Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

need help with malware analysis


  • This topic is locked This topic is locked
14 replies to this topic

#1 runner1

runner1

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:42 AM

Posted 23 January 2010 - 11:20 AM

Hi, I had a serious malware problem and out of desperation ran combofix without getting help first. I found a post that said that had worked for others and I tried it. I did not read all the warnings but have since realized that would have been the way to go but at this point it is done and I have to go on from here.

It seems to have worked but after a previous post requesting help on posting the combofix log I was asked by Orange blossom to go to different forum and quietman7 refered me to instructions for Combo fix usage which contains the Preparation Guide Before Using malware removal tool.

I am not experienced in posting to forums etc. so I have tried to do what was requested but apologize if this is incorrect.

As instructed in these pages I have made the DDS log and Root repeal log which are posted below. I would appreciate any help you can give me. I did not post the combofix log since this seems to be the wrong approach but would be glad to do that too. THANKS!!!!


DDS (Ver_09-12-01.01) - NTFSx86
Run by Neal at 10:23:50.01 on Sat 01/23/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1681 [GMT -5:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Picasa\PicasaMediaDetector.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9SA.EXE
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Documents and Settings\Neal.NEAL1\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.spiritdaily.com/
mURLSearchHooks: H - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {C7768536-96F8-4001-B1A2-90EE21279187} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [diagent] "c:\program files\creative\sblive\diagnostics\diagent.exe" startup
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [LifeScape Media Detector] c:\program files\picasa\PicasaMediaDetector.exe
mRun: [EPSON Stylus Pro 9600] c:\windows\system32\spool\drivers\w32x86\3\E_S10IC2.EXE /P21 "EPSON Stylus Pro 9600" /O6 "USB002" /M "Stylus Pro 9600"
mRun: [EPSON Stylus Photo R2400] c:\windows\system32\spool\drivers\w32x86\3\E_FATI9SA.EXE /P24 "EPSON Stylus Photo R2400" /O6 "USB003" /M "Stylus Photo R2400"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE
mPolicies-explorer: <NO NAME> =
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: {9BAF1FF0-E09D-4713-92C1-C281420C6CDE} = 207.69.188.185 207.69.188.186
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\neal~1.nea\applic~1\mozilla\firefox\profiles\6yap86dl.default\
FF - prefs.js: browser.search.selectedEngine - Google

============= SERVICES / DRIVERS ===============

R0 AVG Anti-Rootkit;AVG Anti-Rootkit;c:\windows\system32\drivers\avgarkt.sys [2007-1-31 5632]
R1 AvgArCln;Avg Anti-Rootkit Clean Driver;c:\windows\system32\drivers\AvgArCln.sys [2010-1-20 3968]
S1 a59S5t2;a59S5t2;c:\windows\system32\drivers\a59S5t2.sys [2010-1-20 72192]
S3 Bercotibic;Bercotibic; [x]
S3 BW2NDIS5;BW2NDIS5;c:\windows\system32\drivers\bw2ndis5.sys --> c:\windows\system32\drivers\BW2NDIS5.sys [?]
S3 Evcpadxvtsts;Evcpadxvtsts;c:\windows\system32\drivers\fdc.sys [2003-7-16 27392]
S3 Imapnrye;Imapnrye;c:\windows\system32\ntkrnlpa.exe [2002-8-28 2066048]
S3 Isaenrrv;Isaenrrv; [x]
S3 Mrcrdeheuad;Mrcrdeheuad; [x]
S3 Mtisocn5;Mtisocn5;c:\windows\system32\drivers\ftdisk.sys [2003-7-16 125056]
S3 Pamotient;Pamotient;c:\windows\system32\drivers\ipnat.sys [2003-7-16 152832]
S3 Rdaavnlo;Rdaavnlo; [x]
S3 Splitlrtvar;Splitlrtvar; [x]
S3 Swprdr;Swprdr; [x]
S3 Tcpitloparect;Tcpitloparect; [x]

=============== Created Last 30 ================

2010-01-23 14:50:04 0 ----a-w- c:\windows\system32\drivers\^??????.sys
2010-01-22 02:03:14 0 d-sha-r- C:\cmdcons
2010-01-22 01:45:24 0 d-----w- c:\windows\system32\LogFiles
2010-01-22 01:43:09 98816 ----a-w- c:\windows\sed.exe
2010-01-22 01:43:09 77312 ----a-w- c:\windows\MBR.exe
2010-01-22 01:43:09 261632 ----a-w- c:\windows\PEV.exe
2010-01-22 01:43:09 161792 ----a-w- c:\windows\SWREG.exe
2010-01-21 02:42:38 0 d-----w- c:\docume~1\neal~1.nea\applic~1\AVG8
2010-01-21 01:45:20 0 d-----w- c:\docume~1\neal~1.nea\applic~1\Malwarebytes
2010-01-21 01:45:15 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-21 01:45:13 0 d-----w- c:\docume~1\alluse~1.win\applic~1\Malwarebytes
2010-01-21 01:45:12 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-21 01:45:12 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-21 01:41:18 3968 ----a-w- c:\windows\system32\drivers\AvgArCln.sys
2010-01-20 21:00:29 72192 ----a-w- c:\windows\system32\drivers\a59S5t2.sys

==================== Find3M ====================

2009-10-29 07:45:38 916480 ------w- c:\windows\system32\wininet.dll
2008-10-01 00:47:52 172 ----a-w- c:\program files\ThumbsReg.exe.log
2008-09-30 15:34:47 8562 ----a-w- c:\program files\Thumbs.typ
2008-09-30 15:34:47 672 ----a-w- c:\program files\thumbs.tdo
2008-09-30 15:34:47 14009 ----a-w- c:\program files\Thumbs.flt
2007-11-29 20:00:34 8859304 ----a-w- c:\program files\Thumbs.exe
2007-11-29 19:58:46 216744 ----a-w- c:\program files\cswshlex.dll
2007-11-29 19:58:02 278184 ----a-w- c:\program files\Thumbspriv64.exe
2007-11-29 19:58:02 114344 ----a-w- c:\program files\Thumbspriv.exe
2007-11-29 19:57:52 174760 ----a-w- c:\program files\ThumbsReg64.exe
2007-11-29 19:57:52 143016 ----a-w- c:\program files\ThumbsReg.exe
2007-11-08 17:36:40 183976 ----a-w- c:\program files\TpView.exe
2007-10-27 07:16:30 2658304 ----a-w- c:\program files\PolyImagepro.dll
2007-10-24 20:48:34 83112 ----a-w- c:\program files\cswshlex64.dll
2007-10-24 20:11:40 65192 ----a-w- c:\program files\tpsndrdr.ax
2007-10-23 18:28:16 551424 ----a-w- c:\program files\Thumbs.sef
2007-09-06 19:58:32 453153 ----a-w- c:\program files\toolbar_sample.png
2007-01-23 16:36:00 26906 ----a-w- c:\program files\Notes70sp1.htm
2007-01-09 15:47:44 5337 ----a-w- c:\program files\Exifval.dat
2006-08-23 17:34:00 176128 ----a-w- c:\program files\Dzip32.dll
2006-08-23 17:34:00 143360 ----a-w- c:\program files\Dunzip32.dll
2004-09-28 20:41:14 18575 ----a-w- c:\program files\Notes70.htm
2003-07-15 19:17:06 24576 ----a-w- c:\program files\Cswole.dll
2003-02-20 16:01:04 267264 ----a-w- c:\program files\LTDIS13n.dll
2003-02-20 15:29:46 271360 ----a-w- c:\program files\LFJ2K13n.dll
2003-02-20 15:27:32 33280 ----a-w- c:\program files\lfwmp13n.dll
2003-02-20 15:24:54 400384 ----a-w- c:\program files\LFCMP13n.DLL
2003-02-20 15:20:30 1684992 ----a-w- c:\program files\LTCLR13n.dll
2003-02-20 15:19:12 25600 ----a-w- c:\program files\lfxwd13n.dll
2003-02-20 15:19:06 47104 ----a-w- c:\program files\lfXpm13n.dll
2003-02-20 15:19:00 45056 ----a-w- c:\program files\lfXbm13n.dll
2003-02-20 15:18:52 19968 ----a-w- c:\program files\lfwfx13n.dll
2003-02-20 15:17:46 31744 ----a-w- c:\program files\lflmb13n.dll
2003-02-20 15:17:30 19968 ----a-w- c:\program files\lfitg13n.dll
2003-02-20 15:17:14 48128 ----a-w- c:\program files\lfica13n.dll
2003-02-20 15:17:04 84480 ----a-w- c:\program files\lffpx13n.dll
2003-02-20 15:16:48 20992 ----a-w- c:\program files\lfCUT13n.dll
2003-02-20 15:16:14 23040 ----a-w- c:\program files\lfawd13n.dll
2003-02-20 15:15:52 73216 ----a-w- c:\program files\lffax13n.dll
2003-02-20 15:15:12 446464 ----a-w- c:\program files\ltimg13n.dll
2003-02-20 15:14:16 141824 ----a-w- c:\program files\ltfil13n.DLL
2003-02-20 15:14:00 445952 ----a-w- c:\program files\ltkrn13n.dll
2003-02-20 03:04:04 205824 ----a-w- c:\program files\ltefx13n.dll
2002-09-11 14:26:52 63730 -c--a-w- c:\program files\viewsonicinstruct_xp.pdf
2002-07-26 20:02:06 153088 ----a-w- c:\program files\UNWISE.EXE
2002-06-26 16:17:36 6144 ----a-w- c:\program files\awdcxc32.dll
2002-06-26 16:17:36 26624 ----a-w- c:\program files\awresx32.dll
2002-06-26 16:17:36 24576 ----a-w- c:\program files\awcodc32.dll
2002-06-26 16:17:36 11776 ----a-w- c:\program files\awdenc32.dll
2002-06-26 16:17:36 10240 ----a-w- c:\program files\awview32.dll
2001-06-14 14:30:50 1044480 ----a-w- c:\program files\Roboex32.dll
2001-01-22 14:30:34 61440 ----a-w- c:\program files\TpCmd.exe
2000-08-04 18:25:30 49152 ----a-w- c:\program files\Inetwh32.dll
2000-04-12 19:28:12 118784 ----a-w- c:\program files\lfkodak.dll
2000-04-12 19:24:10 338944 ----a-w- c:\program files\lffpx7.dll
1999-01-26 16:20:24 32768 ----a-w- c:\program files\Cvt3.exe
1998-08-17 03:04:10 269312 ----a-w- c:\program files\Fpxacc.dll
1998-07-23 15:42:54 172032 ----a-w- c:\program files\Tpdb.dll
1998-07-23 15:39:12 44032 ----a-w- c:\program files\Cswrt.dll
1998-03-30 08:00:00 434176 ----a-w- c:\program files\DC120v10_32.dll
1996-07-17 16:45:40 227840 ----a-w- c:\program files\Deco_32.dll
1995-09-30 02:06:48 312832 ----a-w- c:\program files\Msvcrt40.dll
1995-07-31 16:44:46 212480 ----a-w- c:\program files\Pcdlib32.dll
1995-07-01 01:01:00 56832 ----a-w- c:\program files\Im30dxf.dil
2008-08-14 15:59:25 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008081420080815\index.dat

============= FINISH: 10:24:29.50 ===============


ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2010/01/23 10:31
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================

Drivers
-------------------
Name: a59S5t2.sys
Image Path: C:\WINDOWS\system32\drivers\a59S5t2.sys
Address: 0xB8712000 Size: 94208 File Visible: - Signed: -
Status: Hidden from the Windows API!

Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xB86DC000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF79E1000 Size: 8192 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB63B5000 Size: 49152 File Visible: No Signed: -
Status: -

Hidden/Locked Files
-------------------
Path: c:\documents and settings\neal.neal1\local settings\temp\~df493f.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\neal.neal1\local settings\temp\~dfb807.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\neal.neal1\local settings\temp\~dfbdc9.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Stealth Objects
-------------------
Object: Hidden Code [ETHREAD: 0x89f2f020]
Process: System Address: 0xb8714af0 Size: 632

Object: Hidden Code [ETHREAD: 0x89e658f0]
Process: System Address: 0xb8714dd0 Size: 183

Object: Hidden Code [ETHREAD: 0x89eebc70]
Process: System Address: 0xb87144e0 Size: 634

Hidden Services
-------------------
Service Name: ^
Image Path: C:\WINDOWS\system32\drivers\^ஸ設„†ᇘ觵.sys

==EOF==

BC AdBot (Login to Remove)

 


#2 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:42 AM

Posted 29 January 2010 - 03:47 PM

Hi,

My name is Extremeboy (or EB for short), and I will be helping you with your log.

We apologize for the delay of response.

Do you still require help?

If you still require assistance we would like to see the current condition of your system so please post a new set of DDS Logs as well as a RootRepeal log and a description of any remaining problems or symptoms you may still have please.

If for any reason you did not post a DDS log or RootRepeal log please refer to this page and in step #6 and Step #7 for further instructions on downloading and running DDS & RootRepeal. If you have any problems when running the tools or unable to produce a report for any reason, just let me know in your next reply.


For your next reply I would like to see:
-The DDS logs
---DDS.txt and Attach logs
-RootRepeal logs
-Description of any remaining problems you may still have.


Thanks again and we apologize for the delay.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#3 runner1

runner1
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:42 AM

Posted 30 January 2010 - 10:24 AM

Thanks, EB
I have been running anti spyware programs which seemed to help. Below is the DDS and Root Repeal logs. Any help would be greatly appreciated. I can't point to any specific sypmtoms at the moment but it would be good to have you check the logs since there could still be issues that are hidden. THANKS!!!

DDS (Ver_09-12-01.01) - NTFSx86
Run by Neal at 10:11:37.17 on Sat 01/30/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1176 [GMT -5:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Picasa\PicasaMediaDetector.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9SA.EXE
C:\WINDOWS\system32\RunDLL32.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Neal.NEAL1\Desktop\RootRepeal.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Neal.NEAL1\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.spiritdaily.com/
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
TB: {C7768536-96F8-4001-B1A2-90EE21279187} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [diagent] "c:\program files\creative\sblive\diagnostics\diagent.exe" startup
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [LifeScape Media Detector] c:\program files\picasa\PicasaMediaDetector.exe
mRun: [EPSON Stylus Pro 9600] c:\windows\system32\spool\drivers\w32x86\3\E_S10IC2.EXE /P21 "EPSON Stylus Pro 9600" /O6 "USB002" /M "Stylus Pro 9600"
mRun: [EPSON Stylus Photo R2400] c:\windows\system32\spool\drivers\w32x86\3\E_FATI9SA.EXE /P24 "EPSON Stylus Photo R2400" /O6 "USB003" /M "Stylus Photo R2400"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE
mPolicies-explorer: =
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: {9BAF1FF0-E09D-4713-92C1-C281420C6CDE} = 207.69.188.185 207.69.188.186
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: avgrsstarter - avgrsstx.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\neal~1.nea\applic~1\mozilla\firefox\profiles\6yap86dl.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll

============= SERVICES / DRIVERS ===============

R0 AVG Anti-Rootkit;AVG Anti-Rootkit;c:\windows\system32\drivers\avgarkt.sys [2007-1-31 5632]
R1 AvgArCln;Avg Anti-Rootkit Clean Driver;c:\windows\system32\drivers\AvgArCln.sys [2010-1-20 3968]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-1-23 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-1-23 28424]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-1-23 360584]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-1-5 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-1-5 74480]
R2 a2free;a-squared Free Service;c:\program files\a-squared free\a2service.exe [2010-1-27 1858144]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-1-23 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-1-23 285392]
R3 rootrepeal;rootrepeal;\??\c:\windows\system32\drivers\rootrepeal.sys --> c:\windows\system32\drivers\rootrepeal.sys [?]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-1-5 7408]
S1 a59S5t2;a59S5t2;\??\c:\windows\system32\drivers\a59s5t2.sys --> c:\windows\system32\drivers\a59S5t2.sys [?]
S3 Aic7es;Aic7es;c:\windows\system32\label.exe [2003-7-16 9728]
S3 Bercotibic;Bercotibic; [x]
S3 BW2NDIS5;BW2NDIS5;c:\windows\system32\drivers\bw2ndis5.sys --> c:\windows\system32\drivers\BW2NDIS5.sys [?]
S3 Evcpadxvtsts;Evcpadxvtsts;c:\windows\system32\drivers\fdc.sys [2003-7-16 27392]
S3 Imapnrye;Imapnrye;c:\windows\system32\ntkrnlpa.exe [2002-8-28 2066048]
S3 Isaenrrv;Isaenrrv; [x]
S3 Mtisocn5;Mtisocn5;c:\windows\system32\drivers\ftdisk.sys [2003-7-16 125056]
S3 Pamotient;Pamotient;c:\windows\system32\drivers\ipnat.sys [2003-7-16 152832]
S3 Rdaavnlo;Rdaavnlo; [x]
S3 Splitlrtvar;Splitlrtvar; [x]
S3 Swprdr;Swprdr; [x]
S3 Tcpitloparect;Tcpitloparect; [x]

=============== Created Last 30 ================


==================== Find3M ====================

2008-10-01 00:47:52 172 ----a-w- c:\program files\ThumbsReg.exe.log
2008-09-30 15:34:47 8562 ----a-w- c:\program files\Thumbs.typ
2008-09-30 15:34:47 672 ----a-w- c:\program files\thumbs.tdo
2008-09-30 15:34:47 14009 ----a-w- c:\program files\Thumbs.flt
2007-11-29 20:00:34 8859304 ----a-w- c:\program files\Thumbs.exe
2007-11-29 19:58:46 216744 ----a-w- c:\program files\cswshlex.dll
2007-11-29 19:58:02 278184 ----a-w- c:\program files\Thumbspriv64.exe
2007-11-29 19:58:02 114344 ----a-w- c:\program files\Thumbspriv.exe
2007-11-29 19:57:52 174760 ----a-w- c:\program files\ThumbsReg64.exe
2007-11-29 19:57:52 143016 ----a-w- c:\program files\ThumbsReg.exe
2007-11-08 17:36:40 183976 ----a-w- c:\program files\TpView.exe
2007-10-27 07:16:30 2658304 ----a-w- c:\program files\PolyImagepro.dll
2007-10-24 20:48:34 83112 ----a-w- c:\program files\cswshlex64.dll
2007-10-24 20:11:40 65192 ----a-w- c:\program files\tpsndrdr.ax
2007-10-23 18:28:16 551424 ----a-w- c:\program files\Thumbs.sef
2007-09-06 19:58:32 453153 ----a-w- c:\program files\toolbar_sample.png
2007-01-23 16:36:00 26906 ----a-w- c:\program files\Notes70sp1.htm
2007-01-09 15:47:44 5337 ----a-w- c:\program files\Exifval.dat
2006-08-23 17:34:00 176128 ----a-w- c:\program files\Dzip32.dll
2006-08-23 17:34:00 143360 ----a-w- c:\program files\Dunzip32.dll
2004-09-28 20:41:14 18575 ----a-w- c:\program files\Notes70.htm
2003-07-15 19:17:06 24576 ----a-w- c:\program files\Cswole.dll
2003-02-20 16:01:04 267264 ----a-w- c:\program files\LTDIS13n.dll
2003-02-20 15:29:46 271360 ----a-w- c:\program files\LFJ2K13n.dll
2003-02-20 15:27:32 33280 ----a-w- c:\program files\lfwmp13n.dll
2003-02-20 15:24:54 400384 ----a-w- c:\program files\LFCMP13n.DLL
2003-02-20 15:20:30 1684992 ----a-w- c:\program files\LTCLR13n.dll
2003-02-20 15:19:12 25600 ----a-w- c:\program files\lfxwd13n.dll
2003-02-20 15:19:06 47104 ----a-w- c:\program files\lfXpm13n.dll
2003-02-20 15:19:00 45056 ----a-w- c:\program files\lfXbm13n.dll
2003-02-20 15:18:52 19968 ----a-w- c:\program files\lfwfx13n.dll
2003-02-20 15:17:46 31744 ----a-w- c:\program files\lflmb13n.dll
2003-02-20 15:17:30 19968 ----a-w- c:\program files\lfitg13n.dll
2003-02-20 15:17:14 48128 ----a-w- c:\program files\lfica13n.dll
2003-02-20 15:17:04 84480 ----a-w- c:\program files\lffpx13n.dll
2003-02-20 15:16:48 20992 ----a-w- c:\program files\lfCUT13n.dll
2003-02-20 15:16:14 23040 ----a-w- c:\program files\lfawd13n.dll
2003-02-20 15:15:52 73216 ----a-w- c:\program files\lffax13n.dll
2003-02-20 15:15:12 446464 ----a-w- c:\program files\ltimg13n.dll
2003-02-20 15:14:16 141824 ----a-w- c:\program files\ltfil13n.DLL
2003-02-20 15:14:00 445952 ----a-w- c:\program files\ltkrn13n.dll
2003-02-20 03:04:04 205824 ----a-w- c:\program files\ltefx13n.dll
2002-09-11 14:26:52 63730 -c--a-w- c:\program files\viewsonicinstruct_xp.pdf
2002-07-26 20:02:06 153088 ----a-w- c:\program files\UNWISE.EXE
2002-06-26 16:17:36 6144 ----a-w- c:\program files\awdcxc32.dll
2002-06-26 16:17:36 26624 ----a-w- c:\program files\awresx32.dll
2002-06-26 16:17:36 24576 ----a-w- c:\program files\awcodc32.dll
2002-06-26 16:17:36 11776 ----a-w- c:\program files\awdenc32.dll
2002-06-26 16:17:36 10240 ----a-w- c:\program files\awview32.dll
2001-06-14 14:30:50 1044480 ----a-w- c:\program files\Roboex32.dll
2001-01-22 14:30:34 61440 ----a-w- c:\program files\TpCmd.exe
2000-08-04 18:25:30 49152 ----a-w- c:\program files\Inetwh32.dll
2000-04-12 19:28:12 118784 ----a-w- c:\program files\lfkodak.dll
2000-04-12 19:24:10 338944 ----a-w- c:\program files\lffpx7.dll
1999-01-26 16:20:24 32768 ----a-w- c:\program files\Cvt3.exe
1998-08-17 03:04:10 269312 ----a-w- c:\program files\Fpxacc.dll
1998-07-23 15:42:54 172032 ----a-w- c:\program files\Tpdb.dll
1998-07-23 15:39:12 44032 ----a-w- c:\program files\Cswrt.dll
1998-03-30 08:00:00 434176 ----a-w- c:\program files\DC120v10_32.dll
1996-07-17 16:45:40 227840 ----a-w- c:\program files\Deco_32.dll
1995-09-30 02:06:48 312832 ----a-w- c:\program files\Msvcrt40.dll
1995-07-31 16:44:46 212480 ----a-w- c:\program files\Pcdlib32.dll
1995-07-01 01:01:00 56832 ----a-w- c:\program files\Im30dxf.dil
2008-08-14 15:59:25 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008081420080815\index.dat

============= FINISH: 10:12:07.04 ===============


ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2010/01/30 09:55
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================

Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xB80ED000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF79CD000 Size: 8192 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB6346000 Size: 49152 File Visible: No Signed: -
Status: -

Hidden/Locked Files
-------------------
Path: C:\RootRepeal report 01-30-10 (09-55-41).txt
Status: Visible to the Windows API, but not on disk.

Path: c:\documents and settings\neal.neal1\local settings\temp\~df7927.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\neal.neal1\local settings\temp\~dfd534.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\neal.neal1\local settings\temp\~dfd955.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

SSDT
-------------------
#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys" at address 0xb82e50b0

Hidden Services
-------------------
Service Name: ^
Image Path: C:\WINDOWS\system32\drivers\^ஸ設„†ᇘ觵.sys

==EOF==

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 4/23/2005 4:05:54 PM
System Uptime: 1/29/2010 2:50:40 PM (20 hours ago)

Motherboard: Dell Computer Corp. | | 02Y832
Processor: Intel® Pentium® 4 CPU 2.66GHz | Microprocessor | 2660/533mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 112 GiB total, 45.542 GiB free.
D: is CDROM (CDFS)
E: is CDROM ()
F: is FIXED (NTFS) - 699 GiB total, 405.714 GiB free.
G: is Removable

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP1: 1/27/2010 8:57:09 AM - System Checkpoint
RP2: 1/27/2010 9:07:53 AM - Avg8 Update
RP3: 1/27/2010 9:20:35 PM - Installed SUPERAntiSpyware Free Edition
RP4: 1/29/2010 10:20:52 AM - System Checkpoint

==== Installed Programs ======================


a-squared Free 4.5
ABBYY FineReader 5.0 Sprint
Ad-aware 6 Personal
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Illustrator 8.0
Adobe Photoshop CS
Adobe Reader 7.1.0
Apple Software Update
AVG Anti-Rootkit Free
AVG Free 9.0
CorelDRAW 10
Dell ResourceCD
EPSON Printer Software
EPSON Scan
EPSON SPR2400 Reference Guide
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
ICC Color Profiles
Intel® PRO Network Adapters and Drivers
Macromedia Dreamweaver MX 2004
Macromedia Extension Manager
Malwarebytes' Anti-Malware
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Streets and Trips 2002
Microsoft Visual C++ 2005 Redistributable
Microsoft Word 2002
Microsoft Works 2003 Setup Launcher
Microsoft Works 7.0
Microsoft Works Suite Add-in for Microsoft Word
Modem Helper
Mozilla Firefox (3.0.5)
Netscape Navigator (9.0b2)
NetWaiting
Nikon Message Center
NVIDIA Drivers
PENTAX Digital Camera Utility
Picasa
PowerDVD
QuickTime
RealPlayer
SeaTools Enterprise
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
SilverFast Epson
SilverFast Epson (Photoshop Plugin)
SilverFast Epson (TWAIN Plugin)
Soft Voice SoftRing Modem with SmartSP
Sonic DLA
Sonic MyDVD
Sonic RecordNow!
Sonic Update Manager
Sound Blaster Live!
Spybot - Search & Destroy
SUPERAntiSpyware Free Edition
ThumbsPlus version 7 SP2
TotalAccess Smart Installer
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
V92 PCI Voice Faxmodem
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage v1.3.0254.0
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows XP Service Pack 3
WinZip
Works Suite OS Pack

==== Event Viewer Messages From Past Week ========

1/29/2010 2:15:40 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000243' while processing the file 'lmrgcachem.sam' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume.
1/26/2010 9:25:52 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
1/26/2010 2:59:04 PM, error: Print [19] - Sharing printer failed + 1722, Printer EPSON Stylus Pro 9600 share name EPSON_9600.
1/26/2010 2:42:14 PM, error: Service Control Manager [7000] - The Aic7es service failed to start due to the following error: The system cannot find the file specified.
1/26/2010 11:04:43 PM, error: System Error [1003] - Error code 1000008e, parameter1 c0000005, parameter2 00000000, parameter3 b61fa9f8, parameter4 00000000.
1/23/2010 9:50:31 AM, error: Service Control Manager [7000] - The Swprdr service failed to start due to the following error: The system cannot find the file specified.
1/23/2010 9:50:31 AM, error: Service Control Manager [7000] - The Splitlrtvar service failed to start due to the following error: The system cannot find the path specified.
1/23/2010 9:50:31 AM, error: Service Control Manager [7000] - The Pamotient service failed to start due to the following error: The filename, directory name, or volume label syntax is incorrect.
1/23/2010 9:50:31 AM, error: Service Control Manager [7000] - The Mtisocn5 service failed to start due to the following error: The filename, directory name, or volume label syntax is incorrect.
1/23/2010 9:50:31 AM, error: Service Control Manager [7000] - The Isaenrrv service failed to start due to the following error: The system cannot find the path specified.
1/23/2010 9:42:13 AM, error: Srv [2019] - The server was unable to allocate from the system nonpaged pool because the pool was empty.

==== End Of File ===========================

QUOTE(extremeboy @ Jan 29 2010, 03:47 PM) View Post
Hi,

My name is Extremeboy (or EB for short), and I will be helping you with your log.

We apologize for the delay of response.

Do you still require help?

If you still require assistance we would like to see the current condition of your system so please post a new set of DDS Logs as well as a RootRepeal log and a description of any remaining problems or symptoms you may still have please.

If for any reason you did not post a DDS log or RootRepeal log please refer to this page and in step #6 and Step #7 for further instructions on downloading and running DDS & RootRepeal. If you have any problems when running the tools or unable to produce a report for any reason, just let me know in your next reply.


For your next reply I would like to see:
-The DDS logs
---DDS.txt and Attach logs
-RootRepeal logs
-Description of any remaining problems you may still have.


Thanks again and we apologize for the delay.

With Regards,
Extremeboy

Edited by runner1, 30 January 2010 - 12:37 PM.


#4 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:42 AM

Posted 30 January 2010 - 04:13 PM

Hello.

Thanks for those logs. Overall seems good, but just some leftover entries and one suspicious entry that we may need to deal with. Let's start with Combofix.

Download and Run Combofix

Please visit this webpage for instructions for downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Refer to this page on instructions on doing so.

Please include the C:\ComboFix.txt in your next reply for further review.

Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#5 runner1

runner1
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:42 AM

Posted 01 February 2010 - 12:07 PM

Thanks!!! here is the combofix log:

ComboFix 10-01-31.06 - Neal 02/01/2010 11:39:52.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1574 [GMT -5:00]
Running from: c:\documents and settings\Neal.NEAL1\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Mozilla Firefox\plc4.dll
c:\windows\EventSystem.log

.
((((((((((((((((((((((((( Files Created from 2010-01-01 to 2010-02-01 )))))))))))))))))))))))))))))))
.

2010-01-29 19:55 . 2010-01-29 20:12 -------- d-----w- c:\program files\eParentalControl
2010-01-29 19:55 . 2010-01-29 19:55 -------- d-----w- c:\program files\Accessories
2010-01-29 19:55 . 2010-01-29 19:55 180224 ----a-w- c:\windows\system32\cpreg.dll
2010-01-29 19:55 . 2010-01-29 19:55 180224 ----a-w- c:\windows\cpreg.dll
2010-01-29 18:30 . 2010-01-29 19:15 8672 ----a-w- c:\windows\system32\sbnetkey.sys
2010-01-28 02:35 . 2010-01-28 02:35 52224 ----a-w- c:\documents and settings\Neal.NEAL1\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-28 02:35 . 2010-01-28 02:35 117760 ----a-w- c:\documents and settings\Neal.NEAL1\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-28 02:21 . 2010-01-28 02:21 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2010-01-28 02:20 . 2010-01-28 02:20 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-28 02:20 . 2010-01-28 02:20 -------- d-----w- c:\documents and settings\Neal.NEAL1\Application Data\SUPERAntiSpyware.com
2010-01-28 02:20 . 2010-01-28 02:20 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-28 01:14 . 2010-01-28 06:35 -------- d-----w- c:\program files\a-squared Free
2010-01-27 14:07 . 2010-01-23 22:41 3777280 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\avg9\update\backup\setup.exe
2010-01-27 14:07 . 2010-01-23 22:41 1260800 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\avg9\update\backup\avgfrw.exe
2010-01-27 02:09 . 2010-01-27 02:09 -------- d-----w- c:\documents and settings\Neal.NEAL1\Local Settings\Application Data\AVG Security Toolbar
2010-01-25 14:39 . 2009-11-25 18:01 1230080 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\AVG Security Toolbar\IEToolbar.dll
2010-01-23 22:41 . 2010-01-23 22:41 -------- d-----w- C:\$AVG
2010-01-23 22:41 . 2010-01-23 22:41 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-23 22:41 . 2010-01-23 22:41 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-01-23 22:41 . 2010-01-23 22:41 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-23 22:41 . 2010-01-23 22:41 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-23 22:41 . 2010-02-01 14:48 -------- d-----w- c:\windows\system32\drivers\Avg
2010-01-23 22:41 . 2010-01-25 14:39 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\AVG Security Toolbar
2010-01-23 22:39 . 2010-01-23 22:39 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\avg9
2010-01-23 14:50 . 2010-01-23 14:50 0 ----a-w- c:\windows\system32\drivers\^??????.sys
2010-01-22 01:45 . 2010-01-22 01:45 -------- d-----w- c:\windows\system32\LogFiles
2010-01-21 01:45 . 2010-01-21 01:45 -------- d-----w- c:\documents and settings\Neal.NEAL1\Application Data\Malwarebytes
2010-01-21 01:45 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-21 01:45 . 2010-01-21 01:45 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2010-01-21 01:45 . 2010-01-21 01:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-21 01:45 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-21 01:41 . 2007-01-18 12:00 3968 ----a-w- c:\windows\system32\drivers\AvgArCln.sys
2010-01-20 06:11 . 2010-01-20 06:11 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-01-09 23:07 . 2006-12-14 15:00 110592 ----a-w- c:\documents and settings\Neal.NEAL1\Application Data\U3\temp\cleanup.exe
2010-01-09 22:56 . 2007-02-12 22:46 3096576 ---ha-w- c:\documents and settings\Neal.NEAL1\Application Data\U3\temp\Launchpad Removal.exe
2010-01-09 22:56 . 2010-01-09 23:07 -------- d-----w- c:\documents and settings\Neal.NEAL1\Application Data\U3

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-30 21:03 . 2005-05-06 00:21 -------- d-----w- c:\documents and settings\Neal.NEAL1\Application Data\ThumbsPlus
2010-01-27 14:23 . 2005-04-15 00:35 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-23 22:39 . 2009-02-19 01:58 -------- d-----w- c:\program files\AVG
2010-01-20 20:41 . 2005-04-26 23:49 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2010-01-09 19:41 . 2009-03-23 19:12 -------- d-----w- c:\documents and settings\Neal.NEAL1\Application Data\Lasersoft Imaging
2009-12-18 20:07 . 2005-04-26 23:58 -------- d-----w- c:\program files\Picasa
2009-12-17 19:35 . 2009-12-17 19:35 57368 ----a-w- c:\documents and settings\Neal Hughes\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-21 15:51 . 2003-07-16 16:17 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2008-10-01 00:47 . 2008-09-30 15:36 172 ----a-w- c:\program files\ThumbsReg.exe.log
2002-09-11 14:26 . 2003-11-07 22:17 63730 -c--a-w- c:\program files\viewsonicinstruct_xp.pdf
2002-07-26 20:02 . 2008-09-30 15:34 153088 ----a-w- c:\program files\UNWISE.EXE
2002-06-26 16:17 . 2008-09-30 15:34 6144 ----a-w- c:\program files\awdcxc32.dll
2002-06-26 16:17 . 2008-09-30 15:34 26624 ----a-w- c:\program files\awresx32.dll
2002-06-26 16:17 . 2008-09-30 15:34 24576 ----a-w- c:\program files\awcodc32.dll
2002-06-26 16:17 . 2008-09-30 15:34 11776 ----a-w- c:\program files\awdenc32.dll
2002-06-26 16:17 . 2008-09-30 15:34 10240 ----a-w- c:\program files\awview32.dll
2001-06-14 14:30 . 2008-09-30 15:34 1044480 ----a-w- c:\program files\Roboex32.dll
2001-01-22 14:30 . 2008-09-30 15:34 61440 ----a-w- c:\program files\TpCmd.exe
2000-08-04 18:25 . 2008-09-30 15:34 49152 ----a-w- c:\program files\Inetwh32.dll
2000-04-12 19:28 . 2008-09-30 15:34 118784 ----a-w- c:\program files\lfkodak.dll
2000-04-12 19:24 . 2008-09-30 15:34 338944 ----a-w- c:\program files\lffpx7.dll
1999-01-26 16:20 . 2008-09-30 15:34 32768 ----a-w- c:\program files\Cvt3.exe
1998-08-17 03:04 . 2008-09-30 15:34 269312 ----a-w- c:\program files\Fpxacc.dll
1998-07-23 15:42 . 2008-09-30 15:34 172032 ----a-w- c:\program files\Tpdb.dll
1998-07-23 15:39 . 2008-09-30 15:34 44032 ----a-w- c:\program files\Cswrt.dll
1998-03-30 08:00 . 2008-09-30 15:34 434176 ----a-w- c:\program files\DC120v10_32.dll
1996-07-17 16:45 . 2008-09-30 15:34 227840 ----a-w- c:\program files\Deco_32.dll
1995-09-30 02:06 . 2008-09-30 15:34 312832 ----a-w- c:\program files\Msvcrt40.dll
1995-07-31 16:44 . 2008-09-30 15:34 212480 ----a-w- c:\program files\Pcdlib32.dll
1995-07-01 01:01 . 2008-09-30 15:34 56832 ----a-w- c:\program files\Im30dxf.dil
.

((((((((((((((((((((((((((((( SnapShot@2010-01-22_02.18.47 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-12 01:54 . 2009-07-12 01:54 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e79c4723\vcomp.dll
+ 2009-07-12 01:32 . 2009-07-12 01:32 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80KOR.dll
+ 2009-07-12 01:32 . 2009-07-12 01:32 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80JPN.dll
+ 2009-07-12 01:32 . 2009-07-12 01:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ITA.dll
+ 2009-07-12 01:32 . 2009-07-12 01:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80FRA.dll
+ 2009-07-12 01:32 . 2009-07-12 01:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ESP.dll
+ 2009-07-12 01:32 . 2009-07-12 01:32 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ENU.dll
+ 2009-07-12 01:32 . 2009-07-12 01:32 65536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80DEU.dll
+ 2009-07-12 01:32 . 2009-07-12 01:32 45056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHT.dll
+ 2009-07-12 01:32 . 2009-07-12 01:32 40960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHS.dll
+ 2009-07-12 06:07 . 2009-07-12 06:07 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80u.dll
+ 2009-07-12 06:19 . 2009-07-12 06:19 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80.dll
+ 2009-07-12 00:41 . 2009-07-12 00:41 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll
+ 2010-01-28 02:20 . 2010-01-28 02:20 65024 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
+ 2010-01-28 02:20 . 2010-01-28 02:20 18944 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2010-01-28 02:20 . 2010-01-28 02:20 5120 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF16.exe
+ 2009-07-12 06:12 . 2009-07-12 06:12 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
+ 2009-07-12 06:09 . 2009-07-12 06:09 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll
+ 2009-07-12 06:08 . 2009-07-12 06:08 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll
+ 2010-01-23 22:39 . 2010-01-23 22:39 424448 c:\windows\Installer\1add5c2.msi
+ 2009-07-12 01:46 . 2009-07-12 01:46 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80u.dll
+ 2009-07-12 01:46 . 2009-07-12 01:46 1105920 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80.dll
+ 2010-01-28 02:20 . 2010-01-28 02:20 1583616 c:\windows\Installer\15415e6.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-11-25 18:01 1230080 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-01 7618560]
"diagent"="c:\program files\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 135264]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2003-08-06 114741]
"LifeScape Media Detector"="c:\program files\Picasa\PicasaMediaDetector.exe" [2005-04-26 151552]
"EPSON Stylus Pro 9600"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE" [2002-02-18 74240]
"EPSON Stylus Photo R2400"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9SA.EXE" [2004-11-09 98304]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"nwiz"="nwiz.exe" [2006-06-01 1519616]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 86016]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-01-23 2033432]

c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2003-11-7 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2004-7-21 118784]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-01-23 22:41 12464 ----a-w- c:\windows\SYSTEM32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver MX 2004\\Dreamweaver.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Corel\\Graphics10\\Register\\NAVBrowser.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [1/23/2010 5:41 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [1/23/2010 5:41 PM 360584]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/5/2010 7:56 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 7:56 AM 74480]
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [1/27/2010 8:14 PM 1858144]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [1/23/2010 5:40 PM 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [1/23/2010 5:39 PM 285392]
S1 a59S5t2;a59S5t2;\??\c:\windows\system32\drivers\a59S5t2.sys --> c:\windows\system32\drivers\a59S5t2.sys [?]
S3 Aic7es;Aic7es;c:\windows\SYSTEM32\label.exe [7/16/2003 11:26 AM 9728]
S3 Bercotibic;Bercotibic; [x]
S3 BW2NDIS5;BW2NDIS5;c:\windows\system32\Drivers\BW2NDIS5.sys --> c:\windows\system32\Drivers\BW2NDIS5.sys [?]
S3 Evcpadxvtsts;Evcpadxvtsts;c:\windows\SYSTEM32\DRIVERS\fdc.sys [7/16/2003 11:22 AM 27392]
S3 Imapnrye;Imapnrye;c:\windows\SYSTEM32\ntkrnlpa.exe [8/28/2002 8:04 PM 2066048]
S3 Isaenrrv;Isaenrrv; [x]
S3 Mtisocn5;Mtisocn5;c:\windows\SYSTEM32\DRIVERS\ftdisk.sys [7/16/2003 11:22 AM 125056]
S3 Pamotient;Pamotient;c:\windows\SYSTEM32\DRIVERS\ipnat.sys [7/16/2003 11:25 AM 152832]
S3 Rdaavnlo;Rdaavnlo; [x]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 7:56 AM 7408]
S3 Splitlrtvar;Splitlrtvar; [x]
S3 Swprdr;Swprdr; [x]
S3 Tcpitloparect;Tcpitloparect; [x]
.
Contents of the 'Scheduled Tasks' folder

2010-02-01 c:\windows\Tasks\User_Feed_Synchronization-{9C3640D6-FB96-437D-8C0D-9C9B4097EF00}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.spiritdaily.com/
TCP: {9BAF1FF0-E09D-4713-92C1-C281420C6CDE} = 207.69.188.185 207.69.188.186
FF - ProfilePath - c:\documents and settings\Neal.NEAL1\Application Data\Mozilla\Firefox\Profiles\6yap86dl.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-^??????



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-01 11:47
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(676)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\ACTIVEDS.dll
.
Completion time: 2010-02-01 11:49:32
ComboFix-quarantined-files.txt 2010-02-01 16:49
ComboFix2.txt 2010-01-22 02:23

Pre-Run: 52,554,285,056 bytes free
Post-Run: 52,593,512,448 bytes free

- - End Of File - - 9ED43A694A6FC70286C45EC439D8C973


#6 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:42 AM

Posted 01 February 2010 - 01:15 PM

Hello.

Run ComboFix with CFScript

We will run ComboFix again. This time, the instructions are slightly different.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are unsure how.
  • Open notepad (Start>Run>"notepad") and copy/paste the text in the quotebox below into it:
    CODE
    File::
    c:\windows\system32\drivers\^??????.sys
    c:\windows\system32\drivers\a59S5t2.sys
    Driver::
    Splitlrtvar
    Swprdr
    Tcpitloparect
    Bercotibic
    Isaenrrv
    Rdaavnlo
    a59S5t2ma
    Save this as CFScript.txt, in the same location as ComboFix.exe. (This should be your desktop.)

    Refering to the picture above, drag CFScript into ComboFix.exe.
When finished, it shall produce a log for you at "C:\ComboFix.txt". Post back with that log.

Do not mouseclick ComboFix's window while it's running. That may cause it to stall

Download and run MalwareBytes Anti-Malware

Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

For complete or visual instructions on installing and running Malwarebytes Anti-Malware please read this link

With regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#7 runner1

runner1
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:42 AM

Posted 01 February 2010 - 04:08 PM

here are the new logs requested. thanks again,

ComboFix 10-02-01.02 - Neal 02/01/2010 15:09:58.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1518 [GMT -5:00]
Running from: c:\documents and settings\Neal.NEAL1\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Neal.NEAL1\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

FILE ::
"c:\windows\system32\drivers\a59S5t2.sys"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_BERCOTIBIC
-------\Legacy_ISAENRRV
-------\Legacy_SPLITLRTVAR
-------\Service_Bercotibic
-------\Service_Isaenrrv
-------\Service_Rdaavnlo
-------\Service_Splitlrtvar
-------\Service_Swprdr
-------\Service_Tcpitloparect


((((((((((((((((((((((((( Files Created from 2010-01-01 to 2010-02-01 )))))))))))))))))))))))))))))))
.

2010-01-29 19:55 . 2010-01-29 20:12 -------- d-----w- c:\program files\eParentalControl
2010-01-29 19:55 . 2010-01-29 19:55 -------- d-----w- c:\program files\Accessories
2010-01-29 19:55 . 2010-01-29 19:55 180224 ----a-w- c:\windows\system32\cpreg.dll
2010-01-29 19:55 . 2010-01-29 19:55 180224 ----a-w- c:\windows\cpreg.dll
2010-01-29 18:30 . 2010-01-29 19:15 8672 ----a-w- c:\windows\system32\sbnetkey.sys
2010-01-28 02:35 . 2010-01-28 02:35 52224 ----a-w- c:\documents and settings\Neal.NEAL1\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-28 02:35 . 2010-01-28 02:35 117760 ----a-w- c:\documents and settings\Neal.NEAL1\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-28 02:21 . 2010-01-28 02:21 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2010-01-28 02:20 . 2010-01-28 02:20 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-28 02:20 . 2010-01-28 02:20 -------- d-----w- c:\documents and settings\Neal.NEAL1\Application Data\SUPERAntiSpyware.com
2010-01-28 02:20 . 2010-01-28 02:20 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-28 01:14 . 2010-01-28 06:35 -------- d-----w- c:\program files\a-squared Free
2010-01-27 14:07 . 2010-01-23 22:41 3777280 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\avg9\update\backup\setup.exe
2010-01-27 14:07 . 2010-01-23 22:41 1260800 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\avg9\update\backup\avgfrw.exe
2010-01-27 02:09 . 2010-01-27 02:09 -------- d-----w- c:\documents and settings\Neal.NEAL1\Local Settings\Application Data\AVG Security Toolbar
2010-01-25 14:39 . 2009-11-25 18:01 1230080 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\AVG Security Toolbar\IEToolbar.dll
2010-01-23 22:41 . 2010-01-23 22:41 -------- d-----w- C:\$AVG
2010-01-23 22:41 . 2010-01-23 22:41 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-23 22:41 . 2010-01-23 22:41 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-01-23 22:41 . 2010-01-23 22:41 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-23 22:41 . 2010-01-23 22:41 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-23 22:41 . 2010-02-01 14:48 -------- d-----w- c:\windows\system32\drivers\Avg
2010-01-23 22:41 . 2010-01-25 14:39 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\AVG Security Toolbar
2010-01-23 22:39 . 2010-01-23 22:39 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\avg9
2010-01-23 14:50 . 2010-01-23 14:50 0 ----a-w- c:\windows\system32\drivers\^??????.sys
2010-01-22 01:45 . 2010-01-22 01:45 -------- d-----w- c:\windows\system32\LogFiles
2010-01-21 01:45 . 2010-01-21 01:45 -------- d-----w- c:\documents and settings\Neal.NEAL1\Application Data\Malwarebytes
2010-01-21 01:45 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-21 01:45 . 2010-01-21 01:45 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2010-01-21 01:45 . 2010-01-21 01:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-21 01:45 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-21 01:41 . 2007-01-18 12:00 3968 ----a-w- c:\windows\system32\drivers\AvgArCln.sys
2010-01-20 06:11 . 2010-01-20 06:11 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-01-09 23:07 . 2006-12-14 15:00 110592 ----a-w- c:\documents and settings\Neal.NEAL1\Application Data\U3\temp\cleanup.exe
2010-01-09 22:56 . 2007-02-12 22:46 3096576 ---ha-w- c:\documents and settings\Neal.NEAL1\Application Data\U3\temp\Launchpad Removal.exe
2010-01-09 22:56 . 2010-01-09 23:07 -------- d-----w- c:\documents and settings\Neal.NEAL1\Application Data\U3

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-30 21:03 . 2005-05-06 00:21 -------- d-----w- c:\documents and settings\Neal.NEAL1\Application Data\ThumbsPlus
2010-01-27 14:23 . 2005-04-15 00:35 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-23 22:39 . 2009-02-19 01:58 -------- d-----w- c:\program files\AVG
2010-01-20 20:41 . 2005-04-26 23:49 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2010-01-09 19:41 . 2009-03-23 19:12 -------- d-----w- c:\documents and settings\Neal.NEAL1\Application Data\Lasersoft Imaging
2009-12-18 20:07 . 2005-04-26 23:58 -------- d-----w- c:\program files\Picasa
2009-12-17 19:35 . 2009-12-17 19:35 57368 ----a-w- c:\documents and settings\Neal Hughes\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-21 15:51 . 2003-07-16 16:17 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2008-10-01 00:47 . 2008-09-30 15:36 172 ----a-w- c:\program files\ThumbsReg.exe.log
2002-09-11 14:26 . 2003-11-07 22:17 63730 -c--a-w- c:\program files\viewsonicinstruct_xp.pdf
2002-07-26 20:02 . 2008-09-30 15:34 153088 ----a-w- c:\program files\UNWISE.EXE
2002-06-26 16:17 . 2008-09-30 15:34 6144 ----a-w- c:\program files\awdcxc32.dll
2002-06-26 16:17 . 2008-09-30 15:34 26624 ----a-w- c:\program files\awresx32.dll
2002-06-26 16:17 . 2008-09-30 15:34 24576 ----a-w- c:\program files\awcodc32.dll
2002-06-26 16:17 . 2008-09-30 15:34 11776 ----a-w- c:\program files\awdenc32.dll
2002-06-26 16:17 . 2008-09-30 15:34 10240 ----a-w- c:\program files\awview32.dll
2001-06-14 14:30 . 2008-09-30 15:34 1044480 ----a-w- c:\program files\Roboex32.dll
2001-01-22 14:30 . 2008-09-30 15:34 61440 ----a-w- c:\program files\TpCmd.exe
2000-08-04 18:25 . 2008-09-30 15:34 49152 ----a-w- c:\program files\Inetwh32.dll
2000-04-12 19:28 . 2008-09-30 15:34 118784 ----a-w- c:\program files\lfkodak.dll
2000-04-12 19:24 . 2008-09-30 15:34 338944 ----a-w- c:\program files\lffpx7.dll
1999-01-26 16:20 . 2008-09-30 15:34 32768 ----a-w- c:\program files\Cvt3.exe
1998-08-17 03:04 . 2008-09-30 15:34 269312 ----a-w- c:\program files\Fpxacc.dll
1998-07-23 15:42 . 2008-09-30 15:34 172032 ----a-w- c:\program files\Tpdb.dll
1998-07-23 15:39 . 2008-09-30 15:34 44032 ----a-w- c:\program files\Cswrt.dll
1998-03-30 08:00 . 2008-09-30 15:34 434176 ----a-w- c:\program files\DC120v10_32.dll
1996-07-17 16:45 . 2008-09-30 15:34 227840 ----a-w- c:\program files\Deco_32.dll
1995-09-30 02:06 . 2008-09-30 15:34 312832 ----a-w- c:\program files\Msvcrt40.dll
1995-07-31 16:44 . 2008-09-30 15:34 212480 ----a-w- c:\program files\Pcdlib32.dll
1995-07-01 01:01 . 2008-09-30 15:34 56832 ----a-w- c:\program files\Im30dxf.dil
.

((((((((((((((((((((((((((((( SnapShot@2010-01-22_02.18.47 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-12 01:54 . 2009-07-12 01:54 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e79c4723\vcomp.dll
+ 2009-07-12 01:32 . 2009-07-12 01:32 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80KOR.dll
+ 2009-07-12 01:32 . 2009-07-12 01:32 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80JPN.dll
+ 2009-07-12 01:32 . 2009-07-12 01:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ITA.dll
+ 2009-07-12 01:32 . 2009-07-12 01:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80FRA.dll
+ 2009-07-12 01:32 . 2009-07-12 01:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ESP.dll
+ 2009-07-12 01:32 . 2009-07-12 01:32 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ENU.dll
+ 2009-07-12 01:32 . 2009-07-12 01:32 65536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80DEU.dll
+ 2009-07-12 01:32 . 2009-07-12 01:32 45056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHT.dll
+ 2009-07-12 01:32 . 2009-07-12 01:32 40960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHS.dll
+ 2009-07-12 06:07 . 2009-07-12 06:07 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80u.dll
+ 2009-07-12 06:19 . 2009-07-12 06:19 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80.dll
+ 2009-07-12 00:41 . 2009-07-12 00:41 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll
+ 2010-01-28 02:20 . 2010-01-28 02:20 65024 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
+ 2010-01-28 02:20 . 2010-01-28 02:20 18944 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2010-01-28 02:20 . 2010-01-28 02:20 5120 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF16.exe
+ 2009-07-12 06:12 . 2009-07-12 06:12 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
+ 2009-07-12 06:09 . 2009-07-12 06:09 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll
+ 2009-07-12 06:08 . 2009-07-12 06:08 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll
+ 2010-01-23 22:39 . 2010-01-23 22:39 424448 c:\windows\Installer\1add5c2.msi
+ 2009-07-12 01:46 . 2009-07-12 01:46 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80u.dll
+ 2009-07-12 01:46 . 2009-07-12 01:46 1105920 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80.dll
+ 2010-01-28 02:20 . 2010-01-28 02:20 1583616 c:\windows\Installer\15415e6.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-11-25 18:01 1230080 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-01 7618560]
"diagent"="c:\program files\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 135264]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2003-08-06 114741]
"LifeScape Media Detector"="c:\program files\Picasa\PicasaMediaDetector.exe" [2005-04-26 151552]
"EPSON Stylus Pro 9600"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE" [2002-02-18 74240]
"EPSON Stylus Photo R2400"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9SA.EXE" [2004-11-09 98304]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"nwiz"="nwiz.exe" [2006-06-01 1519616]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 86016]

c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2003-11-7 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2004-7-21 118784]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-01-23 22:41 12464 ----a-w- c:\windows\SYSTEM32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver MX 2004\\Dreamweaver.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Corel\\Graphics10\\Register\\NAVBrowser.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [1/23/2010 5:41 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [1/23/2010 5:41 PM 360584]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/5/2010 7:56 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/5/2010 7:56 AM 74480]
R2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [1/27/2010 8:14 PM 1858144]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [1/23/2010 5:40 PM 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [1/23/2010 5:39 PM 285392]
S1 a59S5t2;a59S5t2;\??\c:\windows\system32\drivers\a59S5t2.sys --> c:\windows\system32\drivers\a59S5t2.sys [?]
S3 Aic7es;Aic7es;c:\windows\SYSTEM32\label.exe [7/16/2003 11:26 AM 9728]
S3 BW2NDIS5;BW2NDIS5;c:\windows\system32\Drivers\BW2NDIS5.sys --> c:\windows\system32\Drivers\BW2NDIS5.sys [?]
S3 Evcpadxvtsts;Evcpadxvtsts;c:\windows\SYSTEM32\DRIVERS\fdc.sys [7/16/2003 11:22 AM 27392]
S3 Imapnrye;Imapnrye;c:\windows\SYSTEM32\ntkrnlpa.exe [8/28/2002 8:04 PM 2066048]
S3 Mtisocn5;Mtisocn5;c:\windows\SYSTEM32\DRIVERS\ftdisk.sys [7/16/2003 11:22 AM 125056]
S3 Pamotient;Pamotient;c:\windows\SYSTEM32\DRIVERS\ipnat.sys [7/16/2003 11:25 AM 152832]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/5/2010 7:56 AM 7408]
.
Contents of the 'Scheduled Tasks' folder

2010-02-01 c:\windows\Tasks\User_Feed_Synchronization-{9C3640D6-FB96-437D-8C0D-9C9B4097EF00}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.spiritdaily.com/
TCP: {9BAF1FF0-E09D-4713-92C1-C281420C6CDE} = 207.69.188.185 207.69.188.186
FF - ProfilePath - c:\documents and settings\Neal.NEAL1\Application Data\Mozilla\Firefox\Profiles\6yap86dl.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-^??????



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-01 15:19
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(680)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(3960)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\System32\CTsvcCDA.exe
c:\program files\Common Files\EPSON\EBAPI\eEBSVC.exe
c:\windows\system32\nvsvc32.exe
c:\windows\System32\MsPMSPSv.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RunDLL32.exe
.
**************************************************************************
.
Completion time: 2010-02-01 15:25:10 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-01 20:25
ComboFix2.txt 2010-02-01 16:49
ComboFix3.txt 2010-01-22 02:23

Pre-Run: 52,570,738,688 bytes free
Post-Run: 52,530,659,328 bytes free

- - End Of File - - 72377CC653955CFB0BA6C38B26C361B1



Malwarebytes' Anti-Malware 1.44
Database version: 3674
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

2/1/2010 4:04:51 PM
mbam-log-2010-02-01 (16-04-51).txt

Scan type: Quick Scan
Objects scanned: 150964
Time elapsed: 3 minute(s), 22 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

#8 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:42 AM

Posted 01 February 2010 - 08:14 PM

Hello.

Download and Run SystemLook

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it. (If you are using Vista, please right-click and select run as administartor)
  • A blank Windows shall open with the title "SystemLook v1.0-by Jpshortstuff".
  • Copy and Paste the content of the following codebox into the main textfield under "File":
    CODE
    :dir
    c:\windows\system32\drivers /w*
  • Please Confirm everything is copied and Pasted as I have provided above
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan.
  • Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
2nd Note: The scan may take a while from several seconds to a minute or more depending on the number of files you have and how fast your computer can perform the task


Run ESET Online Scan
  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the icon on your desktop.
  4. Check
  5. Click the button.
  6. Accept any security warnings from your browser.
  7. Check
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push
  11. Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  12. Push the button.
  13. Push
You can refer to this animation by neomage if needed.

Take a new DDS run afterward and post back with both the DDS and Attach logs in your next reply. Also, let me know how your computer is running and if you have any more problems, issues or symptoms left.

Thanks.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#9 runner1

runner1
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:42 AM

Posted 02 February 2010 - 01:44 PM

Hi, Looks like ESET found some bad stuff. Here are the logs, thanks.

SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 13:39 on 02/02/2010 by Neal (Administrator - Elevation successful)

========== dir ==========

c:\windows\system32\drivers - Parameters: "/w*"

c:\windows\system32\drivers\Avg - Parameters: "(none)"

---Files---
avi7.avg --a--- 6061540 bytes [22:41 23/01/2010] [22:41 23/01/2010]
iavichjw.avm --a--- 113461 bytes [22:41 23/01/2010] [22:41 23/01/2010]
incavi.avm --a--- 54983659 bytes [22:41 23/01/2010] [14:49 02/02/2010]
microavi.avg --a--- 142495 bytes [22:41 23/01/2010] [22:41 23/01/2010]
miniavi.avg --a--- 492629 bytes [22:41 23/01/2010] [22:41 23/01/2010]

---Folders---
None found.

c:\windows\system32\drivers\DISDN - Parameters: "(none)"

---Files---
None found.

---Folders---
None found.

c:\windows\system32\drivers\ETC - Parameters: "(none)"

---Files---
hosts --a--- 27 bytes [16:23 16/07/2003] [20:19 01/02/2010]
hosts.20080503-101933.backup --a--- 734 bytes [14:19 03/05/2008] [16:23 16/07/2003]
hosts.20090123-153859.backup -ra--- 236669 bytes [20:38 23/01/2009] [14:19 03/05/2008]
hosts.20090209-110153.backup -ra--- 291684 bytes [16:01 09/02/2009] [20:39 23/01/2009]
hosts.20100127-102346.backup --a--- 27 bytes [15:23 27/01/2010] [02:18 22/01/2010]
lmhosts.sam --a--c 3683 bytes [16:26 16/07/2003] [16:26 16/07/2003]
networks --a--c 407 bytes [16:32 16/07/2003] [16:32 16/07/2003]
protocol --a--c 799 bytes [16:35 16/07/2003] [16:35 16/07/2003]
services --a--c 7116 bytes [16:38 16/07/2003] [16:38 16/07/2003]

---Folders---
None found.

-=End Of File=-

C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\WinAgentwu.zip Win32/Bagle.gen.zip worm cleaned by deleting - quarantined
C:\Program Files\eParentalControl\smss.exe probably unknown NewHeur_PE virus deleted - quarantined
C:\System Volume Information\_restore{9DBF6563-8D2C-4D32-8C47-75D203047CF8}\RP6\A0002871.exe probably unknown NewHeur_PE virus deleted - quarantined

DDS (Ver_09-12-01.01) - NTFSx86
Run by Neal at 13:47:00.05 on Tue 02/02/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1123 [GMT -5:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Picasa\PicasaMediaDetector.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9SA.EXE
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Documents and Settings\Neal.NEAL1\Desktop\SystemLook.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Neal.NEAL1\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.spiritdaily.com/
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
TB: {C7768536-96F8-4001-B1A2-90EE21279187} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [diagent] "c:\program files\creative\sblive\diagnostics\diagent.exe" startup
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [LifeScape Media Detector] c:\program files\picasa\PicasaMediaDetector.exe
mRun: [EPSON Stylus Pro 9600] c:\windows\system32\spool\drivers\w32x86\3\E_S10IC2.EXE /P21 "EPSON Stylus Pro 9600" /O6 "USB002" /M "Stylus Pro 9600"
mRun: [EPSON Stylus Photo R2400] c:\windows\system32\spool\drivers\w32x86\3\E_FATI9SA.EXE /P24 "EPSON Stylus Photo R2400" /O6 "USB003" /M "Stylus Photo R2400"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE
mPolicies-explorer: <NO NAME> =
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: {9BAF1FF0-E09D-4713-92C1-C281420C6CDE} = 207.69.188.185 207.69.188.186
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: avgrsstarter - avgrsstx.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\neal~1.nea\applic~1\mozilla\firefox\profiles\6yap86dl.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll

============= SERVICES / DRIVERS ===============

R0 AVG Anti-Rootkit;AVG Anti-Rootkit;c:\windows\system32\drivers\avgarkt.sys [2007-1-31 5632]
R1 AvgArCln;Avg Anti-Rootkit Clean Driver;c:\windows\system32\drivers\AvgArCln.sys [2010-1-20 3968]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-1-23 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-1-23 28424]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-1-23 360584]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-1-5 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-1-5 74480]
R2 a2free;a-squared Free Service;c:\program files\a-squared free\a2service.exe [2010-1-27 1858144]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-1-23 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-1-23 285392]
S1 a59S5t2;a59S5t2;\??\c:\windows\system32\drivers\a59s5t2.sys --> c:\windows\system32\drivers\a59S5t2.sys [?]
S3 Aic7es;Aic7es;c:\windows\system32\label.exe [2003-7-16 9728]
S3 BW2NDIS5;BW2NDIS5;c:\windows\system32\drivers\bw2ndis5.sys --> c:\windows\system32\drivers\BW2NDIS5.sys [?]
S3 Evcpadxvtsts;Evcpadxvtsts;c:\windows\system32\drivers\fdc.sys [2003-7-16 27392]
S3 Imapnrye;Imapnrye;c:\windows\system32\ntkrnlpa.exe [2002-8-28 2066048]
S3 Mtisocn5;Mtisocn5;c:\windows\system32\drivers\ftdisk.sys [2003-7-16 125056]
S3 Pamotient;Pamotient;c:\windows\system32\drivers\ipnat.sys [2003-7-16 152832]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-1-5 7408]

=============== Created Last 30 ================

2010-02-02 15:44:23 0 d-----w- c:\program files\ESET
2010-01-29 19:55:41 109248 ----a-w- c:\windows\system32\MSWINSCK.OCX
2010-01-29 19:55:40 0 d-----w- c:\program files\eParentalControl
2010-01-29 19:55:40 0 d-----w- c:\program files\Accessories
2010-01-29 19:55:03 180224 ----a-w- c:\windows\system32\cpreg.dll
2010-01-29 19:55:03 180224 ----a-w- c:\windows\cpreg.dll
2010-01-29 19:15:40 4286 ----a-w- c:\windows\system32\sentrylite.ico
2010-01-29 19:15:30 258 ----a-w- c:\windows\system32\suntfs.nfx
2010-01-29 18:30:05 8672 ----a-w- c:\windows\system32\spnetrm.nfx
2010-01-29 18:30:05 8672 ----a-w- c:\windows\system32\sbnetkey.sys
2010-01-28 02:21:01 0 d-----w- c:\docume~1\alluse~1.win\applic~1\SUPERAntiSpyware.com
2010-01-28 02:20:36 0 d-----w- c:\program files\SUPERAntiSpyware
2010-01-28 02:20:36 0 d-----w- c:\docume~1\neal~1.nea\applic~1\SUPERAntiSpyware.com
2010-01-28 02:20:01 0 d-----w- c:\program files\common files\Wise Installation Wizard
2010-01-28 01:14:11 0 d-----w- c:\program files\a-squared Free
2010-01-27 20:30:25 54156 ---ha-w- c:\windows\QTFont.qfn
2010-01-27 20:30:25 1409 ----a-w- c:\windows\QTFont.for
2010-01-23 22:41:49 0 d-----w- C:\$AVG
2010-01-23 22:41:39 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-23 22:41:39 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-01-23 22:41:31 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-23 22:41:22 0 d-----w- c:\windows\system32\drivers\Avg
2010-01-23 22:41:20 0 d-----w- c:\docume~1\alluse~1.win\applic~1\AVG Security Toolbar
2010-01-23 22:39:56 0 d-----w- c:\docume~1\alluse~1.win\applic~1\avg9
2010-01-23 14:50:04 0 ----a-w- c:\windows\system32\drivers\^??????.sys
2010-01-22 02:03:14 0 d-sha-r- C:\cmdcons
2010-01-22 01:45:24 0 d-----w- c:\windows\system32\LogFiles
2010-01-22 01:43:09 98816 ----a-w- c:\windows\sed.exe
2010-01-22 01:43:09 77312 ----a-w- c:\windows\MBR.exe
2010-01-22 01:43:09 261632 ----a-w- c:\windows\PEV.exe
2010-01-22 01:43:09 161792 ----a-w- c:\windows\SWREG.exe
2010-01-21 01:45:20 0 d-----w- c:\docume~1\neal~1.nea\applic~1\Malwarebytes
2010-01-21 01:45:15 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-21 01:45:13 0 d-----w- c:\docume~1\alluse~1.win\applic~1\Malwarebytes
2010-01-21 01:45:12 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-21 01:45:12 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-21 01:41:18 3968 ----a-w- c:\windows\system32\drivers\AvgArCln.sys

==================== Find3M ====================

2008-10-01 00:47:52 172 ----a-w- c:\program files\ThumbsReg.exe.log
2008-09-30 15:34:47 8562 ----a-w- c:\program files\Thumbs.typ
2008-09-30 15:34:47 672 ----a-w- c:\program files\thumbs.tdo
2008-09-30 15:34:47 14009 ----a-w- c:\program files\Thumbs.flt
2007-11-29 20:00:34 8859304 ----a-w- c:\program files\Thumbs.exe
2007-11-29 19:58:46 216744 ----a-w- c:\program files\cswshlex.dll
2007-11-29 19:58:02 278184 ----a-w- c:\program files\Thumbspriv64.exe
2007-11-29 19:58:02 114344 ----a-w- c:\program files\Thumbspriv.exe
2007-11-29 19:57:52 174760 ----a-w- c:\program files\ThumbsReg64.exe
2007-11-29 19:57:52 143016 ----a-w- c:\program files\ThumbsReg.exe
2007-11-08 17:36:40 183976 ----a-w- c:\program files\TpView.exe
2007-10-27 07:16:30 2658304 ----a-w- c:\program files\PolyImagepro.dll
2007-10-24 20:48:34 83112 ----a-w- c:\program files\cswshlex64.dll
2007-10-24 20:11:40 65192 ----a-w- c:\program files\tpsndrdr.ax
2007-10-23 18:28:16 551424 ----a-w- c:\program files\Thumbs.sef
2007-09-06 19:58:32 453153 ----a-w- c:\program files\toolbar_sample.png
2007-01-23 16:36:00 26906 ----a-w- c:\program files\Notes70sp1.htm
2007-01-09 15:47:44 5337 ----a-w- c:\program files\Exifval.dat
2006-08-23 17:34:00 176128 ----a-w- c:\program files\Dzip32.dll
2006-08-23 17:34:00 143360 ----a-w- c:\program files\Dunzip32.dll
2004-09-28 20:41:14 18575 ----a-w- c:\program files\Notes70.htm
2003-07-15 19:17:06 24576 ----a-w- c:\program files\Cswole.dll
2003-02-20 16:01:04 267264 ----a-w- c:\program files\LTDIS13n.dll
2003-02-20 15:29:46 271360 ----a-w- c:\program files\LFJ2K13n.dll
2003-02-20 15:27:32 33280 ----a-w- c:\program files\lfwmp13n.dll
2003-02-20 15:24:54 400384 ----a-w- c:\program files\LFCMP13n.DLL
2003-02-20 15:20:30 1684992 ----a-w- c:\program files\LTCLR13n.dll
2003-02-20 15:19:12 25600 ----a-w- c:\program files\lfxwd13n.dll
2003-02-20 15:19:06 47104 ----a-w- c:\program files\lfXpm13n.dll
2003-02-20 15:19:00 45056 ----a-w- c:\program files\lfXbm13n.dll
2003-02-20 15:18:52 19968 ----a-w- c:\program files\lfwfx13n.dll
2003-02-20 15:17:46 31744 ----a-w- c:\program files\lflmb13n.dll
2003-02-20 15:17:30 19968 ----a-w- c:\program files\lfitg13n.dll
2003-02-20 15:17:14 48128 ----a-w- c:\program files\lfica13n.dll
2003-02-20 15:17:04 84480 ----a-w- c:\program files\lffpx13n.dll
2003-02-20 15:16:48 20992 ----a-w- c:\program files\lfCUT13n.dll
2003-02-20 15:16:14 23040 ----a-w- c:\program files\lfawd13n.dll
2003-02-20 15:15:52 73216 ----a-w- c:\program files\lffax13n.dll
2003-02-20 15:15:12 446464 ----a-w- c:\program files\ltimg13n.dll
2003-02-20 15:14:16 141824 ----a-w- c:\program files\ltfil13n.DLL
2003-02-20 15:14:00 445952 ----a-w- c:\program files\ltkrn13n.dll
2003-02-20 03:04:04 205824 ----a-w- c:\program files\ltefx13n.dll
2002-09-11 14:26:52 63730 -c--a-w- c:\program files\viewsonicinstruct_xp.pdf
2002-07-26 20:02:06 153088 ----a-w- c:\program files\UNWISE.EXE
2002-06-26 16:17:36 6144 ----a-w- c:\program files\awdcxc32.dll
2002-06-26 16:17:36 26624 ----a-w- c:\program files\awresx32.dll
2002-06-26 16:17:36 24576 ----a-w- c:\program files\awcodc32.dll
2002-06-26 16:17:36 11776 ----a-w- c:\program files\awdenc32.dll
2002-06-26 16:17:36 10240 ----a-w- c:\program files\awview32.dll
2001-06-14 14:30:50 1044480 ----a-w- c:\program files\Roboex32.dll
2001-01-22 14:30:34 61440 ----a-w- c:\program files\TpCmd.exe
2000-08-04 18:25:30 49152 ----a-w- c:\program files\Inetwh32.dll
2000-04-12 19:28:12 118784 ----a-w- c:\program files\lfkodak.dll
2000-04-12 19:24:10 338944 ----a-w- c:\program files\lffpx7.dll
1999-01-26 16:20:24 32768 ----a-w- c:\program files\Cvt3.exe
1998-08-17 03:04:10 269312 ----a-w- c:\program files\Fpxacc.dll
1998-07-23 15:42:54 172032 ----a-w- c:\program files\Tpdb.dll
1998-07-23 15:39:12 44032 ----a-w- c:\program files\Cswrt.dll
1998-03-30 08:00:00 434176 ----a-w- c:\program files\DC120v10_32.dll
1996-07-17 16:45:40 227840 ----a-w- c:\program files\Deco_32.dll
1995-09-30 02:06:48 312832 ----a-w- c:\program files\Msvcrt40.dll
1995-07-31 16:44:46 212480 ----a-w- c:\program files\Pcdlib32.dll
1995-07-01 01:01:00 56832 ----a-w- c:\program files\Im30dxf.dil
2008-08-14 15:59:25 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008081420080815\index.dat

============= FINISH: 13:47:47.05 ===============

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 4/23/2005 4:05:54 PM
System Uptime: 2/2/2010 9:42:25 AM (4 hours ago)

Motherboard: Dell Computer Corp. | | 02Y832
Processor: Intel® Pentium® 4 CPU 2.66GHz | Microprocessor | 2660/533mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 112 GiB total, 48.844 GiB free.
D: is CDROM (CDFS)
E: is CDROM ()
F: is FIXED (NTFS) - 699 GiB total, 405.711 GiB free.

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP1: 1/27/2010 8:57:09 AM - System Checkpoint
RP2: 1/27/2010 9:07:53 AM - Avg8 Update
RP3: 1/27/2010 9:20:35 PM - Installed SUPERAntiSpyware Free Edition
RP4: 1/29/2010 10:20:52 AM - System Checkpoint
RP5: 1/30/2010 11:31:18 AM - System Checkpoint
RP6: 2/1/2010 2:28:37 PM - System Checkpoint

==== Installed Programs ======================


a-squared Free 4.5
ABBYY FineReader 5.0 Sprint
Ad-aware 6 Personal
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Illustrator 8.0
Adobe Photoshop CS
Adobe Reader 7.1.0
Apple Software Update
AVG Anti-Rootkit Free
AVG Free 9.0
CorelDRAW 10
Dell ResourceCD
EPSON Printer Software
EPSON Scan
EPSON SPR2400 Reference Guide
ESET Online Scanner v3
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
ICC Color Profiles
Intel® PRO Network Adapters and Drivers
Macromedia Dreamweaver MX 2004
Macromedia Extension Manager
Malwarebytes' Anti-Malware
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Streets and Trips 2002
Microsoft Visual C++ 2005 Redistributable
Microsoft Word 2002
Microsoft Works 2003 Setup Launcher
Microsoft Works 7.0
Microsoft Works Suite Add-in for Microsoft Word
Modem Helper
Mozilla Firefox (3.0.5)
Netscape Navigator (9.0b2)
NetWaiting
Nikon Message Center
NVIDIA Drivers
PENTAX Digital Camera Utility
Picasa
PowerDVD
QuickTime
RealPlayer
SeaTools Enterprise
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
SilverFast Epson
SilverFast Epson (Photoshop Plugin)
SilverFast Epson (TWAIN Plugin)
Soft Voice SoftRing Modem with SmartSP
Sonic DLA
Sonic MyDVD
Sonic RecordNow!
Sonic Update Manager
Sound Blaster Live!
Spybot - Search & Destroy
SUPERAntiSpyware Free Edition
ThumbsPlus version 7 SP2
TotalAccess Smart Installer
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
V92 PCI Voice Faxmodem
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage v1.3.0254.0
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows XP Service Pack 3
WinZip
Works Suite OS Pack

==== Event Viewer Messages From Past Week ========

2/1/2010 11:39:36 AM, error: Service Control Manager [7034] - The EpsonBidirectionalService service terminated unexpectedly. It has done this 1 time(s).
2/1/2010 11:00:23 AM, error: Print [19] - Sharing printer failed + 1722, Printer EPSON Stylus Photo R2400 share name EPSON_2400.
1/29/2010 2:15:40 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000243' while processing the file 'lmrgcachem.sam' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume.
1/26/2010 9:27:20 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
1/26/2010 2:59:04 PM, error: Print [19] - Sharing printer failed + 1722, Printer EPSON Stylus Pro 9600 share name EPSON_9600.
1/26/2010 2:59:01 PM, error: Service Control Manager [7000] - The Swprdr service failed to start due to the following error: The system cannot find the file specified.
1/26/2010 2:59:01 PM, error: Service Control Manager [7000] - The Splitlrtvar service failed to start due to the following error: The system cannot find the path specified.
1/26/2010 2:59:01 PM, error: Service Control Manager [7000] - The Pamotient service failed to start due to the following error: The filename, directory name, or volume label syntax is incorrect.
1/26/2010 2:59:01 PM, error: Service Control Manager [7000] - The Mtisocn5 service failed to start due to the following error: The filename, directory name, or volume label syntax is incorrect.
1/26/2010 2:59:01 PM, error: Service Control Manager [7000] - The Isaenrrv service failed to start due to the following error: The system cannot find the path specified.
1/26/2010 2:59:01 PM, error: Service Control Manager [7000] - The Aic7es service failed to start due to the following error: The system cannot find the file specified.
1/26/2010 11:04:43 PM, error: System Error [1003] - Error code 1000008e, parameter1 c0000005, parameter2 00000000, parameter3 b61fa9f8, parameter4 00000000.

==== End Of File ===========================

Edited by runner1, 02 February 2010 - 01:50 PM.


#10 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:42 AM

Posted 02 February 2010 - 04:37 PM

Hello.

The log looks good overall, but do you know what this file is:
c:\windows\system32\drivers\^??????.sys

That file appears to be unicoded and thus can't be displayed correctly. May be some application you installed. If you can find a file similar to that I would delete it.

Other than that it looks good/ Any problems left?

Your FireFox is outdated though, so I suggest you update that.
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#11 runner1

runner1
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:42 AM

Posted 02 February 2010 - 08:19 PM

I'm not sure what that file is (^??????.sys). I will update firefox, thanks.

Thanks, very much. My computer does seem to be working fine now. Your willingness to take the time to deal with these issues is most appreciated.

MANY THANKS!!!!!!!!!!!!!!!

Runner

#12 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:42 AM

Posted 02 February 2010 - 08:39 PM

You're very welcome.

Glad I could help. Let me know once you have completed that and if all is good on your side then we can warp up here.
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#13 runner1

runner1
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:01:42 AM

Posted 03 February 2010 - 06:22 PM

I updated Firefox and everything is working great. I can't thank you enough for your help, EB. I guess that's a wrap!

THANKS!!!

Runner

#14 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:42 AM

Posted 04 February 2010 - 08:13 PM

Not quite, below is the real wrap up part. ;)

Please follow/read the steps below to remove the tools we used and for some more information. smile.gif


Uninstall ComboFix

Remove Combofix now that we're done with it.
  • Please press the Windows Key and R on your keyboard. This will bring up the Run... command.
  • Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between the "x" and "/")
  • Please follow the prompts to uninstall Combofix.
  • You will then recieve a message saying Combofix was uninstalled successfully once it's done uninstalling itself.
This will uninstall Combofix and anything assoicated with it.

Download and Run OTC

We will now remove the tools we used during this fix using OTC.
  • Download OTC by OldTimer and save it to your desktop.
  • Double click icon to start the program. If you are using Vista, please right-click and choose run as administrator
  • Then Click the big button.
  • You will get a prompt saying "Being Cleanup Process". Please select Yes.
  • Restart your computer when prompted.

System A bit Slow? Try StartupLight

You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve preformance.

If that does not work, you can try the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware.


Congratulations! You now appear clean! specool.gif

Now that you are clean, please follow and read some of the prevention tips below.

Preventing Infections in the Future


Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

Some of the main things you should consider to perform/read are:
  • Disabling Autorun/Play on Flash-Drive/Removable Drives
  • Avoid gaming sites, underground web pages, pirated software sites, and Peer to Peer Programs
  • Keep Windows Updated through going to Windows Updates
  • Updating Non-Microsoft Programs
  • Keeping Security softwares updated

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.

Update all programs regularly - Make sure you update all the programs you have installed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.

Glad I was able to help and thank you for choosing Bleeping Computer as you malware removal source.
Don't forget to tell your friends about us and Good luck thumbup2.gif


If you have no more questions, comments or problems please tell us, so we can close off the topic.

Thanks smile.gif

With Regards,
Extremeboy

Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#15 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:42 AM

Posted 12 February 2010 - 04:33 PM

Hello.

Since the problem appears to be resolved, this topic is now Closed. Glad we could help smile.gif
If you need this topic reopened, please Send Me a Message. In your message please include the address of this thread in your request.

This applies only to the original topic starter

Everyone else please start a new topic.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users