Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

infected with worm??


  • This topic is locked This topic is locked
70 replies to this topic

#1 rachy

rachy

  • Members
  • 93 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:uk
  • Local time:04:47 AM

Posted 11 October 2009 - 02:38 AM

hello,
im not sure if iv posted in the correct section.

iv been having major problems with my pc yestarday and today, i kept getting messages says b.exe had to be terminated, everything kept sticking and freezing on me.

i tryed to do do a system restore and it said that system restore could no successfully finish.. i tryed in safe mode and normal mode a few times and still kept saying the same thing. i then got a message from windows saying i had a worm.

iv now reformatted my pc, but i keep getting messages saying windows stopped working, close programme, wait for a responce etc, things are not installing prolly on my pc.

after opening the rootrepeal scan i had a blue screen message, i was in a little bit of a panic and couldnt quiet catch all of the message but it began with iqol_

i dont no what to do, would really reall really apperiate some help if possible please.
Thank you
Rachel

here are my scans


DDS (Ver_09-09-29.01) - NTFSx86
Run by Rachel at 8:00:42.65 on 11/10/2009
Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_16
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.767.141 [GMT 1:00]

SP: ZoneAlarm Anti-Spyware *enabled* (Outdated) {F245A209-1085-48B4-B927-35D56015EC60}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\ZoneLabs\vsmon.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\Windows\system32\IoctlSvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\Dwm.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Packard Bell\Carbonite\CarboniteSetupLitePBPreInstaller.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\PC Tools AntiVirus\PCTAV.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\wuauclt.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Rachel\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://go.packardbell.com/?id=9067
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\google\google_bae\BAE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [SmpcSys] c:\program files\packard bell\setupmypc\SmpSys.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [CarboniteSetupLite] "c:\program files\packard bell\carbonite\CarboniteSetupLitePBPreInstaller.exe" /preinstalled
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [toolbar_eula_launcher] c:\program files\packard bell\google_eula\EULALauncher.exe
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [PCTAVApp] "c:\program files\pc tools antivirus\PCTAV.exe" /MONITORSCAN
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [<NO NAME>]
mRun: [LogitechQuickCamRibbon] "c:\program files\labtec\webcam10\WebCam10.exe" /hide
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - c:\program files\paltalk messenger\Paltalk.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
AppInit_DLLs: c:\progra~1\google\google~4\GOEC62~1.DLL

================= FIREFOX ===================

FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.allow_platform_file_picker", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.accept.default", "application/x-shockwave-flash,text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5");
c:\program files\mozilla firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\mozilla firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.remoteLookups", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.updateURL", "http://sb.google.com/safebrowsing/update?client={moz:client}&appver={moz:version}&");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.lookupURL", "http://sb.google.com/safebrowsing/lookup?sourceid=firefox-antiphish&features=TrustRank&client={moz:client}&appver={moz:version}&");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.reportURL", "http://sb.google.com/safebrowsing/report?");

============= SERVICES / DRIVERS ===============

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-10-11 206256]
S3 GoogleDesktopManager-071508-051939;Google Desktop Manager 5.7.807.15159;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-8-22 24064]
S4 nvrd32;NVIDIA nForce RAID Driver;c:\windows\system32\drivers\nvrd32.sys [2008-8-22 124960]

=============== Created Last 30 ================

2009-10-11 07:20 <DIR> --d----- c:\users\rachel\appdata\roaming\Paltalk
2009-10-11 07:07 <DIR> --d----- c:\programdata\WindowsSearch
2009-10-11 06:53 2,048 a------- c:\windows\system32\tzres.dll
2009-10-11 06:06 <DIR> --d----- c:\program files\common files\Labtec
2009-10-11 06:04 97,800 a------- c:\windows\system32\infocardapi.dll
2009-10-11 06:04 105,016 a------- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-10-11 06:04 622,080 a------- c:\windows\system32\icardagt.exe
2009-10-11 06:04 43,544 a------- c:\windows\system32\PresentationHostProxy.dll
2009-10-11 06:04 37,384 a------- c:\windows\system32\infocardcpl.cpl
2009-10-11 06:04 11,264 a------- c:\windows\system32\icardres.dll
2009-10-11 06:04 781,344 a------- c:\windows\system32\PresentationNative_v0300.dll
2009-10-11 06:04 326,160 a------- c:\windows\system32\PresentationHost.exe
2009-10-11 06:03 <DIR> --d----- c:\program files\Labtec
2009-10-11 05:58 <DIR> --d----- c:\program files\common files\Windows Live
2009-10-11 05:53 411,368 a------- c:\windows\system32\deploytk.dll
2009-10-11 05:48 96,760 a------- c:\windows\system32\dfshim.dll
2009-10-11 05:48 282,112 a------- c:\windows\system32\mscoree.dll
2009-10-11 05:48 41,984 a------- c:\windows\system32\netfxperf.dll
2009-10-11 05:48 158,720 a------- c:\windows\system32\mscorier.dll
2009-10-11 05:48 83,968 a------- c:\windows\system32\mscories.dll
2009-10-11 05:46 195,440 -------- c:\windows\system32\MpSigStub.exe
2009-10-11 05:46 <DIR> --d----- c:\users\rachel\appdata\roaming\Godlike
2009-10-11 05:45 <DIR> --d----- c:\program files\Godlike Developers
2009-10-11 05:45 <DIR> --d----- c:\program files\MSXML 4.0
2009-10-11 05:35 289,792 a------- c:\windows\system32\atmfd.dll
2009-10-11 05:35 156,672 a------- c:\windows\system32\t2embed.dll
2009-10-11 05:35 72,704 a------- c:\windows\system32\fontsub.dll
2009-10-11 05:35 10,240 a------- c:\windows\system32\dciman32.dll
2009-10-11 05:35 71,680 a------- c:\windows\system32\atl.dll
2009-10-11 05:35 361,984 a------- c:\windows\system32\IPSECSVC.DLL
2009-10-11 05:32 595,456 a------- c:\windows\system32\FWPUCLNT.DLL
2009-10-11 05:32 328,704 a------- c:\windows\system32\BFE.DLL
2009-10-11 05:32 27,136 a------- c:\windows\system32\NETSTAT.EXE
2009-10-11 05:32 19,968 a------- c:\windows\system32\ARP.EXE
2009-10-11 05:32 11,264 a------- c:\windows\system32\MRINFO.EXE
2009-10-11 05:32 10,240 a------- c:\windows\system32\finger.exe
2009-10-11 05:32 9,728 a------- c:\windows\system32\TCPSVCS.EXE
2009-10-11 05:32 8,704 a------- c:\windows\system32\HOSTNAME.EXE
2009-10-11 05:32 17,920 a------- c:\windows\system32\ROUTE.EXE
2009-10-11 05:32 17,920 a------- c:\windows\system32\netevent.dll
2009-10-11 05:32 <DIR> --d----- c:\users\rachel\appdata\roaming\PC Tools
2009-10-11 05:31 2,033,152 a------- c:\windows\system32\win32k.sys
2009-10-11 05:31 269,312 a------- c:\windows\system32\es.dll
2009-10-11 05:31 296,960 a------- c:\windows\system32\gdi32.dll
2009-10-11 05:31 2,501,921 a------- c:\windows\system32\wlan.tmf
2009-10-11 05:31 513,024 a------- c:\windows\system32\wlansvc.dll
2009-10-11 05:31 302,592 a------- c:\windows\system32\wlansec.dll
2009-10-11 05:31 293,376 a------- c:\windows\system32\wlanmsm.dll
2009-10-11 05:31 127,488 a------- c:\windows\system32\L2SecHC.dll
2009-10-11 05:31 2,066,432 a------- c:\windows\system32\mstscax.dll
2009-10-11 05:31 <DIR> a-d----- c:\programdata\TEMP
2009-10-11 05:30 206,256 a------- c:\windows\system32\drivers\PCTCore.sys
2009-10-11 05:30 86,888 a------- c:\windows\system32\drivers\PCTAppEvent.sys
2009-10-11 05:30 7,396 a------- c:\windows\system32\drivers\pctcore.cat
2009-10-11 05:30 <DIR> --d----- c:\program files\common files\PC Tools
2009-10-11 05:30 28,560 a------- c:\windows\system32\drivers\AVHook.sys
2009-10-11 05:30 21,904 a------- c:\windows\system32\drivers\AVRec.sys
2009-10-11 05:30 21,904 a------- c:\windows\system32\drivers\AVFilter.sys
2009-10-11 05:30 <DIR> --d----- c:\programdata\PC Tools
2009-10-11 05:30 <DIR> --d----- c:\program files\PC Tools AntiVirus
2009-10-11 05:30 <DIR> --d----- c:\progra~2\PC Tools
2009-10-11 05:29 711,168 a------- c:\windows\system32\sbe.dll
2009-10-11 05:29 604,672 a------- c:\windows\system32\CPFilters.dll
2009-10-11 05:29 153,088 a------- c:\windows\system32\sbeio.dll
2009-10-11 05:29 763,904 a------- c:\windows\system32\MSDTVVDEC.DLL
2009-10-11 05:29 562,176 a------- c:\windows\system32\msdtcprx.dll
2009-10-11 05:29 38,912 a------- c:\windows\system32\xolehlp.dll
2009-10-11 05:28 170,496 a------- c:\windows\system32\tcpipcfg.dll
2009-10-11 05:28 22,528 a------- c:\windows\system32\netiougc.exe
2009-10-11 05:28 160,256 a------- c:\windows\system32\wkssvc.dll
2009-10-11 05:28 376,832 a------- c:\windows\system32\winhttp.dll
2009-10-11 05:28 2,868,224 a------- c:\windows\system32\mf.dll
2009-10-11 05:27 212,480 a------- c:\windows\system32\drivers\mrxsmb10.sys
2009-10-11 05:27 241,152 a------- c:\windows\system32\PortableDeviceApi.dll
2009-10-11 05:27 24,064 a------- c:\windows\system32\amxread.dll
2009-10-11 05:27 13,824 a------- c:\windows\system32\apilogen.dll
2009-10-11 05:25 1,221,512 a------- c:\windows\system32\zpeng25.dll
2009-10-11 05:25 <DIR> --d----- c:\program files\Zone Labs
2009-10-11 05:23 350,192 a---h--- c:\windows\system32\drivers\vsconfig.xml
2009-10-11 05:23 293,528 a------- c:\windows\system32\drivers\vsdatant.sys
2009-10-11 05:23 <DIR> --d----- c:\windows\system32\ZoneLabs
2009-10-11 05:22 <DIR> --d----- c:\programdata\CheckPoint
2009-10-11 05:22 <DIR> --d----- c:\progra~2\CheckPoint
2009-10-11 05:22 <DIR> --d----- c:\windows\Internet Logs
2009-10-11 05:22 636,928 a------- c:\windows\system32\localspl.dll
2009-10-11 05:20 147,456 a------- c:\windows\system32\Faultrep.dll
2009-10-11 05:19 288,768 a------- c:\windows\system32\drivers\srv.sys
2009-10-11 05:18 996,352 a------- c:\windows\system32\WMNetMgr.dll
2009-10-11 05:18 94,720 a------- c:\windows\system32\logagent.exe
2009-10-11 05:18 28,672 a------- c:\windows\system32\Apphlpdm.dll
2009-10-11 05:18 4,240,384 a------- c:\windows\system32\GameUXLegacyGDFs.dll
2009-10-11 05:18 738,304 a------- c:\windows\system32\inetcomm.dll
2009-10-11 05:18 784,896 a------- c:\windows\system32\rpcrt4.dll
2009-10-11 05:11 <DIR> --d----- c:\users\rachel\appdata\roaming\Symantec
2009-10-11 05:11 1,334,272 a------- c:\windows\system32\msxml6.dll
2009-10-11 05:10 <DIR> --dsh--- C:\$RECYCLE.BIN
2009-10-11 05:03 <DIR> --d----- c:\users\Rachel
2009-10-11 05:00 1,524,736 a------- c:\windows\system32\wucltux.dll
2009-10-11 05:00 162,064 a------- c:\windows\system32\wuwebv.dll
2009-10-11 05:00 31,232 a------- c:\windows\system32\wuapp.exe

==================== Find3M ====================

2009-10-11 06:40 86,016 a------- c:\windows\inf\infstrng.dat
2009-10-11 06:40 86,016 a------- c:\windows\inf\infstor.dat
2009-10-11 06:40 51,200 a------- c:\windows\inf\infpub.dat
2009-08-28 13:39 173,056 a------- c:\windows\apppatch\AcXtrnal.dll
2009-08-28 13:38 2,153,984 a------- c:\windows\apppatch\AcGenral.dll
2009-08-28 13:38 541,696 a------- c:\windows\apppatch\AcLayers.dll
2009-08-28 13:38 459,776 a------- c:\windows\apppatch\AcSpecfc.dll
2009-08-14 18:01 900,168 a------- c:\windows\system32\drivers\tcpip.sys
2009-08-14 18:01 220,232 a------- c:\windows\system32\drivers\netio.sys
2009-08-14 18:01 98,376 a------- c:\windows\system32\drivers\FWPKCLNT.SYS
2009-08-14 17:29 104,960 a------- c:\windows\system32\netiohlp.dll
2009-08-14 17:23 438,272 a------- c:\windows\system32\IKEEXT.DLL
2009-07-18 17:06 827,904 a------- c:\windows\system32\wininet.dll
2009-07-18 17:01 78,336 a------- c:\windows\system32\ieencode.dll
2009-07-18 10:46 26,624 a------- c:\windows\system32\ieUnatt.exe
2009-07-15 15:51 4,096 a------- c:\windows\system32\dxmasf.dll
2009-07-15 15:51 7,680 a------- c:\windows\system32\spwmp.dll
2009-07-15 14:07 8,147,456 a------- c:\windows\system32\wmploc.DLL
2009-07-14 14:00 313,344 a------- c:\windows\system32\wmpdxm.dll
2008-08-22 19:26 665,600 a------- c:\windows\inf\drvindex.dat
2008-01-21 03:43 174 a--sh--- c:\program files\desktop.ini
2006-11-02 13:42 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 13:42 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 13:42 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 13:42 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 10:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 10:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 10:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 10:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat
2008-08-22 19:12 65,536 a--sh--- c:\windows\oem\mp\boot\bootstat.dat
2008-08-22 19:26 8,192 a--sh--- c:\windows\users\default\NTUSER.DAT

============= FINISH: 8:06:16.46 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:04:47 AM

Posted 26 October 2009 - 02:51 PM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.


Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#3 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:04:47 AM

Posted 31 October 2009 - 11:04 AM

Due to the lack of feedback, this topic is now closed.
If you need this topic reopened, please PM a staff member and we will reopen it for you (include the address of this thread in your request). This applies to the original topic starter only. Everyone else with similar problems, please start a new topic.
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#4 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:04:47 AM

Posted 02 November 2009 - 12:07 PM

Reopened by user request.
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#5 rachy

rachy
  • Topic Starter

  • Members
  • 93 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:uk
  • Local time:04:47 AM

Posted 02 November 2009 - 02:25 PM

hello, thank you for reopening,
here are the scans i done, iv attached the attched log one :(
im still having major sticking and freezing happening, also everything takes ages to load, and media files just break all the time, buffer, then stop playing my anti virus stops working some times and has said it has found virus's, i have cleaned my pc and reformated and its not made any difference.

DDS LOG:

DDS (Ver_09-10-26.01) - NTFSx86
Run by rachel at 19:20:04.11 on 02/11/2009
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.767.155 [GMT 0:00]

SP: ZoneAlarm Anti-Spyware *enabled* (Outdated) {F245A209-1085-48B4-B927-35D56015EC60}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\ZoneLabs\vsmon.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Labtec\WebCam10\WebCam10.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Paltalk Messenger\paltalk.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\rachel\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://go.packardbell.com/?id=9067
uDefault_Page_URL = hxxp://go.packardbell.com/?id=9067
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\google\google_bae\BAE.dll
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [SmpcSys] c:\program files\packard bell\setupmypc\SmpSys.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [PCTAVApp] "c:\program files\pc tools antivirus\PCTAV.exe" /MONITORSCAN
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [<NO NAME>] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [toolbar_eula_launcher] c:\program files\packard bell\google_eula\EULALauncher.exe
mRun: [LogitechQuickCamRibbon] "c:\program files\labtec\webcam10\WebCam10.exe" /hide
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\paltalk.lnk - c:\program files\paltalk messenger\paltalk.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - c:\program files\paltalk messenger\Paltalk.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_03\bin\npjpi150_03.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
AppInit_DLLs: c:\progra~1\google\google~4\GOEC62~1.DLL

================= FIREFOX ===================

FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.allow_platform_file_picker", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.accept.default", "application/x-shockwave-flash,text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5");
c:\program files\mozilla firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\mozilla firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.remoteLookups", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.updateURL", "http://sb.google.com/safebrowsing/update?client={moz:client}&appver={moz:version}&");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.lookupURL", "http://sb.google.com/safebrowsing/lookup?sourceid=firefox-antiphish&features=TrustRank&client={moz:client}&appver={moz:version}&");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.reportURL", "http://sb.google.com/safebrowsing/report?");

============= SERVICES / DRIVERS ===============

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-10-12 206256]
R2 TeamViewer4;TeamViewer 4;c:\program files\teamviewer\version4\TeamViewer_Service.exe [2009-5-18 185640]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [2008-1-14 21632]
S3 GoogleDesktopManager-071508-051939;Google Desktop Manager 5.7.807.15159;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-8-22 24064]
S4 nvrd32;NVIDIA nForce RAID Driver;c:\windows\system32\drivers\nvrd32.sys [2008-8-22 124960]

=============== Created Last 30 ================

2009-10-27 18:16:51 310784 ----a-w- c:\windows\system32\unregmp2.exe
2009-10-27 18:16:49 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-10-27 18:16:48 4096 ----a-w- c:\windows\system32\msdxm.ocx
2009-10-27 18:16:48 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-10-27 18:16:46 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-10-27 00:43:41 0 d-----w- c:\windows\system32\EventProviders
2009-10-22 01:15:39 49265 ----a-w- c:\windows\system32\jpicpl32.cpl
2009-10-20 19:13:22 0 d-----w- c:\windows\system32\Adobe
2009-10-19 13:34:03 0 d-----w- c:\program files\VirtualDJ
2009-10-17 00:23:01 773120 ----a-w- c:\windows\system32\NEROINSTAEC43759.DB
2009-10-17 00:22:59 1414440 ----a-w- c:\windows\system32\ShellManager310E2D762.dll
2009-10-17 00:19:58 1024 ----a-w- c:\users\rachel\.rnd
2009-10-17 00:18:46 0 ----a-w- c:\windows\Irremote.ini
2009-10-16 18:39:42 0 d-----w- c:\program files\common files\PX Storage Engine
2009-10-15 17:30:53 3597896 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-10-15 17:30:52 3546184 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-10-15 17:29:45 428544 ----a-w- c:\windows\system32\EncDec.dll
2009-10-15 17:29:04 763904 ----a-w- c:\windows\system32\MSDTVVDEC.DLL
2009-10-15 17:29:03 711168 ----a-w- c:\windows\system32\sbe.dll
2009-10-15 17:29:03 604672 ----a-w- c:\windows\system32\CPFilters.dll
2009-10-15 17:28:59 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-10-15 17:28:54 61440 ----a-w- c:\windows\system32\msasn1.dll
2009-10-15 17:28:49 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2009-10-15 17:20:48 0 d-----w- c:\users\rachel\appdata\roaming\Godlike
2009-10-15 17:20:38 0 d-----w- c:\program files\Godlike Developers
2009-10-14 15:41:09 0 d-----w- c:\program files\YouTube Downloader
2009-10-14 03:04:22 0 d-----w- c:\users\rachel\appdata\roaming\TeamViewer
2009-10-14 03:03:59 0 d-----w- c:\program files\TeamViewer
2009-10-14 03:02:37 0 d-----w- c:\users\rachel\temp
2009-10-13 23:27:04 0 d-----w- c:\users\rachel\appdata\roaming\ManyCam
2009-10-13 23:27:03 0 d-----w- c:\program files\ManyCam 2.4
2009-10-13 19:56:42 107864 ----a-w- c:\windows\system32\tsccvid.dll
2009-10-13 19:56:39 0 d-----w- c:\windows\system32\QuickTime
2009-10-13 19:56:09 0 d-----w- c:\programdata\TechSmith
2009-10-13 19:55:30 0 d-----w- c:\program files\common files\TechSmith Shared
2009-10-12 20:37:16 56 ---ha-w- c:\programdata\ezsidmv.dat
2009-10-12 20:35:45 0 d-----r- c:\program files\Skype
2009-10-12 20:02:30 0 d-----w- c:\program files\common files\Labtec
2009-10-12 19:57:41 0 d-----w- c:\program files\Labtec
2009-10-12 14:11:35 0 d-----w- c:\users\rachel\Tracing
2009-10-12 14:08:45 0 d-----w- c:\program files\Paltalk Messenger
2009-10-12 13:43:51 0 d-----w- c:\programdata\Office Genuine Advantage
2009-10-12 12:22:25 0 d-----w- c:\programdata\WindowsSearch
2009-10-12 05:03:22 2048 ----a-w- c:\windows\system32\tzres.dll
2009-10-12 04:26:36 0 d-----w- c:\users\rachel\appdata\roaming\Paltalk
2009-10-12 04:25:52 0 d-----w- c:\program files\Microsoft
2009-10-12 04:25:12 0 d-----w- c:\program files\Windows Live SkyDrive
2009-10-12 04:20:38 0 d-----w- c:\program files\common files\Windows Live
2009-10-12 04:13:54 97800 ----a-w- c:\windows\system32\infocardapi.dll
2009-10-12 04:13:54 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-10-12 04:13:53 622080 ----a-w- c:\windows\system32\icardagt.exe
2009-10-12 04:13:53 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2009-10-12 04:13:53 37384 ----a-w- c:\windows\system32\infocardcpl.cpl
2009-10-12 04:13:53 11264 ----a-w- c:\windows\system32\icardres.dll
2009-10-12 04:13:48 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2009-10-12 04:13:44 326160 ----a-w- c:\windows\system32\PresentationHost.exe
2009-10-12 04:06:45 0 d-----w- c:\users\rachel\appdata\roaming\PC Tools
2009-10-12 04:05:37 96760 ----a-w- c:\windows\system32\dfshim.dll
2009-10-12 04:05:35 282112 ----a-w- c:\windows\system32\mscoree.dll
2009-10-12 04:05:34 41984 ----a-w- c:\windows\system32\netfxperf.dll
2009-10-12 04:05:22 158720 ----a-w- c:\windows\system32\mscorier.dll
2009-10-12 04:05:18 83968 ----a-w- c:\windows\system32\mscories.dll
2009-10-12 04:04:44 0 d---a-w- c:\programdata\TEMP
2009-10-12 04:04:24 86888 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-10-12 04:04:24 7396 ----a-w- c:\windows\system32\drivers\pctcore.cat
2009-10-12 04:04:24 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-10-12 04:04:12 0 d-----w- c:\program files\common files\PC Tools
2009-10-12 04:04:11 28560 ----a-w- c:\windows\system32\drivers\AVHook.sys
2009-10-12 04:04:11 21904 ----a-w- c:\windows\system32\drivers\AVRec.sys
2009-10-12 04:04:11 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-10-12 04:04:10 21904 ----a-w- c:\windows\system32\drivers\AVFilter.sys
2009-10-12 04:03:50 0 d-----w- c:\programdata\PC Tools
2009-10-12 04:03:50 0 d-----w- c:\program files\PC Tools AntiVirus
2009-10-12 03:53:00 900168 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-10-12 03:51:58 615424 ----a-w- c:\windows\system32\wbem\fastprox.dll
2009-10-12 03:50:49 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-10-12 03:50:49 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-10-12 03:50:49 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-10-12 03:50:49 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-10-12 03:50:34 2868224 ----a-w- c:\windows\system32\mf.dll
2009-10-12 03:50:26 296960 ----a-w- c:\windows\system32\gdi32.dll
2009-10-12 03:50:18 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-10-12 03:50:12 361984 ----a-w- c:\windows\system32\IPSECSVC.DLL
2009-10-12 03:49:58 91136 ----a-w- c:\windows\system32\avifil32.dll
2009-10-12 03:49:44 22528 ----a-w- c:\windows\system32\netiougc.exe
2009-10-12 03:49:44 170496 ----a-w- c:\windows\system32\tcpipcfg.dll
2009-10-12 03:49:41 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-10-12 03:49:29 43520 ----a-w- c:\windows\system32\msdxm.tlb
2009-10-12 03:49:29 18432 ----a-w- c:\windows\system32\amcompat.tlb
2009-10-12 03:49:18 71680 ----a-w- c:\windows\system32\atl.dll
2009-10-12 03:49:11 376832 ----a-w- c:\windows\system32\winhttp.dll
2009-10-12 03:47:10 1221512 ----a-w- c:\windows\system32\zpeng25.dll
2009-10-12 03:47:07 0 d-----w- c:\program files\Zone Labs
2009-10-12 03:46:00 499712 ----a-w- c:\windows\system32\kerberos.dll
2009-10-12 03:46:00 270848 ----a-w- c:\windows\system32\schannel.dll
2009-10-12 03:46:00 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-10-12 03:44:57 147456 ----a-w- c:\windows\system32\Faultrep.dll
2009-10-12 03:44:56 125952 ----a-w- c:\windows\system32\wersvc.dll
2009-10-12 03:44:43 0 d-----w- c:\programdata\CheckPoint
2009-10-12 03:44:34 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-10-12 03:44:24 269312 ----a-w- c:\windows\system32\es.dll
2009-10-12 03:44:19 2927104 ----a-w- c:\windows\explorer.exe
2009-10-12 03:44:15 303616 ----a-w- c:\windows\system32\wmpeffects.dll
2009-10-12 03:44:05 443392 ----a-w- c:\windows\system32\win32spl.dll
2009-10-12 03:44:01 1645568 ----a-w- c:\windows\system32\connect.dll
2009-10-12 03:44:01 0 d-----w- c:\windows\Internet Logs
2009-10-12 03:43:50 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-10-12 03:43:45 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-10-12 03:40:50 425472 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-10-12 03:40:49 712704 ----a-w- c:\windows\system32\WindowsCodecs.dll
2009-10-12 03:40:49 347136 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-10-12 03:40:46 565248 ----a-w- c:\windows\system32\emdmgmt.dll
2009-10-12 03:40:45 625152 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-10-12 03:40:45 45056 ----a-w- c:\windows\system32\dataclen.dll
2009-10-12 03:40:45 36864 ----a-w- c:\windows\system32\cdd.dll
2009-10-12 03:35:32 0 d-----w- c:\users\rachel\appdata\roaming\Symantec
2009-10-12 03:34:49 0 d-sh--w- C:\$RECYCLE.BIN
2009-10-12 03:33:14 1334272 ----a-w- c:\windows\system32\msxml6.dll
2009-10-12 03:25:50 1524736 ----a-w- c:\windows\system32\wucltux.dll
2009-10-12 03:25:33 83456 ----a-w- c:\windows\system32\wudriver.dll
2009-10-12 03:25:24 31232 ----a-w- c:\windows\system32\wuapp.exe
2009-10-12 03:25:24 162064 ----a-w- c:\windows\system32\wuwebv.dll

==================== Find3M ====================

2009-11-02 11:48:32 350192 ---ha-w- c:\windows\system32\drivers\vsconfig.xml
2009-10-13 23:28:36 86016 ----a-w- c:\windows\inf\infstrng.dat
2009-10-13 23:28:36 51200 ----a-w- c:\windows\inf\infpub.dat
2009-10-13 23:28:25 86016 ----a-w- c:\windows\inf\infstor.dat
2009-09-10 17:30:12 213504 ----a-w- c:\windows\system32\msv1_0.dll
2009-08-27 13:32:41 833024 ----a-w- c:\windows\system32\wininet.dll
2009-08-27 13:29:25 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-27 10:58:58 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-08-17 22:33:52 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-14 16:29:41 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 16:29:41 104960 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-14 16:23:16 438272 ----a-w- c:\windows\system32\IKEEXT.DLL
2009-08-14 16:22:53 595456 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2009-08-14 16:21:33 328704 ----a-w- c:\windows\system32\BFE.DLL
2009-08-14 14:16:55 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:16:55 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 14:16:52 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 14:16:51 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 14:16:50 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 14:16:49 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:16:49 10240 ----a-w- c:\windows\system32\finger.exe
2008-08-22 18:26:24 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2008-08-22 18:26:23 8192 --sha-w- c:\windows\users\default\NTUSER.DAT

============= FINISH: 19:21:42.01 ===============

Attached Files



#6 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:04:47 AM

Posted 02 November 2009 - 04:40 PM

Hello, rachy and again
Welcome to the Bleeping Computer Forums. My name is Thomas (Tom is fine), and I will be helping you fixing your problems.

If you do not make a reply in 5 days, we will have to close your topic.

You may want to keep the link to this topic in your favourites. Alternatively, you can click the Posted Image button at the top bar of this topic and Track this Topic. The topics you are tracking can be found here.

Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
  • Please reply using the Posted Image button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
  • Old topics are closed after 3 days with no reply, and working topics are closed after 5 days. If for any reason you cannot complete instructions within that time, that's fine, just post back here so that we know you're still here.
  • Please set your system to show all files.
    Click Start, open My Computer, select the Tools menu and click Folder Options.
    Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
    Uncheck: Hide file extensions for known file types
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm.






Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

    Posted Image
  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.
-- If you encounter any problems, try running GMER in Safe Mode.
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#7 rachy

rachy
  • Topic Starter

  • Members
  • 93 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:uk
  • Local time:04:47 AM

Posted 02 November 2009 - 05:36 PM

hello tom thanks for the reply,
i can not do this part of the step you asked to do...
Please set your system to show all files.
Click Start, open My Computer, select the Tools menu and click Folder Options.
Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
Uncheck: Hide file extensions for known file types
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.

also i tryed to run the gmer, it started fine then it said microsoft windows had to shut down the programme, a problem caused the programme to stop working..
i tryed to do it in safe mode and it done the same thing

#8 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:04:47 AM

Posted 03 November 2009 - 02:56 PM

Hi,

Please go to Start > system control > Folder Options

Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
Uncheck: Hide file extensions for known file types
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.






RootRepeal - Rootkit Detector


Download RootRepeal.zip and unzip it to your Desktop.

  • Double click RootRepeal.exe to start the program
  • Click on the Report tab at the bottom of the program window
  • Clickthe Scan button
  • In the Select Scan dialog, check:
    • Drivers
    • Files
    • Processes
    • SSDT
    • Stealth Objects
    • Hidden Services
  • Click the OK button
  • In the next dialog, select all drives showing
  • Click OK to start the scan

    The scan can take some time. DO NOT run any other programs while the scan is running

  • When the scan is complete, the Save Report button will become available
  • Click this and save the report to your Desktop as RootRepeal.txt
  • Go to File, then Exit to close the program

regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#9 rachy

rachy
  • Topic Starter

  • Members
  • 93 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:uk
  • Local time:04:47 AM

Posted 03 November 2009 - 04:41 PM

hello, i clicked the download rootrepeal and i got this message..
The bandwidth or page view limit for this site has been exceeded and the page cannot be viewed at this time. Once the site is below the limit, it will once again begin serving as normal.

#10 rachy

rachy
  • Topic Starter

  • Members
  • 93 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:uk
  • Local time:04:47 AM

Posted 04 November 2009 - 12:37 AM

ok iv managed to get the rootrepeal now, the 1st time i tryed to run it my pc blue screened,
just tryed again and it worked apart from i had messages that said....
could not read the boot sector try adjusting the disk access level in options dialog..... and....
could not read system registry please contact the author...
but here is what the scan gave me...

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/11/04 05:49
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP1
==================================================

Drivers
-------------------
Name: dump_diskdump.sys
Image Path: C:\Windows\System32\Drivers\dump_diskdump.sys
Address: 0x8AC6A000 Size: 40960 File Visible: No Signed: -
Status: -

Name: dump_nvstor32.sys
Image Path: C:\Windows\System32\Drivers\dump_nvstor32.sys
Address: 0x8AC74000 Size: 122880 File Visible: No Signed: -
Status: -

Name: mchInjDrv.sys
Image Path: C:\Windows\system32\Drivers\mchInjDrv.sys
Address: 0x81122000 Size: 2560 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x81139000 Size: 49152 File Visible: No Signed: -
Status: -

Hidden/Locked Files
-------------------
Path: Volume C:\
Status: MBR Rootkit Detected!

Path: Volume C:\, Sector 1
Status: Sector mismatch

Path: Volume C:\, Sector 2
Status: Sector mismatch

Path: Volume C:\, Sector 3
Status: Sector mismatch

Path: Volume C:\, Sector 4
Status: Sector mismatch

Path: Volume C:\, Sector 5
Status: Sector mismatch

Path: Volume C:\, Sector 6
Status: Sector mismatch

Path: Volume C:\, Sector 7
Status: Sector mismatch

Path: Volume C:\, Sector 8
Status: Sector mismatch

Path: Volume C:\, Sector 9
Status: Sector mismatch

Path: Volume C:\, Sector 10
Status: Sector mismatch

Path: Volume C:\, Sector 11
Status: Sector mismatch

Path: Volume C:\, Sector 12
Status: Sector mismatch

Path: Volume C:\, Sector 13
Status: Sector mismatch

Path: Volume C:\, Sector 14
Status: Sector mismatch

Path: Volume C:\, Sector 15
Status: Sector mismatch

Path: Volume C:\, Sector 16
Status: Sector mismatch

Path: Volume C:\, Sector 17
Status: Sector mismatch

Path: Volume C:\, Sector 18
Status: Sector mismatch

Path: Volume C:\, Sector 19
Status: Sector mismatch

Path: Volume C:\, Sector 20
Status: Sector mismatch

Path: Volume C:\, Sector 21
Status: Sector mismatch

Path: Volume C:\, Sector 22
Status: Sector mismatch

Path: Volume C:\, Sector 23
Status: Sector mismatch

Path: Volume C:\, Sector 24
Status: Sector mismatch

Path: Volume C:\, Sector 25
Status: Sector mismatch

Path: Volume C:\, Sector 26
Status: Sector mismatch

Path: Volume C:\, Sector 27
Status: Sector mismatch

Path: Volume C:\, Sector 28
Status: Sector mismatch

Path: Volume C:\, Sector 29
Status: Sector mismatch

Path: Volume C:\, Sector 30
Status: Sector mismatch

Path: Volume C:\, Sector 31
Status: Sector mismatch

Path: Volume C:\, Sector 32
Status: Sector mismatch

Path: Volume C:\, Sector 33
Status: Sector mismatch

Path: Volume C:\, Sector 34
Status: Sector mismatch

Path: Volume C:\, Sector 35
Status: Sector mismatch

Path: Volume C:\, Sector 36
Status: Sector mismatch

Path: Volume C:\, Sector 37
Status: Sector mismatch

Path: Volume C:\, Sector 38
Status: Sector mismatch

Path: Volume C:\, Sector 39
Status: Sector mismatch

Path: Volume C:\, Sector 40
Status: Sector mismatch

Path: Volume C:\, Sector 41
Status: Sector mismatch

Path: Volume C:\, Sector 42
Status: Sector mismatch

Path: Volume C:\, Sector 43
Status: Sector mismatch

Path: Volume C:\, Sector 44
Status: Sector mismatch

Path: Volume C:\, Sector 45
Status: Sector mismatch

Path: Volume C:\, Sector 46
Status: Sector mismatch

Path: Volume C:\, Sector 47
Status: Sector mismatch

Path: Volume C:\, Sector 48
Status: Sector mismatch

Path: Volume C:\, Sector 49
Status: Sector mismatch

Path: Volume C:\, Sector 50
Status: Sector mismatch

Path: Volume C:\, Sector 51
Status: Sector mismatch

Path: Volume C:\, Sector 52
Status: Sector mismatch

Path: Volume C:\, Sector 53
Status: Sector mismatch

Path: Volume C:\, Sector 54
Status: Sector mismatch

Path: Volume C:\, Sector 55
Status: Sector mismatch

Path: Volume C:\, Sector 56
Status: Sector mismatch

Path: Volume C:\, Sector 57
Status: Sector mismatch

Path: Volume C:\, Sector 58
Status: Sector mismatch

Path: Volume C:\, Sector 59
Status: Sector mismatch

Path: Volume C:\, Sector 60
Status: Sector mismatch

Path: Volume C:\, Sector 61
Status: Sector mismatch

Path: Volume C:\, Sector 62
Status: Sector mismatch

Processes
-------------------
Path: System
PID: 4 Status: Locked to the Windows API!

Path: C:\Windows\System32\audiodg.exe
PID: 1252 Status: Locked to the Windows API!

SSDT
-------------------
#: 021 Function Name: NtAlpcConnectPort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af49880

#: 054 Function Name: NtConnectPort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af494e0

#: 060 Function Name: NtCreateFile
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af46828

#: 064 Function Name: NtCreateKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af5cd9c

#: 071 Function Name: NtCreatePort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af49c36

#: 072 Function Name: NtCreateProcess
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af5aaf8

#: 073 Function Name: NtCreateProcessEx
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af5ad12

#: 075 Function Name: NtCreateSection
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af5e780

#: 115 Function Name: NtCreateWaitablePort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af49cde

#: 122 Function Name: NtDeleteFile
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af46d0a

#: 123 Function Name: NtDeleteKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af5d698

#: 126 Function Name: NtDeleteValueKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af5d414

#: 129 Function Name: NtDuplicateObject
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af5a4f8

#: 166 Function Name: NtLoadKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af5dbc6

#: 167 Function Name: NtLoadKey2
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af5dc3e

#: 168 Function Name: NtLoadKeyEx
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af5dd2e

#: 186 Function Name: NtOpenFile
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af46ba2

#: 194 Function Name: NtOpenProcess
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af5bf18

#: 267 Function Name: NtRenameKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af5e370

#: 268 Function Name: NtReplaceKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af5dda6

#: 276 Function Name: NtRequestWaitReplyPort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af4916a

#: 280 Function Name: NtRestoreKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af5e1b0

#: 286 Function Name: NtSecureConnectPort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af49680

#: 301 Function Name: NtSetInformationFile
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af46ef8

#: 324 Function Name: NtSetValueKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af5d11a

#: 332 Function Name: NtSystemDebugControl
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af5b486

#: 334 Function Name: NtTerminateProcess
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af5b362

#: 383 Function Name: NtCreateUserProcess
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8af5af30

==EOF==

Edited by rachy, 04 November 2009 - 12:54 AM.


#11 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:04:47 AM

Posted 04 November 2009 - 04:31 PM

Hi,


Please go here and have a look how you can disable your security software.

Download Combofix from any of the links below but rename it to before saving it to your desktop.

Link 1
Link 2



--------------------------------------------------------------------

Double click on the renamed Combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Posted Image


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image


Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.

This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


If you need help, see this link:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#12 rachy

rachy
  • Topic Starter

  • Members
  • 93 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:uk
  • Local time:04:47 AM

Posted 04 November 2009 - 07:43 PM

ComboFix 09-11-04.02 - rachel 05/11/2009 0:17.1.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.767.296 [GMT 0:00]
Running from: c:\users\rachel\Desktop\schrauber.exe
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: ZoneAlarm Anti-Spyware *enabled* (Outdated) {F245A209-1085-48B4-B927-35D56015EC60}
.

((((((((((((((((((((((((( Files Created from 2009-10-05 to 2009-11-05 )))))))))))))))))))))))))))))))
.

2009-11-05 00:32 . 2009-11-05 00:32 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-11-04 13:39 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll
2009-11-04 13:39 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-11-04 13:39 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll
2009-11-04 13:39 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-11-04 13:39 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll
2009-11-04 13:39 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-11-04 13:39 . 2009-08-07 01:44 87552 ----a-w- c:\windows\system32\wudriver.dll
2009-11-04 13:38 . 2009-08-06 19:23 171608 ----a-w- c:\windows\system32\wuwebv.dll
2009-11-04 13:38 . 2009-08-06 18:44 33792 ----a-w- c:\windows\system32\wuapp.exe
2009-10-27 18:16 . 2009-09-10 15:21 310784 ----a-w- c:\windows\system32\unregmp2.exe
2009-10-27 18:16 . 2009-09-10 20:45 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-10-27 18:16 . 2009-09-10 20:45 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-10-27 18:16 . 2009-09-10 15:24 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-10-27 00:43 . 2009-10-27 00:43 4096 d-----w- c:\windows\system32\EventProviders
2009-10-22 01:14 . 2009-10-22 01:15 4096 d-----w- c:\program files\Java
2009-10-22 01:12 . 2009-10-22 01:12 -------- d-----w- c:\program files\Common Files\Java
2009-10-20 19:48 . 2009-11-02 22:28 1356 ----a-w- c:\users\rachel\AppData\Local\d3d9caps.dat
2009-10-20 19:13 . 2009-10-20 19:13 -------- d-----w- c:\windows\system32\Adobe
2009-10-19 13:34 . 2009-10-19 13:34 4096 d-----w- c:\program files\VirtualDJ
2009-10-17 00:54 . 2009-10-17 00:55 4096 d-----w- c:\program files\Windows Live Safety Center
2009-10-17 00:22 . 2008-05-02 07:26 1414440 ----a-w- c:\windows\system32\ShellManager310E2D762.dll
2009-10-17 00:18 . 2009-10-17 00:18 -------- d-----w- c:\users\rachel\AppData\Roaming\Nero
2009-10-16 18:39 . 2009-10-16 18:39 4096 d-----w- c:\program files\Common Files\PX Storage Engine
2009-10-16 18:39 . 2009-10-31 01:28 4096 d-----w- c:\program files\Winamp
2009-10-15 17:30 . 2009-08-05 14:22 3597896 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-10-15 17:30 . 2009-08-05 14:22 3546184 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-10-15 17:29 . 2009-08-31 13:55 428544 ----a-w- c:\windows\system32\EncDec.dll
2009-10-15 17:29 . 2009-08-26 17:48 763904 ----a-w- c:\windows\system32\MSDTVVDEC.DLL
2009-10-15 17:29 . 2009-08-26 17:50 711168 ----a-w- c:\windows\system32\sbe.dll
2009-10-15 17:29 . 2009-08-26 17:50 604672 ----a-w- c:\windows\system32\CPFilters.dll
2009-10-15 17:28 . 2009-09-14 09:44 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-10-15 17:28 . 2009-09-04 12:24 61440 ----a-w- c:\windows\system32\msasn1.dll
2009-10-15 17:28 . 2009-04-02 12:37 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2009-10-15 17:20 . 2009-10-17 01:04 -------- d-----w- c:\users\rachel\AppData\Roaming\Godlike
2009-10-15 17:20 . 2009-10-15 17:20 -------- d-----w- c:\program files\Godlike Developers
2009-10-14 15:41 . 2009-10-16 02:26 4096 d-----w- c:\program files\YouTube Downloader
2009-10-14 03:04 . 2009-10-14 03:10 -------- d-----w- c:\users\rachel\AppData\Roaming\TeamViewer
2009-10-14 03:03 . 2009-10-14 03:03 -------- d-----w- c:\program files\TeamViewer
2009-10-14 03:02 . 2009-10-14 03:02 -------- d-----w- c:\users\rachel\temp
2009-10-13 23:27 . 2009-10-13 23:29 -------- d-----w- c:\users\rachel\AppData\Roaming\ManyCam
2009-10-13 23:27 . 2009-10-13 23:29 12288 d-----w- c:\program files\ManyCam 2.4
2009-10-13 19:56 . 2008-07-10 13:56 107864 ----a-w- c:\windows\system32\tsccvid.dll
2009-10-13 19:56 . 2009-10-13 19:56 -------- d-----w- c:\windows\system32\QuickTime
2009-10-13 19:56 . 2009-10-13 19:56 -------- d-----w- c:\programdata\TechSmith
2009-10-13 19:55 . 2009-10-13 19:55 -------- d-----w- c:\program files\Common Files\TechSmith Shared
2009-10-13 19:55 . 2009-10-13 19:55 -------- d-----w- c:\program files\TechSmith
2009-10-12 20:37 . 2009-10-18 23:02 -------- d-----w- c:\users\rachel\AppData\Roaming\skypePM
2009-10-12 20:36 . 2009-10-19 01:43 4096 d-----w- c:\users\rachel\AppData\Roaming\Skype
2009-10-12 20:35 . 2009-10-12 20:35 -------- d-----w- c:\program files\Common Files\Skype
2009-10-12 20:35 . 2009-10-12 20:35 -------- d-----r- c:\program files\Skype
2009-10-12 20:04 . 2009-10-12 20:04 10134 ----a-r- c:\users\rachel\AppData\Roaming\Microsoft\Installer\{BEF726DD-4037-4214-8C6A-E625C02D2870}\ARPPRODUCTICON.exe
2009-10-12 20:03 . 2009-10-12 20:03 10134 ----a-r- c:\users\rachel\AppData\Roaming\Microsoft\Installer\{35725FBC-A136-4A46-9F29-091759D9BB93}\ARPPRODUCTICON.exe
2009-10-12 20:03 . 2009-10-12 20:03 10134 ----a-r- c:\users\rachel\AppData\Roaming\Microsoft\Installer\{EA516024-D84D-41F1-814F-83175A6188F2}\ARPPRODUCTICON.exe
2009-10-12 20:02 . 2009-10-12 20:02 -------- d-----w- c:\program files\Common Files\Labtec
2009-10-12 20:00 . 2009-10-12 20:00 -------- d-----w- c:\program files\Common Files\LogiShrd
2009-10-12 19:57 . 2009-10-12 20:00 -------- d-----w- c:\program files\Labtec
2009-10-12 14:26 . 2009-10-12 14:26 1961720 ----a-w- c:\users\rachel\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-10-12 14:11 . 2009-11-04 20:20 -------- d-----w- c:\users\rachel\Tracing
2009-10-12 14:08 . 2009-10-12 14:08 8192 d-----w- c:\program files\Paltalk Messenger
2009-10-12 13:43 . 2009-10-12 13:43 -------- d-----w- c:\programdata\Office Genuine Advantage
2009-10-12 12:42 . 2009-10-12 12:42 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2009-10-12 12:22 . 2009-10-12 12:22 -------- d-----w- c:\programdata\WindowsSearch
2009-10-12 05:03 . 2009-06-22 10:22 2048 ----a-w- c:\windows\system32\tzres.dll
2009-10-12 04:26 . 2009-10-12 19:54 -------- d-----w- c:\users\rachel\AppData\Roaming\Paltalk
2009-10-12 04:25 . 2009-10-12 04:25 -------- d-----w- c:\program files\Microsoft
2009-10-12 04:25 . 2009-10-12 04:25 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-10-12 04:24 . 2009-10-12 04:25 -------- d-----w- c:\program files\Windows Live
2009-10-12 04:20 . 2009-10-12 04:20 -------- d-----w- c:\program files\Common Files\Windows Live
2009-10-12 04:13 . 2008-06-20 01:14 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-10-12 04:13 . 2008-06-20 01:14 97800 ----a-w- c:\windows\system32\infocardapi.dll
2009-10-12 04:13 . 2008-06-20 01:14 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2009-10-12 04:13 . 2008-06-20 01:14 11264 ----a-w- c:\windows\system32\icardres.dll
2009-10-12 04:13 . 2008-06-20 01:14 622080 ----a-w- c:\windows\system32\icardagt.exe
2009-10-12 04:13 . 2008-06-20 01:14 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2009-10-12 04:13 . 2008-06-20 01:14 326160 ----a-w- c:\windows\system32\PresentationHost.exe
2009-10-12 04:06 . 2009-10-12 04:06 -------- d-----w- c:\users\rachel\AppData\Roaming\PC Tools
2009-10-12 04:05 . 2008-07-27 18:03 96760 ----a-w- c:\windows\system32\dfshim.dll
2009-10-12 04:05 . 2008-07-27 18:03 282112 ----a-w- c:\windows\system32\mscoree.dll
2009-10-12 03:53 . 2009-08-14 17:01 900168 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-10-12 03:51 . 2009-03-03 04:40 499200 ----a-w- c:\windows\system32\wbem\WmiPrvSD.dll
2009-10-12 03:50 . 2009-06-15 15:24 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-10-12 03:50 . 2009-06-15 15:20 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-10-12 03:50 . 2009-06-15 15:20 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-10-12 03:50 . 2009-06-15 12:52 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-10-12 03:50 . 2009-06-10 12:11 2868224 ----a-w- c:\windows\system32\mf.dll
2009-10-12 03:50 . 2008-10-21 05:25 296960 ----a-w- c:\windows\system32\gdi32.dll
2009-10-12 03:50 . 2008-10-22 03:57 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-10-12 03:50 . 2008-06-19 03:31 361984 ----a-w- c:\windows\system32\IPSECSVC.DLL
2009-10-12 03:49 . 2009-06-10 12:07 91136 ----a-w- c:\windows\system32\avifil32.dll
2009-10-12 03:49 . 2008-02-23 04:38 170496 ----a-w- c:\windows\system32\tcpipcfg.dll
2009-10-12 03:49 . 2008-02-23 02:41 22528 ----a-w- c:\windows\system32\netiougc.exe
2009-10-12 03:49 . 2009-07-14 13:00 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-10-12 03:49 . 2009-07-17 14:35 71680 ----a-w- c:\windows\system32\atl.dll
2009-10-12 03:49 . 2008-12-06 04:42 376832 ----a-w- c:\windows\system32\winhttp.dll
2009-10-12 03:47 . 2009-02-15 23:10 69000 ----a-w- c:\windows\system32\zlcomm.dll
2009-10-12 03:47 . 2009-02-15 23:10 103816 ----a-w- c:\windows\system32\zlcommdb.dll
2009-10-12 03:47 . 2009-02-15 23:10 1221512 ----a-w- c:\windows\system32\zpeng25.dll
2009-10-12 03:47 . 2009-10-12 03:47 -------- d-----w- c:\program files\Zone Labs
2009-10-12 03:46 . 2009-06-15 15:24 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-10-12 03:46 . 2009-06-15 15:24 270848 ----a-w- c:\windows\system32\schannel.dll
2009-10-12 03:46 . 2009-06-15 15:21 499712 ----a-w- c:\windows\system32\kerberos.dll
2009-10-12 03:44 . 2008-09-18 04:56 147456 ----a-w- c:\windows\system32\Faultrep.dll
2009-10-12 03:44 . 2008-09-18 04:56 125952 ----a-w- c:\windows\system32\wersvc.dll
2009-10-12 03:44 . 2009-10-12 03:44 -------- d-----w- c:\programdata\CheckPoint
2009-10-12 03:44 . 2009-04-23 12:43 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-10-12 03:44 . 2008-04-18 05:48 269312 ----a-w- c:\windows\system32\es.dll
2009-10-12 03:44 . 2008-10-29 06:29 2927104 ----a-w- c:\windows\explorer.exe
2009-10-12 03:44 . 2008-06-26 03:29 303616 ----a-w- c:\windows\system32\wmpeffects.dll
2009-10-12 03:44 . 2008-08-12 03:39 443392 ----a-w- c:\windows\system32\win32spl.dll
2009-10-12 03:44 . 2009-11-04 20:38 12288 d-----w- c:\windows\Internet Logs
2009-10-12 03:44 . 2008-10-21 05:25 1645568 ----a-w- c:\windows\system32\connect.dll
2009-10-12 03:43 . 2009-08-28 12:39 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-10-12 03:43 . 2009-08-28 10:15 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-10-12 03:40 . 2008-08-28 03:40 425472 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-10-12 03:40 . 2008-08-28 03:40 712704 ----a-w- c:\windows\system32\WindowsCodecs.dll
2009-10-12 03:40 . 2008-08-28 03:40 347136 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-10-12 03:40 . 2008-06-26 03:29 565248 ----a-w- c:\windows\system32\emdmgmt.dll
2009-10-12 03:40 . 2008-08-02 03:26 36864 ----a-w- c:\windows\system32\cdd.dll
2009-10-12 03:40 . 2008-08-02 01:01 625152 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-10-12 03:40 . 2008-06-26 03:29 45056 ----a-w- c:\windows\system32\dataclen.dll
2009-10-12 03:35 . 2009-10-12 03:36 -------- d-----w- c:\users\rachel\AppData\Local\Google
2009-10-12 03:35 . 2009-10-12 03:35 -------- d-----w- c:\users\rachel\AppData\Roaming\Symantec
2009-10-12 03:35 . 2009-10-20 22:58 70944 ----a-w- c:\users\rachel\AppData\Local\GDIPFONTCACHEV1.DAT
2009-10-12 03:35 . 2009-10-12 03:45 -------- d-----w- c:\users\rachel\AppData\Local\Packard Bell

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-04 20:18 . 2009-10-12 03:45 350192 ---ha-w- c:\windows\system32\drivers\vsconfig.xml
2009-11-02 22:27 . 2009-10-12 04:03 12288 d-----w- c:\program files\PC Tools AntiVirus
2009-11-01 03:37 . 2009-11-01 16:33 1463808 ----a-w- c:\windows\Internet Logs\xDBC1D4.tmp
2009-10-31 17:54 . 2009-10-13 20:03 3472286 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
2009-10-31 17:53 . 2009-10-31 17:55 1462784 ----a-w- c:\windows\Internet Logs\xDB879D.tmp
2009-10-31 01:00 . 2008-08-22 10:09 8192 d-----w- c:\programdata\Microsoft Help
2009-10-17 00:27 . 2008-08-22 09:58 4096 d-----w- c:\program files\Common Files\Nero
2009-10-17 00:26 . 2008-08-22 09:58 -------- d-----w- c:\programdata\Nero
2009-10-16 02:31 . 2006-11-02 11:18 4096 d-----w- c:\program files\Windows Mail
2009-10-16 02:26 . 2008-08-22 09:52 28672 d-----w- c:\program files\Microsoft Works
2009-10-15 06:34 . 2008-08-22 09:43 4096 d--h--w- c:\program files\InstallShield Installation Information
2009-10-14 23:01 . 2008-08-22 09:54 4096 d-----w- c:\program files\Google
2009-10-12 20:37 . 2009-10-12 20:37 56 ---ha-w- c:\programdata\ezsidmv.dat
2009-10-12 20:35 . 2008-08-22 10:19 4096 d-----w- c:\programdata\Skype
2009-10-12 04:05 . 2009-10-12 04:03 -------- d-----w- c:\programdata\PC Tools
2009-10-12 04:04 . 2009-10-12 04:04 -------- d-----w- c:\program files\Common Files\PC Tools
2009-10-12 03:58 . 2008-08-22 10:02 12288 d-----w- c:\program files\Common Files\Symantec Shared
2009-10-12 03:56 . 2008-08-22 10:02 4096 d-----w- c:\programdata\Symantec
2009-10-01 09:29 . 2009-10-12 04:04 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-09-10 17:30 . 2009-10-15 17:32 213504 ----a-w- c:\windows\system32\msv1_0.dll
2009-08-27 13:32 . 2009-10-15 17:32 833024 ----a-w- c:\windows\system32\wininet.dll
2009-08-27 13:29 . 2009-10-15 17:32 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-27 10:58 . 2009-10-15 17:32 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-08-24 13:05 . 2009-10-12 04:04 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-08-19 10:01 . 2009-10-12 04:04 86888 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-08-17 22:33 . 2009-08-17 22:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-14 17:01 . 2009-10-12 03:52 220232 ----a-w- c:\windows\system32\drivers\netio.sys
2009-08-14 17:01 . 2009-10-12 03:52 98376 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2009-08-14 16:29 . 2009-10-12 03:52 104960 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-14 16:29 . 2009-10-12 03:52 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 16:23 . 2009-10-12 03:52 438272 ----a-w- c:\windows\system32\IKEEXT.DLL
2009-08-14 16:22 . 2009-10-12 03:52 595456 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2009-08-14 16:21 . 2009-10-12 03:52 328704 ----a-w- c:\windows\system32\BFE.DLL
2009-08-14 14:16 . 2009-10-12 03:52 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:16 . 2009-10-12 03:52 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 14:16 . 2009-10-12 03:52 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 14:16 . 2009-10-12 03:52 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 14:16 . 2009-10-12 03:52 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 14:16 . 2009-10-12 03:52 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:16 . 2009-10-12 03:52 10240 ----a-w- c:\windows\system32\finger.exe
2008-08-22 10:20 . 2008-08-22 10:20 123392 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2007-11-28 19:31 . 2008-08-22 09:50 67696 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2007-11-28 19:31 . 2008-08-22 09:50 54376 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2007-11-28 19:31 . 2008-08-22 09:50 34952 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2007-11-28 19:31 . 2008-08-22 09:50 46720 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2007-11-28 19:31 . 2008-08-22 09:50 172144 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2008-08-22 18:26 . 2008-08-22 18:14 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"SmpcSys"="c:\program files\Packard Bell\SetUpMyPC\SmpSys.exe" [2008-02-04 1038136]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"WindowsWelcomeCenter"="oobefldr.dll" - c:\windows\System32\oobefldr.dll [2008-01-21 2153472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-12-20 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-20 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-20 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-08-22 24064]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-15 981384]
"PCTAVApp"="c:\program files\PC Tools AntiVirus\PCTAV.exe" [2009-04-16 1505168]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-03-06 488984]
"toolbar_eula_launcher"="c:\program files\Packard Bell\GOOGLE_EULA\EULALauncher.exe" [2007-02-20 28672]
"LogitechQuickCamRibbon"="c:\program files\Labtec\WebCam10\WebCam10.exe" [2007-03-06 1060376]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-05-07 6139904]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
PalTalk.lnk - c:\program files\Paltalk Messenger\paltalk.exe [2009-1-28 10950144]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~4\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCTAVSvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

R0 PCTCore;PCTools KDS;c:\windows\System32\drivers\PCTCore.sys [12/10/2009 04:04 206256]
R2 TeamViewer4;TeamViewer 4;c:\program files\TeamViewer\Version4\TeamViewer_Service.exe [18/05/2009 13:13 185640]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\System32\drivers\ManyCam.sys [14/01/2008 10:06 21632]
S3 GoogleDesktopManager-071508-051939;Google Desktop Manager 5.7.807.15159;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [22/08/2008 10:20 24064]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - MBR
*NewlyCreated* - PROCEXP113
*Deregistered* - mbr
*Deregistered* - mchInjDrv
*Deregistered* - PROCEXP113
.
Contents of the 'Scheduled Tasks' folder

2009-11-05 c:\windows\Tasks\Recovery DVD Creator-rachel.job
- c:\program files\Packard Bell\SetupMyPc\MCDCheck.exe [2008-08-22 10:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://go.packardbell.com/?id=9067
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.allow_platform_file_picker", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.accept.default", "application/x-shockwave-flash,text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.remoteLookups", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.updateURL", "http://sb.google.com/safebrowsing/update?client={moz:client}&appver={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.lookupURL", "http://sb.google.com/safebrowsing/lookup?sourceid=firefox-antiphish&features=TrustRank&client={moz:client}&appver={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.reportURL", "http://sb.google.com/safebrowsing/report?");
.
- - - - ORPHANS REMOVED - - - -

AddRemove-PalTalk8.2 - c:\windows\PaltalkScene\uninstall.exe
AddRemove-{18AE8ACB-0419-45F6-9CF6-155E128A4BCE}_is1 - c:\program files\Godlike Developers\WinTools.net



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-05 00:35
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-11-05 0:41
ComboFix-quarantined-files.txt 2009-11-05 00:41

Pre-Run: 241,358,647,296 bytes free
Post-Run: 241,377,001,472 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=1 Sets=1,2,3,4,5,8

#13 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:04:47 AM

Posted 05 November 2009 - 01:01 PM

Hi,


Step 1

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

MBR::

Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.







Step 2

I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Check Posted Image
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push Posted Image
  • Push Posted Image, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the Posted Image button.
  • Push Posted Image
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#14 rachy

rachy
  • Topic Starter

  • Members
  • 93 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:uk
  • Local time:04:47 AM

Posted 05 November 2009 - 04:43 PM

heya tom....i done both scans... when i was doing the combo fix, it said that i had zonealarm spyware installed, i shut down the zone alarm but i couldnt find how to stop the spyware thing, i dont recall installin a spyware though, also when combofix was scanning i had a message that said...PEV.CFXXE stopped working correctly and windows had to shut it down...also i done the ESET scan and it came up with no results, it didnt give me a log... also is it ok to delete some of these logs iv saved?
but heres my log for the combofix.....

ComboFix 09-11-04.02 - rachel 05/11/2009 18:42.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.767.195 [GMT 0:00]
Running from: c:\users\rachel\Desktop\schrauber.exe
Command switches used :: c:\users\rachel\Desktop\CFScript.txt
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: ZoneAlarm Anti-Spyware *enabled* (Outdated) {F245A209-1085-48B4-B927-35D56015EC60}
.

((((((((((((((((((((((((( Files Created from 2009-10-05 to 2009-11-05 )))))))))))))))))))))))))))))))
.

2009-11-05 18:57 . 2009-11-05 18:57 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-11-05 18:57 . 2009-11-05 18:57 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-11-05 00:14 . 2009-11-05 00:41 -------- d-----w- C:\schrauber
2009-11-04 13:39 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll
2009-11-04 13:39 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-11-04 13:39 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll
2009-11-04 13:39 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-11-04 13:39 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll
2009-11-04 13:39 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-11-04 13:39 . 2009-08-07 01:44 87552 ----a-w- c:\windows\system32\wudriver.dll
2009-11-04 13:38 . 2009-08-06 19:23 171608 ----a-w- c:\windows\system32\wuwebv.dll
2009-11-04 13:38 . 2009-08-06 18:44 33792 ----a-w- c:\windows\system32\wuapp.exe
2009-10-27 18:16 . 2009-09-10 15:21 310784 ----a-w- c:\windows\system32\unregmp2.exe
2009-10-27 18:16 . 2009-09-10 20:45 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-10-27 18:16 . 2009-09-10 20:45 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-10-27 18:16 . 2009-09-10 15:24 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-10-27 00:43 . 2009-10-27 00:43 4096 d-----w- c:\windows\system32\EventProviders
2009-10-22 01:14 . 2009-10-22 01:15 -------- d-----w- c:\program files\Java
2009-10-22 01:12 . 2009-10-22 01:12 -------- d-----w- c:\program files\Common Files\Java
2009-10-20 19:48 . 2009-11-02 22:28 1356 ----a-w- c:\users\rachel\AppData\Local\d3d9caps.dat
2009-10-20 19:13 . 2009-10-20 19:13 -------- d-----w- c:\windows\system32\Adobe
2009-10-19 13:34 . 2009-10-19 13:34 4096 d-----w- c:\program files\VirtualDJ
2009-10-17 00:54 . 2009-10-17 00:55 -------- d-----w- c:\program files\Windows Live Safety Center
2009-10-17 00:22 . 2008-05-02 07:26 1414440 ----a-w- c:\windows\system32\ShellManager310E2D762.dll
2009-10-17 00:18 . 2009-10-17 00:18 -------- d-----w- c:\users\rachel\AppData\Roaming\Nero
2009-10-16 18:39 . 2009-10-16 18:39 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2009-10-16 18:39 . 2009-10-31 01:28 -------- d-----w- c:\program files\Winamp
2009-10-15 17:30 . 2009-08-05 14:22 3597896 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-10-15 17:30 . 2009-08-05 14:22 3546184 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-10-15 17:29 . 2009-08-31 13:55 428544 ----a-w- c:\windows\system32\EncDec.dll
2009-10-15 17:29 . 2009-08-26 17:48 763904 ----a-w- c:\windows\system32\MSDTVVDEC.DLL
2009-10-15 17:29 . 2009-08-26 17:50 711168 ----a-w- c:\windows\system32\sbe.dll
2009-10-15 17:29 . 2009-08-26 17:50 604672 ----a-w- c:\windows\system32\CPFilters.dll
2009-10-15 17:28 . 2009-09-14 09:44 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-10-15 17:28 . 2009-09-04 12:24 61440 ----a-w- c:\windows\system32\msasn1.dll
2009-10-15 17:28 . 2009-04-02 12:37 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL
2009-10-15 17:20 . 2009-10-17 01:04 -------- d-----w- c:\users\rachel\AppData\Roaming\Godlike
2009-10-15 17:20 . 2009-10-15 17:20 -------- d-----w- c:\program files\Godlike Developers
2009-10-14 15:41 . 2009-10-16 02:26 4096 d-----w- c:\program files\YouTube Downloader
2009-10-14 03:04 . 2009-10-14 03:10 -------- d-----w- c:\users\rachel\AppData\Roaming\TeamViewer
2009-10-14 03:03 . 2009-10-14 03:03 -------- d-----w- c:\program files\TeamViewer
2009-10-14 03:02 . 2009-10-14 03:02 -------- d-----w- c:\users\rachel\temp
2009-10-13 23:27 . 2009-10-13 23:29 -------- d-----w- c:\users\rachel\AppData\Roaming\ManyCam
2009-10-13 23:27 . 2009-10-13 23:29 12288 d-----w- c:\program files\ManyCam 2.4
2009-10-13 19:56 . 2008-07-10 13:56 107864 ----a-w- c:\windows\system32\tsccvid.dll
2009-10-13 19:56 . 2009-10-13 19:56 -------- d-----w- c:\windows\system32\QuickTime
2009-10-13 19:56 . 2009-10-13 19:56 -------- d-----w- c:\programdata\TechSmith
2009-10-13 19:55 . 2009-10-13 19:55 -------- d-----w- c:\program files\Common Files\TechSmith Shared
2009-10-13 19:55 . 2009-10-13 19:55 -------- d-----w- c:\program files\TechSmith
2009-10-12 20:37 . 2009-10-18 23:02 -------- d-----w- c:\users\rachel\AppData\Roaming\skypePM
2009-10-12 20:36 . 2009-10-19 01:43 -------- d-----w- c:\users\rachel\AppData\Roaming\Skype
2009-10-12 20:35 . 2009-10-12 20:35 -------- d-----w- c:\program files\Common Files\Skype
2009-10-12 20:35 . 2009-10-12 20:35 -------- d-----r- c:\program files\Skype
2009-10-12 20:04 . 2009-10-12 20:04 10134 ----a-r- c:\users\rachel\AppData\Roaming\Microsoft\Installer\{BEF726DD-4037-4214-8C6A-E625C02D2870}\ARPPRODUCTICON.exe
2009-10-12 20:03 . 2009-10-12 20:03 10134 ----a-r- c:\users\rachel\AppData\Roaming\Microsoft\Installer\{35725FBC-A136-4A46-9F29-091759D9BB93}\ARPPRODUCTICON.exe
2009-10-12 20:03 . 2009-10-12 20:03 10134 ----a-r- c:\users\rachel\AppData\Roaming\Microsoft\Installer\{EA516024-D84D-41F1-814F-83175A6188F2}\ARPPRODUCTICON.exe
2009-10-12 20:02 . 2009-10-12 20:02 -------- d-----w- c:\program files\Common Files\Labtec
2009-10-12 20:00 . 2009-10-12 20:00 -------- d-----w- c:\program files\Common Files\LogiShrd
2009-10-12 19:57 . 2009-10-12 20:00 -------- d-----w- c:\program files\Labtec
2009-10-12 14:26 . 2009-10-12 14:26 1961720 ----a-w- c:\users\rachel\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-10-12 14:11 . 2009-11-05 18:28 -------- d-----w- c:\users\rachel\Tracing
2009-10-12 14:08 . 2009-10-12 14:08 8192 d-----w- c:\program files\Paltalk Messenger
2009-10-12 13:43 . 2009-10-12 13:43 -------- d-----w- c:\programdata\Office Genuine Advantage
2009-10-12 12:42 . 2009-10-12 12:42 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2009-10-12 12:22 . 2009-10-12 12:22 -------- d-----w- c:\programdata\WindowsSearch
2009-10-12 05:03 . 2009-06-22 10:22 2048 ----a-w- c:\windows\system32\tzres.dll
2009-10-12 04:26 . 2009-10-12 19:54 -------- d-----w- c:\users\rachel\AppData\Roaming\Paltalk
2009-10-12 04:25 . 2009-10-12 04:25 -------- d-----w- c:\program files\Microsoft
2009-10-12 04:25 . 2009-10-12 04:25 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-10-12 04:24 . 2009-10-12 04:25 -------- d-----w- c:\program files\Windows Live
2009-10-12 04:20 . 2009-10-12 04:20 -------- d-----w- c:\program files\Common Files\Windows Live
2009-10-12 04:13 . 2008-06-20 01:14 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-10-12 04:13 . 2008-06-20 01:14 97800 ----a-w- c:\windows\system32\infocardapi.dll
2009-10-12 04:13 . 2008-06-20 01:14 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2009-10-12 04:13 . 2008-06-20 01:14 11264 ----a-w- c:\windows\system32\icardres.dll
2009-10-12 04:13 . 2008-06-20 01:14 622080 ----a-w- c:\windows\system32\icardagt.exe
2009-10-12 04:13 . 2008-06-20 01:14 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2009-10-12 04:13 . 2008-06-20 01:14 326160 ----a-w- c:\windows\system32\PresentationHost.exe
2009-10-12 04:06 . 2009-10-12 04:06 -------- d-----w- c:\users\rachel\AppData\Roaming\PC Tools
2009-10-12 04:05 . 2008-07-27 18:03 96760 ----a-w- c:\windows\system32\dfshim.dll
2009-10-12 04:05 . 2008-07-27 18:03 282112 ----a-w- c:\windows\system32\mscoree.dll
2009-10-12 03:53 . 2009-08-14 17:01 900168 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-10-12 03:51 . 2009-03-03 04:40 499200 ----a-w- c:\windows\system32\wbem\WmiPrvSD.dll
2009-10-12 03:50 . 2009-06-15 15:24 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-10-12 03:50 . 2009-06-15 15:20 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-10-12 03:50 . 2009-06-15 15:20 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-10-12 03:50 . 2009-06-15 12:52 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-10-12 03:50 . 2009-06-10 12:11 2868224 ----a-w- c:\windows\system32\mf.dll
2009-10-12 03:50 . 2008-10-21 05:25 296960 ----a-w- c:\windows\system32\gdi32.dll
2009-10-12 03:50 . 2008-10-22 03:57 241152 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-10-12 03:50 . 2008-06-19 03:31 361984 ----a-w- c:\windows\system32\IPSECSVC.DLL
2009-10-12 03:49 . 2009-06-10 12:07 91136 ----a-w- c:\windows\system32\avifil32.dll
2009-10-12 03:49 . 2008-02-23 04:38 170496 ----a-w- c:\windows\system32\tcpipcfg.dll
2009-10-12 03:49 . 2008-02-23 02:41 22528 ----a-w- c:\windows\system32\netiougc.exe
2009-10-12 03:49 . 2009-07-14 13:00 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-10-12 03:49 . 2009-07-17 14:35 71680 ----a-w- c:\windows\system32\atl.dll
2009-10-12 03:49 . 2008-12-06 04:42 376832 ----a-w- c:\windows\system32\winhttp.dll
2009-10-12 03:47 . 2009-02-15 23:10 69000 ----a-w- c:\windows\system32\zlcomm.dll
2009-10-12 03:47 . 2009-02-15 23:10 103816 ----a-w- c:\windows\system32\zlcommdb.dll
2009-10-12 03:47 . 2009-02-15 23:10 1221512 ----a-w- c:\windows\system32\zpeng25.dll
2009-10-12 03:47 . 2009-10-12 03:47 -------- d-----w- c:\program files\Zone Labs
2009-10-12 03:46 . 2009-06-15 15:24 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-10-12 03:46 . 2009-06-15 15:24 270848 ----a-w- c:\windows\system32\schannel.dll
2009-10-12 03:46 . 2009-06-15 15:21 499712 ----a-w- c:\windows\system32\kerberos.dll
2009-10-12 03:44 . 2008-09-18 04:56 147456 ----a-w- c:\windows\system32\Faultrep.dll
2009-10-12 03:44 . 2008-09-18 04:56 125952 ----a-w- c:\windows\system32\wersvc.dll
2009-10-12 03:44 . 2009-10-12 03:44 -------- d-----w- c:\programdata\CheckPoint
2009-10-12 03:44 . 2009-04-23 12:43 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-10-12 03:44 . 2008-04-18 05:48 269312 ----a-w- c:\windows\system32\es.dll
2009-10-12 03:44 . 2008-10-29 06:29 2927104 ----a-w- c:\windows\explorer.exe
2009-10-12 03:44 . 2008-06-26 03:29 303616 ----a-w- c:\windows\system32\wmpeffects.dll
2009-10-12 03:44 . 2008-08-12 03:39 443392 ----a-w- c:\windows\system32\win32spl.dll
2009-10-12 03:44 . 2009-11-05 18:37 12288 d-----w- c:\windows\Internet Logs
2009-10-12 03:44 . 2008-10-21 05:25 1645568 ----a-w- c:\windows\system32\connect.dll
2009-10-12 03:43 . 2009-08-28 12:39 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-10-12 03:43 . 2009-08-28 10:15 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-10-12 03:40 . 2008-08-28 03:40 425472 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-10-12 03:40 . 2008-08-28 03:40 712704 ----a-w- c:\windows\system32\WindowsCodecs.dll
2009-10-12 03:40 . 2008-08-28 03:40 347136 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-10-12 03:40 . 2008-06-26 03:29 565248 ----a-w- c:\windows\system32\emdmgmt.dll
2009-10-12 03:40 . 2008-08-02 03:26 36864 ----a-w- c:\windows\system32\cdd.dll
2009-10-12 03:40 . 2008-08-02 01:01 625152 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-10-12 03:40 . 2008-06-26 03:29 45056 ----a-w- c:\windows\system32\dataclen.dll
2009-10-12 03:35 . 2009-10-12 03:36 -------- d-----w- c:\users\rachel\AppData\Local\Google
2009-10-12 03:35 . 2009-10-12 03:35 -------- d-----w- c:\users\rachel\AppData\Roaming\Symantec

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-05 18:58 . 2009-10-12 03:45 350192 ---ha-w- c:\windows\system32\drivers\vsconfig.xml
2009-11-02 22:27 . 2009-10-12 04:03 12288 d-----w- c:\program files\PC Tools AntiVirus
2009-11-01 03:37 . 2009-11-01 16:33 1463808 ----a-w- c:\windows\Internet Logs\xDBC1D4.tmp
2009-10-31 17:54 . 2009-10-13 20:03 3472286 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
2009-10-31 17:53 . 2009-10-31 17:55 1462784 ----a-w- c:\windows\Internet Logs\xDB879D.tmp
2009-10-31 01:00 . 2008-08-22 10:09 8192 d-----w- c:\programdata\Microsoft Help
2009-10-17 00:27 . 2008-08-22 09:58 4096 d-----w- c:\program files\Common Files\Nero
2009-10-17 00:26 . 2008-08-22 09:58 -------- d-----w- c:\programdata\Nero
2009-10-16 02:31 . 2006-11-02 11:18 4096 d-----w- c:\program files\Windows Mail
2009-10-16 02:26 . 2008-08-22 09:52 28672 d-----w- c:\program files\Microsoft Works
2009-10-15 06:34 . 2008-08-22 09:43 4096 d--h--w- c:\program files\InstallShield Installation Information
2009-10-14 23:01 . 2008-08-22 09:54 4096 d-----w- c:\program files\Google
2009-10-12 20:37 . 2009-10-12 20:37 56 ---ha-w- c:\programdata\ezsidmv.dat
2009-10-12 20:35 . 2008-08-22 10:19 4096 d-----w- c:\programdata\Skype
2009-10-12 04:05 . 2009-10-12 04:03 -------- d-----w- c:\programdata\PC Tools
2009-10-12 04:04 . 2009-10-12 04:04 -------- d-----w- c:\program files\Common Files\PC Tools
2009-10-12 03:58 . 2008-08-22 10:02 12288 d-----w- c:\program files\Common Files\Symantec Shared
2009-10-12 03:56 . 2008-08-22 10:02 4096 d-----w- c:\programdata\Symantec
2009-10-01 09:29 . 2009-10-12 04:04 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-09-10 17:30 . 2009-10-15 17:32 213504 ----a-w- c:\windows\system32\msv1_0.dll
2009-08-27 13:32 . 2009-10-15 17:32 833024 ----a-w- c:\windows\system32\wininet.dll
2009-08-27 13:29 . 2009-10-15 17:32 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-27 10:58 . 2009-10-15 17:32 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-08-24 13:05 . 2009-10-12 04:04 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-08-19 10:01 . 2009-10-12 04:04 86888 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-08-17 22:33 . 2009-08-17 22:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-14 17:01 . 2009-10-12 03:52 220232 ----a-w- c:\windows\system32\drivers\netio.sys
2009-08-14 17:01 . 2009-10-12 03:52 98376 ----a-w- c:\windows\system32\drivers\FWPKCLNT.SYS
2009-08-14 16:29 . 2009-10-12 03:52 104960 ----a-w- c:\windows\system32\netiohlp.dll
2009-08-14 16:29 . 2009-10-12 03:52 17920 ----a-w- c:\windows\system32\netevent.dll
2009-08-14 16:23 . 2009-10-12 03:52 438272 ----a-w- c:\windows\system32\IKEEXT.DLL
2009-08-14 16:22 . 2009-10-12 03:52 595456 ----a-w- c:\windows\system32\FWPUCLNT.DLL
2009-08-14 16:21 . 2009-10-12 03:52 328704 ----a-w- c:\windows\system32\BFE.DLL
2009-08-14 14:16 . 2009-10-12 03:52 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
2009-08-14 14:16 . 2009-10-12 03:52 17920 ----a-w- c:\windows\system32\ROUTE.EXE
2009-08-14 14:16 . 2009-10-12 03:52 11264 ----a-w- c:\windows\system32\MRINFO.EXE
2009-08-14 14:16 . 2009-10-12 03:52 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
2009-08-14 14:16 . 2009-10-12 03:52 19968 ----a-w- c:\windows\system32\ARP.EXE
2009-08-14 14:16 . 2009-10-12 03:52 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
2009-08-14 14:16 . 2009-10-12 03:52 10240 ----a-w- c:\windows\system32\finger.exe
2008-08-22 10:20 . 2008-08-22 10:20 123392 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2007-11-28 19:31 . 2008-08-22 09:50 67696 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2007-11-28 19:31 . 2008-08-22 09:50 54376 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2007-11-28 19:31 . 2008-08-22 09:50 34952 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2007-11-28 19:31 . 2008-08-22 09:50 46720 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2007-11-28 19:31 . 2008-08-22 09:50 172144 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2008-08-22 18:26 . 2008-08-22 18:14 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"SmpcSys"="c:\program files\Packard Bell\SetUpMyPC\SmpSys.exe" [2008-02-04 1038136]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"WindowsWelcomeCenter"="oobefldr.dll" - c:\windows\System32\oobefldr.dll [2008-01-21 2153472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-12-20 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-20 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-20 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-08-22 24064]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-02-15 981384]
"PCTAVApp"="c:\program files\PC Tools AntiVirus\PCTAV.exe" [2009-04-16 1505168]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-03-06 488984]
"toolbar_eula_launcher"="c:\program files\Packard Bell\GOOGLE_EULA\EULALauncher.exe" [2007-02-20 28672]
"LogitechQuickCamRibbon"="c:\program files\Labtec\WebCam10\WebCam10.exe" [2007-03-06 1060376]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-05-07 6139904]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
PalTalk.lnk - c:\program files\Paltalk Messenger\paltalk.exe [2009-1-28 10950144]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~4\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCTAVSvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

R0 PCTCore;PCTools KDS;c:\windows\System32\drivers\PCTCore.sys [12/10/2009 04:04 206256]
R2 TeamViewer4;TeamViewer 4;c:\program files\TeamViewer\Version4\TeamViewer_Service.exe [18/05/2009 13:13 185640]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\System32\drivers\ManyCam.sys [14/01/2008 10:06 21632]
S3 GoogleDesktopManager-071508-051939;Google Desktop Manager 5.7.807.15159;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [22/08/2008 10:20 24064]

--- Other Services/Drivers In Memory ---

*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder

2009-11-05 c:\windows\Tasks\Recovery DVD Creator-rachel.job
- c:\program files\Packard Bell\SetupMyPc\MCDCheck.exe [2008-08-22 10:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://go.packardbell.com/?id=9067
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.allow_platform_file_picker", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.accept.default", "application/x-shockwave-flash,text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.remoteLookups", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.updateURL", "http://sb.google.com/safebrowsing/update?client={moz:client}&appver={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.lookupURL", "http://sb.google.com/safebrowsing/lookup?sourceid=firefox-antiphish&features=TrustRank&client={moz:client}&appver={moz:version}&");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.reportURL", "http://sb.google.com/safebrowsing/report?");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-05 19:06
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\PC Tools AntiVirus\PCTAVSvc.exe
c:\windows\System32\rundll32.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Common Files\LogiShrd\LComMgr\LVComSX.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2009-11-05 19:08 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-05 19:08
ComboFix2.txt 2009-11-05 00:41

Pre-Run: 241,169,510,400 bytes free
Post-Run: 241,164,869,632 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=6 Sets=1,2,3,4,5,6,8

Edited by rachy, 05 November 2009 - 04:51 PM.


#15 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:04:47 AM

Posted 06 November 2009 - 01:27 PM

Hi,


How is your system running?


  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)

regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users