronizeExecution] 00000076
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoStartNextPacket] 000000CA
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!KeBugCheckEx] 00000082
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!KeRemoveDeviceQueue] 000000C9
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!KeSetTimer] 0000007D
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!KeCancelTimer] 000000FA
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!_allmul] 00000059
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!MmProbeAndLockPages] 00000047
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!_except_handler3] 000000F0
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!PoSetPowerState] 000000AD
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoOpenDeviceRegistryKey] 000000D4
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!RtlWriteRegistryValue] 000000A2
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!_aulldiv] 000000AF
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!strstr] 0000009C
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!_strupr] 000000A4
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!KeQuerySystemTime] 00000072
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoWMIRegistrationControl] 000000C0
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!KeTickCount] 000000B7
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoAttachDeviceToDeviceStack] 000000FD
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoDeleteDevice] 00000093
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!ExAllocatePoolWithTag] 00000026
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoAllocateWorkItem] 00000036
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoAllocateIrp] 0000003F
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoAllocateMdl] 000000F7
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!MmBuildMdlForNonPagedPool] 000000CC
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!MmLockPagableDataSection] 00000034
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoGetDriverObjectExtension] 000000A5
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!MmUnlockPagableImageSection] 000000E5
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!ExFreePoolWithTag] 000000F1
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoFreeIrp] 00000071
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!IoFreeWorkItem] 000000D8
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!InitSafeBootMode] 00000031
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!RtlCompareMemory] 00000015
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!RtlCopyUnicodeString] 00000004
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!memmove] 000000C7
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[ntoskrnl.exe!MmHighestUserAddress] 00000023
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[HAL.dll!KfAcquireSpinLock] 0A64D90F
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[HAL.dll!READ_PORT_UCHAR] 046FD406
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[HAL.dll!KeGetCurrentIrql] 1672C31D
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[HAL.dll!KfRaiseIrql] 1879CE14
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[HAL.dll!KfLowerIrql] 3248ED2B
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[HAL.dll!HalGetInterruptVector] 3C43E022
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[HAL.dll!HalTranslateBusAddress] 2E5EF739
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[HAL.dll!KeStallExecutionProcessor] 2055FA30
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[HAL.dll!KfReleaseSpinLock] EC01B79A
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] E20ABA93
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[HAL.dll!READ_PORT_USHORT] F017AD88
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] FE1CA081
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[HAL.dll!WRITE_PORT_UCHAR] D42D83BE
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[WMILIB.SYS!WmiSystemControl] C83B99AC
IAT \SystemRoot\System32\Drivers\al7jgyyt.SYS[WMILIB.SYS!WmiCompleteRequest] C63094A5
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [AE6B89F0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [AE6B8F10] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [AE6B9070] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [AE6B8B60] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [AE6B8B60] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [AE6B89F0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [AE6B8F10] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [AE6B9070] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [AE6B89F0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [AE6B9070] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [AE6B8F10] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [AE6B8B60] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [AE6B9070] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [AE6B89F0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [AE6B8F10] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [AE6B8B60] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [AE6B89F0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [AE6B8F10] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [AE6B9070] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\drivers\afd.sys[ntoskrnl.exe!IoCreateFile] [AE6C63D0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [AE6B89F0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [AE6B8B60] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [AE6B9070] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [AE6B8F10] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!NtOpenFile] [AE6B15C0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!NtSetInformationFile] [AE6B1510] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!IoCreateFile] [AE6B16C0] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
IAT \SystemRoot\System32\DRIVERS\srv.sys[ntoskrnl.exe!NtCreateFile] [AE6B1220] \SystemRoot\System32\vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)

—- Devices - GMER 1.0.14 —-

Device \FileSystem\Ntfs \Ntfs 873501F8

AttachedDevice \FileSystem\Ntfs \Ntfs avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)

Device \FileSystem\Fastfat \FatCdrom 87187500
Device \Driver\USBSTOR \Device\0000009b 860351F8
Device \Driver\Tcpip \Device\Ip vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
Device \Driver\sptd \Device\1236977082 spyk.sys
Device \Driver\usbohci \Device\USBPDO-0 8715E1F8
Device \Driver\sptd \Device\1236820832 spyk.sys
Device \Driver\usbehci \Device\USBPDO-1 8715D1F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 873521F8
Device \Driver\dmio \Device\DmControl\DmConfig 873521F8
Device \Driver\dmio \Device\DmControl\DmPnP 873521F8
Device \Driver\dmio \Device\DmControl\DmInfo 873521F8
Device \Driver\Tcpip \Device\Tcp vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
Device \Driver\NetBT \Device\NetBT_Tcpip_{6E02604C-F26B-45B7-AA4F-2C0AF39E0D7D} 861C11F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 873C41F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 873C41F8
Device \Driver\atapi \Device\Ide\IdePort0 873C31F8
Device \Driver\atapi \Device\Ide\IdePort1 873C31F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 873C31F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c 873C31F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 861C11F8
Device \Driver\NetBT \Device\NetbiosSmb 861C11F8
Device \Driver\Tcpip \Device\Udp vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
Device \Driver\PCI_PNP3332 \Device\0000006a spyk.sys
Device \Driver\PCI_PNP3332 \Device\0000006a spyk.sys
Device \Driver\Tcpip \Device\RawIp vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
Device \Driver\PCI_PNP3332 \Device\0000006b spyk.sys
Device \Driver\PCI_PNP3332 \Device\0000006b spyk.sys
Device \Driver\USBSTOR \Device\00000098 860351F8
Device \Driver\usbohci \Device\USBFDO-0 8715E1F8
Device \Driver\nvata \Device\NvAta0 873511F8
Device \Driver\usbehci \Device\USBFDO-1 8715D1F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 860511F8
Device \Driver\nvata \Device\NvAta1 873511F8
Device \Driver\Tcpip \Device\IPMULTICAST vsdatant.sys (TrueVector Device Driver/Zone Labs, LLC)
Device \FileSystem\MRxSmb \Device\LanmanRedirector 860511F8
Device \Driver\nvata \Device\NvAta2 873511F8
Device \Driver\Ftdisk \Device\FtControl 873C41F8
Device \Driver\al7jgyyt \Device\Scsi\al7jgyyt1Port6Path0Target0Lun0 87045500
Device \Driver\apq4r13t \Device\Scsi\apq4r13t1 8700A368
Device \Driver\al7jgyyt \Device\Scsi\al7jgyyt1 87045500
Device \FileSystem\Fastfat \Fat 87187500

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat avg7rsw.sys (AVG Resident Shield Unload Helper/GRISOFT, s.r.o.)

Device \FileSystem\Cdfs \Cdfs 860311F8

—- Registry - GMER 1.0.14 —-

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xA8 0xEB 0x97 0xAA …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x17 0xE1 0x7F 0x70 …
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xD2 0x09 0x23 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xA8 0xEB 0x97 0xAA …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x17 0xE1 0x7F 0x70 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xD2 0x09 0x23 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x38 0x12 0x20 0x6E …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x17 0xE1 0x7F 0x70 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x0F 0xD4 0x1E 0xC9 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xA8 0xEB 0x97 0xAA …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x17 0xE1 0x7F 0x70 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xD2 0x09 0x23 0x00 …
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xA8 0xEB 0x97 0xAA …
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x17 0xE1 0x7F 0x70 …
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xD2 0x09 0x23 0x00 …
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x38 0x12 0x20 0x6E …
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x17 0xE1 0x7F 0x70 …
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x24 0x2D 0x00 0x0D …
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x38 0x12 0x20 0x6E …
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x17 0xE1 0x7F 0x70 …
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x0F 0xD4 0x1E 0xC9 …
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x38 0x12 0x20 0x6E …
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x17 0xE1 0x7F 0x70 …
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x0F 0xD4 0x1E 0xC9 …
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x38 0x12 0x20 0x6E …
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x17 0xE1 0x7F 0x70 …
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x0F 0xD4 0x1E 0xC9 …
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x6A 0x1E 0x7E 0xB3 …
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x4D 0x17 0x4C 0x44 …
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xFA 0x7F 0x0F 0x16 …
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x6A 0x1E 0x7E 0xB3 …
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x4D 0x17 0x4C 0x44 …
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xFA 0x7F 0x0F 0x16 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 740215585
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 103984758
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 52\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x0C 0xEF 0xBF 0xAE …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xC8 0x19 0x9A 0xB1 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x1D 0x85 0x6E 0xFC …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x83 0xF2 0x24 0xD5 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x56 0x35 0x90 0xBC …
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 52\
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 2
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x0C 0xEF 0xBF 0xAE …
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xC8 0x19 0x9A 0xB1 …
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x1D 0x85 0x6E 0xFC …
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x83 0xF2 0x24 0xD5 …
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x56 0x35 0x90 0xBC …
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ Â
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ Â@SlowInfoCache 0x28 0x02 0x00 0x00 …
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ Â@Changed 0
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@C:\Program Files\illusion\Sexy\x30d3\x30fc\x30c13\data\cap\ 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@C:\Program Files\illusion\Sexy\x30d3\x30fc\x30c13\data\ 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@C:\Program Files\illusion\Sexy\x30d3\x30fc\x30c13\ 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders@C:\Program Files\illusion\Sexy\x30d3\x30fc\x30c13\data\save\ 1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ Â
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ Â@DisplayName ???????f???I ?`???????????d?w?`
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ Â@UninstallString C:\Program Files\TinkleBell\TD\LSUin000.exe "C:\Program Files\TinkleBell\TD\LSUin000.lil"
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts@Acadian\x2122 (TrueType) AC______.TTF
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts@Brandywine\x2122 (TrueType) brandywi.ttf
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\’e
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\’e@Order 0x08 0x00 0x00 0x00 …
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\’e\ Â
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\’e\ Â@Order 0x08 0x00 0x00 0x00 …
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache@C:\download\hem1\Ashe 1\dat\üÖé+éTéFé\x2ddâAü[âVâF!!ver2.exe ???+?T?F???A?[?V?F!!ver2

—- EOF - GMER 1.0.14 —-
OK, here we go. Here is the opinion that I received with which I totally concur:

It could be a legitimate program creating these random drivers (as I have seen some security software creating these), but ofcourse they could be malware as well. The only way to figure it is to collect the files


A. We need to show Hidden Files:

To enable the viewing of Hidden files follow these steps:

1. Close all programs so that you are at your desktop.
2. Double-click on the My Computer icon.
3. Select the Tools menu and click Folder Options.
4. After the new window appears select the View tab.
5. Put a checkmark in the checkbox labeled Display the contents of system folders.
6. Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
7. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
8. Remove the checkmark from the checkbox labeled Hide protected operating system files.
9. Press the Apply button and then the OK button and shutdown My Computer.
10. Now your computer is configured to show all hidden files.


B. Locate the folllowing files:

C:\Windows\System32\Drivers\al7jgyyt.SYS

and

C:\Windows\System32\Drivers\apq4r13t.SYS


I need you to right click on each one of these files, choose Properties and jot down all the information that you can find about these files (Manufacturer, size, date etc….) and post the results back into the thread.


C. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

http://forums.whatthetech.com/Trouble_removing_stubborn_infections_t89188.html&gopid=442606#entry442606

Suspect::
C:\Windows\System32\Drivers\al7jgyyt.SYS
C:\Windows\System32\Drivers\apq4r13t.SYS

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


6. Additonally, ComboFix will generate the following files on your desktop
  • A zipped file on your desktop called Submit [Date Time].zip
  • And another file named - CF-Submit.htm
7. ComboFix may need to reboot to finish its work. Let it.

8. Re-enable all the programs that were disabled during the running of ComboFix.

9. When CF has finished its run, it will generate ComboFix.log which will appear on your screen.

10. Next, a window will popup prompting you to "Submit Files for further analysis". Click "OK"

11. Your system's browser will automatically respond by loading the CF-Submit.htm file and open a window :
  • Click the "Browse" button and locate the Submit [Date Time].zip file on your desktop.
  • Click on the file to Select it.
  • Submit the file by clicking "OK"
12. Once the file has been submitted, you may DELETE both files on your desktop.

13. Post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Sorry for the delay, i have uploaded the file now. I was not able to manually find the files even though i can see hidden files, which is fairly strange (for example the boot.ini and config.sys on the c:\). The filenames changed once more, I took the liberty of modifying the CFScript.txt to match the new filenames.

It looks like the compressed file made by combofix contains them, i did not meddle with the contents however lest I end up infected with something that was just cleaned.

Edit: Forgot the logs

Combofix

ComboFix 08-02-25.3 - Scrangos 2008-02-29 20:21:57.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.658 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Scrangos\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat

—– BITS: Possible infected sites —–

hxxp://launcher.patcher.ncsoft.com
.
((((((((((((((((((((((((( Files Created from 2008-02-01 to 2008-03-01 )))))))))))))))))))))))))))))))
.

2008-02-28 11:50 . 2008-02-28 11:51 25,088 –ahs—- C:\WINDOWS\system32\Thumbs.db
2008-02-26 23:26 . 2008-02-27 07:02 250 –a—— C:\WINDOWS\gmer.ini
2008-02-25 21:58 . 2008-02-29 10:07 141,612 –a—— C:\WINDOWS\system32\drivers\dump_wmimmc.sys
2008-02-25 20:40 . 2008-02-25 20:40 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-02-25 20:40 . 2008-02-25 20:40 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-02-25 16:22 . 2008-02-26 21:44 d——– C:\Program Files\microtrend
2008-02-25 15:50 . 2008-02-25 15:50 d——– C:\Deckard
2008-02-25 15:47 . 2008-02-25 15:49 d——– C:\Program Files\EULAlyzer
2008-02-25 15:34 . 2008-02-25 15:34 30,601 –a—— C:\Documents and Settings\Scrangos\x.exe
2008-02-24 23:21 . 2007-09-28 21:05 593,920 ——— C:\WINDOWS\system32\ati2sgag.exe
2008-02-24 12:17 . 2008-02-24 12:17 d——– C:\Documents and Settings\Scrangos\Application Data\Grisoft
2008-02-24 12:17 . 2007-05-30 08:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-24 12:00 . 2008-02-26 14:44 d——– C:\Documents and Settings\Scrangos\Application Data\AVG7
2008-02-24 11:59 . 2008-02-24 11:59 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-24 11:59 . 2008-02-24 12:17 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-24 11:59 . 2008-02-24 12:29 d——– C:\Documents and Settings\All Users\Application Data\avg7
2008-02-24 11:25 . 2007-01-18 08:00 3,968 –a—— C:\WINDOWS\system32\drivers\AvgArCln.sys
2008-02-24 03:27 . 2008-02-24 04:07 d——– C:\Documents and Settings\Administrator\.housecall6.6
2008-02-23 20:32 . 2008-02-23 20:28 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-02-23 20:28 . 2008-02-23 21:41 d——– C:\Documents and Settings\Scrangos\.housecall6.6
2008-02-19 19:26 . 2008-02-19 19:27 d——– C:\Program Files\Dofus
2008-02-18 23:05 . 2008-02-18 23:09 d——– C:\Program Files\OpenVPN
2008-02-18 22:30 . 2008-02-18 22:30 d——– C:\Program Files\Your Freedom
2008-02-18 17:39 . 2008-02-18 17:40 d——– C:\Program Files\AutoTunnel GG
2008-02-18 13:19 . 2008-02-18 13:19 d——– C:\Documents and Settings\Scrangos\Builds
2008-02-18 13:12 . 2008-02-18 13:19 d——– C:\Documents and Settings\All Users\Application Data\Outspark
2008-02-17 17:22 . 2008-02-17 17:22 d——– C:\Program Files\MaxOn Soft
2008-02-17 10:59 . 2008-02-17 11:40 d——– C:\Program Files\SealOnline
2008-02-17 05:15 . 2008-02-17 05:47 d——– C:\Program Files\Neffy
2008-02-14 22:13 . 2007-09-18 23:41 258,352 –a—— C:\WINDOWS\system32\unicows.dll
2008-02-13 18:03 . 2008-02-13 18:03 d——– C:\mGame
2008-02-13 08:11 . 2008-02-13 08:11 d——– C:\Program Files\Common Files\INCA Shared
2008-02-09 15:35 . 2008-02-09 15:35 d——– C:\Program Files\Lavasoft
2008-02-09 15:35 . 2008-02-25 16:14 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-09 01:11 . 2008-02-09 01:11 118,784 –a—— C:\WINDOWS\system32\sbcrreag.dll
2008-02-09 00:00 . 2008-02-09 00:00 d——– C:\Documents and Settings\Scrangos\Application Data\ProxyCap
2008-02-08 23:26 . 2008-02-08 23:47 d——– C:\Program Files\HTTP-Tunnel
2008-02-08 21:02 . 2008-02-08 23:47 d——– C:\Program Files\ProxyWay
2008-02-02 02:05 . 2008-02-02 02:08 d——– C:\Program Files\eVer-Craft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-01 00:30 21,018,656 –sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-03-01 00:28 250,472 –sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-03-01 00:21 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\Free Download Manager
2008-03-01 00:20 ——— d—–w C:\Program Files\Trillian
2008-02-29 06:45 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\MegauploadToolbar
2008-02-27 12:01 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-26 00:19 5,521,896 —-a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2008-02-25 20:14 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-02-25 19:52 ——— d—–w C:\Program Files\SpywareBlaster
2008-02-25 19:34 ——— d—–w C:\Program Files\VisualRoute
2008-02-25 02:37 ——— d—–w C:\Program Files\MultiRes
2008-02-25 02:28 ——— d—–w C:\Program Files\Radeon Omega Drivers
2008-02-24 21:07 ——— d—–w C:\Program Files\Game Elements PC Recoil Pad
2008-02-23 01:37 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-02-22 18:41 ——— d—–w C:\Program Files\Granado Espada
2008-02-20 23:13 ——— d—–w C:\Program Files\mIRC
2008-02-17 03:40 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\Xfire
2008-02-16 13:15 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\IGN_DLM
2008-02-09 19:13 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\Lavasoft
2008-02-07 19:58 107,888 —-a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-02-01 07:28 ——— d—–w C:\Program Files\World of Warcraft
2008-01-31 02:02 54,608 —-a-w C:\WINDOWS\system32\xfcodec.dll
2008-01-30 18:14 70,656 —-a-w C:\WINDOWS\ScUnin.exe
2008-01-30 00:41 25,216 —-a-w C:\WINDOWS\system32\drivers\tap0901.sys
2008-01-27 19:52 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\ATI
2008-01-27 01:28 ——— d—–w C:\Program Files\Microsoft IntelliPoint
2008-01-27 01:27 ——— d—–w C:\Program Files\MSXML 6.0
2008-01-26 23:53 ——— d—–w C:\Program Files\Warkeys
2008-01-26 04:28 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\atitray
2008-01-26 04:20 472,576 —-a-w C:\WINDOWS\Radeon Omega Drivers v4.8.442 Uninstall.exe
2008-01-26 02:19 139,264 —-a-w C:\WINDOWS\War3Unin.exe
2008-01-26 01:34 51,472 —-a-w C:\WINDOWS\system32\imagecfg.exe
2008-01-22 21:27 ——— d—–w C:\Program Files\Codec Pack - All In 1
2008-01-22 21:25 737,280 —-a-w C:\WINDOWS\iun6002.exe
2008-01-18 00:44 ——— d—–w C:\Program Files\Analog Devices
2008-01-15 00:16 ——— d—–w C:\Program Files\Sims2Pack Clean Installer
2008-01-15 00:16 ——— d—–w C:\Program Files\SimPE
2008-01-12 22:06 ——— d—–w C:\Program Files\EA GAMES
2008-01-12 03:08 ——— d—–w C:\Program Files\Alcohol Soft
2008-01-07 20:11 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\Sonic
2008-01-07 20:07 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\Leadertech
2008-01-07 20:04 ——— d—–w C:\Program Files\Sonic
2008-01-06 17:10 ——— d—–w C:\Program Files\Microsoft ActiveSync
2008-01-06 17:10 ——— d—–w C:\Program Files\Common Files\L&H;
2008-01-06 17:09 ——— d—–w C:\Program Files\Microsoft Works
2008-01-06 17:08 ——— d—–w C:\Program Files\Microsoft.NET
2008-01-05 12:45 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\OpenOffice.org2
2008-01-04 22:41 ——— d—–w C:\Program Files\Black Isle
2008-01-04 22:29 ——— d—–w C:\Documents and Settings\Scrangos\Application Data\DAEMON Tools
2008-01-04 22:27 ——— d—–w C:\Program Files\DAEMON Tools Lite
2008-01-03 21:01 715,248 —-a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-01-03 21:01 ——— d—–w C:\Program Files\DAEMON Tools Pro
2007-12-21 02:24 46,080 —-a-w C:\WINDOWS\system32\amdpcom32.dll
2007-12-05 03:05 368,640 —-a-w C:\WINDOWS\system32\ATIDEMGX.dll
2007-12-05 03:04 269,312 —-a-w C:\WINDOWS\system32\ati2dvag.dll
2007-12-05 02:56 147,456 —-a-w C:\WINDOWS\system32\atipdlxx.dll
2007-12-05 02:55 43,520 —-a-w C:\WINDOWS\system32\ati2edxx.dll
2007-12-05 02:55 26,112 —-a-w C:\WINDOWS\system32\Ati2mdxx.exe
2007-12-05 02:55 122,880 —-a-w C:\WINDOWS\system32\Oemdspif.dll
2007-12-05 02:55 122,880 —-a-w C:\WINDOWS\system32\ati2evxx.dll
2007-12-05 02:53 53,248 —-a-w C:\WINDOWS\system32\ATIDDC.DLL
2007-12-05 02:53 495,616 —-a-w C:\WINDOWS\system32\ati2evxx.exe
2007-12-05 02:48 9,535,488 —-a-w C:\WINDOWS\system32\atioglx2.dll
2007-12-05 02:44 3,175,584 —-a-w C:\WINDOWS\system32\ati3duag.dll
2007-12-05 02:33 1,640,192 —-a-w C:\WINDOWS\system32\ativvaxx.dll
2007-12-05 02:19 5,435,392 —-a-w C:\WINDOWS\system32\atioglxx.dll
2007-12-05 02:19 385,024 —-a-w C:\WINDOWS\system32\atikvmag.dll
2007-12-05 02:17 17,408 —-a-w C:\WINDOWS\system32\atitvo32.dll
2007-12-05 02:14 180,224 —-a-w C:\WINDOWS\system32\atiok3x2.dll
2007-12-05 02:11 499,712 —-a-w C:\WINDOWS\system32\ati2cqag.dll
2007-04-19 22:42 205,778 —-a-w C:\Program Files\CustomKeys.txt
2006-11-20 07:54 202,277,175 —-a-w C:\Program Files\se.ipf
2006-10-05 17:58 1,134,282,010 —-a-w C:\Documents and Settings\Scrangos\RAG_SETUP0711.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-01-03 09:54 486856]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" [2007-12-22 03:09 221056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14 919016]
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14 919016]
"amd_dc_opt"="C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2006-11-17 16:49 77824]
"SoundMax"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2006-05-18 14:26 729088]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-05-18 14:22 843776]
"IntelliPoint"="c:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 12:01 1037736]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-24 11:59 579072]
"AtiPTA"="atiptaxx.exe" [2006-02-21 21:05 344064 C:\WINDOWS\system32\atiptaxx.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-24 11:59 219136]

C:\Documents and Settings\test17\Start Menu\Programs\Startup\
OpenOffice.org 2.0.lnk - C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe [2006-07-14 21:26:34 393216]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.exe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^TabUserW.exe.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\TabUserW.exe.lnk
backup=C:\WINDOWS\pss\TabUserW.exe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Scrangos^Start Menu^Programs^Startup^hamachi.lnk]
path=C:\Documents and Settings\Scrangos\Start Menu\Programs\Startup\hamachi.lnk
backup=C:\WINDOWS\pss\hamachi.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ANIWZCS2Service]
–a—— 2004-08-16 16:45 45056 C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\D-Link AirPlus G]
–a—— 2004-08-18 11:47 1249280 C:\Program Files\D-Link\AirPlus G\AirGCFG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
–a—— 2007-03-05 17:57 1103480 C:\Program Files\Download Manager\DLM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMEKRMIG6.1]
–a—— 2001-08-23 18:00 44032 C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
–a—— 2004-08-03 22:32 208952 C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
–a—— 2005-08-11 15:30 249856 C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
–a—— 2005-08-11 15:30 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 3100 Series]
–a—— 2003-07-28 18:50 106496 C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXBRKsk]
–a—— 2003-06-13 14:57 294912 C:\PROGRA~1\LEXMAR~1\LXBRKsk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
–a—— 2004-08-03 22:31 59392 C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
–a—— 2004-08-03 22:32 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
–a—— 2004-08-03 22:32 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
–a—— 2004-11-02 20:24 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
–a—— 2006-05-18 14:26 729088 C:\Program Files\Analog Devices\SoundMAX\Smax4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
–a—— 2006-05-18 14:22 843776 C:\Program Files\Analog Devices\Core\smax4pnp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
–a—— 2004-05-12 01:03 1038336 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2005-11-10 13:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"ANIWZCS2Service"=C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
"PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
"PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
"newname"=C:\\nwnmff_e21.exe
"MSPY2002"=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
"IMEKRMIG6.1"=C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"F:\\Program Files\\Flagship Studios\\Hellgate London\\Launcher.exe"=
"F:\\Program Files\\Flagship Studios\\Mythos\\bin\\Mythos.exe"=
"C:\\Program Files\\GRISOFT\\AVG7\\avginet.exe"=
"C:\\Program Files\\GRISOFT\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\GRISOFT\\AVG7\\avgcc.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9842:TCP"= 9842:TCP:*:Disabled:SolidNetworkManager
"9842:UDP"= 9842:UDP:*:Disabled:SolidNetworkManager
"10737:TCP"= 10737:TCP:*:Disabled:SolidNetworkManager
"10737:UDP"= 10737:UDP:*:Disabled:SolidNetworkManager
"12623:TCP"= 12623:TCP:*:Disabled:SolidNetworkManager
"12623:UDP"= 12623:UDP:*:Disabled:SolidNetworkManager

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-29 20:30:00
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
.
**************************************************************************
.
Completion time: 2008-02-29 20:35:24 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-01 00:35:21
ComboFix2.txt 2008-02-27 01:42:39
ComboFix3.txt 2008-02-26 00:36:22
ComboFix4.txt 2008-02-25 22:30:48


Hijackthis


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:11, on 2008-02-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\IrfanView\I_VIEW32.EXE
C:\Program Files\microtrend\thisjackhi\canthidefromthispt2.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:81
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [SoundMax] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" /automount
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CBF7EDC-17EC-442C-8AE9-5E804707B6CA} (NeffyClient Class) - http://dist.cdnetworks.co.jp/cdndist/neffy/Neffy.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1159060709606
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1159060656684
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {7C5D062A-7A1E-4A46-A02B-A928084CBD66} (MLauncherNew Class) - http://legendofares.netgame.com/download/MusaLauncherNew.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6E02604C-F26B-45B7-AA4F-2C0AF39E0D7D}: NameServer = 81.169.172.219,81.169.141.30
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\system32\npkcsvc.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: setaffinity - Unknown owner - F:\rc-warhammer\setaffinity\\setaffinity_service.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

–
End of file - 7214 bytes
Need to know: Are you located in or near Berlin or are you aware that some of your search requests are passing through there?


Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6u4.
  • Scroll down to where it says "The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • In the pull down menu next to Platform select Windows
  • Check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement"
  • Click Continue
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u4-windowsi586-p.exe to install the newest version.


Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon.
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.
Alright I updated my java, the steps to delete the temp files were slightly different but they are deleted, Ill update my IE as well while im at it, even though i dont use it. I live in GMT-4, there shoudnt be content going to germany. I did recently install a search bar on firefox to support a group which i dont know where the country its based from is at. Its disabled most of the time, though ive done 2-3 searches on it. Edit: Removed a double negative.
There is a file in your log of which I am unsure. For that reason, I need you to submit it to Jotti's for analysis.

1. Click HERE to get to Jotti's site.

2. At the top of the Jotti window, use the Browse button to locate the following file on your system:

The first file name that changes

3. Once you have located the file, click SUBMIT and the content of the file will be uploaded by the site and analysed.

4. Please provide me with the results of the analysis.

5. Now do the same with the second.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI