This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan? / auto updates prevented; browser hijacked

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The following message is from my husband, who has a virus that seems to have hijacked his browser (in addition to preventing automatic updates). It isn't allowing him on this site or any others that might help solve the problem. If anyone has any advice, it would be most appreciated …


Help!
It appears that my browser may be highjacked.
I cannot browse with Firefox anymore.
I can't turn on Windows Automatic Updates.
I can't update my SuperAntiSpyware nor my SpyBot programs to deals with this.
I could not even register for this forum on my own computer (I'm using my wifes)
I downloaded and scanned using Highjack This but I of course can't even upload the scan logfile.
I am somewhere between enraged and apoplectic at the little ####'s that created this.
I'll attempt to attach my logfile to this posting.
Thanks hugely!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:35:32 PM, on 1/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svch?st.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\sesinetd.exe
C:\WINDOWS\system32\hserver.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\spm\spmdib.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\atwtusb.exe
C:\Program Files\QuickTime\QTTask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\NoAdware\NoAdware5.exe
C:\Program Files\NoAdware\NoAdware5.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.drudgereport.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.drudgereport.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: Shell=Explorer.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\uoyzsydz.exe,
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [HP Component Manager] C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [type32] C:\Program Files\Microsoft IntelliType Pro\type32.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [atwtusb] atwtusb.exe beta
O4 - HKLM\..\Run: [Redemption] "\redemption.exe" /STARTUP
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Startup Manager] "C:\Program Files\Advanced System Optimizer\startUp manager.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_srl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3C9CA678-2A8D-4A87-9E31-5A4043DDB227}: NameServer = 4.2.2.1,4.2.2.2
O17 - HKLM\System\CCS\Services\Tcpip\..\{8B97A32A-DD1D-46CA-A90E-72D93850DCF1}: NameServer = 85.255.115.70,85.255.112.138
O17 - HKLM\System\CCS\Services\Tcpip\..\{9267197E-2DCD-4433-9043-6E697F54006C}: NameServer = 85.255.115.70,85.255.112.138
O17 - HKLM\System\CS1\Services\Tcpip\..\{3C9CA678-2A8D-4A87-9E31-5A4043DDB227}: NameServer = 4.2.2.1,4.2.2.2
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.70,85.255.112.138
O17 - HKLM\System\CS2\Services\Tcpip\..\{3C9CA678-2A8D-4A87-9E31-5A4043DDB227}: NameServer = 4.2.2.1,4.2.2.2
O17 - HKLM\System\CS3\Services\Tcpip\..\{3C9CA678-2A8D-4A87-9E31-5A4043DDB227}: NameServer = 4.2.2.1,4.2.2.2
O17 - HKLM\System\CS4\Services\Tcpip\Parameters: NameServer = 85.255.115.70,85.255.112.138
O17 - HKLM\System\CS4\Services\Tcpip\..\{3C9CA678-2A8D-4A87-9E31-5A4043DDB227}: NameServer = 4.2.2.1,4.2.2.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.70,85.255.112.138
O20 - AppInit_DLLs: zboncf.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HoudiniLicenseServer - Side Effects Software Inc. - C:\WINDOWS\system32\sesinetd.exe
O23 - Service: HoudiniServer - Side Effects Software Inc. - C:\WINDOWS\system32\hserver.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Documents and Settings\mentalray\satellite\raysat_3dsmax8server.exe
O23 - Service: mental ray 3.5 Satellite (32-bit) (mi-raysat_3dsmax9_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max 9\mentalray\satellite\raysat_3dsmax9_32server.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SPM License Server (spmd) - mental images GmbH - C:\spm\spmdib.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
hello

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.


Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.
Thank you very very much. Everything appears to be working fine now.
You sir/madam are a legend !
Here is the log.

ComboFix 09-01-17.03 - Client 2009-01-17 18:06:35.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.632 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
FW: Symantec Client Firewall *enabled*
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\3dsmax.exe
c:\documents and settings\3dsmaxcmd.exe
c:\documents and settings\All Users\Application Data\Microsoft\bits.dll
c:\documents and settings\All Users\Application Data\Microsoft\ipdll.dll
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Client\Application Data\inst.exe
c:\program files\INSTALL.LOG
c:\program files\Mozilla Firefox\components\iamfamous.dll
c:\windows\BM7bfff582.txt
c:\windows\BM7bfff582.xml
c:\windows\cookies.ini
c:\windows\Downloaded Program Files\setup.inf
c:\windows\IE4 Error Log.txt
c:\windows\jestertb.dll
c:\windows\system32\drivers\msqpdxayvpktap.sys
c:\windows\system32\drivers\msqpdxkfrhotod.sys
c:\windows\system32\drivers\msqpdxlhmnbgoe.sys
c:\windows\system32\drivers\msqpdxlwowxngw.sys
c:\windows\system32\drivers\npf.sys
c:\windows\system32\dsehvxdt.ini
c:\windows\system32\ffNqAcdd.ini
c:\windows\system32\ffNqAcdd.ini2
c:\windows\system32\hydemsda.ini
c:\windows\system32\jkkIButt.dll
c:\windows\system32\jkkKcCsQ.dll
c:\windows\system32\kajnggpl.dll
c:\windows\system32\kmhqtq.dll
c:\windows\system32\mcrh.tmp
c:\windows\system32\mpjvygqq.ini
c:\windows\system32\msqpdxrrgaiqjk.dll
c:\windows\system32\nnnaffir.ini
c:\windows\system32\NVuxaGgh.ini
c:\windows\system32\NVuxaGgh.ini2
c:\windows\system32\packet.dll
c:\windows\system32\qujabiay.ini
c:\windows\system32\qvscqmnk.dll
c:\windows\system32\raipywxv.ini
c:\windows\system32\sfnouuuw.dll
c:\windows\system32\skiowaoj.ini
c:\windows\system32\tmp.reg
c:\windows\system32\ttuBIkkj.ini
c:\windows\system32\ttuBIkkj.ini2
c:\windows\system32\udjdlxak.ini
c:\windows\system32\vjzszh.dll
c:\windows\system32\wpcap.dll
c:\windows\system32\xnbydmyp.ini
c:\windows\system32\ycqohqad.ini
c:\windows\system32\yogbdfyy.ini
c:\windows\system32\yyfdbgoy.dll
c:\windows\system32\zboncf.dll

—– BITS: Possible infected sites —–

hxxp://bestworldguide.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_MSQPDXSERV.SYS
——-\Legacy_ISODRIVE
——-\Service_ISODrive


((((((((((((((((((((((((( Files Created from 2008-12-18 to 2009-01-18 )))))))))))))))))))))))))))))))
.

2009-01-17 12:05 . 2009-01-17 12:05 578,560 –a–c— c:\windows\system32\dllcache\user32.dll
2009-01-17 11:52 . 2009-01-17 11:53 d——– c:\windows\ERUNT
2009-01-17 11:36 . 2009-01-17 12:40 d—-c— C:\SDFix
2009-01-15 17:35 . 2009-01-15 17:35 d——– c:\program files\Trend Micro
2009-01-15 16:28 . 2009-01-15 17:25 d——– c:\program files\NoAdware
2009-01-14 17:42 . 2009-01-16 22:12 73,216 –a—— c:\windows\system32\drivers\gaopdxserv.sys
2009-01-11 14:39 . 2009-01-11 14:39 d——– c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-01-11 14:38 . 2009-01-14 23:49 d——– c:\program files\SUPERAntiSpyware
2009-01-11 14:38 . 2009-01-11 14:38 d——– c:\documents and settings\Client\Application Data\SUPERAntiSpyware.com
2009-01-09 05:15 . 2008-04-13 16:12 61,440 –a—— c:\windows\system32\svchost.exe
2009-01-09 05:14 . 2009-01-09 05:14 d——– c:\program files\totalvid
2008-12-20 16:15 . 2003-01-08 14:06 61,440 –a—— c:\windows\system32\ni_dfd.dll
2008-12-20 12:49 . 2008-12-20 12:49 d——– c:\program files\Synth1
2008-12-20 12:36 . 2008-12-20 16:16 d——– c:\program files\Native Instruments
2008-12-20 12:36 . 2008-12-20 12:36 d——– c:\program files\Digidesign
2008-12-20 12:33 . 2002-04-22 01:20 16,371,712 –a—— c:\windows\system32\AbsynthIAC.dll
2008-12-20 12:22 . 2008-12-20 12:22 d——– c:\program files\Voice Trap
2008-12-20 12:02 . 2008-12-20 12:02 d—-c— C:\Camel Audio Cameleon 5000 v1.2
2008-12-20 11:56 . 2008-12-20 11:56 d——– c:\program files\Bornemark
2008-12-20 11:52 . 2001-06-14 19:48 520,267 –a—— c:\windows\system32\libmmd.dll
2008-12-20 11:51 . 2008-12-20 11:51 d——– c:\windows\Desktop
2008-12-20 11:50 . 2003-10-08 22:54 287,743 –a—— c:\windows\LOOP.exe
2008-12-20 11:45 . 2008-12-20 13:12 d——– c:\program files\Translator
2008-12-20 11:45 . 1998-06-24 00:00 164,144 –a—— c:\windows\system32\comct232.ocx
2008-12-20 11:45 . 2000-08-29 11:42 45,056 –a—— c:\windows\system32\aspi.ocx
2008-12-20 11:45 . 1999-08-18 18:30 36,864 –a—— c:\windows\system32\utilpt32.dll
2008-12-20 11:45 . 1999-04-23 22:22 5,532 –a—— c:\windows\system32\Stdole.tlb
2008-12-20 11:44 . 2008-12-20 11:44 d——– c:\program files\Sonitus-fx
2008-12-20 10:38 . 2008-12-20 10:38 d——– c:\program files\DreamStation DXi
2008-12-20 10:38 . 2008-12-20 10:38 118,784 –a—— c:\windows\dsdxirmv.exe
2008-12-20 10:37 . 2008-12-20 10:37 d—-c— C:\Samples
2008-12-20 10:37 . 2008-12-20 10:37 d—-c— C:\Plugins
2008-12-18 19:13 . 2008-12-18 19:13 d——– c:\program files\Common Files\Adobe AIR
2008-12-18 19:03 . 2008-12-18 19:03 d——– c:\documents and settings\Client\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2008-12-18 17:10 . 2008-12-18 17:17 d——– c:\program files\ASIO4ALL v2
2008-12-18 17:10 . 2002-07-07 14:14 1,294,336 –a—— c:\windows\system32\vorbis.acm
2008-12-18 17:09 . 2008-12-18 17:09 d——– c:\program files\Outsim
2008-12-18 17:07 . 2008-12-18 17:18 d——– c:\program files\Image-Line
2008-12-18 01:58 . 2008-12-18 01:57 410,984 –a—— c:\windows\system32\deploytk.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-18 01:47 ——— d—–w c:\program files\Norton Security Scan
2009-01-17 19:12 ——— d—–w c:\documents and settings\Client\Application Data\Azureus
2009-01-17 08:11 ——— d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-01-15 05:22 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2009-01-10 04:04 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-01-06 20:04 8,282,112 -c–a-w C:\XSI.EXE
2009-01-05 05:46 ——— d—–w c:\program files\Autodesk
2008-12-25 22:15 ——— d—–w c:\program files\QuickTime
2008-12-21 02:19 ——— d—–w c:\program files\Ableton
2008-12-20 20:16 ——— d—–w c:\documents and settings\Client\Application Data\Cakewalk
2008-12-20 19:47 ——— d—–w c:\program files\Cakewalk
2008-12-19 02:59 ——— d—–w c:\program files\Common Files\Adobe
2008-12-19 02:42 ——— d—–w c:\documents and settings\Client\Application Data\Ableton
2008-12-18 09:57 ——— d—–w c:\program files\Java
2008-12-17 17:51 ——— d—–w c:\documents and settings\All Users\Application Data\Cakewalk
2008-12-17 07:14 ——— d—–w c:\documents and settings\Client\Application Data\Thinstall
2008-12-17 04:35 ——— d—–w c:\documents and settings\Client\Application Data\MAGIX
2008-12-17 04:34 ——— d—–w c:\program files\MAGIX
2008-12-17 04:34 ——— d—–w c:\documents and settings\All Users\Application Data\MAGIX
2008-12-15 16:14 ——— d—–w c:\program files\Audjoo Helix
2008-12-15 15:32 ——— d—–w c:\documents and settings\Client\Application Data\uTorrent
2008-12-15 03:02 ——— d—–w c:\documents and settings\All Users\Application Data\Nero
2008-12-13 03:05 ——— d—–w c:\program files\Nero
2008-12-12 23:20 ——— d—–w c:\program files\uTorrent
2008-12-09 13:25 ——— d—–w c:\documents and settings\Client\Application Data\Nero
2008-12-08 02:01 ——— d—–w c:\documents and settings\Client\Application Data\Renoise
2008-12-08 02:00 ——— d—–w c:\program files\Renoise 1.9.1
2008-12-07 18:04 ——— d—–w c:\program files\FlashGet
2008-12-06 23:34 ——— d—–w c:\program files\FinalUninstaller
2008-12-06 17:47 ——— d—–w c:\documents and settings\All Users\Application Data\NortonInstaller
2008-11-23 15:18 ——— d—–w c:\program files\Azureus
2008-11-21 13:45 ——— d—–w c:\program files\ATI
2008-11-21 13:37 ——— d—–w c:\program files\iTunes
2008-11-21 13:37 ——— d—–w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-21 13:36 ——— d—–w c:\program files\iPod
2008-11-21 13:32 ——— d—–w c:\program files\Common Files\Apple
2008-11-19 21:19 ——— d—–w c:\program files\SystemRequirementsLab
2008-11-18 01:27 ——— d—–w c:\documents and settings\Client\Application Data\ATI
2008-11-18 01:27 ——— d—–w c:\documents and settings\All Users\Application Data\ATI
2008-11-18 01:21 ——— d—–w c:\program files\ATI Technologies
2008-11-18 01:19 ——— d–h–w c:\program files\InstallShield Installation Information
2007-10-29 02:49 47,360 —-a-w c:\documents and settings\Client\Application Data\pcouffin.sys
2007-09-11 23:21 1,904,584 —-a-w c:\program files\daemon410-x86.exe
2007-09-11 13:13 4,641,447 —-a-w c:\program files\eMule0.48a-Installer.exe
2007-04-25 13:39 374 —-a-w c:\documents and settings\Client\Application Data\internaldb6334.dat
2007-04-25 13:36 18,432 —-a-w c:\documents and settings\Client\Application Data\internaldb41.dat
2007-04-25 12:43 538 —-a-w c:\documents and settings\Client\Application Data\internaldb8467.dat
2005-09-21 23:07 73,216 —-a-w c:\documents and settings\stdplugs\XmlMapMods.dll
2005-09-21 22:05 364,544 —-a-w c:\documents and settings\stdplugs\XmlMtl.dll
2005-09-21 21:59 861,184 —-a-w c:\documents and settings\dlcomponents\libDLrad.dll
2005-09-21 21:45 22,016 —-a-w c:\documents and settings\dlcomponents\libDLradRes.dll
2005-09-21 21:44 387,072 —-a-w c:\documents and settings\dlcomponents\libDLphoto.dll
2005-09-21 21:44 16,384 —-a-w c:\documents and settings\dlcomponents\libDLphotoRes.dll
2005-09-21 21:34 9,728 —-a-w c:\documents and settings\stdplugs\epsres.dll
2005-09-21 21:28 21,504 —-a-w c:\documents and settings\stdplugs\Cube2QTVR.exe
2005-09-21 21:12 90,112 —-a-w c:\documents and settings\plugins\JSR184ExporterRes.dll
2005-09-21 21:12 69,632 —-a-w c:\documents and settings\plugins\LandXML2MaxRes.dll
2005-09-21 21:05 10,779 —-a-w c:\documents and settings\UI\ClassIcons.dat
2004-08-23 22:58 1,110,518 —-a-w c:\documents and settings\JSR\M3Gplayer.exe
2004-08-13 21:57 139,334 —-a-w c:\documents and settings\JSR\m3g.dll
2004-06-12 00:06 229,442 —-a-w c:\documents and settings\JSR\libGLES_CM.dll
2003-05-30 16:22 344,064 —-a-r c:\program files\msvcr70.dll
2002-01-05 10:40 487,424 —-a-w c:\program files\msvcp70.dll
2008-09-10 01:53 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008090920080910\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Startup Manager"="c:\program files\Advanced System Optimizer\startUp manager.exe" [2007-06-22 919280]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-11 1805552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-31 344064]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-04-08 48752]
"vptray"="c:\progra~1\SYMANT~1\SYMANT~2\VPTray.exe" [2005-04-17 85184]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2005-03-15 196608]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-30 155648]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-03-21 69632]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-18 136600]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2008-07-06 167936]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"atwtusb"="atwtusb.exe" [2003-08-07 c:\windows\system32\Atwtusb.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-02-23 389120]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"SENTINEL"= snti386.dll
"msacm.divxa32"= msaud32_divx.acm
"vidc.3IV2"= 3ivxVfWCodec_dec.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 9\\3dsmax.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Adobe\\Adobe After Effects 7.0\\Support Files\\AfterFX.exe"=
"c:\\Documents and Settings\\Client\\My Documents\\Azureus Downloads\\3d Inv\\3d Inv\\keygen.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Alias\\Maya8.0\\bin\\maya.exe"=
"c:\\XSI.EXE"=
"c:\\Program Files\\Autodesk\\Maya2009\\bin\\maya.exe"=
"c:\\Program Files\\Side Effects Software\\Houdini 9.5.170\\bin\\houdini.exe"=
"c:\\Program Files\\Side Effects Software\\Houdini 9.5.170\\bin\\hmaster.exe"=
"c:\\Program Files\\Luxology\\modo 301\\modo.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\SUPERAntiSpyware\\SUPERANTISPYWARE.EXE"=
"c:\\Program Files\\Advanced System Optimizer\\Spyware Detective.exe"=
"c:\\SUPERAntiSpyware.exe"=

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2008-11-17 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2008-11-17 55024]
R3 EraserUtilDrvI7;EraserUtilDrvI7;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrvI7.sys [2009-01-09 99376]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-11-17 7408]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2007-10-10 16512]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe [2008-12-16 1527900]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-11-08 33752]
S3 SavRoam;SAVRoam;c:\program files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe [2005-04-17 124608]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3302fe38-54e4-11dd-9b54-00188b0305d0}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com i:
\Shell\Open\command - i:\resycled\boot.com i:

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e027e21c-e236-11dc-9b1d-00188b0305d0}]
\Shell\AutoRun\command - G:\ONSPCLCK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f66ac24a-38e3-11dd-9b48-00188b0305d0}]
\Shell\AutoRun\command - j:\system\viewer\FlipVideoforPC.exe
\Shell\Flip Video for PC\command - j:\system\viewer\FlipVideoforPC.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f905e3ab-b571-11db-9929-0016b693394e}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2009-01-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2008-11-23 c:\windows\Tasks\HubTask 0 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0.job
- c:\program files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe [2005-11-07 02:04]

2008-11-23 c:\windows\Tasks\HubTask 0 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0.job
- c:\documents and settings\Client\My Documents [2008-12-16 20:35]

2009-01-17 c:\windows\Tasks\Norton Security Scan for Client.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 03:18]

2007-01-22 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-03-31 17:32]

2009-01-13 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []

2007-09-24 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
.
- - - - ORPHANS REMOVED - - - -

BHO-{3E288C4D-2B7B-4C0A-8E86-BC8B8BB3F461} - c:\documents and settings\Client\Local Settings\Temporary Internet Files\Content.IE5\B39UR845\3077htsbdjyf[1].dll
BHO-{9AA42353-B306-288D-9B50-E2C19B614941} - (no file)
BHO-{a45fc771-8dfe-4f8f-85d8-315b07727624} - c:\windows\system32\vjzszh.dll
BHO-{C67677AF-B806-491C-B7BF-42088F0E8163} - c:\windows\system32\jkkIButt.dll
WebBrowser-{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - (no file)
HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe
HKLM-Run-Redemption - \redemption.exe
HKLM-Run-NBKeyScan - c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe


.
——- Supplementary Scan ——-
.
uLocal Page = \blank.htm
uStart Page = hxxp://www.drudgereport.com/
mStart Page = hxxp://www.drudgereport.com/
uInternet Settings,ProxyOverride = *.local
Trusted Zone: www.officepools.com
TCP: {3C9CA678-2A8D-4A87-9E31-5A4043DDB227} = 4.2.2.1,4.2.2.2
FF - ProfilePath - c:\documents and settings\Client\Application Data\Mozilla\Firefox\Profiles\gyomm1tk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Search
FF - prefs.js: browser.startup.homepage - hxxp://www.drudgereport.com/
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-17 18:20:07
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:52,cd,81,8a,f8,59,54,b9,a1,e5,64,dd,08,23,f0,2a,17,f4,8c,27,52,
b1,44,bb,d1,47,57,7e,ee,5f,72,05,34,72,45,20,de,f7,78,b9,04,eb,8c,9c,b1,a2,\

[HKEY_LOCAL_MACHINE\software\GenArts\Sapphire AE\Install-{4E41A485-04D4-CF7C-6CE3-27F7BEAE7048}\Data*]
@DACL=
"CTE_32 Name"="52930:{C3B8A1BC-8B18-94D5-AD04-2B3354994626}"

[HKEY_LOCAL_MACHINE\software\GenArts\Sapphire AE\Install-{EC3F6705-85EF-4FB1-4E30-80781324E273}\Data*]
@DACL=
"DefaultSettings"="99:{C6DDA450-F687-55DF-CA23-1A5083308C5D}"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\Current Version\{8AC25C6A-D4B3-FF2F-2A61-C75CA1DB6116}\Install*Loc\VxDs]
@DACL=
"CTE_32 Name"="2454394:{301564B2-67A6-1A66-9C4E-A1FE91DE9752}"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\Current Version\{ADD916B7-3238-B642-38AC-F31A4E6EE8C3}\Install*Loc\VxDs]
@DACL=
"DefaultSettings"="-19:{3C7DA433-1047-9FC4-00BA-978A09424856}"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Install*Loc\xga-1-{F997431D-28AF-BB84-0050-670A83CDD3AD}\Version 1.1]
@DACL=
"dat"="806585365:{4BB5A823-C93C-5B32-AAC1-52CE2226230B}"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•Ôw*]
"5E7CEC10DF0760D4F8DAFB12FDC06CCD"="02:\\Software\\Adobe\\FeatureSubscriptions\\DVAAdobeDocMeta\\{01CEC7E5-70FD-4D06-8FAD-BF21DF0CC6DC}\\Registered"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\z*\{{05FF8CB8-4942-FCF6-301D-6930181DE865}}]
@DACL=
"DefaultSettings"="2454415:{37C8840C-72FD-B1F6-4FC1-23A6EF5B6255}"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows Install VBX*\Current*Version\Install*Loc\xga-1-{F997431D-28AF-BB84-0050-670A83CDD3AD}\Version 3.x]
@DACL=
"dat"="1767914624:{08169AB5-B966-6746-7018-F62714647642}"

[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:52,cd,81,8a,f8,59,54,b9,a1,e5,64,dd,08,23,f0,2a,17,f4,8c,27,52,
b1,44,bb,d1,47,57,7e,ee,5f,72,05,34,72,45,20,de,f7,78,b9,04,eb,8c,9c,b1,a2,\

[HKEY_LOCAL_MACHINE\software\xGenArts\Sapphire AE\DLL ver*\{A6D90D08-68DD-2B46-E2AC-5782669B2696}]
@DACL=
"CTE_32 Name"="0:{19C42D30-D844-8A07-12A4-E783E7D228F7}"

[HKEY_LOCAL_MACHINE\software\xGenArts\Sapphire AE\DLL ver*\{B08ECCAD-FEC0-A273-8DFD-B47BE795EE25}]
@DACL=
"DefaultSettings"="19:{5351C505-4E6C-6ECA-E5BD-7AE84A571B0A}"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(976)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccProxy.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\windows\system32\sesinetd.exe
c:\windows\system32\hserver.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\spm\spmdib.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
c:\program files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2009-01-17 18:29:57 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-18 02:29:52

Pre-Run: 65,626,193,920 bytes free
Post-Run: 65,778,937,856 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

Current=2 Default=2 Failed=1 LastKnownGood=4 Sets=1,2,3,4
398 — E O F — 2008-12-20 11:01:06
hello

  • 1 - Flash Drive Disinfector
    Download Flash_Disinfector.exe by sUBs from >here< and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder…it will help protect your drives from future infection.



1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

folder::
c:\program files\NoAdware
c:\program files\totalvid
file::
c:\windows\system32\drivers\gaopdxserv.sys


Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3302fe38-54e4-11dd-9b54-00188b0305d0}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e027e21c-e236-11dc-9b1d-00188b0305d0}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f66ac24a-38e3-11dd-9b48-00188b0305d0}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f905e3ab-b571-11db-9929-0016b693394e}]

Driver::


Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Thanks very much for the responses. My husband's computer is now working as it should be. He posted the log of the clean-up below if you're interested. Thanks again. Roxane
He followed the instructions from your first response and it fixed the problem, so he didn't do the second. I'm not sure why you can't see the log – it showing for me earlier in this thread. If you like, I can ask him to email you the log (if you send us your address). Thanks again, Roxane
Hello there
Here is the Combofix .txt.
ComboFix 09-01-17.03 - Client 2009-01-18 10:49:24.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.443 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Client\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
FW: Symantec Client Firewall *enabled*
* Created a new restore point

FILE ::
c:\windows\system32\drivers\gaopdxserv.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\NoAdware
c:\program files\NoAdware\logs\Date(15-1-2009) Time(17-30-6).txt
c:\program files\NoAdware\noadware4_011509.na
c:\program files\NoAdware\NoAdware5.exe
c:\program files\NoAdware\NoAdwareBackup\1,15,2009_17,25,32.zip
c:\program files\NoAdware\nutilities.dll
c:\program files\NoAdware\unins000.dat
c:\program files\NoAdware\unins000.exe
c:\program files\totalvid
c:\program files\totalvid\Uninstall.exe
I:\Autorun.inf
I:\resycled
i:\resycled\boot.com

.
((((((((((((((((((((((((( Files Created from 2008-12-18 to 2009-01-18 )))))))))))))))))))))))))))))))
.

2009-01-17 12:05 . 2009-01-17 12:05 578,560 –a–c— c:\windows\system32\dllcache\user32.dll
2009-01-17 11:52 . 2009-01-17 11:53 d——– c:\windows\ERUNT
2009-01-17 11:36 . 2009-01-17 12:40 d—-c— C:\SDFix
2009-01-15 17:35 . 2009-01-15 17:35 d——– c:\program files\Trend Micro
2009-01-11 14:39 . 2009-01-11 14:39 d——– c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-01-11 14:38 . 2009-01-18 08:18 d——– c:\program files\SUPERAntiSpyware
2009-01-11 14:38 . 2009-01-11 14:38 d——– c:\documents and settings\Client\Application Data\SUPERAntiSpyware.com
2009-01-09 05:15 . 2008-04-13 16:12 61,440 –a—— c:\windows\system32\svchost.exe
2008-12-20 16:15 . 2003-01-08 14:06 61,440 –a—— c:\windows\system32\ni_dfd.dll
2008-12-20 12:49 . 2008-12-20 12:49 d——– c:\program files\Synth1
2008-12-20 12:36 . 2008-12-20 16:16 d——– c:\program files\Native Instruments
2008-12-20 12:36 . 2008-12-20 12:36 d——– c:\program files\Digidesign
2008-12-20 12:33 . 2002-04-22 01:20 16,371,712 –a—— c:\windows\system32\AbsynthIAC.dll
2008-12-20 12:22 . 2008-12-20 12:22 d——– c:\program files\Voice Trap
2008-12-20 12:02 . 2008-12-20 12:02 d—-c— C:\Camel Audio Cameleon 5000 v1.2
2008-12-20 11:56 . 2008-12-20 11:56 d——– c:\program files\Bornemark
2008-12-20 11:52 . 2001-06-14 19:48 520,267 –a—— c:\windows\system32\libmmd.dll
2008-12-20 11:51 . 2008-12-20 11:51 d——– c:\windows\Desktop
2008-12-20 11:50 . 2003-10-08 22:54 287,743 –a—— c:\windows\LOOP.exe
2008-12-20 11:45 . 2008-12-20 13:12 d——– c:\program files\Translator
2008-12-20 11:45 . 1998-06-24 00:00 164,144 –a—— c:\windows\system32\comct232.ocx
2008-12-20 11:45 . 2000-08-29 11:42 45,056 –a—— c:\windows\system32\aspi.ocx
2008-12-20 11:45 . 1999-08-18 18:30 36,864 –a—— c:\windows\system32\utilpt32.dll
2008-12-20 11:45 . 1999-04-23 22:22 5,532 –a—— c:\windows\system32\Stdole.tlb
2008-12-20 11:44 . 2008-12-20 11:44 d——– c:\program files\Sonitus-fx
2008-12-20 10:38 . 2008-12-20 10:38 d——– c:\program files\DreamStation DXi
2008-12-20 10:38 . 2008-12-20 10:38 118,784 –a—— c:\windows\dsdxirmv.exe
2008-12-20 10:37 . 2008-12-20 10:37 d—-c— C:\Samples
2008-12-20 10:37 . 2008-12-20 10:37 d—-c— C:\Plugins
2008-12-18 19:13 . 2008-12-18 19:13 d——– c:\program files\Common Files\Adobe AIR
2008-12-18 19:03 . 2008-12-18 19:03 d——– c:\documents and settings\Client\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2008-12-18 17:10 . 2008-12-18 17:17 d——– c:\program files\ASIO4ALL v2
2008-12-18 17:10 . 2002-07-07 14:14 1,294,336 –a—— c:\windows\system32\vorbis.acm
2008-12-18 17:09 . 2008-12-18 17:09 d——– c:\program files\Outsim
2008-12-18 17:07 . 2008-12-18 17:18 d——– c:\program files\Image-Line
2008-12-18 01:58 . 2008-12-18 01:57 410,984 –a—— c:\windows\system32\deploytk.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-18 18:43 ——— d—–w c:\program files\Norton Security Scan
2009-01-18 18:30 ——— d—–w c:\documents and settings\Client\Application Data\Azureus
2009-01-18 09:11 ——— d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-01-18 02:47 ——— d—–w c:\documents and settings\Client\Application Data\Autodesk
2009-01-15 05:22 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2009-01-10 04:04 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-01-06 20:04 8,282,112 -c–a-w C:\XSI.EXE
2009-01-05 05:46 ——— d—–w c:\program files\Autodesk
2008-12-25 22:15 ——— d—–w c:\program files\QuickTime
2008-12-21 02:19 ——— d—–w c:\program files\Ableton
2008-12-20 20:16 ——— d—–w c:\documents and settings\Client\Application Data\Cakewalk
2008-12-20 19:47 ——— d—–w c:\program files\Cakewalk
2008-12-19 02:59 ——— d—–w c:\program files\Common Files\Adobe
2008-12-19 02:42 ——— d—–w c:\documents and settings\Client\Application Data\Ableton
2008-12-18 09:57 ——— d—–w c:\program files\Java
2008-12-17 17:51 ——— d—–w c:\documents and settings\All Users\Application Data\Cakewalk
2008-12-17 07:14 ——— d—–w c:\documents and settings\Client\Application Data\Thinstall
2008-12-17 04:35 ——— d—–w c:\documents and settings\Client\Application Data\MAGIX
2008-12-17 04:34 ——— d—–w c:\program files\MAGIX
2008-12-17 04:34 ——— d—–w c:\documents and settings\All Users\Application Data\MAGIX
2008-12-15 16:14 ——— d—–w c:\program files\Audjoo Helix
2008-12-15 15:32 ——— d—–w c:\documents and settings\Client\Application Data\uTorrent
2008-12-15 03:02 ——— d—–w c:\documents and settings\All Users\Application Data\Nero
2008-12-13 03:05 ——— d—–w c:\program files\Nero
2008-12-12 23:20 ——— d—–w c:\program files\uTorrent
2008-12-11 10:57 333,952 —-a-w c:\windows\system32\drivers\srv.sys
2008-12-09 13:25 ——— d—–w c:\documents and settings\Client\Application Data\Nero
2008-12-08 02:01 ——— d—–w c:\documents and settings\Client\Application Data\Renoise
2008-12-08 02:00 ——— d—–w c:\program files\Renoise 1.9.1
2008-12-07 18:04 ——— d—–w c:\program files\FlashGet
2008-12-06 23:34 ——— d—–w c:\program files\FinalUninstaller
2008-12-06 17:47 ——— d—–w c:\documents and settings\All Users\Application Data\NortonInstaller
2008-12-01 19:20 138,363,389 —-a-w c:\windows\system32\xa21856953.exe
2008-12-01 19:20 138,363,389 —-a-w c:\windows\system32\xa21854000.exe
2008-11-23 15:18 ——— d—–w c:\program files\Azureus
2008-11-21 13:45 ——— d—–w c:\program files\ATI
2008-11-21 13:37 ——— d—–w c:\program files\iTunes
2008-11-21 13:37 ——— d—–w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-21 13:36 ——— d—–w c:\program files\iPod
2008-11-21 13:32 ——— d—–w c:\program files\Common Files\Apple
2008-11-19 21:19 ——— d—–w c:\program files\SystemRequirementsLab
2008-11-18 01:27 ——— d—–w c:\documents and settings\Client\Application Data\ATI
2008-11-18 01:27 ——— d—–w c:\documents and settings\All Users\Application Data\ATI
2008-11-18 01:21 ——— d—–w c:\program files\ATI Technologies
2008-11-18 01:19 ——— d–h–w c:\program files\InstallShield Installation Information
2008-10-29 05:05 593,920 —-a-w c:\windows\system32\ati2sgag.exe
2008-10-29 02:23 425,984 —-a-w c:\windows\system32\ATIDEMGX.dll
2008-10-29 02:22 314,880 —-a-w c:\windows\system32\ati2dvag.dll
2008-10-29 02:11 43,520 —-a-w c:\windows\system32\ati2edxx.dll
2008-10-29 02:11 26,112 —-a-w c:\windows\system32\Ati2mdxx.exe
2008-10-29 02:11 188,416 —-a-w c:\windows\system32\atipdlxx.dll
2008-10-29 02:11 147,456 —-a-w c:\windows\system32\Oemdspif.dll
2008-10-29 02:10 143,360 —-a-w c:\windows\system32\ati2evxx.dll
2008-10-29 02:10 10,973,184 —-a-w c:\windows\system32\atioglxx.dll
2008-10-29 02:09 585,728 —-a-w c:\windows\system32\ati2evxx.exe
2008-10-29 02:07 53,248 —-a-w c:\windows\system32\ATIDDC.DLL
2008-10-29 01:57 4,041,472 —-a-w c:\windows\system32\ati3duag.dll
2008-10-29 01:49 307,200 —-a-w c:\windows\system32\atiiiexx.dll
2008-10-29 01:41 2,472,832 —-a-w c:\windows\system32\ativvaxx.dll
2008-10-29 01:25 48,640 —-a-w c:\windows\system32\amdpcom32.dll
2008-10-29 01:21 389,120 —-a-w c:\windows\system32\atikvmag.dll
2008-10-29 01:19 44,032 —-a-w c:\windows\system32\atiadlxx.dll
2008-10-29 01:19 17,408 —-a-w c:\windows\system32\atitvo32.dll
2008-10-29 01:18 253,952 —-a-w c:\windows\system32\atiok3x2.dll
2008-10-29 01:12 577,536 —-a-w c:\windows\system32\ati2cqag.dll
2008-10-27 18:04 70,992 —-a-w c:\windows\system32\XAPOFX1_2.dll
2008-10-27 18:04 514,384 —-a-w c:\windows\system32\XAudio2_3.dll
2008-10-27 18:04 235,856 —-a-w c:\windows\system32\xactengine3_3.dll
2008-10-27 18:04 23,376 —-a-w c:\windows\system32\X3DAudio1_5.dll
2008-10-23 12:36 286,720 —-a-w c:\windows\system32\gdi32.dll
2008-10-21 17:51 118,784 —-a-w c:\windows\system32\atibrtmon.exe
2007-10-29 02:49 47,360 —-a-w c:\documents and settings\Client\Application Data\pcouffin.sys
2007-09-11 23:21 1,904,584 —-a-w c:\program files\daemon410-x86.exe
2007-09-11 13:13 4,641,447 —-a-w c:\program files\eMule0.48a-Installer.exe
2007-04-25 13:39 374 —-a-w c:\documents and settings\Client\Application Data\internaldb6334.dat
2007-04-25 13:36 18,432 —-a-w c:\documents and settings\Client\Application Data\internaldb41.dat
2007-04-25 12:43 538 —-a-w c:\documents and settings\Client\Application Data\internaldb8467.dat
2005-09-21 23:07 73,216 —-a-w c:\documents and settings\stdplugs\XmlMapMods.dll
2005-09-21 22:05 364,544 —-a-w c:\documents and settings\stdplugs\XmlMtl.dll
2005-09-21 21:59 861,184 —-a-w c:\documents and settings\dlcomponents\libDLrad.dll
2005-09-21 21:45 22,016 —-a-w c:\documents and settings\dlcomponents\libDLradRes.dll
2005-09-21 21:44 387,072 —-a-w c:\documents and settings\dlcomponents\libDLphoto.dll
2005-09-21 21:44 16,384 —-a-w c:\documents and settings\dlcomponents\libDLphotoRes.dll
2005-09-21 21:34 9,728 —-a-w c:\documents and settings\stdplugs\epsres.dll
2005-09-21 21:28 21,504 —-a-w c:\documents and settings\stdplugs\Cube2QTVR.exe
2005-09-21 21:12 90,112 —-a-w c:\documents and settings\plugins\JSR184ExporterRes.dll
2005-09-21 21:12 69,632 —-a-w c:\documents and settings\plugins\LandXML2MaxRes.dll
2005-09-21 21:05 10,779 —-a-w c:\documents and settings\UI\ClassIcons.dat
2004-08-23 22:58 1,110,518 —-a-w c:\documents and settings\JSR\M3Gplayer.exe
2004-08-13 21:57 139,334 —-a-w c:\documents and settings\JSR\m3g.dll
2004-06-12 00:06 229,442 —-a-w c:\documents and settings\JSR\libGLES_CM.dll
2003-05-30 16:22 344,064 —-a-r c:\program files\msvcr70.dll
2002-01-05 10:40 487,424 —-a-w c:\program files\msvcp70.dll
2008-09-10 01:53 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008090920080910\index.dat
.

((((((((((((((((((((((((((((( snapshot@2009-01-17_18.28.29.25 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-13 05:08:15 593,920 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2009-01-18 18:35:25 593,920 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2008-12-13 05:08:15 12,288 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2009-01-18 18:35:25 12,288 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-12-13 05:08:15 86,016 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2009-01-18 18:35:25 86,016 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2008-12-13 05:08:15 135,168 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2009-01-18 18:35:24 135,168 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-12-13 05:08:15 11,264 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2009-01-18 18:35:25 11,264 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-12-13 05:08:16 27,136 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2009-01-18 18:35:25 27,136 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-12-13 05:08:16 4,096 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2009-01-18 18:35:25 4,096 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2008-12-13 05:08:16 794,624 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2009-01-18 18:35:25 794,624 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-12-13 05:08:15 249,856 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2009-01-18 18:35:25 249,856 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2008-12-13 05:08:15 61,440 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2009-01-18 18:35:24 61,440 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2008-12-13 05:08:16 23,040 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2009-01-18 18:35:25 23,040 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-12-13 05:08:15 286,720 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2009-01-18 18:35:24 286,720 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-12-13 05:08:15 409,600 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2009-01-18 18:35:24 409,600 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2008-09-08 10:41:42 333,824 -c—-w c:\windows\system32\dllcache\srv.sys
+ 2008-12-11 10:57:09 333,952 -c—-w c:\windows\system32\dllcache\srv.sys
- 2008-12-09 23:24:38 17,593,280 —-a-w c:\windows\system32\MRT.exe
+ 2009-01-10 01:35:28 20,853,704 —-a-w c:\windows\system32\MRT.exe
+ 2009-01-18 18:38:38 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_390.dat
+ 2009-01-18 18:38:40 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_408.dat
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Startup Manager"="c:\program files\Advanced System Optimizer\startUp manager.exe" [2007-06-22 919280]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-18 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-31 344064]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-04-08 48752]
"vptray"="c:\progra~1\SYMANT~1\SYMANT~2\VPTray.exe" [2005-04-17 85184]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2005-03-15 196608]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-30 155648]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-03-21 69632]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-18 136600]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2008-07-06 167936]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"atwtusb"="atwtusb.exe" [2003-08-07 c:\windows\system32\Atwtusb.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-02-23 389120]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-01-18 08:18 356352 c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"SENTINEL"= snti386.dll
"msacm.divxa32"= msaud32_divx.acm
"vidc.3IV2"= 3ivxVfWCodec_dec.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 9\\3dsmax.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Adobe\\Adobe After Effects 7.0\\Support Files\\AfterFX.exe"=
"c:\\Documents and Settings\\Client\\My Documents\\Azureus Downloads\\3d Inv\\3d Inv\\keygen.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Alias\\Maya8.0\\bin\\maya.exe"=
"c:\\XSI.EXE"=
"c:\\Program Files\\Autodesk\\Maya2009\\bin\\maya.exe"=
"c:\\Program Files\\Side Effects Software\\Houdini 9.5.170\\bin\\houdini.exe"=
"c:\\Program Files\\Side Effects Software\\Houdini 9.5.170\\bin\\hmaster.exe"=
"c:\\Program Files\\Luxology\\modo 301\\modo.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\SUPERAntiSpyware\\SUPERANTISPYWARE.EXE"=
"c:\\Program Files\\Advanced System Optimizer\\Spyware Detective.exe"=
"c:\\SUPERAntiSpyware.exe"=

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2008-11-17 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2008-11-17 55024]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-11-17 7408]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [2007-10-10 16512]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe [2008-12-16 1527900]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-11-08 33752]
S3 SavRoam;SAVRoam;c:\program files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe [2005-04-17 124608]

— Other Services/Drivers In Memory —

*NewlyCreated* - SASDIFSV
*Deregistered* - EraserUtilDrvI7
.
Contents of the 'Scheduled Tasks' folder

2009-01-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

2008-11-23 c:\windows\Tasks\HubTask 0 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0.job
- c:\program files\Common Files\Sonic Shared\Sonic Central\Main\Mediahub.exe [2005-11-07 02:04]

2008-11-23 c:\windows\Tasks\HubTask 0 {0E7C166E-2D2F-4269-9034-DE1898BF2B1A} 0~0.job
- c:\documents and settings\Client\My Documents [2008-12-16 20:35]

2009-01-17 c:\windows\Tasks\Norton Security Scan for Client.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 03:18]

2007-01-22 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-03-31 17:32]

2009-01-13 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []

2007-09-24 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
.
.
——- Supplementary Scan ——-
.
uLocal Page = \blank.htm
uStart Page = hxxp://www.drudgereport.com/
mStart Page = hxxp://www.drudgereport.com/
uInternet Settings,ProxyOverride = *.local
Trusted Zone: www.officepools.com
FF - ProfilePath - c:\documents and settings\Client\Application Data\Mozilla\Firefox\Profiles\gyomm1tk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Search
FF - prefs.js: browser.startup.homepage - hxxp://www.drudgereport.com/
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-18 10:54:55
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:52,cd,81,8a,f8,59,54,b9,a1,e5,64,dd,08,23,f0,2a,17,f4,8c,27,52,
b1,44,bb,d1,47,57,7e,ee,5f,72,05,34,72,45,20,de,f7,78,b9,04,eb,8c,9c,b1,a2,\

[HKEY_LOCAL_MACHINE\software\GenArts\Sapphire AE\Install-{4E41A485-04D4-CF7C-6CE3-27F7BEAE7048}\Data*]
@DACL=
"CTE_32 Name"="52930:{C3B8A1BC-8B18-94D5-AD04-2B3354994626}"

[HKEY_LOCAL_MACHINE\software\GenArts\Sapphire AE\Install-{EC3F6705-85EF-4FB1-4E30-80781324E273}\Data*]
@DACL=
"DefaultSettings"="99:{C6DDA450-F687-55DF-CA23-1A5083308C5D}"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\Current Version\{8AC25C6A-D4B3-FF2F-2A61-C75CA1DB6116}\Install*Loc\VxDs]
@DACL=
"CTE_32 Name"="2454394:{301564B2-67A6-1A66-9C4E-A1FE91DE9752}"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\Current Version\{ADD916B7-3238-B642-38AC-F31A4E6EE8C3}\Install*Loc\VxDs]
@DACL=
"DefaultSettings"="-19:{3C7DA433-1047-9FC4-00BA-978A09424856}"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Install*Loc\xga-1-{F997431D-28AF-BB84-0050-670A83CDD3AD}\Version 1.1]
@DACL=
"dat"="806585365:{4BB5A823-C93C-5B32-AAC1-52CE2226230B}"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•Ôw*]
"5E7CEC10DF0760D4F8DAFB12FDC06CCD"="02:\\Software\\Adobe\\FeatureSubscriptions\\DVAAdobeDocMeta\\{01CEC7E5-70FD-4D06-8FAD-BF21DF0CC6DC}\\Registered"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\z*\{{05FF8CB8-4942-FCF6-301D-6930181DE865}}]
@DACL=
"DefaultSettings"="2454415:{37C8840C-72FD-B1F6-4FC1-23A6EF5B6255}"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows Install VBX*\Current*Version\Install*Loc\xga-1-{F997431D-28AF-BB84-0050-670A83CDD3AD}\Version 3.x]
@DACL=
"dat"="1767914624:{08169AB5-B966-6746-7018-F62714647642}"

[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:52,cd,81,8a,f8,59,54,b9,a1,e5,64,dd,08,23,f0,2a,17,f4,8c,27,52,
b1,44,bb,d1,47,57,7e,ee,5f,72,05,34,72,45,20,de,f7,78,b9,04,eb,8c,9c,b1,a2,\

[HKEY_LOCAL_MACHINE\software\xGenArts\Sapphire AE\DLL ver*\{A6D90D08-68DD-2B46-E2AC-5782669B2696}]
@DACL=
"CTE_32 Name"="0:{19C42D30-D844-8A07-12A4-E783E7D228F7}"

[HKEY_LOCAL_MACHINE\software\xGenArts\Sapphire AE\DLL ver*\{B08ECCAD-FEC0-A273-8DFD-B47BE795EE25}]
@DACL=
"DefaultSettings"="19:{5351C505-4E6C-6ECA-E5BD-7AE84A571B0A}"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(972)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-01-18 11:02:04
ComboFix-quarantined-files.txt 2009-01-18 19:02:00
ComboFix2.txt 2009-01-18 02:29:58

Pre-Run: 65,508,741,120 bytes free
Post-Run: 65,516,064,768 bytes free

Current=2 Default=2 Failed=1 LastKnownGood=4 Sets=1,2,3,4
369 — E O F — 2009-01-18 18:35:28
hello

Please download the OTMoveIt3 by OldTimer
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    c:\windows\system32\xa21856953.exe
    c:\windows\system32\xa21854000.exe
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised by a trained Security Analyst

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is Unchecked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.
Hello there,
After I redid your original instructions,I followed the new ones.
Here are the logs.

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
c:\windows\system32\xa21856953.exe moved successfully.
c:\windows\system32\xa21854000.exe moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Client\LOCALS~1\Temp\~DF6C6.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Client\LOCALS~1\Temp\~DF6D1.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_1d8.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_2e4.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01182009_182942

Files moved on Reboot…
File C:\DOCUME~1\Client\LOCALS~1\Temp\~DF6C6.tmp not found!
File C:\DOCUME~1\Client\LOCALS~1\Temp\~DF6D1.tmp not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File C:\WINDOWS\temp\Perflib_Perfdata_1d8.dat not found!
C:\WINDOWS\temp\Perflib_Perfdata_2e4.dat moved successfully.

And the GMER Log

GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2009-01-18 19:18:00
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.14 —-

SSDT 86AFD3D8 ZwConnectPort
SSDT sptd.sys ZwCreateKey [0xF761B0D0]
SSDT sptd.sys ZwEnumerateKey [0xF7620FB2]
SSDT sptd.sys ZwEnumerateValueKey [0xF7621340]
SSDT sptd.sys ZwOpenKey [0xF761B0B0]
SSDT sptd.sys ZwQueryKey [0xF7621418]
SSDT sptd.sys ZwQueryValueKey [0xF7621298]
SSDT sptd.sys ZwSetValueKey [0xF76214AA]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xAE03FF20]

INT 0x06 \??\C:\WINDOWS\system32\drivers\Haspnt.sys (HASP Kernel Device Driver for Windows NT/Aladdin Knowledge Systems) ABA7116D
INT 0x0E \??\C:\WINDOWS\system32\drivers\Haspnt.sys (HASP Kernel Device Driver for Windows NT/Aladdin Knowledge Systems) ABA70FC2

—- Kernel code sections - GMER 1.0.14 —-

? C:\WINDOWS\system32\drivers\sptd.sys The process cannot access the file because it is being used by another process.
.text USBPORT.SYS!DllUnload F6E588AC 5 Bytes JMP 8735C1C8

—- Kernel IAT/EAT - GMER 1.0.14 —-

IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!IoConnectInterrupt] [F763206C] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F7632018] sptd.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F76549AE] sptd.sys
IAT atapi.sys[ntoskrnl.exe!IoConnectInterrupt] [F763206C] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F761BAD4] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F761BC1A] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F761BB9C] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F761C748] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F761C61E] sptd.sys

—- Devices - GMER 1.0.14 —-

Device \FileSystem\Ntfs \Ntfs 8735B1E8

AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)

Device \FileSystem\Fastfat \FatCdrom 86BF6430

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\NetBT \Device\NetBT_Tcpip_{9267197E-2DCD-4433-9043-6E697F54006C} 84D3C1E8
Device \Driver\usbuhci \Device\USBPDO-0 8724A5D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 8735D1E8
Device \Driver\dmio \Device\DmControl\DmConfig 8735D1E8
Device \Driver\dmio \Device\DmControl\DmPnP 8735D1E8
Device \Driver\dmio \Device\DmControl\DmInfo 8735D1E8
Device \Driver\usbuhci \Device\USBPDO-1 8724A5D8
Device \Driver\usbuhci \Device\USBPDO-2 8724A5D8
Device \Driver\usbuhci \Device\USBPDO-3 8724A5D8
Device \Driver\usbehci \Device\USBPDO-4 87210790

AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\Ftdisk \Device\HarddiskVolume1 873D01E8
Device \Driver\Cdrom \Device\CdRom0 87100790
Device \Driver\Cdrom \Device\CdRom1 87100790
Device \Driver\NetBT \Device\NetBt_Wins_Export 84D3C1E8
Device \Driver\NetBT \Device\NetbiosSmb 84D3C1E8

AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\NetBT \Device\NetBT_Tcpip_{8B97A32A-DD1D-46CA-A90E-72D93850DCF1} 84D3C1E8
Device \Driver\usbuhci \Device\USBFDO-0 8724A5D8
Device \Driver\usbuhci \Device\USBFDO-1 8724A5D8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 84564790
Device \Driver\usbuhci \Device\USBFDO-2 8724A5D8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 84564790
Device \Driver\usbuhci \Device\USBFDO-3 8724A5D8
Device \Driver\usbehci \Device\USBFDO-4 87210790
Device \Driver\Ftdisk \Device\FtControl 873D01E8
Device \FileSystem\Fastfat \Fat 86BF6430

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)

Device \FileSystem\Cdfs \Cdfs 86BD7790
Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)

—- Registry - GMER 1.0.14 —-

Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xB9 0x7C 0x14 0xA6 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xB9 0x7C 0x14 0xA6 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xB9 0x7C 0x14 0xA6 …
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xB9 0x7C 0x14 0xA6 …
Reg HKLM\SOFTWARE\Microsoft\Windows\Current Version\{8AC25C6A-D4B3-FF2F-2A61-C75CA1DB6116}\Install
Reg HKLM\SOFTWARE\Microsoft\Windows\Current Version\{8AC25C6A-D4B3-FF2F-2A61-C75CA1DB6116}\Install\VxDs
Reg HKLM\SOFTWARE\Microsoft\Windows\Current Version\{8AC25C6A-D4B3-FF2F-2A61-C75CA1DB6116}\Install\VxDs@CTE_32 Name 2454394:{301564B2-67A6-1A66-9C4E-A1FE91DE9752}
Reg HKLM\SOFTWARE\Microsoft\Windows\Current Version\{ADD916B7-3238-B642-38AC-F31A4E6EE8C3}\Install
Reg HKLM\SOFTWARE\Microsoft\Windows\Current Version\{ADD916B7-3238-B642-38AC-F31A4E6EE8C3}\Install\VxDs
Reg HKLM\SOFTWARE\Microsoft\Windows\Current Version\{ADD916B7-3238-B642-38AC-F31A4E6EE8C3}\Install\VxDs@DefaultSettings -19:{3C7DA433-1047-9FC4-00BA-978A09424856}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Install
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Install\xga-1-{F997431D-28AF-BB84-0050-670A83CDD3AD}
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Install\xga-1-{F997431D-28AF-BB84-0050-670A83CDD3AD}\Version 1.1
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Install\xga-1-{F997431D-28AF-BB84-0050-670A83CDD3AD}\Version 1.1@dat 806585365:{4BB5A823-C93C-5B32-AAC1-52CE2226230B}
Reg HKLM\SOFTWARE\Microsoft\Windows Install VBX
Reg HKLM\SOFTWARE\Microsoft\Windows Install VBX\Current
Reg HKLM\SOFTWARE\Microsoft\Windows Install VBX\Current\Install
Reg HKLM\SOFTWARE\Microsoft\Windows Install VBX\Current\Install\xga-1-{F997431D-28AF-BB84-0050-670A83CDD3AD}
Reg HKLM\SOFTWARE\Microsoft\Windows Install VBX\Current\Install\xga-1-{F997431D-28AF-BB84-0050-670A83CDD3AD}\Version 3.x
Reg HKLM\SOFTWARE\Microsoft\Windows Install VBX\Current\Install\xga-1-{F997431D-28AF-BB84-0050-670A83CDD3AD}\Version 3.x@dat 1767914624:{08169AB5-B966-6746-7018-F62714647642}
Reg HKLM\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version
Reg HKLM\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version@Version 0x52 0xCD 0x81 0x8A …

—- EOF - GMER 1.0.14 —-

Cheers
hello

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
Hello Rorschach112 I ran the first log and I'll post that log. I attempted to run Kaspersky several times but was told that : Java applet failed. Not sure a of way around it. Cheers - Rox Malwarebytes' Anti-Malware 1.33 Database version: 1668 Windows 5.1.2600 Service Pack 3 1/19/2009 9:20:39 PM mbam-log-2009-01-19 (21-20-39).txt Scan type: Quick Scan Objects scanned: 68637 Time elapsed: 5 minute(s), 22 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 3 Registry Values Infected: 1 Registry Data Items Infected: 9 Folders Infected: 1 Files Infected: 7 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\videoplay (Trojan.DNSChanger) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Startup Manager (Backdoor.Bot) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.113.117,85.255.112.26 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8b97a32a-dd1d-46ca-a90e-72d93850dcf1}\NameServer (Trojan.DNSChanger) -> Data: 85.255.113.117,85.255.112.26 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9267197e-2dcd-4433-9043-6e697f54006c}\NameServer (Trojan.DNSChanger) -> Data: 85.255.113.117,85.255.112.26 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.113.117,85.255.112.26 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{8b97a32a-dd1d-46ca-a90e-72d93850dcf1}\NameServer (Trojan.DNSChanger) -> Data: 85.255.113.117,85.255.112.26 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{9267197e-2dcd-4433-9043-6e697f54006c}\NameServer (Trojan.DNSChanger) -> Data: 85.255.113.117,85.255.112.26 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.113.117,85.255.112.26 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Tcpip\Parameters\Interfaces\{8b97a32a-dd1d-46ca-a90e-72d93850dcf1}\NameServer (Trojan.DNSChanger) -> Data: 85.255.113.117,85.255.112.26 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Tcpip\Parameters\Interfaces\{9267197e-2dcd-4433-9043-6e697f54006c}\NameServer (Trojan.DNSChanger) -> Data: 85.255.113.117,85.255.112.26 -> Quarantined and deleted successfully. Folders Infected: C:\Documents and Settings\Client\Start Menu\Programs\totalvid (Trojan.DNSChanger) -> Quarantined and deleted successfully. Files Infected: C:\WINDOWS\system32\gaopdxypnbodqw.dll (Trojan.DNSChanger) -> Quarantined and deleted successfully. C:\Program Files\Mozilla Firefox\Components\iamfamous.dll (Spyware.Passwords) -> Quarantined and deleted successfully. C:\Documents and Settings\Client\Local Settings\temp\tmp322.tmp (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\Client\Start Menu\Programs\totalvid\Uninstall.lnk (Trojan.DNSChanger) -> Quarantined and deleted successfully. C:\Program Files\Advanced System Optimizer\startUp manager.exe (Backdoor.Bot) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tempo-1CD.tmp (Trojan.DNSChanger) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\tempo-AF7.tmp (Trojan.DNSChanger) -> Quarantined and deleted successfully.
hello

Please click here to download AVP Tool by Kaspersky.
  • Save it to your desktop.
  • Reboot your computer into SafeMode.

    You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
    Use your up arrow key to highlight SafeMode then hit enter
    .

  • Double click the setup file to run it.
  • Click Next to continue.
  • It will by default install it to your desktop folder.Click Next.
  • Hit ok at the prompt for scanning in Safe Mode.
  • It will then open a box There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.

  • System Memory
  • Startup Objects
  • Disk Boot Sectors.
  • My Computer.
  • Also any other drives (Removable that you may have)


  • Then click on Scan at the to right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left unneutralized then click the button that says Neutralize all
  • If it says it cannot be Neutralized then chooose The delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file name it Kas.
  • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.





It sounds like a case of Zlob/DNSchanger that change the router's DNS settings. Please download Malwarebytes' Anti-Malware from Here or Here

Next disconnect your system from the internet, and your router, then…

Double Click mbam-setup.exe to install the application.
  • Launch Malwarebytes' Anti-Malware, then click Finish.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
===============================================

Next you must reset the router to its default configuration. This can be done by inserting something tiny like a paper clip end or pencil tip into a small hole labeled "reset" located on the back of the router. Press and hold down the small button inside until the lights on the front of the router blink off and then on again (usually about 10 seconds). If you don’t know the router's default password, you can look it up HERE

However, if there are other Zlob-infected machines using the same router, they will need to be cleared with the above steps before resetting the router. Otherwise, the malware will simply go back and change the router's DNS settings. You also need to reconfigure any security settings you had in place prior to the reset. Check out this site here for video tutorials on how to properly configure your router's encryption and security settings. You may also need to consult with your Internet service provider to find out which DNS servers your network should be using.

Once you have ran Malwarebytes' Anti-Malware on the infected system, and reset the router to its default configuration you can reconnect to the internet, and router. Then return to this site to post your logs.

===============================================

Please post the Malwarebytes log and let me know how things are running now :thumbsup:
Hello Rorschach112 I tried to download Kaspersky from your link and was unable to,once again, so I got it from a bittorrent. I installed it but found I could not get online anymore to follow your instructions. Rereading them ,I realized that you wanted me to install them in Safe mode, so I uninstalled it, rebooted in Safe mode and was told that I could not install due to some sorta Administrator prohibition. I rebooted again in Safe mode as the Administrator and was told the same thing.To my obviously very limited knowledge, I AM the Administrator(?) What gives? Please excuse my tardy responses as my day job is very far removed from a keyboard. Cheers - Rox P.S. I believe I already ran a Malwarebytes' Anti-Malware scan. Did you want me to do this again?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI