Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with Trojan horse Injector.EL


  • This topic is locked This topic is locked
15 replies to this topic

#1 creid

creid

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:06:35 AM

Posted 14 June 2009 - 07:59 PM

I've just been recently infected with a couple Trojan horse viruses that AVG was able to remove but this particular Trojan horse Injector.EL persists. Its located in my /Window/System32 folder and appears as MSIV(randomletters).dll. I get a warning of it each time I open up a browser (both IE and Firefox). I've looked around for help for the past few hours and have tried some of the suggestions given to other folks but the worst part about is that while looking for help on this and following suggestions that lead me to places that could help, the browser would inform me the site can't be loaded. Whether the sites aren't working anymore or this virus is blocking me from using them, I wouldn't know. One of the sites was malwarebytes.org which seems to be the scanner most folks have suggested to use. I managed to download it through cnet but when I attempted to use it after installing it wouldn't run, I had to rename it to have it load up. Unfortunately, during the few times I've scanned with it it would freeze up and I've been forced to shut it down through ctrl+alt+del. I've also tried the online scan from Kaspersky's but when trying to update it also ends up canceling.

While looking for more answers I was told to use HiJackThis and post my log on this forum. Anyway, hopefully I can get all of this resolved. Here is the DDS.txt I was supposed to post along with the details of my problem:

DDS (Ver_09-05-14.01) - NTFSx86
Run by Alann Cabang at 20:25:27.63 on Sun 06/14/2009
Internet Explorer: 8.0.6001.18783 BrowserJavaVersion: 1.6.0_13
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.3326.2175 [GMT -4:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Logitech\Gaming Software\LWEMon.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Windows\system32\SearchIndexer.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Common Files\Steam\SteamService.exe
C:\program files\mozilla firefox\firefox.exe
C:\Users\Alann Cabang\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
uRun: [BitTorrent] "c:\program files\bittorrent\bittorrent.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Steam] "c:\program files\steam\steam.exe" -silent
uRun: [PLAYXPERT] c:\program files\playxpert\PXP.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [VirtualCloneDrive] "c:\program files\elaborate bytes\virtualclonedrive\VCDDaemon.exe" /s
mRun: [Start WingMan Profiler] c:\program files\logitech\gaming software\LWEMon.exe /noui
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
StartupFolder: c:\users\alannc~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\stardo~1.lnk - c:\program files\stardock\objectdock\ObjectDock.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.srtest.com/srl_bin/sysreqlab_srl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
TCP: NameServer = 85.255.112.235,85.255.112.106
TCP: {069EEB30-5BE5-4D3C-96D0-87038C25EB46} = 85.255.112.235,85.255.112.106
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
AppInit_DLLs: avgrsstx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\alannc~1\appdata\roaming\mozilla\firefox\profiles\2irh67p6.default\
FF - prefs.js: browser.search.selectedEngine - Dictionary
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - plugin: c:\program files\mozilla firefox\plugins\nphssb.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-1-15 325896]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-2-18 108552]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-4-28 176128]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-1-15 908568]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-1-15 298776]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2009-4-24 95544]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2009-6-3 55280]
S3 fsssvc;Windows Live Family Safety;c:\program files\windows live\family safety\fsssvc.exe [2009-2-6 533360]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-6-14 40160]

=============== Created Last 30 ================

2009-06-14 18:29 <DIR> --d----- c:\users\alannc~1\appdata\roaming\Malwarebytes
2009-06-14 18:24 40,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-14 18:24 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-06-14 18:24 <DIR> --d----- c:\programdata\Malwarebytes
2009-06-14 18:24 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-06-14 18:24 <DIR> --d----- c:\progra~2\Malwarebytes
2009-06-14 17:21 <DIR> --d----- c:\users\alannc~1\appdata\roaming\GetRightToGo
2009-06-13 09:00 428,544 a------- c:\windows\system32\EncDec.dll
2009-06-13 09:00 293,376 a------- c:\windows\system32\psisdecd.dll
2009-06-13 09:00 217,088 a------- c:\windows\system32\psisrndr.ax
2009-06-13 09:00 177,664 a------- c:\windows\system32\mpg2splt.ax
2009-06-13 09:00 80,896 a------- c:\windows\system32\MSNP.ax
2009-06-07 16:01 <DIR> --d----- c:\programdata\Apple Computer
2009-06-05 15:03 107,888 a------- c:\windows\system32\CmdLineExt.dll
2009-06-04 10:42 <DIR> --d----- c:\program files\Microsoft Games for Windows - LIVE
2009-06-04 01:37 <DIR> --d----- c:\windows\system32\xlive
2009-06-03 21:00 55,280 a------- c:\windows\system32\drivers\fssfltr.sys
2009-06-03 20:58 <DIR> --d----- c:\program files\Microsoft SQL Server Compact Edition
2009-06-03 19:09 <DIR> --d----- c:\program files\Pcsx2
2009-06-02 11:09 <DIR> --d----- c:\programdata\ATI
2009-06-02 10:46 <DIR> --d----- c:\programdata\Adobe
2009-06-02 10:15 410,984 a------- c:\windows\system32\deploytk.dll
2009-06-01 12:48 <DIR> --d----- c:\program files\VentSrv
2009-05-30 11:05 <DIR> --d----- c:\program files\Microsoft IntelliType Pro
2009-05-26 17:18 90,112 a------- c:\windows\system32\QuickTimeVR.qtx
2009-05-26 17:18 57,344 a------- c:\windows\system32\QuickTime.qts
2009-05-26 13:47 1,846,632 a------- c:\windows\system32\D3DCompiler_41.dll
2009-05-26 13:47 453,456 a------- c:\windows\system32\d3dx10_41.dll
2009-05-26 13:47 4,178,264 a------- c:\windows\system32\D3DX9_41.dll
2009-05-26 13:47 517,448 a------- c:\windows\system32\XAudio2_4.dll
2009-05-26 13:47 235,352 a------- c:\windows\system32\xactengine3_4.dll
2009-05-26 13:47 69,448 a------- c:\windows\system32\XAPOFX1_3.dll
2009-05-26 13:47 2,036,576 a------- c:\windows\system32\D3DCompiler_40.dll
2009-05-26 13:47 452,440 a------- c:\windows\system32\d3dx10_40.dll
2009-05-26 13:47 22,360 a------- c:\windows\system32\X3DAudio1_6.dll
2009-05-26 13:47 4,379,984 a------- c:\windows\system32\D3DX9_40.dll
2009-05-26 07:25 <DIR> --d----- c:\windows\pss

==================== Find3M ====================

2009-06-02 11:08 143,360 a------- c:\windows\inf\infstrng.dat
2009-06-02 11:08 51,200 a------- c:\windows\inf\infpub.dat
2009-06-02 11:08 86,016 a------- c:\windows\inf\infstor.dat
2009-05-09 01:50 915,456 a------- c:\windows\system32\wininet.dll
2009-05-09 01:34 71,680 a------- c:\windows\system32\iesetup.dll
2009-05-08 01:43 11,952 a------- c:\windows\system32\avgrsstx.dll
2009-05-08 01:43 325,896 a------- c:\windows\system32\drivers\avgldx86.sys
2009-05-08 01:43 108,552 a------- c:\windows\system32\drivers\avgtdix.sys
2009-04-28 23:31 4,491,776 a------- c:\windows\system32\drivers\atikmdag.sys
2009-04-28 22:08 442,368 a------- c:\windows\system32\ATIDEMGX.dll
2009-04-28 22:08 303,104 a------- c:\windows\system32\atieclxx.exe
2009-04-28 22:07 176,128 a------- c:\windows\system32\atiesrxx.exe
2009-04-28 22:06 159,744 a------- c:\windows\system32\atitmmxx.dll
2009-04-28 22:06 356,352 a------- c:\windows\system32\atipdlxx.dll
2009-04-28 22:05 278,528 a------- c:\windows\system32\Oemdspif.dll
2009-04-28 22:05 11,776 a------- c:\windows\system32\atimuixx.dll
2009-04-28 22:05 43,520 a------- c:\windows\system32\ati2edxx.dll
2009-04-28 22:02 2,428,928 a------- c:\windows\system32\atidxx32.dll
2009-04-28 21:52 3,082,752 a------- c:\windows\system32\atiumdag.dll
2009-04-28 21:41 11,559,424 a------- c:\windows\system32\atioglxx.dll
2009-04-28 21:37 4,963,840 a------- c:\windows\system32\atiumdva.dll
2009-04-28 21:25 51,712 a------- c:\windows\system32\atimpc32.dll
2009-04-28 21:25 51,712 a------- c:\windows\system32\amdpcom32.dll
2009-04-28 21:24 163,840 a------- c:\windows\system32\atiadlxx.dll
2009-04-28 21:22 53,248 a------- c:\windows\system32\aticalrt.dll
2009-04-28 21:22 53,248 a------- c:\windows\system32\aticalcl.dll
2009-04-28 21:20 3,293,184 a------- c:\windows\system32\aticaldd.dll
2009-04-28 21:11 53,248 a------- c:\windows\system32\drivers\ati2erec.dll
2009-04-24 01:43 95,544 a------- c:\windows\system32\drivers\AtiHdmi.sys
2009-04-23 08:43 784,896 a------- c:\windows\system32\rpcrt4.dll
2009-04-23 08:42 636,928 a------- c:\windows\system32\localspl.dll
2009-04-22 00:20 14,311,680 a------- c:\windows\system32\xlive.dll
2009-04-22 00:20 13,642,496 a------- c:\windows\system32\xlivefnt.dll
2009-04-21 07:55 2,033,152 a------- c:\windows\system32\win32k.sys
2009-03-16 23:38 40,960 a------- c:\windows\apppatch\apihex86.dll
2009-03-16 23:38 13,824 a------- c:\windows\system32\apilogen.dll
2009-03-16 23:38 24,064 a------- c:\windows\system32\amxread.dll
2008-06-11 20:03 665,600 a------- c:\windows\inf\drvindex.dat
2008-01-20 22:41 174 a--sh--- c:\program files\desktop.ini
2006-11-02 08:40 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 08:40 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 08:40 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 08:40 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 05:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 05:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 05:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 05:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat
2008-04-09 19:35 8,192 a--sh--- c:\windows\users\default\NTUSER.DAT

============= FINISH: 20:26:19.91 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 fireman4it

fireman4it

    Bleepin' Fireman


  • Malware Response Team
  • 13,505 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Greenup, Ill USA
  • Local time:06:35 AM

Posted 22 June 2009 - 02:15 PM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.


Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE

" Extinguishing Malware from the world"

The Virus, Trojan, Spyware, and Malware Removal forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.

ALL OTHER HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
Thanks-


  userbar_eis_500.gif

If I have helped you, consider making a donation to help me continue the fight against Malware! Just click btn_donate_LG.gif


#3 creid

creid
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:06:35 AM

Posted 22 June 2009 - 11:22 PM

I appreciate the response but yeah, after running through with ComboFix I seem to have resolved the issue since posting this thread. It ended up finding a few rootkits and quarantined them which has stopped all the problems I was having. Should I go ahead and scan with DDS anyway to make sure nothing else is hiding or maybe post the ComboFix log that I saved?

#4 thewall

thewall

  • Malware Response Team
  • 6,425 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:06:35 AM

Posted 23 June 2009 - 07:05 PM

Hello creid :thumbup2: Welcome to the BC HijackThis Log and Analysis forum. Sorry about your wait, but I will be assisting you in cleaning up your system from here on out.


I ask that you refrain from running tools other than those we suggest while we are performing the clean-up. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.



In the upper right hand corner of the topic you will see a button called Options. If you click on this in the drop-down menu you can choose Track this topic. By doing this and then choosing Immediate E-Mail notification and then clicking on Proceed you will be advised when we respond the your topic and facilitate the cleaning of your machine.

After 5 days if a topic is not replied to we assume it has been abandoned and it is closed.





