This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] [Resolved] Virtumonde lockdown

29 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Good morning

Yes something got past us, please make sure your old combofix is deleted and we will do another:

Download ComboFix to your Desktop.
Get it

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

http://subs.geekstogo.com/ComboFix.exe

**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
Please do not re-connect your machine back to the Internet until Combofix has completely finished.


——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the C:\ComboFix.txt along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Give it atleast 20-30 minutes to finish

good luck mschroe919
ComboFix 08-12-18.03 - zarbuchan 2008-12-19 10:42:15.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2045.1464 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-11-19 to 2008-12-19 )))))))))))))))))))))))))))))))
.

2008-12-17 13:25 . 2008-12-17 13:25 0 –a—— C:\backup.reg
2008-12-14 23:26 . 2008-12-14 23:26 d——– c:\program files\COMODO
2008-12-14 23:26 . 2008-12-15 00:08 d——– c:\documents and settings\All Users\Application Data\comodo
2008-12-14 23:26 . 2008-12-14 23:26 147,192 –a—— c:\windows\system32\guard32.dll
2008-12-14 23:26 . 2008-12-14 23:26 101,776 –a—— c:\windows\system32\drivers\cmdguard.sys
2008-12-14 23:26 . 2008-12-14 23:26 31,504 –a—— c:\windows\system32\drivers\cmdhlp.sys
2008-12-14 23:23 . 2008-12-14 23:25 d——– c:\program files\SpywareGuard
2008-12-14 23:06 . 2008-12-14 23:06 d——– c:\program files\SUPERAntiSpyware
2008-12-14 23:06 . 2008-12-14 23:06 d——– c:\documents and settings\zarbuchan\Application Data\SUPERAntiSpyware.com
2008-12-14 23:06 . 2008-12-14 23:06 d——– c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-14 23:04 . 2008-12-14 23:05 d——– c:\program files\SpywareBlaster
2008-12-14 23:04 . 2008-12-17 13:30 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2008-12-14 21:17 . 2008-12-14 21:17 d——– C:\CombuttFix
2008-12-14 00:56 . 2008-12-14 22:49 d——– c:\documents and settings\All Users\Application Data\avg8
2008-12-13 22:53 . 2008-12-13 22:53 d——– c:\documents and settings\Administrator\Application Data\Malwarebytes
2008-12-13 22:07 . 2008-12-13 23:18 d——– c:\program files\Malwarebytes' Anti-Malwareddd
2008-12-13 22:07 . 2008-12-03 19:59 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-13 22:07 . 2008-12-03 19:59 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-13 20:38 . 2008-12-18 20:02 18,944 –ahs—- c:\windows\system32\Thumbs.db
2008-12-12 10:22 . 2008-12-12 10:22 d——– C:\rsit
2008-12-11 16:34 . 2008-12-11 16:35 d——– c:\program files\iTunes
2008-12-11 16:34 . 2008-12-11 16:34 d——– c:\program files\iPod
2008-12-11 16:34 . 2008-12-11 16:34 d——– c:\program files\Bonjour
2008-12-11 16:34 . 2008-12-11 16:35 d——– c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-11 16:33 . 2008-12-11 16:33 d——– c:\program files\QuickTime
2008-12-10 21:24 . 2007-12-08 14:48 d——– C:\msinst
2008-12-07 22:05 . 2008-12-07 22:35 d——– c:\windows\system32\Adobe
2008-12-07 12:33 . 2008-12-07 12:33 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-07 12:33 . 2008-12-07 12:33 d——– c:\documents and settings\zarbuchan\Application Data\Malwarebytes
2008-12-07 12:33 . 2008-12-07 12:33 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-07 02:00 . 2008-12-07 02:00 d——– c:\program files\ERUNT
2008-12-07 01:55 . 2008-12-07 01:55 d——– c:\program files\Trend Micro
2008-12-07 00:34 . 2008-12-11 18:36 d——– c:\program files\Spybot - Search & Destroy
2008-12-07 00:34 . 2008-12-11 18:36 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-07 00:06 . 2004-08-10 04:00 169,984 –a—— c:\windows\system32\dllcache\iisui.dll
2008-12-07 00:06 . 2004-08-10 04:00 94,720 –a—— c:\windows\system32\dllcache\certmap.ocx
2008-12-07 00:06 . 2001-08-17 14:56 66,048 –a—— c:\windows\system32\dllcache\s3legacy.dll
2008-12-07 00:06 . 2004-08-10 04:00 19,968 –a—— c:\windows\system32\dllcache\inetsloc.dll
2008-12-07 00:06 . 2004-08-10 04:00 14,336 –a—— c:\windows\system32\dllcache\iisreset.exe
2008-12-07 00:06 . 2004-08-10 04:00 7,680 –a—— c:\windows\system32\dllcache\inetmgr.exe
2008-12-07 00:06 . 2004-08-10 04:00 7,168 –a—— c:\windows\system32\dllcache\wamregps.dll
2008-12-07 00:06 . 2004-08-10 04:00 6,144 –a—— c:\windows\system32\dllcache\ftpsapi2.dll
2008-12-07 00:06 . 2004-08-10 04:00 5,632 –a—— c:\windows\system32\dllcache\iisrstap.dll
2008-12-06 22:58 . 2008-12-06 22:58 d——– c:\program files\Alwil Software
2008-12-06 20:32 . 2008-12-06 20:32 d——– c:\program files\Lavasoft
2008-12-06 20:32 . 2008-12-11 18:51 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-29 00:57 . 2008-11-29 00:57 d——– c:\windows\system32\AGEIA
2008-11-29 00:56 . 2008-11-29 00:56 d——– c:\windows\nview
2008-11-29 00:56 . 2008-11-13 16:20 203,540 –a—— c:\windows\system32\nvapps.nvb
2008-11-29 00:55 . 2008-11-12 13:45 453,152 –a—— c:\windows\system32\NVUNINST.EXE
2008-11-29 00:51 . 2008-11-12 14:54 453,152 –a—— c:\windows\system32\nvudisp.exe
2008-11-29 00:51 . 2008-12-19 10:45 194,311 –a—— c:\windows\system32\nvapps.xml
2008-11-29 00:51 . 2008-11-12 14:54 18,537 –a—— c:\windows\system32\nvdisp.nvu
2008-11-29 00:49 . 2008-11-29 00:49 664 –a—— c:\windows\system32\d3d9caps.dat
2008-11-28 17:41 . 2008-11-28 17:45 d——– c:\windows\NV54325456.TMP
2008-11-28 17:04 . 2008-11-29 00:57 d——– c:\program files\AGEIA Technologies
2008-11-21 11:29 . 2008-11-21 11:29 d——– c:\program files\Chromium

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-19 16:39 ——— d—–w c:\program files\mIRC
2008-12-19 05:53 ——— d—–w c:\documents and settings\zarbuchan\Application Data\Skype
2008-12-19 01:02 ——— d—–w c:\documents and settings\zarbuchan\Application Data\skypePM
2008-12-16 21:14 ——— d—–w c:\program files\World of Warcraft
2008-12-15 17:59 ——— d—–w c:\program files\City of Heroes
2008-12-15 05:06 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-12-11 22:34 ——— d—–w c:\program files\Common Files\Apple
2008-12-07 07:12 ——— d—–w c:\documents and settings\All Users\Application Data\McAfee
2008-12-07 06:03 ——— d—–w c:\documents and settings\LocalService\Application Data\SACore
2008-12-05 05:57 36,928 —-a-w c:\windows\system32\drivers\pssdk41.sys
2008-11-23 23:22 ——— d—–w c:\program files\XLink Kai
2008-11-15 04:47 ——— d–h–w c:\program files\InstallShield Installation Information
2008-11-13 06:28 ——— d—–w c:\program files\AIM
2008-11-12 20:54 6,188,320 —-a-w c:\windows\system32\drivers\nv4_mini.sys
2008-11-12 01:32 ——— d—–w c:\program files\Activision
2008-11-11 21:40 ——— d—–w c:\documents and settings\zarbuchan\Application Data\uTorrent
2008-11-11 17:48 ——— d—–w c:\program files\FLV Player
2008-11-07 22:36 ——— d—–w c:\documents and settings\All Users\Application Data\WinZip
2008-11-07 17:05 ——— d—–w c:\program files\Common Files\Blizzard Entertainment
2008-10-31 02:28 22,328 —-a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-10-31 02:28 22,328 —-a-w c:\documents and settings\zarbuchan\Application Data\PnkBstrK.sys
2008-10-24 11:21 455,296 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-22 14:25 ——— d—–w c:\program files\Apple Software Update
2004-03-15 22:51 114,688 —-a-w c:\program files\internet explorer\plugins\LV71ActiveXControl.dll
2006-01-23 15:32 131,072 —-a-w c:\program files\internet explorer\plugins\LV80ActiveXControl.dll
2007-02-08 15:48 133,920 —-a-w c:\program files\internet explorer\plugins\LV82ActiveXControl.dll
2007-07-24 23:03 118,784 —-a-w c:\program files\internet explorer\plugins\LV85ActiveXControl.dll
2008-06-26 03:51 118,784 —-a-w c:\program files\internet explorer\plugins\LV86ActiveXControl.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-12-04 1809648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2006-07-13 122880]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-12 13672448]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2008-12-14 1797880]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]

c:\documents and settings\zarbuchan\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-08-29 360448]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-03 14:56 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\National Instruments\\Shared\\mDNS Responder\\nimdnsResponder.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 nipbcfk;National Instruments Class Upper Filter Driver;c:\windows\system32\drivers\nipbcfk.sys [2007-07-10 15448]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-14 111184]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2008-12-14 101776]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2008-12-14 31504]
R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-12-04 8944]
R1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-12-04 55024]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-14 20560]
R2 ni488enumsvc;NI-488.2 Enumeration Service;c:\windows\system32\nipalsm.exe [2007-02-16 12696]
R2 nidevldu;NI Device Loader;c:\windows\system32\nipalsm.exe [2007-02-16 12696]
R2 niLXIDiscovery;National Instruments LXI Discovery Service;"c:\program files\IVI Foundation\VISA\WinNT\NIvisa\niLxiDiscovery.exe" [2008-06-20 129144]
R2 nimDNSResponder;National Instruments mDNS Responder Service;"c:\program files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe" [2008-06-18 192112]
R2 nipxirmk;nipxirmk;\??\c:\windows\system32\drivers\nipxirmkl.sys [2007-09-18 11552]
R2 NiViPxiK;NI-VISA PXI Driver;c:\windows\system32\drivers\NiViPxiKl.sys [2008-06-20 11360]
R3 nidimk;nidimk;\??\c:\windows\system32\drivers\nidimkl.sys [2008-06-13 11360]
R3 nimru2k;nimru2k;\??\c:\windows\system32\drivers\nimru2kl.sys [2008-06-13 11360]
R3 nimstsk;nimstsk;\??\c:\windows\system32\drivers\nimstskl.sys [2007-12-18 11360]
R3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-04 7408]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys []
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe []
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe []
S2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys []
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;"c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe" [2008-08-31 79360]
S3 lvalarmk;lvalarmk;\??\c:\windows\system32\drivers\lvalarmk.sys [2007-12-20 20056]
S3 ni1006k;NI PXI-1006 Chassis Pilot;\??\c:\windows\system32\drivers\ni1006k.sys [2007-10-08 25888]
S3 ni1045k;NI PXI-1045 Chassis Pilot;\??\c:\windows\system32\drivers\ni1045kl.sys [2007-10-08 11552]
S3 ni1065k;NI PXIe-1065 Chassis Pilot;\??\c:\windows\system32\drivers\ni1065k.sys [2007-10-08 22360]
S3 ni488lock;NI-488.2 Locking Service;\??\c:\windows\system32\drivers\ni488lock.sys [2007-02-26 16672]
S3 nicdrk;nicdrk;\??\c:\windows\system32\drivers\nicdrkl.sys [2007-12-26 11352]
S3 nicsrk;nicsrk;\??\c:\windows\system32\drivers\nicsrkl.sys [2008-02-22 11336]
S3 nidmxfk;nidmxfk;\??\c:\windows\system32\drivers\nidmxfkl.sys [2007-12-18 11336]
S3 nidsark;nidsark;\??\c:\windows\system32\drivers\nidsarkl.sys [2008-02-29 11344]
S3 niemrk;niemrk;\??\c:\windows\system32\drivers\niemrkl.sys [2008-02-22 11336]
S3 niesrk;niesrk;\??\c:\windows\system32\drivers\niesrkl.sys [2008-02-22 11336]
S3 nifslk;nifslk;\??\c:\windows\system32\drivers\nifslkl.sys [2007-12-26 11352]
S3 nimsdrk;nimsdrk;\??\c:\windows\system32\drivers\nimsdrkl.sys [2008-01-11 11392]
S3 nimslk;nimslk;\??\c:\windows\system32\drivers\nimslk.dll [2007-06-24 14464]
S3 nimsrlk;nimsrlk;\??\c:\windows\system32\drivers\nimsrlk.dll [2007-06-24 151683]
S3 nimxpk;nimxpk;\??\c:\windows\system32\drivers\nimxpkl.sys [2007-12-18 11368]
S3 ninshsdk;ninshsdk;\??\c:\windows\system32\drivers\ninshsdkl.sys [2007-12-27 11360]
S3 nipalfwedl;nipalfwedl;c:\windows\system32\drivers\nipalfwedl.sys [2008-06-13 11904]
S3 nipalusbedl;nipalusbedl;c:\windows\system32\drivers\nipalusbedl.sys [2008-06-13 11896]
S3 nipxigpk;NI PXI Generic Chassis Pilot;\??\c:\windows\system32\drivers\nipxigpk.sys [2007-11-26 20768]
S3 niscdk;niscdk;\??\c:\windows\system32\drivers\niscdkl.sys [2008-01-07 11376]
S3 nisdigk;nisdigk;\??\c:\windows\system32\drivers\nisdigkl.sys [2008-01-07 11352]
S3 nisftk;nisftk;\??\c:\windows\system32\drivers\nisftkl.sys [2007-12-20 11344]
S3 nispdk;nispdk;\??\c:\windows\system32\drivers\nispdkl.sys [2008-01-07 11376]
S3 nissrk;nissrk;\??\c:\windows\system32\drivers\nissrkl.sys [2008-02-22 11336]
S3 nistc2k;nistc2k;\??\c:\windows\system32\drivers\nistc2kl.sys [2008-01-07 11312]
S3 nistcrk;nistcrk;\??\c:\windows\system32\drivers\nistcrkl.sys [2008-02-14 11360]
S3 niswdk;niswdk;\??\c:\windows\system32\drivers\niswdkl.sys [2008-01-02 11336]
S3 nitiork;nitiork;\??\c:\windows\system32\drivers\nitiorkl.sys [2008-02-19 11360]
S3 niufurk;niufurk;\??\c:\windows\system32\drivers\niufurkl.sys [2008-02-22 11368]
S3 NiViFWK;NI-VISA FireWire Driver;c:\windows\system32\drivers\NiViFWKl.sys [2008-06-20 11384]
S3 NiViPciK;NI-VISA PCI Driver;c:\windows\system32\drivers\NiViPciKl.sys [2008-06-20 11360]
S3 niwfrk;niwfrk;\??\c:\windows\system32\drivers\niwfrkl.sys [2008-02-22 11336]
S3 nixsrk;nixsrk;\??\c:\windows\system32\drivers\nixsrkl.sys [2008-02-22 11336]
S3 PsSdk41;PsSdk41;\??\c:\windows\system32\Drivers\pssdk41.sys [2008-09-11 36928]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys []
S3 usb6xxxk;usb6xxxk;\??\c:\windows\system32\drivers\usb6xxxkl.sys []
S3 ZD1211BU(SMC);802.11g Wireless USB2.0 Adapter Driver(SMC);c:\windows\system32\DRIVERS\zd1211Bu.sys [2006-08-24 477696]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - d:\setup\rsrc\Autorun.exe
\Shell\dinstall\command - d:\directx\dxsetup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder

2008-12-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.dell.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: {6637E906-5A9B-4FFF-900E-1254039BBAB8} = 68.113.206.10,66.196.221.10
FF - ProfilePath - c:\documents and settings\zarbuchan\Application Data\Mozilla\Firefox\Profiles\dpyo2cei.default\
FF - prefs.js: browser.search.selectedEngine - Wowhead
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV80Win32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV82Win32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nplv85win32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nplv86win32.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-19 10:45:24
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(748)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
———————— Other Running Processes ————————
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Creative\Shared Files\CTAudSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\windows\system32\lkcitdl.exe
c:\windows\system32\lkads.exe
c:\windows\system32\lktsrv.exe
c:\windows\system32\CTxfispi.exe
c:\program files\National Instruments\MAX\nimxs.exe
c:\program files\SpywareGuard\sgbhp.exe
c:\program files\National Instruments\Shared\Security\nidmsrv.exe
c:\windows\system32\nisvcloc.exe
c:\program files\National Instruments\Shared\Tagger\tagsrv.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-12-19 10:48:45 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-19 16:48:42
ComboFix2.txt 2008-12-14 22:08:33

Pre-Run: 126,864,474,112 bytes free
Post-Run: 126,812,717,056 bytes free

275 — E O F — 2008-12-19 01:57:24

















Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:49:15 AM, on 12/19/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\lkcitdl.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\WINDOWS\system32\lkads.exe
C:\WINDOWS\system32\lktsrv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\National Instruments\MAX\nimxs.exe
C:\WINDOWS\system32\nipalsm.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS\system32\nisvcloc.exe
C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe
C:\WINDOWS\system32\nipalsm.exe
C:\Program Files\IVI Foundation\VISA\WinNT\NIvisa\niLxiDiscovery.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=4071012
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\national instruments\shared\mdns responder\nimdnsnsp.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1214061259171
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6637E906-5A9B-4FFF-900E-1254039BBAB8}: NameServer = 68.113.206.10,66.196.221.10
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Unknown owner - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgemc.exe (file missing)
O23 - Service: AVG Free8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\WINDOWS\system32\lkcitdl.exe
O23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments Corporation - C:\WINDOWS\system32\lkads.exe
O23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments Corporation - C:\WINDOWS\system32\lktsrv.exe
O23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - C:\Program Files\National Instruments\MAX\nimxs.exe
O23 - Service: NI-488.2 Enumeration Service (ni488enumsvc) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exe
O23 - Service: NI Device Loader (nidevldu) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exe
O23 - Service: National Instruments Domain Service (NIDomainService) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
O23 - Service: NILM License Manager - Macrovision Corporation - C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe
O23 - Service: National Instruments LXI Discovery Service (niLXIDiscovery) - National Instruments Corporation - C:\Program Files\IVI Foundation\VISA\WinNT\NIvisa\niLxiDiscovery.exe
O23 - Service: National Instruments mDNS Responder Service (nimDNSResponder) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe
O23 - Service: NI PXI Resource Manager (nipxirmu) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exe
O23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corporation - C:\WINDOWS\system32\nisvcloc.exe
O23 - Service: National Instruments Variable Engine (NITaggerService) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

–
End of file - 9847 bytes
Hi

NEXT:
1. Please open Notepad
Click Start , then Run
Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
C:\CombuttFix
 c:\windows\NV54325456.TMP

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.
[external image: Posted Image]
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Next, re-enable all the programs that you disabled prior to running ComboFix.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

NEXT:
after reboot do this one please:

Using Internet Explorer, please do a Kaspersky online scan] This scan takes about 60 minutes to complete.

Answer Yes, when prompted to install an ActiveX component.
The program will then begin downloading the latest definition files.
Once the files have been downloaded click on NEXT
Locate the Scan Settings button & configure as follows:
Scan using the following Anti-Virus database:
Extended
Scan Options:
Scan Archives
Scan Mail Bases
Click OK & have it scan My Computer
Once the scan is complete, it will provide a report if your system is infected. It does not provide an option to clean/disinfect. We only require a report from it.

[external image: Posted Image]

Click the Save as Text button to save the file to your desktop and post it in your next reply along with a fresh HijackThis logand the CF log

* Turn off the real time scanner of any existing antivirus program while performing the online scan
Apologies, I have been a little busy lately due to the holidays, and yesterday while performing the steps I accidentally cancelled during the Kapersky scan, which was taking over an hour and a half. I am going to run the scanner again today and then I should have my logs ready to present.
Thats okay I know about the being tied up cause of the holidays. I would be done if I didn't have the Grankids. Anyway take your time I just didn't know if you quit or not. I will be here today and Tue, but for 24, 25, I will be checking late in the evening. mschroe919
Alright…

CF Log:

ComboFix 08-12-21.01 - zarbuchan 2008-12-21 13:23:11.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2045.1519 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\zarbuchan\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\CombuttFix
c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
c:\windows\NV54325456.TMP
.
/wow section - STAGE 32A
The process cannot access the file because it is being used by another process.


((((((((((((((((((((((((( Files Created from 2008-11-21 to 2008-12-21 )))))))))))))))))))))))))))))))
.

2008-12-17 13:25 . 2008-12-17 13:25 0 –a—— C:\backup.reg
2008-12-14 23:26 . 2008-12-14 23:26 d——– c:\program files\COMODO
2008-12-14 23:26 . 2008-12-15 00:08 d——– c:\documents and settings\All Users\Application Data\comodo
2008-12-14 23:26 . 2008-12-14 23:26 147,192 –a—— c:\windows\system32\guard32.dll
2008-12-14 23:26 . 2008-12-14 23:26 101,776 –a—— c:\windows\system32\drivers\cmdguard.sys
2008-12-14 23:26 . 2008-12-14 23:26 31,504 –a—— c:\windows\system32\drivers\cmdhlp.sys
2008-12-14 23:23 . 2008-12-14 23:25 d——– c:\program files\SpywareGuard
2008-12-14 23:06 . 2008-12-14 23:06 d——– c:\program files\SUPERAntiSpyware
2008-12-14 23:06 . 2008-12-14 23:06 d——– c:\documents and settings\zarbuchan\Application Data\SUPERAntiSpyware.com
2008-12-14 23:06 . 2008-12-14 23:06 d——– c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-14 23:04 . 2008-12-14 23:05 d——– c:\program files\SpywareBlaster
2008-12-14 23:04 . 2008-12-17 13:30 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2008-12-14 00:56 . 2008-12-14 22:49 d——– c:\documents and settings\All Users\Application Data\avg8
2008-12-13 22:53 . 2008-12-13 22:53 d——– c:\documents and settings\Administrator\Application Data\Malwarebytes
2008-12-13 22:07 . 2008-12-13 23:18 d——– c:\program files\Malwarebytes' Anti-Malwareddd
2008-12-13 22:07 . 2008-12-03 19:59 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-13 22:07 . 2008-12-03 19:59 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-13 20:38 . 2008-12-18 20:02 18,944 –ahs—- c:\windows\system32\Thumbs.db
2008-12-12 10:22 . 2008-12-12 10:22 d——– C:\rsit
2008-12-11 16:34 . 2008-12-11 16:35 d——– c:\program files\iTunes
2008-12-11 16:34 . 2008-12-11 16:34 d——– c:\program files\iPod
2008-12-11 16:34 . 2008-12-11 16:34 d——– c:\program files\Bonjour
2008-12-11 16:34 . 2008-12-11 16:35 d——– c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-11 16:33 . 2008-12-11 16:33 d——– c:\program files\QuickTime
2008-12-10 21:24 . 2007-12-08 14:48 d——– C:\msinst
2008-12-07 22:05 . 2008-12-07 22:35 d——– c:\windows\system32\Adobe
2008-12-07 12:33 . 2008-12-07 12:33 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-07 12:33 . 2008-12-07 12:33 d——– c:\documents and settings\zarbuchan\Application Data\Malwarebytes
2008-12-07 12:33 . 2008-12-07 12:33 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-07 02:00 . 2008-12-07 02:00 d——– c:\program files\ERUNT
2008-12-07 01:55 . 2008-12-07 01:55 d——– c:\program files\Trend Micro
2008-12-07 00:34 . 2008-12-11 18:36 d——– c:\program files\Spybot - Search & Destroy
2008-12-07 00:34 . 2008-12-11 18:36 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-07 00:06 . 2004-08-10 04:00 169,984 –a—— c:\windows\system32\dllcache\iisui.dll
2008-12-07 00:06 . 2004-08-10 04:00 94,720 –a—— c:\windows\system32\dllcache\certmap.ocx
2008-12-07 00:06 . 2001-08-17 14:56 66,048 –a—— c:\windows\system32\dllcache\s3legacy.dll
2008-12-07 00:06 . 2004-08-10 04:00 19,968 –a—— c:\windows\system32\dllcache\inetsloc.dll
2008-12-07 00:06 . 2004-08-10 04:00 14,336 –a—— c:\windows\system32\dllcache\iisreset.exe
2008-12-07 00:06 . 2004-08-10 04:00 7,680 –a—— c:\windows\system32\dllcache\inetmgr.exe
2008-12-07 00:06 . 2004-08-10 04:00 7,168 –a—— c:\windows\system32\dllcache\wamregps.dll
2008-12-07 00:06 . 2004-08-10 04:00 6,144 –a—— c:\windows\system32\dllcache\ftpsapi2.dll
2008-12-07 00:06 . 2004-08-10 04:00 5,632 –a—— c:\windows\system32\dllcache\iisrstap.dll
2008-12-06 22:58 . 2008-12-06 22:58 d——– c:\program files\Alwil Software
2008-12-06 20:32 . 2008-12-06 20:32 d——– c:\program files\Lavasoft
2008-12-06 20:32 . 2008-12-11 18:51 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-29 00:57 . 2008-11-29 00:57 d——– c:\windows\system32\AGEIA
2008-11-29 00:56 . 2008-11-29 00:56 d——– c:\windows\nview
2008-11-29 00:56 . 2008-11-13 16:20 203,540 –a—— c:\windows\system32\nvapps.nvb
2008-11-29 00:55 . 2008-11-12 13:45 453,152 –a—— c:\windows\system32\NVUNINST.EXE
2008-11-29 00:51 . 2008-11-12 14:54 453,152 –a—— c:\windows\system32\nvudisp.exe
2008-11-29 00:51 . 2008-12-21 13:26 194,311 –a—— c:\windows\system32\nvapps.xml
2008-11-29 00:51 . 2008-11-12 14:54 18,537 –a—— c:\windows\system32\nvdisp.nvu
2008-11-29 00:49 . 2008-11-29 00:49 664 –a—— c:\windows\system32\d3d9caps.dat
2008-11-28 17:41 . 2008-11-28 17:45 d——– c:\windows\NV54325456.TMP
2008-11-28 17:04 . 2008-11-29 00:57 d——– c:\program files\AGEIA Technologies
2008-11-21 11:29 . 2008-11-21 11:29 d——– c:\program files\Chromium

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-21 19:19 ——— d—–w c:\program files\mIRC
2008-12-21 19:19 ——— d—–w c:\documents and settings\zarbuchan\Application Data\Skype
2008-12-21 19:14 ——— d—–w c:\documents and settings\zarbuchan\Application Data\skypePM
2008-12-16 21:14 ——— d—–w c:\program files\World of Warcraft
2008-12-15 17:59 ——— d—–w c:\program files\City of Heroes
2008-12-15 05:06 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2008-12-11 22:34 ——— d—–w c:\program files\Common Files\Apple
2008-12-07 07:12 ——— d—–w c:\documents and settings\All Users\Application Data\McAfee
2008-12-07 06:03 ——— d—–w c:\documents and settings\LocalService\Application Data\SACore
2008-12-05 05:57 36,928 —-a-w c:\windows\system32\drivers\pssdk41.sys
2008-11-23 23:22 ——— d—–w c:\program files\XLink Kai
2008-11-15 04:47 ——— d–h–w c:\program files\InstallShield Installation Information
2008-11-13 06:28 ——— d—–w c:\program files\AIM
2008-11-12 20:54 6,188,320 —-a-w c:\windows\system32\drivers\nv4_mini.sys
2008-11-12 01:32 ——— d—–w c:\program files\Activision
2008-11-11 21:40 ——— d—–w c:\documents and settings\zarbuchan\Application Data\uTorrent
2008-11-11 17:48 ——— d—–w c:\program files\FLV Player
2008-11-07 22:36 ——— d—–w c:\documents and settings\All Users\Application Data\WinZip
2008-11-07 17:05 ——— d—–w c:\program files\Common Files\Blizzard Entertainment
2008-10-31 02:28 22,328 —-a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-10-31 02:28 22,328 —-a-w c:\documents and settings\zarbuchan\Application Data\PnkBstrK.sys
2008-10-24 11:21 455,296 —-a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-22 14:25 ——— d—–w c:\program files\Apple Software Update
2004-03-15 22:51 114,688 —-a-w c:\program files\internet explorer\plugins\LV71ActiveXControl.dll
2006-01-23 15:32 131,072 —-a-w c:\program files\internet explorer\plugins\LV80ActiveXControl.dll
2007-02-08 15:48 133,920 —-a-w c:\program files\internet explorer\plugins\LV82ActiveXControl.dll
2007-07-24 23:03 118,784 —-a-w c:\program files\internet explorer\plugins\LV85ActiveXControl.dll
2008-06-26 03:51 118,784 —-a-w c:\program files\internet explorer\plugins\LV86ActiveXControl.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-12-04 1809648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2006-07-13 122880]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-12 13672448]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2008-12-14 1797880]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]

c:\documents and settings\zarbuchan\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-08-29 360448]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-03 14:56 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\National Instruments\\Shared\\mDNS Responder\\nimdnsResponder.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 nipbcfk;National Instruments Class Upper Filter Driver;c:\windows\system32\drivers\nipbcfk.sys [2007-07-10 15448]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-14 111184]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2008-12-14 101776]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2008-12-14 31504]
R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-12-04 8944]
R1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-12-04 55024]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-14 20560]
R2 ni488enumsvc;NI-488.2 Enumeration Service;c:\windows\system32\nipalsm.exe [2007-02-16 12696]
R2 nidevldu;NI Device Loader;c:\windows\system32\nipalsm.exe [2007-02-16 12696]
R2 niLXIDiscovery;National Instruments LXI Discovery Service;"c:\program files\IVI Foundation\VISA\WinNT\NIvisa\niLxiDiscovery.exe" [2008-06-20 129144]
R2 nimDNSResponder;National Instruments mDNS Responder Service;"c:\program files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe" [2008-06-18 192112]
R2 nipxirmk;nipxirmk;\??\c:\windows\system32\drivers\nipxirmkl.sys [2007-09-18 11552]
R2 NiViPxiK;NI-VISA PXI Driver;c:\windows\system32\drivers\NiViPxiKl.sys [2008-06-20 11360]
R3 nidimk;nidimk;\??\c:\windows\system32\drivers\nidimkl.sys [2008-06-13 11360]
R3 nimru2k;nimru2k;\??\c:\windows\system32\drivers\nimru2kl.sys [2008-06-13 11360]
R3 nimstsk;nimstsk;\??\c:\windows\system32\drivers\nimstskl.sys [2007-12-18 11360]
R3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-12-04 7408]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys []
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe []
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe []
S2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys []
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;"c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe" [2008-08-31 79360]
S3 lvalarmk;lvalarmk;\??\c:\windows\system32\drivers\lvalarmk.sys [2007-12-20 20056]
S3 ni1006k;NI PXI-1006 Chassis Pilot;\??\c:\windows\system32\drivers\ni1006k.sys [2007-10-08 25888]
S3 ni1045k;NI PXI-1045 Chassis Pilot;\??\c:\windows\system32\drivers\ni1045kl.sys [2007-10-08 11552]
S3 ni1065k;NI PXIe-1065 Chassis Pilot;\??\c:\windows\system32\drivers\ni1065k.sys [2007-10-08 22360]
S3 ni488lock;NI-488.2 Locking Service;\??\c:\windows\system32\drivers\ni488lock.sys [2007-02-26 16672]
S3 nicdrk;nicdrk;\??\c:\windows\system32\drivers\nicdrkl.sys [2007-12-26 11352]
S3 nicsrk;nicsrk;\??\c:\windows\system32\drivers\nicsrkl.sys [2008-02-22 11336]
S3 nidmxfk;nidmxfk;\??\c:\windows\system32\drivers\nidmxfkl.sys [2007-12-18 11336]
S3 nidsark;nidsark;\??\c:\windows\system32\drivers\nidsarkl.sys [2008-02-29 11344]
S3 niemrk;niemrk;\??\c:\windows\system32\drivers\niemrkl.sys [2008-02-22 11336]
S3 niesrk;niesrk;\??\c:\windows\system32\drivers\niesrkl.sys [2008-02-22 11336]
S3 nifslk;nifslk;\??\c:\windows\system32\drivers\nifslkl.sys [2007-12-26 11352]
S3 nimsdrk;nimsdrk;\??\c:\windows\system32\drivers\nimsdrkl.sys [2008-01-11 11392]
S3 nimslk;nimslk;\??\c:\windows\system32\drivers\nimslk.dll [2007-06-24 14464]
S3 nimsrlk;nimsrlk;\??\c:\windows\system32\drivers\nimsrlk.dll [2007-06-24 151683]
S3 nimxpk;nimxpk;\??\c:\windows\system32\drivers\nimxpkl.sys [2007-12-18 11368]
S3 ninshsdk;ninshsdk;\??\c:\windows\system32\drivers\ninshsdkl.sys [2007-12-27 11360]
S3 nipalfwedl;nipalfwedl;c:\windows\system32\drivers\nipalfwedl.sys [2008-06-13 11904]
S3 nipalusbedl;nipalusbedl;c:\windows\system32\drivers\nipalusbedl.sys [2008-06-13 11896]
S3 nipxigpk;NI PXI Generic Chassis Pilot;\??\c:\windows\system32\drivers\nipxigpk.sys [2007-11-26 20768]
S3 niscdk;niscdk;\??\c:\windows\system32\drivers\niscdkl.sys [2008-01-07 11376]
S3 nisdigk;nisdigk;\??\c:\windows\system32\drivers\nisdigkl.sys [2008-01-07 11352]
S3 nisftk;nisftk;\??\c:\windows\system32\drivers\nisftkl.sys [2007-12-20 11344]
S3 nispdk;nispdk;\??\c:\windows\system32\drivers\nispdkl.sys [2008-01-07 11376]
S3 nissrk;nissrk;\??\c:\windows\system32\drivers\nissrkl.sys [2008-02-22 11336]
S3 nistc2k;nistc2k;\??\c:\windows\system32\drivers\nistc2kl.sys [2008-01-07 11312]
S3 nistcrk;nistcrk;\??\c:\windows\system32\drivers\nistcrkl.sys [2008-02-14 11360]
S3 niswdk;niswdk;\??\c:\windows\system32\drivers\niswdkl.sys [2008-01-02 11336]
S3 nitiork;nitiork;\??\c:\windows\system32\drivers\nitiorkl.sys [2008-02-19 11360]
S3 niufurk;niufurk;\??\c:\windows\system32\drivers\niufurkl.sys [2008-02-22 11368]
S3 NiViFWK;NI-VISA FireWire Driver;c:\windows\system32\drivers\NiViFWKl.sys [2008-06-20 11384]
S3 NiViPciK;NI-VISA PCI Driver;c:\windows\system32\drivers\NiViPciKl.sys [2008-06-20 11360]
S3 niwfrk;niwfrk;\??\c:\windows\system32\drivers\niwfrkl.sys [2008-02-22 11336]
S3 nixsrk;nixsrk;\??\c:\windows\system32\drivers\nixsrkl.sys [2008-02-22 11336]
S3 PsSdk41;PsSdk41;\??\c:\windows\system32\Drivers\pssdk41.sys [2008-09-11 36928]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys []
S3 usb6xxxk;usb6xxxk;\??\c:\windows\system32\drivers\usb6xxxkl.sys []
S3 ZD1211BU(SMC);802.11g Wireless USB2.0 Adapter Driver(SMC);c:\windows\system32\DRIVERS\zd1211Bu.sys [2006-08-24 477696]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - d:\setup\rsrc\Autorun.exe
\Shell\dinstall\command - d:\directx\dxsetup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder

2008-12-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.dell.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: {6637E906-5A9B-4FFF-900E-1254039BBAB8} = 68.113.206.10,66.196.221.10
FF - ProfilePath - c:\documents and settings\zarbuchan\Application Data\Mozilla\Firefox\Profiles\dpyo2cei.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV80Win32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV82Win32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nplv85win32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nplv86win32.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-21 13:26:23
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(748)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
———————— Other Running Processes ————————
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Creative\Shared Files\CTAudSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\COMODO\COMODO Internet Security\cmdagent.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\windows\system32\lkcitdl.exe
c:\windows\system32\lkads.exe
c:\windows\system32\lktsrv.exe
c:\windows\system32\CTxfispi.exe
c:\program files\National Instruments\MAX\nimxs.exe
c:\program files\National Instruments\Shared\Security\nidmsrv.exe
c:\windows\system32\nisvcloc.exe
c:\program files\National Instruments\Shared\Tagger\tagsrv.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-12-21 13:29:32 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-21 19:29:29
ComboFix2.txt 2008-12-19 16:48:46

Pre-Run: 122,663,297,024 bytes free
Post-Run: 122,642,333,696 bytes free

278 — E O F — 2008-12-19 01:57:24










Kaspersky log:

——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Monday, December 22, 2008
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, December 22, 2008 14:17:26
Records in database: 1500464
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Files scanned: 99730
Threat name: 2
Infected objects: 3
Suspicious objects: 0
Duration of the scan: 01:55:28


File name / Threat name / Threats count
C:\Program Files\mIRC\mirc.exe/C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.617 1
C:\Documents and Settings\zarbuchan\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-5286af48-2e92c776.zip Infected: Exploit.Java.Gimsh.a 1
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.617 1

The selected area was scanned.













HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:04:31 PM, on 12/22/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\lkcitdl.exe
C:\WINDOWS\system32\lkads.exe
C:\WINDOWS\system32\lktsrv.exe
C:\Program Files\National Instruments\MAX\nimxs.exe
C:\WINDOWS\system32\nipalsm.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS\system32\nisvcloc.exe
C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe
C:\WINDOWS\system32\nipalsm.exe
C:\Program Files\IVI Foundation\VISA\WinNT\NIvisa\niLxiDiscovery.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=4071012
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\national instruments\shared\mdns responder\nimdnsnsp.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1214061259171
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6637E906-5A9B-4FFF-900E-1254039BBAB8}: NameServer = 68.113.206.10,66.196.221.10
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Unknown owner - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgemc.exe (file missing)
O23 - Service: AVG Free8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\WINDOWS\system32\lkcitdl.exe
O23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments Corporation - C:\WINDOWS\system32\lkads.exe
O23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments Corporation - C:\WINDOWS\system32\lktsrv.exe
O23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - C:\Program Files\National Instruments\MAX\nimxs.exe
O23 - Service: NI-488.2 Enumeration Service (ni488enumsvc) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exe
O23 - Service: NI Device Loader (nidevldu) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exe
O23 - Service: National Instruments Domain Service (NIDomainService) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
O23 - Service: NILM License Manager - Macrovision Corporation - C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe
O23 - Service: National Instruments LXI Discovery Service (niLXIDiscovery) - National Instruments Corporation - C:\Program Files\IVI Foundation\VISA\WinNT\NIvisa\niLxiDiscovery.exe
O23 - Service: National Instruments mDNS Responder Service (nimDNSResponder) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe
O23 - Service: NI PXI Resource Manager (nipxirmu) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exe
O23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corporation - C:\WINDOWS\system32\nisvcloc.exe
O23 - Service: National Instruments Variable Engine (NITaggerService) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

–
End of file - 10133 bytes
Hi

  • Please download The Avenger2 by SwanDog46.
  • Unzip avenger.exe to your desktop.
  • Copy all the text contained in the quote box below to your Clipboard by highlighting it and pressing (Ctrl+C):

    Files to delete:
    C:\Program Files\mIRC\mirc.exe/C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.617 1
    C:\Documents and Settings\zarbuchan\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-5286af48-2e92c776.zip Infected: Exploit.Java.Gimsh.a 1
    C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.617 1

    Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
  • Now start The Avenger2 by double clicking avenger.exe on your desktop.
  • Read the prompt that appears, and press OK.
  • Paste the script into the textbox that appears, using (Control + V) or by right clicking and choosing "Paste".
  • Press the Execute button.
  • You will be presented with 2 confirmation prompts. Select yes on each. Your system will reboot.
    Note: It is possible that Avenger will reboot your system TWICE.
  • Upon reboot, a command prompt window will appear on your screen for a few seconds, and then Avenger's log will open. Please paste that log here.


good luck mschroe919
It seems awfully hard to read. Is it really necessary for it to put extra spaces between everything?

L o g f i l e o f T h e A v e n g e r V e r s i o n 2 . 0 , ( c ) b y S w a n d o g 4 6

h t t p : / / s w a n d o g 4 6 . g e e k s t o g o . c o m



P l a t f o r m : W i n d o w s X P



* * * * * * * * * * * * * * * * * * *



S c r i p t f i l e o p e n e d s u c c e s s f u l l y .

S c r i p t f i l e r e a d s u c c e s s f u l l y .



B a c k u p s d i r e c t o r y o p e n e d s u c c e s s f u l l y a t C : \ A v e n g e r



* * * * * * * * * * * * * * * * * * *



B e g i n n i n g t o p r o c e s s s c r i p t f i l e :



R o o t k i t s c a n a c t i v e .

N o r o o t k i t s f o u n d !





E r r o r : c o u l d n o t o p e n f i l e " C : \ P r o g r a m F i l e s \ m I R C \ m i r c . e x e / C : \ P r o g r a m F i l e s \ m I R C \ m i r c . e x e I n f e c t e d : n o t - a - v i r u s : C l i e n t - I R C . W i n 3 2 . m I R C . 6 1 7 1 "

D e l e t i o n o f f i l e " C : \ P r o g r a m F i l e s \ m I R C \ m i r c . e x e / C : \ P r o g r a m F i l e s \ m I R C \ m i r c . e x e I n f e c t e d : n o t - a - v i r u s : C l i e n t - I R C . W i n 3 2 . m I R C . 6 1 7 1 " f a i l e d !

S t a t u s : 0 x c 0 0 0 0 0 3 3 ( S T A T U S _ O B J E C T _ N A M E _ I N V A L I D )

- - > a n o b j e c t c a n n o t h a v e t h i s n a m e





E r r o r : f i l e " C : \ D o c u m e n t s a n d S e t t i n g s \ z a r b u c h a n \ A p p l i c a t i o n D a t a \ S u n \ J a v a \ D e p l o y m e n t \ c a c h e \ j a v a p i \ v 1 . 0 \ j a r \ j v m i m p r o . j a r - 5 2 8 6 a f 4 8 - 2 e 9 2 c 7 7 6 . z i p I n f e c t e d : E x p l o i t . J a v a . G i m s h . a 1 " n o t f o u n d !

D e l e t i o n o f f i l e " C : \ D o c u m e n t s a n d S e t t i n g s \ z a r b u c h a n \ A p p l i c a t i o n D a t a \ S u n \ J a v a \ D e p l o y m e n t \ c a c h e \ j a v a p i \ v 1 . 0 \ j a r \ j v m i m p r o . j a r - 5 2 8 6 a f 4 8 - 2 e 9 2 c 7 7 6 . z i p I n f e c t e d : E x p l o i t . J a v a . G i m s h . a 1 " f a i l e d !

S t a t u s : 0 x c 0 0 0 0 0 3 4 ( S T A T U S _ O B J E C T _ N A M E _ N O T _ F O U N D )

- - > t h e o b j e c t d o e s n o t e x i s t





E r r o r : f i l e " C : \ P r o g r a m F i l e s \ m I R C \ m i r c . e x e I n f e c t e d : n o t - a - v i r u s : C l i e n t - I R C . W i n 3 2 . m I R C . 6 1 7 1 " n o t f o u n d !

D e l e t i o n o f f i l e " C : \ P r o g r a m F i l e s \ m I R C \ m i r c . e x e I n f e c t e d : n o t - a - v i r u s : C l i e n t - I R C . W i n 3 2 . m I R C . 6 1 7 1 " f a i l e d !

S t a t u s : 0 x c 0 0 0 0 0 3 4 ( S T A T U S _ O B J E C T _ N A M E _ N O T _ F O U N D )

- - > t h e o b j e c t d o e s n o t e x i s t





C o m p l e t e d s c r i p t p r o c e s s i n g .



* * * * * * * * * * * * * * * * * * *



F i n i s h e d ! T e r m i n a t e .




If I might make a suggestion, the addresses to some of the results Kaspersky produced seem pretty non-standard–particularly, the mIRC ones:

C:\Program Files\mIRC\mirc.exe/C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.617 1
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.617 1

These appear to be the same thing, but the first entry is a strange address that Windows explorer cannot navigate to. Also, is Avenger designed to function straight off of Kaspersky's logs? (IE, with the "Infected:" bits at the end?)

I experimented a little with this and had avast! scan mIRC.exe. It did not find any results. However, to double check this, I scanned the suspected .zip file in the Java application folder, and avast! did find a virus on it. However, I didn't take any action other than scan it, as you are supervising me.

I guess that's more of an observation than a suggestion, though.
Hi

Yes if avast gets it good, this is the guy we are looking for:

If avast doesn't find or get it go to the following and delete the file in RED

C:\Program Files\mIRC\mirc.exe

also we want this guy

C:\Documents and Settings\zarbuchan\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-5286af48-2e92c776

same thing here:
If avast doesn't find or get it go to the following and delete the file in RED

when avast gets done and you put it in a vault, you can then go to the vault and delete it.

when you get that done

post back and let me know if you found them and got rid of them.
good luck mschroe919

Happy holidays
Didn't get detections on mIRC.exe like before, so I just deleted it. The java file didnt actually go away, but re-scanning it did not pick anything up after I had avast! delete it did not detect the infection again. I can only assume it removed the infection but spared the zip file? Either way, I await further instructions.
Hi ocphox I believe the infections are gone just to make sure let see one more hjt log please, and I am pretty sure you will have graet holidays knowing you clean again. mschroe919
I've taken more careful notice of what happens when my browser gets hijacked, and I notice that the first thing I see on the status bar when I click a link in google after opening a fresh instance of Firefox, the following is displayed:

http://goougly.com/c.php?url=http://(actual website clicked address here)&p=4&rf=http://viaje.nom.es/index.php

It always says goougly.com at the beginning and always viaje.nom.es at the end. Not always do I get redirected, but this shows first in the status bar every time I click any link on Google for a certain amount of time (certain number of clicks?) before it goes away. Restarting the browser continues this issue.

Are there perhaps some tools that are specifically for solving browser hijacks?

Anyway, HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:48:36 PM, on 12/23/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\lkcitdl.exe
C:\WINDOWS\system32\lkads.exe
C:\WINDOWS\system32\lktsrv.exe
C:\Program Files\National Instruments\MAX\nimxs.exe
C:\WINDOWS\system32\nipalsm.exe
C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
C:\WINDOWS\system32\nisvcloc.exe
C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe
C:\WINDOWS\system32\nipalsm.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\IVI Foundation\VISA\WinNT\NIvisa\niLxiDiscovery.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=4071012
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\national instruments\shared\mdns responder\nimdnsnsp.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1214061259171
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{6637E906-5A9B-4FFF-900E-1254039BBAB8}: NameServer = 68.113.206.10,66.196.221.10
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Unknown owner - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgemc.exe (file missing)
O23 - Service: AVG Free8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lookout Citadel Server (LkCitadelServer) - National Instruments, Inc. - C:\WINDOWS\system32\lkcitdl.exe
O23 - Service: National Instruments PSP Server Locator (lkClassAds) - National Instruments Corporation - C:\WINDOWS\system32\lkads.exe
O23 - Service: National Instruments Time Synchronization (lkTimeSync) - National Instruments Corporation - C:\WINDOWS\system32\lktsrv.exe
O23 - Service: NI Configuration Manager (mxssvr) - National Instruments Corporation - C:\Program Files\National Instruments\MAX\nimxs.exe
O23 - Service: NI-488.2 Enumeration Service (ni488enumsvc) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exe
O23 - Service: NI Device Loader (nidevldu) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exe
O23 - Service: National Instruments Domain Service (NIDomainService) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
O23 - Service: NILM License Manager - Macrovision Corporation - C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe
O23 - Service: National Instruments LXI Discovery Service (niLXIDiscovery) - National Instruments Corporation - C:\Program Files\IVI Foundation\VISA\WinNT\NIvisa\niLxiDiscovery.exe
O23 - Service: National Instruments mDNS Responder Service (nimDNSResponder) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsResponder.exe
O23 - Service: NI PXI Resource Manager (nipxirmu) - National Instruments Corporation - C:\WINDOWS\system32\nipalsm.exe
O23 - Service: NI Service Locator (niSvcLoc) - National Instruments Corporation - C:\WINDOWS\system32\nisvcloc.exe
O23 - Service: National Instruments Variable Engine (NITaggerService) - National Instruments Corporation - C:\Program Files\National Instruments\Shared\Tagger\tagsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

–
End of file - 10143 bytes
Good morning

Lets do this :

Please download GooredFix and save it to your Desktop. Get it:

HERE:


Double-click Goored.exe to run it. Select 1. Find Goored (no fix) by typing 1 and pressing Enter. A log will open, please post the contents of that log in your next reply (it can also be found on your desktop, called Goored.txt).
Note: Do not run Option #2 yet.

good luck mschroe919
GooredFix v1.6 by jpshortstuff Log created at 10:58 on 24/12/2008 running Option #1 Firefox version 3.0.5 (en-US) =====Suspect Goored Entries===== [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions] "{76BD3F33-01D9-43B8-B140-E9C39622071B}"="C:\Documents and Settings\zarbuchan\Local Settings\Application Data\{76BD3F33-01D9-43B8-B140-E9C39622071B}" =====Dumping Registry Values===== [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.5\extensions] "Plugins"="C:\Program Files\Mozilla Firefox\plugins" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.5\extensions] "Components"="C:\Program Files\Mozilla Firefox\components" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions] "{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG8\Firefox" (Folder Missing) [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions] "{76BD3F33-01D9-43B8-B140-E9C39622071B}"="C:\Documents and Settings\zarbuchan\Local Settings\Application Data\{76BD3F33-01D9-43B8-B140-E9C39622071B}"

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI