Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with Win32/Cryptor


  • This topic is locked This topic is locked
10 replies to this topic

#1 5678

5678

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:09:25 AM

Posted 26 July 2009 - 10:39 PM

Hi, my computer's been infected with Win32/Cryptor. My attempt at removing it with AVG and Malawarebytes was unsuccessful.


Here's my DDS.txt:

DDS (Ver_09-06-26.01) - NTFSx86
Run by user at 18:08:23.67 on Sun 07/26/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.229 [GMT -7:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall Plus *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\dlcxcoms.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AVG\AVG8\avgui.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Documents and Settings\user\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
uSearch Bar = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
uDefault_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
uInternet Settings,ProxyOverride = *.local
mSearchAssistant = hxxp://www.google.com/hws/sb/dell-usuk/en/side.html?channel=us
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [FaxCenterServer] "c:\program files\dell pc fax\fm3032.exe" /s
mRun: [dlcxmon.exe] "c:\program files\dell photo aio printer 926\dlcxmon.exe"
mRun: [MemoryCardManager] "c:\program files\dell photo aio printer 926\memcard.exe"
mRun: [DLCXCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLCXtime.dll,_RunDLLEntry@16
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Boggle/Images/stg_drm.ocx
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/Boggle/Images/armhelper.ocx
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: avgrsstarter - avgrsstx.dll
AppInit_DLLs: c:\progra~1\google\google~1\goec62~1.dll c:\windows\system32\jamajide.dll c:\windows\system32\ c:\windows\system32\ c:\windows\system32\
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
LSA: Notification Packages = scecli c:\windows\system32\jamajide.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\jzifm9d2.default\
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\user\application data\mozilla\firefox\profiles\jzifm9d2.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-6-18 335752]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-6-18 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-4-19 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-6-23 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-6-23 72944]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2006-7-29 353672]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-6-18 298776]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-12-22 24652]
R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service --> c:\windows\system32\zonelabs\vsmon.exe -service [?]
R3 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-6-23 7408]
R3 WMP11;Instant Wireless PCI Card Driver;c:\windows\system32\drivers\WMP11NDS.sys [2002-5-16 54083]
RUnknown mmmxuevs;mmmxuevs; [x]

=============== Created Last 30 ================

2009-07-26 17:37 <DIR> --d----- c:\program files\Trend Micro
2009-07-26 16:24 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-07-26 16:24 <DIR> --d----- c:\program files\SUPERAntiSpyware
2009-07-26 16:24 <DIR> --d----- c:\docume~1\user\applic~1\SUPERAntiSpyware.com
2009-07-26 16:24 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-07-26 13:51 <DIR> --d----- c:\docume~1\user\applic~1\Malwarebytes
2009-07-26 13:50 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-26 13:50 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-07-26 13:50 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-07-26 13:50 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-07-19 01:47 <DIR> --d----- c:\docume~1\user\applic~1\OpenOffice.org
2009-07-19 01:44 <DIR> --d----- c:\program files\JRE
2009-07-19 01:44 <DIR> --d----- c:\program files\OpenOffice.org 3
2009-07-19 01:19 73,728 a------- c:\windows\system32\javacpl.cpl
2009-07-11 14:38 269 a------- c:\windows\wininit.ini
2009-07-10 01:24 <DIR> --d----- c:\program files\Microsoft
2009-07-10 01:24 <DIR> --d----- c:\program files\Windows Live SkyDrive
2009-07-02 00:31 <DIR> --d----- c:\documents and settings\user\Tracing
2009-07-02 00:25 <DIR> --d----- c:\program files\common files\Windows Live

==================== Find3M ====================

2009-07-19 01:19 410,984 a------- c:\windows\system32\deploytk.dll
2009-07-15 13:45 8,456 a--sh--- c:\windows\system32\KGyGaAvL.sys
2009-07-02 11:58 335,752 a------- c:\windows\system32\drivers\avgldx86.sys
2009-06-26 11:21 11,952 a------- c:\windows\system32\avgrsstx.dll
2009-05-30 20:52 360 a------- C:\drmHeader.bin
2009-05-07 08:44 344,064 a------- c:\windows\system32\localspl.dll
2009-05-07 08:44 344,064 -------- c:\windows\system32\dllcache\localspl.dll
2009-04-28 21:56 827,392 a------- c:\windows\system32\wininet.dll
2009-04-28 21:56 827,392 -------- c:\windows\system32\dllcache\wininet.dll
2009-04-28 21:56 233,472 -------- c:\windows\system32\dllcache\webcheck.dll
2009-04-28 21:56 44,544 a------- c:\windows\system32\dllcache\pngfilt.dll
2009-04-28 21:56 1,159,680 -------- c:\windows\system32\dllcache\urlmon.dll
2009-04-28 21:56 671,232 -------- c:\windows\system32\dllcache\mstime.dll
2009-04-28 21:56 105,984 -------- c:\windows\system32\dllcache\url.dll
2009-04-28 21:56 102,912 -------- c:\windows\system32\dllcache\occache.dll
2009-04-28 21:56 3,596,288 -------- c:\windows\system32\dllcache\mshtml.dll
2009-04-28 21:56 477,696 -------- c:\windows\system32\dllcache\mshtmled.dll
2009-04-28 21:56 193,024 -------- c:\windows\system32\dllcache\msrating.dll
2009-04-28 02:05 70,656 -------- c:\windows\system32\dllcache\ie4uinit.exe
2009-04-28 02:05 13,824 -------- c:\windows\system32\dllcache\ieudinit.exe
2008-11-25 02:03 88 ---shr-- c:\windows\system32\89B015B610.sys

============= FINISH: 18:10:19.39 ===============


(I won't attach my Attach.txt yet, unless requested.)


Here's what came up from my AVG scan:

"\\?\globalroot\systemroot\system32\geyekrivkhiyid.dll";"Virus identified Win32/Cryptor";"Infected" (33 instances)
"C:\PROGRA~1\AVG\AVG8\avgnsx.exe (288)";"Virus identified Win32/Cryptor";"Infected"
"C:\PROGRA~1\AVG\AVG8\avgtray.exe (2084)";"Virus identified Win32/Cryptor";"Infected"
"C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (148)";"Virus identified Win32/Cryptor";"Infected"
"C:\Program Files\AVG\AVG8\avgrsx.exe (272)";"Virus identified Win32/Cryptor";"Infected"
"C:\Program Files\AVG\AVG8\avgscanx.exe (2548)";"Virus identified Win32/Cryptor";"Infected"
"C:\Program Files\AVG\AVG8\avgui.exe (2496)";"Virus identified Win32/Cryptor";"Infected"
"C:\Program Files\AVG\AVG8\avgcsrvx.exe (3960)";"Virus identified Win32/Cryptor";"Infected"
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe (2092)";"Virus identified Win32/Cryptor";"Infected"
"C:\Program Files\iTunes\iTunesHelper.exe (2076)";"Virus identified Win32/Cryptor";"Infected"
"C:\WINDOWS\system32\LEXBCES.EXE (1660)";"Virus identified Win32/Cryptor";"Infected"
"C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe (1980)";"Virus identified Win32/Cryptor";"Infected"
"C:\Program Files\Dell Photo AIO Printer 926\memcard.exe (2052)";"Virus identified Win32/Cryptor";"Infected"
"C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (156)";"Virus identified Win32/Cryptor";"Infected"
"C:\Program Files\iPod\bin\iPodService.exe (564)";"Virus identified Win32/Cryptor";"Infected"
"C:\Program Files\Java\jre6\bin\jqs.exe (212)";"Virus identified Win32/Cryptor";"Infected"
"C:\Program Files\Java\jre6\bin\jusched.exe (2108)";"Virus identified Win32/Cryptor";"Infected"
"C:\Program Files\Mozilla Firefox\firefox.exe (3848)";"Virus identified Win32/Cryptor";"Infected"
"C:\Program Files\Viewpoint\Common\ViewpointService.exe (1180)";"Virus identified Win32/Cryptor";"Infected"
"C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (2100)";"Virus identified Win32/Cryptor";"Infected"
"C:\WINDOWS\system32\ctfmon.exe (1596)";"Virus identified Win32/Cryptor";"Infected"
"C:\WINDOWS\system32\dlcxcoms.exe (2300)";"Virus identified Win32/Cryptor";"Infected"
"C:\WINDOWS\system32\LEXPPS.EXE (1708)";"Virus identified Win32/Cryptor";"Infected"
"C:\WINDOWS\explorer.exe (584)";"Virus identified Win32/Cryptor";"Infected"
"C:\WINDOWS\system32\lsass.exe (792)";"Virus identified Win32/Cryptor";"Infected"
"C:\WINDOWS\system32\msiexec.exe (1856)";"Virus identified Win32/Cryptor";"Infected"
"C:\WINDOWS\system32\services.exe (780)";"Virus identified Win32/Cryptor";"Infected"
"C:\WINDOWS\system32\spoolsv.exe (1700)";"Virus identified Win32/Cryptor";"Infected"
"C:\WINDOWS\system32\wuauclt.exe (2984)";"Virus identified Win32/Cryptor";"Infected"
"C:\WINDOWS\system32\svchost.exe (1216)";"Virus identified Win32/Cryptor";"Infected"
"C:\WINDOWS\system32\svchost.exe (408)";"Virus identified Win32/Cryptor";"Infected"
"C:\WINDOWS\system32\svchost.exe (988)";"Virus identified Win32/Cryptor";"Infected"
"C:\WINDOWS\system32\winlogon.exe (732)";"Virus identified Win32/Cryptor";"Infected"
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe (1328)";"Virus identified Win32/Cryptor";"Infected"


And here's what appeared on my Malawarebytes scan:

Memory Modules Infected:
\\?\globalroot\systemroot\system32\geyekrivkhiyid.dll (Trojan.TDSS) -> No action taken.
Files Infected:
\\?\globalroot\systemroot\system32\geyekrivkhiyid.dll (Trojan.TDSS) -> No action taken.


Help would be much appreciated. Thanks!

Edited by 5678, 27 July 2009 - 12:02 AM.


BC AdBot (Login to Remove)

 


#2 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:12:25 AM

Posted 28 July 2009 - 04:28 PM

Go HERE and download SysProt AntiRootkit. Unzip it to your Desktop
  • Run SysProt >> Click on the Log tab
  • Tick ALL the boxes at the "Write to log" section (Do NOT tick the "Hidden Objects Only" options)
  • Hit the Create Log button
  • When it asked for scanning option, choose Scanning all drives >> Hit Start button (Do NOT hit "Ok" button)
  • Let it scan until finish
  • Find the log.txt inside the SysProt folder and attach the log here.

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#3 5678

5678
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:09:25 AM

Posted 28 July 2009 - 07:14 PM

Here's my SysProt log file.

Attached Files



#4 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:12:25 AM

Posted 29 July 2009 - 01:36 AM

Please make sure you disable ALL of your Antivirus/Antispyware/Firewall before running ComboFix.. Please visit HERE if you don't know how.. Please re-enable them back after performing all steps given..

Please download ComboFix by sUBs from HERE or HERE and save it to your Desktop.

During the download, rename Combofix to Combo-Fix as follows:

Posted Image

Posted Image


It is important you rename Combofix during the download, but not after.

**NOTE: If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".

After that, double-click and run Combo-Fix. Let it finish its job and post the log here

If ComboFix asked you to install Recovery Console, please do so.. It will be your best interest..

Note: DON'T do anything with your computer while ComboFix is running.. Let ComboFix finishes its job..

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#5 5678

5678
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:09:25 AM

Posted 29 July 2009 - 02:51 AM

ComboFix 09-07-28.01 - user 07/29/2009 0:32.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.551 [GMT -7:00]
Running from: c:\documents and settings\user\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall Plus *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Installer\2db827a.msp
c:\windows\Installer\32ede1a.msp
c:\windows\Installer\32ede22.msp
c:\windows\Installer\32ede2b.msp
c:\windows\Installer\32ede33.msp
c:\windows\system32\bszip.dll
c:\windows\system32\drivers\geyekrorgixevp.sys
c:\windows\system32\geyekreruwpiba.dat
c:\windows\system32\geyekrppqlaswi.dll
c:\windows\system32\geyekrqdujnfto.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_geyekrsdovhohi


((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-29 )))))))))))))))))))))))))))))))
.

2009-07-29 00:50 . 2009-07-29 00:50 -------- d-----w- c:\program files\Cobian Backup 9
2009-07-28 17:33 . 2009-07-28 17:33 -------- d-sh--w- c:\documents and settings\user\IETldCache
2009-07-28 08:50 . 2009-07-28 08:50 -------- d-----w- c:\windows\ie8updates
2009-07-28 08:49 . 2009-07-28 08:49 -------- dc-h--w- c:\windows\ie8
2009-07-28 08:48 . 2009-07-01 07:08 101376 ------w- c:\windows\system32\dllcache\iecompat.dll
2009-07-28 08:42 . 2009-07-28 08:42 -------- d-----w- c:\program files\iPod
2009-07-28 08:42 . 2009-07-28 08:42 -------- d-----w- c:\program files\iTunes
2009-07-28 08:42 . 2009-07-28 08:42 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-28 08:41 . 2009-07-28 08:41 -------- d-----w- c:\program files\Bonjour
2009-07-28 08:41 . 2009-07-28 08:42 -------- d-----w- c:\program files\Common Files\Apple
2009-07-28 08:32 . 2009-07-28 08:33 -------- d-----w- c:\program files\QuickTime
2009-07-28 08:32 . 2009-07-28 08:32 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\Apple
2009-07-28 08:32 . 2009-07-28 08:32 -------- d-----w- c:\program files\Apple Software Update
2009-07-28 08:32 . 2009-07-28 08:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-07-27 01:57 . 2009-07-27 01:57 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-07-27 00:37 . 2009-07-27 00:37 -------- d-----w- c:\program files\Trend Micro
2009-07-26 23:25 . 2009-07-28 17:34 117760 ----a-w- c:\documents and settings\user\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-26 23:24 . 2009-07-26 23:24 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-07-26 23:24 . 2009-07-26 23:24 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-07-26 23:24 . 2009-07-26 23:24 -------- d-----w- c:\documents and settings\user\Application Data\SUPERAntiSpyware.com
2009-07-26 23:24 . 2009-07-26 23:24 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-07-26 20:51 . 2009-07-26 20:51 -------- d-----w- c:\documents and settings\user\Application Data\Malwarebytes
2009-07-26 20:50 . 2009-07-13 20:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-26 20:50 . 2009-07-26 20:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-26 20:50 . 2009-07-26 20:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-26 20:50 . 2009-07-13 20:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-19 08:48 . 2009-07-24 06:18 1 ----a-w- c:\documents and settings\user\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-07-19 08:47 . 2009-07-19 08:47 -------- d-----w- c:\documents and settings\user\Application Data\OpenOffice.org
2009-07-19 08:44 . 2009-07-19 08:44 -------- d-----w- c:\program files\JRE
2009-07-19 08:44 . 2009-07-19 08:44 -------- d-----w- c:\program files\OpenOffice.org 3
2009-07-19 08:19 . 2009-07-19 08:19 152576 ----a-w- c:\documents and settings\user\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-07-17 17:26 . 2009-07-02 18:58 3403032 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-07-13 21:22 . 2009-07-13 21:22 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe
2009-07-11 17:34 . 2009-07-02 18:58 2054424 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-07-10 08:24 . 2009-07-10 08:24 -------- d-----w- c:\program files\Microsoft
2009-07-10 08:24 . 2009-07-10 08:24 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-07-10 08:24 . 2009-07-10 08:24 -------- d-----w- c:\program files\Windows Live
2009-07-02 19:00 . 2009-07-02 18:58 2167576 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgresf.dll
2009-07-02 07:31 . 2009-07-15 04:25 -------- d-----w- c:\documents and settings\user\Tracing
2009-07-02 07:25 . 2009-07-02 07:25 -------- d-----w- c:\program files\Common Files\Windows Live

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-29 07:26 . 2007-07-15 21:50 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-29 04:55 . 2007-09-03 08:40 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-07-28 17:30 . 2006-11-23 21:19 21826470 ----a-w- c:\windows\Internet Logs\tvDebug.zip
2009-07-28 08:33 . 2006-08-02 10:21 48840 ----a-w- c:\documents and settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-28 04:32 . 2006-07-23 05:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-07-28 04:22 . 2007-01-27 09:42 -------- d-----w- c:\program files\EcoBeaker
2009-07-28 04:16 . 2007-04-07 22:39 -------- d-----w- c:\program files\Microsoft Works
2009-07-27 20:44 . 2006-07-31 00:43 -------- d-----w- c:\program files\Common Files\Adobe
2009-07-26 23:53 . 2006-07-23 05:10 -------- d-----w- c:\program files\MUSICMATCH
2009-07-21 04:55 . 2006-08-24 09:39 -------- d-----w- c:\program files\SpywareBlaster
2009-07-19 08:55 . 2007-06-06 18:43 69008 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-19 08:19 . 2009-01-11 19:22 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-19 08:19 . 2006-07-23 05:04 -------- d-----w- c:\program files\Java
2009-07-15 20:45 . 2006-08-13 06:34 8456 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-07-15 20:45 . 2006-08-13 06:34 104 --sh--r- c:\windows\system32\10B615B089.sys
2009-07-13 17:06 . 2008-06-18 20:49 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-07-11 17:32 . 2006-12-02 22:58 -------- d-----w- c:\program files\dl_cats
2009-07-02 18:58 . 2008-06-18 20:50 335752 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-01 01:07 . 2006-08-12 22:33 -------- d-----w- c:\program files\DivX
2009-06-26 18:21 . 2008-06-18 20:50 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-26 18:21 . 2008-06-18 20:50 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-24 04:05 . 2007-03-25 23:15 -------- d--h--w- c:\documents and settings\user\Application Data\Move Networks
2009-06-16 14:55 . 2004-08-10 17:51 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:55 . 2004-08-10 17:51 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-06-03 19:27 . 2004-08-10 17:51 1290752 ----a-w- c:\windows\system32\quartz.dll
2009-05-31 03:52 . 2007-11-21 09:45 360 ----a-w- C:\drmHeader.bin
2009-05-30 00:31 . 2009-05-30 00:31 390664 ----a-w- c:\documents and settings\user\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-05-12 18:34 . 2009-04-19 07:19 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-07 15:44 . 2004-08-10 17:51 344064 ----a-w- c:\windows\system32\localspl.dll
2009-07-23 03:28 . 2008-06-18 20:11 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-11-25 09:03 . 2006-12-02 23:01 88 --sh--r- c:\windows\system32\89B015B610.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FaxCenterServer"="c:\program files\Dell PC Fax\fm3032.exe" [2006-06-15 307200]
"dlcxmon.exe"="c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe" [2006-06-14 286720]
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 926\memcard.exe" [2006-06-27 299008]
"DLCXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-06-07 106496]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-26 1948440]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-16 981384]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2005-09-27 169984]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-26 18:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\WINDOWS\\system32\\dlcxcoms.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Novell\\GroupWise\\grpwise.exe"=
"c:\\Novell\\GroupWise\\notify.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/18/2008 1:50 PM 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/19/2009 12:19 AM 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 72944]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [6/18/2008 1:49 PM 298776]
R3 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R3 WMP11;Instant Wireless PCI Card Driver;c:\windows\system32\drivers\WMP11NDS.sys [5/16/2002 4:41 PM 54083]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-07-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\jzifm9d2.default\
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\jzifm9d2.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
.

**************************************************************************

driver loading error catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-29 00:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(728)
c:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(3496)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\dlcxcoms.exe
.
**************************************************************************
.
Completion time: 2009-07-29 0:40 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-29 07:40

Pre-Run: 35,850,543,104 bytes free
Post-Run: 35,944,943,616 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

226 --- E O F --- 2009-07-27 18:10

#6 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:12:25 AM

Posted 29 July 2009 - 11:27 AM

You have two antivirus (AVG and McAfee).. Uninstall one of them...


1. Please open Notepad
  • If you don't know how, just go to Start >> Run >> copy/paste notepad.exe >> Enter
2. Now copy/paste the entire content of the codebox below into the Notepad window:

KillAll::

File::
c:\windows\system32\89B015B610.sys

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#7 5678

5678
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:09:25 AM

Posted 29 July 2009 - 01:40 PM

ComboFix.txt:

ComboFix 09-07-28.01 - user 07/29/2009 11:15.2.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.588 [GMT -7:00]
Running from: c:\documents and settings\user\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\user\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

FILE ::
"c:\windows\system32\89B015B610.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\89B015B610.sys

.
((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-29 )))))))))))))))))))))))))))))))
.

2009-07-29 00:50 . 2009-07-29 00:50 -------- d-----w- c:\program files\Cobian Backup 9
2009-07-28 17:34 . 2009-07-03 17:09 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-07-28 17:34 . 2009-07-03 17:09 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-07-28 17:33 . 2009-07-28 17:33 -------- d-sh--w- c:\documents and settings\user\IETldCache
2009-07-28 08:50 . 2009-07-29 17:52 -------- d-----w- c:\windows\ie8updates
2009-07-28 08:49 . 2009-07-28 08:49 -------- dc-h--w- c:\windows\ie8
2009-07-28 08:48 . 2009-07-01 07:08 101376 ------w- c:\windows\system32\dllcache\iecompat.dll
2009-07-28 08:42 . 2009-07-28 08:42 -------- d-----w- c:\program files\iPod
2009-07-28 08:42 . 2009-07-28 08:42 -------- d-----w- c:\program files\iTunes
2009-07-28 08:42 . 2009-07-28 08:42 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-28 08:41 . 2009-07-28 08:41 -------- d-----w- c:\program files\Bonjour
2009-07-28 08:41 . 2009-07-28 08:42 -------- d-----w- c:\program files\Common Files\Apple
2009-07-28 08:32 . 2009-07-28 08:33 -------- d-----w- c:\program files\QuickTime
2009-07-28 08:32 . 2009-07-28 08:32 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\Apple
2009-07-28 08:32 . 2009-07-28 08:32 -------- d-----w- c:\program files\Apple Software Update
2009-07-28 08:32 . 2009-07-28 08:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-07-27 01:57 . 2009-07-27 01:57 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-07-27 00:37 . 2009-07-27 00:37 -------- d-----w- c:\program files\Trend Micro
2009-07-26 23:25 . 2009-07-28 17:34 117760 ----a-w- c:\documents and settings\user\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-26 23:24 . 2009-07-26 23:24 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-07-26 23:24 . 2009-07-26 23:24 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-07-26 23:24 . 2009-07-26 23:24 -------- d-----w- c:\documents and settings\user\Application Data\SUPERAntiSpyware.com
2009-07-26 23:24 . 2009-07-26 23:24 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-07-26 20:51 . 2009-07-26 20:51 -------- d-----w- c:\documents and settings\user\Application Data\Malwarebytes
2009-07-26 20:50 . 2009-07-13 20:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-26 20:50 . 2009-07-26 20:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-26 20:50 . 2009-07-26 20:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-26 20:50 . 2009-07-13 20:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-19 08:48 . 2009-07-24 06:18 1 ----a-w- c:\documents and settings\user\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-07-19 08:47 . 2009-07-19 08:47 -------- d-----w- c:\documents and settings\user\Application Data\OpenOffice.org
2009-07-19 08:44 . 2009-07-19 08:44 -------- d-----w- c:\program files\JRE
2009-07-19 08:44 . 2009-07-19 08:44 -------- d-----w- c:\program files\OpenOffice.org 3
2009-07-19 08:19 . 2009-07-19 08:19 152576 ----a-w- c:\documents and settings\user\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-07-17 17:26 . 2009-07-02 18:58 3403032 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-07-13 21:22 . 2009-07-13 21:22 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe
2009-07-11 17:34 . 2009-07-02 18:58 2054424 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-07-10 08:24 . 2009-07-10 08:24 -------- d-----w- c:\program files\Microsoft
2009-07-10 08:24 . 2009-07-10 08:24 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-07-10 08:24 . 2009-07-10 08:24 -------- d-----w- c:\program files\Windows Live
2009-07-02 19:00 . 2009-07-02 18:58 2167576 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgresf.dll
2009-07-02 07:31 . 2009-07-15 04:25 -------- d-----w- c:\documents and settings\user\Tracing
2009-07-02 07:25 . 2009-07-02 07:25 -------- d-----w- c:\program files\Common Files\Windows Live

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-29 18:13 . 2007-07-15 21:50 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-29 07:44 . 2006-08-24 09:39 -------- d-----w- c:\program files\SpywareBlaster
2009-07-29 04:55 . 2007-09-03 08:40 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-07-28 17:30 . 2006-11-23 21:19 21826470 ----a-w- c:\windows\Internet Logs\tvDebug.zip
2009-07-28 08:33 . 2006-08-02 10:21 48840 ----a-w- c:\documents and settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-28 04:32 . 2006-07-23 05:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-07-28 04:22 . 2007-01-27 09:42 -------- d-----w- c:\program files\EcoBeaker
2009-07-28 04:16 . 2007-04-07 22:39 -------- d-----w- c:\program files\Microsoft Works
2009-07-27 20:44 . 2006-07-31 00:43 -------- d-----w- c:\program files\Common Files\Adobe
2009-07-26 23:53 . 2006-07-23 05:10 -------- d-----w- c:\program files\MUSICMATCH
2009-07-19 08:55 . 2007-06-06 18:43 69008 ----a-w- c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-19 08:19 . 2009-01-11 19:22 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-19 08:19 . 2006-07-23 05:04 -------- d-----w- c:\program files\Java
2009-07-15 20:45 . 2006-08-13 06:34 8456 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-07-15 20:45 . 2006-08-13 06:34 104 --sh--r- c:\windows\system32\10B615B089.sys
2009-07-13 17:06 . 2008-06-18 20:49 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-07-11 17:32 . 2006-12-02 22:58 -------- d-----w- c:\program files\dl_cats
2009-07-03 17:09 . 2004-08-10 17:51 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-02 18:58 . 2008-06-18 20:50 335752 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-01 01:07 . 2006-08-12 22:33 -------- d-----w- c:\program files\DivX
2009-06-26 18:21 . 2008-06-18 20:50 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-26 18:21 . 2008-06-18 20:50 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-24 04:05 . 2007-03-25 23:15 -------- d--h--w- c:\documents and settings\user\Application Data\Move Networks
2009-06-16 14:55 . 2004-08-10 17:51 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:55 . 2004-08-10 17:51 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-06-03 19:27 . 2004-08-10 17:51 1290752 ----a-w- c:\windows\system32\quartz.dll
2009-05-31 03:52 . 2007-11-21 09:45 360 ----a-w- C:\drmHeader.bin
2009-05-30 00:31 . 2009-05-30 00:31 390664 ----a-w- c:\documents and settings\user\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-05-12 18:34 . 2009-04-19 07:19 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-07 15:44 . 2004-08-10 17:51 344064 ----a-w- c:\windows\system32\localspl.dll
2009-07-23 03:28 . 2008-06-18 20:11 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-07-29_07.37.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-12 02:41 . 2009-07-12 02:41 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll
+ 2009-07-29 18:20 . 2009-07-29 18:20 16384 c:\windows\temp\Perflib_Perfdata_98.dat
+ 2007-08-14 02:54 . 2009-07-03 17:09 55296 c:\windows\system32\msfeedsbs.dll
- 2007-08-14 02:54 . 2009-03-08 11:31 55296 c:\windows\system32\msfeedsbs.dll
- 2004-08-10 17:51 . 2009-03-08 11:33 25600 c:\windows\system32\jsproxy.dll
+ 2004-08-10 17:51 . 2009-07-03 17:09 25600 c:\windows\system32\jsproxy.dll
+ 2007-12-14 21:28 . 2009-07-03 17:09 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2007-12-14 21:28 . 2009-03-08 11:31 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2006-07-23 05:05 . 2009-03-08 11:33 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2006-07-23 05:05 . 2009-07-03 17:09 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2009-07-29 17:52 . 2009-03-08 11:33 12288 c:\windows\ie8updates\KB972260-IE8\xpshims.dll
+ 2009-07-29 17:52 . 2009-03-08 11:31 55296 c:\windows\ie8updates\KB972260-IE8\msfeedsbs.dll
+ 2009-07-29 17:52 . 2009-03-08 11:33 25600 c:\windows\ie8updates\KB972260-IE8\jsproxy.dll
+ 2004-08-10 17:51 . 2009-07-03 17:09 206848 c:\windows\system32\occache.dll
- 2007-08-14 02:54 . 2009-03-08 11:32 594432 c:\windows\system32\msfeeds.dll
+ 2007-08-14 02:54 . 2009-07-03 17:09 594432 c:\windows\system32\msfeeds.dll
+ 2004-08-10 17:51 . 2009-07-03 17:09 184320 c:\windows\system32\iepeers.dll
+ 2004-08-10 17:51 . 2009-07-03 17:09 386048 c:\windows\system32\iedkcs32.dll
+ 2004-08-10 17:51 . 2009-07-03 11:01 173056 c:\windows\system32\ie4uinit.exe
- 2004-08-10 17:51 . 2009-03-08 11:32 173056 c:\windows\system32\ie4uinit.exe
+ 2006-07-23 05:05 . 2009-07-03 17:09 915456 c:\windows\system32\dllcache\wininet.dll
+ 2007-08-14 02:44 . 2009-07-03 17:09 206848 c:\windows\system32\dllcache\occache.dll
- 2007-12-14 21:28 . 2009-03-08 11:32 594432 c:\windows\system32\dllcache\msfeeds.dll
+ 2007-12-14 21:28 . 2009-07-03 17:09 594432 c:\windows\system32\dllcache\msfeeds.dll
+ 2006-07-23 05:05 . 2009-07-03 17:09 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2007-08-14 02:39 . 2009-07-03 17:09 386048 c:\windows\system32\dllcache\iedkcs32.dll
- 2007-08-14 02:39 . 2009-03-08 11:32 173056 c:\windows\system32\dllcache\ie4uinit.exe
+ 2007-08-14 02:39 . 2009-07-03 11:01 173056 c:\windows\system32\dllcache\ie4uinit.exe
+ 2009-07-29 17:51 . 2009-07-29 17:51 248832 c:\windows\Installer\2337f24.msi
+ 2009-07-29 17:52 . 2009-03-08 11:34 914944 c:\windows\ie8updates\KB972260-IE8\wininet.dll
+ 2009-07-29 17:52 . 2009-05-26 11:40 382840 c:\windows\ie8updates\KB972260-IE8\spuninst\updspapi.dll
+ 2009-07-29 17:52 . 2009-05-26 11:40 231288 c:\windows\ie8updates\KB972260-IE8\spuninst\spuninst.exe
+ 2009-07-29 17:52 . 2009-03-08 11:34 109568 c:\windows\ie8updates\KB972260-IE8\occache.dll
+ 2009-07-29 17:52 . 2009-03-08 11:32 594432 c:\windows\ie8updates\KB972260-IE8\msfeeds.dll
+ 2009-07-29 17:52 . 2009-03-08 11:33 246784 c:\windows\ie8updates\KB972260-IE8\ieproxy.dll
+ 2009-07-29 17:52 . 2009-03-08 11:31 183808 c:\windows\ie8updates\KB972260-IE8\iepeers.dll
+ 2009-07-29 17:52 . 2009-03-08 21:09 391536 c:\windows\ie8updates\KB972260-IE8\iedkcs32.dll
+ 2009-07-29 17:52 . 2009-03-08 11:32 173056 c:\windows\ie8updates\KB972260-IE8\ie4uinit.exe
+ 2004-08-10 17:51 . 2009-07-03 17:09 1208832 c:\windows\system32\urlmon.dll
- 2004-08-10 17:51 . 2009-03-08 11:41 5937152 c:\windows\system32\mshtml.dll
+ 2004-08-10 17:51 . 2009-07-19 13:18 5937152 c:\windows\system32\mshtml.dll
+ 2007-08-14 02:34 . 2009-07-03 17:09 1985536 c:\windows\system32\iertutil.dll
+ 2006-07-23 05:05 . 2009-07-03 17:09 1208832 c:\windows\system32\dllcache\urlmon.dll
+ 2006-05-19 13:08 . 2009-07-19 13:18 5937152 c:\windows\system32\dllcache\mshtml.dll
- 2006-05-19 13:08 . 2009-03-08 11:41 5937152 c:\windows\system32\dllcache\mshtml.dll
+ 2007-12-14 21:28 . 2009-07-03 17:09 1985536 c:\windows\system32\dllcache\iertutil.dll
+ 2009-07-29 17:52 . 2009-03-08 11:34 1206784 c:\windows\ie8updates\KB972260-IE8\urlmon.dll
+ 2009-07-29 17:52 . 2009-03-08 11:41 5937152 c:\windows\ie8updates\KB972260-IE8\mshtml.dll
+ 2009-07-29 17:52 . 2009-03-08 11:32 1985024 c:\windows\ie8updates\KB972260-IE8\iertutil.dll
+ 2007-08-14 02:54 . 2009-07-20 01:48 11067392 c:\windows\system32\ieframe.dll
+ 2007-12-14 21:28 . 2009-07-20 01:48 11067392 c:\windows\system32\dllcache\ieframe.dll
+ 2009-07-29 17:52 . 2009-03-08 11:39 11063808 c:\windows\ie8updates\KB972260-IE8\ieframe.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FaxCenterServer"="c:\program files\Dell PC Fax\fm3032.exe" [2006-06-15 307200]
"dlcxmon.exe"="c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe" [2006-06-14 286720]
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 926\memcard.exe" [2006-06-27 299008]
"DLCXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-06-07 106496]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-26 1948440]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-16 981384]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2005-09-27 169984]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-26 18:21 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\WINDOWS\\system32\\dlcxcoms.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Novell\\GroupWise\\grpwise.exe"=
"c:\\Novell\\GroupWise\\notify.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/18/2008 1:50 PM 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [4/19/2009 12:19 AM 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 72944]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [6/18/2008 1:49 PM 298776]
R3 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R3 WMP11;Instant Wireless PCI Card Driver;c:\windows\system32\drivers\WMP11NDS.sys [5/16/2002 4:41 PM 54083]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-07-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\jzifm9d2.default\
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\jzifm9d2.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
.

**************************************************************************

catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-29 11:24
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(724)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(3312)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\dlcxcoms.exe
.
**************************************************************************
.
Completion time: 2009-07-29 11:27 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-29 18:27
ComboFix2.txt 2009-07-29 07:40

Pre-Run: 35,817,885,696 bytes free
Post-Run: 35,788,783,616 bytes free

266 --- E O F --- 2009-07-29 17:53




DDS.txt:

DDS (Ver_09-06-26.01) - NTFSx86
Run by user at 11:33:08.62 on Wed 07/29/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.501 [GMT -7:00]

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\dlcxcoms.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\user\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [FaxCenterServer] "c:\program files\dell pc fax\fm3032.exe" /s
mRun: [dlcxmon.exe] "c:\program files\dell photo aio printer 926\dlcxmon.exe"
mRun: [MemoryCardManager] "c:\program files\dell photo aio printer 926\memcard.exe"
mRun: [DLCXCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLCXtime.dll,_RunDLLEntry@16
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Boggle/Images/stg_drm.ocx
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/Boggle/Images/armhelper.ocx
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\user\applic~1\mozilla\firefox\profiles\jzifm9d2.default\
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\user\application data\mozilla\firefox\profiles\jzifm9d2.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-6-18 335752]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-6-18 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-4-19 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-6-23 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-6-23 72944]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2006-7-29 353672]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-6-18 298776]
R3 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R3 WMP11;Instant Wireless PCI Card Driver;c:\windows\system32\drivers\WMP11NDS.sys [2002-5-16 54083]
S2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service --> c:\windows\system32\zonelabs\vsmon.exe -service [?]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-6-23 7408]

=============== Created Last 30 ================

2009-07-29 00:39 <DIR> --d----- c:\windows\system32\dllcache\cache
2009-07-29 00:31 <DIR> a-dshr-- C:\cmdcons
2009-07-29 00:28 219,648 a------- c:\windows\PEV.exe
2009-07-29 00:28 161,792 a------- c:\windows\SWREG.exe
2009-07-29 00:28 98,816 a------- c:\windows\sed.exe
2009-07-28 17:50 <DIR> --d----- c:\program files\Cobian Backup 9
2009-07-28 10:34 246,272 -------- c:\windows\system32\dllcache\ieproxy.dll
2009-07-28 10:34 12,800 -------- c:\windows\system32\dllcache\xpshims.dll
2009-07-28 10:33 <DIR> --dsh--- c:\documents and settings\user\IETldCache
2009-07-28 01:50 <DIR> --d----- c:\windows\ie8updates
2009-07-28 01:49 <DIR> -cd-h--- c:\windows\ie8
2009-07-28 01:48 101,376 -------- c:\windows\system32\dllcache\iecompat.dll
2009-07-28 01:42 <DIR> --d----- c:\program files\iPod
2009-07-28 01:42 <DIR> --d----- c:\program files\iTunes
2009-07-28 01:42 <DIR> --d----- c:\docume~1\alluse~1\applic~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-07-28 01:41 <DIR> --d----- c:\program files\Bonjour
2009-07-27 11:09 118 a------- c:\windows\system32\MRT.INI
2009-07-26 17:37 <DIR> --d----- c:\program files\Trend Micro
2009-07-26 16:24 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-07-26 16:24 <DIR> --d----- c:\program files\SUPERAntiSpyware
2009-07-26 16:24 <DIR> --d----- c:\docume~1\user\applic~1\SUPERAntiSpyware.com
2009-07-26 16:24 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-07-26 13:51 <DIR> --d----- c:\docume~1\user\applic~1\Malwarebytes
2009-07-26 13:50 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-26 13:50 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-07-26 13:50 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-07-26 13:50 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-07-19 01:47 <DIR> --d----- c:\docume~1\user\applic~1\OpenOffice.org
2009-07-19 01:44 <DIR> --d----- c:\program files\JRE
2009-07-19 01:44 <DIR> --d----- c:\program files\OpenOffice.org 3
2009-07-19 01:19 73,728 a------- c:\windows\system32\javacpl.cpl
2009-07-11 14:38 269 a------- c:\windows\wininit.ini
2009-07-10 01:24 <DIR> --d----- c:\program files\Microsoft
2009-07-10 01:24 <DIR> --d----- c:\program files\Windows Live SkyDrive
2009-07-02 00:31 <DIR> --d----- c:\documents and settings\user\Tracing
2009-07-02 00:25 <DIR> --d----- c:\program files\common files\Windows Live

==================== Find3M ====================

2009-07-19 18:48 11,067,392 a------- c:\windows\system32\dllcache\ieframe.dll
2009-07-19 06:18 5,937,152 a------- c:\windows\system32\dllcache\mshtml.dll
2009-07-19 01:19 410,984 a------- c:\windows\system32\deploytk.dll
2009-07-15 13:45 8,456 a--sh--- c:\windows\system32\KGyGaAvL.sys
2009-07-03 10:09 915,456 a------- c:\windows\system32\wininet.dll
2009-07-03 10:09 915,456 a------- c:\windows\system32\dllcache\wininet.dll
2009-07-03 10:09 915,456 a------- c:\windows\system32\dllcache\cache\wininet.dll
2009-07-03 10:09 1,208,832 a------- c:\windows\system32\dllcache\urlmon.dll
2009-07-03 10:09 206,848 a------- c:\windows\system32\dllcache\occache.dll
2009-07-03 10:09 594,432 a------- c:\windows\system32\dllcache\msfeeds.dll
2009-07-03 10:09 55,296 a------- c:\windows\system32\dllcache\msfeedsbs.dll
2009-07-03 10:09 1,985,536 a------- c:\windows\system32\dllcache\iertutil.dll
2009-07-03 10:09 25,600 a------- c:\windows\system32\dllcache\jsproxy.dll
2009-07-03 10:09 184,320 a------- c:\windows\system32\dllcache\iepeers.dll
2009-07-03 10:09 386,048 a------- c:\windows\system32\dllcache\iedkcs32.dll
2009-07-03 04:01 173,056 a------- c:\windows\system32\dllcache\ie4uinit.exe
2009-07-02 11:58 335,752 a------- c:\windows\system32\drivers\avgldx86.sys
2009-06-26 11:21 11,952 a------- c:\windows\system32\avgrsstx.dll
2009-06-16 07:55 119,808 a------- c:\windows\system32\t2embed.dll
2009-06-16 07:55 82,432 a------- c:\windows\system32\fontsub.dll
2009-06-16 07:55 119,808 -------- c:\windows\system32\dllcache\t2embed.dll
2009-06-16 07:55 82,432 -------- c:\windows\system32\dllcache\fontsub.dll
2009-06-03 12:27 1,290,752 a------- c:\windows\system32\quartz.dll
2009-06-03 12:27 1,290,752 -------- c:\windows\system32\dllcache\quartz.dll
2009-05-30 20:52 360 a------- C:\drmHeader.bin
2009-05-07 08:44 344,064 a------- c:\windows\system32\localspl.dll
2009-05-07 08:44 344,064 -------- c:\windows\system32\dllcache\localspl.dll

============= FINISH: 11:33:19.15 ===============

#8 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:12:25 AM

Posted 29 July 2009 - 04:55 PM

Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer for this scan.
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan
    Wait for the scan to finish
  • Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic
How's the computer now? :thumbup2:

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#9 5678

5678
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:09:25 AM

Posted 30 July 2009 - 01:23 AM

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=6
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.5889
# api_version=3.0.2
# EOSSerial=c5672f88d173d44bbbd247a6dfbb79f5
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2009-07-30 12:42:38
# local_time=2009-07-29 05:42:38 (-0800, Pacific Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 2
# compatibility_mode=1026 21 83 97 10629854062500
# scanned=60662
# found=0
# cleaned=0
# scan_time=1317


My computer appears to be clean now; virus is gone. Thank you so much for your help! :thumbup2:

#10 fenzodahl512

fenzodahl512

  • Members
  • 6,738 posts
  • OFFLINE
  •  
  • Local time:12:25 AM

Posted 30 July 2009 - 08:55 AM

Looks good to me.. Lets do some cleanup...


Please download OTC and save it to Desktop.
  • Make sure you have internet connection..
  • Double-click OTC
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes


Please read these excellent articles write by my friends:
Preventing Malware and Safe Computing by Rorschach112
What makes your machine slow? by Artellos


Also, please read these excellent articles by miekiemoes :
Help! My computer is slow!
How to prevent Malware


Read these great info's about safe internet surfing..

http://www.pcpitstop.com/spycheck/safesurfing.asp
http://bluefive.pair.com/practice_safe_surfing.htm




Please reply to this thread once more and tell us about the computer behaviour before we can close this thread :thumbup2:



Have a safe and happy computing day!


Regards
fenzodahl512

Keep calm, make it simple, use your brain, don't freak out, and you'll be just fine..
Awesomeness: When I get sad, I stop being sad and be awesome instead.. True story - Barney Stinson
Posted Image Posted Image
Its gonna be legen.. wait for it.. dary! Cherish the pain, it means you're still alive


#11 5678

5678
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:09:25 AM

Posted 30 July 2009 - 05:00 PM

fenzodahl512,

My Google searches are no longer being redirected. Also, my computer seems to be much faster. Thanks a lot! :thumbup2:




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users