This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Please Help me with a infected system

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Quick Synopsis: Downloaded a executable file on the internet. The .rar file contained 3 .exe files after i ran the first one they all ran/disappeared and the directory became empty. I was not able to delete the directory or find the files. Immediately i noticed my memory running at close to 65%, so i opened the task manager and saw something pretty scary, a familiar virus i found on my desktop (this is my laptop that is the problem now) i saw 4 or 5 .dll files named crazy things. I recalled Virtumonde was the culprit, and i was right too an extent. I solved virtumonde with a program by Atribune last time on my desktop it was the only thing after weeks of trying that worked. this time even his updated version will not remove the issues at hand. I cannot remove what is on the system at this time please advise for further information.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:20:58 PM, on 11/2/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16757)
Boot mode: Normal

Running processes:
C:\Windows\system32\csrss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Windows\system32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Windows\system32\svchost.exe
C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
C:\Acer\Empowering Technology\eNet\eNet Service.exe
C:\Windows\system32\gearsec.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Acer\Mobility Center\MobilityService.exe
C:\Windows\system32\svchost.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\explorer.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/def…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\System32\msconfig.exe" /auto
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {8CF6E9E0-4FC0-48F6-A744-800A09D79D6B} (WebView2 Class) - http://192.168.1.3/webview.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O17 - HKLM\System\CCS\Services\Tcpip\..\{5A7A63D0-E13C-4782-9C69-0BF7449F314F}: NameServer = 85.255.112.153;85.255.112.24
O17 - HKLM\System\CCS\Services\Tcpip\..\{C812779A-59F8-407F-8190-17A854B6B23D}: NameServer = 85.255.112.153;85.255.112.24
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: gearsec - GEAR Software - C:\Windows\system32\gearsec.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Windows Tribute Service - Unknown owner - C:\Windows\system32\kduoa.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 11474 bytes
Hello

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
I hope this works, please reply at your earliest convenience before i throw the laptop out :) just so you know.. the virus/trojan or whatever has got me will not allow me to do updates to ANY programs such as virus definitions, windows update, or go to any download pages that might have a fix for this, it tells me there not even there, but when i go on my desktop i can go to the pages no problrm


ComboFix 08-11-03.01 - Acer Customer 2008-11-03 16:41:16.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1071 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\setup.exe
c:\windows\temp.exe
D:\install.exe

.
((((((((((((((((((((((((( Files Created from 2008-10-03 to 2008-11-03 )))))))))))))))))))))))))))))))
.

2008-11-03 15:43 . 2008-11-03 15:40 13,163,350 –a—— C:\core.zip
2008-11-03 00:54 . 2008-11-03 00:54 d——– c:\users\All Users\SUPERAntiSpyware.com
2008-11-03 00:54 . 2008-11-03 00:54 d——– c:\users\Acer Customer\AppData\Roaming\SUPERAntiSpyware.com
2008-11-03 00:54 . 2008-11-03 00:54 d——– c:\programdata\SUPERAntiSpyware.com
2008-11-03 00:54 . 2008-11-03 00:54 d——– c:\program files\SUPERAntiSpyware
2008-11-03 00:05 . 2008-11-03 00:05 d——– c:\users\All Users\Malwarebytes
2008-11-03 00:05 . 2008-11-03 00:05 d——– c:\users\Acer Customer\AppData\Roaming\Malwarebytes
2008-11-03 00:05 . 2008-11-03 00:05 d——– c:\programdata\Malwarebytes
2008-11-03 00:05 . 2008-11-03 00:05 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-03 00:05 . 2008-10-22 16:10 38,496 –a—— c:\windows\System32\drivers\mbamswissarmy.sys
2008-11-03 00:05 . 2008-10-22 16:10 15,504 –a—— c:\windows\System32\drivers\mbam.sys
2008-11-02 20:05 . 2008-11-02 20:05 d——– c:\program files\Trend Micro
2008-11-02 11:41 . 2008-10-30 17:58 102,664 –a—— c:\windows\System32\drivers\tmcomm.sys
2008-11-02 00:27 . 2008-11-03 16:34 d——– c:\users\All Users\Kaspersky Lab
2008-11-02 00:27 . 2008-11-03 16:34 d——– c:\programdata\Kaspersky Lab
2008-11-02 00:27 . 2008-11-02 00:27 d——– c:\program files\Kaspersky Lab
2008-11-01 23:35 . 2008-11-03 01:08 d——– c:\program files\Panda Security
2008-11-01 11:53 . 2008-11-01 23:29 d——– c:\users\All Users\Kaspersky Lab Setup Files
2008-11-01 11:53 . 2008-11-01 23:29 d——– c:\programdata\Kaspersky Lab Setup Files
2008-11-01 11:29 . 2008-11-01 11:30 288,446,156 –a—— c:\windows\MEMORY.DMP
2008-11-01 09:03 . 2008-11-01 09:03 d——– C:\limedl
2008-10-31 23:10 . 2008-10-31 23:10 d——– C:\VundoFix Backups
2008-10-31 10:09 . 2008-10-31 10:09 d——– c:\windows\Sun
2008-10-30 18:15 . 2008-10-30 18:18 d——– c:\users\All Users\Lavasoft
2008-10-30 18:15 . 2008-10-30 18:18 d——– c:\programdata\Lavasoft
2008-10-30 18:15 . 2008-10-30 18:15 d——– c:\program files\Lavasoft
2008-10-30 17:57 . 2008-11-02 22:31 d——– c:\users\Acer Customer\.housecall6.6
2008-10-30 16:49 . 2008-10-30 16:49 d——– c:\program files\MixMeister Pro 6
2008-10-30 16:47 . 2008-11-03 00:40 d——– c:\program files\Common Files\Wise Installation Wizard
2008-10-29 11:35 . 2008-08-11 22:29 441,856 –a—— c:\windows\System32\win32spl.dll
2008-10-29 11:35 . 2008-08-11 22:29 37,376 –a—— c:\windows\System32\printcom.dll
2008-10-22 23:05 . 2008-08-05 22:27 1,244,672 –a—— c:\windows\System32\mcmde.dll
2008-10-22 23:05 . 2008-08-05 22:27 428,032 –a—— c:\windows\System32\EncDec.dll
2008-10-22 23:05 . 2008-08-05 22:27 292,352 –a—— c:\windows\System32\psisdecd.dll
2008-10-22 23:05 . 2008-08-05 22:26 217,088 –a—— c:\windows\System32\psisrndr.ax
2008-10-22 23:05 . 2008-08-05 22:26 177,152 –a—— c:\windows\System32\mpg2splt.ax
2008-10-22 23:05 . 2008-08-05 22:26 80,896 –a—— c:\windows\System32\MSNP.ax
2008-10-22 23:05 . 2008-08-05 22:26 68,608 –a—— c:\windows\System32\Mpeg2Data.ax
2008-10-22 23:05 . 2008-08-05 22:26 57,856 –a—— c:\windows\System32\MSDvbNP.ax
2008-10-22 11:27 . 2002-01-05 05:48 974,848 –a—— c:\windows\System32\mfc70.dll
2008-10-22 11:27 . 2000-05-22 05:00 647,872 –a—— c:\windows\System32\mscomct2.ocx
2008-10-22 11:27 . 2002-01-05 04:40 487,424 –a—— c:\windows\System32\msvcp70.dll
2008-10-22 11:27 . 2002-01-05 10:37 344,064 –a—— c:\windows\System32\msvcr70.dll
2008-10-22 11:27 . 2004-03-08 23:00 224,016 –a—— c:\windows\System32\tabctl32.ocx
2008-10-21 11:17 . 2008-10-30 16:50 d——– c:\users\Acer Customer\AppData\Roaming\MixMeister Technology
2008-10-21 11:17 . 2008-10-21 11:18 d——– c:\program files\MixMeister Fusion
2008-10-19 19:39 . 2008-10-19 19:39 d——– c:\program files\Curse
2008-10-15 11:01 . 2008-09-17 23:35 3,505,208 –a—— c:\windows\System32\ntkrnlpa.exe
2008-10-15 11:01 . 2008-09-17 23:35 3,470,904 –a—— c:\windows\System32\ntoskrnl.exe
2008-10-15 11:01 . 2008-09-17 21:03 2,027,520 –a—— c:\windows\System32\win32k.sys
2008-10-15 11:01 . 2008-08-25 20:12 290,304 –a—— c:\windows\System32\drivers\srv.sys
2008-10-14 15:03 . 2008-10-14 15:30 d——– c:\users\Public\Games
2008-10-14 14:05 . 2008-10-14 14:05 d——– c:\users\All Users\Blizzard
2008-10-14 14:05 . 2008-10-14 14:05 d——– c:\programdata\Blizzard
2008-10-10 10:08 . 2008-10-10 10:31 d——– c:\program files\Common Files\Blizzard Entertainment
2008-10-09 22:35 . 2008-10-09 22:35 d——– C:\wow
2008-10-09 21:41 . 2008-10-09 21:41 d——– C:\DVR

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-03 06:07 ——— d—–w c:\program files\Java
2008-11-03 05:43 ——— d—–w c:\program files\LogMeIn
2008-11-02 19:25 ——— d—–w c:\users\Acer Customer\AppData\Roaming\LimeWire
2008-11-02 05:34 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-11-02 05:17 ——— d—–w c:\programdata\Symantec
2008-10-18 14:13 ——— d—–w c:\program files\Windows Mail
2008-10-17 00:35 87,352 —-a-w c:\windows\System32\LMIinit.dll
2008-10-17 00:35 83,288 —-a-w c:\windows\System32\LMIRfsClientNP.dll
2008-10-17 00:35 28,984 —-a-w c:\windows\System32\LMIport.dll
2008-10-17 00:35 23,736 —-a-w c:\windows\System32\lmimirr.dll
2008-10-17 00:35 10,040 —-a-w c:\windows\System32\lmimirr2.dll
2008-10-02 03:49 826,368 —-a-w c:\windows\System32\wininet.dll
2008-10-02 03:49 56,320 —-a-w c:\windows\System32\iesetup.dll
2008-10-02 03:49 52,736 —-a-w c:\windows\AppPatch\iebrshim.dll
2008-10-02 03:48 26,624 —-a-w c:\windows\System32\ieUnatt.exe
2008-09-28 15:46 ——— d—–w c:\program files\Mozilla Thunderbird
2008-09-21 13:54 ——— d—–w c:\program files\PCDJ DEX
2008-09-18 22:27 ——— d-s—w c:\program files\Xfire
2008-09-15 03:34 ——— d—–w c:\users\Acer Customer\AppData\Roaming\Xfire
2008-09-15 03:24 ——— d—–w c:\users\Acer Customer\AppData\Roaming\My Games
2008-09-15 03:20 ——— d—–w c:\programdata\Xfire
2008-09-15 02:56 ——— d–h–w c:\program files\InstallShield Installation Information
2008-09-15 02:56 ——— d—–w c:\program files\Firaxis Games
2008-09-15 02:50 ——— d—–w c:\users\Acer Customer\AppData\Roaming\InstallShield
2008-09-06 21:31 ——— d—–w c:\program files\BitPim
2008-08-27 21:03 42,320 —-a-w c:\windows\System32\xfcodec.dll
2008-07-09 19:30 174 –sha-w c:\program files\desktop.ini
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-05-09 1232896]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-09-03 1576176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-22 815104]
"Acer Assist Launcher"="c:\program files\Acer Assist\launcher.exe" [2006-12-04 1261568]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2006-11-17 453120]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-02-28 63048]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040]
"MSConfig"="c:\windows\System32\msconfig.exe" [2006-11-02 222208]
"RtHDVCpl"="RtHDVCpl.exe" [2006-11-20 c:\windows\RtHDVCpl.exe]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2006-11-14 528384]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 16:28 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd.dll,c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-07-30 09:47 289064 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
–a—— 2006-11-15 01:02 614400 c:\progra~1\LAUNCH~1\LManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-05-27 09:50 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra—— 2004-11-22 11:18 307200 c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
–a—— 2008-05-09 13:28 1006264 c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
–a—— 2006-11-02 07:36 201728 c:\program files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{927248FD-E49B-4655-A7C9-99CFC38C9A01}"= UDP:c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"{85F06963-6C2E-4DFB-8907-9431AD1D0926}"= TCP:c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"TCP Query User{5C079876-ADE9-4B77-A23C-323DA05615C4}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{515FDA7E-0980-4ACE-8663-4212377BB3B6}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{6BA5A8BE-D5B8-4F2A-A963-C43C8A7F7927}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{99E8DE9C-1170-4F9D-B876-76CDDA2CDF4B}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{BD8D1DB0-68A4-464F-B526-D5B3945A7AB2}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{0CFB5615-C1B2-4D31-BAF5-3C00D6EFF6F3}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{58C40520-AE90-4BE3-ADFF-9EC8300F08C0}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{CEEA3D1C-01F2-411D-92F3-A162593566FB}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{65942541-83C3-4DEE-A888-96CCA158D2CA}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire
"{1AC9233B-69B3-4A16-A4F5-C173DC71D9BC}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{BD618358-3CE5-4C3A-A545-15F5CA51095E}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{4FC4EBF1-914F-45C9-A537-AB0A7A2C9FA7}"= UDP:c:\program files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:Sid Meier's Civilization 4
"{C8DAE858-CDC4-4BEC-B62F-308BF006CD5E}"= TCP:c:\program files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:Sid Meier's Civilization 4
"{7449CD4C-7AB4-46E3-B917-671243E49989}"= UDP:c:\program files\World of Warcraft\BackgroundDownloader.exe:BackgroundDownloader
"{114169F8-6A43-419C-87B6-EAE31ADAE339}"= TCP:c:\program files\World of Warcraft\BackgroundDownloader.exe:BackgroundDownloader
"{295809F8-E08D-44EB-8822-A6526D02A113}"= UDP:c:\program files\Curse\CurseClient.exe:Curse Client
"{2EBAC877-E743-4518-BE9A-29F4BC17503F}"= TCP:c:\program files\Curse\CurseClient.exe:Curse Client
"TCP Query User{3FD31841-B7DC-4B11-A54A-8B0BF9E9A222}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{85618F3B-7A1B-455B-8E1C-005A49641472}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{A185DAD2-AEFC-4A58-8E85-B45916F8626A}c:\\users\\acer customer\\appdata\\local\\temp\\wzse0.tmp\\symnrt.exe"= UDP:c:\users\acer customer\appdata\local\temp\wzse0.tmp\symnrt.exe:symnrt.exe
"UDP Query User{2FBE6A1F-C0F9-4C1D-B408-C28A15B59939}c:\\users\\acer customer\\appdata\\local\\temp\\wzse0.tmp\\symnrt.exe"= TCP:c:\users\acer customer\appdata\local\temp\wzse0.tmp\symnrt.exe:symnrt.exe
"TCP Query User{5AFCC9A3-220E-46CE-B913-5D30B430BBDD}c:\\users\\acer customer\\appdata\\local\\temp\\lmi6f19.tmp\\lmi_rescue.exe"= UDP:c:\users\acer customer\appdata\local\temp\lmi6f19.tmp\lmi_rescue.exe:lmi_rescue.exe
"UDP Query User{F267F759-8FA1-4903-BCDE-6D7AAE8E780F}c:\\users\\acer customer\\appdata\\local\\temp\\lmi6f19.tmp\\lmi_rescue.exe"= TCP:c:\users\acer customer\appdata\local\temp\lmi6f19.tmp\lmi_rescue.exe:lmi_rescue.exe
"TCP Query User{D62A8041-E13C-4C60-80B8-593857D6297B}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{5113DA7E-0313-44AA-AC0E-5C2005DE60BF}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{73325A98-E4F1-4094-87A0-30C7373FC89B}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{2C07C300-97C4-485E-8C96-643A3C32063D}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

R0 AtiPcie;ATI PCI Express (3GIO) Filter;c:\windows\system32\DRIVERS\AtiPcie.sys [2006-10-30 8192]
R2 gearsec;gearsec;c:\windows\system32\gearsec.exe [2003-12-02 53248]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\RaInfo.sys [2008-02-28 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2008-07-24 47640]
R3 atikmdag;atikmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2008-06-03 3695104]
S2 Windows Tribute Service;Windows Tribute Service;c:\windows\system32\kduoa.exe [2008-05-09 69120]
S3 SMSCIRDA;SMSC Infrared Device Driver;c:\windows\system32\DRIVERS\SMSCirda.sys [2006-10-18 31232]
S3 Steam Client Service;Steam Client Service;c:\program files\Common Files\Steam\SteamService.exe [2008-05-09 87288]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dad1fb1b-384e-11dd-b82a-0016d4c86128}]
\shell\AutoRun\command - G:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f171496c-85d0-11dd-b18a-0016d4c86128}]
\shell\AutoRun\command - F:\LaunchU3.exe -a

*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Acer Tour - (no file)
HKLM-Run-SetPanel - (no file)
HKLM-Run-eRecoveryService - (no file)
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe


.
——- Supplementary Scan ——-
.
FireFox -: Profile - c:\users\Acer Customer\AppData\Roaming\Mozilla\Firefox\Profiles\v89xbz84.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - yahoo.com
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\users\Acer Customer\AppData\Roaming\Mozilla\Firefox\Profiles\v89xbz84.default\extensions\[removed]\plugins\npRACtrl.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-03 16:44:34
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\windows\TEMP\TMP0000005B9B32F928F940C364

scan completed successfully
hidden files: 1

**************************************************************************
.
Completion time: 2008-11-03 16:46:45
ComboFix-quarantined-files.txt 2008-11-03 21:46:42

Pre-Run: 14,419,984,384 bytes free
Post-Run: 14,258,819,072 bytes free

238 — E O F — 2008-10-30 07:02:24
Do you recognise this file

C:\core.zip


Please download the OTMoveIt3 by OldTimer or from here.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dad1fb1b-384e-11dd-b82a-0016d4c86128}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f171496c-85d0-11dd-b18a-0016d4c86128}]
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI