Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

wow.. slow computer with popups **HELP**


  • This topic is locked This topic is locked
13 replies to this topic

#1 ClassX

ClassX

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:10:46 AM

Posted 29 April 2009 - 06:01 PM

Hey i was wondering if anyone could help me out. I have been geting a great amount of pop ups lately, and their really annoying. I ran malwarebytes and it got rid of alot of stuff, but i dont think its everything. Please help if you can. Im begging YOU


DDS (Ver_09-03-16.01) - NTFSx86
Run by Kristian at 18:55:47.14 on Wed 04/29/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.760.384 [GMT -4:00]

AV: avast! antivirus 4.8.1335 [VPS 090429-0] *On-access scanning enabled* (Updated)

============== Running Processes ===============

D:\WINDOWS\System32\Ati2evxx.exe
D:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
D:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
D:\Program Files\Alwil Software\Avast4\ashServ.exe
D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
D:\WINDOWS\system32\rundll32.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\WINDOWS\system32\msiexec.exe
D:\Program Files\Windows Live\Messenger\msnmsgr.exe
D:\Program Files\Windows Live\Contacts\wlcomm.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
D:\Documents and Settings\Kristian\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - d:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [autochk] rundll32.exe d:\docume~1\kristian\protect.dll,_IWMPEvents@16
mRun: [autochk] rundll32.exe d:\windows\system32\autochk.dll,_IWMPEvents@16
mRun: [avast!] d:\progra~1\alwils~1\avast4\ashDisp.exe
dRun: [autochk] rundll32.exe d:\docume~1\locals~1\protect.dll,_IWMPEvents@16
StartupFolder: d:\documents and settings\kristian\start menu\programs\startup\ChkDisk.dll
StartupFolder: d:\docume~1\kristian\startm~1\programs\startup\chkdisk.lnk - d:\windows\system32\rundll32.exe
dPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
dPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
dPolicies-system: DisableTaskMgr = 1 (0x1)
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - d:\program files\messenger\msmsgs.exe
Notify: AtiExtEvent - Ati2evxx.dll

================= FIREFOX ===================

FF - ProfilePath - d:\docume~1\kristian\applic~1\mozilla\firefox\profiles\ylkmy3tq.default\

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;d:\windows\system32\drivers\aswSP.sys [2009-4-29 114768]
R2 aswFsBlk;aswFsBlk;d:\windows\system32\drivers\aswFsBlk.sys [2009-4-29 20560]
R2 avast! Antivirus;avast! Antivirus;d:\program files\alwil software\avast4\ashServ.exe [2009-4-29 138680]
R3 avast! Mail Scanner;avast! Mail Scanner;d:\program files\alwil software\avast4\ashMaiSv.exe [2009-4-29 254040]
R3 avast! Web Scanner;avast! Web Scanner;d:\program files\alwil software\avast4\ashWebSv.exe [2009-4-29 352920]

=============== Created Last 30 ================

2009-04-29 18:54 <DIR> --d----- d:\program files\Trend Micro
2009-04-29 18:49 <DIR> --d----- d:\documents and settings\kristian\Tracing
2009-04-29 18:48 <DIR> --d----- d:\program files\Microsoft
2009-04-29 18:48 <DIR> --d----- d:\program files\Windows Live SkyDrive
2009-04-29 18:42 <DIR> --d----- d:\program files\common files\Windows Live
2009-04-29 18:18 <DIR> --d----- d:\windows\system32\PreInstall
2009-04-29 18:18 <DIR> --d-h--- d:\windows\$hf_mig$
2009-04-29 16:34 1,060,864 a------- d:\windows\system32\MFC71.dll
2009-04-29 16:34 499,712 a------- d:\windows\system32\MSVCP71.dll
2009-04-29 16:34 348,160 a------- d:\windows\system32\MSVCR71.dll
2009-04-29 16:32 24,064 a--sh--- d:\windows\system32\autochk.dll
2009-04-29 16:32 24,064 a--sh--- d:\documents and settings\kristian\protect.dll
2009-04-29 16:32 27,648 a------- d:\windows\system32\lmppcsetup.exe
2009-04-29 16:11 <DIR> --d----- d:\docume~1\kristian\applic~1\Malwarebytes
2009-04-29 16:11 15,504 a------- d:\windows\system32\drivers\mbam.sys
2009-04-29 16:11 38,496 a------- d:\windows\system32\drivers\mbamswissarmy.sys
2009-04-29 16:11 <DIR> --d----- d:\program files\Malwarebytes' Anti-Malware
2009-04-29 16:11 <DIR> --d----- d:\docume~1\alluse~1\applic~1\Malwarebytes
2009-04-29 15:50 <DIR> --ds---- d:\documents and settings\kristian\UserData
2009-04-28 23:00 1 a------- d:\windows\system32\uniq.tll
2009-04-28 22:12 1,398,506 ---sh--- d:\windows\system32\ifobejan.ini
2009-04-28 22:05 122,912 a--sh--- d:\windows\system32\drivers\fidbox2.dat
2009-04-28 22:05 1,500 a--sh--- d:\windows\system32\drivers\fidbox2.idx
2009-04-28 22:05 32 a--sh--- d:\windows\system32\drivers\fidbox.idx
2009-04-28 22:05 32 a--sh--- d:\windows\system32\drivers\fidbox.dat
2009-04-28 22:04 <DIR> --d----- d:\docume~1\alluse~1\applic~1\Kaspersky Lab Setup Files
2009-04-28 21:53 <DIR> --d----- d:\windows\system32\SoftwareDistribution
2009-04-28 21:39 <DIR> --d----- d:\windows\ServicePackFiles
2009-04-28 21:37 2,897,920 -------- d:\windows\system32\xpsp2res.dll
2009-04-28 21:36 19,528 a------- d:\windows\002236_.tmp
2009-04-28 21:36 22,752 a------- d:\windows\system32\spupdsvc.exe
2009-04-28 21:34 <DIR> --d----- d:\windows\EHome
2009-04-28 20:25 520,192 -------- d:\windows\system32\ati2sgag.exe
2009-04-28 20:25 <DIR> --d----- d:\windows\system32\ReinstallBackups
2009-04-28 20:24 <DIR> --d----- d:\program files\ATI Technologies
2009-04-28 20:14 <DIR> --ds---- d:\windows\system32\Microsoft
2009-04-28 20:14 6,400 a------- d:\windows\system32\drivers\splitter.sys
2009-04-28 20:14 82,944 a------- d:\windows\system32\drivers\wdmaud.sys
2009-04-28 20:14 52,864 a------- d:\windows\system32\drivers\dmusic.sys
2009-04-28 20:14 54,272 ac------ d:\windows\system32\dllcache\swmidi.sys
2009-04-28 20:14 54,272 a------- d:\windows\system32\drivers\swmidi.sys
2009-04-28 20:14 577,536 a------- d:\windows\soundman.exe
2009-04-28 20:14 49,152 a------- d:\windows\system32\ChCfg.exe
2009-04-28 20:13 <DIR> --d----- d:\program files\Realtek AC97
2009-04-28 20:07 <DIR> --dsh--- d:\windows\Installer
2009-04-28 20:07 <DIR> --d----- d:\documents and settings\Kristian
2009-04-28 20:06 8,192 a------- d:\windows\REGLOCS.OLD
2009-04-28 20:03 471,102 ac------ d:\windows\system32\dllcache\imskdic.dll
2009-04-28 20:02 2,626 a------- d:\windows\system32\CONFIG.NT
2009-04-28 20:02 0 a------- d:\windows\control.ini
2009-04-28 20:02 25,065 a------- d:\windows\system32\wmpscheme.xml
2009-04-28 20:02 23,392 a------- d:\windows\system32\nscompat.tlb
2009-04-28 20:02 16,832 a------- d:\windows\system32\amcompat.tlb
2009-04-28 20:02 299,552 a------- d:\windows\WMSysPrx.prx
2009-04-28 20:01 <DIR> --dsh--- d:\documents and settings\all users\DRM
2009-04-28 20:01 488 a---hr-- d:\windows\system32\WindowsLogon.manifest
2009-04-28 20:01 488 a---hr-- d:\windows\system32\logonui.exe.manifest
2009-04-28 20:01 <DIR> --ds---- d:\windows\Downloaded Program Files
2009-04-28 20:01 <DIR> --d--r-- d:\windows\Offline Web Pages
2009-04-28 20:01 749 a---hr-- d:\windows\WindowsShell.Manifest
2009-04-28 20:01 749 a---hr-- d:\windows\system32\wuaucpl.cpl.manifest
2009-04-28 20:01 749 a---hr-- d:\windows\system32\sapi.cpl.manifest
2009-04-28 20:01 749 a---hr-- d:\windows\system32\nwc.cpl.manifest
2009-04-28 20:01 749 a---hr-- d:\windows\system32\ncpa.cpl.manifest
2009-04-28 20:01 749 a---hr-- d:\windows\system32\cdplayer.exe.manifest
2009-04-28 20:01 4,399,505 ac------ d:\windows\system32\dllcache\nls302en.lex
2009-04-28 20:01 <DIR> --d----- d:\windows\system32\DirectX
2009-04-28 20:00 <DIR> --d----- d:\program files\common files\MSSoap
2009-04-28 19:59 <DIR> --d-h--- d:\program files\WindowsUpdate
2009-04-28 19:59 <DIR> --d----- d:\program files\Online Services
2009-04-28 19:59 <DIR> --d----- d:\program files\MSN Gaming Zone
2009-04-28 19:58 <DIR> --d----- d:\program files\Windows NT
2009-04-28 15:23 <DIR> --d----- d:\program files\common files\ODBC
2009-04-28 15:23 <DIR> --d----- d:\program files\common files\SpeechEngines
2009-04-28 15:22 <DIR> --d--r-- d:\documents and settings\all users\Documents

==================== Find3M ====================

2009-04-28 22:12 88,064 a--sh--- d:\windows\system32\bubopoyu.dll
2009-04-28 22:12 51,200 a--sh--- d:\windows\system32\hebedogu.exe
2009-04-28 21:43 86,327 a------- d:\windows\pchealth\helpctr\offlinecache\index.dat
2009-04-28 19:59 21,640 a------- d:\windows\system32\emptyregdb.dat
2009-02-06 18:52 49,504 a------- d:\windows\system32\sirenacm.dll

============= FINISH: 18:56:02.54 ===============




UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-03-16.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 4/28/2009 8:05:03 PM
System Uptime: 4/29/2009 6:38:25 PM (0 hours ago)

Motherboard: ASUSTeK Computer INC. | | KIRIN-V
Processor: Intel® Pentium® 4 CPU 2.66GHz | PGA 478 | 2680/133mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 14 GiB total, 8.373 GiB free.
D: is FIXED (NTFS) - 93 GiB total, 88.451 GiB free.
E: is CDROM ()
F: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Video Controller (VGA Compatible)
Device ID: PCI\VEN_8086&DEV_2562&SUBSYS_813B104D&REV_03\3&61AAA01&0&10
Manufacturer:
Name: Video Controller (VGA Compatible)
PNP Device ID: PCI\VEN_8086&DEV_2562&SUBSYS_813B104D&REV_03\3&61AAA01&0&10
Service:

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Camera
Device ID: USB\VID_046D&PID_08F0\5&380B3931&0&2
Manufacturer:
Name: Camera
PNP Device ID: USB\VID_046D&PID_08F0\5&380B3931&0&2
Service:

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: PCI Modem
Device ID: PCI\VEN_8086&DEV_24C6&SUBSYS_8128104D&REV_02\3&61AAA01&0&FE
Manufacturer:
Name: PCI Modem
PNP Device ID: PCI\VEN_8086&DEV_24C6&SUBSYS_8128104D&REV_02\3&61AAA01&0&FE
Service:

==== System Restore Points ===================

RP1: 4/28/2009 8:07:47 PM - System Checkpoint
RP2: 4/28/2009 8:13:26 PM - Installed Realtek AC'97 Audio
RP3: 4/28/2009 9:36:34 PM - Installed Windows XP Service Pack 2.
RP4: 4/28/2009 10:04:52 PM - Installed Kaspersky Internet Security 2009.
RP5: 4/29/2009 4:28:38 PM - Removed Kaspersky Internet Security 2009.
RP6: 4/29/2009 6:18:35 PM - Software Distribution Service 3.0
RP7: 4/29/2009 6:37:07 PM - Installed Windows Installer KB893803v2.

==== Installed Programs ======================

Adobe Flash Player 10 Plugin
ATI - Software Uninstall Utility
ATI Display Driver
avast! Antivirus
Choice Guard
HijackThis 2.0.2
Malwarebytes' Anti-Malware
Microsoft Application Error Reporting
Mozilla Firefox (3.0.10)
MSVCRT
Realtek AC'97 Audio
Segoe UI
Update for Windows XP (KB898461)
WebFldrs XP
Windows Installer 3.1 (KB893803)
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Upload Tool
Windows XP Service Pack 2
WinRAR archiver

==== Event Viewer Messages From Past Week ========

4/29/2009 4:18:00 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: PCIIde
4/29/2009 3:56:28 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
4/28/2009 10:07:18 PM, error: Service Control Manager [7031] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.

==== End Of File ===========================

BC AdBot (Login to Remove)

 


#2 ClassX

ClassX
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:10:46 AM

Posted 02 May 2009 - 08:57 AM

Does anyone see any problems?
============
Hello

While we understand your frustration at having to wait, please note that Bleeping Computer deals with several hundred requests for assistance such as yours on a daily basis. As a result, our backlog is quite large as are other comparable sites that help others with malware issues. Although our HJT Team members work on hundreds of requests each day, they are all volunteers who work logs when they can and are able to do so. No one is paid by Bleeping Computer for their assistance to our members.

Further, our malware removal staff is comprised of team members with various levels of skill and expertise to deal with thousands of malware variants, some more complex than others. Although we try to take DDS/HJT logs in order (starting with the oldest), it is often the skill level of the particular helper and sometimes the operating system that dictates which logs get selected first. Some infections are more complicated than others and require a higher skill level to remove. Without that skill level attempted removal could result in disastrous results. In other instances, the helper may not be familiar with the operating system that you are using, since they use another. In either case, neither of us want someone to assist you who is not familiar with your issue and attempt to fix it.

We ask that once you have posted your log and are waiting, please DO NOT "bump" your thread or make further replies until it has been responded to by a member of the HJT Team. The reason we ask this or do not respond to your requests is because that would remove you from the active queue that Techs and Staff have access to. The malware staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response, there will be 1 reply. A team member, looking for a new log to work may assume another HJT Team member is already assisting you and not open the thread to respond.

That is why I have made an edit to your last post, instead of a reply. Please do not multiple post here, as that only pushes you further down the queue and causes confusion to the staff.

Please be patient. It may take a while to get a response but your log will be reviewed and answered as soon as possible.

Thank you for understanding.

Orange Blossom ~ forum moderator

Edited by Orange Blossom, 06 May 2009 - 11:20 PM.


#3 Orange Blossom

Orange Blossom

    OBleepin Investigator


  • Moderator
  • 36,960 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:10:46 AM

Posted 11 May 2009 - 10:39 PM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.

Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results, click no to the Optional_Scan
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. You can find information on A/V control HERE

Orange Blossom :thumbup2:
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript

#4 ClassX

ClassX
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:10:46 AM

Posted 16 May 2009 - 10:58 AM

DDS (Ver_09-05-14.01) - NTFSx86
Run by Kristian at 11:56:53.32 on Sat 05/16/2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.760.331 [GMT -4:00]

AV: avast! antivirus 4.8.1335 [VPS 090515-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

D:\WINDOWS\System32\Ati2evxx.exe
D:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
D:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
D:\Program Files\Alwil Software\Avast4\ashServ.exe
D:\WINDOWS\system32\rundll32.exe
D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Documents and Settings\Kristian\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
svchost.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\WINDOWS\system32\HPZipm12.exe
D:\WINDOWS\System32\svchost.exe -k imgsvc
D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Windows Live\Messenger\msnmsgr.exe
D:\Program Files\Windows Live\Contacts\wlcomm.exe
D:\Documents and Settings\Kristian\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - d:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - d:\progra~1\micros~4\office12\GRA8E1~1.DLL
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - d:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - d:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [autochk] rundll32.exe d:\docume~1\kristian\protect.dll,_IWMPEvents@16
uRun: [Google Update] "d:\documents and settings\kristian\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [ctfmon.exe] d:\windows\system32\ctfmon.exe
mRun: [autochk] rundll32.exe d:\windows\system32\autochk.dll,_IWMPEvents@16
mRun: [avast!] d:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [Adobe Reader Speed Launcher] "d:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "d:\program files\java\jre6\bin\jusched.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [GrooveMonitor] "d:\program files\microsoft office\office12\GrooveMonitor.exe"
dRun: [autochk] rundll32.exe d:\docume~1\locals~1\protect.dll,_IWMPEvents@16
StartupFolder: d:\documents and settings\kristian\start menu\programs\startup\ChkDisk.dll
StartupFolder: d:\docume~1\kristian\startm~1\programs\startup\chkdisk.lnk - d:\windows\system32\rundll32.exe
dPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
dPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
dPolicies-system: DisableTaskMgr = 1 (0x1)
IE: E&xport to Microsoft Excel - d:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - d:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - d:\progra~1\micros~4\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - d:\progra~1\micros~4\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - d:\progra~1\micros~4\office12\GR99D3~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - d:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - d:\progra~1\micros~4\office12\GRA8E1~1.DLL

================= FIREFOX ===================

FF - ProfilePath - d:\docume~1\kristian\applic~1\mozilla\firefox\profiles\ylkmy3tq.default\
FF - plugin: d:\documents and settings\kristian\local settings\application data\google\update\1.2.145.5\npGoogleOneClick8.dll

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;d:\windows\system32\drivers\aswSP.sys [2009-4-29 114768]
R2 aswFsBlk;aswFsBlk;d:\windows\system32\drivers\aswFsBlk.sys [2009-4-29 20560]
R2 avast! Antivirus;avast! Antivirus;d:\program files\alwil software\avast4\ashServ.exe [2009-4-29 138680]
R3 avast! Mail Scanner;avast! Mail Scanner;d:\program files\alwil software\avast4\ashMaiSv.exe [2009-4-29 254040]
R3 avast! Web Scanner;avast! Web Scanner;d:\program files\alwil software\avast4\ashWebSv.exe [2009-4-29 352920]

=============== Created Last 30 ================

2009-05-15 17:27 32,592 a------- d:\windows\system32\msonpmon.dll
2009-05-15 17:00 <DIR> --d----- d:\windows\SHELLNEW
2009-05-12 08:02 <DIR> --d----- d:\program files\uTorrent
2009-05-12 08:02 <DIR> --d----- d:\docume~1\kristian\applic~1\uTorrent
2009-05-12 03:00 <DIR> --d----- d:\windows\system32\KB905474
2009-05-11 21:10 73,728 a------- d:\windows\system32\javacpl.cpl
2009-05-10 10:10 <DIR> --d----- d:\program files\Web Publish
2009-05-09 10:21 <DIR> --d----- d:\program files\common files\Hewlett-Packard
2009-05-09 10:20 38,400 a------- d:\windows\system32\hpz3l054.dll
2009-05-09 10:19 282,680 a------- d:\windows\system32\HPZidr12.dll
2009-05-09 10:19 204,800 a------- d:\windows\system32\HPZipr12.dll
2009-05-09 10:19 94,208 a------- d:\windows\system32\HPZipt12.dll
2009-05-09 10:19 69,632 a------- d:\windows\system32\HPZipm12.exe
2009-05-09 10:19 65,536 a------- d:\windows\system32\HPZinw12.exe
2009-05-09 10:19 57,344 a------- d:\windows\system32\HPZisn12.dll
2009-05-09 10:19 306,688 a------- d:\windows\IsUninst.exe
2009-05-09 10:18 <DIR> --d----- d:\program files\HP
2009-05-09 10:18 25,856 ac------ d:\windows\system32\dllcache\usbprint.sys
2009-05-09 10:18 25,856 a------- d:\windows\system32\drivers\usbprint.sys
2009-05-09 10:18 32,128 ac------ d:\windows\system32\dllcache\usbccgp.sys
2009-05-09 10:18 32,128 a------- d:\windows\system32\drivers\usbccgp.sys
2009-05-09 10:18 110,389 a------- d:\windows\hpoins11.dat
2009-05-09 10:18 49,664 a------- d:\windows\system32\drivers\HPZid412.sys
2009-05-09 10:18 21,568 a------- d:\windows\system32\drivers\HPZius12.sys
2009-05-09 10:18 16,496 a------- d:\windows\system32\drivers\HPZipr12.sys
2009-05-09 10:17 827,392 a------- d:\windows\system32\hpotiop2.dll
2009-05-09 10:17 659,456 a------- d:\windows\system32\hpowiax2.dll
2009-05-09 10:17 282,624 a------- d:\windows\system32\HPZc3212.dll
2009-05-09 10:17 254,026 a------- d:\windows\system32\hpovst09.dll
2009-05-09 10:17 98,304 a------- d:\windows\system32\hpzjsn01.dll
2009-05-09 10:17 77,824 a------- d:\windows\system32\HPZIDS01.dll
2009-05-09 10:17 6,947 a------- d:\windows\hpomdl11.dat
2009-05-07 08:09 <DIR> --d----- d:\program files\Messenger
2009-05-07 08:09 <DIR> --d----- d:\windows\system32\scripting
2009-05-07 08:09 <DIR> --d----- d:\windows\system32\en
2009-05-07 08:09 <DIR> --d----- d:\windows\l2schemas
2009-05-07 08:09 <DIR> --d----- d:\windows\system32\bits
2009-05-07 08:07 <DIR> --d----- d:\windows\network diagnostic
2009-05-03 22:13 118 a------- d:\windows\system32\MRT.INI
2009-05-02 21:13 221,184 a------- d:\windows\system32\wmpns.dll
2009-05-02 16:27 410,984 a------- d:\windows\system32\deploytk.dll
2009-05-02 16:16 159,232 a------- d:\windows\system32\ptpusd.dll
2009-05-02 16:16 5,632 a------- d:\windows\system32\ptpusb.dll
2009-05-02 16:16 15,104 a------- d:\windows\system32\drivers\usbscan.sys
2009-05-02 11:18 <DIR> --d----- D:\ClassX
2009-05-02 10:27 <DIR> --d----- d:\program files\Windows Media Connect 2
2009-04-30 19:38 397,312 -------- d:\windows\system32\mmcex.dll
2009-04-30 12:09 268,648 a------- d:\windows\system32\mucltui.dll
2009-04-30 12:09 208,744 a------- d:\windows\system32\muweb.dll
2009-04-30 12:09 27,496 a------- d:\windows\system32\mucltui.dll.mui
2009-04-29 18:54 <DIR> --d----- d:\program files\Trend Micro
2009-04-29 18:49 <DIR> --d----- d:\documents and settings\kristian\Tracing
2009-04-29 18:48 <DIR> --d----- d:\program files\Microsoft
2009-04-29 18:48 <DIR> --d----- d:\program files\Windows Live SkyDrive
2009-04-29 18:42 <DIR> --d----- d:\program files\common files\Windows Live
2009-04-29 18:27 272,128 -c------ d:\windows\system32\dllcache\bthport.sys
2009-04-29 18:24 473,600 -c------ d:\windows\system32\dllcache\fastprox.dll
2009-04-29 18:24 401,408 -c------ d:\windows\system32\dllcache\rpcss.dll
2009-04-29 18:24 284,160 -c------ d:\windows\system32\dllcache\pdh.dll
2009-04-29 18:24 110,592 -c------ d:\windows\system32\dllcache\services.exe
2009-04-29 18:24 729,088 -c------ d:\windows\system32\dllcache\lsasrv.dll
2009-04-29 18:24 617,472 -c------ d:\windows\system32\dllcache\advapi32.dll
2009-04-29 18:24 453,120 -c------ d:\windows\system32\dllcache\wmiprvsd.dll
2009-04-29 18:24 227,840 -c------ d:\windows\system32\dllcache\wmiprvse.exe
2009-04-29 18:24 714,752 -c------ d:\windows\system32\dllcache\ntdll.dll
2009-04-29 18:24 2,145,280 -c------ d:\windows\system32\dllcache\ntkrnlmp.exe
2009-04-29 18:24 2,189,056 -c------ d:\windows\system32\dllcache\ntoskrnl.exe
2009-04-29 18:24 2,023,936 -c------ d:\windows\system32\dllcache\ntkrpamp.exe
2009-04-29 18:21 203,136 -c------ d:\windows\system32\dllcache\rmcast.sys
2009-04-29 18:20 455,296 -c------ d:\windows\system32\dllcache\mrxsmb.sys
2009-04-29 18:20 333,952 -c------ d:\windows\system32\dllcache\srv.sys
2009-04-29 18:20 331,776 -c------ d:\windows\system32\dllcache\msadce.dll
2009-04-29 18:20 691,712 -c------ d:\windows\system32\dllcache\inetcomm.dll
2009-04-29 18:19 337,408 -c------ d:\windows\system32\dllcache\netapi32.dll
2009-04-29 18:19 1,106,944 -c------ d:\windows\system32\dllcache\msxml3.dll
2009-04-29 18:19 1,203,922 -c------ d:\windows\system32\dllcache\sysmain.sdb
2009-04-29 18:19 2,560 -------- d:\windows\system32\xpsp4res.dll
2009-04-29 18:19 215,552 -c------ d:\windows\system32\dllcache\wordpad.exe
2009-04-29 18:18 <DIR> --d----- d:\windows\system32\PreInstall
2009-04-29 18:18 <DIR> --d-h--- d:\windows\$hf_mig$
2009-04-29 18:18 247,326 -c------ d:\windows\system32\dllcache\strmdll.dll
2009-04-29 16:34 1,060,864 a------- d:\windows\system32\MFC71.dll
2009-04-29 16:34 499,712 a------- d:\windows\system32\MSVCP71.dll
2009-04-29 16:34 348,160 a------- d:\windows\system32\MSVCR71.dll
2009-04-29 16:32 24,064 a--sh--- d:\windows\system32\autochk.dll
2009-04-29 16:32 24,064 a--sh--- d:\documents and settings\kristian\protect.dll
2009-04-29 16:32 27,648 a------- d:\windows\system32\lmppcsetup.exe
2009-04-29 16:11 <DIR> --d----- d:\docume~1\kristian\applic~1\Malwarebytes
2009-04-29 16:11 15,504 a------- d:\windows\system32\drivers\mbam.sys
2009-04-29 16:11 38,496 a------- d:\windows\system32\drivers\mbamswissarmy.sys
2009-04-29 16:11 <DIR> --d----- d:\program files\Malwarebytes' Anti-Malware
2009-04-29 16:11 <DIR> --d----- d:\docume~1\alluse~1\applic~1\Malwarebytes
2009-04-29 15:50 <DIR> --ds---- d:\documents and settings\kristian\UserData
2009-04-28 23:00 1 a------- d:\windows\system32\uniq.tll
2009-04-28 22:12 1,398,506 ---sh--- d:\windows\system32\ifobejan.ini
2009-04-28 22:05 122,912 a--sh--- d:\windows\system32\drivers\fidbox2.dat
2009-04-28 22:05 1,500 a--sh--- d:\windows\system32\drivers\fidbox2.idx
2009-04-28 22:05 32 a--sh--- d:\windows\system32\drivers\fidbox.idx
2009-04-28 22:05 32 a--sh--- d:\windows\system32\drivers\fidbox.dat
2009-04-28 22:04 <DIR> --d----- d:\docume~1\alluse~1\applic~1\Kaspersky Lab Setup Files
2009-04-28 21:53 <DIR> --d----- d:\windows\system32\SoftwareDistribution
2009-04-28 21:39 <DIR> --d----- d:\windows\ServicePackFiles
2009-04-28 21:37 2,897,920 -------- d:\windows\system32\xpsp2res.dll
2009-04-28 21:36 19,528 a------- d:\windows\002236_.tmp
2009-04-28 21:36 26,488 a------- d:\windows\system32\spupdsvc.exe
2009-04-28 21:34 <DIR> --d----- d:\windows\EHome
2009-04-28 20:25 520,192 -------- d:\windows\system32\ati2sgag.exe
2009-04-28 20:25 <DIR> --d----- d:\windows\system32\ReinstallBackups
2009-04-28 20:24 <DIR> --d----- d:\program files\ATI Technologies
2009-04-28 20:14 <DIR> --ds---- d:\windows\system32\Microsoft
2009-04-28 20:14 6,272 a------- d:\windows\system32\drivers\splitter.sys
2009-04-28 20:14 83,072 a------- d:\windows\system32\drivers\wdmaud.sys
2009-04-28 20:14 52,864 a------- d:\windows\system32\drivers\dmusic.sys
2009-04-28 20:14 56,576 a------- d:\windows\system32\drivers\swmidi.sys
2009-04-28 20:14 577,536 a------- d:\windows\soundman.exe
2009-04-28 20:14 49,152 a------- d:\windows\system32\ChCfg.exe
2009-04-28 20:13 <DIR> --d----- d:\program files\Realtek AC97
2009-04-28 20:07 <DIR> --dsh--- d:\windows\Installer
2009-04-28 20:07 <DIR> --d----- d:\documents and settings\Kristian
2009-04-28 20:06 8,192 a------- d:\windows\REGLOCS.OLD
2009-04-28 20:03 471,102 ac------ d:\windows\system32\dllcache\imskdic.dll
2009-04-28 20:02 2,626 a------- d:\windows\system32\CONFIG.NT
2009-04-28 20:02 0 a------- d:\windows\control.ini
2009-04-28 20:02 25,065 a------- d:\windows\system32\wmpscheme.xml
2009-04-28 20:02 23,392 a------- d:\windows\system32\nscompat.tlb
2009-04-28 20:02 16,832 a------- d:\windows\system32\amcompat.tlb
2009-04-28 20:02 299,552 a------- d:\windows\WMSysPrx.prx
2009-04-28 20:01 <DIR> --dsh--- d:\documents and settings\all users\DRM
2009-04-28 20:01 488 a---hr-- d:\windows\system32\WindowsLogon.manifest
2009-04-28 20:01 488 a---hr-- d:\windows\system32\logonui.exe.manifest
2009-04-28 20:01 <DIR> --ds---- d:\windows\Downloaded Program Files
2009-04-28 20:01 <DIR> --d--r-- d:\windows\Offline Web Pages
2009-04-28 20:01 749 a---hr-- d:\windows\WindowsShell.Manifest
2009-04-28 20:01 749 a---hr-- d:\windows\system32\wuaucpl.cpl.manifest
2009-04-28 20:01 749 a---hr-- d:\windows\system32\sapi.cpl.manifest
2009-04-28 20:01 749 a---hr-- d:\windows\system32\nwc.cpl.manifest
2009-04-28 20:01 749 a---hr-- d:\windows\system32\ncpa.cpl.manifest
2009-04-28 20:01 749 a---hr-- d:\windows\system32\cdplayer.exe.manifest
2009-04-28 20:01 4,399,505 ac------ d:\windows\system32\dllcache\nls302en.lex
2009-04-28 20:01 <DIR> --d----- d:\windows\system32\DirectX
2009-04-28 20:00 <DIR> --d----- d:\program files\common files\MSSoap
2009-04-28 19:59 <DIR> --d-h--- d:\program files\WindowsUpdate
2009-04-28 19:59 <DIR> --d----- d:\program files\Online Services
2009-04-28 19:59 <DIR> --d----- d:\program files\MSN Gaming Zone
2009-04-28 19:58 <DIR> --d----- d:\program files\Windows NT
2009-04-28 15:23 <DIR> --d----- d:\program files\common files\ODBC
2009-04-28 15:23 <DIR> --d----- d:\program files\common files\SpeechEngines
2009-04-28 15:22 <DIR> --d--r-- d:\documents and settings\all users\Documents

==================== Find3M ====================

2009-05-10 10:04 2,678 a------- d:\windows\java\packages\data\FLF7PRTN.DAT
2009-05-10 10:04 2,678 a------- d:\windows\java\packages\data\LR7P7XN9.DAT
2009-05-10 10:04 2,678 a------- d:\windows\java\packages\data\C7PRL7DZ.DAT
2009-05-10 10:04 2,678 a------- d:\windows\java\packages\data\AWWJTN5B.DAT
2009-05-07 08:12 86,327 a------- d:\windows\pchealth\helpctr\offlinecache\index.dat
2009-04-28 22:12 88,064 a--sh--- d:\windows\system32\bubopoyu.dll
2009-04-28 22:12 51,200 a--sh--- d:\windows\system32\hebedogu.exe
2009-04-28 19:59 21,640 a------- d:\windows\system32\emptyregdb.dat
2009-03-06 10:22 284,160 a------- d:\windows\system32\pdh.dll
2009-02-20 04:10 666,112 a------- d:\windows\system32\wininet.dll
2009-02-20 04:10 81,920 -------- d:\windows\system32\ieencode.dll

============= FINISH: 11:57:15.74 ===============




UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-05-14.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 4/28/2009 8:05:03 PM
System Uptime: 5/15/2009 4:55:33 PM (19 hours ago)

Motherboard: ASUSTeK Computer INC. | | KIRIN-V
Processor: Intel® Pentium® 4 CPU 2.66GHz | PGA 478 | 2680/133mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 14 GiB total, 8.373 GiB free.
D: is FIXED (NTFS) - 93 GiB total, 82.8 GiB free.
E: is CDROM ()
F: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Video Controller (VGA Compatible)
Device ID: PCI\VEN_8086&DEV_2562&SUBSYS_813B104D&REV_03\3&61AAA01&0&10
Manufacturer:
Name: Video Controller (VGA Compatible)
PNP Device ID: PCI\VEN_8086&DEV_2562&SUBSYS_813B104D&REV_03\3&61AAA01&0&10
Service:

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Camera
Device ID: USB\VID_046D&PID_08F0\5&380B3931&0&2
Manufacturer:
Name: Camera
PNP Device ID: USB\VID_046D&PID_08F0\5&380B3931&0&2
Service:

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: PCI Modem
Device ID: PCI\VEN_8086&DEV_24C6&SUBSYS_8128104D&REV_02\3&61AAA01&0&FE
Manufacturer:
Name: PCI Modem
PNP Device ID: PCI\VEN_8086&DEV_24C6&SUBSYS_8128104D&REV_02\3&61AAA01&0&FE
Service:

==== System Restore Points ===================

RP1: 4/28/2009 8:07:47 PM - System Checkpoint
RP2: 4/28/2009 8:13:26 PM - Installed Realtek AC'97 Audio
RP3: 4/28/2009 9:36:34 PM - Installed Windows XP Service Pack 2.
RP4: 4/28/2009 10:04:52 PM - Installed Kaspersky Internet Security 2009.
RP5: 4/29/2009 4:28:38 PM - Removed Kaspersky Internet Security 2009.
RP6: 4/29/2009 6:18:35 PM - Software Distribution Service 3.0
RP7: 4/29/2009 6:37:07 PM - Installed Windows Installer KB893803v2.
RP8: 4/30/2009 6:42:35 PM - System Checkpoint
RP9: 5/1/2009 3:00:16 AM - Software Distribution Service 3.0
RP10: 5/10/2009 11:17:19 AM - System Checkpoint
RP11: 5/11/2009 3:00:13 AM - Software Distribution Service 3.0
RP12: 5/11/2009 7:55:35 PM - Installed Adobe Reader 9.1.
RP13: 5/11/2009 9:09:59 PM - Removed Java™ 6 Update 13
RP14: 5/11/2009 9:10:20 PM - Installed Java™ 6 Update 13
RP15: 5/12/2009 3:00:13 AM - Software Distribution Service 3.0
RP16: 5/13/2009 3:00:14 AM - Software Distribution Service 3.0
RP17: 5/14/2009 3:09:47 AM - System Checkpoint
RP18: 5/15/2009 4:09:47 AM - System Checkpoint
RP19: 5/15/2009 4:58:40 PM - Installed Microsoft Office Enterprise 2007
RP20: 5/15/2009 5:27:52 PM - Printer Driver Send To Microsoft OneNote Driver Installed
RP21: 5/16/2009 3:00:17 AM - Software Distribution Service 3.0

==== Installed Programs ======================


µTorrent
Acrobat.com
Adobe AIR
Adobe Flash Player 10 Plugin
Adobe Reader 9.1
AiO_Scan_CDA
ATI - Software Uninstall Utility
ATI Display Driver
avast! Antivirus
Choice Guard
Critical Update for Windows Media Player 11 (KB959772)
FLV Player 2.0 (build 25)
Google Chrome
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
HP Photosmart, Officejet and Deskjet 7.0.A
Java™ 6 Update 13
Malwarebytes' Anti-Malware
Microsoft Application Error Reporting
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Software Update for Web Folders (English) 12
Microsoft Visual Studio 6.0 Enterprise Edition
Microsoft VM for Java
Microsoft Web Publishing Wizard 1.53
Mozilla Firefox (3.0.10)
MSVCRT
QFolder
Realtek AC'97 Audio
Scan
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB963027)
Segoe UI
Update for 2007 Microsoft Office System (KB967642)
Update for Outlook 2007 Junk Email Filter (kb968503)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
WebFldrs XP
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Upload Tool
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinRAR archiver

==== Event Viewer Messages From Past Week ========

5/9/2009 7:47:27 PM, error: LDMS [3023] - The Logical Disk Manager Service failed while registering for device handle notifications on device \\?\STORAGE#RemovableMedia#8&3befb14&0&RM#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}. Win32 Error: 565.

==== End Of File ===========================

#5 PropagandaPanda

PropagandaPanda


  • Malware Response Team
  • 10,433 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:46 AM

Posted 16 May 2009 - 06:05 PM

Hello. I am PropagandaPanda (Panda or PP for short), and I will be helping you.

Disable Realtime Protection
Antimalware programs can interfere with ComboFix and other tools we need to run. Please temporarily disable all realtime protections you have enabled. Refer to this page, if you are unsure how.

Download and Run ComboFix
Download Combofix by sUBs from any of the links below, and save it to your desktop.
Link 1, Link 2, Link 3
  • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are not sure how.
  • Double click on ComboFix.exe and follow the prompts. If you are using Windows Vista, right click the icon and select "Run as Administrator". You will not recieve the prompts below if you are not using Windows XP. ComboFix will check to see if you have the Windows Recovery Console installed.
  • If you did not have it installed, you will see the prompt below. Choose YES.
    Posted ImagePosted Image

  • When the Recovery Console has been installed, you will see the prompt below. Choose YES.
    Posted Image
  • When finished, ComboFix will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).
Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

Download and Run Scan with GMER
We will use GMER to scan for rootkits.

Please download GMER to your desktop. Note that the file will be randomly named to prevent active malware from stopping the download.
  • Close all other open programs as there is a slight chance your computer will crash.
  • Double click the GMER program ******.exe. Your security programs may detect GMER's driver trying to load. Allow it.
  • You may see a warning saying "GMER has detected rootkit activity". If so, select NO.
  • Leaving the settings at default, click Scan.
  • When the scan is complete, click Save and save the log onto your desktop.
Please include the log in your next reply.

In your next reply include:
-the ComboFix log
-the GMER scan log

Please also tell me of any changes you have made to your computer since you started your topic.

With Regards,
The Panda

#6 ClassX

ClassX
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:10:46 AM

Posted 17 May 2009 - 11:39 AM

heres my Combo log
ComboFix 09-05-16.05 - Kristian 05/17/2009 11:39.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.760.507 [GMT -4:00]
Running from: d:\documents and settings\Kristian\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090516-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-1-5-21-2807240034-4116831272-1055463431-1005\Dc198.url
c:\recycler\S-1-5-21-2807240034-4116831272-1055463431-1005\Dc199.cfg
c:\recycler\S-1-5-21-2807240034-4116831272-1055463431-1005\Dc200
c:\recycler\S-1-5-21-2807240034-4116831272-1055463431-1005\Dc201.exe
c:\recycler\S-1-5-21-2807240034-4116831272-1055463431-1005\Dc202.avi
c:\recycler\S-1-5-21-2807240034-4116831272-1055463431-1005\Dc203.avi
c:\recycler\S-1-5-21-2807240034-4116831272-1055463431-1005\Dc204.avi
c:\recycler\S-1-5-21-2807240034-4116831272-1055463431-1005\INFO2
c:\recycler\S-1-5-21-343818398-823518204-725345543-1004\Dc1.exe
c:\recycler\S-1-5-21-343818398-823518204-725345543-1004\Dc2\HipHop4_Demo\eJay\eJay\install.log
c:\recycler\S-1-5-21-343818398-823518204-725345543-1004\Dc3.mp3
c:\recycler\S-1-5-21-343818398-823518204-725345543-1004\INFO2
c:\recycler\S-1-5-21-796845957-2025429265-725345543-1004\Dc2.pk3
c:\recycler\S-1-5-21-796845957-2025429265-725345543-1004\Dc3.exe
c:\recycler\S-1-5-21-796845957-2025429265-725345543-1004\Dc4.exe
c:\recycler\S-1-5-21-796845957-2025429265-725345543-1004\Dc5.dll
c:\recycler\S-1-5-21-796845957-2025429265-725345543-1004\Dc6.dll
c:\recycler\S-1-5-21-796845957-2025429265-725345543-1004\INFO2
d:\documents and settings\Kristian\Local Settings\Temporary Internet Files\fbk.sts
d:\documents and settings\Kristian\protect.dll
d:\documents and settings\Kristian\Start Menu\Programs\Startup\ChkDisk.dll
d:\documents and settings\Kristian\Start Menu\Programs\Startup\ChkDisk.lnk
d:\documents and settings\LocalService\protect.dll
d:\windows\system32\autochk.dll
d:\windows\system32\bubopoyu.dll
d:\windows\system32\config\systemprofile\protect.dll
d:\windows\system32\drivers\ovfsthkvvmpydcrmktpayvtbdokxdlqkvkfrmp.sys
d:\windows\system32\hebedogu.exe
d:\windows\system32\ifobejan.ini
d:\windows\system32\lmppcsetup.exe
d:\windows\system32\ovfsthbfworwokxvuhblfxcilrylraknstxhje.dll
d:\windows\system32\ovfsthcqiboikxxgidhlkuhxgahfkpgniubylm.dll
d:\windows\system32\ovfsthkxjxoulehcephgwhutvfrkyfmvqxqjct.dat
d:\windows\system32\ovfsthnloxkdsgavpyimfehooipppxspmkxqfy.dll
d:\windows\system32\ovfsthxaynnyrlyqbraxtnhdlghqnpnthlgplb.dat
d:\windows\system32\uniq.tll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy


((((((((((((((((((((((((( Files Created from 2009-04-17 to 2009-05-17 )))))))))))))))))))))))))))))))
.

2009-05-15 21:27 . 2006-10-26 23:56 32592 ----a-w d:\windows\system32\msonpmon.dll
2009-05-15 21:26 . 2009-05-15 21:26 -------- d-----w d:\program files\Microsoft Works
2009-05-15 21:26 . 2009-05-15 21:26 -------- d-----w d:\program files\MSBuild
2009-05-15 21:00 . 2009-05-15 21:16 -------- d-----w d:\windows\SHELLNEW
2009-05-15 20:59 . 2009-05-15 20:59 -------- d-----w d:\documents and settings\Kristian\Local Settings\Application Data\Microsoft Help
2009-05-15 20:59 . 2009-05-16 07:00 -------- d-----w d:\documents and settings\All Users\Application Data\Microsoft Help
2009-05-15 20:58 . 2009-05-15 20:58 -------- d--h--r D:\MSOCache
2009-05-12 12:02 . 2009-05-12 12:02 -------- d-----w d:\program files\uTorrent
2009-05-12 12:02 . 2009-05-16 17:48 -------- d-----w d:\documents and settings\Kristian\Application Data\uTorrent
2009-05-12 07:00 . 2009-05-12 07:00 -------- d-----w d:\windows\system32\KB905474
2009-05-12 07:00 . 2009-03-11 02:26 1403264 ----a-w d:\windows\system32\KB905474\wganotifypackageinner.exe
2009-05-12 07:00 . 2009-03-11 02:18 453512 ----a-w d:\windows\system32\KB905474\wgasetup.exe
2009-05-12 01:10 . 2009-05-12 01:10 -------- d-----w d:\program files\Java
2009-05-11 23:56 . 2009-05-11 23:57 -------- d-----w d:\documents and settings\Kristian\Local Settings\Application Data\Adobe
2009-05-11 23:56 . 2009-05-11 23:56 -------- d-----w d:\program files\Common Files\Adobe AIR
2009-05-11 23:55 . 2009-05-11 23:56 -------- d-----w d:\program files\Common Files\Adobe
2009-05-10 14:10 . 2009-05-10 14:10 -------- d-----w d:\program files\Web Publish
2009-05-09 14:21 . 2009-05-09 14:21 -------- d-----w d:\program files\Hewlett-Packard
2009-05-09 14:21 . 2009-05-09 14:21 -------- d-----w d:\program files\Common Files\Hewlett-Packard
2009-05-09 14:20 . 2006-04-10 18:03 38400 ----a-w d:\windows\system32\hpz3l054.dll
2009-05-09 14:19 . 2006-03-04 01:02 57344 ----a-w d:\windows\system32\HPZisn12.dll
2009-05-09 14:19 . 2006-03-04 01:03 69632 ----a-w d:\windows\system32\HPZipm12.exe
2009-05-09 14:19 . 2006-03-04 01:02 204800 ----a-w d:\windows\system32\HPZipr12.dll
2009-05-09 14:19 . 2006-03-04 01:02 94208 ----a-w d:\windows\system32\HPZipt12.dll
2009-05-09 14:19 . 2006-03-04 01:03 282680 ----a-w d:\windows\system32\HPZidr12.dll
2009-05-09 14:19 . 2006-03-04 01:03 65536 ----a-w d:\windows\system32\HPZinw12.exe
2009-05-09 14:19 . 1998-10-29 20:45 306688 ----a-w d:\windows\IsUninst.exe
2009-05-09 14:18 . 2009-05-09 14:19 -------- d-----w d:\program files\HP
2009-05-09 14:18 . 2008-04-13 18:47 25856 -c--a-w d:\windows\system32\dllcache\usbprint.sys
2009-05-09 14:18 . 2008-04-13 18:47 25856 ----a-w d:\windows\system32\drivers\usbprint.sys
2009-05-09 14:18 . 2008-04-13 18:45 32128 -c--a-w d:\windows\system32\dllcache\usbccgp.sys
2009-05-09 14:18 . 2008-04-13 18:45 32128 ----a-w d:\windows\system32\drivers\usbccgp.sys
2009-05-09 14:18 . 2009-05-09 14:22 110389 ----a-w d:\windows\hpoins11.dat
2009-05-09 14:18 . 2006-04-13 00:04 49664 ----a-w d:\windows\system32\drivers\HPZid412.sys
2009-05-09 14:18 . 2006-04-13 00:04 16496 ----a-w d:\windows\system32\drivers\HPZipr12.sys
2009-05-09 14:18 . 2006-04-13 00:04 21568 ----a-w d:\windows\system32\drivers\HPZius12.sys
2009-05-09 14:17 . 2006-04-13 00:02 827392 ----a-w d:\windows\system32\hpotiop2.dll
2009-05-09 14:17 . 2006-04-13 00:02 659456 ----a-w d:\windows\system32\hpowiax2.dll
2009-05-09 14:17 . 2006-04-13 00:04 282624 ----a-w d:\windows\system32\HPZc3212.dll
2009-05-09 14:17 . 2006-04-13 00:02 254026 ----a-w d:\windows\system32\hpovst09.dll
2009-05-09 14:17 . 2006-01-04 08:12 77824 ----a-w d:\windows\system32\HPZIDS01.dll
2009-05-09 14:17 . 2005-07-19 01:38 98304 ----a-w d:\windows\system32\hpzjsn01.dll
2009-05-09 14:17 . 2006-05-06 03:10 6947 ----a-w d:\windows\hpomdl11.dat
2009-05-08 21:28 . 2009-05-08 21:28 -------- d-----w d:\program files\FLV Player
2009-05-07 12:09 . 2009-05-07 12:09 -------- d-----w d:\windows\system32\scripting
2009-05-07 12:09 . 2009-05-07 12:09 -------- d-----w d:\windows\l2schemas
2009-05-07 12:09 . 2009-05-07 12:09 -------- d-----w d:\windows\system32\en
2009-05-07 12:09 . 2009-05-07 12:09 -------- d-----w d:\windows\system32\bits
2009-05-03 01:13 . 2004-08-04 04:56 221184 ----a-w d:\windows\system32\wmpns.dll
2009-05-02 20:28 . 2009-05-02 20:28 -------- d-----w d:\windows\Sun
2009-05-02 20:27 . 2009-05-12 01:10 410984 ----a-w d:\windows\system32\deploytk.dll
2009-05-02 20:16 . 2001-08-18 02:36 5632 ----a-w d:\windows\system32\ptpusb.dll
2009-05-02 20:16 . 2004-08-04 04:56 159232 ----a-w d:\windows\system32\ptpusd.dll
2009-05-02 20:16 . 2008-04-13 18:45 15104 ----a-w d:\windows\system32\drivers\usbscan.sys
2009-05-02 15:18 . 2009-05-16 21:11 -------- d-----w D:\ClassX
2009-05-02 14:28 . 2009-05-02 14:28 -------- d-----w d:\windows\system32\drivers\umdf
2009-05-02 14:27 . 2009-05-02 14:27 -------- d-----w d:\program files\Windows Media Connect 2
2009-04-30 23:38 . 2008-04-14 00:12 33792 ------w d:\windows\system32\mmcperf.exe
2009-04-30 16:09 . 2008-10-16 18:06 208744 ----a-w d:\windows\system32\muweb.dll
2009-04-30 16:09 . 2008-10-16 18:06 268648 ----a-w d:\windows\system32\mucltui.dll
2009-04-29 23:10 . 2009-04-29 23:12 -------- d-----w d:\documents and settings\Kristian\Local Settings\Application Data\Google
2009-04-29 22:54 . 2009-04-29 22:54 -------- d-----w d:\program files\Trend Micro
2009-04-29 22:49 . 2009-05-10 13:15 -------- d-----w d:\documents and settings\Kristian\Tracing
2009-04-29 22:48 . 2009-04-29 22:48 -------- d-----w d:\program files\Microsoft
2009-04-29 22:48 . 2009-04-29 22:48 -------- d-----w d:\program files\Windows Live SkyDrive
2009-04-29 22:48 . 2009-04-29 22:48 -------- d-----w d:\program files\Windows Live
2009-04-29 22:42 . 2009-04-29 22:42 -------- d-----w d:\program files\Common Files\Windows Live
2009-04-29 22:27 . 2008-06-13 11:05 272128 -c----w d:\windows\system32\dllcache\bthport.sys
2009-04-29 22:24 . 2009-03-06 14:22 284160 -c----w d:\windows\system32\dllcache\pdh.dll
2009-04-29 22:24 . 2009-02-09 12:10 401408 -c----w d:\windows\system32\dllcache\rpcss.dll
2009-04-29 22:24 . 2009-02-06 11:11 110592 -c----w d:\windows\system32\dllcache\services.exe
2009-04-29 22:24 . 2009-02-09 12:10 473600 -c----w d:\windows\system32\dllcache\fastprox.dll
2009-04-29 22:24 . 2009-02-06 10:10 227840 -c----w d:\windows\system32\dllcache\wmiprvse.exe
2009-04-29 22:24 . 2009-02-09 12:10 453120 -c----w d:\windows\system32\dllcache\wmiprvsd.dll
2009-04-29 22:24 . 2009-02-09 12:10 729088 -c----w d:\windows\system32\dllcache\lsasrv.dll
2009-04-29 22:24 . 2009-02-09 12:10 617472 -c----w d:\windows\system32\dllcache\advapi32.dll
2009-04-29 22:24 . 2009-02-09 12:10 714752 -c----w d:\windows\system32\dllcache\ntdll.dll
2009-04-29 22:24 . 2009-02-06 11:06 2145280 -c----w d:\windows\system32\dllcache\ntkrnlmp.exe
2009-04-29 22:24 . 2009-02-06 11:08 2189056 -c----w d:\windows\system32\dllcache\ntoskrnl.exe
2009-04-29 22:24 . 2009-02-06 10:32 2023936 -c----w d:\windows\system32\dllcache\ntkrpamp.exe
2009-04-29 22:21 . 2008-05-08 14:02 203136 -c----w d:\windows\system32\dllcache\rmcast.sys
2009-04-29 22:20 . 2008-10-24 11:21 455296 -c----w d:\windows\system32\dllcache\mrxsmb.sys
2009-04-29 22:20 . 2008-12-11 10:57 333952 -c----w d:\windows\system32\dllcache\srv.sys
2009-04-29 22:20 . 2008-05-01 14:33 331776 -c----w d:\windows\system32\dllcache\msadce.dll
2009-04-29 22:20 . 2008-04-11 19:04 691712 -c----w d:\windows\system32\dllcache\inetcomm.dll
2009-04-29 22:19 . 2008-10-15 16:34 337408 -c----w d:\windows\system32\dllcache\netapi32.dll
2009-04-29 22:19 . 2008-09-04 17:15 1106944 -c----w d:\windows\system32\dllcache\msxml3.dll
2009-04-29 22:19 . 2008-05-03 11:55 2560 ------w d:\windows\system32\xpsp4res.dll
2009-04-29 22:19 . 2008-04-21 12:08 215552 -c----w d:\windows\system32\dllcache\wordpad.exe
2009-04-29 22:18 . 2009-05-08 07:00 -------- d--h--w d:\windows\$hf_mig$
2009-04-29 22:18 . 2008-10-03 10:02 247326 -c----w d:\windows\system32\dllcache\strmdll.dll
2009-04-29 20:34 . 2003-03-18 19:20 1060864 ----a-w d:\windows\system32\MFC71.dll
2009-04-29 20:34 . 2003-03-18 18:14 499712 ----a-w d:\windows\system32\MSVCP71.dll
2009-04-29 20:34 . 2003-02-21 02:42 348160 ----a-w d:\windows\system32\MSVCR71.dll
2009-04-29 20:34 . 2009-04-29 20:34 -------- d-----w d:\program files\Alwil Software
2009-04-29 20:11 . 2009-04-29 20:11 -------- d-----w d:\documents and settings\Kristian\Application Data\Malwarebytes
2009-04-29 20:11 . 2009-04-06 19:32 15504 ----a-w d:\windows\system32\drivers\mbam.sys
2009-04-29 20:11 . 2009-04-06 19:32 38496 ----a-w d:\windows\system32\drivers\mbamswissarmy.sys
2009-04-29 20:11 . 2009-04-29 20:11 -------- d-----w d:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-29 20:11 . 2009-04-29 20:11 -------- d-----w d:\program files\Malwarebytes' Anti-Malware
2009-04-29 20:06 . 2009-04-29 20:06 0 ----a-w d:\windows\nsreg.dat
2009-04-29 20:06 . 2009-04-29 20:06 -------- d-----w d:\documents and settings\Kristian\Local Settings\Application Data\Mozilla
2009-04-29 19:50 . 2009-04-29 19:50 -------- d-s---w d:\documents and settings\Kristian\UserData
2009-04-29 02:05 . 2009-04-29 02:14 32 --sha-w d:\windows\system32\drivers\fidbox.dat
2009-04-29 02:05 . 2009-04-29 02:14 122912 --sha-w d:\windows\system32\drivers\fidbox2.dat
2009-04-29 02:04 . 2009-04-29 02:04 -------- d-----w d:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-04-29 02:02 . 2009-04-29 02:02 -------- d-sh--w d:\documents and settings\Kristian\Local Settings\Application Data\.#
2009-04-29 01:53 . 2009-04-29 22:49 13688 ----a-w d:\documents and settings\Kristian\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-29 01:40 . 2008-04-14 00:12 286792 ------w d:\windows\system32\slextspk.dll
2009-04-29 01:39 . 2009-05-07 12:09 -------- d-----w d:\windows\ServicePackFiles
2009-04-29 01:37 . 2008-04-13 17:39 2897920 ------w d:\windows\system32\xpsp2res.dll
2009-04-29 01:36 . 2007-08-11 00:46 26488 ----a-w d:\windows\system32\spupdsvc.exe
2009-04-29 01:34 . 2009-05-07 12:02 -------- d-----w d:\windows\EHome

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-16 17:52 . 2009-05-16 17:51 -------- d-----w d:\program files\DivX
2009-04-15 20:24 . 2009-04-15 20:24 90112 ----a-w d:\windows\system32\dpl100.dll
2009-04-15 20:24 . 2009-04-15 20:24 823296 ----a-w d:\windows\system32\divx_xx0c.dll
2009-04-15 20:24 . 2009-04-15 20:24 823296 ----a-w d:\windows\system32\divx_xx07.dll
2009-04-15 20:24 . 2009-04-15 20:24 815104 ----a-w d:\windows\system32\divx_xx0a.dll
2009-04-15 20:24 . 2009-04-15 20:24 802816 ----a-w d:\windows\system32\divx_xx11.dll
2009-04-15 20:24 . 2009-04-15 20:24 684032 ----a-w d:\windows\system32\DivX.dll
2009-03-06 14:22 . 2002-08-29 01:41 284160 ----a-w d:\windows\system32\pdh.dll
2009-02-20 08:10 . 2002-08-29 01:41 666112 ----a-w d:\windows\system32\wininet.dll
2009-02-20 08:10 . 2009-04-29 01:41 81920 ------w d:\windows\system32\ieencode.dll
2009-04-15 20:24 . 2009-04-15 20:24 1044480 ----a-w d:\program files\mozilla firefox\plugins\libdivx.dll
2009-04-15 20:24 . 2009-04-15 20:24 200704 ----a-w d:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="d:\documents and settings\Kristian\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-04-29 133104]
"ctfmon.exe"="d:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="d:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2009-05-12 148888]
"GrooveMonitor"="d:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Messenger\\msmsgs.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

R1 aswSP;avast! Self Protection;d:\windows\system32\drivers\aswSP.sys [4/29/2009 4:35 PM 114768]
R2 aswFsBlk;aswFsBlk;d:\windows\system32\drivers\aswFsBlk.sys [4/29/2009 4:35 PM 20560]

--- Other Services/Drivers In Memory ---

*Deregistered* - Spooler
*Deregistered* - srservice
*Deregistered* - SSDPSRV
*Deregistered* - stisvc
*Deregistered* - TapiSrv
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TrkWks
*Deregistered* - W32Time
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
.
Contents of the 'Scheduled Tasks' folder

2009-05-17 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-1767777339-725345543-1003.job
- d:\documents and settings\Kristian\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-29 23:10]

2009-05-17 d:\windows\Tasks\WGASetup.job
- d:\windows\system32\KB905474\wgasetup.exe [2009-05-12 02:18]
.
- - - - ORPHANS REMOVED - - - -

HKU-Default-Run-autochk - d:\docume~1\LOCALS~1\protect.dll


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
FF - ProfilePath - d:\documents and settings\Kristian\Application Data\Mozilla\Firefox\Profiles\ylkmy3tq.default\
FF - plugin: d:\documents and settings\Kristian\Local Settings\Application Data\Google\Update\1.2.145.5\npGoogleOneClick8.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-17 11:46
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(612)
d:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3956)
d:\windows\system32\WPDShServiceObj.dll
d:\windows\system32\PortableDeviceTypes.dll
d:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
d:\windows\system32\ati2evxx.exe
d:\program files\Alwil Software\Avast4\aswUpdSv.exe
d:\program files\Alwil Software\Avast4\ashServ.exe
d:\windows\system32\ati2evxx.exe
d:\program files\Java\jre6\bin\jqs.exe
d:\windows\system32\HPZipm12.exe
d:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-05-17 11:50 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-17 15:50

Pre-Run: 88,974,393,344 bytes free
Post-Run: 89,866,846,208 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(3)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(3)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect

285 --- E O F --- 2009-05-16 07:00

and heres the other scan

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-05-17 12:36:59
Windows 5.1.2600 Service Pack 3


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xEDDED6B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xEDDED574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xEDDEDA52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xEDDED14C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xEDDED64E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xEDDED08C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xEDDED0F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xEDDED76E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xEDDED72E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xEDDED8AE]

Code \??\D:\DOCUME~1\Kristian\LOCALS~1\Temp\catchme.sys pIofCallDriver

---- Kernel code sections - GMER 1.0.15 ----

? Combo-Fix.sys The system cannot find the file specified. !
? D:\DOCUME~1\Kristian\LOCALS~1\Temp\catchme.sys The system cannot find the file specified. !
? D:\WINDOWS\system32\Drivers\PROCEXP90.SYS The system cannot find the file specified. !

---- User IAT/EAT - GMER 1.0.15 ----

IAT D:\WINDOWS\system32\services.exe[660] @ D:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT D:\WINDOWS\system32\services.exe[660] @ D:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy@imagepath \systemroot\system32\drivers\ovfsthkvvmpydcrmktpayvtbdokxdlqkvkfrmp.sys
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy@inst 0
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main@ver sni060409
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main@cid 01
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main@bid 1224293322-1417001333-1767777339-725345543
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main@aid 998
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main@sid 3
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main@feed 0x22 0x64 0x78 0x36 ...
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main@cmddelay 28801
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main\delete
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main\ff
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main\ff@extension \\?\D:\Program Files\Mozilla Firefox\extensions\{EAEF60DF-1687-4BBF-A1A2-B3F2A7F4E790}
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main\ff@version 1
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main\injector
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main\injector@iexplore.exe ovfsthwi.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main\injector@explorer.exe ovfsthff.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main\tasks
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\modules
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\modules@ovfsth.sys \systemroot\system32\drivers\ovfsthkvvmpydcrmktpayvtbdokxdlqkvkfrmp.sys
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\modules@ovfsth.dll \systemroot\system32\ovfsthnloxkdsgavpyimfehooipppxspmkxqfy.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\modules@ovfsthlog.dat \systemroot\system32\ovfsthkxjxoulehcephgwhutvfrkyfmvqxqjct.dat
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\modules@ovfsthwi.dll \systemroot\system32\ovfsthcqiboikxxgidhlkuhxgahfkpgniubylm.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\modules@ovfsthff.dll \systemroot\system32\ovfsthbfworwokxvuhblfxcilrylraknstxhje.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\modules@ovfsth.dat \systemroot\system32\ovfsthxaynnyrlyqbraxtnhdlghqnpnthlgplb.dat

---- EOF - GMER 1.0.15 ----

#7 PropagandaPanda

PropagandaPanda


  • Malware Response Team
  • 10,433 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:46 AM

Posted 17 May 2009 - 11:55 AM

Hello ClassX.

Posted ImageBackdoor Threat
I'm sorry to say that your computer was infected with one or more backdoor trojans.

This means that sensitive information could have been stolen. I would advise to change any passwords for any accounts that you have accessed with the infected computer using a clean computer ASAP. If you have used this computer for banking, I would strongly suggest that you report the possible stolen information. Please do not use the computer for any further transactions, or to enter any other information, if at all possible, until it is declared clean.

You may want to read this article on how to handle identity theft.
You may also want to read this article regarding preventing of identity theft.

This computer can still be cleaned, however, I cannot guarantee that it will be 100% safe even after disinfection.

Please read When Should I Format, How Should I Reinstall.

I will proceed assuming you wish to disinfect. If you want to do a reinstall, reply back saying so.

Download and Run ATFCleaner
Please download ATF Cleaner by Atribune. This program will clear out temporary files and settings. You will likely be logged out of the forum where you are recieving help.
  • Double-click ATF-Cleaner.exe to run the program. If you are using Windows Vista, right click the icon and select Run As Administrator.
  • Under Main Select Files to Delete choose: Select All.
  • Click the Empty Selected button.
F-Secure Online Scan
Please run F-Secure Online Scanner.
This scan is for Internet Explorer only.
  • It is suggested that you disable security programs and close any other windows during the scan. While your security is disabled, please refrain from surfing on other sites. Refer to this page if you are unsure how.
  • Go to F-Secure Online Scanner
  • Follow the instructions here for installation.
  • Accept the License Agreement.
  • Once the ActiveX installs, click Full System Scan
  • Once the download completes, the scan will begin automatically. The scan will take some time to finish, so please be patient.
  • When the scan completes, click the Automatic cleaning (recommended) button.
  • Click the Show Report button and copy the entire report in your next reply.
  • Be sure to re-enable any security programs.

Please also include a new DDS.txt log.

Give me an update on the symptoms.

With Regards,
The Panda

#8 ClassX

ClassX
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:10:46 AM

Posted 17 May 2009 - 07:19 PM

Scanning Report
Sunday, May 17, 2009 19:17:52 - 19:44:15

Computer name: CLASSX-BJ1FVIK5
Scanning type: Scan system for malware, spyware and rootkits
Target: C:\ D:\
No malware found
Statistics
Scanned:

* Files: 30940
* System: 2994
* Not scanned: 41

Actions:

* Disinfected: 0
* Renamed: 0
* Deleted: 0
* Not cleaned: 0
* Submitted: 0

Files not scanned:

* C:\WINDOWS\$NTUNINSTALLKB835732$\CALLCONT.DLL
* C:\WINDOWS\$NTUNINSTALLKB835732$\GDI32.DLL
* C:\WINDOWS\$NTUNINSTALLKB835732$\H323.TSP
* C:\WINDOWS\$NTUNINSTALLKB835732$\H323MSP.DLL
* C:\WINDOWS\$NTUNINSTALLKB835732$\HELPCTR.EXE
* C:\WINDOWS\$NTUNINSTALLKB835732$\IPNATHLP.DLL
* C:\WINDOWS\$NTUNINSTALLKB835732$\LSASRV.DLL
* C:\WINDOWS\$NTUNINSTALLKB835732$\MF3216.DLL
* C:\WINDOWS\$NTUNINSTALLKB835732$\MSASN1.DLL
* C:\WINDOWS\$NTUNINSTALLKB835732$\MSGINA.DLL
* C:\WINDOWS\$NTUNINSTALLKB835732$\MST120.DLL
* C:\WINDOWS\$NTUNINSTALLKB835732$\NETAPI32.DLL
* C:\WINDOWS\$NTUNINSTALLKB835732$\NMCOM.DLL
* C:\WINDOWS\$NTUNINSTALLKB835732$\RTCDLL.DLL
* C:\WINDOWS\$NTUNINSTALLKB835732$\SCHANNEL.DLL
* C:\WINDOWS\$NTUNINSTALLKB828741$\CATSRV.DLL
* C:\WINDOWS\$NTUNINSTALLKB828741$\CATSRVUT.DLL
* C:\WINDOWS\$NTUNINSTALLKB828741$\CLBCATEX.DLL
* C:\WINDOWS\$NTUNINSTALLKB828741$\CLBCATQ.DLL
* C:\WINDOWS\$NTUNINSTALLKB828741$\COLBACT.DLL
* C:\WINDOWS\$NTUNINSTALLKB828741$\COMADMIN.DLL
* C:\WINDOWS\$NTUNINSTALLKB828741$\COMREPL.EXE
* C:\WINDOWS\$NTUNINSTALLKB828741$\COMSVCS.DLL
* C:\WINDOWS\$NTUNINSTALLKB828741$\COMUID.DLL
* C:\WINDOWS\$NTUNINSTALLKB828741$\ES.DLL
* C:\WINDOWS\$NTUNINSTALLKB828741$\MSDTCPRX.DLL
* C:\WINDOWS\$NTUNINSTALLKB828741$\MSDTCTM.DLL
* C:\WINDOWS\$NTUNINSTALLKB828741$\MSDTCUIU.DLL
* C:\WINDOWS\$NTUNINSTALLKB828741$\MTXCLU.DLL
* C:\WINDOWS\$NTUNINSTALLKB828741$\MTXOCI.DLL
* C:\WINDOWS\$NTUNINSTALLKB828741$\OLE32.DLL
* C:\WINDOWS\$NTUNINSTALLKB828741$\RPCRT4.DLL
* C:\WINDOWS\$NTUNINSTALLKB828741$\RPCSS.DLL
* C:\WINDOWS\$NTUNINSTALLKB828741$\TXFLOG.DLL
* C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\154299224197F4F64A5A44B0296054B4_72C7BA7F-AA61-4C8D-9B70-586B98C98F2C
* C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\19A01B8B6B71370BB6ED8ED7913C95AE_72C7BA7F-AA61-4C8D-9B70-586B98C98F2C
* C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\1E97877B31A96031B9F86A20168ADA28_72C7BA7F-AA61-4C8D-9B70-586B98C98F2C
* C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\3C9E3E2C028F24B5DABDF41CC4CBC764_72C7BA7F-AA61-4C8D-9B70-586B98C98F2C
* C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\5D1CA08D0C6E745621BF5F5ED9961705_72C7BA7F-AA61-4C8D-9B70-586B98C98F2C
* C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\91D101E739D7C3B53BE51F49FDA5487D_72C7BA7F-AA61-4C8D-9B70-586B98C98F2C
* C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\MICROSOFT\CRYPTO\DSS\MACHINEKEYS\3AEFA285455290BDE8601D2A10F7F419_72C7BA7F-AA61-4C8D-9B70-586B98C98F2C

Options
Scanning engines:

* F-Secure USS: 3.0.0
* F-Secure Hydra: 3.8.9080, 2009-05-15
* F-Secure AVP: 7.0.171, 2009-05-16
* F-Secure Pegasus: 1.20.0
* F-Secure Blacklight

Scanning options:

* Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX ANI AVB BAT CMD JOB LSP MAP MHT MIF PHP POT SWF WMF NWS TAR
* Use advanced heuristics

Copyright © 1998-2009 Product support | Send virus sample to F-Secure
F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name. This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability.



heres my dds log


DDS (Ver_09-05-14.01) - NTFSx86
Run by Kristian at 20:18:05.42 on Sun 05/17/2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.760.297 [GMT -4:00]

AV: avast! antivirus 4.8.1335 [VPS 090517-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

D:\WINDOWS\System32\Ati2evxx.exe
D:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
D:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
D:\Program Files\Alwil Software\Avast4\ashServ.exe
D:\WINDOWS\system32\Ati2evxx.exe
D:\WINDOWS\system32\spoolsv.exe
svchost.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\WINDOWS\system32\HPZipm12.exe
D:\WINDOWS\System32\svchost.exe -k imgsvc
D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
D:\Documents and Settings\Kristian\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
D:\WINDOWS\explorer.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Documents and Settings\Kristian\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - d:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - d:\progra~1\micros~4\office12\GRA8E1~1.DLL
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - d:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - d:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [Google Update] "d:\documents and settings\kristian\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [ctfmon.exe] d:\windows\system32\ctfmon.exe
mRun: [avast!] d:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [Adobe Reader Speed Launcher] "d:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "d:\program files\java\jre6\bin\jusched.exe"
mRun: [GrooveMonitor] "d:\program files\microsoft office\office12\GrooveMonitor.exe"
dPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
dPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
IE: E&xport to Microsoft Excel - d:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - d:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - d:\progra~1\micros~4\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - d:\progra~1\micros~4\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {C237A80A-4C55-4C68-BAA9-CBE4408D12B2} - hxxp://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - d:\progra~1\micros~4\office12\GR99D3~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - d:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - d:\progra~1\micros~4\office12\GRA8E1~1.DLL

================= FIREFOX ===================

FF - ProfilePath - d:\docume~1\kristian\applic~1\mozilla\firefox\profiles\ylkmy3tq.default\
FF - plugin: d:\documents and settings\kristian\local settings\application data\google\update\1.2.145.5\npGoogleOneClick8.dll

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;d:\windows\system32\drivers\aswSP.sys [2009-4-29 114768]
R2 aswFsBlk;aswFsBlk;d:\windows\system32\drivers\aswFsBlk.sys [2009-4-29 20560]
R2 avast! Antivirus;avast! Antivirus;d:\program files\alwil software\avast4\ashServ.exe [2009-4-29 138680]
R3 avast! Mail Scanner;avast! Mail Scanner;d:\program files\alwil software\avast4\ashMaiSv.exe [2009-4-29 254040]
R3 avast! Web Scanner;avast! Web Scanner;d:\program files\alwil software\avast4\ashWebSv.exe [2009-4-29 352920]

=============== Created Last 30 ================

2009-05-17 11:32 161,792 a------- d:\windows\SWREG.exe
2009-05-17 11:32 98,816 a------- d:\windows\sed.exe
2009-05-16 13:51 <DIR> --d----- d:\program files\common files\DivX Shared
2009-05-16 13:51 <DIR> --d----- d:\program files\DivX
2009-05-15 17:27 32,592 a------- d:\windows\system32\msonpmon.dll
2009-05-15 17:00 <DIR> --d----- d:\windows\SHELLNEW
2009-05-12 08:02 <DIR> --d----- d:\program files\uTorrent
2009-05-12 08:02 <DIR> --d----- d:\docume~1\kristian\applic~1\uTorrent
2009-05-12 03:00 <DIR> --d----- d:\windows\system32\KB905474
2009-05-11 21:10 73,728 a------- d:\windows\system32\javacpl.cpl
2009-05-10 10:10 <DIR> --d----- d:\program files\Web Publish
2009-05-09 10:21 <DIR> --d----- d:\program files\common files\Hewlett-Packard
2009-05-09 10:20 38,400 a------- d:\windows\system32\hpz3l054.dll
2009-05-09 10:19 282,680 a------- d:\windows\system32\HPZidr12.dll
2009-05-09 10:19 204,800 a------- d:\windows\system32\HPZipr12.dll
2009-05-09 10:19 94,208 a------- d:\windows\system32\HPZipt12.dll
2009-05-09 10:19 69,632 a------- d:\windows\system32\HPZipm12.exe
2009-05-09 10:19 65,536 a------- d:\windows\system32\HPZinw12.exe
2009-05-09 10:19 57,344 a------- d:\windows\system32\HPZisn12.dll
2009-05-09 10:19 306,688 a------- d:\windows\IsUninst.exe
2009-05-09 10:18 <DIR> --d----- d:\program files\HP
2009-05-09 10:18 25,856 ac------ d:\windows\system32\dllcache\usbprint.sys
2009-05-09 10:18 25,856 a------- d:\windows\system32\drivers\usbprint.sys
2009-05-09 10:18 32,128 ac------ d:\windows\system32\dllcache\usbccgp.sys
2009-05-09 10:18 32,128 a------- d:\windows\system32\drivers\usbccgp.sys
2009-05-09 10:18 110,389 a------- d:\windows\hpoins11.dat
2009-05-09 10:18 49,664 a------- d:\windows\system32\drivers\HPZid412.sys
2009-05-09 10:18 21,568 a------- d:\windows\system32\drivers\HPZius12.sys
2009-05-09 10:18 16,496 a------- d:\windows\system32\drivers\HPZipr12.sys
2009-05-09 10:17 827,392 a------- d:\windows\system32\hpotiop2.dll
2009-05-09 10:17 659,456 a------- d:\windows\system32\hpowiax2.dll
2009-05-09 10:17 282,624 a------- d:\windows\system32\HPZc3212.dll
2009-05-09 10:17 254,026 a------- d:\windows\system32\hpovst09.dll
2009-05-09 10:17 98,304 a------- d:\windows\system32\hpzjsn01.dll
2009-05-09 10:17 77,824 a------- d:\windows\system32\HPZIDS01.dll
2009-05-09 10:17 6,947 a------- d:\windows\hpomdl11.dat
2009-05-07 08:09 <DIR> --d----- d:\program files\Messenger
2009-05-07 08:09 <DIR> --d----- d:\windows\system32\scripting
2009-05-07 08:09 <DIR> --d----- d:\windows\system32\en
2009-05-07 08:09 <DIR> --d----- d:\windows\l2schemas
2009-05-07 08:09 <DIR> --d----- d:\windows\system32\bits
2009-05-07 08:07 <DIR> --d----- d:\windows\network diagnostic
2009-05-03 22:13 118 a------- d:\windows\system32\MRT.INI
2009-05-02 21:13 221,184 a------- d:\windows\system32\wmpns.dll
2009-05-02 16:27 410,984 a------- d:\windows\system32\deploytk.dll
2009-05-02 16:16 159,232 a------- d:\windows\system32\ptpusd.dll
2009-05-02 16:16 5,632 a------- d:\windows\system32\ptpusb.dll
2009-05-02 16:16 15,104 a------- d:\windows\system32\drivers\usbscan.sys
2009-05-02 11:18 <DIR> --d----- D:\ClassX
2009-05-02 10:27 <DIR> --d----- d:\program files\Windows Media Connect 2
2009-04-30 19:38 397,312 -------- d:\windows\system32\mmcex.dll
2009-04-30 12:09 268,648 a------- d:\windows\system32\mucltui.dll
2009-04-30 12:09 208,744 a------- d:\windows\system32\muweb.dll
2009-04-30 12:09 27,496 a------- d:\windows\system32\mucltui.dll.mui
2009-04-29 18:54 <DIR> --d----- d:\program files\Trend Micro
2009-04-29 18:49 <DIR> --d----- d:\documents and settings\kristian\Tracing
2009-04-29 18:48 <DIR> --d----- d:\program files\Microsoft
2009-04-29 18:48 <DIR> --d----- d:\program files\Windows Live SkyDrive
2009-04-29 18:42 <DIR> --d----- d:\program files\common files\Windows Live
2009-04-29 18:27 272,128 -c------ d:\windows\system32\dllcache\bthport.sys
2009-04-29 18:24 473,600 -c------ d:\windows\system32\dllcache\fastprox.dll
2009-04-29 18:24 401,408 -c------ d:\windows\system32\dllcache\rpcss.dll
2009-04-29 18:24 284,160 -c------ d:\windows\system32\dllcache\pdh.dll
2009-04-29 18:24 110,592 -c------ d:\windows\system32\dllcache\services.exe
2009-04-29 18:24 729,088 -c------ d:\windows\system32\dllcache\lsasrv.dll
2009-04-29 18:24 617,472 -c------ d:\windows\system32\dllcache\advapi32.dll
2009-04-29 18:24 453,120 -c------ d:\windows\system32\dllcache\wmiprvsd.dll
2009-04-29 18:24 227,840 -c------ d:\windows\system32\dllcache\wmiprvse.exe
2009-04-29 18:24 714,752 -c------ d:\windows\system32\dllcache\ntdll.dll
2009-04-29 18:24 2,145,280 -c------ d:\windows\system32\dllcache\ntkrnlmp.exe
2009-04-29 18:24 2,189,056 -c------ d:\windows\system32\dllcache\ntoskrnl.exe
2009-04-29 18:24 2,023,936 -c------ d:\windows\system32\dllcache\ntkrpamp.exe
2009-04-29 18:21 203,136 -c------ d:\windows\system32\dllcache\rmcast.sys
2009-04-29 18:20 455,296 -c------ d:\windows\system32\dllcache\mrxsmb.sys
2009-04-29 18:20 333,952 -c------ d:\windows\system32\dllcache\srv.sys
2009-04-29 18:20 331,776 -c------ d:\windows\system32\dllcache\msadce.dll
2009-04-29 18:20 691,712 -c------ d:\windows\system32\dllcache\inetcomm.dll
2009-04-29 18:19 337,408 -c------ d:\windows\system32\dllcache\netapi32.dll
2009-04-29 18:19 1,106,944 -c------ d:\windows\system32\dllcache\msxml3.dll
2009-04-29 18:19 1,203,922 -c------ d:\windows\system32\dllcache\sysmain.sdb
2009-04-29 18:19 2,560 -------- d:\windows\system32\xpsp4res.dll
2009-04-29 18:19 215,552 -c------ d:\windows\system32\dllcache\wordpad.exe
2009-04-29 18:18 <DIR> --d----- d:\windows\system32\PreInstall
2009-04-29 18:18 <DIR> --d-h--- d:\windows\$hf_mig$
2009-04-29 18:18 247,326 -c------ d:\windows\system32\dllcache\strmdll.dll
2009-04-29 16:34 1,060,864 a------- d:\windows\system32\MFC71.dll
2009-04-29 16:34 499,712 a------- d:\windows\system32\MSVCP71.dll
2009-04-29 16:34 348,160 a------- d:\windows\system32\MSVCR71.dll
2009-04-29 16:11 <DIR> --d----- d:\docume~1\kristian\applic~1\Malwarebytes
2009-04-29 16:11 15,504 a------- d:\windows\system32\drivers\mbam.sys
2009-04-29 16:11 38,496 a------- d:\windows\system32\drivers\mbamswissarmy.sys
2009-04-29 16:11 <DIR> --d----- d:\program files\Malwarebytes' Anti-Malware
2009-04-29 16:11 <DIR> --d----- d:\docume~1\alluse~1\applic~1\Malwarebytes
2009-04-29 15:50 <DIR> --ds---- d:\documents and settings\kristian\UserData
2009-04-28 22:05 122,912 a--sh--- d:\windows\system32\drivers\fidbox2.dat
2009-04-28 22:05 1,500 a--sh--- d:\windows\system32\drivers\fidbox2.idx
2009-04-28 22:05 32 a--sh--- d:\windows\system32\drivers\fidbox.idx
2009-04-28 22:05 32 a--sh--- d:\windows\system32\drivers\fidbox.dat
2009-04-28 22:04 <DIR> --d----- d:\docume~1\alluse~1\applic~1\Kaspersky Lab Setup Files
2009-04-28 21:53 <DIR> --d----- d:\windows\system32\SoftwareDistribution
2009-04-28 21:39 <DIR> --d----- d:\windows\ServicePackFiles
2009-04-28 21:37 2,897,920 -------- d:\windows\system32\xpsp2res.dll
2009-04-28 21:36 19,528 a------- d:\windows\002236_.tmp
2009-04-28 21:36 26,488 a------- d:\windows\system32\spupdsvc.exe
2009-04-28 21:34 <DIR> --d----- d:\windows\EHome
2009-04-28 20:25 520,192 -------- d:\windows\system32\ati2sgag.exe
2009-04-28 20:25 <DIR> --d----- d:\windows\system32\ReinstallBackups
2009-04-28 20:24 <DIR> --d----- d:\program files\ATI Technologies
2009-04-28 20:14 <DIR> --ds---- d:\windows\system32\Microsoft
2009-04-28 20:14 6,272 a------- d:\windows\system32\drivers\splitter.sys
2009-04-28 20:14 83,072 a------- d:\windows\system32\drivers\wdmaud.sys
2009-04-28 20:14 52,864 a------- d:\windows\system32\drivers\dmusic.sys
2009-04-28 20:14 56,576 a------- d:\windows\system32\drivers\swmidi.sys
2009-04-28 20:14 577,536 a------- d:\windows\soundman.exe
2009-04-28 20:14 49,152 a------- d:\windows\system32\ChCfg.exe
2009-04-28 20:13 <DIR> --d----- d:\program files\Realtek AC97
2009-04-28 20:07 <DIR> --dsh--- d:\windows\Installer
2009-04-28 20:07 <DIR> --d----- d:\documents and settings\Kristian
2009-04-28 20:06 8,192 a------- d:\windows\REGLOCS.OLD
2009-04-28 20:03 471,102 ac------ d:\windows\system32\dllcache\imskdic.dll
2009-04-28 20:02 2,626 a------- d:\windows\system32\CONFIG.NT
2009-04-28 20:02 0 a------- d:\windows\control.ini
2009-04-28 20:02 25,065 a------- d:\windows\system32\wmpscheme.xml
2009-04-28 20:02 23,392 a------- d:\windows\system32\nscompat.tlb
2009-04-28 20:02 16,832 a------- d:\windows\system32\amcompat.tlb
2009-04-28 20:02 299,552 a------- d:\windows\WMSysPrx.prx
2009-04-28 20:01 <DIR> --dsh--- d:\documents and settings\all users\DRM
2009-04-28 20:01 488 a---hr-- d:\windows\system32\WindowsLogon.manifest
2009-04-28 20:01 488 a---hr-- d:\windows\system32\logonui.exe.manifest
2009-04-28 20:01 <DIR> --ds---- d:\windows\Downloaded Program Files
2009-04-28 20:01 <DIR> --d--r-- d:\windows\Offline Web Pages
2009-04-28 20:01 749 a---hr-- d:\windows\WindowsShell.Manifest
2009-04-28 20:01 749 a---hr-- d:\windows\system32\wuaucpl.cpl.manifest
2009-04-28 20:01 749 a---hr-- d:\windows\system32\sapi.cpl.manifest
2009-04-28 20:01 749 a---hr-- d:\windows\system32\nwc.cpl.manifest
2009-04-28 20:01 749 a---hr-- d:\windows\system32\ncpa.cpl.manifest
2009-04-28 20:01 749 a---hr-- d:\windows\system32\cdplayer.exe.manifest
2009-04-28 20:01 4,399,505 ac------ d:\windows\system32\dllcache\nls302en.lex
2009-04-28 20:01 <DIR> --d----- d:\windows\system32\DirectX
2009-04-28 20:00 <DIR> --d----- d:\program files\common files\MSSoap
2009-04-28 19:59 <DIR> --d-h--- d:\program files\WindowsUpdate
2009-04-28 19:59 <DIR> --d----- d:\program files\Online Services
2009-04-28 19:59 <DIR> --d----- d:\program files\MSN Gaming Zone
2009-04-28 19:58 <DIR> --d----- d:\program files\Windows NT
2009-04-28 15:23 <DIR> --d----- d:\program files\common files\ODBC
2009-04-28 15:23 <DIR> --d----- d:\program files\common files\SpeechEngines
2009-04-28 15:22 <DIR> --d--r-- d:\documents and settings\all users\Documents

==================== Find3M ====================

2009-05-10 10:04 2,678 a------- d:\windows\java\packages\data\FLF7PRTN.DAT
2009-05-10 10:04 2,678 a------- d:\windows\java\packages\data\LR7P7XN9.DAT
2009-05-10 10:04 2,678 a------- d:\windows\java\packages\data\C7PRL7DZ.DAT
2009-05-10 10:04 2,678 a------- d:\windows\java\packages\data\AWWJTN5B.DAT
2009-05-07 08:12 86,327 a------- d:\windows\pchealth\helpctr\offlinecache\index.dat
2009-04-28 19:59 21,640 a------- d:\windows\system32\emptyregdb.dat
2009-04-15 16:25 129,784 -------- d:\windows\system32\pxafs.dll
2009-04-15 16:25 120,056 -------- d:\windows\system32\pxcpyi64.exe
2009-04-15 16:25 118,520 -------- d:\windows\system32\pxinsi64.exe
2009-04-15 16:25 43,528 -------- d:\windows\system32\drivers\PxHelp20.sys
2009-04-15 16:25 9,464 -------- d:\windows\system32\drivers\cdralw2k.sys
2009-04-15 16:25 9,336 -------- d:\windows\system32\drivers\cdr4_xp.sys
2009-04-15 16:24 90,112 a------- d:\windows\system32\dpl100.dll
2009-04-15 16:24 823,296 a------- d:\windows\system32\divx_xx0c.dll
2009-04-15 16:24 823,296 a------- d:\windows\system32\divx_xx07.dll
2009-04-15 16:24 815,104 a------- d:\windows\system32\divx_xx0a.dll
2009-04-15 16:24 802,816 a------- d:\windows\system32\divx_xx11.dll
2009-04-15 16:24 684,032 a------- d:\windows\system32\DivX.dll
2009-03-06 10:22 284,160 a------- d:\windows\system32\pdh.dll
2009-02-20 04:10 666,112 a------- d:\windows\system32\wininet.dll
2009-02-20 04:10 81,920 -------- d:\windows\system32\ieencode.dll

============= FINISH: 20:18:25.64 ===============

#9 PropagandaPanda

PropagandaPanda


  • Malware Response Team
  • 10,433 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:46 AM

Posted 18 May 2009 - 09:25 AM

Hello.

It looks good. Unless there are any issues at the moment, we can wrap up.

Uninstall ComboFix
Remove Combofix now that we're done with it.
  • Click on your Start Menu, then Run....
  • Now type the following into the runbox and click OK. Notice the space between the "x" and "/".
    ComboFix /u

    Posted Image
Uninstalling ComboFix will do the following:
  • Delete ComboFix and its components from your computer.
  • Delete other tools commonly used during the malware removal process.
  • Resets clock settings to standard format.
  • Hides file extensions and hidden/system files.
  • Clears System Restore cache and creates new restore point.
Preventing Malware Infection in the Future
Please take some time to look at the following links, giving some advice and suggestions for preventing future infections: For general slowness problems that you may have, take a look at Slow Computer/browser? It May Not Be Malware. Read How to use the Startup Database to identify and disable uneeded processes and increase the amount of available resources.

Do you have any questions or concerns?

With Regards,
The Panda

#10 ClassX

ClassX
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:10:46 AM

Posted 20 May 2009 - 06:56 AM

Yah... Sometimes when im in google. I try to click on a link, but it redirects me to a complete different site,
Usually i have to put the URL manually in my browser for it to work?

#11 PropagandaPanda

PropagandaPanda


  • Malware Response Team
  • 10,433 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:46 AM

Posted 20 May 2009 - 07:06 AM

Hello.

This is still occuring right now?

If so, download and run a new copy of ComboFix. Also take a new GMER log.

With Regards,
The Panda

#12 ClassX

ClassX
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:10:46 AM

Posted 22 May 2009 - 06:46 PM

ComboFix 09-05-22.05 - Kristian 05/22/2009 18:38.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.760.397 [GMT -4:00]
Running from: d:\documents and settings\Kristian\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090522-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((( Files Created from 2009-04-22 to 2009-05-22 )))))))))))))))))))))))))))))))
.

2009-05-19 23:59 . 2009-05-20 00:03 -------- d-----w d:\program files\Steam
2009-05-18 21:58 . 2009-05-18 22:03 -------- d-----w d:\program files\Soldier of Fortune II - Double Helix MP TEST
2009-05-17 21:11 . 2009-05-17 21:11 -------- d-----w d:\documents and settings\Kristian\Application Data\DivX
2009-05-15 21:27 . 2006-10-26 23:56 32592 ----a-w d:\windows\system32\msonpmon.dll
2009-05-15 21:26 . 2009-05-15 21:26 -------- d-----w d:\program files\Microsoft Works
2009-05-15 21:26 . 2009-05-15 21:26 -------- d-----w d:\program files\MSBuild
2009-05-15 21:00 . 2009-05-15 21:16 -------- d-----w d:\windows\SHELLNEW
2009-05-15 20:59 . 2009-05-15 20:59 -------- d-----w d:\documents and settings\Kristian\Local Settings\Application Data\Microsoft Help
2009-05-15 20:59 . 2009-05-16 07:00 -------- d-----w d:\documents and settings\All Users\Application Data\Microsoft Help
2009-05-15 20:58 . 2009-05-15 20:58 -------- d--h--r D:\MSOCache
2009-05-12 12:02 . 2009-05-12 12:02 -------- d-----w d:\program files\uTorrent
2009-05-12 12:02 . 2009-05-18 19:06 -------- d-----w d:\documents and settings\Kristian\Application Data\uTorrent
2009-05-12 07:00 . 2009-05-12 07:00 -------- d-----w d:\windows\system32\KB905474
2009-05-12 07:00 . 2009-03-11 02:26 1403264 ----a-w d:\windows\system32\KB905474\wganotifypackageinner.exe
2009-05-12 07:00 . 2009-03-11 02:18 453512 ----a-w d:\windows\system32\KB905474\wgasetup.exe
2009-05-12 01:10 . 2009-05-12 01:10 -------- d-----w d:\program files\Java
2009-05-11 23:56 . 2009-05-11 23:57 -------- d-----w d:\documents and settings\Kristian\Local Settings\Application Data\Adobe
2009-05-11 23:56 . 2009-05-11 23:56 -------- d-----w d:\program files\Common Files\Adobe AIR
2009-05-11 23:55 . 2009-05-11 23:56 -------- d-----w d:\program files\Common Files\Adobe
2009-05-10 14:10 . 2009-05-10 14:10 -------- d-----w d:\program files\Web Publish
2009-05-09 14:21 . 2009-05-09 14:21 -------- d-----w d:\program files\Hewlett-Packard
2009-05-09 14:21 . 2009-05-09 14:21 -------- d-----w d:\program files\Common Files\Hewlett-Packard
2009-05-09 14:20 . 2006-04-10 18:03 38400 ----a-w d:\windows\system32\hpz3l054.dll
2009-05-09 14:19 . 2006-03-04 01:03 282680 ----a-w d:\windows\system32\HPZidr12.dll
2009-05-09 14:19 . 2006-03-04 01:03 65536 ----a-w d:\windows\system32\HPZinw12.exe
2009-05-09 14:19 . 2006-03-04 01:03 69632 ----a-w d:\windows\system32\HPZipm12.exe
2009-05-09 14:19 . 2006-03-04 01:02 204800 ----a-w d:\windows\system32\HPZipr12.dll
2009-05-09 14:19 . 2006-03-04 01:02 94208 ----a-w d:\windows\system32\HPZipt12.dll
2009-05-09 14:19 . 2006-03-04 01:02 57344 ----a-w d:\windows\system32\HPZisn12.dll
2009-05-09 14:19 . 1998-10-29 20:45 306688 ----a-w d:\windows\IsUninst.exe
2009-05-09 14:18 . 2009-05-09 14:19 -------- d-----w d:\program files\HP
2009-05-09 14:18 . 2008-04-13 18:47 25856 -c--a-w d:\windows\system32\dllcache\usbprint.sys
2009-05-09 14:18 . 2008-04-13 18:47 25856 ----a-w d:\windows\system32\drivers\usbprint.sys
2009-05-09 14:18 . 2008-04-13 18:45 32128 -c--a-w d:\windows\system32\dllcache\usbccgp.sys
2009-05-09 14:18 . 2008-04-13 18:45 32128 ----a-w d:\windows\system32\drivers\usbccgp.sys
2009-05-09 14:18 . 2009-05-09 14:22 110389 ----a-w d:\windows\hpoins11.dat
2009-05-09 14:18 . 2006-04-13 00:04 49664 ----a-w d:\windows\system32\drivers\HPZid412.sys
2009-05-09 14:18 . 2006-04-13 00:04 21568 ----a-w d:\windows\system32\drivers\HPZius12.sys
2009-05-09 14:18 . 2006-04-13 00:04 16496 ----a-w d:\windows\system32\drivers\HPZipr12.sys
2009-05-09 14:17 . 2006-04-13 00:04 282624 ----a-w d:\windows\system32\HPZc3212.dll
2009-05-09 14:17 . 2006-04-13 00:02 659456 ----a-w d:\windows\system32\hpowiax2.dll
2009-05-09 14:17 . 2006-04-13 00:02 254026 ----a-w d:\windows\system32\hpovst09.dll
2009-05-09 14:17 . 2006-04-13 00:02 827392 ----a-w d:\windows\system32\hpotiop2.dll
2009-05-09 14:17 . 2006-01-04 08:12 77824 ----a-w d:\windows\system32\HPZIDS01.dll
2009-05-09 14:17 . 2005-07-19 01:38 98304 ----a-w d:\windows\system32\hpzjsn01.dll
2009-05-09 14:17 . 2006-05-06 03:10 6947 ----a-w d:\windows\hpomdl11.dat
2009-05-08 21:28 . 2009-05-08 21:28 -------- d-----w d:\program files\FLV Player
2009-05-07 12:09 . 2009-05-07 12:09 -------- d-----w d:\windows\system32\scripting
2009-05-07 12:09 . 2009-05-07 12:09 -------- d-----w d:\windows\system32\en
2009-05-07 12:09 . 2009-05-07 12:09 -------- d-----w d:\windows\l2schemas
2009-05-07 12:09 . 2009-05-07 12:09 -------- d-----w d:\windows\system32\bits
2009-05-03 01:14 . 2008-04-14 00:12 26624 ----a-w d:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-05-03 01:13 . 2004-08-04 04:56 221184 ----a-w d:\windows\system32\wmpns.dll
2009-05-02 20:28 . 2009-05-02 20:28 -------- d-----w d:\windows\Sun
2009-05-02 20:27 . 2009-05-02 20:27 57344 ----a-w d:\documents and settings\Kristian\Application Data\Sun\Java\Deployment\cache\6.0\50\5b902232-2334530f-n\Decora-SSE.dll
2009-05-02 20:27 . 2009-05-02 20:27 315392 ----a-w d:\documents and settings\Kristian\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-3ae55003-n\jogl.dll
2009-05-02 20:27 . 2009-05-02 20:27 24064 ----a-w d:\documents and settings\Kristian\Application Data\Sun\Java\Deployment\cache\6.0\15\4e09eacf-569374d8-n\Decora-D3D.dll
2009-05-02 20:27 . 2009-05-02 20:27 20480 ----a-w d:\documents and settings\Kristian\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-3ae55003-n\jogl_awt.dll
2009-05-02 20:27 . 2009-05-02 20:27 114688 ----a-w d:\documents and settings\Kristian\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-3ae55003-n\jogl_cg.dll
2009-05-02 20:27 . 2009-05-02 20:27 20480 ----a-w d:\documents and settings\Kristian\Application Data\Sun\Java\Deployment\cache\6.0\45\4f710eed-4d2081e4-n\gluegen-rt.dll
2009-05-02 20:27 . 2009-05-02 20:27 499712 ----a-w d:\documents and settings\Kristian\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-747a62f1-n\msvcp71.dll
2009-05-02 20:27 . 2009-05-02 20:27 499712 ----a-w d:\documents and settings\Kristian\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-747a62f1-n\jmc.dll
2009-05-02 20:27 . 2009-05-02 20:27 348160 ----a-w d:\documents and settings\Kristian\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-747a62f1-n\msvcr71.dll
2009-05-02 20:27 . 2009-05-12 01:10 410984 ----a-w d:\windows\system32\deploytk.dll
2009-05-02 20:26 . 2009-05-12 01:09 152576 ----a-w d:\documents and settings\Kristian\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-02 20:16 . 2004-08-04 04:56 159232 ----a-w d:\windows\system32\ptpusd.dll
2009-05-02 20:16 . 2001-08-18 02:36 5632 ----a-w d:\windows\system32\ptpusb.dll
2009-05-02 20:16 . 2008-04-13 18:45 15104 ----a-w d:\windows\system32\drivers\usbscan.sys
2009-05-02 15:18 . 2009-05-22 22:33 -------- d-----w D:\ClassX
2009-05-02 14:28 . 2009-05-02 14:28 -------- d-----w d:\windows\system32\drivers\umdf
2009-05-02 14:27 . 2009-05-02 14:27 -------- d-----w d:\program files\Windows Media Connect 2
2009-04-30 23:38 . 2008-04-14 00:12 33792 ------w d:\windows\system32\mmcperf.exe
2009-04-30 16:09 . 2008-10-16 18:06 268648 ----a-w d:\windows\system32\mucltui.dll
2009-04-30 16:09 . 2008-10-16 18:06 208744 ----a-w d:\windows\system32\muweb.dll
2009-04-29 23:10 . 2009-04-29 23:12 -------- d-----w d:\documents and settings\Kristian\Local Settings\Application Data\Google
2009-04-29 22:54 . 2009-04-29 22:54 -------- d-----w d:\program files\Trend Micro
2009-04-29 22:49 . 2009-05-22 21:49 -------- d-----w d:\documents and settings\Kristian\Tracing
2009-04-29 22:48 . 2009-04-29 22:48 -------- d-----w d:\program files\Microsoft
2009-04-29 22:48 . 2009-04-29 22:48 -------- d-----w d:\program files\Windows Live SkyDrive
2009-04-29 22:48 . 2009-04-29 22:48 -------- d-----w d:\program files\Windows Live
2009-04-29 22:42 . 2009-04-29 22:42 -------- d-----w d:\program files\Common Files\Windows Live
2009-04-29 22:27 . 2008-06-13 11:05 272128 -c----w d:\windows\system32\dllcache\bthport.sys
2009-04-29 22:24 . 2009-03-06 14:22 284160 -c----w d:\windows\system32\dllcache\pdh.dll
2009-04-29 22:24 . 2009-02-09 12:10 473600 -c----w d:\windows\system32\dllcache\fastprox.dll
2009-04-29 22:24 . 2009-02-09 12:10 401408 -c----w d:\windows\system32\dllcache\rpcss.dll
2009-04-29 22:24 . 2009-02-06 11:11 110592 -c----w d:\windows\system32\dllcache\services.exe
2009-04-29 22:24 . 2009-02-09 12:10 729088 -c----w d:\windows\system32\dllcache\lsasrv.dll
2009-04-29 22:24 . 2009-02-09 12:10 617472 -c----w d:\windows\system32\dllcache\advapi32.dll
2009-04-29 22:24 . 2009-02-09 12:10 453120 -c----w d:\windows\system32\dllcache\wmiprvsd.dll
2009-04-29 22:24 . 2009-02-06 10:10 227840 -c----w d:\windows\system32\dllcache\wmiprvse.exe
2009-04-29 22:24 . 2009-02-09 12:10 714752 -c----w d:\windows\system32\dllcache\ntdll.dll
2009-04-29 22:24 . 2009-02-06 11:06 2145280 -c----w d:\windows\system32\dllcache\ntkrnlmp.exe
2009-04-29 22:24 . 2009-02-06 11:08 2189056 -c----w d:\windows\system32\dllcache\ntoskrnl.exe
2009-04-29 22:24 . 2009-02-06 10:32 2023936 -c----w d:\windows\system32\dllcache\ntkrpamp.exe
2009-04-29 22:21 . 2008-05-08 14:02 203136 -c----w d:\windows\system32\dllcache\rmcast.sys
2009-04-29 22:20 . 2008-10-24 11:21 455296 -c----w d:\windows\system32\dllcache\mrxsmb.sys
2009-04-29 22:20 . 2008-12-11 10:57 333952 -c----w d:\windows\system32\dllcache\srv.sys
2009-04-29 22:20 . 2008-05-01 14:33 331776 -c----w d:\windows\system32\dllcache\msadce.dll
2009-04-29 22:20 . 2008-04-11 19:04 691712 -c----w d:\windows\system32\dllcache\inetcomm.dll
2009-04-29 22:19 . 2008-10-15 16:34 337408 -c----w d:\windows\system32\dllcache\netapi32.dll
2009-04-29 22:19 . 2008-09-04 17:15 1106944 -c----w d:\windows\system32\dllcache\msxml3.dll
2009-04-29 22:19 . 2008-05-03 11:55 2560 ------w d:\windows\system32\xpsp4res.dll
2009-04-29 22:19 . 2008-04-21 12:08 215552 -c----w d:\windows\system32\dllcache\wordpad.exe
2009-04-29 22:18 . 2009-05-08 07:00 -------- d--h--w d:\windows\$hf_mig$
2009-04-29 22:18 . 2008-10-03 10:02 247326 -c----w d:\windows\system32\dllcache\strmdll.dll
2009-04-29 20:35 . 2009-02-05 20:06 23152 ----a-w d:\windows\system32\drivers\aswRdr.sys
2009-04-29 20:35 . 2009-02-05 20:06 51376 ----a-w d:\windows\system32\drivers\aswTdi.sys
2009-04-29 20:35 . 2009-02-05 20:05 26944 ----a-w d:\windows\system32\drivers\aavmker4.sys
2009-04-29 20:35 . 2009-02-05 20:04 97480 ----a-w d:\windows\system32\AvastSS.scr
2009-04-29 20:35 . 2009-02-05 20:08 93296 ----a-w d:\windows\system32\drivers\aswmon.sys
2009-04-29 20:35 . 2009-02-05 20:08 94032 ----a-w d:\windows\system32\drivers\aswmon2.sys
2009-04-29 20:35 . 2009-02-05 20:07 114768 ----a-w d:\windows\system32\drivers\aswSP.sys
2009-04-29 20:35 . 2009-02-05 20:07 20560 ----a-w d:\windows\system32\drivers\aswFsBlk.sys
2009-04-29 20:34 . 2009-02-05 20:11 1256296 ----a-w d:\windows\system32\aswBoot.exe
2009-04-29 20:34 . 2003-03-18 19:20 1060864 ----a-w d:\windows\system32\MFC71.dll
2009-04-29 20:34 . 2003-03-18 18:14 499712 ----a-w d:\windows\system32\MSVCP71.dll
2009-04-29 20:34 . 2003-02-21 02:42 348160 ----a-w d:\windows\system32\MSVCR71.dll
2009-04-29 20:34 . 2009-04-29 20:34 -------- d-----w d:\program files\Alwil Software
2009-04-29 20:11 . 2009-04-29 20:11 -------- d-----w d:\documents and settings\Kristian\Application Data\Malwarebytes
2009-04-29 20:11 . 2009-04-06 19:32 15504 ----a-w d:\windows\system32\drivers\mbam.sys
2009-04-29 20:11 . 2009-04-06 19:32 38496 ----a-w d:\windows\system32\drivers\mbamswissarmy.sys
2009-04-29 20:11 . 2009-04-29 20:11 -------- d-----w d:\program files\Malwarebytes' Anti-Malware
2009-04-29 20:11 . 2009-04-29 20:11 -------- d-----w d:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-29 20:06 . 2009-04-29 20:06 0 ----a-w d:\windows\nsreg.dat
2009-04-29 20:06 . 2009-04-29 20:06 -------- d-----w d:\documents and settings\Kristian\Local Settings\Application Data\Mozilla

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-16 17:52 . 2009-05-16 17:51 -------- d-----w d:\program files\DivX
2009-05-16 17:51 . 2009-05-16 17:51 -------- d-----w d:\program files\Common Files\DivX Shared
2009-05-10 14:04 . 2009-05-10 14:04 2678 ----a-w d:\windows\java\Packages\Data\FLF7PRTN.DAT
2009-05-10 14:04 . 2009-05-10 14:04 2678 ----a-w d:\windows\java\Packages\Data\LR7P7XN9.DAT
2009-05-10 14:04 . 2009-05-10 14:04 2678 ----a-w d:\windows\java\Packages\Data\C7PRL7DZ.DAT
2009-05-10 14:04 . 2009-05-10 14:04 2678 ----a-w d:\windows\java\Packages\Data\AWWJTN5B.DAT
2009-05-07 12:12 . 2009-04-29 00:02 86327 ----a-w d:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-04-29 02:14 . 2009-04-29 02:05 32 --sha-w d:\windows\system32\drivers\fidbox.idx
2009-04-29 02:14 . 2009-04-29 02:05 1500 --sha-w d:\windows\system32\drivers\fidbox2.idx
2009-04-29 00:25 . 2009-04-29 00:13 -------- d-----w d:\program files\Common Files\InstallShield
2009-04-29 00:25 . 2009-04-29 00:13 -------- d--h--w d:\program files\InstallShield Installation Information
2009-04-29 00:24 . 2009-04-29 00:24 -------- d-----w d:\program files\ATI Technologies
2009-04-29 00:13 . 2009-04-29 00:13 -------- d-----w d:\program files\Realtek AC97
2009-04-29 00:03 . 2009-04-29 00:03 -------- d-----w d:\program files\microsoft frontpage
2009-04-28 23:59 . 2009-04-28 23:59 21640 ----a-w d:\windows\system32\emptyregdb.dat
2009-04-15 20:25 . 2009-05-16 17:51 9464 ------w d:\windows\system32\drivers\cdralw2k.sys
2009-04-15 20:25 . 2009-05-16 17:51 9336 ------w d:\windows\system32\drivers\cdr4_xp.sys
2009-04-15 20:25 . 2009-05-16 17:51 43528 ------w d:\windows\system32\drivers\PxHelp20.sys
2009-04-15 20:25 . 2009-05-16 17:51 129784 ------w d:\windows\system32\pxafs.dll
2009-04-15 20:25 . 2009-05-16 17:51 120056 ------w d:\windows\system32\pxcpyi64.exe
2009-04-15 20:25 . 2009-05-16 17:51 118520 ------w d:\windows\system32\pxinsi64.exe
2009-04-15 20:24 . 2009-04-15 20:24 90112 ----a-w d:\windows\system32\dpl100.dll
2009-04-15 20:24 . 2009-04-15 20:24 823296 ----a-w d:\windows\system32\divx_xx0c.dll
2009-04-15 20:24 . 2009-04-15 20:24 823296 ----a-w d:\windows\system32\divx_xx07.dll
2009-04-15 20:24 . 2009-04-15 20:24 815104 ----a-w d:\windows\system32\divx_xx0a.dll
2009-04-15 20:24 . 2009-04-15 20:24 802816 ----a-w d:\windows\system32\divx_xx11.dll
2009-04-15 20:24 . 2009-04-15 20:24 684032 ----a-w d:\windows\system32\DivX.dll
2009-03-06 14:22 . 2002-08-29 01:41 284160 ----a-w d:\windows\system32\pdh.dll
2009-04-15 20:24 . 2009-04-15 20:24 1044480 ----a-w d:\program files\mozilla firefox\plugins\libdivx.dll
2009-04-15 20:24 . 2009-04-15 20:24 200704 ----a-w d:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-05-17_15.46.25 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-19 23:59 . 2009-05-19 23:59 27648 d:\windows\Installer\{048298C9-A4D3-490B-9FF9-AB023A9238F3}\Icon048298C91.exe
+ 2009-04-22 22:05 . 2009-04-22 22:05 406640 d:\windows\Downloaded Program Files\fslauncher.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="d:\documents and settings\Kristian\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-04-29 133104]
"ctfmon.exe"="d:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Steam"="d:\program files\Steam\Steam.exe" [2009-05-20 1217784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="d:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2009-05-12 148888]
"GrooveMonitor"="d:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\Messenger\\msmsgs.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"d:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\Program Files\\Soldier of Fortune II - Double Helix MP TEST\\SoF2MP-Test.exe"=

R1 aswSP;avast! Self Protection;d:\windows\system32\drivers\aswSP.sys [4/29/2009 4:35 PM 114768]
R2 aswFsBlk;aswFsBlk;d:\windows\system32\drivers\aswFsBlk.sys [4/29/2009 4:35 PM 20560]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - AUJASNKJ
*NewlyCreated* - F-SECURE_STANDALONE_MINIFILTER
*NewlyCreated* - FSBL
*Deregistered* - aujasnkj
*Deregistered* - F-Secure Standalone Minifilter
*Deregistered* - fsbl
.
Contents of the 'Scheduled Tasks' folder

2009-05-22 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-1767777339-725345543-1003.job
- d:\documents and settings\Kristian\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-29 23:10]

2009-05-17 d:\windows\Tasks\WGASetup.job
- d:\windows\system32\KB905474\wgasetup.exe [2009-05-12 02:18]
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-procexp90.Sys


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
FF - ProfilePath - d:\documents and settings\Kristian\Application Data\Mozilla\Firefox\Profiles\ylkmy3tq.default\
FF - plugin: d:\documents and settings\Kristian\Local Settings\Application Data\Google\Update\1.2.145.5\npGoogleOneClick8.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-22 18:40
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(612)
d:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(4112)
d:\windows\system32\WPDShServiceObj.dll
d:\windows\system32\PortableDeviceTypes.dll
d:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-05-22 18:42
ComboFix-quarantined-files.txt 2009-05-22 22:41
ComboFix2.txt 2009-05-17 15:50

Pre-Run: 89,137,029,120 bytes free
Post-Run: 89,309,003,776 bytes free

252 --- E O F --- 2009-05-16 07:00






GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-05-22 19:45:19
Windows 5.1.2600 Service Pack 3


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xEDDED6B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xEDDED574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xEDDEDA52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xEDDED14C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xEDDED64E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xEDDED08C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xEDDED0F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xEDDED76E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xEDDED72E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xEDDED8AE]

Code \??\D:\DOCUME~1\Kristian\LOCALS~1\Temp\catchme.sys pIofCallDriver

---- Kernel code sections - GMER 1.0.15 ----

? Combo-Fix.sys The system cannot find the file specified. !
? D:\DOCUME~1\Kristian\LOCALS~1\Temp\catchme.sys The system cannot find the file specified. !
? D:\WINDOWS\system32\Drivers\PROCEXP90.SYS The system cannot find the file specified. !

---- User IAT/EAT - GMER 1.0.15 ----

IAT D:\WINDOWS\system32\services.exe[660] @ D:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT D:\WINDOWS\system32\services.exe[660] @ D:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy@imagepath \systemroot\system32\drivers\ovfsthkvvmpydcrmktpayvtbdokxdlqkvkfrmp.sys
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy@inst 0
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main@ver sni060409
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main@cid 01
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main@bid 1224293322-1417001333-1767777339-725345543
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main@aid 998
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main@sid 3
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main@feed 0x22 0x64 0x78 0x36 ...
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main@cmddelay 28801
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main\delete
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main\ff
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main\ff@extension \\?\D:\Program Files\Mozilla Firefox\extensions\{EAEF60DF-1687-4BBF-A1A2-B3F2A7F4E790}
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main\ff@version 1
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main\injector
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main\injector@iexplore.exe ovfsthwi.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main\injector@explorer.exe ovfsthff.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\main\tasks
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\modules
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\modules@ovfsth.sys \systemroot\system32\drivers\ovfsthkvvmpydcrmktpayvtbdokxdlqkvkfrmp.sys
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\modules@ovfsth.dll \systemroot\system32\ovfsthnloxkdsgavpyimfehooipppxspmkxqfy.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\modules@ovfsthlog.dat \systemroot\system32\ovfsthkxjxoulehcephgwhutvfrkyfmvqxqjct.dat
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\modules@ovfsthwi.dll \systemroot\system32\ovfsthcqiboikxxgidhlkuhxgahfkpgniubylm.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\modules@ovfsthff.dll \systemroot\system32\ovfsthbfworwokxvuhblfxcilrylraknstxhje.dll
Reg HKLM\SYSTEM\ControlSet003\Services\ovfsthboyeuiqtgenqtjwlotxejiaimovrjboy\modules@ovfsth.dat \systemroot\system32\ovfsthxaynnyrlyqbraxtnhdlghqnpnthlgplb.dat

---- EOF - GMER 1.0.15 ----

#13 PropagandaPanda

PropagandaPanda


  • Malware Response Team
  • 10,433 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:46 AM

Posted 23 May 2009 - 04:25 PM

Hello.

I don't see any active infection remaining.

Let's run another scan.

Download and Run ATFCleaner
Please download ATF Cleaner by Atribune. This program will clear out temporary files and settings. You will likely be logged out of the forum where you are recieving help.
  • Double-click ATF-Cleaner.exe to run the program. If you are using Windows Vista, right click the icon and select Run As Administrator.
  • Under Main Select Files to Delete choose: Select All.
  • Click the Empty Selected button.
Run Scan with Kaspersky
Please do a scan with Kaspersky Online Scanner.

This scan is for Internet Explorer Only.

If you are using Windows Vista, open your browser by right-clicking on its icon and select Run as administrator to perform this scan.

  • Please disable your realtime protection software before proceeding. Refer to this page if you are unsure how.
  • Open the Kaspersky Scanner page.
  • Click on Accept and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
You can refer to this animation by sundavis.

This scanner will only scan. It does not remove any malware it finds.


Download and Run SmitFruadFix Scan
  • Please download SmitFraudFix by S!Ri to your desktop.
  • Double click the icon to run it.
  • Select Option 1 by typing 1 and hitting Enter.
  • When the scan is complete, a log file will appear. Please copy the contents of the log into your next post.

With Regards,
The Panda

#14 PropagandaPanda

PropagandaPanda


  • Malware Response Team
  • 10,433 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:46 AM

Posted 16 June 2009 - 07:43 AM

Hello.

There had been no reply from the topic starter in 5 days. Due to inactivity, this topic is now closed.
If you are the topic starter and need this topic reopened, send me a message.

Everyone else, please begin a new topic.

With Regards,
The Panda




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users