Normally we try to dissuade people from using ComboFix unless being assisted by those who are trained in its use. It can cause severe problem to your system under certain conditions. However since you have already run it go ahead and post your log so I can take a look at it to see if there is some more clean-up to be done.



Thanks,



thewall
If I have helped you then please consider donating so I can continue the fight against malware Posted Image
All donations go directly to the helper

Posted Image

Due to the large amount of backlogs we have I cannot respond to PMs for help unless I am already working with you

#5 creid

creid
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:06:35 AM

Posted 23 June 2009 - 11:38 PM

I'm sorry, I had gotten a bit impatient and figured it'd be fine if I just went ahead with it. I'll be sure to refrain if I need to do anything further and wait for your next steps. I did follow instructions on how to use ComboFix from what I had read in other threads though even after taking the steps to shut down my anti-virus programs it still showed as enabled so I'm sure I screwed it up somewhere and whatever efforts I made was all for naught. I just figured it worked since all the problems that I was having went away after running it. I also had to rename ComboFix to even get it to run but anyway here's the log:

ComboFix 09-06-14.02 - Alann Cabang 06/15/2009 12:43.1 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.3326.2215 [GMT -4:00]
Running from: c:\users\Alann Cabang\Desktop\ComboPhix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\MSIVXffiqkteamwcqyxfonwqobrtxmginbkcd.sys
c:\windows\system32\MSIVXcount
c:\windows\system32\MSIVXrybsmdcbklbfmehdghmsuveeihxgxwek.dll
c:\windows\system32\MSIVXuvvqihtiupjecctcrfygfdfjsiruubgr.dll
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_MSIVXserv.sys


((((((((((((((((((((((((( Files Created from 2009-05-15 to 2009-06-15 )))))))))))))))))))))))))))))))
.

2009-06-15 16:46 . 2009-06-15 16:46 -------- d-----w- c:\users\Alann Cabang\AppData\Local\temp
2009-06-14 22:29 . 2009-06-14 22:29 -------- d-----w- c:\users\Alann Cabang\AppData\Roaming\Malwarebytes
2009-06-14 22:24 . 2009-06-14 22:24 -------- d-----w- c:\programdata\Malwarebytes
2009-06-14 21:21 . 2009-06-14 21:21 -------- d-----w- c:\users\Alann Cabang\AppData\Roaming\GetRightToGo
2009-06-13 13:00 . 2009-04-30 12:37 293376 ----a-w- c:\windows\system32\psisdecd.dll
2009-06-13 13:00 . 2009-04-30 12:37 428544 ----a-w- c:\windows\system32\EncDec.dll
2009-06-07 20:01 . 2009-06-07 20:01 -------- d-----w- c:\program files\QuickTime
2009-06-07 20:01 . 2009-06-07 20:01 -------- d-----w- c:\programdata\Apple Computer
2009-06-06 05:45 . 2009-06-06 05:45 -------- d-----w- c:\users\Alann Cabang\AppData\Local\capcom
2009-06-05 19:03 . 2009-06-05 19:03 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-06-04 14:42 . 2009-06-04 14:43 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2009-06-04 06:57 . 2009-06-04 06:58 -------- d-----w- c:\users\Alann Cabang\AppData\Local\Fallout3
2009-06-04 05:37 . 2009-06-04 05:37 -------- d-----w- c:\windows\system32\xlive
2009-06-04 01:00 . 2009-06-04 01:00 -------- dc----w- c:\windows\system32\DRVSTORE
2009-06-04 01:00 . 2009-02-06 22:08 55280 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2009-06-04 00:59 . 2009-06-04 00:59 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-06-04 00:58 . 2009-06-04 00:58 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-06-03 23:09 . 2009-06-03 23:09 -------- d-----w- c:\program files\Pcsx2
2009-06-02 15:09 . 2009-06-02 15:09 -------- d-----w- c:\programdata\ATI
2009-06-02 15:07 . 2009-06-02 15:07 10134 ----a-r- c:\users\Alann Cabang\AppData\Roaming\Microsoft\Installer\{AA3DDA7B-A960-51C2-69C5-86F3AFB3E074}\ARPPRODUCTICON.exe
2009-06-02 14:47 . 2009-06-02 14:47 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-06-02 14:17 . 2009-06-02 14:18 -------- d-----w- c:\users\Alann Cabang\AppData\Roaming\SystemRequirementsLab
2009-06-02 14:17 . 2009-06-02 14:17 207872 ----a-w- c:\users\Alann Cabang\AppData\Roaming\SystemRequirementsLab\SRLProxy_srl_4.dll
2009-06-02 14:17 . 2009-06-02 14:17 207872 ----a-w- c:\users\Alann Cabang\AppData\Roaming\SystemRequirementsLab\SRLProxy_srl_3.dll
2009-06-02 14:17 . 2009-06-02 14:17 207872 ----a-w- c:\users\Alann Cabang\AppData\Roaming\SystemRequirementsLab\SRLProxy_srl_2.dll
2009-06-02 14:17 . 2009-06-02 14:17 207872 ----a-w- c:\users\Alann Cabang\AppData\Roaming\SystemRequirementsLab\SRLProxy_srl_1.dll
2009-06-02 14:17 . 2009-06-02 14:17 -------- d-----w- c:\windows\Sun
2009-06-02 14:15 . 2009-06-02 14:15 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-02 14:15 . 2009-06-02 14:15 -------- d-----w- c:\program files\Java
2009-06-01 16:48 . 2009-06-01 16:51 -------- d-----w- c:\program files\VentSrv
2009-05-30 15:05 . 2009-05-30 15:05 -------- d-----w- c:\program files\Microsoft IntelliType Pro
2009-05-26 17:47 . 2009-03-09 19:27 453456 ----a-w- c:\windows\system32\d3dx10_41.dll
2009-05-26 17:47 . 2009-03-09 19:27 1846632 ----a-w- c:\windows\system32\D3DCompiler_41.dll
2009-05-26 17:47 . 2009-03-16 18:18 69448 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2009-05-26 17:47 . 2009-03-16 18:18 517448 ----a-w- c:\windows\system32\XAudio2_4.dll
2009-05-26 17:47 . 2009-03-16 18:18 235352 ----a-w- c:\windows\system32\xactengine3_4.dll
2009-05-26 17:47 . 2009-03-09 19:27 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
2009-05-26 17:47 . 2009-03-16 18:18 22360 ----a-w- c:\windows\system32\X3DAudio1_6.dll
2009-05-26 17:47 . 2008-10-15 10:22 452440 ----a-w- c:\windows\system32\d3dx10_40.dll
2009-05-26 17:47 . 2008-10-15 10:22 2036576 ----a-w- c:\windows\system32\D3DCompiler_40.dll
2009-05-26 17:47 . 2008-10-15 10:22 4379984 ----a-w- c:\windows\system32\D3DX9_40.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-15 16:42 . 2009-01-15 11:15 -------- d-----w- c:\programdata\avg8
2009-06-15 16:41 . 2009-01-15 12:51 -------- d-----w- c:\users\Alann Cabang\AppData\Roaming\DNA
2009-06-15 16:12 . 2009-02-15 02:05 -------- d-----w- c:\program files\Steam
2009-06-15 16:12 . 2009-01-15 04:55 -------- d-----w- c:\program files\DNA
2009-06-15 00:13 . 2009-01-15 08:02 -------- d-----w- c:\users\Alann Cabang\AppData\Roaming\BitTorrent
2009-06-15 00:13 . 2009-01-15 04:53 -------- d-----w- c:\program files\BitTorrent
2009-06-14 23:58 . 2009-01-16 17:55 1356 ----a-w- c:\users\Alann Cabang\AppData\Local\d3d9caps.dat
2009-06-14 21:52 . 2009-02-15 02:05 -------- d-----w- c:\program files\Common Files\Steam
2009-06-07 02:07 . 2009-01-15 02:39 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-04 01:00 . 2009-01-27 18:56 -------- d-----w- c:\program files\Windows Live
2009-06-02 15:11 . 2009-01-15 02:50 -------- d-----w- c:\programdata\NOS
2009-06-02 15:11 . 2009-01-15 02:50 -------- d-----w- c:\program files\NOS
2009-06-02 15:09 . 2009-01-15 02:55 -------- d-----w- c:\program files\ATI Technologies
2009-06-02 14:47 . 2009-01-15 05:12 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-01 16:47 . 2009-01-15 05:13 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-05-18 23:43 . 2009-01-15 01:38 159752 ----a-w- c:\users\Alann Cabang\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-14 02:17 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-12 03:59 . 2009-05-12 03:59 -------- d-----w- c:\programdata\PC Drivers HeadQuarters
2009-05-09 05:50 . 2009-06-10 01:25 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-09 05:34 . 2009-06-10 01:25 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-05-08 05:43 . 2009-01-15 11:15 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-05-08 05:43 . 2009-01-15 11:15 325896 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-05-08 05:43 . 2009-01-15 11:15 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-05-08 05:43 . 2009-02-18 14:24 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-04 14:02 . 2009-05-04 14:02 -------- d-----w- c:\programdata\www.TheXSoft.com
2009-05-04 14:02 . 2009-05-04 14:02 -------- d-----w- c:\users\Alann Cabang\AppData\Roaming\www.TheXSoft.com
2009-05-04 14:02 . 2009-05-04 14:02 -------- d-----w- c:\program files\Conan Stats
2009-04-29 03:31 . 2009-04-29 03:31 4491776 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2009-04-29 02:08 . 2009-04-29 02:08 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2009-04-29 02:08 . 2009-04-29 02:08 303104 ----a-w- c:\windows\system32\atieclxx.exe
2009-04-29 02:07 . 2009-04-29 02:07 176128 ----a-w- c:\windows\system32\atiesrxx.exe
2009-04-29 02:06 . 2009-04-29 02:06 159744 ----a-w- c:\windows\system32\atitmmxx.dll
2009-04-29 02:06 . 2009-04-29 02:06 356352 ----a-w- c:\windows\system32\atipdlxx.dll
2009-04-29 02:05 . 2009-04-29 02:05 278528 ----a-w- c:\windows\system32\Oemdspif.dll
2009-04-29 02:05 . 2009-04-29 02:05 11776 ----a-w- c:\windows\system32\atimuixx.dll
2009-04-29 02:05 . 2009-04-29 02:05 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2009-04-29 02:02 . 2009-04-29 02:02 2428928 ----a-w- c:\windows\system32\atidxx32.dll
2009-04-29 01:52 . 2009-02-25 21:18 3082752 ----a-w- c:\windows\system32\atiumdag.dll
2009-04-29 01:41 . 2009-04-29 01:41 11559424 ----a-w- c:\windows\system32\atioglxx.dll
2009-04-29 01:37 . 2009-02-25 20:56 4963840 ----a-w- c:\windows\system32\atiumdva.dll
2009-04-29 01:25 . 2009-04-29 01:25 51712 ----a-w- c:\windows\system32\atimpc32.dll
2009-04-29 01:25 . 2009-04-29 01:25 51712 ----a-w- c:\windows\system32\amdpcom32.dll
2009-04-29 01:24 . 2009-04-29 01:24 163840 ----a-w- c:\windows\system32\atiadlxx.dll
2009-04-29 01:22 . 2009-04-29 01:22 53248 ----a-w- c:\windows\system32\aticalrt.dll
2009-04-29 01:22 . 2009-04-29 01:22 53248 ----a-w- c:\windows\system32\aticalcl.dll
2009-04-29 01:20 . 2009-04-29 01:20 3293184 ----a-w- c:\windows\system32\aticaldd.dll
2009-04-29 01:11 . 2009-04-29 01:11 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2009-04-25 22:38 . 2009-04-25 22:38 -------- d-----w- c:\program files\ATI
2009-04-24 05:43 . 2009-04-24 05:43 95544 ----a-w- c:\windows\system32\drivers\AtiHdmi.sys
2009-04-23 12:43 . 2009-06-10 01:25 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:42 . 2009-06-10 01:25 636928 ----a-w- c:\windows\system32\localspl.dll
2009-04-22 04:20 . 2009-04-22 04:20 14311680 ----a-w- c:\windows\system32\xlive.dll
2009-04-22 04:20 . 2009-04-22 04:20 13642496 ----a-w- c:\windows\system32\xlivefnt.dll
2009-04-21 11:55 . 2009-06-10 01:25 2033152 ----a-w- c:\windows\system32\win32k.sys
2008-04-09 23:35 . 2008-04-09 23:35 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-01-15 342848]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"Steam"="c:\program files\steam\steam.exe" [2009-06-11 1217784]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-08 1947928]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2008-06-29 52168]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2009-01-21 92168]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2007-08-31 988584]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-02 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-04-29 61440]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-05-20 6144000]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-10-10 69632]

c:\users\Alann Cabang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2009-1-15 3450608]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-1-15 113664]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-1-15 809488]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{707DCE29-FD88-4C32-9551-158A00ACDA90}c:\\program files\\bittorrent\\bittorrent.exe"= UDP:c:\program files\bittorrent\bittorrent.exe:bittorrent
"UDP Query User{6422B19D-F29A-436A-91F3-87DD16B0C50C}c:\\program files\\bittorrent\\bittorrent.exe"= TCP:c:\program files\bittorrent\bittorrent.exe:bittorrent
"{28667487-83C3-4FDF-8491-DF748623AB21}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{B49D308C-D3C1-4473-8C0A-9868DEDAC745}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"TCP Query User{39BE3CDF-C551-4B6F-9A25-E1ED06D6DAFB}c:\\users\\alann cabang\\program files\\dna\\btdna.exe"= UDP:c:\users\alann cabang\program files\dna\btdna.exe:btdna.exe
"UDP Query User{AB9F7A8E-E479-4DF2-B1CD-F567DE07B5DC}c:\\users\\alann cabang\\program files\\dna\\btdna.exe"= TCP:c:\users\alann cabang\program files\dna\btdna.exe:btdna.exe
"TCP Query User{AA862306-AFB5-43B0-AB1E-41DF152E8170}c:\\users\\public\\games\\world of warcraft\\launcher.exe"= UDP:c:\users\public\games\world of warcraft\launcher.exe:Blizzard Launcher
"UDP Query User{78FD09A3-FE95-42C3-95C8-CD9F1832127F}c:\\users\\public\\games\\world of warcraft\\launcher.exe"= TCP:c:\users\public\games\world of warcraft\launcher.exe:Blizzard Launcher
"{9B4F0DC1-AC35-4BAA-A022-2197962AAA0C}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwn2main.exe:Neverwinter Nights 2 Main
"{538C1C16-AB8C-405A-91A3-B76B73258312}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwn2main.exe:Neverwinter Nights 2 Main
"{C25F4D0D-4837-457F-A30E-8FEF32CEF230}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe:Neverwinter Nights 2 AMD
"{46D09DA2-A3A0-47B1-901B-5AA0B1D5D2DA}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe:Neverwinter Nights 2 AMD
"{45A02E46-48DD-4CB1-A236-593B45606614}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwupdate.exe:Neverwinter Nights 2 Updater
"{7376E767-768B-46FD-B240-B508A0280978}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwupdate.exe:Neverwinter Nights 2 Updater
"{8C29419C-49A6-4FF1-B918-7885091B05B6}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwn2server.exe:Neverwinter Nights 2 Server
"{700E6463-F231-41B7-8FFE-D19F7E5F2ABC}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwn2server.exe:Neverwinter Nights 2 Server
"TCP Query User{72DA4060-8F03-4137-849E-71CAB0C24334}c:\\program files\\bittorrent\\bittorrent.exe"= UDP:c:\program files\bittorrent\bittorrent.exe:BitTorrent
"UDP Query User{3BD6188E-987C-4ADA-8545-404256DC4836}c:\\program files\\bittorrent\\bittorrent.exe"= TCP:c:\program files\bittorrent\bittorrent.exe:BitTorrent
"TCP Query User{35DCA63A-5A5F-4388-BA2E-EE736FD4C19A}c:\\users\\alann cabang\\program files\\dna\\btdna.exe"= UDP:c:\users\alann cabang\program files\dna\btdna.exe:btdna.exe
"UDP Query User{2A9A15EE-1E2D-4327-87AE-6047ECCDB368}c:\\users\\alann cabang\\program files\\dna\\btdna.exe"= TCP:c:\users\alann cabang\program files\dna\btdna.exe:btdna.exe
"{F38D706E-05D0-428A-97F6-7E5122B9D53C}"= UDP:c:\program files\DNA\btdna.exe:DNA (TCP-In)
"{6BD1DC96-7337-40E6-B3A9-5E82865CCCC1}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent (TCP-In)
"{3B559F33-EC79-4F08-AF00-A246A6802F19}"= TCP:c:\program files\DNA\btdna.exe:DNA (UDP-In)
"{EDFD88EA-DFB6-4845-AD0A-9AABEDC28F0D}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent (UDP-In)
"TCP Query User{58B14621-E391-45BE-913D-84F365C3E43C}c:\\program files\\dna\\btdna.exe"= UDP:c:\program files\dna\btdna.exe:DNA
"UDP Query User{0168D501-07EA-48E8-A178-10F348E2779F}c:\\program files\\dna\\btdna.exe"= TCP:c:\program files\dna\btdna.exe:DNA
"TCP Query User{84401C2A-20F7-4483-9149-280EB68D1E18}c:\\program files\\ventsrv\\ventrilo_srv.exe"= UDP:c:\program files\ventsrv\ventrilo_srv.exe:ventrilo_srv.exe
"UDP Query User{680BC1B5-B370-47BF-84BE-A9E92AFD8E99}c:\\program files\\ventsrv\\ventrilo_srv.exe"= TCP:c:\program files\ventsrv\ventrilo_srv.exe:ventrilo_srv.exe
"{17A179BB-7F59-48A3-9BAB-D8FD241AD578}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"{74599373-F0E7-4BF4-B9E8-9B2CB62CC0CF}"= UDP:c:\program files\Malwarebytes' Anti-Malware\test.exe:Malwarebytes' Anti-Malware
"{075AD53A-D01E-4994-A56A-C0C09E587D72}"= TCP:c:\program files\Malwarebytes' Anti-Malware\test.exe:Malwarebytes' Anti-Malware

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [1/15/2009 7:15 AM 325896]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [2/18/2009 10:24 AM 108552]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\System32\atiesrxx.exe [4/28/2009 10:07 PM 176128]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [1/15/2009 12:53 AM 908568]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [1/15/2009 12:53 AM 298776]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\System32\drivers\AtiHdmi.sys [4/24/2009 1:43 AM 95544]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [6/3/2009 9:00 PM 55280]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2/6/2009 6:08 PM 533360]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-BitTorrent - c:\program files\BitTorrent\bittorrent.exe
HKCU-Run-PLAYXPERT - c:\program files\PLAYXPERT\PXP.exe


.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\users\Alann Cabang\AppData\Roaming\Mozilla\Firefox\Profiles\2irh67p6.default\
FF - prefs.js: browser.search.selectedEngine - Dictionary
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\mozilla firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\mozilla firefox\plugins\nphssb.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-15 12:46
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


c:\windows\TEMP\TMP0000002CFDC7BA02B08865A5 524288 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-2130824749-712716907-1453544777-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
.
Completion time: 2009-06-15 12:47
ComboFix-quarantined-files.txt 2009-06-15 16:47

Pre-Run: 267,305,455,616 bytes free
Post-Run: 267,445,125,120 bytes free

234 --- E O F --- 2009-06-14 07:01

#6 thewall

thewall

  • Malware Response Team
  • 6,425 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:06:35 AM

Posted 24 June 2009 - 08:24 AM

I really don't like us running CF with AVG still active and you are not the first one who has had problems disabling the program. What I would like you to do is a temporary uninstall of the program and the reinstall it after completing the script below. I'll supply you with a link to install it again or if you choose Avira a link for it too.



Special ComboFix script made for this computer only

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs including TeaTimer if you have it so they do not interfere with the running of ComboFix. Instructions for doing so are located here

3. Open notepad and copy/paste the text in the quotebox below into it:

Folder::
c:\windows\TEMP\TMP0000002CFDC7BA02B08865A5


Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.






For a free anti-virus please follow these instructions:


Click on this link: AVG
  • Underneath AVG Anti-Virus Free click on Download
  • Click on AVG 8.5 Free for Windows
  • Click on Download
  • A window will open. Click on Save File-A window will open. Click on Next
  • Click on Accept
  • Make sure standard install is checked and click Next
  • You can enter your name and click Next
  • click Finish After install is complete click OK
  • Follow prompters to update and check for viruses
Some more links to free anti-virus programs(Note. Choose only one)

Avira
If I have helped you then please consider donating so I can continue the fight against malware Posted Image
All donations go directly to the helper

Posted Image

Due to the large amount of backlogs we have I cannot respond to PMs for help unless I am already working with you

#7 creid

creid
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:06:35 AM

Posted 25 June 2009 - 01:46 AM

Here's the new log. Noticed that it shows Windows Defender as enabled and I'm sure I had disabled it, I'm hoping that hasn't affected this new log.

ComboFix 09-06-23.01 - Alann Cabang 06/25/2009 2:33.2 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.3326.2464 [GMT -4:00]
Running from: c:\users\Alann Cabang\Desktop\ComboPhix.exe
Command switches used :: c:\users\Alann Cabang\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\ATIODCLI.exe
c:\windows\system32\ATIODE.exe

.
((((((((((((((((((((((((( Files Created from 2009-05-25 to 2009-06-25 )))))))))))))))))))))))))))))))
.

2009-06-25 06:36 . 2009-06-25 06:36 -------- d-----w- c:\users\Alann Cabang\AppData\Local\temp
2009-06-18 22:53 . 2009-06-18 22:53 -------- d-----w- c:\program files\Mad Scientist Productions
2009-06-18 02:30 . 2009-06-18 02:30 -------- d-----w- c:\windows\system32\Futuremark
2009-06-18 02:30 . 2009-06-18 02:30 -------- d-----w- c:\program files\Common Files\Futuremark Shared
2009-06-18 02:30 . 2008-09-17 19:14 27672 ----a-r- c:\windows\system32\drivers\Entech.sys
2009-06-16 08:19 . 2009-06-16 08:19 -------- d-----w- c:\programdata\DAEMON Tools Lite
2009-06-16 08:19 . 2009-06-16 08:19 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-06-16 08:19 . 2009-06-16 08:19 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-06-16 08:18 . 2009-06-16 08:19 -------- d-----w- c:\users\Alann Cabang\AppData\Roaming\DAEMON Tools Lite
2009-06-16 07:13 . 2009-06-16 07:13 -------- d-----w- c:\programdata\Electronic Arts
2009-06-16 07:12 . 2009-06-16 07:12 18944 ----a-r- c:\users\Alann Cabang\AppData\Roaming\Microsoft\Installer\{08E9C35A-A0AE-43FA-AEA1-E4F58A87FBD1}\Icon7BD916931.exe
2009-06-16 07:12 . 2009-06-16 07:12 11264 ----a-r- c:\users\Alann Cabang\AppData\Roaming\Microsoft\Installer\{08E9C35A-A0AE-43FA-AEA1-E4F58A87FBD1}\Icon7BD91693.exe
2009-06-16 07:07 . 2009-06-16 07:07 -------- d-----w- C:\Sierra
2009-06-16 07:01 . 2009-06-16 07:01 10134 ----a-r- c:\users\Alann Cabang\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-06-16 07:01 . 2009-06-16 07:01 -------- d-----w- c:\program files\Microsoft WSE
2009-06-16 06:48 . 2009-06-16 07:03 -------- d-----w- c:\program files\Electronic Arts
2009-06-16 06:39 . 2009-06-16 08:16 -------- d-----w- c:\program files\DAEMON Tools Pro
2009-06-16 06:39 . 2009-06-16 06:39 -------- d-----w- c:\programdata\DAEMON Tools Pro
2009-06-16 06:36 . 2009-06-16 06:43 -------- d-----w- c:\users\Alann Cabang\AppData\Roaming\DAEMON Tools Pro
2009-06-16 04:41 . 2009-06-16 05:10 -------- d-----w- C:\Root
2009-06-16 04:41 . 2009-06-16 04:41 -------- d-----w- c:\program files\Activision
2009-06-16 04:38 . 2009-06-16 04:38 -------- d-sh--w- c:\windows\ftpcache
2009-06-15 16:59 . 2009-05-26 17:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-15 16:59 . 2009-06-15 17:00 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-15 16:59 . 2009-05-26 17:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-14 22:29 . 2009-06-14 22:29 -------- d-----w- c:\users\Alann Cabang\AppData\Roaming\Malwarebytes
2009-06-14 22:24 . 2009-06-14 22:24 -------- d-----w- c:\programdata\Malwarebytes
2009-06-14 21:21 . 2009-06-14 21:21 -------- d-----w- c:\users\Alann Cabang\AppData\Roaming\GetRightToGo
2009-06-13 13:00 . 2009-04-30 12:37 293376 ----a-w- c:\windows\system32\psisdecd.dll
2009-06-13 13:00 . 2009-04-30 12:37 428544 ----a-w- c:\windows\system32\EncDec.dll
2009-06-07 20:01 . 2009-06-07 20:01 -------- d-----w- c:\program files\QuickTime
2009-06-07 20:01 . 2009-06-07 20:01 -------- d-----w- c:\programdata\Apple Computer
2009-06-06 05:45 . 2009-06-06 05:45 -------- d-----w- c:\users\Alann Cabang\AppData\Local\capcom
2009-06-05 19:03 . 2009-06-05 19:03 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-06-04 14:42 . 2009-06-04 14:43 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2009-06-04 06:57 . 2009-06-04 06:58 -------- d-----w- c:\users\Alann Cabang\AppData\Local\Fallout3
2009-06-04 05:37 . 2009-06-04 05:37 -------- d-----w- c:\windows\system32\xlive
2009-06-04 01:00 . 2009-06-04 01:00 -------- dc----w- c:\windows\system32\DRVSTORE
2009-06-04 01:00 . 2009-02-06 22:08 55280 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2009-06-04 00:59 . 2009-06-04 00:59 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-06-04 00:58 . 2009-06-04 00:58 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-06-03 23:09 . 2009-06-03 23:09 -------- d-----w- c:\program files\Pcsx2
2009-06-02 15:09 . 2009-06-02 15:09 -------- d-----w- c:\programdata\ATI
2009-06-02 15:07 . 2009-06-02 15:07 10134 ----a-r- c:\users\Alann Cabang\AppData\Roaming\Microsoft\Installer\{AA3DDA7B-A960-51C2-69C5-86F3AFB3E074}\ARPPRODUCTICON.exe
2009-06-02 14:47 . 2009-06-02 14:47 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-06-02 14:17 . 2009-06-02 14:18 -------- d-----w- c:\users\Alann Cabang\AppData\Roaming\SystemRequirementsLab
2009-06-02 14:17 . 2009-06-02 14:17 207872 ----a-w- c:\users\Alann Cabang\AppData\Roaming\SystemRequirementsLab\SRLProxy_srl_4.dll
2009-06-02 14:17 . 2009-06-02 14:17 207872 ----a-w- c:\users\Alann Cabang\AppData\Roaming\SystemRequirementsLab\SRLProxy_srl_3.dll
2009-06-02 14:17 . 2009-06-02 14:17 207872 ----a-w- c:\users\Alann Cabang\AppData\Roaming\SystemRequirementsLab\SRLProxy_srl_2.dll
2009-06-02 14:17 . 2009-06-02 14:17 207872 ----a-w- c:\users\Alann Cabang\AppData\Roaming\SystemRequirementsLab\SRLProxy_srl_1.dll
2009-06-02 14:17 . 2009-06-02 14:17 -------- d-----w- c:\windows\Sun
2009-06-02 14:15 . 2009-06-02 14:15 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-02 14:15 . 2009-06-02 14:15 -------- d-----w- c:\program files\Java
2009-06-01 16:48 . 2009-06-01 16:51 -------- d-----w- c:\program files\VentSrv
2009-05-30 15:05 . 2009-05-30 15:05 -------- d-----w- c:\program files\Microsoft IntelliType Pro
2009-05-26 17:47 . 2009-03-09 19:27 453456 ----a-w- c:\windows\system32\d3dx10_41.dll
2009-05-26 17:47 . 2009-03-09 19:27 1846632 ----a-w- c:\windows\system32\D3DCompiler_41.dll
2009-05-26 17:47 . 2009-03-16 18:18 69448 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2009-05-26 17:47 . 2009-03-16 18:18 517448 ----a-w- c:\windows\system32\XAudio2_4.dll
2009-05-26 17:47 . 2009-03-16 18:18 235352 ----a-w- c:\windows\system32\xactengine3_4.dll
2009-05-26 17:47 . 2009-03-09 19:27 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
2009-05-26 17:47 . 2009-03-16 18:18 22360 ----a-w- c:\windows\system32\X3DAudio1_6.dll
2009-05-26 17:47 . 2008-10-15 10:22 452440 ----a-w- c:\windows\system32\d3dx10_40.dll
2009-05-26 17:47 . 2008-10-15 10:22 2036576 ----a-w- c:\windows\system32\D3DCompiler_40.dll
2009-05-26 17:47 . 2008-10-15 10:22 4379984 ----a-w- c:\windows\system32\D3DX9_40.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-25 06:35 . 2009-01-15 12:51 -------- d-----w- c:\users\Alann Cabang\AppData\Roaming\DNA
2009-06-25 06:25 . 2009-01-15 04:55 -------- d-----w- c:\program files\DNA
2009-06-25 06:23 . 2009-01-15 08:02 -------- d-----w- c:\users\Alann Cabang\AppData\Roaming\BitTorrent
2009-06-25 06:20 . 2009-01-15 11:15 -------- d-----w- c:\programdata\avg8
2009-06-18 02:30 . 2009-01-15 02:39 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-16 08:19 . 2009-01-15 08:03 -------- d-----w- c:\users\Alann Cabang\AppData\Roaming\DAEMON Tools
2009-06-16 06:56 . 2009-01-15 04:53 -------- d-----w- c:\program files\BitTorrent
2009-06-16 06:36 . 2009-01-15 08:03 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-06-16 01:01 . 2009-02-15 02:05 -------- d-----w- c:\program files\Steam
2009-06-14 23:58 . 2009-01-16 17:55 1356 ----a-w- c:\users\Alann Cabang\AppData\Local\d3d9caps.dat
2009-06-14 21:52 . 2009-02-15 02:05 -------- d-----w- c:\program files\Common Files\Steam
2009-06-04 01:00 . 2009-01-27 18:56 -------- d-----w- c:\program files\Windows Live
2009-06-02 15:11 . 2009-01-15 02:50 -------- d-----w- c:\programdata\NOS
2009-06-02 15:11 . 2009-01-15 02:50 -------- d-----w- c:\program files\NOS
2009-06-02 15:09 . 2009-01-15 02:55 -------- d-----w- c:\program files\ATI Technologies
2009-06-02 14:47 . 2009-01-15 05:12 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-01 16:47 . 2009-01-15 05:13 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-05-18 23:43 . 2009-01-15 01:38 159752 ----a-w- c:\users\Alann Cabang\AppData\Local\GDIPFONTCACHEV1.DAT
2009-05-14 02:17 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-12 03:59 . 2009-05-12 03:59 -------- d-----w- c:\programdata\PC Drivers HeadQuarters
2009-05-09 05:50 . 2009-06-10 01:25 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-09 05:34 . 2009-06-10 01:25 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-05-04 14:02 . 2009-05-04 14:02 -------- d-----w- c:\programdata\www.TheXSoft.com
2009-05-04 14:02 . 2009-05-04 14:02 -------- d-----w- c:\users\Alann Cabang\AppData\Roaming\www.TheXSoft.com
2009-05-04 14:02 . 2009-05-04 14:02 -------- d-----w- c:\program files\Conan Stats
2009-04-29 03:31 . 2009-04-29 03:31 4491776 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2009-04-29 02:08 . 2009-04-29 02:08 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2009-04-29 02:08 . 2009-04-29 02:08 303104 ----a-w- c:\windows\system32\atieclxx.exe
2009-04-29 02:07 . 2009-04-29 02:07 176128 ----a-w- c:\windows\system32\atiesrxx.exe
2009-04-29 02:06 . 2009-04-29 02:06 159744 ----a-w- c:\windows\system32\atitmmxx.dll
2009-04-29 02:06 . 2009-04-29 02:06 356352 ----a-w- c:\windows\system32\atipdlxx.dll
2009-04-29 02:05 . 2009-04-29 02:05 278528 ----a-w- c:\windows\system32\Oemdspif.dll
2009-04-29 02:05 . 2009-04-29 02:05 11776 ----a-w- c:\windows\system32\atimuixx.dll
2009-04-29 02:05 . 2009-04-29 02:05 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2009-04-29 02:02 . 2009-04-29 02:02 2428928 ----a-w- c:\windows\system32\atidxx32.dll
2009-04-29 01:52 . 2009-02-25 21:18 3082752 ----a-w- c:\windows\system32\atiumdag.dll
2009-04-29 01:41 . 2009-04-29 01:41 11559424 ----a-w- c:\windows\system32\atioglxx.dll
2009-04-29 01:37 . 2009-02-25 20:56 4963840 ----a-w- c:\windows\system32\atiumdva.dll
2009-04-29 01:25 . 2009-04-29 01:25 51712 ----a-w- c:\windows\system32\atimpc32.dll
2009-04-29 01:25 . 2009-04-29 01:25 51712 ----a-w- c:\windows\system32\amdpcom32.dll
2009-04-29 01:24 . 2009-04-29 01:24 163840 ----a-w- c:\windows\system32\atiadlxx.dll
2009-04-29 01:22 . 2009-04-29 01:22 53248 ----a-w- c:\windows\system32\aticalrt.dll
2009-04-29 01:22 . 2009-04-29 01:22 53248 ----a-w- c:\windows\system32\aticalcl.dll
2009-04-29 01:20 . 2009-04-29 01:20 3293184 ----a-w- c:\windows\system32\aticaldd.dll
2009-04-29 01:11 . 2009-04-29 01:11 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2009-04-24 05:43 . 2009-04-24 05:43 95544 ----a-w- c:\windows\system32\drivers\AtiHdmi.sys
2009-04-23 12:43 . 2009-06-10 01:25 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:42 . 2009-06-10 01:25 636928 ----a-w- c:\windows\system32\localspl.dll
2009-04-22 04:20 . 2009-04-22 04:20 14311680 ----a-w- c:\windows\system32\xlive.dll
2009-04-22 04:20 . 2009-04-22 04:20 13642496 ----a-w- c:\windows\system32\xlivefnt.dll
2009-04-21 11:55 . 2009-06-10 01:25 2033152 ----a-w- c:\windows\system32\win32k.sys
2008-04-09 23:35 . 2008-04-09 23:35 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((( SnapShot@2009-06-15_16.46.48 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:56 . 2009-06-25 06:26 37388 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:03 . 2009-06-25 06:26 77186 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-02-15 02:09 . 2009-06-25 06:31 74137 c:\windows\System32\Macromed\Flash\uninstall_activeX.exe
+ 2009-06-18 02:30 . 2008-09-17 19:14 70392 c:\windows\System32\Futuremark\MSC\Direcpll.dll
- 2009-01-15 04:32 . 2009-06-15 16:37 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-01-15 04:32 . 2009-06-19 13:33 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-01-15 04:32 . 2009-06-19 13:33 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-01-15 04:32 . 2009-06-15 16:37 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-01-15 04:32 . 2009-06-15 16:37 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-01-15 04:32 . 2009-06-19 13:33 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-06-16 05:10 . 2009-06-16 05:10 11502 c:\windows\Installer\{9322A850-9091-4D0E-B252-3E82EDA3D94A}\ARPPRODUCTICON.exe
- 2009-06-05 18:50 . 2009-06-05 18:50 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2009-06-16 05:11 . 2009-06-16 05:11 12800 c:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2009-06-05 18:50 . 2009-06-05 18:50 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2009-06-16 05:11 . 2009-06-16 05:11 53248 c:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2009-01-16 23:16 . 2009-06-15 05:30 4702 c:\windows\System32\WDI\ERCQueuedResolutions.dat
+ 2009-01-16 23:16 . 2009-06-25 06:23 4702 c:\windows\System32\WDI\ERCQueuedResolutions.dat
+ 2009-01-15 01:39 . 2009-06-25 06:26 6140 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2130824749-712716907-1453544777-1000_UserData.bin
+ 2009-06-25 06:25 . 2009-06-25 06:25 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-06-15 16:42 . 2009-06-15 16:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-06-25 06:25 . 2009-06-25 06:25 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-06-15 16:42 . 2009-06-15 16:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-05-09 18:58 . 2009-06-20 15:43 149062 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S4.bin
+ 2009-01-15 07:58 . 2009-06-24 17:51 290982 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
+ 2008-09-04 20:11 . 2008-09-04 20:11 447752 c:\windows\System32\vp6vfw.dll
- 2006-11-02 10:33 . 2009-06-15 16:19 595446 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-06-25 06:29 595446 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-06-15 16:19 101144 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-06-25 06:29 101144 c:\windows\System32\perfc009.dat
+ 2008-03-25 02:32 . 2008-03-25 02:32 218496 c:\windows\System32\Macromed\Flash\FlashUtil9f.exe
+ 2009-01-18 20:05 . 2009-01-18 20:05 675840 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0100000010\9.1.0\JP2KLib.dll
+ 2009-06-16 07:01 . 2009-06-16 07:01 884736 c:\windows\assembly\GAC_MSIL\Microsoft.Web.Services3\3.0.0.0__31bf3856ad364e35\Microsoft.Web.Services3.dll
+ 2009-06-16 05:11 . 2009-06-16 05:11 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
- 2009-06-05 18:50 . 2009-06-05 18:50 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
- 2009-06-05 18:50 . 2009-06-05 18:50 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2009-06-16 05:11 . 2009-06-16 05:11 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2009-06-05 18:50 . 2009-06-05 18:50 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2009-06-16 05:11 . 2009-06-16 05:11 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2009-06-05 18:50 . 2009-06-05 18:50 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2009-06-16 05:11 . 2009-06-16 05:11 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2009-06-16 05:11 . 2009-06-16 05:11 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2009-06-05 18:50 . 2009-06-05 18:50 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2009-06-16 05:11 . 2009-06-16 05:11 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-05 18:50 . 2009-06-05 18:50 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-16 05:11 . 2009-06-16 05:11 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-05 18:50 . 2009-06-05 18:50 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-05 18:50 . 2009-06-05 18:50 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-16 05:11 . 2009-06-16 05:11 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-16 05:11 . 2009-06-16 05:11 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-05 18:50 . 2009-06-05 18:50 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-16 05:11 . 2009-06-16 05:11 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-05 18:50 . 2009-06-05 18:50 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-05 18:50 . 2009-06-05 18:50 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-16 05:11 . 2009-06-16 05:11 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-05 18:50 . 2009-06-05 18:50 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-16 05:11 . 2009-06-16 05:11 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-05 18:50 . 2009-06-05 18:50 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-16 05:11 . 2009-06-16 05:11 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-16 05:11 . 2009-06-16 05:11 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
- 2009-06-05 18:50 . 2009-06-05 18:50 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
- 2006-11-02 10:22 . 2009-06-14 21:43 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2006-11-02 10:22 . 2009-06-25 06:24 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2008-12-18 20:48 . 2008-12-18 20:48 3645440 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0100000010\9.1.0\authplay.dll
- 2009-06-05 18:50 . 2009-06-05 18:50 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-16 05:11 . 2009-06-16 05:11 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-06-05 18:50 . 2009-06-05 18:50 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-06-16 05:11 . 2009-06-16 05:11 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-05-16 09:52 . 2009-06-23 18:24 70266435 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
+ 2009-02-27 20:37 . 2009-02-27 20:37 20403568 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0100000010\9.1.0\AcroRd32.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-01-15 342848]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-04-29 3338240]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2008-06-29 52168]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2009-01-21 92168]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2007-08-31 988584]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-02 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-04-29 61440]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-05-20 6144000]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2008-10-10 69632]

c:\users\Alann Cabang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2009-1-15 3450608]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-1-15 113664]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-1-15 809488]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{707DCE29-FD88-4C32-9551-158A00ACDA90}c:\\program files\\bittorrent\\bittorrent.exe"= UDP:c:\program files\bittorrent\bittorrent.exe:bittorrent
"UDP Query User{6422B19D-F29A-436A-91F3-87DD16B0C50C}c:\\program files\\bittorrent\\bittorrent.exe"= TCP:c:\program files\bittorrent\bittorrent.exe:bittorrent
"{28667487-83C3-4FDF-8491-DF748623AB21}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{B49D308C-D3C1-4473-8C0A-9868DEDAC745}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"TCP Query User{39BE3CDF-C551-4B6F-9A25-E1ED06D6DAFB}c:\\users\\alann cabang\\program files\\dna\\btdna.exe"= UDP:c:\users\alann cabang\program files\dna\btdna.exe:btdna.exe
"UDP Query User{AB9F7A8E-E479-4DF2-B1CD-F567DE07B5DC}c:\\users\\alann cabang\\program files\\dna\\btdna.exe"= TCP:c:\users\alann cabang\program files\dna\btdna.exe:btdna.exe
"TCP Query User{AA862306-AFB5-43B0-AB1E-41DF152E8170}c:\\users\\public\\games\\world of warcraft\\launcher.exe"= UDP:c:\users\public\games\world of warcraft\launcher.exe:Blizzard Launcher
"UDP Query User{78FD09A3-FE95-42C3-95C8-CD9F1832127F}c:\\users\\public\\games\\world of warcraft\\launcher.exe"= TCP:c:\users\public\games\world of warcraft\launcher.exe:Blizzard Launcher
"{9B4F0DC1-AC35-4BAA-A022-2197962AAA0C}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwn2main.exe:Neverwinter Nights 2 Main
"{538C1C16-AB8C-405A-91A3-B76B73258312}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwn2main.exe:Neverwinter Nights 2 Main
"{C25F4D0D-4837-457F-A30E-8FEF32CEF230}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe:Neverwinter Nights 2 AMD
"{46D09DA2-A3A0-47B1-901B-5AA0B1D5D2DA}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe:Neverwinter Nights 2 AMD
"{45A02E46-48DD-4CB1-A236-593B45606614}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwupdate.exe:Neverwinter Nights 2 Updater
"{7376E767-768B-46FD-B240-B508A0280978}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwupdate.exe:Neverwinter Nights 2 Updater
"{8C29419C-49A6-4FF1-B918-7885091B05B6}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwn2server.exe:Neverwinter Nights 2 Server
"{700E6463-F231-41B7-8FFE-D19F7E5F2ABC}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwn2server.exe:Neverwinter Nights 2 Server
"TCP Query User{72DA4060-8F03-4137-849E-71CAB0C24334}c:\\program files\\bittorrent\\bittorrent.exe"= UDP:c:\program files\bittorrent\bittorrent.exe:BitTorrent
"UDP Query User{3BD6188E-987C-4ADA-8545-404256DC4836}c:\\program files\\bittorrent\\bittorrent.exe"= TCP:c:\program files\bittorrent\bittorrent.exe:BitTorrent
"TCP Query User{35DCA63A-5A5F-4388-BA2E-EE736FD4C19A}c:\\users\\alann cabang\\program files\\dna\\btdna.exe"= UDP:c:\users\alann cabang\program files\dna\btdna.exe:btdna.exe
"UDP Query User{2A9A15EE-1E2D-4327-87AE-6047ECCDB368}c:\\users\\alann cabang\\program files\\dna\\btdna.exe"= TCP:c:\users\alann cabang\program files\dna\btdna.exe:btdna.exe
"{F38D706E-05D0-428A-97F6-7E5122B9D53C}"= UDP:c:\program files\DNA\btdna.exe:DNA (TCP-In)
"{6BD1DC96-7337-40E6-B3A9-5E82865CCCC1}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent (TCP-In)
"{3B559F33-EC79-4F08-AF00-A246A6802F19}"= TCP:c:\program files\DNA\btdna.exe:DNA (UDP-In)
"{EDFD88EA-DFB6-4845-AD0A-9AABEDC28F0D}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent (UDP-In)
"TCP Query User{58B14621-E391-45BE-913D-84F365C3E43C}c:\\program files\\dna\\btdna.exe"= UDP:c:\program files\dna\btdna.exe:DNA
"UDP Query User{0168D501-07EA-48E8-A178-10F348E2779F}c:\\program files\\dna\\btdna.exe"= TCP:c:\program files\dna\btdna.exe:DNA
"TCP Query User{84401C2A-20F7-4483-9149-280EB68D1E18}c:\\program files\\ventsrv\\ventrilo_srv.exe"= UDP:c:\program files\ventsrv\ventrilo_srv.exe:ventrilo_srv.exe
"UDP Query User{680BC1B5-B370-47BF-84BE-A9E92AFD8E99}c:\\program files\\ventsrv\\ventrilo_srv.exe"= TCP:c:\program files\ventsrv\ventrilo_srv.exe:ventrilo_srv.exe
"{17A179BB-7F59-48A3-9BAB-D8FD241AD578}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"{74599373-F0E7-4BF4-B9E8-9B2CB62CC0CF}"= UDP:c:\program files\Malwarebytes' Anti-Malware\test.exe:Malwarebytes' Anti-Malware
"{075AD53A-D01E-4994-A56A-C0C09E587D72}"= TCP:c:\program files\Malwarebytes' Anti-Malware\test.exe:Malwarebytes' Anti-Malware
"{10FCD5BE-8354-4D66-8410-D5D88F9F4E2A}"= UDP:c:\program files\Activision\Prototype\prototypef.exe:Prototype™
"{C8A859DA-7482-4BD5-9F11-C29FFC220DEA}"= TCP:c:\program files\Activision\Prototype\prototypef.exe:Prototype™
"TCP Query User{5DB899B9-D24E-4F02-A68A-E3BA5DE515DD}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{CC9EAEE9-A9D5-48A0-8A3D-7AAACDE33AD6}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent

R2 AMD External Events Utility;AMD External Events Utility;c:\windows\System32\atiesrxx.exe [4/28/2009 10:07 PM 176128]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\System32\drivers\AtiHdmi.sys [4/24/2009 1:43 AM 95544]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [6/3/2009 9:00 PM 55280]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2/6/2009 6:08 PM 533360]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
------- Supplementary Scan -------
.
FF - ProfilePath - c:\users\Alann Cabang\AppData\Roaming\Mozilla\Firefox\Profiles\2irh67p6.default\
FF - prefs.js: browser.search.selectedEngine - Dictionary
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nphssb.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-25 02:36
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-06-25 2:37
ComboFix-quarantined-files.txt 2009-06-25 06:37
ComboFix2.txt 2009-06-15 16:47

Pre-Run: 231,148,494,848 bytes free
Post-Run: 231,166,128,128 bytes free

313 --- E O F --- 2009-06-22 19:29

#8 thewall

thewall

  • Malware Response Team
  • 6,425 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:06:35 AM

Posted 25 June 2009 - 09:17 AM

It seemed to run OK with Defender still showing as active.

Now let's do the following next:

Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.






  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)



In your next reply please include both logs from RSIT and the one from Kaspersky.
If I have helped you then please consider donating so I can continue the fight against malware Posted Image
All donations go directly to the helper

Posted Image

Due to the large amount of backlogs we have I cannot respond to PMs for help unless I am already working with you

#9 creid

creid
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:06:35 AM

Posted 25 June 2009 - 05:08 PM

Separated the logs with bold/underline titles.

RSIT log.txt

Logfile of random's system information tool 1.06 (written by random/random)
Run by Alann Cabang at 2009-06-25 17:54:10
Microsoft® Windows Vista™ Ultimate Service Pack 1
System drive C: has 216 GB (45%) free of 477 GB
Total RAM: 3326 MB (73% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:54:31 PM, on 6/25/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Logitech\Gaming Software\LWEMon.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\Explorer.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\Users\Alann Cabang\Desktop\RSIT.exe
C:\Program Files\trend micro\Alann Cabang.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe /noui
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O13 - Gopher Prefix:
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_srl.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

--
End of file - 5806 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2009-06-25 1107224]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2009-05-19 137600]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-06-02 35840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-05-20 6144000]
"Kernel and Hardware Abstraction Layer"=C:\Windows\KHALMNPR.EXE [2008-10-10 69632]
"VirtualCloneDrive"=C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [2008-06-29 52168]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2009-01-21 92168]
"itype"=C:\Program Files\Microsoft IntelliType Pro\itype.exe [2007-08-31 988584]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-06-02 148888]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2009-04-28 61440]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-05-26 413696]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-06-25 1948440]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-20 1233920]
"BitTorrent DNA"=C:\Program Files\DNA\btdna.exe [2009-01-15 342848]
"EA Core"=C:\Program Files\Electronic Arts\EADM\Core.exe [2009-04-29 3338240]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-20 202240]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-02-06 3885408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
c:\program files\steam\steam.exe [2009-06-11 1217784]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe

C:\Users\Alann Cabang\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="avgrsstx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2009-06-25 17:54:13 ----D---- C:\Program Files\trend micro
2009-06-25 17:54:10 ----D---- C:\rsit
2009-06-25 03:13:14 ----HD---- C:\$AVG8.VAULT$
2009-06-25 02:54:50 ----A---- C:\Windows\system32\avgrsstx.dll
2009-06-25 02:37:35 ----D---- C:\Windows\temp
2009-06-25 02:37:33 ----A---- C:\ComboFix.txt
2009-06-25 02:31:38 ----SD---- C:\ComboPhix
2009-06-18 18:53:41 ----D---- C:\Program Files\Mad Scientist Productions
2009-06-17 22:30:53 ----D---- C:\Windows\system32\Futuremark
2009-06-17 22:30:53 ----D---- C:\Program Files\Common Files\Futuremark Shared
2009-06-16 04:19:13 ----D---- C:\ProgramData\DAEMON Tools Lite
2009-06-16 04:19:09 ----D---- C:\Program Files\DAEMON Tools Toolbar
2009-06-16 04:19:08 ----D---- C:\Program Files\DAEMON Tools Lite
2009-06-16 04:18:56 ----D---- C:\Users\Alann Cabang\AppData\Roaming\DAEMON Tools Lite
2009-06-16 03:13:37 ----D---- C:\ProgramData\Electronic Arts
2009-06-16 03:07:09 ----D---- C:\Sierra
2009-06-16 03:01:34 ----D---- C:\Program Files\Microsoft WSE
2009-06-16 02:48:19 ----D---- C:\Program Files\Electronic Arts
2009-06-16 02:39:43 ----D---- C:\ProgramData\DAEMON Tools Pro
2009-06-16 02:39:43 ----D---- C:\Program Files\DAEMON Tools Pro
2009-06-16 02:36:38 ----D---- C:\Users\Alann Cabang\AppData\Roaming\DAEMON Tools Pro
2009-06-16 00:41:23 ----D---- C:\Root
2009-06-16 00:41:19 ----D---- C:\Program Files\Activision
2009-06-16 00:38:55 ----SHD---- C:\Windows\ftpcache
2009-06-15 12:59:56 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-06-15 12:47:51 ----SHD---- C:\$RECYCLE.BIN
2009-06-15 12:36:29 ----A---- C:\Windows\zip.exe
2009-06-15 12:36:29 ----A---- C:\Windows\SWXCACLS.exe
2009-06-15 12:36:29 ----A---- C:\Windows\SWSC.exe
2009-06-15 12:36:29 ----A---- C:\Windows\SWREG.exe
2009-06-15 12:36:29 ----A---- C:\Windows\sed.exe
2009-06-15 12:36:29 ----A---- C:\Windows\PEV.exe
2009-06-15 12:36:29 ----A---- C:\Windows\NIRCMD.exe
2009-06-15 12:36:29 ----A---- C:\Windows\grep.exe
2009-06-15 12:36:25 ----D---- C:\Windows\ERDNT
2009-06-15 12:32:46 ----D---- C:\Qoobox
2009-06-14 19:57:45 ----A---- C:\Windows\ntbtlog.txt
2009-06-14 18:29:24 ----D---- C:\Users\Alann Cabang\AppData\Roaming\Malwarebytes
2009-06-14 18:24:49 ----D---- C:\ProgramData\Malwarebytes
2009-06-14 17:21:03 ----D---- C:\Users\Alann Cabang\AppData\Roaming\GetRightToGo
2009-06-13 09:00:40 ----A---- C:\Windows\system32\psisdecd.dll
2009-06-13 09:00:40 ----A---- C:\Windows\system32\EncDec.dll
2009-06-09 21:25:54 ----A---- C:\Windows\system32\localspl.dll
2009-06-09 21:25:53 ----A---- C:\Windows\system32\mshtml.dll
2009-06-09 21:25:52 ----A---- C:\Windows\system32\ieframe.dll
2009-06-09 21:25:51 ----A---- C:\Windows\system32\wininet.dll
2009-06-09 21:25:51 ----A---- C:\Windows\system32\urlmon.dll
2009-06-09 21:25:51 ----A---- C:\Windows\system32\jsproxy.dll
2009-06-09 21:25:51 ----A---- C:\Windows\system32\ieui.dll
2009-06-09 21:25:51 ----A---- C:\Windows\system32\iesetup.dll
2009-06-09 21:25:51 ----A---- C:\Windows\system32\iertutil.dll
2009-06-09 21:25:51 ----A---- C:\Windows\system32\iernonce.dll
2009-06-09 21:25:51 ----A---- C:\Windows\system32\iedkcs32.dll
2009-06-09 21:25:51 ----A---- C:\Windows\system32\ie4uinit.exe
2009-06-09 21:25:49 ----A---- C:\Windows\system32\rpcrt4.dll
2009-06-07 16:01:25 ----D---- C:\ProgramData\Apple Computer
2009-06-07 16:01:25 ----D---- C:\Program Files\QuickTime
2009-06-05 15:03:47 ----A---- C:\Windows\system32\CmdLineExt.dll
2009-06-04 10:42:55 ----D---- C:\Program Files\Microsoft Games for Windows - LIVE
2009-06-04 01:37:01 ----D---- C:\Windows\system32\xlive
2009-06-03 21:00:28 ----DC---- C:\Windows\system32\DRVSTORE
2009-06-03 20:59:54 ----D---- C:\Program Files\Microsoft Sync Framework
2009-06-03 20:58:25 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2009-06-03 19:09:50 ----D---- C:\Program Files\Pcsx2
2009-06-02 11:09:35 ----D---- C:\ProgramData\ATI
2009-06-02 10:47:53 ----D---- C:\Program Files\Common Files\Adobe AIR
2009-06-02 10:46:58 ----D---- C:\ProgramData\Adobe
2009-06-02 10:17:59 ----D---- C:\Users\Alann Cabang\AppData\Roaming\SystemRequirementsLab
2009-06-02 10:17:54 ----D---- C:\Windows\Sun
2009-06-02 10:15:49 ----A---- C:\Windows\system32\javaws.exe
2009-06-02 10:15:49 ----A---- C:\Windows\system32\javaw.exe
2009-06-02 10:15:49 ----A---- C:\Windows\system32\java.exe
2009-06-02 10:15:49 ----A---- C:\Windows\system32\deploytk.dll
2009-06-02 10:15:32 ----D---- C:\Program Files\Java
2009-06-01 12:48:06 ----D---- C:\Program Files\VentSrv
2009-05-30 11:05:03 ----D---- C:\Program Files\Microsoft IntelliType Pro
2009-05-29 10:00:13 ----A---- C:\Windows\system32\msls31.dll
2009-05-29 10:00:13 ----A---- C:\Windows\system32\mshtmler.dll
2009-05-29 10:00:13 ----A---- C:\Windows\system32\mshtmled.dll
2009-05-29 10:00:13 ----A---- C:\Windows\system32\icardie.dll
2009-05-29 10:00:13 ----A---- C:\Windows\system32\corpol.dll
2009-05-29 10:00:13 ----A---- C:\Windows\system32\admparse.dll
2009-05-29 10:00:12 ----A---- C:\Windows\system32\webcheck.dll
2009-05-29 10:00:12 ----A---- C:\Windows\system32\occache.dll
2009-05-29 10:00:12 ----A---- C:\Windows\system32\msrating.dll
2009-05-29 10:00:12 ----A---- C:\Windows\system32\msfeedsbs.dll
2009-05-29 10:00:12 ----A---- C:\Windows\system32\licmgr10.dll
2009-05-29 10:00:12 ----A---- C:\Windows\system32\inseng.dll
2009-05-29 10:00:12 ----A---- C:\Windows\system32\imgutil.dll
2009-05-29 10:00:12 ----A---- C:\Windows\system32\iepeers.dll
2009-05-29 10:00:12 ----A---- C:\Windows\system32\ieaksie.dll
2009-05-29 10:00:12 ----A---- C:\Windows\system32\ieakeng.dll
2009-05-29 10:00:12 ----A---- C:\Windows\system32\dxtrans.dll
2009-05-29 10:00:12 ----A---- C:\Windows\system32\dxtmsft.dll
2009-05-29 10:00:11 ----A---- C:\Windows\system32\WinFXDocObj.exe
2009-05-29 10:00:11 ----A---- C:\Windows\system32\wextract.exe
2009-05-29 10:00:11 ----A---- C:\Windows\system32\vbscript.dll
2009-05-29 10:00:11 ----A---- C:\Windows\system32\pngfilt.dll
2009-05-29 10:00:11 ----A---- C:\Windows\system32\mstime.dll
2009-05-29 10:00:11 ----A---- C:\Windows\system32\msfeedssync.exe
2009-05-29 10:00:11 ----A---- C:\Windows\system32\msfeeds.dll
2009-05-29 10:00:11 ----A---- C:\Windows\system32\jscript.dll
2009-05-29 10:00:11 ----A---- C:\Windows\system32\ieapfltr.dll
2009-05-29 10:00:11 ----A---- C:\Windows\system32\ieakui.dll
2009-05-29 10:00:11 ----A---- C:\Windows\system32\advpack.dll
2009-05-29 10:00:10 ----A---- C:\Windows\system32\url.dll
2009-05-29 10:00:09 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2009-05-29 10:00:09 ----A---- C:\Windows\system32\SetDepNx.exe
2009-05-29 10:00:09 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2009-05-29 10:00:09 ----A---- C:\Windows\system32\PDMSetup.exe
2009-05-29 10:00:09 ----A---- C:\Windows\system32\mshta.exe
2009-05-29 10:00:09 ----A---- C:\Windows\system32\iexpress.exe
2009-05-29 10:00:09 ----A---- C:\Windows\system32\ieUnatt.exe
2009-05-29 10:00:09 ----A---- C:\Windows\system32\iesysprep.dll
2009-05-26 13:47:41 ----A---- C:\Windows\system32\d3dx10_41.dll
2009-05-26 13:47:41 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2009-05-26 13:47:40 ----A---- C:\Windows\system32\XAudio2_4.dll
2009-05-26 13:47:40 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2009-05-26 13:47:40 ----A---- C:\Windows\system32\xactengine3_4.dll
2009-05-26 13:47:40 ----A---- C:\Windows\system32\D3DX9_41.dll
2009-05-26 13:47:39 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2009-05-26 13:47:39 ----A---- C:\Windows\system32\d3dx10_40.dll
2009-05-26 13:47:39 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2009-05-26 13:47:38 ----A---- C:\Windows\system32\D3DX9_40.dll
2009-05-26 07:25:03 ----D---- C:\Windows\pss

======List of files/folders modified in the last 1 months======

2009-06-25 17:54:13 ----RD---- C:\Program Files
2009-06-25 17:52:33 ----D---- C:\Users\Alann Cabang\AppData\Roaming\DNA
2009-06-25 14:24:45 ----SHD---- C:\System Volume Information
2009-06-25 14:22:30 ----D---- C:\Program Files\Mozilla Firefox
2009-06-25 02:54:50 ----D---- C:\Windows\System32
2009-06-25 02:54:48 ----D---- C:\Windows\system32\drivers
2009-06-25 02:54:35 ----D---- C:\ProgramData\avg8
2009-06-25 02:54:28 ----SHD---- C:\Windows\Installer
2009-06-25 02:53:42 ----SD---- C:\Users\Alann Cabang\AppData\Roaming\Microsoft
2009-06-25 02:53:42 ----D---- C:\Windows
2009-06-25 02:53:41 ----HD---- C:\ProgramData
2009-06-25 02:37:36 ----D---- C:\Windows\system32\en-US
2009-06-25 02:36:27 ----A---- C:\Windows\system.ini
2009-06-25 02:35:07 ----D---- C:\Windows\AppPatch
2009-06-25 02:35:06 ----D---- C:\Program Files\Common Files
2009-06-25 02:29:33 ----D---- C:\Windows\inf
2009-06-25 02:29:33 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-06-25 02:25:17 ----D---- C:\Program Files\DNA
2009-06-25 02:23:16 ----D---- C:\Users\Alann Cabang\AppData\Roaming\BitTorrent
2009-06-25 01:58:43 ----D---- C:\Windows\system32\Tasks
2009-06-23 14:24:31 ----D---- C:\Windows\system32\catroot
2009-06-23 14:24:29 ----D---- C:\Windows\winsxs
2009-06-19 10:17:11 ----D---- C:\Windows\system32\catroot2
2009-06-17 22:30:52 ----HD---- C:\Program Files\InstallShield Installation Information
2009-06-16 04:19:54 ----D---- C:\Users\Alann Cabang\AppData\Roaming\DAEMON Tools
2009-06-16 03:01:36 ----RSD---- C:\Windows\assembly
2009-06-16 02:56:25 ----D---- C:\Program Files\BitTorrent
2009-06-15 21:01:24 ----D---- C:\Program Files\Steam
2009-06-15 12:43:16 ----D---- C:\Windows\Tasks
2009-06-15 00:44:37 ----D---- C:\Windows\system32\WDI
2009-06-14 17:52:14 ----D---- C:\Program Files\Common Files\Steam
2009-06-14 05:51:04 ----D---- C:\Windows\Microsoft.NET
2009-06-14 03:01:41 ----D---- C:\Windows\ehome
2009-06-11 12:11:57 ----D---- C:\Windows\system32\migration
2009-06-11 12:11:57 ----D---- C:\Program Files\Internet Explorer
2009-06-03 21:00:28 ----D---- C:\Program Files\Windows Live
2009-06-03 20:59:45 ----SD---- C:\ProgramData\Microsoft
2009-06-03 20:57:25 ----D---- C:\Windows\SoftwareDistribution
2009-06-02 11:11:37 ----D---- C:\ProgramData\NOS
2009-06-02 11:11:37 ----D---- C:\Program Files\NOS
2009-06-02 11:09:13 ----D---- C:\Program Files\ATI Technologies
2009-06-02 10:48:08 ----D---- C:\Program Files\Adobe
2009-06-02 10:47:54 ----D---- C:\Users\Alann Cabang\AppData\Roaming\Adobe
2009-06-02 10:47:00 ----D---- C:\Program Files\Common Files\Adobe
2009-06-01 12:51:12 ----A---- C:\Windows\system32\mrt.exe
2009-06-01 12:47:21 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-05-30 03:39:17 ----D---- C:\Windows\Debug
2009-05-29 10:20:40 ----D---- C:\Windows\rescache
2009-05-29 10:02:25 ----D---- C:\Windows\PolicyDefinitions
2009-05-26 16:32:35 ----D---- C:\Windows\Minidump
2009-05-26 12:41:03 ----D---- C:\Windows\Prefetch

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2009-06-25 327688]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2009-06-25 27784]
R1 AvgTdiX;AVG Free8 Network Redirector; C:\Windows\System32\Drivers\avgtdix.sys [2009-06-25 108552]
R1 CSC;Offline Files Driver; C:\Windows\system32\drivers\csc.sys [2008-01-20 350720]
R1 ElbyCDIO;ElbyCDIO Driver; C:\Windows\System32\Drivers\ElbyCDIO.sys [2008-07-21 24392]
R3 AtiHdmiService;ATI Function Driver for HDMI Service; C:\Windows\system32\drivers\AtiHdmi.sys [2009-04-24 95544]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-04-28 4491776]
R3 catchme;catchme; \??\C:\Users\ALANNC~1\AppData\Local\Temp\catchme.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-05-20 2143136]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2008-09-26 35472]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2008-09-26 37392]
R3 LUsbFilt;Logitech SetPoint KMDF USB Filter; C:\Windows\System32\Drivers\LUsbFilt.Sys [2008-09-26 28816]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2006-10-19 7680]
R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh86.sys [2009-03-06 140800]
R3 VClone;VClone; C:\Windows\system32\DRIVERS\VClone.sys [2008-09-24 29184]
R3 WmBEnum;Logitech Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\WmBEnum.sys [2009-01-13 19336]
R3 WmFilter;Logitech Gaming HID Filter Driver; C:\Windows\system32\drivers\WmFilter.sys [2009-01-13 29192]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-20 11264]
R3 WmVirHid;Logitech Virtual Hid Device Driver; C:\Windows\system32\drivers\WmVirHid.sys [2009-01-13 14728]
R3 WmXlCore;Logitech Translation Layer Driver; C:\Windows\system32\drivers\WmXlCore.sys [2009-01-13 49160]
S3 abbwxqep;abbwxqep; C:\Windows\system32\drivers\abbwxqep.sys []
S3 ATIAVAIW;ATI T200 Unified AVStream service; C:\Windows\system32\DRIVERS\atinavt2.sys [2008-05-14 175488]
S3 cpuz130;cpuz130; \??\C:\Users\ALANNC~1\AppData\Local\Temp\cpuz130\cpuz_x32.sys []
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-20 5632]
S3 ENTECH;ENTECH; \??\C:\Windows\system32\DRIVERS\ENTECH.sys [2008-09-17 27672]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2009-02-06 55280]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 L8042Kbd;Logitech SetPoint Keyboard Driver; C:\Windows\system32\DRIVERS\L8042Kbd.sys [2008-09-26 20240]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-20 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-20 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-20 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-20 6016]
S3 R300;R300; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-04-28 4491776]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-20 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-20 386616]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2009-04-28 176128]
R2 avg8emc;AVG Free8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2009-06-25 906520]
R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-06-25 298776]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2008-01-20 21504]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-05-19 240512]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2008-01-20 21504]
S3 Fax;@%systemroot%\system32\fxsresm.dll,-118; C:\Windows\system32\fxssvc.exe [2008-01-20 523776]
S3 fsssvc;Windows Live Family Safety; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe [2008-11-07 121360]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2009-06-14 316664]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2008-01-20 21504]
S3 wbengine;@%systemroot%\system32\wbengine.exe,-104; C:\Windows\system32\wbengine.exe [2008-01-20 917504]

-----------------EOF-----------------





RSIT info.txt

info.txt logfile of random's system information tool 1.06 2009-06-25 17:54:34

======Uninstall list======

7-Zip 4.64-->"C:\Program Files\7-Zip\Uninstall.exe"
Acrobat.com-->MsiExec.exe /X{287ECFA4-719A-2143-A09B-D6A12DE54E40}
Adobe AIR-->c:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723}
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Photoshop 7.0-->C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
Adobe Reader 9.1.2-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A91000000001}
Age of Conan - Hyborian Adventures-->"C:\Program Files\Funcom\Age of Conan\unins000.exe"
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Arcanum-->MsiExec.exe /I{08E9C35A-A0AE-43FA-AEA1-E4F58A87FBD1}
AVG Free 8.5-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
Catalyst Control Center - Branding-->MsiExec.exe /I{D3B1C799-CB73-42DE-BA0F-2344793A095C}
CDDRV_Installer-->MsiExec.exe /I{0C826C5B-B131-423A-A229-C71B3CACCD6A}
Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
Conan Stats ( Remove only)-->"C:\Program Files\Conan Stats\uninstall.exe"
DAEMON Tools Toolbar-->C:\Program Files\DAEMON Tools Toolbar\uninst.exe
EA Download Manager-->C:\Program Files\Electronic Arts\EADM\Uninstall.exe
ffdshow [rev 2734] [2009-03-01]-->"C:\Program Files\ffdshow\unins000.exe"
Futuremark SystemInfo-->"C:\Program Files\InstallShield Installation Information\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}\setup.exe" -runfromtemp -l0x0009 -removeonly
HijackThis 2.0.2-->"C:\Users\Alann Cabang\My Downloads\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Java™ 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216013FF}
Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
KhalInstallWrapper-->MsiExec.exe /I{3101CB58-3482-4D21-AF1A-7057FC935355}
Logitech Gaming Software 5.04-->MsiExec.exe /X{768F22DC-2D20-4F52-A9A1-5E231FB7F752}
Logitech SetPoint-->"C:\Program Files\InstallShield Installation Information\{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}\setup.exe" -runfromtemp -l0x0009 -removeonly
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Games for Windows - LIVE -->MsiExec.exe /X{4D243BA7-9AC4-46D1-90E5-EEB88974F501}
Microsoft Games for Windows - LIVE Redistributable-->MsiExec.exe /X{05B49229-22A2-4F88-842A-BBC2EBE1CCF6}
Microsoft Search Enhancement Pack-->MsiExec.exe /X{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft WSE 3.0 Runtime-->MsiExec.exe /X{E3E71D07-CD27-46CB-8448-16D4FB29AA13}
Mozilla Firefox (3.0.11)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
ObjectDock-->C:\PROGRA~1\Stardock\OBJECT~1\UNWISE.EXE C:\PROGRA~1\Stardock\OBJECT~1\INSTALL.LOG
OpenAL-->"C:\Program Files\OpenAL\oalinst.exe" /U
Pcsx2 0.9.6-->MsiExec.exe /I{0E2B767B-EA6A-489B-BF83-8083FE1DB661}
Prototype™-->C:\Program Files\InstallShield Installation Information\{9322A850-9091-4D0E-B252-3E82EDA3D94A}\setup.exe -runfromtemp -l0x0409
QuickTime-->MsiExec.exe /I{C78EAC6F-7A73-452E-8134-DBB2165C5A68}
Realtek 8169 8168 8101E 8102E Ethernet Driver-->C:\Program Files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\Setup.exe -runfromtemp -l0x0009 -removeonly
Realtek High Definition Audio Driver-->RtlUpd.exe -r -m -nrg2709
Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
The Sims™ 3-->"C:\Program Files\InstallShield Installation Information\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}\Sims3Setup.exe" -runfromtemp -l0x0009 -removeonly
Ventrilo Client-->MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F}
Ventrilo Server-->MsiExec.exe /X{1D46A3A0-B37D-423A-91C2-101A49E2FF80}
VideoLAN VLC media player 0.8.6c-->C:\Program Files\VideoLAN\VLC\uninstall.exe
VirtualCloneDrive-->"C:\Program Files\Elaborate Bytes\VirtualCloneDrive\vcd-uninst.exe" /D="C:\Program Files\Elaborate Bytes\VirtualCloneDrive"
Windows Live Call-->MsiExec.exe /I{F6BD194C-4190-4D73-B1B1-C48C99921BFE}
Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
Windows Live Essentials-->C:\Program Files\Windows Live\Installer\wlarp.exe
Windows Live Essentials-->MsiExec.exe /I{C6CA8874-5F22-4AF0-9BE3-016BF299C536}
Windows Live Family Safety-->MsiExec.exe /X{76CD2979-09C0-493A-84B3-8FD97EF4BCEA}
Windows Live Mail-->MsiExec.exe /I{63C1109E-D977-49ED-BCE3-D00D0BF187D6}
Windows Live Messenger-->MsiExec.exe /X{0AAA9C97-74D4-47CE-B089-0B147EF3553C}
Windows Live Photo Gallery-->MsiExec.exe /X{3C52E7DA-C431-4239-B66B-1BF703D5B194}
Windows Live Sign-in Assistant-->MsiExec.exe /I{9422C8EA-B0C6-4197-B8FC-DC797658CA00}
Windows Live Sync-->MsiExec.exe /X{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}
Windows Live Toolbar-->MsiExec.exe /X{995F1E2E-F542-4310-8E1D-9926F5A279B3}
Windows Live Upload Tool-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
Windows Live Writer-->MsiExec.exe /X{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}

======Security center information======

AS: Windows Defender

======System event log======

Computer Name: AlannCabang-PC
Event Code: 7030
Message: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
Record Number: 34277
Source Name: Service Control Manager
Time Written: 20090625063622.000000-000
Event Type: Error
User:

Computer Name: AlannCabang-PC
Event Code: 7009
Message: A timeout was reached (30000 milliseconds) while waiting for the PEVSystemStart service to connect.
Record Number: 34278
Source Name: Service Control Manager
Time Written: 20090625063623.000000-000
Event Type: Error
User:

Computer Name: AlannCabang-PC
Event Code: 7030
Message: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
Record Number: 34279
Source Name: Service Control Manager
Time Written: 20090625063623.000000-000
Event Type: Error
User:

Computer Name: AlannCabang-PC
Event Code: 7009
Message: A timeout was reached (30000 milliseconds) while waiting for the PEVSystemStart service to connect.
Record Number: 34280
Source Name: Service Control Manager
Time Written: 20090625063624.000000-000
Event Type: Error
User:

Computer Name: AlannCabang-PC
Event Code: 4321
Message: The name "WORKGROUP :1d" could not be registered on the interface with IP address 192.168.0.188. The computer with the IP address 192.168.0.126 did not allow the name to be claimed by this computer.
Record Number: 34324
Source Name: netbt
Time Written: 20090625193800.565500-000
Event Type: Error
User:

=====Application event log=====

Computer Name: AlannCabang-PC
Event Code: 1000
Message: Faulting application prototypef.exe, version 1.0.0.1, time stamp 0x49ef07ae, faulting module prototypeenginef.dll, version 1.0.0.1, time stamp 0x49ef9366, exception code 0xc0000005, fault offset 0x0062b325, process id 0x112c, application start time 0x01c9efb9de7e7ef0.
Record Number: 5474
Source Name: Application Error
Time Written: 20090618031905.000000-000
Event Type: Error
User:

Computer Name: AlannCabang-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

DETAIL -
31 user registry handles leaked from \Registry\User\S-1-5-21-2130824749-712716907-1453544777-1000:
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000
Process 1080 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software\Microsoft\SystemCertificates\trust
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software\Microsoft\Windows NT\CurrentVersion
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software\Microsoft\Internet Explorer\IETld
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software\Microsoft\Windows\CurrentVersion\Explorer
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software\Policies
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software\Microsoft\SystemCertificates\My
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume\{2bff80c8-e2bc-11dd-96f4-806e6f6e6963}
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software\Microsoft\SystemCertificates\Root
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software\Microsoft\Windows NT\CurrentVersion\Network\Location Awareness
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software\Microsoft\SystemCertificates\Disallowed
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software\Microsoft\SystemCertificates\CA
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software\Microsoft\SystemCertificates\TrustedPeople
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software\Policies\Microsoft\SystemCertificates
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN

Record Number: 5555
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20090625062340.000000-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM

Computer Name: AlannCabang-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

DETAIL -
4 user registry handles leaked from \Registry\User\S-1-5-21-2130824749-712716907-1453544777-1000_Classes:
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000_CLASSES
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000_CLASSES
Process 1080 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000_CLASSES
Process 3060 (\Device\HarddiskVolume1\Program Files\Stardock\ObjectDock\ObjectDock.exe) has opened key \REGISTRY\USER\S-1-5-21-2130824749-712716907-1453544777-1000_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\MuiCache

Record Number: 5556
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20090625062340.000000-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM

Computer Name: AlannCabang-PC
Event Code: 10
Message: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Record Number: 5574
Source Name: Microsoft-Windows-WMI
Time Written: 20090625062628.000000-000
Event Type: Error
User:

Computer Name: AlannCabang-PC
Event Code: 8194
Message: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005. This is often caused by incorrect security settings in either the writer or requestor process.

Operation:
Gathering Writer Data

Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {ea52d63b-495b-4198-977e-cf61e17cb1bd}
Record Number: 5596
Source Name: VSS
Time Written: 20090625182441.000000-000
Event Type: Error
User:

=====Security event log=====

Computer Name: AlannCabang-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name: \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
Record Number: 13087
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090625215429.644500-000
Event Type: Audit Failure
User:

Computer Name: AlannCabang-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name: \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
Record Number: 13088
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090625215429.684500-000
Event Type: Audit Failure
User:

Computer Name: AlannCabang-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name: \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
Record Number: 13089
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090625215429.726500-000
Event Type: Audit Failure
User:

Computer Name: AlannCabang-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name: \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
Record Number: 13090
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090625215429.766500-000
Event Type: Audit Failure
User:

Computer Name: AlannCabang-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name: \Device\HarddiskVolume1\Windows\System32\drivers\tcpip.sys
Record Number: 13091
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090625215429.807500-000
Event Type: Audit Failure
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files\QuickTime\QTSystem
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 67 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=4302
"NUMBER_OF_PROCESSORS"=2
"TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
"DFSTRACINGON"=FALSE
"CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip

-----------------EOF-----------------





Kaspersky Online Scan Log

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
Thursday, June 25, 2009
Operating System: Microsoft Windows Vista Ultimate Edition, 32-bit Service Pack 1 (build 6001)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Thursday, June 25, 2009 20:19:53
Records in database: 2389318
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Scan statistics:
Files scanned: 121726
Threat name: 1
Infected objects: 1
Suspicious objects: 0
Duration of the scan: 01:58:13


File name / Threat name / Threats count
C:\System Volume Information\_restore{D119EE51-DF94-4358-8DE1-E8D567C04E35}\RP91\A0019160.exe Infected: Trojan-Dropper.Win32.Agent.acvm 1

The selected area was scanned.

#10 thewall

thewall

  • Malware Response Team
  • 6,425 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:06:35 AM

Posted 25 June 2009 - 08:03 PM

How is everything running now?
If I have helped you then please consider donating so I can continue the fight against malware Posted Image
All donations go directly to the helper

Posted Image

Due to the large amount of backlogs we have I cannot respond to PMs for help unless I am already working with you

#11 creid

creid
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:06:35 AM

Posted 25 June 2009 - 09:25 PM

Everything has been running the same since I first used ComboFix, which is to say its looked fine the whole time, but I did notice that Kaspersky's caught that other Trojan. Is there something I should do with that or has it already been cleared up with the other scans?

#12 thewall

thewall

  • Malware Response Team
  • 6,425 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:06:35 AM

Posted 26 June 2009 - 08:06 AM

The infection which Kaspersky showed is in your restore points. That will be taken care of when we uninstall ComboFix which resets them. I'll be back a little later with some last things.
If I have helped you then please consider donating so I can continue the fight against malware Posted Image
All donations go directly to the helper

Posted Image

Due to the large amount of backlogs we have I cannot respond to PMs for help unless I am already working with you

#13 creid

creid
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:06:35 AM

Posted 26 June 2009 - 11:39 AM

Alright, thank you for all the help so far :thumbup2: Hopefully everything will be cleared up soon.

#14 thewall

thewall

  • Malware Response Team
  • 6,425 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:06:35 AM

Posted 26 June 2009 - 06:45 PM

From everything I see now you are clean. :thumbup2:



We will now uninstall ComboFix:

Go to Start > Run - type in ComboFix /u (case insensitive) >>OK

Among other things this will reset your Restore Points which will get rid of the entry that showed up in Kaspersky.

Below are some steps to follow in order to dramatically lower the chances of reinfection
You may have already implemented some of the steps below, however you should follow any steps that you have not already implemented
  • Make sure you install all the security updates for Windows, Internet explorer & Microsoft Office
    Whenever a security problem in its software is found, Microsoft will usually create a patch for it to that after the patch is installed, attackers can't use the vulnerability to install malicious software on your PC, so keeping up with these patches will help to prevent malicious software being installed on your PC
    Go here to check for & install updates to Microsoft applications
    Note: The update process uses activex, so you will need to use internet explorer for it, and allow the activex control that it wants to install
  • Keep your non-Microsoft applications updated as well
    Microsoft isn't the only company whose products can contain security vulnerabilities, to check for other vulnerable programs running on your PC that are in need of an update, you can use the Secunia Software Inspector - I suggest that you run it at least once a month
  • Make Internet Explorer more secure
    Click Start > Run
    Type Inetcpl.cpl & click OK
    Click on the Security tab
    Click Reset all zones to default level
    Make sure the Internet Zone is selected & Click Custom level
    In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • Install SpywareBlaster & make sure to update it regularly
    SpywareBlaster sets killbits in the registry to prevent known malicious activex controls from installing themselves on your computer.
    If you don't know what activex controls are, see here
    You can download SpywareBlaster from here
  • Install and use Spybot Search & Destroy
    Instructions are located here
    Make sure you update, reimmunize & scan regularly
  • Make use of the HOSTS file included with Spybot Search & Destroy
    Every version of windows includes a hosts file as part of them. A hosts file is a bit like a phone book, it points to the actual numeric address (i.e. the IP address) from the human friendly name of a website. This feature can be used to block malicious websites
    Spybot Search & Destroy has a good HOSTS file built in, to enable the HOSTS file in Spybot Search & Destroy
    • Run Spybot Search & Destroy
    • Click on Mode, and then place a tick next to Advanced mode
    • Click Yes
    • In the left hand pane of Spybot Search & Destroy, click on Tools, and then on Hosts File
    • Click on Add Spybot-S&D hosts list
    Note: On some PCs, having a custom HOSTS file installed can cause a significant slowdown. Following these instructions should resolve the issue
    • Click Start > Run
    • Type services.msc & click OK
    • In the list, find the service called DNS Client & double click on it.
    • On the dropdown box, change the setting from automatic to manual.
    • Click OK & then close the Services window
    For a more detailed explanation of the HOSTS file, click here
  • Install a-squared Free & update and scan with it regularly
    a-squared free is a product from Emsi Software provided free for private use that can detect and remove a variety of malicious software. You can get it here
    Note: If you have a dialup internet connection, you may also like to install a-squared Anti-Dialer which provides some real time protection against premium rate dialers
  • Finally, this is very important. It is absolutely essential to keep all of your security programs up to date



If you have any other questions or issues feel free to ask as I will be checking back on this topic.



Other than that if there is nothing else I can do for you then I wish you good luck in the future and thank you for using our forum. :)


thewall
If I have helped you then please consider donating so I can continue the fight against malware Posted Image
All donations go directly to the helper

Posted Image

Due to the large amount of backlogs we have I cannot respond to PMs for help unless I am already working with you

#15 creid

creid
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:06:35 AM

Posted 26 June 2009 - 07:27 PM

Excellent! Thank you again for your help :thumbup2:




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users