This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] The "Bad Image" Warning

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here is the other one. The previous post has the other information. Malwarebytes' Anti-Malware 1.30 Database version: 1306 Windows 5.1.2600 Service Pack 3 10/26/2008 5:02:00 PM mbam-log-2008-10-26 (17-02-00).txt Scan type: Quick Scan Objects scanned: 56288 Time elapsed: 9 minute(s), 52 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hello

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\drivers\TDSSmxoe.sys
C:\WINDOWS\system32\sdmyqru.dll


Folder::

Registry::
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDSSserv.sys]




Driver::
TDSSserv


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.




Also post a new HJT log
Here is Combofix.

ComboFix 08-10-25.01 - HP_Administrator 2008-10-27 16:31:09.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.545 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\HP_Administrator\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\WINDOWS\system32\drivers\TDSSmxoe.sys
C:\WINDOWS\system32\sdmyqru.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\sdmyqru.dll

.
((((((((((((((((((((((((( Files Created from 2008-09-27 to 2008-10-27 )))))))))))))))))))))))))))))))
.

2008-10-26 19:00 . 2008-10-26 19:00 d——– C:\ERDNT
2008-10-26 18:51 . 2001-08-17 14:56 66,048 –a—— C:\WINDOWS\system32\dllcache\s3legacy.dll
2008-10-26 15:06 . 2008-10-26 15:06 578,560 –a—— C:\WINDOWS\system32\dllcache\user32.dll
2008-10-26 15:02 . 2008-10-26 15:02 d——– C:\WINDOWS\ERUNT
2008-10-26 14:58 . 2008-10-26 16:45 d——– C:\SDFix
2008-10-26 03:45 . 2008-10-26 03:45 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-26 03:45 . 2008-10-26 03:45 d——– C:\Documents and Settings\HP_Administrator\Application Data\Malwarebytes
2008-10-26 03:45 . 2008-10-26 03:45 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-26 03:45 . 2008-10-22 16:10 38,496 –a—— C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-26 03:45 . 2008-10-22 16:10 15,504 –a—— C:\WINDOWS\system32\drivers\mbam.sys
2008-10-26 03:42 . 2008-10-26 03:42 d——– C:\Program Files\ERUNT
2008-10-26 03:38 . 2008-10-26 03:38 d——– C:\Program Files\Trend Micro
2008-10-26 01:35 . 2008-10-26 01:35 d——– C:\Documents and Settings\HP_Administrator\Application Data\Uniblue
2008-10-26 01:32 . 2008-10-26 21:58 d——– C:\Program Files\Crawler
2008-10-25 23:25 . 2008-10-25 23:25 d——– C:\Documents and Settings\Administrator\Application Data\Spyware Terminator
2008-10-25 23:15 . 2008-10-26 01:30 d——– C:\Program Files\WinClamAVShield
2008-10-25 23:14 . 2008-10-26 10:19 d——– C:\Program Files\Spyware Terminator
2008-10-25 23:14 . 2008-10-27 11:00 d——– C:\Documents and Settings\HP_Administrator\Application Data\Spyware Terminator
2008-10-25 23:14 . 2008-10-26 03:33 d——– C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-10-25 23:14 . 2008-10-25 23:14 141,312 –a—— C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-10-25 19:41 . 2008-10-25 19:41 d——– C:\Program Files\Alwil Software
2008-10-25 12:18 . 2008-10-25 12:18 164 –a—— C:\WINDOWS\system32\TDSSmupe.dat
2008-10-15 08:22 . 2008-09-15 08:12 1,846,400 ——— C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-15 08:22 . 2008-09-08 06:41 333,824 ——— C:\WINDOWS\system32\dllcache\srv.sys
2008-10-15 08:21 . 2008-08-14 06:09 2,145,280 –a—— C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 08:21 . 2008-08-14 05:33 2,066,048 ——— C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-15 08:21 . 2008-08-14 05:33 2,023,936 ——— C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-12 17:09 . 2008-10-12 17:09 d——– C:\Program Files\Combined Community Codec Pack
2008-10-12 16:53 . 2008-10-12 17:09 d——– C:\Program Files\VideoLAN
2008-10-10 21:36 . 2008-10-10 21:36 d——– C:\Documents and Settings\All Users\Application Data\acccore
2008-10-10 00:19 . 2008-10-10 00:19 d——– C:\Program Files\eRightSoft
2008-10-09 22:51 . 2008-10-09 23:15 d——– C:\Program Files\Red Kawa
2008-10-09 22:51 . 2008-10-09 22:51 d——– C:\Program Files\AviSynth 2.5
2008-10-09 22:32 . 2005-02-27 21:48 356,352 –a—— C:\WINDOWS\system32\RealMediaSplitter.ax
2008-10-09 21:38 . 2008-10-09 21:38 d——– C:\ConverterOutput
2008-10-09 21:38 . 2007-03-25 00:51 3,049,984 –a—— C:\WINDOWS\system32\libavcodec.dll
2008-10-09 21:38 . 2007-03-25 21:40 2,174,976 –a—— C:\WINDOWS\system32\ffdshow.ax
2008-10-09 21:38 . 2007-03-25 00:51 404,480 –a—— C:\WINDOWS\system32\libmplayer.dll
2008-10-09 21:38 . 2003-03-30 20:08 372,736 –a—— C:\WINDOWS\system32\xvid.ax
2008-10-09 21:38 . 2007-01-01 05:30 200,704 –a—— C:\WINDOWS\system32\TomsMoComp_ff.dll
2008-10-09 21:38 . 2007-03-25 00:51 114,688 –a—— C:\WINDOWS\system32\libmpeg2_ff.dll
2008-10-09 21:38 . 2004-09-10 13:50 34,820 –a—— C:\WINDOWS\system32\ffdshow.reg
2008-10-09 21:37 . 2008-10-09 23:29 d——– C:\Program Files\Cucusoft
2008-10-09 21:34 . 2008-10-09 23:50 d——– C:\Program Files\Handbrake
2008-10-09 20:26 . 2008-10-25 19:42 d——– C:\Documents and Settings\HP_Administrator\Application Data\BitTorrent
2008-10-09 20:25 . 2008-10-09 20:25 d——– C:\Program Files\DNA
2008-10-09 20:25 . 2008-10-09 20:26 d——– C:\Program Files\BitTorrent
2008-10-09 20:25 . 2008-10-27 16:33 d——– C:\Documents and Settings\HP_Administrator\Application Data\DNA
2008-10-05 00:15 . 2008-10-05 00:15 d——– C:\Program Files\iTunes
2008-10-05 00:15 . 2008-10-05 00:15 d——– C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-05 00:12 . 2008-10-01 13:01 32,000 –a—— C:\WINDOWS\system32\drivers\usbaapl.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-25 23:37 ——— d—–w C:\Documents and Settings\All Users\Application Data\avg8
2008-10-25 18:06 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\FrostWire
2008-10-24 20:30 ——— d—–w C:\Program Files\AIM6
2008-10-24 20:30 ——— d—–w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-10-24 07:07 ——— d—–w C:\Program Files\Microsoft Silverlight
2008-10-15 22:18 60,512 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\GDIPFONTCACHEV1.DAT
2008-10-15 16:34 337,408 —-a-w C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-13 02:08 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\Printer Info Cache
2008-10-13 02:08 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\Image Zone Express
2008-10-12 23:41 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\Yahoo!
2008-10-05 19:09 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\Apple Computer
2008-10-05 04:15 ——— d—–w C:\Program Files\iPod
2008-10-03 17:41 6,066,176 ——w C:\WINDOWS\system32\dllcache\ieframe.dll
2008-09-24 22:09 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\AdobeUM
2008-09-15 12:12 1,846,400 —-a-w C:\WINDOWS\system32\win32k.sys
2008-09-12 01:31 61,440 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\modemutil.dll
2008-09-12 01:31 45,056 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\uninstallUI\eHelpSetup.exe
2008-09-12 01:31 44,032 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Scripts\devcon.exe
2008-09-12 01:31 40,960 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\ScDmi.dll
2008-09-12 01:31 341,048 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\HPBasicDetection3.dll
2008-09-12 01:31 32,768 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\uploadHSC.dll
2008-09-12 01:31 32,768 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\Scom.dll
2008-09-12 01:31 217,088 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
2008-09-12 01:31 163,840 —-a-w C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\modemcheck.dll
2008-09-10 03:37 ——— d—–w C:\Program Files\QuickTime
2008-09-10 03:16 ——— d—–w C:\Program Files\Bonjour
2008-09-08 10:41 333,824 —-a-w C:\WINDOWS\system32\drivers\srv.sys
2008-09-05 03:43 ——— d—–w C:\Documents and Settings\HP_Administrator\Application Data\U3
2008-08-29 14:18 87,336 —-a-w C:\WINDOWS\system32\dns-sd.exe
2008-08-29 13:53 61,440 —-a-w C:\WINDOWS\system32\dnssd.dll
2008-08-27 08:24 3,593,216 —-a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-08-25 08:38 13,824 ——w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-08-25 08:37 70,656 —-a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-08-23 05:56 635,848 —-a-w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-08-23 05:54 161,792 —-a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-08-14 10:11 2,189,184 —-a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 10:11 2,189,184 —-a-w C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-08-14 10:04 138,496 ——w C:\WINDOWS\system32\dllcache\afd.sys
2008-08-14 09:33 2,066,048 —-a-w C:\WINDOWS\system32\ntkrnlpa.exe
2006-11-28 23:49 320 —-a-w C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
2006-06-24 15:13 251 —-a-w C:\Program Files\wt3d.ini
2006-05-03 09:06 163,328 –sh–r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47 31,232 –sh–r C:\WINDOWS\system32\msfDX.dll
2008-03-16 12:30 216,064 –sh–r C:\WINDOWS\system32\nbDX.dll
.

((((((((((((((((((((((((((((( snapshot@2008-10-26_12.30.49.10 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 16:02:28 163,328 —-a-w C:\WINDOWS\ERDNT\10-26-2008-2\ERDNT.EXE
+ 2008-10-26 22:46:43 7,172,096 —-a-w C:\WINDOWS\ERDNT\10-26-2008-2\Users\00000001\NTUSER.DAT
+ 2008-10-26 22:46:43 344,064 —-a-w C:\WINDOWS\ERDNT\10-26-2008-2\Users\00000002\UsrClass.dat
+ 2008-08-07 20:27:04 163,328 —-a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-10-26 19:03:01 7,172,096 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2008-10-26 19:03:01 344,064 —-a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-08-07 20:27:04 163,328 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-10-26 19:02:49 7,172,096 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2008-10-26 19:02:49 344,064 —-a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
+ 2008-04-14 00:11:48 136,192 —-a-w C:\WINDOWS\system32\dllcache\aaclient.dll
+ 2008-04-14 00:11:48 1,852,928 —-a-w C:\WINDOWS\system32\dllcache\acgenral.dll
+ 2008-04-14 00:11:48 451,072 —-a-w C:\WINDOWS\system32\dllcache\aclayers.dll
+ 2008-04-14 00:11:48 245,248 —-a-w C:\WINDOWS\system32\dllcache\acspecfc.dll
+ 2008-04-14 00:11:48 116,224 —-a-w C:\WINDOWS\system32\dllcache\acxtrnal.dll
+ 2008-04-14 00:11:48 20,540 —-a-w C:\WINDOWS\system32\dllcache\admin.dll
+ 2008-04-14 00:12:12 16,439 —-a-w C:\WINDOWS\system32\dllcache\admin.exe
+ 2008-04-14 00:11:48 43,520 —-a-w C:\WINDOWS\system32\dllcache\admwprox.dll
+ 2008-04-14 00:11:48 290,816 —-a-w C:\WINDOWS\system32\dllcache\adsiis51.dll
+ 2008-04-14 00:12:12 98,304 —-a-w C:\WINDOWS\system32\dllcache\ahui.exe
+ 2008-04-14 00:11:49 125,952 —-a-w C:\WINDOWS\system32\dllcache\apphelp.dll
+ 2008-04-14 00:11:49 65,024 —-a-w C:\WINDOWS\system32\dllcache\asycfilt.dll
+ 2008-04-14 00:11:50 30,208 —-a-w C:\WINDOWS\system32\dllcache\atmlib.dll
+ 2008-04-14 00:11:50 20,540 —-a-w C:\WINDOWS\system32\dllcache\author.dll
+ 2008-04-14 00:12:12 16,439 —-a-w C:\WINDOWS\system32\dllcache\author.exe
+ 2008-04-14 00:11:50 233,472 —-a-w C:\WINDOWS\system32\dllcache\azroles.dll
+ 2008-04-14 00:11:50 7,168 —-a-w C:\WINDOWS\system32\dllcache\bitsprx4.dll
+ 2008-04-14 00:09:05 16,896 —-a-w C:\WINDOWS\system32\dllcache\cfgmgr32.dll
+ 2008-04-14 00:12:14 188,480 —-a-w C:\WINDOWS\system32\dllcache\cfgwiz.exe
+ 2008-04-14 00:11:51 46,592 —-a-w C:\WINDOWS\system32\dllcache\coadmin.dll
+ 2008-04-14 00:11:51 617,472 —-a-w C:\WINDOWS\system32\dllcache\comctl32.dll
+ 2008-04-14 00:11:51 276,992 —-a-w C:\WINDOWS\system32\dllcache\comdlg32.dll
+ 2008-04-14 00:11:51 252,928 —-a-w C:\WINDOWS\system32\dllcache\compatui.dll
+ 2008-04-14 00:11:51 599,040 —-a-w C:\WINDOWS\system32\dllcache\crypt32.dll
+ 2008-04-14 00:11:51 74,752 —-a-w C:\WINDOWS\system32\dllcache\cryptdlg.dll
+ 2008-04-14 00:11:51 33,280 —-a-w C:\WINDOWS\system32\dllcache\cryptdll.dll
+ 2008-04-14 00:11:51 53,760 —-a-w C:\WINDOWS\system32\dllcache\cryptext.dll
+ 2008-04-14 00:11:51 64,512 —-a-w C:\WINDOWS\system32\dllcache\cryptnet.dll
+ 2008-04-14 00:11:51 62,464 —-a-w C:\WINDOWS\system32\dllcache\cryptsvc.dll
+ 2008-04-14 00:11:51 512,512 —-a-w C:\WINDOWS\system32\dllcache\cryptui.dll
+ 2008-04-14 00:11:52 19,456 —-a-w C:\WINDOWS\system32\dllcache\dimsntfy.dll
+ 2008-04-14 00:11:52 39,936 —-a-w C:\WINDOWS\system32\dllcache\dimsroam.dll
+ 2008-04-14 00:11:52 32,768 —-a-w C:\WINDOWS\system32\dllcache\dispex.dll
+ 2008-04-14 00:11:52 16,384 —-a-w C:\WINDOWS\system32\dllcache\ds32gt.dll
+ 2008-04-13 17:37:57 138,752 —-a-w C:\WINDOWS\system32\dllcache\dssenh.dll
+ 2008-04-14 00:11:53 380,445 —-a-w C:\WINDOWS\system32\dllcache\expsrv.dll
+ 2008-04-13 19:14:29 143,744 —-a-w C:\WINDOWS\system32\dllcache\fastfat.sys
+ 2008-04-14 00:11:53 184,435 —-a-w C:\WINDOWS\system32\dllcache\fp4amsft.dll
+ 2008-04-14 00:11:53 82,035 —-a-w C:\WINDOWS\system32\dllcache\fp4anscp.dll
+ 2008-04-14 00:11:53 147,513 —-a-w C:\WINDOWS\system32\dllcache\fp4apws.dll
+ 2008-04-14 00:11:53 49,210 —-a-w C:\WINDOWS\system32\dllcache\fp4areg.dll
+ 2008-04-14 00:11:53 102,509 —-a-w C:\WINDOWS\system32\dllcache\fp4atxt.dll
+ 2008-04-14 00:11:53 41,020 —-a-w C:\WINDOWS\system32\dllcache\fp4avnb.dll
+ 2008-04-14 00:11:53 32,826 —-a-w C:\WINDOWS\system32\dllcache\fp4avss.dll
+ 2008-04-14 00:11:53 49,212 —-a-w C:\WINDOWS\system32\dllcache\fp4awebs.dll
+ 2008-04-14 00:11:53 876,653 —-a-w C:\WINDOWS\system32\dllcache\fp4awel.dll
+ 2008-04-14 00:12:20 15,120 —-a-w C:\WINDOWS\system32\dllcache\fp98sadm.exe
+ 2008-04-14 00:12:20 109,840 —-a-w C:\WINDOWS\system32\dllcache\fp98swin.exe
+ 2008-04-14 00:12:20 188,494 —-a-w C:\WINDOWS\system32\dllcache\fpcount.exe
+ 2008-04-14 00:11:53 20,541 —-a-w C:\WINDOWS\system32\dllcache\fpexedll.dll
+ 2008-04-14 00:11:53 598,071 —-a-w C:\WINDOWS\system32\dllcache\fpmmc.dll
+ 2007-04-02 16:36:04 208,896 —-a-w C:\WINDOWS\system32\dllcache\fpmmcsat.dll
+ 2008-04-14 00:12:20 20,538 —-a-w C:\WINDOWS\system32\dllcache\fpremadm.exe
+ 2008-04-14 00:11:54 68,608 —-a-w C:\WINDOWS\system32\dllcache\iisext51.dll
+ 2008-04-14 00:11:54 64,512 —-a-w C:\WINDOWS\system32\dllcache\iismap.dll
+ 2008-04-14 00:12:22 30,720 —-a-w C:\WINDOWS\system32\dllcache\iisrstas.exe
+ 2008-04-14 00:11:54 133,632 —-a-w C:\WINDOWS\system32\dllcache\iisrtl.dll
+ 2008-04-14 00:11:54 36,921 —-a-w C:\WINDOWS\system32\dllcache\imeshare.dll
+ 2008-04-14 00:11:55 829,440 —-a-w C:\WINDOWS\system32\dllcache\inetmgr.dll
+ 2008-04-14 00:11:55 13,312 —-a-w C:\WINDOWS\system32\dllcache\infoadmn.dll
+ 2008-04-13 19:19:42 75,264 —-a-w C:\WINDOWS\system32\dllcache\ipsec.sys
+ 2008-04-14 00:11:55 68,608 —-a-w C:\WINDOWS\system32\dllcache\isatq.dll
+ 2008-04-14 00:11:55 155,136 —-a-w C:\WINDOWS\system32\dllcache\itircl.dll
+ 2008-04-14 00:11:55 138,240 —-a-w C:\WINDOWS\system32\dllcache\itss.dll
+ 2008-04-14 00:09:55 6,144 —-a-w C:\WINDOWS\system32\dllcache\kbdbhc.dll
+ 2008-04-14 00:09:55 6,144 —-a-w C:\WINDOWS\system32\dllcache\kbdiultn.dll
+ 2008-04-14 00:09:55 6,144 —-a-w C:\WINDOWS\system32\dllcache\kbdnepr.dll
+ 2008-04-14 00:09:55 6,144 —-a-w C:\WINDOWS\system32\dllcache\kbdpash.dll
+ 2008-04-14 00:11:56 989,696 —-a-w C:\WINDOWS\system32\dllcache\kernel32.dll
+ 2008-04-14 00:11:56 728,064 —-a-w C:\WINDOWS\system32\dllcache\lsasrv.dll
+ 2008-04-14 00:11:56 927,504 —-a-w C:\WINDOWS\system32\dllcache\mfc40u.dll
+ 2008-04-14 00:11:56 1,028,096 —-a-w C:\WINDOWS\system32\dllcache\mfc42.dll
+ 2008-04-14 00:11:56 22,528 —-a-w C:\WINDOWS\system32\dllcache\mfcsubs.dll
+ 2008-04-13 17:25:57 20,480 —-a-w C:\WINDOWS\system32\dllcache\msadcer.dll
+ 2008-04-14 00:11:58 61,440 —-a-w C:\WINDOWS\system32\dllcache\msadcf.dll
+ 2008-04-13 17:25:57 16,384 —-a-w C:\WINDOWS\system32\dllcache\msadcfr.dll
+ 2008-04-14 00:11:58 143,360 —-a-w C:\WINDOWS\system32\dllcache\msadco.dll
+ 2008-04-13 17:25:57 16,384 —-a-w C:\WINDOWS\system32\dllcache\msadcor.dll
+ 2008-04-14 00:11:58 53,248 —-a-w C:\WINDOWS\system32\dllcache\msadcs.dll
+ 2008-04-14 00:11:58 155,648 —-a-w C:\WINDOWS\system32\dllcache\msadds.dll
+ 2008-04-13 17:25:58 24,576 —-a-w C:\WINDOWS\system32\dllcache\msaddsr.dll
+ 2008-04-13 17:26:17 24,576 —-a-w C:\WINDOWS\system32\dllcache\msader15.dll
+ 2008-04-14 00:11:58 536,576 —-a-w C:\WINDOWS\system32\dllcache\msado15.dll
+ 2008-04-14 00:11:58 180,224 —-a-w C:\WINDOWS\system32\dllcache\msadomd.dll
+ 2008-04-14 00:11:58 57,344 —-a-w C:\WINDOWS\system32\dllcache\msador15.dll
+ 2008-04-14 00:11:58 200,704 —-a-w C:\WINDOWS\system32\dllcache\msadox.dll
+ 2008-04-14 00:11:58 57,344 —-a-w C:\WINDOWS\system32\dllcache\msadrh15.dll
+ 2008-04-14 00:11:58 36,864 —-a-w C:\WINDOWS\system32\dllcache\mscpxl32.dll
+ 2008-04-14 00:11:58 4,096 —-a-w C:\WINDOWS\system32\dllcache\msdadc.dll
+ 2008-04-14 00:11:58 4,096 —-a-w C:\WINDOWS\system32\dllcache\msdaenum.dll
+ 2008-04-14 00:11:58 4,096 —-a-w C:\WINDOWS\system32\dllcache\msdaer.dll
+ 2008-04-14 00:11:58 233,472 —-a-w C:\WINDOWS\system32\dllcache\msdaora.dll
+ 2008-04-14 00:11:58 77,824 —-a-w C:\WINDOWS\system32\dllcache\msdaosp.dll
+ 2008-04-13 17:25:58 16,384 —-a-w C:\WINDOWS\system32\dllcache\msdaprsr.dll
+ 2008-04-14 00:11:58 200,704 —-a-w C:\WINDOWS\system32\dllcache\msdaprst.dll
+ 2008-04-14 00:11:59 204,800 —-a-w C:\WINDOWS\system32\dllcache\msdaps.dll
+ 2008-04-14 00:11:59 118,784 —-a-w C:\WINDOWS\system32\dllcache\msdarem.dll
+ 2008-04-13 17:25:58 16,384 —-a-w C:\WINDOWS\system32\dllcache\msdaremr.dll
+ 2008-04-14 00:11:59 4,096 —-a-w C:\WINDOWS\system32\dllcache\msdasc.dll
+ 2008-04-14 00:11:59 315,392 —-a-w C:\WINDOWS\system32\dllcache\msdasql.dll
+ 2008-04-13 17:26:07 16,384 —-a-w C:\WINDOWS\system32\dllcache\msdasqlr.dll
+ 2008-04-14 00:11:59 20,480 —-a-w C:\WINDOWS\system32\dllcache\msdatt.dll
+ 2008-04-14 00:11:59 4,096 —-a-w C:\WINDOWS\system32\dllcache\msdaurl.dll
+ 2008-04-14 00:11:59 36,864 —-a-w C:\WINDOWS\system32\dllcache\msdfmap.dll
+ 2008-04-14 00:12:00 151,583 —-a-w C:\WINDOWS\system32\dllcache\msjint40.dll
+ 2008-04-14 00:12:00 102,400 —-a-w C:\WINDOWS\system32\dllcache\msjro.dll
+ 2008-04-14 00:12:00 143,360 —-a-w C:\WINDOWS\system32\dllcache\msorcl32.dll
+ 2008-04-14 00:12:01 343,040 —-a-w C:\WINDOWS\system32\dllcache\msvcrt.dll
+ 2008-04-13 18:30:46 61,440 —-a-w C:\WINDOWS\system32\dllcache\msvcrt40.dll
+ 2008-04-14 00:12:01 24,576 —-a-w C:\WINDOWS\system32\dllcache\msxactps.dll
+ 2008-04-13 19:20:42 91,520 —-a-w C:\WINDOWS\system32\dllcache\ndiswan.sys
+ 2008-04-14 00:11:24 706,048 —-a-w C:\WINDOWS\system32\dllcache\ntdll.dll
+ 2008-04-13 19:15:53 574,976 —-a-w C:\WINDOWS\system32\dllcache\ntfs.sys
+ 2008-04-14 00:12:02 64,000 —-a-w C:\WINDOWS\system32\dllcache\nwapi32.dll
+ 2008-04-14 00:12:02 67,584 —-a-w C:\WINDOWS\system32\dllcache\ocmanage.dll
+ 2008-04-14 00:12:02 249,856 —-a-w C:\WINDOWS\system32\dllcache\odbc32.dll
+ 2008-04-14 00:12:02 16,384 —-a-w C:\WINDOWS\system32\dllcache\odbc32gt.dll
+ 2008-04-14 00:12:30 32,768 —-a-w C:\WINDOWS\system32\dllcache\odbcad32.exe
+ 2008-04-14 00:12:02 135,168 —-a-w C:\WINDOWS\system32\dllcache\odbcconf.dll
+ 2008-04-14 00:12:30 69,632 —-a-w C:\WINDOWS\system32\dllcache\odbcconf.exe
+ 2008-04-14 00:12:02 106,496 —-a-w C:\WINDOWS\system32\dllcache\odbccp32.dll
+ 2008-04-14 00:12:02 65,536 —-a-w C:\WINDOWS\system32\dllcache\odbccr32.dll
+ 2008-04-14 00:12:02 65,536 —-a-w C:\WINDOWS\system32\dllcache\odbccu32.dll
+ 2008-04-13 17:26:05 94,208 —-a-w C:\WINDOWS\system32\dllcache\odbcint.dll
+ 2008-04-14 00:10:31 53,279 —-a-w C:\WINDOWS\system32\dllcache\odbcji32.dll
+ 2008-04-14 00:12:02 278,559 —-a-w C:\WINDOWS\system32\dllcache\odbcjt32.dll
+ 2008-04-14 00:12:02 20,511 —-a-w C:\WINDOWS\system32\dllcache\odtext32.dll
+ 2008-04-14 00:12:02 1,287,168 —-a-w C:\WINDOWS\system32\dllcache\ole32.dll
+ 2008-04-14 00:12:02 551,936 —-a-w C:\WINDOWS\system32\dllcache\oleaut32.dll
+ 2008-04-14 00:12:02 84,992 —-a-w C:\WINDOWS\system32\dllcache\olepro32.dll
+ 2008-04-14 00:12:04 433,664 —-a-w C:\WINDOWS\system32\dllcache\riched20.dll
+ 2008-04-13 17:37:57 208,384 —-a-w C:\WINDOWS\system32\dllcache\rsaenh.dll
+ 2008-04-14 00:12:04 64,000 —-a-w C:\WINDOWS\system32\dllcache\samlib.dll
+ 2008-04-14 00:12:04 415,744 —-a-w C:\WINDOWS\system32\dllcache\samsrv.dll
+ 2008-04-14 00:12:05 144,384 —-a-w C:\WINDOWS\system32\dllcache\schannel.dll
+ 2008-04-14 00:12:34 77,312 —-a-w C:\WINDOWS\system32\dllcache\sdbinst.exe
+ 2008-04-14 09:42:06 985,088 —-a-w C:\WINDOWS\system32\dllcache\setupapi.dll
+ 2008-04-14 00:12:05 5,120 —-a-w C:\WINDOWS\system32\dllcache\sfc.dll
+ 2008-04-14 00:12:05 1,614,848 —-a-w C:\WINDOWS\system32\dllcache\sfcfiles.dll
+ 2008-04-14 00:12:05 65,024 —-a-w C:\WINDOWS\system32\dllcache\shimeng.dll
+ 2008-04-14 00:12:05 20,536 —-a-w C:\WINDOWS\system32\dllcache\shtml.dll
+ 2008-04-14 00:12:35 16,437 —-a-w C:\WINDOWS\system32\dllcache\shtml.exe
+ 2008-04-14 00:12:06 25,088 —-a-w C:\WINDOWS\system32\dllcache\slayerxp.dll
+ 2008-04-14 00:12:06 189,440 —-a-w C:\WINDOWS\system32\dllcache\smtpadm.dll
+ 2008-04-14 00:12:06 2,134,528 —-a-w C:\WINDOWS\system32\dllcache\smtpsnap.dll
+ 2008-04-14 00:12:07 8,192 —-a-w C:\WINDOWS\system32\dllcache\staxmem.dll
+ 2008-04-14 00:12:37 106,496 —-a-w C:\WINDOWS\system32\dllcache\sysocmgr.exe
+ 2008-04-14 00:12:37 32,827 —-a-w C:\WINDOWS\system32\dllcache\tcptest.exe
+ 2007-04-02 16:36:07 16,384 —-a-w C:\WINDOWS\system32\dllcache\tcptsat.dll
+ 2008-04-14 00:12:07 123,392 —-a-w C:\WINDOWS\system32\dllcache\umpnpmgr.dll
+ 2008-04-14 00:12:39 507,904 —-a-w C:\WINDOWS\system32\dllcache\winlogon.exe
+ 2008-04-14 00:12:09 176,640 —-a-w C:\WINDOWS\system32\dllcache\wintrust.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-08-30 4670704]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"VoipStunt"="C:\VOIP\VoipStunt.exe" [2007-12-19 8824112]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2008-10-17 49960]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-10-09 289088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-03-27 185896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-09 44032]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-03 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-10-25 1783808]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-13 C:\WINDOWS\system32\narrator.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=C:\WINDOWS\pss\Acrobat Assistant.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AT&T Self Support Tool.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AT&T Self Support Tool.lnk
backup=C:\WINDOWS\pss\AT&T Self Support Tool.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Color Calibration.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Color Calibration.lnk
backup=C:\WINDOWS\pss\Color Calibration.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MagicTune 3.6.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\MagicTune 3.6.lnk
backup=C:\WINDOWS\pss\MagicTune 3.6.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SBC Self Support Tool.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SBC Self Support Tool.lnk
backup=C:\WINDOWS\pss\SBC Self Support Tool.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Updates From HP.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Updates From HP.lnk
backup=C:\WINDOWS\pss\Updates From HP.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
–a—— 2008-10-17 10:45 49960 C:\Program Files\AIM6\aim6.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2008-04-13 20:12 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMAScheduler]
–a—— 2005-11-01 06:01 90112 c:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
–a—— 2005-08-05 17:56 64512 C:\WINDOWS\ehome\ehtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
–a—— 2005-05-12 03:12 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPBootOp]
–a—— 2005-11-09 13:29 249856 C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD08]
–a—— 2005-06-01 19:35 49152 c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
–a–c— 2004-07-27 20:50 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-10-01 18:57 289576 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
–a—— 2005-02-02 16:44 61440 C:\hp\KBD\kbd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
–a—— 2006-11-13 23:17 380928 C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2008-04-13 20:12 1695232 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2006-05-09 22:50 7311360 C:\WINDOWS\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIDIA nTune]
–a–c— 2006-06-06 08:54 81920 C:\NVIDIA Corporation\nTune\nTuneCmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2006-05-09 22:50 86016 C:\WINDOWS\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCDrSmartMonitor]
–a—— 2005-12-20 07:34 368640 C:\Program Files\PC-Doctor 5 for Windows\PcdSmartMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-09-06 15:09 413696 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
–a—— 2005-07-22 19:14 237568 C:\WINDOWS\SMINST\Recguard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
–a—— 2004-12-13 23:23 663552 C:\WINDOWS\CREATOR\Remind_XP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-07-12 04:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2008-03-27 22:04 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
–a—— 2006-03-30 16:45 313472 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VoipStunt]
–a—— 2007-12-19 00:23 8824112 C:\VOIP\voipstunt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
–a—— 2007-08-30 18:43 4670704 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YBrowser]
–a—— 2006-07-21 17:19 129536 C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YOP]
–a—— 2007-10-26 16:42 509224 C:\PROGRA~1\Yahoo!\YOP\yop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlwaysReady Power Message APP]
–a—— 2005-08-02 20:19 77312 C:\WINDOWS\arpwrmsg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2006-05-09 22:50 1519616 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
–a—— 2006-01-23 06:53 15969280 C:\WINDOWS\RTHDCPL.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"YPCService"=3 (0x3)
"NVSvc"=2 (0x2)
"nTuneService"=2 (0x2)
"iPod Service"=3 (0x3)
"Viewpoint Manager Service"=2 (0x2)
"Symantec Core LC"=2 (0x2)
"ARSVC"=2 (0x2)
"Apple Mobile Device"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"C:\\PROGRA~1\\Yahoo!\\MESSEN~1\\yserver.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\VOIP\\VoipStunt.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\AIM6\\aim6.exe"=
"C:\\Program Files\\FrostWire\\FrostWire.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\DNA\\btdna.exe"=
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=

R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-10-25 141312]
S2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files\Viewpoint\Common\ViewpointService.exe [ ]
.
Contents of the 'Scheduled Tasks' folder

2008-10-24 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe []

2008-10-23 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-27 16:34:38
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TDSSserv.sys]
"imagepath"="\systemroot\system32\drivers\TDSSmxoe.sys"
.
Completion time: 2008-10-27 16:35:44
ComboFix-quarantined-files.txt 2008-10-27 20:35:40
ComboFix2.txt 2008-10-26 18:19:04
ComboFix3.txt 2008-10-26 16:31:07

Pre-Run: 136,136,986,624 bytes free
Post-Run: 136,120,700,928 bytes free

472 — E O F — 2008-10-24 07:01:14










And here is Hijackthis:





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:58:22 PM, on 10/27/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\distnoted.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\Companion\Installs\cpn1\yt.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [VoipStunt] "C:\VOIP\VoipStunt.exe" -nosplash -minimized
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Ìí¼Óµ½QQ±íÇé - C:\Program Files\Tencent\QQ\AddEmotion.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: Yahoo! Blackjack - http://download2.games.yahoo.com/games/clients/y/jt0_x.cab
O16 - DPF: Yahoo! Dominoes - http://download2.games.yahoo.com/games/clients/y/dot9_x.cab
O16 - DPF: Yahoo! Games Voice Chat - http://presence.games.yahoo.com/yog/y/va1_x.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)

–
End of file - 7822 bytes
Hello

Please download Gmer:

http://www.gmer.net/gmer.zip

Now let's perform a Gmer rootkit scan:

  • Double-click Gmer.exe to run the program.
  • When the program opens, click the >>> Tab
  • On the right-side, check all the items to be scanned, but leave "Show All" unchecked
  • Select all drives that are connected to your system to be scanned
  • Click the Scan button
  • When the scan is finished, click Copy to save the scan log to the Windows clipboard
  • Open Notepad or a similar text editor
  • Paste the clipboard contents into a text file by clicking Edit | Paste or Ctl V
  • Save the gmer scan log and post it in your next reply.
  • Close Gmer
  • Open a command prompt (Start | run |type cmd and hit Enter)
  • Type or paste the following to unload the Gmer driver:
    • net stop gmer
  • Hit Enter
  • Exit the command prompt.
Sorry for the slow response, but I will do what you said tommorow. How much longer do you think this will take? I'll be able to devote my time tommorow so I'll have lightspeed responses.
here is the log:

GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-10-28 19:28:43
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.14 —-

SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwClose [0xF2F34606]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateFile [0xF2F3405A]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateKey [0xF2F33D3C]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateSection [0xF2F35652]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteKey [0xF2F33E46]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteValueKey [0xF2F33F30]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwLoadDriver [0xF2F348CC]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwOpenFile [0xF2F34362]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwSetValueKey [0xF2F33BBA]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwTerminateProcess [0xF2F34814]
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwWriteFile [0xF2F34494]

—- Kernel code sections - GMER 1.0.14 —-

? C:\WINDOWS\system32\Drivers\PROCEXP90.SYS The system cannot find the file specified. !
? C:\ComboFix\catchme.sys The system cannot find the path specified. !

—- Devices - GMER 1.0.14 —-

AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 arkbcfltr.sys (Microsoft AR PS/2 Keyboard Filter Driver (Beta 2 Release 2)/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 arkbcfltr.sys (Microsoft AR PS/2 Keyboard Filter Driver (Beta 2 Release 2)/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Services - GMER 1.0.14 —-

Service system32\drivers\TDSSmxoe.sys (*** hidden *** ) [SYSTEM] TDSSserv.sys <– ROOTKIT !!!

—- Registry - GMER 1.0.14 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys@imagepath \systemroot\system32\drivers\TDSSmxoe.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@TDSSserv \systemroot\system32\drivers\TDSSmxoe.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@TDSSl \systemroot\system32\TDSSoipa.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdssservers \systemroot\system32\TDSSmupe.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdssmain \systemroot\system32\TDSSirxy.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdsslog \systemroot\system32\TDSSyavu.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdssadw \systemroot\system32\TDSSncur.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdssinit \systemroot\system32\TDSSqxnr.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdssurls \systemroot\system32\TDSSnmxh.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdsspanels \systemroot\system32\TDSSsahc.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdssserf \systemroot\system32\TDSSehys.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@tdsserrors \systemroot\system32\TDSSwghd.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys\modules@TDSSproc \systemroot\system32\TDSSlubs.log
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys@imagepath \systemroot\system32\drivers\TDSSmxoe.sys
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@TDSSserv \systemroot\system32\drivers\TDSSmxoe.sys
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@TDSSl \systemroot\system32\TDSSoipa.dll
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdssservers \systemroot\system32\TDSSmupe.dat
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdssmain \systemroot\system32\TDSSirxy.dll
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdsslog \systemroot\system32\TDSSyavu.dll
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdssadw \systemroot\system32\TDSSncur.dll
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdssinit \systemroot\system32\TDSSqxnr.dll
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdssurls \systemroot\system32\TDSSnmxh.log
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdsspanels \systemroot\system32\TDSSsahc.dll
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdssserf \systemroot\system32\TDSSehys.dll
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@tdsserrors \systemroot\system32\TDSSwghd.log
Reg HKLM\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules@TDSSproc \systemroot\system32\TDSSlubs.log

—- EOF - GMER 1.0.14 —-



















The net stop gmer only came up with an error. I still cannot go onto the internet, and that's been the problem the whole time.
Hello

1. Please download The Avenger by Swandog46 to your Desktop.
  • Click on Avenger.zip to open the file
  • Extract avenger.exe to your desktop

2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Begin copying here:

Files to delete:
C:\windows\system32\drivers\TDSSmxoe.sys
C:\windows\system32\drivers\TDSSserv.sys

Drivers to delete:
TDSSserv
TDSSmxoe

Registry keys to delete:
HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TDSSserv.sys
HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\TDSSmxoe.sys


Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, start The Avenger program by clicking on its icon on your desktop.
  • Under "Script file to execute" choose "Input Script Manually".
  • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
  • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
  • Click Done
  • Now click on the Green Light to begin execution of the script
  • Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log by using Add/Reply
Here is the avenger log:

Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error: file "C:\windows\system32\drivers\TDSSmxoe.sys" not found!
Deletion of file "C:\windows\system32\drivers\TDSSmxoe.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
–> the object does not exist


Error: file "C:\windows\system32\drivers\TDSSserv.sys" not found!
Deletion of file "C:\windows\system32\drivers\TDSSserv.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
–> the object does not exist


Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\TDSSserv" not found!
Deletion of driver "TDSSserv" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
–> the object does not exist


Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\TDSSmxoe" not found!
Deletion of driver "TDSSmxoe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
–> the object does not exist


Error: registry key "HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TDSSserv.sys" not found!
Deletion of registry key "HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TDSSserv.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
–> the object does not exist


Error: registry key "HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\TDSSmxoe.sys" not found!
Deletion of registry key "HKEY_LOCAL_MACHINE\system\CurrentControlSet\Services\TDSSmxoe.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
–> the object does not exist


Completed script processing.

*******************

Finished! Terminate.























Here is the Hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:04:26 PM, on 10/28/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\VOIP\VoipStunt.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\Companion\Installs\cpn1\yt.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [VoipStunt] "C:\VOIP\VoipStunt.exe" -nosplash -minimized
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Ìí¼Óµ½QQ±íÇé - C:\Program Files\Tencent\QQ\AddEmotion.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: Yahoo! Blackjack - http://download2.games.yahoo.com/games/clients/y/jt0_x.cab
O16 - DPF: Yahoo! Dominoes - http://download2.games.yahoo.com/games/clients/y/dot9_x.cab
O16 - DPF: Yahoo! Games Voice Chat - http://presence.games.yahoo.com/yog/y/va1_x.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: Viewpoint Manager Service - Unknown owner - C:\Program Files\Viewpoint\Common\ViewpointService.exe (file missing)

–
End of file - 7872 bytes
One final thing

Please download and unzip Icesword to its own folder on your desktop


If you get a lot of "red entries" in an IceSword log, don't panic.

Step 1 : Close all windows and run IceSword. Click the Processes tab and watch for processes displayed in red color. A red colored process in this list indicates that it's hidden. Write down the PathName of any processes in red color. Then click on LOG at the top left. It will prompt you to save the log, call this Processes and save it to your desktop.


Step 2 : Click the Win32 Services tab and look out for red colored entries in the services list. Write down the Module name of any services in red color, you will need to expand out the Module tab to see the full name. Then click on LOG. It will prompt you to save the log, call this Services and save it to your desktop.


Step 3 : Click the Startup tab and look out for red colored entries in the startup list. Write down the Path of any startup entries in red color. Then click on LOG. It will prompt you to save the log, call this Startup and save it to your desktop.


Step 4 : Click the SSDT tab and check for red colored entries. If there are any, write down the KModule name.


Step 5 : Click the Message Hooks tab and check for any entries that are underneath Type and labelled WH_KEYBOARD. Write down the Process Path of these entries if present.



Now post all of the data collected under the headings for :

Processes
Win32 Services
Startup
SSDT
Message Hooks
Here is everything-Did you want the logs as well? Processes: No Red Entries Win32 Services: No Red Entries Startup: No Red Entries SSDT: \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys Message Hooks: C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Microsoft Office\Office10\WINWORD.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\AIM6\aim6.exe C:\WINDOWS\explorer.exe C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE C:\Program Files\Common Files\Real\Update_OB\realsced.exe C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\DNA\btdna.exe C:\WINDOWS\explorer.exe C:\WINDOWS\explorer.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE C:\Program Files\AIM6\aim6.exe C:\Program Files\AIM6\aim6.exe C:\Program Files\AIM6\aim6.exe C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\AIM6\aolsoftware.exe C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE C:\Program Files\\SBC Self Support Tool\bin\mpbtn.exe C:\PROGRA~1\Yahoo!\browser\ycommon.exe C:\PROGRA~1\Yahoo!\browser\ycommon.exe C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe C:\WINDOWS\explorer.exe C:\WINDOWS\explorer.exe C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe C:\Program Files\BitTorrent\bittorent.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI