Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Seems I have a few trojans I can't get rid of


  • This topic is locked This topic is locked
25 replies to this topic

#1 Starion89

Starion89

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 26 March 2010 - 05:45 PM

Hi All,

I forgot to re-enable my firewall for a day and what do you know, a bunch of trojans found their way into my computer. I've run every anti-virus I know of and then some. A bunch of the symptoms have disappeared, but I still get the occasional slowed computer w/ pop up windows. I'd like to get this thing clean and this site has helped me before, so any more help is much appreciated. Here is my HijackThis log:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:41:32 PM, on 3/26/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\AVG\AVG9\avgfws9.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\IObit\IObit Security 360\IS360srv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\SolidWorks\COSMOS\FloWorks\binCFW\StandAloneSlv.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Sun\SDK\jdk\bin\javaw.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Desktop Search\WindowsSearchFilter.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {01c8cf3f-5ee6-4a53-9db6-3d2207716436} - jomofusi.dll (file missing)
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [ewrgetuj] C:\DOCUME~1\Steve\LOCALS~1\Temp\geurge.exe
O4 - HKLM\..\Run: [QuickTime Task] "c:\program files\quicktime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [IObit Security 360] "C:\Program Files\IObit\IObit Security 360\IS360tray.exe" /autostart
O4 - HKLM\..\Run: [sadahamojo] Rundll32.exe "tesiliva.dll",s
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Steve\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AdobeUpdater6] "C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe"
O4 - HKCU\..\Run: [COM+ Manager] "C:\Documents and Settings\Steve\.COMMgr\complmgr.exe"
O4 - HKCU\..\Run: [YVIBBBHA8C] c:\docume~1\steve\locals~1\temp\xp0 .exe
O4 - HKUS\S-1-5-19\..\Run: [sadahamojo] Rundll32.exe "tesiliva.dll",s (User '?')
O4 - HKUS\S-1-5-20\..\Run: [sadahamojo] Rundll32.exe "tesiliva.dll",s (User '?')
O4 - HKUS\S-1-5-21-2025429265-1500820517-682003330-1004\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden (User '?')
O4 - HKUS\S-1-5-21-2025429265-1500820517-682003330-1004\..\Run: [AdobeUpdater6] "C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe" (User '?')
O4 - HKUS\S-1-5-21-2025429265-1500820517-682003330-1004\..\Run: [COM+ Manager] "C:\Documents and Settings\Steve\.COMMgr\complmgr.exe" (User '?')
O4 - HKUS\S-1-5-21-2025429265-1500820517-682003330-1004\..\Run: [YVIBBBHA8C] c:\docume~1\steve\locals~1\temp\xp0 .exe (User '?')
O4 - S-1-5-21-2025429265-1500820517-682003330-1004 Startup: SDK Tray Menu.lnk = ? (User '?')
O4 - Startup: SDK Tray Menu.lnk = ?
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O17 - HKLM\System\CCS\Services\Tcpip\..\{CFD1CF89-6048-411F-BF11-089E23AAB58A}: NameServer = 217.23.14.75,4.2.2.1,192.168.2.1 68.87.75.198
O17 - HKLM\System\CCS\Services\Tcpip\..\{F9D43D8E-99AF-43AB-A99C-225CB4DE1229}: NameServer = 217.23.14.75,4.2.2.1
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: app_dll.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IS360service - IObit - C:\Program Files\IObit\IObit Security 360\IS360srv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Solver for COSMOSFloWorks 2007 - Unknown owner - C:\Program Files\SolidWorks\COSMOS\FloWorks\binCFW\StandAloneSlv.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe

--
End of file - 14030 bytes


Thanks Again

BC AdBot (Login to Remove)

 


#2 Starion89

Starion89
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 28 March 2010 - 04:51 PM

Here are a few other pieces of information:

Since the popups/slow downs/search engine redirecting has started, I noticed these 3 messages come up on startup that never used to come up before:

1. tesiliva.dll
2. Mouse Suite 98 Daemon
3. Windows Desktop Search

Hopefully that will help to narrow down my problem

#3 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:03:10 PM

Posted 28 March 2010 - 11:09 PM

Hi again smile.gif


You may want to keep the link to this topic in your favourites. Alternatively, you can click the button at the top bar of this topic and Track this Topic. The topics you are tracking can be found here.

Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
  • Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
  • Old topics are closed after 3 days with no reply, and working topics are closed after 5 days. If for any reason you cannot complete instructions within that time, that's fine, just post back here so that we know you're still here.
  • Please set your system to show all files.
    Click Start, open My Computer, select the Tools menu and click Folder Options.
    Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
    Uncheck: Hide file extensions for known file types
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm.





  1. Please download OTL from one of the following mirrors:
  2. Save it to your desktop.
  3. Double click on the icon on your desktop.
  4. Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    safebootminimal
    safebootnetwork
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
  5. Push the Quick Scan button.
  6. Two reports will open, copy and paste them in a reply here:
    • OTL.txt <-- Will be opened
    • Extra.txt <-- Will be minimized





Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.


  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.
-- If you encounter any problems, try running GMER in Safe Mode.
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#4 Starion89

Starion89
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 29 March 2010 - 05:22 PM

Hey Tom,

So I couldn't get GMER to run a full scan without locking up on me. I tried about 5 times and finally just saved what I could. OTL also only gave me one log dry.gif

But anyways I hope they are good for something...

OTL:

OTL logfile created on: 3/29/2010 5:54:02 PM - Run 3
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Steve\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 75.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 174.47 Gb Total Space | 78.78 Gb Free Space | 45.15% Space Free | Partition Type: NTFS
Drive D: | 11.84 Gb Total Space | 2.00 Gb Free Space | 16.86% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: STEVE-LAPTOP
Current User Name: Steve
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan

========== Processes (SafeList) ==========

PRC - [2010/03/29 17:53:25 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Steve\My Documents\Downloads\OTL(3).exe
PRC - [2010/03/29 17:17:55 | 000,027,648 | ---- | M] () -- C:\WINDOWS\system32\ico.exe
PRC - [2010/03/21 23:42:00 | 000,818,256 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2010/03/21 23:41:59 | 001,263,728 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2010/03/14 17:28:45 | 000,508,184 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/03/14 17:28:42 | 000,308,064 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2010/03/14 17:28:06 | 002,325,816 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgfws9.exe
PRC - [2010/03/14 17:28:05 | 000,710,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/03/14 17:28:03 | 001,086,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/03/10 00:54:13 | 000,053,346 | ---- | M] (Sun Microsystems, Inc.) -- C:\Sun\SDK\jdk\bin\javaw.exe
PRC - [2010/02/18 16:57:07 | 000,908,248 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/12/24 17:02:30 | 000,311,568 | ---- | M] (IObit) -- C:\Program Files\IObit\IObit Security 360\is360srv.exe
PRC - [2007/06/13 06:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/04/02 11:38:10 | 000,606,208 | ---- | M] () -- C:\Program Files\SolidWorks\COSMOS\FloWorks\binCFW\StandAloneSlv.exe
PRC - [2006/11/02 17:17:14 | 000,895,088 | ---- | M] (PC Tools Research Pty Ltd) -- C:\Program Files\Spyware Doctor\sdhelp.exe
PRC - [2005/03/14 13:05:02 | 000,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe


========== Modules (SafeList) ==========

MOD - [2010/03/29 17:53:25 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Steve\My Documents\Downloads\OTL(3).exe
MOD - [2010/03/27 21:06:47 | 000,093,696 | ---- | M] () -- C:\WINDOWS\system32\app_dll.dll
MOD - [2006/10/31 17:29:50 | 000,101,448 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\tools\swpg.DAT
MOD - [2006/08/25 11:45:55 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2010/03/21 23:41:59 | 001,263,728 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2010/03/14 17:28:42 | 000,308,064 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2010/03/14 17:28:36 | 005,888,008 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] -- C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2010/03/14 17:28:06 | 002,325,816 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgfws9.exe -- (avgfws9)
SRV - [2010/03/10 23:21:18 | 000,079,360 | ---- | M] (SolidWorks) [On_Demand | Stopped] -- C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe -- (SolidWorks Licensing Service)
SRV - [2009/12/24 17:02:30 | 000,311,568 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files\IObit\IObit Security 360\is360srv.exe -- (IS360service)
SRV - [2008/12/16 02:43:54 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2007/04/02 11:38:10 | 000,606,208 | ---- | M] () [Auto | Running] -- C:\Program Files\SolidWorks\COSMOS\FloWorks\binCFW\StandAloneSlv.exe -- (Remote Solver for COSMOSFloWorks 2007)
SRV - [2006/11/02 17:17:14 | 000,895,088 | ---- | M] (PC Tools Research Pty Ltd) [Auto | Running] -- C:\Program Files\Spyware Doctor\sdhelp.exe -- (SDhelper)
SRV - [2005/03/14 13:05:02 | 000,069,632 | ---- | M] (HP) [Auto | Running] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.8.20091209.4
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0


FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/07/20 22:44:24 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/18 16:57:11 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/03/25 01:22:17 | 000,000,000 | ---D | M]

[2008/09/02 22:52:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\Mozilla\Extensions
[2010/03/27 21:15:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\Mozilla\Firefox\Profiles\qca70k8b.default\extensions
[2010/01/27 02:29:25 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\Steve\Application Data\Mozilla\Firefox\Profiles\qca70k8b.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2010/03/27 21:15:21 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/02/27 19:21:02 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {01c8cf3f-5ee6-4a53-9db6-3d2207716436} - C:\WINDOWS\System32\jomofusi.dll ()
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll ()
O2 - BHO: (dsWebAllowBHO Class) - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dll (Microsoft Corporation)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (PCTools Site Guard) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\Program Files\Spyware Doctor\tools\iesdsg.dll (PC Tools)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (PCTools Browser Monitor) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\Program Files\Spyware Doctor\tools\iesdpb.dll (PC Tools)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ewrgetuj] C:\Documents and Settings\Steve\Local Settings\temp\geurge.exe ()
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe ()
O4 - HKLM..\Run: [IObit Security 360] C:\Program Files\IObit\IObit Security 360\IS360tray.exe ()
O4 - HKLM..\Run: [Mouse Suite 98 Daemon] C:\WINDOWS\System32\ico.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [QuickTime Task] C:\program files\quicktime\qttask .exe ()
O4 - HKLM..\Run: [sadahamojo] C:\WINDOWS\System32\tesiliva.dll ()
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\syntpstart.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe ()
O4 - HKCU..\Run: [AdobeUpdater6] C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe ()
O4 - HKCU..\Run: [COM+ Manager] C:\Documents and Settings\Steve\.COMMgr\complmgr.exe ()
O4 - HKCU..\Run: [YVIBBBHA8C] c:\Documents and Settings\Steve\Local Settings\temp\xp0 .exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Steve\Start Menu\Programs\Startup\SDK Tray Menu.lnk = C:\Sun\SDK\jdk\bin\javaw.exe (Sun Microsystems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\Program Files\Spyware Doctor\tools\iesdpb.dll (PC Tools)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_10)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 68.87.75.198
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (app_dll.dll) - C:\WINDOWS\System32\app_dll.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\Steve\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Steve\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O27 - HKLM IFEO\MpCmdRun.exe: Debugger - C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\MsMpEng.exe: Debugger - C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\msseces.exe: Debugger - C:\WINDOWS\system32\svchost.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/07/09 07:57:29 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2005/09/11 11:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ]
O33 - MountPoints2\{74ef8b7f-3124-11df-b6e3-001fe16c7ade}\Shell - "" = AutoRun
O33 - MountPoints2\{74ef8b7f-3124-11df-b6e3-001fe16c7ade}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{74ef8b7f-3124-11df-b6e3-001fe16c7ade}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
O33 - MountPoints2\{7a0b44d0-cf35-11de-b6b2-001e68763d8c}\Shell - "" = AutoRun
O33 - MountPoints2\{7a0b44d0-cf35-11de-b6b2-001e68763d8c}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{7a0b44d0-cf35-11de-b6b2-001e68763d8c}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2008/07/08 22:03:00 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: Lavasoft Ad-Aware Service - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: Lavasoft Ad-Aware Service - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sermouse.sys - Driver
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vga.sys - Driver
SafeBootNet: {1a3e09be-1e45-494b-9174-d7385b45bbf5} -
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (15203041766539264)

========== Files/Folders - Created Within 14 Days ==========

[2010/03/28 21:25:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2010/03/28 21:25:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/03/28 21:25:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Sun
[2010/03/28 20:31:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Real
[2010/03/26 20:30:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\PC Tools
[2010/03/26 19:27:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/03/25 22:36:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/03/25 22:36:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/03/25 21:45:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Steve\Desktop\TMRBLog
[2010/03/25 21:45:29 | 000,161,296 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2010/03/25 21:45:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Steve\Desktop\log
[2010/03/25 21:45:19 | 002,457,600 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Steve\Desktop\RootkitBuster.exe
[2010/03/25 10:39:17 | 000,000,000 | ---D | C] -- C:\Program Files\Loaris
[2010/03/25 10:35:40 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/03/25 10:22:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\IObit
[2010/03/25 10:22:01 | 000,000,000 | ---D | C] -- C:\Program Files\IObit
[2010/03/25 07:44:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/03/25 01:54:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/03/25 00:32:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/03/25 00:27:50 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Steve\.COMMgr
[2010/03/25 00:27:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Steve\Application Data\618914D8062DA2F74598D85E05FC4296
[2010/01/05 21:33:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/01/05 21:28:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/01/05 21:28:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2008/12/27 04:00:18 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2008/10/08 19:56:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2008/09/23 12:10:42 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2005/09/24 01:49:16 | 000,012,288 | ---- | C] (Hewlett-Packard Development Company, L.P.) -- C:\WINDOWS\Fonts\RandFont.dll
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 14 Days ==========

[2099/01/01 12:00:00 | 000,193,024 | -HS- | M] () -- C:\WINDOWS\System32\sodoruvu.exe
[2099/01/01 12:00:00 | 000,110,592 | -HS- | M] () -- C:\WINDOWS\System32\rujaheyi.exe
[2099/01/01 12:00:00 | 000,083,456 | -HS- | M] () -- C:\WINDOWS\System32\wosarako.exe
[2099/01/01 12:00:00 | 000,083,456 | -HS- | M] () -- C:\WINDOWS\System32\jivagaki.exe
[2099/01/01 12:00:00 | 000,070,144 | -HS- | M] () -- C:\WINDOWS\System32\mesawunu.dll
[2099/01/01 12:00:00 | 000,065,536 | -HS- | M] () -- C:\WINDOWS\System32\tesiliva.dll
[2099/01/01 12:00:00 | 000,065,536 | -HS- | M] () -- C:\WINDOWS\System32\jomofusi.dll
[2010/03/29 17:55:36 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2025429265-1500820517-682003330-1004UA.job
[2010/03/29 17:53:12 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/03/29 17:52:37 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At24.job
[2010/03/29 17:52:37 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At23.job
[2010/03/29 17:52:37 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At22.job
[2010/03/29 17:52:37 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At21.job
[2010/03/29 17:52:37 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At20.job
[2010/03/29 17:52:37 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At19.job
[2010/03/29 17:52:37 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At18.job
[2010/03/29 17:52:37 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At17.job
[2010/03/29 17:52:36 | 000,027,648 | ---- | M] () -- C:\Documents and Settings\Steve\rundll32.exe
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At9.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At8.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At7.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At6.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At5.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At4.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At3.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At2.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At16.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At15.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At14.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At13.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At12.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At11.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At10.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\tasks\At1.job
[2010/03/29 17:52:25 | 000,027,648 | ---- | M] () -- C:\Documents and Settings\Steve\nwiz.exe
[2010/03/29 17:52:20 | 000,027,648 | ---- | M] () -- C:\Documents and Settings\Steve\ico.exe
[2010/03/29 17:51:36 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2010/03/29 17:50:46 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/03/29 17:50:39 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/03/29 17:50:39 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/03/29 17:50:35 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/03/29 17:50:31 | 3152,986,112 | -HS- | M] () -- C:\hiberfil.sys
[2010/03/29 17:17:59 | 000,027,648 | ---- | M] () -- C:\WINDOWS\System32\nwiz.exe
[2010/03/29 17:17:55 | 000,027,648 | ---- | M] () -- C:\WINDOWS\System32\ico.exe
[2010/03/29 13:00:20 | 058,201,009 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/03/28 21:25:37 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/03/28 20:55:42 | 000,000,926 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2025429265-1500820517-682003330-1004Core.job
[2010/03/27 21:06:47 | 000,093,696 | ---- | M] () -- C:\WINDOWS\System32\app_dll.dll
[2010/03/27 21:03:26 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/03/26 19:22:06 | 009,175,040 | -H-- | M] () -- C:\Documents and Settings\Steve\NTUSER.DAT
[2010/03/26 19:21:44 | 000,006,456 | -H-- | M] () -- C:\WINDOWS\System32\zonikofa
[2010/03/26 18:20:31 | 000,027,648 | ---- | M] () -- C:\WINDOWS\System32\nwiz.exe.delme208
[2010/03/26 17:56:19 | 000,002,284 | ---- | M] () -- C:\Documents and Settings\Steve\Desktop\Google Chrome.lnk
[2010/03/25 22:36:58 | 000,000,552 | ---- | M] () -- C:\WINDOWS\System32\d3d8caps.dat
[2010/03/25 21:45:29 | 000,161,296 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2010/03/25 20:47:12 | 000,000,036 | ---- | M] () -- C:\Documents and Settings\Steve\Local Settings\Application Data\housecall.guid.cache
[2010/03/25 10:21:27 | 000,476,062 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/03/25 10:21:27 | 000,404,536 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/03/25 10:21:27 | 000,063,590 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/03/25 10:12:27 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Steve\ntuser.ini
[2010/03/25 09:45:30 | 000,027,648 | ---- | M] () -- C:\Documents and Settings\Steve\nwiz .exe
[2010/03/25 09:45:29 | 000,027,648 | ---- | M] () -- C:\Documents and Settings\Steve\rundll32 .exe
[2010/03/25 09:45:27 | 000,027,648 | ---- | M] () -- C:\Documents and Settings\Steve\ico .exe
[2010/03/25 00:31:35 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\app_dll.dll.235656.old
[2010/03/24 19:56:03 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/03/22 21:20:18 | 000,000,830 | -H-- | M] () -- C:\IPH.PH
[2010/03/21 23:25:14 | 000,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/03/20 22:17:23 | 000,572,937 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\iavifw.avm
[2010/03/18 18:30:26 | 000,002,231 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SolidWorks Student Edition.lnk
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2099/01/01 12:00:00 | 000,193,024 | -HS- | C] () -- C:\WINDOWS\System32\sodoruvu.exe
[2099/01/01 12:00:00 | 000,110,592 | -HS- | C] () -- C:\WINDOWS\System32\rujaheyi.exe
[2099/01/01 12:00:00 | 000,083,456 | -HS- | C] () -- C:\WINDOWS\System32\wosarako.exe
[2099/01/01 12:00:00 | 000,083,456 | -HS- | C] () -- C:\WINDOWS\System32\jivagaki.exe
[2099/01/01 12:00:00 | 000,070,144 | -HS- | C] () -- C:\WINDOWS\System32\mesawunu.dll
[2099/01/01 12:00:00 | 000,065,536 | -HS- | C] () -- C:\WINDOWS\System32\tesiliva.dll
[2099/01/01 12:00:00 | 000,065,536 | -HS- | C] () -- C:\WINDOWS\System32\jomofusi.dll
[2099/01/01 12:00:00 | 000,006,456 | -H-- | C] () -- C:\WINDOWS\System32\zonikofa
[2010/03/28 21:26:07 | 000,201,216 | -HS- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\ave.exe
[2010/03/25 22:36:58 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2010/03/25 20:47:12 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Steve\Local Settings\Application Data\housecall.guid.cache
[2010/03/25 10:16:25 | 3152,986,112 | -HS- | C] () -- C:\hiberfil.sys
[2010/03/25 09:45:30 | 000,027,648 | ---- | C] () -- C:\Documents and Settings\Steve\nwiz.exe
[2010/03/25 09:45:30 | 000,027,648 | ---- | C] () -- C:\Documents and Settings\Steve\nwiz .exe
[2010/03/25 09:45:29 | 000,027,648 | ---- | C] () -- C:\Documents and Settings\Steve\rundll32.exe
[2010/03/25 09:45:29 | 000,027,648 | ---- | C] () -- C:\Documents and Settings\Steve\rundll32 .exe
[2010/03/25 09:45:27 | 000,027,648 | ---- | C] () -- C:\Documents and Settings\Steve\ico.exe
[2010/03/25 09:45:27 | 000,027,648 | ---- | C] () -- C:\Documents and Settings\Steve\ico .exe
[2010/03/25 07:44:24 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/03/25 01:02:36 | 000,015,880 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe
[2010/03/25 00:31:34 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\app_dll.dll.235656.old
[2010/03/25 00:31:34 | 000,093,696 | ---- | C] () -- C:\WINDOWS\System32\app_dll.dll
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At9.job
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At8.job
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At7.job
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At6.job
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At5.job
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At4.job
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At3.job
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At24.job
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At23.job
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At22.job
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At21.job
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At20.job
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At2.job
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At19.job
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At18.job
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At17.job
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At16.job
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At15.job
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At14.job
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At13.job
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At12.job
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At11.job
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At10.job
[2010/03/25 00:28:32 | 000,000,380 | ---- | C] () -- C:\WINDOWS\tasks\At1.job
[2010/03/21 23:25:14 | 000,001,729 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2010/03/10 23:29:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\eDrawingOfficeAutomator.INI
[2010/02/22 00:55:14 | 000,162,304 | ---- | C] () -- C:\WINDOWS\System32\ztvunrar36.dll
[2010/02/22 00:55:14 | 000,153,088 | ---- | C] () -- C:\WINDOWS\System32\UNRAR3.dll
[2010/02/22 00:55:14 | 000,077,312 | ---- | C] () -- C:\WINDOWS\System32\ztvunace26.dll
[2010/02/22 00:55:14 | 000,075,264 | ---- | C] () -- C:\WINDOWS\System32\unacev2.dll
[2010/02/19 00:57:04 | 000,000,093 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2010/02/03 20:43:37 | 000,004,484 | ---- | C] () -- C:\WINDOWS\System32\drivers\cpuidlep.sys
[2009/09/10 17:34:49 | 000,323,584 | ---- | C] () -- C:\WINDOWS\System32\FoxImager.dll
[2009/02/12 13:07:28 | 000,000,280 | ---- | C] () -- C:\WINDOWS\System32\epoPGPsdk.dll.sig
[2008/12/27 14:20:15 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\Steve\Local Settings\Application Data\fusioncache.dat
[2008/12/25 20:12:43 | 000,000,795 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/12/25 20:11:57 | 000,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2008/12/16 03:03:00 | 002,463,976 | ---- | C] () -- C:\WINDOWS\System32\NPSWF32.dll
[2008/11/03 00:53:16 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Steve\Local Settings\Application Data\PUTTY.RND
[2008/10/20 01:24:27 | 000,000,067 | ---- | C] () -- C:\WINDOWS\Easy Video to DVD.INI
[2008/10/20 00:38:04 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/09/23 10:45:29 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/09/19 17:57:34 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008/09/19 17:55:10 | 000,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest
[2008/09/19 17:55:10 | 000,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest
[2008/09/19 17:54:18 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/09/02 11:52:22 | 000,034,304 | ---- | C] () -- C:\Documents and Settings\Steve\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/08/24 04:09:30 | 000,000,100 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2008/08/24 04:09:04 | 000,000,000 | ---- | C] () -- C:\WINDOWS\pcfriend.INI
[2008/07/09 16:11:21 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008/07/09 16:11:21 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008/07/09 16:11:21 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008/07/09 16:11:20 | 001,478,656 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008/07/09 16:06:30 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008/07/09 09:12:12 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Steve\Local Settings\Application Data\QSwitch.txt
[2008/07/09 09:12:12 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Steve\Local Settings\Application Data\DSwitch.txt
[2008/07/09 09:12:12 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Steve\Local Settings\Application Data\AtStart.txt
[2008/07/09 09:03:50 | 000,008,181 | ---- | C] () -- C:\WINDOWS\System32\Setup2k.ini
[2008/07/09 09:03:50 | 000,000,184 | ---- | C] () -- C:\WINDOWS\System32\presetup.ini
[2008/07/09 08:53:01 | 000,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2006/05/12 13:23:22 | 000,090,112 | ---- | C] () -- C:\WINDOWS\System32\btprn2k.dll
[2004/08/12 10:08:06 | 000,047,616 | ---- | C] () -- C:\WINDOWS\p6mgtz1.dll
[2002/05/15 23:29:04 | 000,000,607 | ---- | C] () -- C:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2001/11/23 18:18:00 | 000,000,597 | ---- | C] () -- C:\WINDOWS\System32\btcss.dll.manifest
[2001/11/14 13:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll
[2001/07/06 17:30:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[1998/10/11 00:07:38 | 000,088,576 | ---- | C] () -- C:\WINDOWS\System32\Iticheck.dll
[1996/04/03 15:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys

========== LOP Check ==========

[2009/04/07 15:11:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avanquest
[2010/03/26 19:24:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2009/04/06 22:55:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2008/07/22 01:51:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IM
[2008/07/22 01:50:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IncrediMail
[2010/03/25 10:22:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IObit
[2008/07/09 09:13:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LightScribe
[2008/09/04 14:39:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Network Associates
[2008/11/22 17:45:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RapidSolution
[2008/09/04 15:02:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RoboForm
[2010/02/22 00:55:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Simply Super Software
[2010/03/25 21:45:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/03/02 23:39:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/02/22 00:20:41 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2009/11/25 16:13:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/03/16 22:26:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\1&1
[2010/03/25 10:02:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\618914D8062DA2F74598D85E05FC4296
[2009/09/21 14:13:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\Avanquest
[2010/01/04 11:53:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\AVG9
[2010/03/10 23:30:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\DWGeditor
[2009/10/26 00:19:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\FileZilla
[2009/12/04 16:28:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\Folding@home-x86
[2010/02/22 01:17:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\GlarySoft
[2010/03/22 23:25:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\LimeWire
[2008/11/20 02:19:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\RTPlayer
[2008/09/21 15:58:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\Ruckus Network
[2010/02/22 00:55:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\Simply Super Software
[2008/11/22 15:34:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Steve\Application Data\Tunebite
[2010/03/29 17:53:12 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At1.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At10.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At11.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At12.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At13.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At14.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At15.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At16.job
[2010/03/29 17:52:37 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At17.job
[2010/03/29 17:52:37 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At18.job
[2010/03/29 17:52:37 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At19.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At2.job
[2010/03/29 17:52:37 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At20.job
[2010/03/29 17:52:37 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At21.job
[2010/03/29 17:52:37 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At22.job
[2010/03/29 17:52:37 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At23.job
[2010/03/29 17:52:37 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At24.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At3.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At4.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At5.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At6.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At7.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At8.job
[2010/03/29 17:52:36 | 000,000,380 | ---- | M] () -- C:\WINDOWS\Tasks\At9.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2007/10/09 16:49:00 | 001,409,405 | ---- | M] () -- C:\dfu.exe


< MD5 for: AGP440.SYS >
[2004/08/12 10:06:15 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\agp440.sys

< MD5 for: ATAPI.SYS >
[2004/08/12 10:06:15 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\atapi.sys
[2004/08/12 09:55:51 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2010/03/27 22:31:42 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2010/03/27 22:31:42 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\eventlog.dll
[2004/08/12 09:57:17 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2004/08/12 09:57:17 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2004/08/12 09:57:17 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\eventlog.dll

< MD5 for: IASTOR.SYS >
[2007/09/29 22:03:32 | 000,384,024 | ---- | M] (Intel Corporation) MD5=16A4671255CFB842225F0FDB6DBDB414 -- C:\swsetup\SP38088\Files\64\iastor.sys
[2007/09/29 22:03:12 | 000,308,248 | ---- | M] (Intel Corporation) MD5=E5A0034847537EAEE3C00349D5C34C5F -- C:\swsetup\SP38088\Files\32\iastor.sys
[2004/08/12 10:11:50 | 000,467,200 | ---- | M] (Intel Corporation) MD5=F26BFD48B1C314E0F23BF77ACFA75940 -- C:\WINDOWS\dell\iastor\iastor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$NtUninstallKB975467$\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\system32\netlogon.dll
[2004/08/12 10:02:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtUninstallKB968389$\netlogon.dll
[2004/08/12 10:02:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\ERDNT\cache\netlogon.dll

< MD5 for: NVATA.SYS >
[2006/01/27 00:04:16 | 000,099,584 | ---- | M] (NVIDIA Corporation) MD5=3AC5EEDD35B7437D53960F3998BFA462 -- C:\swsetup\SP33411\IDE\Win2K\sata_ide\nvata.sys
[2006/01/27 00:04:16 | 000,099,584 | ---- | M] (NVIDIA Corporation) MD5=3AC5EEDD35B7437D53960F3998BFA462 -- C:\swsetup\SP33411\IDE\WinXP\sata_ide\nvata.sys
[2006/01/27 00:04:16 | 000,099,584 | ---- | M] (NVIDIA Corporation) MD5=3AC5EEDD35B7437D53960F3998BFA462 -- C:\swsetup\SP33411\nvata.sys

< MD5 for: NVATABUS.SYS >
[2006/01/27 00:04:16 | 000,099,584 | ---- | M] (NVIDIA Corporation) MD5=3AC5EEDD35B7437D53960F3998BFA462 -- C:\swsetup\SP33411\IDE\Win2K\sataraid\nvatabus.sys
[2006/01/27 00:04:16 | 000,099,584 | ---- | M] (NVIDIA Corporation) MD5=3AC5EEDD35B7437D53960F3998BFA462 -- C:\swsetup\SP33411\IDE\WinXP\sataraid\nvatabus.sys
[2006/01/27 00:04:16 | 000,099,584 | ---- | M] (NVIDIA Corporation) MD5=3AC5EEDD35B7437D53960F3998BFA462 -- C:\swsetup\SP33411\nvatabus.sys

< MD5 for: NVGTS.SYS >
[2007/05/04 15:50:10 | 000,103,936 | ---- | M] (NVIDIA Corporation) MD5=859794817394AFAE6E79E069BA5125BA -- C:\NVIDIA\nForceWin2KXP\14.10\IDE\Win2K\sata_ide\nvgts.sys
[2007/05/04 15:50:10 | 000,103,936 | ---- | M] (NVIDIA Corporation) MD5=859794817394AFAE6E79E069BA5125BA -- C:\NVIDIA\nForceWin2KXP\14.10\IDE\Win2K\sataraid\nvgts.sys
[2007/05/04 15:50:10 | 000,103,936 | ---- | M] (NVIDIA Corporation) MD5=859794817394AFAE6E79E069BA5125BA -- C:\NVIDIA\nForceWin2KXP\14.10\IDE\WinXP\sata_ide\nvgts.sys
[2007/05/04 15:50:10 | 000,103,936 | ---- | M] (NVIDIA Corporation) MD5=859794817394AFAE6E79E069BA5125BA -- C:\NVIDIA\nForceWin2KXP\14.10\IDE\WinXP\sataraid\nvgts.sys

< MD5 for: SCECLI.DLL >
[2004/08/12 10:04:44 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2004/08/12 10:04:44 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\dllcache\scecli.dll
[2004/08/12 10:04:44 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\scecli.dll

< %systemroot%\*. /mp /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
< End of report >


GMER:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-29 17:45:26
Windows 5.1.2600 Service Pack 2
Running: t1jwdc2n.exe; Driver: C:\DOCUME~1\Steve\LOCALS~1\Temp\ugtyrpog.sys


---- System - GMER 1.0.15 ----

SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xBA8F887E]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xB01D6670]
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xBA8F8BFE]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xB01D6720]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xB01D67C0]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xB01D6860]

---- Kernel code sections - GMER 1.0.15 ----

.rsrc C:\WINDOWS\system32\drivers\atapi.sys entry point in ".rsrc" section [0xBA747394]
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB8AAA360, 0x305AC7, 0xE8000020]
? C:\WINDOWS\TEMP\mc22.tmp The system cannot find the file specified. !

---- User code sections - GMER 1.0.15 ----

.text C:\WINDOWS\system32\spoolsv.exe[252] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\WINDOWS\system32\spoolsv.exe[252] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\spoolsv.exe[252] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\spoolsv.exe[252] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\spoolsv.exe[252] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\spoolsv.exe[252] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[480] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[480] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[480] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[480] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[480] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[480] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Windows Desktop Search\WindowsSearch.exe[480] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\Explorer.EXE[636] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00C7000A
.text C:\WINDOWS\Explorer.EXE[636] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00C8000A
.text C:\WINDOWS\Explorer.EXE[636] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B1000C
.text C:\Program Files\IObit\IObit Security 360\IS360srv.exe[880] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\Program Files\IObit\IObit Security 360\IS360srv.exe[880] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\IObit\IObit Security 360\IS360srv.exe[880] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\IObit\IObit Security 360\IS360srv.exe[880] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\IObit\IObit Security 360\IS360srv.exe[880] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\IObit\IObit Security 360\IS360srv.exe[880] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Google\Update\GoogleUpdate.exe[888] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\Program Files\Google\Update\GoogleUpdate.exe[888] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Update\GoogleUpdate.exe[888] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Google\Update\GoogleUpdate.exe[888] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Google\Update\GoogleUpdate.exe[888] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Google\Update\GoogleUpdate.exe[888] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text c:\documents and settings\steve\local settings\application data\google\update\googleupdate .exe[920] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text c:\documents and settings\steve\local settings\application data\google\update\googleupdate .exe[920] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text c:\documents and settings\steve\local settings\application data\google\update\googleupdate .exe[920] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text c:\documents and settings\steve\local settings\application data\google\update\googleupdate .exe[920] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text c:\documents and settings\steve\local settings\application data\google\update\googleupdate .exe[920] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text c:\documents and settings\steve\local settings\application data\google\update\googleupdate .exe[920] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text c:\documents and settings\steve\local settings\application data\google\update\googleupdate .exe[920] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\System32\smss.exe[992] ntdll.dll!NtTestAlert 7C90DE8E 8 Bytes JMP 5F000029
.text C:\WINDOWS\system32\csrss.exe[1076] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\csrss.exe[1076] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\csrss.exe[1076] KERNEL32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\csrss.exe[1076] KERNEL32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\csrss.exe[1076] KERNEL32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\winlogon.exe[1104] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\WINDOWS\system32\winlogon.exe[1104] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\winlogon.exe[1104] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\winlogon.exe[1104] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\winlogon.exe[1104] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\winlogon.exe[1104] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\services.exe[1148] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\WINDOWS\system32\services.exe[1148] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\services.exe[1148] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\services.exe[1148] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\services.exe[1148] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\services.exe[1148] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\lsass.exe[1160] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\WINDOWS\system32\lsass.exe[1160] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\lsass.exe[1160] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\lsass.exe[1160] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\lsass.exe[1160] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\lsass.exe[1160] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\svchost.exe[1316] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\WINDOWS\system32\svchost.exe[1316] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1316] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\svchost.exe[1316] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[1316] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\svchost.exe[1316] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\svchost.exe[1364] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\WINDOWS\system32\svchost.exe[1364] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1364] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\svchost.exe[1364] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[1364] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\svchost.exe[1364] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\System32\svchost.exe[1404] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0085000A
.text C:\WINDOWS\System32\svchost.exe[1404] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 0086000A
.text C:\WINDOWS\System32\svchost.exe[1404] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 006F000C
.text C:\WINDOWS\system32\svchost.exe[1544] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\WINDOWS\system32\svchost.exe[1544] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1544] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\svchost.exe[1544] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[1544] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\svchost.exe[1544] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\svchost.exe[1552] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\WINDOWS\system32\svchost.exe[1552] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1552] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\svchost.exe[1552] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[1552] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\svchost.exe[1552] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[1580] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\svchost.exe[1580] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[1580] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\svchost.exe[1580] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1616] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1616] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1616] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1616] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1616] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1616] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\AVG\AVG9\avgwdsvc.exe[1632] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\Program Files\AVG\AVG9\avgwdsvc.exe[1632] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\AVG\AVG9\avgwdsvc.exe[1632] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\AVG\AVG9\avgwdsvc.exe[1632] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\AVG\AVG9\avgwdsvc.exe[1632] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\AVG\AVG9\avgwdsvc.exe[1632] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\AVG\AVG9\avgfws9.exe[1656] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\Program Files\AVG\AVG9\avgfws9.exe[1656] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\AVG\AVG9\avgfws9.exe[1656] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\AVG\AVG9\avgfws9.exe[1656] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\AVG\AVG9\avgfws9.exe[1656] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\AVG\AVG9\avgfws9.exe[1656] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[1704] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[1704] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[1704] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[1704] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[1704] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\AVG\AVG9\avgchsvx.exe[1704] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\AVG\AVG9\avgrsx.exe[1712] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\Program Files\AVG\AVG9\avgrsx.exe[1712] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\AVG\AVG9\avgrsx.exe[1712] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\AVG\AVG9\avgrsx.exe[1712] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\AVG\AVG9\avgrsx.exe[1712] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\AVG\AVG9\avgrsx.exe[1712] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1744] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\Program Files\Bonjour\mDNSResponder.exe[1744] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1744] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Bonjour\mDNSResponder.exe[1744] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1744] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Bonjour\mDNSResponder.exe[1744] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe[1808] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe[1808] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe[1808] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe[1808] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe[1808] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe[1808] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1864] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 00B61534 C:\WINDOWS\system32\app_dll.dll
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1864] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1864] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1864] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1864] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1864] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Documents and Settings\Steve\Desktop\t1jwdc2n.exe[1880] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\Documents and Settings\Steve\Desktop\t1jwdc2n.exe[1880] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\Documents and Settings\Steve\Desktop\t1jwdc2n.exe[1880] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Documents and Settings\Steve\Desktop\t1jwdc2n.exe[1880] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Documents and Settings\Steve\Desktop\t1jwdc2n.exe[1880] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Documents and Settings\Steve\Desktop\t1jwdc2n.exe[1880] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Documents and Settings\Steve\Desktop\t1jwdc2n.exe[1880] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\AVG\AVG9\avgcsrvx.exe[1936] ntdll.dll!NtTestAlert 7C90DE8E 8 Bytes JMP 5F000029
.text C:\Program Files\Java\jre6\bin\jqs.exe[2060] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\Program Files\Java\jre6\bin\jqs.exe[2060] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Java\jre6\bin\jqs.exe[2060] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Java\jre6\bin\jqs.exe[2060] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Java\jre6\bin\jqs.exe[2060] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Java\jre6\bin\jqs.exe[2060] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2136] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2136] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2136] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2136] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2136] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2136] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[2232] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[2232] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[2232] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[2232] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[2232] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[2232] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\nvsvc32.exe[2268] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\WINDOWS\system32\nvsvc32.exe[2268] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\nvsvc32.exe[2268] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\nvsvc32.exe[2268] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\nvsvc32.exe[2268] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\nvsvc32.exe[2268] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\HPZipm12.exe[2288] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\WINDOWS\system32\HPZipm12.exe[2288] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\HPZipm12.exe[2288] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\HPZipm12.exe[2288] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\HPZipm12.exe[2288] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\HPZipm12.exe[2288] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\SolidWorks\COSMOS\FloWorks\binCFW\StandAloneSlv.exe[2308] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\Program Files\SolidWorks\COSMOS\FloWorks\binCFW\StandAloneSlv.exe[2308] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\SolidWorks\COSMOS\FloWorks\binCFW\StandAloneSlv.exe[2308] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\SolidWorks\COSMOS\FloWorks\binCFW\StandAloneSlv.exe[2308] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\SolidWorks\COSMOS\FloWorks\binCFW\StandAloneSlv.exe[2308] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\SolidWorks\COSMOS\FloWorks\binCFW\StandAloneSlv.exe[2308] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text c:\program files\adobe\reader 9.0\reader\reader_sl .exe[2340] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text c:\program files\adobe\reader 9.0\reader\reader_sl .exe[2340] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text c:\program files\adobe\reader 9.0\reader\reader_sl .exe[2340] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text c:\program files\adobe\reader 9.0\reader\reader_sl .exe[2340] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text c:\program files\adobe\reader 9.0\reader\reader_sl .exe[2340] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text c:\program files\adobe\reader 9.0\reader\reader_sl .exe[2340] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text c:\program files\adobe\reader 9.0\reader\reader_sl .exe[2340] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\Spyware Doctor\sdhelp.exe[2440] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\WINDOWS\system32\svchost.exe[2548] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\WINDOWS\system32\svchost.exe[2548] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\svchost.exe[2548] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\svchost.exe[2548] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\svchost.exe[2548] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\svchost.exe[2548] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\svchost.exe[2548] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\RUNDLL32.EXE[2608] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\WINDOWS\system32\RUNDLL32.EXE[2608] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\RUNDLL32.EXE[2608] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\RUNDLL32.EXE[2608] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[2608] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[2608] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\RUNDLL32.EXE[2608] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\wdfmgr.exe[2716] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\WINDOWS\system32\wdfmgr.exe[2716] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\wdfmgr.exe[2716] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\wdfmgr.exe[2716] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\wdfmgr.exe[2716] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\wdfmgr.exe[2716] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\wdfmgr.exe[2716] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe[2788] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe[2788] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe[2788] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe[2788] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe[2788] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe[2788] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe[2788] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\Mozilla Firefox\firefox.exe[3016] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 013C000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3016] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 013D000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[3016] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 013B000C
.text C:\Sun\SDK\jdk\bin\javaw.exe[3076] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\Sun\SDK\jdk\bin\javaw.exe[3076] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\Sun\SDK\jdk\bin\javaw.exe[3076] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Sun\SDK\jdk\bin\javaw.exe[3076] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Sun\SDK\jdk\bin\javaw.exe[3076] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Sun\SDK\jdk\bin\javaw.exe[3076] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Sun\SDK\jdk\bin\javaw.exe[3076] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\System32\alg.exe[3128] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\System32\app_dll.dll
.text C:\WINDOWS\System32\alg.exe[3128] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\System32\alg.exe[3128] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\System32\alg.exe[3128] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\System32\alg.exe[3128] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\System32\alg.exe[3128] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\System32\alg.exe[3128] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\WINDOWS\system32\ctfmon.exe[3332] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\WINDOWS\system32\ctfmon.exe[3332] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\WINDOWS\system32\ctfmon.exe[3332] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\WINDOWS\system32\ctfmon.exe[3332] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\ctfmon.exe[3332] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\WINDOWS\system32\ctfmon.exe[3332] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\ctfmon.exe[3332] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe[3544] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe[3544] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe[3544] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe[3544] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe[3544] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe[3544] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe[3544] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\Windows Desktop Search\WindowsSearchIndexer.exe[3544] kernel32.dll!WriteFile 7C810D97 7 Bytes JMP 00DFE8D9 C:\Program Files\Windows Desktop Search\mssrch.dll (Microsoft Embedded Search/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\wmpscfgs.exe[3584] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\Program Files\Internet Explorer\wmpscfgs.exe[3584] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\wmpscfgs.exe[3584] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Internet Explorer\wmpscfgs.exe[3584] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Internet Explorer\wmpscfgs.exe[3584] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Internet Explorer\wmpscfgs.exe[3584] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Internet Explorer\wmpscfgs.exe[3584] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3716] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3716] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3716] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3716] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3716] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3716] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3716] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D
.text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[3928] ntdll.dll!NtQuerySystemInformation 7C90D92E 5 Bytes JMP 10001534 C:\WINDOWS\system32\app_dll.dll
.text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[3928] ntdll.dll!NtTerminateProcess 7C90DE6E 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[3928] ntdll.dll!NtTerminateProcess + 4 7C90DE72 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[3928] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F070F5A
.text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[3928] kernel32.dll!CreateProcessW 7C802332 6 Bytes JMP 5F0A0F5A
.text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[3928] kernel32.dll!CreateProcessA 7C802367 6 Bytes JMP 5F040F5A
.text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[3928] kernel32.dll!FreeLibrary + 15 7C80AC03 4 Bytes CALL 5F00003D

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\Program Files\Spyware Doctor\sdhelp.exe[2440] @ C:\WINDOWS\system32\user32.dll [KERNEL32.dll!CreateThread] [0042B398] C:\Program Files\Spyware Doctor\sdhelp.exe (PC Tools Research Pty Ltd)
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[2440] @ C:\WINDOWS\system32\advapi32.dll [KERNEL32.dll!CreateThread] [0042B398] C:\Program Files\Spyware Doctor\sdhelp.exe (PC Tools Research Pty Ltd)
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[2440] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateThread] [0042B398] C:\Program Files\Spyware Doctor\sdhelp.exe (PC Tools Research Pty Ltd)
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[2440] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!CreateThread] [0042B398] C:\Program Files\Spyware Doctor\sdhelp.exe (PC Tools Research Pty Ltd)
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[2440] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!CreateThread] [0042B398] C:\Program Files\Spyware Doctor\sdhelp.exe (PC Tools Research Pty Ltd)
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[2440] @ C:\WINDOWS\system32\shell32.dll [KERNEL32.dll!CreateThread] [0042B398] C:\Program Files\Spyware Doctor\sdhelp.exe (PC Tools Research Pty Ltd)
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[2440] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] [0042B398] C:\Program Files\Spyware Doctor\sdhelp.exe (PC Tools Research Pty Ltd)
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[2440] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!CreateThread] [0042B398] C:\Program Files\Spyware Doctor\sdhelp.exe (PC Tools Research Pty Ltd)
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[2440] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!CreateThread] [0042B398] C:\Program Files\Spyware Doctor\sdhelp.exe (PC Tools Research Pty Ltd)
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[2440] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!CreateThread] [0042B398] C:\Program Files\Spyware Doctor\sdhelp.exe (PC Tools Research Pty Ltd)
IAT C:\Program Files\Spyware Doctor\sdhelp.exe[2440] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!CreateThread] [0042B398] C:\Program Files\Spyware Doctor\sdhelp.exe (PC Tools Research Pty Ltd)

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs ikhfile.sys (PCTools Research Pty Ltd.)
AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp Lbd.sys (Boot Driver/Lavasoft AB)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp Lbd.sys (Boot Driver/Lavasoft AB)

Device -> \Driver\atapi \Device\Harddisk0\DR0 8B0D1CA1

---- Processes - GMER 1.0.15 ----

Process c:\documents and settings\steve\local settings\application data\google\update\googleupdate .exe (*** hidden *** ) 920
Process c:\program files\adobe\reader 9.0\reader\reader_sl .exe (*** hidden *** ) 2340
Process C:\Program Files\Internet Explorer\wmpscfgs.exe (*** hidden *** ) 3584
Process C:\Program Files\Internet Explorer\wmpscfgs.exe (*** hidden *** ) 3800


Thanks again for all the help Tom. Can't wait till this computer is finally clean again thumbup2.gif

#5 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:03:10 PM

Posted 31 March 2010 - 12:18 PM

Hi smile.gif


Please go here and have a look how you can disable your security software.

Download Combofix from any of the links below but rename it to before saving it to your desktop.

Link 1
Link 2



--------------------------------------------------------------------

Double click on the renamed Combofix.exe & follow the prompts.
    When finished, it will produce a report for you.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.

This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper


If you need help, see this link:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#6 Starion89

Starion89
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 01 April 2010 - 09:27 PM

Tom,

I can get combofix to run, but it freezes everytime it tries to produce a log. I've let it run about 5 times and each time the log screen has just sat there for around 2 hours. I made sure all my anti-virus software was off and no other programs were running. Not sure what to do here.

#7 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:03:10 PM

Posted 02 April 2010 - 01:25 PM

Please have a look if you can find C:\Combofix txt and post back with the content of the logfile.
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#8 Starion89

Starion89
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 02 April 2010 - 05:31 PM

Got it. Here she is:

ComboFix 10-03-29.04 - Steve 04/01/2010 22:02:17.5.2 - x86
Running from: C:\Documents and Settings\Steve\Desktop\Schrauber.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Steve\ico .exe
C:\Documents and Settings\Steve\nwiz .exe
C:\Documents and Settings\Steve\rundll32 .exe
C:\Documents and Settings\Steve\rundll32.exe
C:\Program Files\Internet Explorer\js.mui
C:\Program Files\Internet Explorer\wmpscfgs.exe
.
---- Previous Run -------
.
C:\Documents and Settings\Steve\ico .exe
C:\Documents and Settings\Steve\nwiz .exe
C:\Documents and Settings\Steve\rundll32 .exe
C:\Documents and Settings\Steve\rundll32.exe
C:\Program Files\Adobe\acrotray .exe
C:\Program Files\Internet Explorer\js.mui
C:\Program Files\Internet Explorer\wmpscfgs.exe
C:\WINDOWS\system32\app_dll.dll
C:\WINDOWS\system32\ico .exe
C:\WINDOWS\system32\nwiz .exe
C:\WINDOWS\system32\rundll32 .exe

.
((((((((((((((((((((((((( Files Created from 2010-03-02 to 2010-04-02 )))))))))))))))))))))))))))))))
.

2010-04-01 17:22:45 . 2010-04-02 01:56:01 27648 ----a-w- C:\Documents and Settings\Steve\Application Data\gjahoaayj\hchgtkgtssd.exe
2010-04-01 17:22:45 . 2010-04-02 01:56:01 -------- d-----w- C:\Documents and Settings\Steve\Application Data\gjahoaayj
2010-04-01 17:22:45 . 2010-04-01 17:22:45 -------- d-----w- C:\Documents and Settings\Steve\Local Settings\Application Data\gjahoaayj
2010-04-01 17:22:45 . 2010-03-31 06:33:08 269312 ----a-w- C:\Documents and Settings\Steve\Application Data\gjahoaayj\hchgtkgtssd .exe
2010-04-01 03:35:13 . 2010-04-01 03:35:14 516480 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\EmailScannerAddin.dll
2010-03-31 15:43:52 . 2010-03-31 15:43:47 238080 --sh--r- C:\WINDOWS\system32\winupd01.exe
2010-03-31 15:43:43 . 2010-03-31 15:43:38 164864 --sh--r- C:\Documents and Settings\Steve\Application Data\gnwwy.exe
2010-03-31 06:33:22 . 2010-04-02 01:56:00 -------- d-----w- C:\Documents and Settings\Steve\Local Settings\Application Data\liebcvcyv
2010-03-31 00:57:40 . 2008-03-21 17:57:18 14640 ------w- C:\WINDOWS\system32\spmsgXP_2k3.dll
2010-03-31 00:41:59 . 2010-03-31 00:41:59 581192 ----a-w- C:\WINDOWS\system32\WinUSBCoInstaller.dll
2010-03-31 00:41:58 . 2010-03-31 00:41:58 1112288 ----a-w- C:\WINDOWS\system32\WdfCoInstaller01007.dll
2010-03-31 00:24:57 . 2010-03-31 00:56:01 -------- d-----w- C:\Documents and Settings\Steve\.android
2010-03-29 01:25:55 . 2010-03-29 01:25:55 -------- d-----w- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
2010-03-27 00:30:26 . 2010-03-27 00:30:26 -------- d-----w- C:\Documents and Settings\LocalService\Application Data\PC Tools
2010-03-26 02:36:58 . 2010-03-26 02:36:58 552 ----a-w- C:\WINDOWS\system32\d3d8caps.dat
2010-03-26 02:36:10 . 2010-03-26 02:36:29 -------- d-----w- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
2010-03-26 01:45:29 . 2010-03-26 01:45:29 161296 ----a-w- C:\WINDOWS\system32\drivers\tmcomm.sys
2010-03-26 00:39:52 . 2009-12-11 23:05:06 3613560 ----a-w- C:\Documents and Settings\Steve\Application Data\Simply Super Software\Trojan Remover\rwwE.exe
2010-03-25 14:39:17 . 2010-03-25 14:39:17 -------- d-----w- C:\Program Files\Loaris
2010-03-25 14:35:40 . 2010-03-28 21:45:34 -------- d-----w- C:\Program Files\Malwarebytes' Anti-Malware
2010-03-25 14:22:03 . 2010-03-25 14:22:03 -------- d-----w- C:\Documents and Settings\All Users\Application Data\IObit
2010-03-25 14:22:01 . 2010-03-25 14:22:01 -------- d-----w- C:\Program Files\IObit
2010-03-25 13:55:02 . 2010-03-25 13:55:02 -------- d-s---w- C:\Documents and Settings\NetworkService\UserData
2010-03-25 13:45:30 . 2010-04-02 01:55:40 27648 ----a-w- C:\Documents and Settings\Steve\nwiz.exe
2010-03-25 13:45:27 . 2010-04-02 01:55:35 27648 ----a-w- C:\Documents and Settings\Steve\ico.exe
2010-03-25 11:44:24 . 2010-03-29 01:25:37 664 ----a-w- C:\WINDOWS\system32\d3d9caps.dat
2010-03-25 05:02:36 . 2010-02-22 04:31:01 15880 ----a-w- C:\WINDOWS\system32\lsdelete.exe
2010-03-25 04:27:50 . 2010-04-02 01:55:32 -------- d-sh--w- C:\Documents and Settings\Steve\.COMMgr
2010-03-25 04:27:18 . 2010-03-25 14:02:43 -------- d-----w- C:\Documents and Settings\Steve\Application Data\618914D8062DA2F74598D85E05FC4296
2010-03-23 02:13:21 . 2010-03-23 02:13:46 20846064 ----a-w- C:\Documents and Settings\Steve\Application Data\Real\Update\setup3.10\rp\RealPlayerSPGold.exe
2010-03-16 02:41:04 . 2010-03-26 00:43:56 79488 ----a-w- C:\Documents and Settings\Steve\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-03-15 18:39:42 . 2010-03-15 18:39:46 8405312 ----a-w- C:\Documents and Settings\Steve\Application Data\Real\Update\setup3.10\gtb\GOOGLE_TOOLBAR\GoogleToolbarInstaller.exe
2010-03-15 18:39:08 . 2010-03-15 18:39:08 149000 ----a-w- C:\Documents and Settings\Steve\Application Data\Real\Update\setup3.10\chr_helper\LaunchHelper.exe
2010-03-15 18:38:58 . 2010-03-15 18:39:02 10309448 ----a-w- C:\Documents and Settings\Steve\Application Data\Real\Update\setup3.10\chr\ChromeInstaller.exe
2010-03-15 18:38:42 . 2010-03-15 18:38:42 283280 ----a-w- C:\Documents and Settings\Steve\Application Data\Real\Update\setup3.10\carb\CarboniteSetupLiteRealPreinstaller.exe
2010-03-15 18:38:42 . 2010-03-15 18:38:42 181768 ----a-w- C:\Documents and Settings\Steve\Application Data\Real\Update\setup3.10\carb\LaunchHelper.exe
2010-03-15 18:38:41 . 2010-03-15 18:38:41 79368 ----a-w- C:\Documents and Settings\Steve\Application Data\Real\Update\setup3.10\RUP\vista.exe
2010-03-15 18:38:41 . 2010-03-15 18:38:41 64000 ----a-w- C:\Documents and Settings\Steve\Application Data\Real\Update\setup3.10\RUP\inst_config\gcapi_dll.dll
2010-03-15 18:38:41 . 2010-03-15 18:38:41 52288 ----a-w- C:\Documents and Settings\Steve\Application Data\Real\Update\setup3.10\RUP\inst_config\gtapi.dll
2010-03-15 18:38:41 . 2010-03-15 18:38:41 50688 ----a-w- C:\Documents and Settings\Steve\Application Data\Real\Update\setup3.10\RUP\inst_config\fftbapi.dll
2010-03-15 18:38:41 . 2010-03-15 18:38:41 49152 ----a-w- C:\Documents and Settings\Steve\Application Data\Real\Update\setup3.10\RUP\inst_config\CarboniteCompatibility.dll
2010-03-15 18:38:41 . 2010-03-15 18:38:41 118784 ----a-w- C:\Documents and Settings\Steve\Application Data\Real\Update\setup3.10\RUP\inst_config\compat.dll
2010-03-14 21:28:59 . 2010-03-14 21:28:59 360584 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2010-03-14 21:28:58 . 2010-03-14 21:28:58 74760 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\UniversalDD.sys
2010-03-14 21:28:58 . 2010-03-14 21:28:58 333192 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\avgldx86.sys
2010-03-14 21:28:58 . 2010-03-14 21:28:58 30216 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\AVGIDSFilter.sys
2010-03-14 21:28:58 . 2010-03-14 21:28:58 28424 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\avgmfx86.sys
2010-03-14 21:28:58 . 2010-03-14 21:28:58 25736 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\AVGIDSShim.sys
2010-03-14 21:28:58 . 2010-03-14 21:28:58 25608 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\AVGIDSxx.sys
2010-03-14 21:28:58 . 2010-03-14 21:28:58 122376 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\AVGIDSDriver.sys
2010-03-14 21:28:57 . 2010-03-14 21:28:57 161800 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\avgrkx86.sys
2010-03-14 21:28:44 . 2010-03-14 21:28:44 12464 ----a-w- C:\WINDOWS\system32\avgrsstx.dll
2010-03-11 05:24:25 . 2010-03-18 22:30:30 -------- d-----w- C:\Documents and Settings\Steve\Application Data\SolidWorks
2010-03-11 03:30:39 . 2010-03-11 03:30:39 -------- d-----w- C:\Documents and Settings\Steve\Application Data\DWGeditor
2010-03-11 03:30:06 . 2010-03-11 03:30:28 -------- d-----w- C:\Program Files\DWGeditor
2010-03-11 03:15:56 . 2010-03-11 03:29:23 -------- d-----w- C:\Program Files\Common Files\eDrawings2007
2010-03-11 03:15:54 . 2010-03-11 03:21:18 -------- d-----w- C:\Program Files\Common Files\SolidWorks Shared
2010-03-11 03:14:42 . 2010-03-11 03:14:42 -------- d-----w- C:\WINDOWS\system32\GroupPolicy
2010-03-11 03:14:36 . 2010-03-11 03:17:54 -------- d-----w- C:\Documents and Settings\All Users\Application Data\SolidWorks
2010-03-11 03:14:34 . 2010-03-11 03:31:31 -------- d-----w- C:\Program Files\SolidWorks
2010-03-11 03:14:34 . 2010-03-11 03:14:37 -------- d-----w- C:\Program Files\Common Files\Solidworks Data
2010-03-11 03:13:54 . 2010-03-11 03:14:02 -------- d-----w- C:\Program Files\Windows Desktop Search
2010-03-10 05:08:16 . 2010-03-10 05:08:16 -------- d-----w- C:\Program Files\Sun
2010-03-08 03:42:18 . 2010-03-08 03:42:18 503808 ----a-w- C:\Documents and Settings\Steve\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-32ed404b-n\msvcp71.dll
2010-03-08 03:42:18 . 2010-03-08 03:42:18 499712 ----a-w- C:\Documents and Settings\Steve\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-32ed404b-n\jmc.dll
2010-03-08 03:42:18 . 2010-03-08 03:42:18 348160 ----a-w- C:\Documents and Settings\Steve\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-32ed404b-n\msvcr71.dll
2010-03-08 03:42:16 . 2010-03-08 03:42:16 61440 ----a-w- C:\Documents and Settings\Steve\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-523e10ea-n\decora-sse.dll
2010-03-08 03:42:16 . 2010-03-08 03:42:16 12800 ----a-w- C:\Documents and Settings\Steve\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-523e10ea-n\decora-d3d.dll
2010-03-08 03:42:10 . 2010-03-10 05:07:45 410976 ----a-w- C:\WINDOWS\system32\deploytk.dll
2010-03-08 03:27:20 . 2010-03-08 03:27:20 -------- d-----w- C:\Sun
2010-03-07 01:32:51 . 2010-03-23 20:56:50 439816 ----a-w- C:\Documents and Settings\Steve\Application Data\Real\Update\setup3.10\setup.exe
2010-03-03 03:48:57 . 2010-03-03 03:48:57 -------- d-----w- C:\Program Files\ESET
2010-03-03 03:43:38 . 2010-03-03 23:24:47 -------- d-----w- C:\Documents and Settings\Steve\.SunDownloadManager

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-02 01:55:53 . 2008-09-24 23:56:26 -------- d-----w- C:\Program Files\QuickTime
2010-04-02 01:55:28 . 2008-07-09 13:07:43 -------- d-----w- C:\Program Files\Common Files\LightScribe
2010-04-01 17:21:20 . 2008-07-09 20:11:22 27648 ----a-w- C:\WINDOWS\system32\nwiz.exe
2010-04-01 17:21:14 . 2008-07-09 13:03:49 27648 ----a-w- C:\WINDOWS\system32\ico.exe
2010-04-01 15:51:02 . 2009-10-20 03:59:53 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2010-04-01 06:25:14 . 2008-10-03 20:49:44 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Google Updater
2010-04-01 03:35:13 . 2010-02-22 03:12:32 885736 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2010-04-01 03:35:11 . 2010-02-22 03:12:30 210552 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2010-04-01 03:35:10 . 2010-02-22 03:12:29 393896 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2010-04-01 03:35:09 . 2010-02-22 04:30:54 565392 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\aawapi.dll
2010-04-01 03:35:08 . 2010-02-22 04:30:52 221920 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\VipreBridge.dll
2010-04-01 03:35:08 . 2010-02-22 03:12:27 17632 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\WSCUpdate.dll
2010-04-01 03:35:07 . 2010-02-22 03:12:26 432032 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2010-04-01 03:35:06 . 2010-02-22 03:12:25 167312 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2010-04-01 03:35:05 . 2010-02-22 03:11:58 329560 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2010-04-01 03:35:04 . 2010-02-22 03:11:57 94712 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2010-04-01 03:35:02 . 2010-02-22 03:11:50 966104 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2010-04-01 03:35:00 . 2010-02-22 03:11:15 849744 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2010-04-01 03:34:58 . 2010-02-22 03:11:14 855864 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2010-04-01 03:34:56 . 2010-02-22 03:11:12 1597952 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2010-04-01 03:34:53 . 2010-02-22 03:11:07 818256 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2010-04-01 03:34:51 . 2010-02-22 03:11:05 1265264 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2010-03-31 04:53:07 . 2004-08-12 13:55:51 95360 ----a-w- C:\WINDOWS\system32\drivers\atapi.sys
2010-03-31 00:58:36 . 2010-03-31 00:58:36 0 ---ha-w- C:\WINDOWS\system32\drivers\Msft_Kernel_WinUSB_01007.Wdf
2010-03-31 00:57:44 . 2010-03-31 00:57:44 0 ---ha-w- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2010-03-26 23:24:38 . 2009-12-10 04:30:47 -------- d-----w- C:\Documents and Settings\All Users\Application Data\avg9
2010-03-26 01:45:27 . 2010-02-22 04:56:43 -------- d---a-w- C:\Documents and Settings\All Users\Application Data\TEMP
2010-03-25 05:21:17 . 2008-07-24 01:46:27 -------- d-----w- C:\Program Files\Common Files\AOL
2010-03-25 05:19:17 . 2010-02-19 04:08:27 -------- d-----w- C:\Program Files\Spybot - Search & Destroy
2010-03-23 14:27:52 . 2010-02-22 04:29:40 3749200 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Defs\Extended\vcore.dll
2010-03-23 03:25:48 . 2008-12-17 01:44:19 -------- d-----w- C:\Documents and Settings\Steve\Application Data\LimeWire
2010-03-22 04:03:38 . 2008-12-17 01:43:21 -------- d-----w- C:\Program Files\LimeWire
2010-03-22 03:25:10 . 2008-07-12 04:28:01 -------- d-----w- C:\Program Files\Common Files\Adobe
2010-03-14 21:28:46 . 2009-12-10 04:31:31 242696 ----a-w- C:\WINDOWS\system32\drivers\avgtdix.sys
2010-03-14 21:28:44 . 2009-12-10 04:31:22 29512 ----a-w- C:\WINDOWS\system32\drivers\avgmfx86.sys
2010-03-14 21:28:39 . 2009-12-10 04:31:32 25096 ----a-w- C:\WINDOWS\system32\drivers\AVGIDSxx.sys
2010-03-14 21:28:05 . 2009-12-10 04:31:26 216200 ----a-w- C:\WINDOWS\system32\drivers\avgldx86.sys
2010-03-14 21:28:02 . 2009-12-10 04:31:32 52872 ----a-w- C:\WINDOWS\system32\drivers\avgrkx86.sys
2010-03-12 21:24:38 . 2010-02-22 04:29:39 83280 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Defs\Extended\kbu.dll
2010-03-12 05:16:19 . 2008-07-09 16:53:20 86928 ----a-w- C:\Documents and Settings\Steve\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-10 05:07:41 . 2008-09-02 02:18:52 -------- d-----w- C:\Program Files\Java
2010-03-03 03:39:54 . 2008-07-24 01:46:44 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Viewpoint
2010-03-01 23:47:43 . 2010-03-01 23:47:43 -------- d-----w- C:\Documents and Settings\Steve\Application Data\Malwarebytes
2010-03-01 23:47:38 . 2010-03-01 23:47:38 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-03-01 23:40:29 . 2009-09-07 01:31:00 227 ----a-w- C:\WINDOWS\system.tmp
2010-02-26 06:12:23 . 2004-08-12 14:09:30 662016 ----a-w- C:\WINDOWS\system32\wininet.dll
2010-02-26 06:12:17 . 2004-08-12 13:58:00 81920 ----a-w- C:\WINDOWS\system32\ieencode.dll
2010-02-23 12:23:13 . 2010-02-22 04:29:39 283984 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Defs\Extended\LIBEMAIL.DLL
2010-02-22 05:17:52 . 2010-02-22 05:17:48 -------- d-----w- C:\Program Files\Quick Startup
2010-02-22 05:17:48 . 2010-02-22 05:17:48 -------- d-----w- C:\Documents and Settings\Steve\Application Data\GlarySoft
2010-02-22 04:55:23 . 2010-02-22 04:55:13 -------- d-----w- C:\Program Files\Trojan Remover
2010-02-22 04:55:13 . 2010-02-22 04:55:13 -------- d-----w- C:\Documents and Settings\Steve\Application Data\Simply Super Software
2010-02-22 04:55:13 . 2010-02-22 04:55:13 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2010-02-22 04:31:10 . 2010-02-22 04:31:11 95024 ----a-w- C:\WINDOWS\system32\drivers\SBREDrv.sys
2010-02-22 04:31:10 . 2010-02-22 04:31:09 95024 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys
2010-02-22 04:31:09 . 2010-02-22 04:31:07 598368 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\EmailScanner.dll
2010-02-22 04:31:03 . 2010-02-22 04:31:01 566608 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\sbap.dll
2010-02-22 04:31:01 . 2010-02-22 03:12:30 15880 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2010-02-22 04:30:48 . 2010-02-22 04:30:46 1230160 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBTE.dll
2010-02-22 04:30:46 . 2010-02-22 04:30:44 247120 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBRE.dll
2010-02-22 04:30:44 . 2010-02-22 03:12:03 6330848 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2010-02-22 04:30:27 . 2010-02-22 04:30:27 17480 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\EmailScannerBridge.dll
2010-02-22 04:20:43 . 2010-02-22 03:05:55 -------- d-----w- C:\Program Files\Lavasoft
2010-02-22 04:20:41 . 2010-02-22 04:20:40 -------- dc-h--w- C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-02-22 03:12:37 . 2010-02-22 03:05:55 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Lavasoft
2010-02-22 03:12:31 . 2010-02-22 03:12:31 25440 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2010-02-22 03:11:56 . 2010-02-22 03:11:56 68640 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\64\lbd.sys
2010-02-22 03:11:55 . 2010-02-22 03:11:55 303976 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\64\AAWDriverTool.exe
2010-02-22 03:11:53 . 2010-02-22 03:11:53 64160 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2010-02-22 03:11:51 . 2010-02-22 03:11:51 85352 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\AAWDriverTool.exe
2010-02-22 03:11:47 . 2010-02-22 03:11:47 3695616 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2010-02-22 03:11:09 . 2010-02-22 03:11:09 640760 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2010-02-19 04:08:52 . 2010-02-19 04:08:27 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-19 04:05:59 . 2010-02-19 04:05:59 -------- d-----w- C:\Program Files\Trend Micro
2010-02-19 00:14:26 . 2010-02-04 00:02:22 -------- d-----w- C:\Program Files\SpeedFan
2010-02-16 16:01:04 . 2010-02-22 04:29:40 259408 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Defs\Extended\remediation.dll
2010-02-16 16:00:54 . 2010-02-22 04:29:39 226640 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Defs\Extended\libZip.dll
2010-02-16 16:00:53 . 2010-02-22 04:29:39 390480 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Defs\Extended\libVvs.dll
2010-02-16 16:00:53 . 2010-02-22 04:29:39 173392 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Defs\Extended\LIBTD.DLL
2010-02-16 16:00:52 . 2010-02-22 04:29:39 296272 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Defs\Extended\libRar.dll
2010-02-16 16:00:51 . 2010-02-22 04:29:39 345424 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Defs\Extended\Libolea.dll
2010-02-16 16:00:50 . 2010-02-22 04:29:39 206160 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Defs\Extended\libNSIS.dll
2010-02-16 16:00:47 . 2010-02-22 04:29:39 177488 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Defs\Extended\libMsi.dll
2010-02-16 16:00:44 . 2010-02-22 04:29:39 206160 ----a-w- C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Defs\Extended\libCHM.dll
2010-02-05 04:28:04 . 2008-09-23 02:50:34 -------- d-----w- C:\Documents and Settings\Steve\Application Data\U3
2010-02-05 03:25:31 . 2010-02-05 03:23:55 -------- d-----w- C:\Program Files\iTunes
2010-02-05 03:24:02 . 2010-02-05 03:24:02 -------- d-----w- C:\Program Files\iPod
2010-02-05 03:23:59 . 2008-07-18 20:54:45 -------- d-----w- C:\Program Files\Common Files\Apple
2010-02-04 15:53:47 . 2010-02-22 04:20:40 2954656 -c--a-w- C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
2010-02-04 15:53:02 . 2010-02-22 03:12:38 64288 ----a-w- C:\WINDOWS\system32\drivers\Lbd.sys
2010-02-04 01:37:07 . 2008-10-03 20:49:42 -------- d-----w- C:\Program Files\Google
2010-02-04 01:33:50 . 2008-08-21 04:04:57 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Skype
2010-02-04 01:32:31 . 2008-10-07 19:09:18 -------- d-----w- C:\Program Files\Maxthon
2010-02-04 01:28:05 . 2009-03-17 02:26:49 -------- d-----w- C:\Program Files\1&1
2010-02-04 00:49:18 . 2008-08-21 04:07:40 -------- d-----w- C:\Documents and Settings\Steve\Application Data\skypePM
2010-02-04 00:43:38 . 2010-02-04 00:43:37 -------- d-----w- C:\Program Files\CpuIdle
2010-02-04 00:43:37 . 2010-02-04 00:43:37 4484 ----a-w- C:\WINDOWS\system32\drivers\cpuidlep.sys
2010-01-23 00:51:36 . 2010-01-23 00:51:36 72488 ----a-w- C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
1601-01-01 00:03:28 . 1601-01-01 00:03:28 83456 --sha-w- C:\WINDOWS\system32\jivagaki.exe
1601-01-01 00:03:28 . 1601-01-01 00:03:28 70144 --sha-w- C:\WINDOWS\system32\mesawunu.dll
1601-01-01 00:03:28 . 1601-01-01 00:03:28 83456 --sha-w- C:\WINDOWS\system32\wosarako.exe
.
CODE
<pre>
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl .exe
C:\Program Files\Common Files\Adobe\ARM\1.0\adobearm .exe
C:\Program Files\Common Files\Adobe\Updater6\adobe_updater .exe
C:\Program Files\Common Files\LightScribe\lightscribecontrolpanel .exe
C:\Program Files\Common Files\Real\Update_OB\realsched .exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\qlbctrl .exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\hpwamain .exe
C:\Program Files\IObit\IObit Security 360\is360tray .exe
C:\Program Files\Java\jre6\bin\jusched .exe
C:\Program Files\Microsoft Office\Office12\groovemonitor .exe
C:\Program Files\QuickTime\qttask             .exe
C:\Program Files\QuickTime\qttask            .exe
C:\Program Files\QuickTime\qttask           .exe
C:\Program Files\QuickTime\qttask          .exe
C:\Program Files\QuickTime\qttask         .exe
C:\Program Files\QuickTime\qttask        .exe
C:\Program Files\QuickTime\qttask       .exe
C:\Program Files\QuickTime\qttask      .exe
C:\Program Files\QuickTime\qttask     .exe
C:\Program Files\QuickTime\qttask    .exe
C:\Program Files\QuickTime\qttask   .exe
C:\Program Files\QuickTime\qttask  .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\Spybot - Search & Destroy\rundll32 .exe
C:\Program Files\Synaptics\SynTP\syntpstart .exe
</pre>




#9 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:03:10 PM

Posted 03 April 2010 - 12:04 PM

Hi,


Open notepad and copy/paste the text in the quotebox below into it:

CODE
http://www.bleepingcomputer.com/forums/t/305109/seems-i-have-a-few-trojans-i-cant-get-rid-of/

KillAll::

Collect::
C:\Documents and Settings\Steve\Application Data\gjahoaayj\hchgtkgtssd.exe
C:\Documents and Settings\Steve\Application Data\gnwwy.exe
C:\Documents and Settings\Steve\nwiz.exe
C:\Documents and Settings\Steve\ico.exe
C:\WINDOWS\system32\jivagaki.exe
C:\WINDOWS\system32\mesawunu.dll
C:\WINDOWS\system32\wosarako.exe

Folder::
C:\Documents and Settings\Steve\Application Data\gjahoaayj
C:\Documents and Settings\Steve\Local Settings\Application Data\gjahoaayj
C:\Documents and Settings\Steve\Local Settings\Application Data\liebcvcyv

FileLook::
C:\WINDOWS\system32\nwiz.exe
C:\WINDOWS\system32\ico.exe

RenV::
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl .exe
C:\Program Files\Common Files\Adobe\ARM\1.0\adobearm .exe
C:\Program Files\Common Files\Adobe\Updater6\adobe_updater .exe
C:\Program Files\Common Files\LightScribe\lightscribecontrolpanel .exe
C:\Program Files\Common Files\Real\Update_OB\realsched .exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\qlbctrl .exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\hpwamain .exe
C:\Program Files\IObit\IObit Security 360\is360tray .exe
C:\Program Files\Java\jre6\bin\jusched .exe
C:\Program Files\Microsoft Office\Office12\groovemonitor .exe
C:\Program Files\QuickTime\qttask             .exe
C:\Program Files\QuickTime\qttask            .exe
C:\Program Files\QuickTime\qttask           .exe
C:\Program Files\QuickTime\qttask          .exe
C:\Program Files\QuickTime\qttask         .exe
C:\Program Files\QuickTime\qttask        .exe
C:\Program Files\QuickTime\qttask       .exe
C:\Program Files\QuickTime\qttask      .exe
C:\Program Files\QuickTime\qttask     .exe
C:\Program Files\QuickTime\qttask    .exe
C:\Program Files\QuickTime\qttask   .exe
C:\Program Files\QuickTime\qttask  .exe
C:\Program Files\QuickTime\qttask .exe
C:\Program Files\Spybot - Search & Destroy\rundll32 .exe
C:\Program Files\Synaptics\SynTP\syntpstart .exe


Save this as CFScript.txt





Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you. Post that log in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.

regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#10 Starion89

Starion89
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 03 April 2010 - 09:19 PM

Tom,

The newest log is posted below. I'm still having some problems (error messages @ startup, firefox still not loading homepage, can't access googledocs to name a few)

Thank you again for all your help
-Steve

ComboFix 10-04-03.01 - Steve 04/03/2010 21:51:50.7.2 - x86
Running from: C:\Documents and Settings\Steve\Desktop\Schrauber.exe
Command switches used :: C:\Documents and Settings\Steve\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
* Created a new restore point

file zipped: C:\Documents and Settings\Steve\ico.exe
file zipped: C:\Documents and Settings\Steve\nwiz.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Steve\ico .exe
C:\Documents and Settings\Steve\ico.exe
C:\Documents and Settings\Steve\nwiz .exe
C:\Documents and Settings\Steve\nwiz.exe
C:\Documents and Settings\Steve\rundll32 .exe
C:\Documents and Settings\Steve\rundll32.exe
C:\Program Files\Internet Explorer\js.mui
C:\Program Files\Internet Explorer\wmpscfgs.exe
C:\WINDOWS\system32\ctfmon .exe
.
---- Previous Run -------
.
C:\Documents and Settings\Steve\Application Data\gjahoaayj\hchgtkgtssd .exe
C:\Documents and Settings\Steve\Application Data\gjahoaayj\hchgtkgtssd.exe
C:\Documents and Settings\Steve\Application Data\gnwwy.exe
C:\Documents and Settings\Steve\ico .exe
C:\Documents and Settings\Steve\ico.exe
C:\Documents and Settings\Steve\Local Settings\Application Data\gjahoaayj\hchgtkgtssd.exe
C:\Documents and Settings\Steve\Local Settings\Application Data\liebcvcyv\uakvddrtssd .exe
C:\Documents and Settings\Steve\Local Settings\Application Data\liebcvcyv\uakvddrtssd.exe
C:\Documents and Settings\Steve\nwiz .exe
C:\Documents and Settings\Steve\nwiz.exe
C:\Documents and Settings\Steve\rundll32 .exe
C:\Documents and Settings\Steve\rundll32.exe
C:\Program Files\Internet Explorer\js.mui
C:\Program Files\Internet Explorer\wmpscfgs.exe
C:\WINDOWS\system32\app_dll.dll
C:\WINDOWS\system32\jivagaki.exe
C:\WINDOWS\system32\mesawunu.dll
C:\WINDOWS\system32\wosarako.exe

.
((((((((((((((((((((((((( Files Created from 2010-03-04 to 2010-04-04 )))))))))))))))))))))))))))))))
.

2010-04-04 01:48:46 . 2010-04-04 01:49:29 -------- d-----w- C:\Documents and Settings\Steve\Local Settings\Application Data\wxphqgwoy
2010-04-04 01:40:14 . 2010-04-04 02:07:33 -------- d-----w- C:\Documents and Settings\Steve\Local Settings\Application Data\nipsxdsoy
2010-04-04 01:40:14 . 2010-04-04 02:07:32 -------- d-----w- C:\Documents and Settings\Steve\Local Settings\Application Data\wvhryvhiq
2010-04-04 01:35:13 . 2010-04-04 01:35:45 -------- d-----w- C:\32788R22FWJFW.1.tmp
2010-04-03 17:56:25 . 2010-04-04 02:07:30 -------- d-----w- C:\Documents and Settings\Steve\Local Settings\Application Data\toggormwt
2010-04-03 17:56:25 . 2010-04-04 02:07:28 -------- d-----w- C:\Documents and Settings\Steve\Local Settings\Application Data\kaogoxxeb
2010-04-03 17:38:38 . 2010-04-03 17:38:38 -------- d-----w- C:\Program Files\Reference Assemblies
2010-04-03 17:38:16 . 2008-07-06 12:06:10 89088 ----a-w- C:\WINDOWS\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2010-04-03 17:37:00 . 2008-07-06 12:06:10 89088 -c----w- C:\WINDOWS\system32\dllcache\filterpipelineprintproc.dll
2010-04-03 17:37:00 . 2008-07-06 12:06:10 117760 ------w- C:\WINDOWS\system32\prntvpt.dll
2010-04-03 17:37:00 . 2008-07-06 10:50:03 597504 -c----w- C:\WINDOWS\system32\dllcache\printfilterpipelinesvc.exe
2010-04-03 17:37:00 . 2008-07-06 10:50:03 597504 ------w- C:\WINDOWS\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2010-04-03 17:36:59 . 2010-04-03 17:38:18 -------- d-----w- C:\db5349d942a45f662fa69f91
2010-04-03 17:36:59 . 2008-07-06 12:06:10 575488 -c----w- C:\WINDOWS\system32\dllcache\xpsshhdr.dll
2010-04-03 17:36:59 . 2008-07-06 12:06:10 575488 ------w- C:\WINDOWS\system32\xpsshhdr.dll
2010-04-03 17:36:59 . 2008-07-06 12:06:10 1676288 -c----w- C:\WINDOWS\system32\dllcache\xpssvcs.dll
2010-04-03 17:36:59 . 2008-07-06 12:06:10 1676288 ------w- C:\WINDOWS\system32\xpssvcs.dll
2010-04-03 17:31:56 . 2010-04-03 17:31:56 -------- d-----w- C:\Program Files\MSXML 6.0
2010-04-03 17:30:59 . 2010-04-03 17:31:00 -------- d-----w- C:\6542e74cd08059573a69f39b8dbe
2010-04-03 17:30:56 . 2010-04-03 17:39:59 -------- d-----w- C:\8ab3e2e80dac4a45d35eed
2010-04-02 02:22:46 . 2010-04-04 02:07:27 -------- d-----w- C:\Documents and Settings\Steve\Local Settings\Application Data\jnccdfmvo
2010-03-31 15:43:52 . 2010-03-31 15:43:47 238080 --sh--r- C:\WINDOWS\system32\winupd01.exe
2010-03-31 00:57:40 . 2008-03-21 17:57:18 14640 ------w- C:\WINDOWS\system32\spmsgXP_2k3.dll
2010-03-31 00:41:59 . 2010-03-31 00:41:59 581192 ----a-w- C:\WINDOWS\system32\WinUSBCoInstaller.dll
2010-03-31 00:41:58 . 2010-03-31 00:41:58 1112288 ----a-w- C:\WINDOWS\system32\WdfCoInstaller01007.dll
2010-03-31 00:24:57 . 2010-03-31 00:56:01 -------- d-----w- C:\Documents and Settings\Steve\.android
2010-03-29 01:25:55 . 2010-03-29 01:25:55 -------- d-----w- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
2010-03-27 00:30:26 . 2010-03-27 00:30:26 -------- d-----w- C:\Documents and Settings\LocalService\Application Data\PC Tools
2010-03-26 02:36:58 . 2010-03-26 02:36:58 552 ----a-w- C:\WINDOWS\system32\d3d8caps.dat
2010-03-25 04:27:50 . 2010-04-04 02:07:21 -------- d-sh--w- C:\Documents and Settings\Steve\.COMMgr
2010-03-25 04:27:18 . 2010-03-25 14:02:43 -------- d-----w- C:\Documents and Settings\Steve\Application Data\618914D8062DA2F74598D85E05FC4296
2010-03-14 21:28:44 . 2010-03-14 21:28:44 12464 ----a-w- C:\WINDOWS\system32\avgrsstx.dll
2010-03-11 05:24:25 . 2010-03-18 22:30:30 -------- d-----w- C:\Documents and Settings\Steve\Application Data\SolidWorks
2010-03-11 03:30:39 . 2010-03-11 03:30:39 -------- d-----w- C:\Documents and Settings\Steve\Application Data\DWGeditor
2010-03-11 03:30:06 . 2010-03-11 03:30:28 -------- d-----w- C:\Program Files\DWGeditor
2010-03-11 03:15:56 . 2010-03-11 03:29:23 -------- d-----w- C:\Program Files\Common Files\eDrawings2007
2010-03-11 03:15:54 . 2010-03-11 03:21:18 -------- d-----w- C:\Program Files\Common Files\SolidWorks Shared
2010-03-11 03:14:42 . 2010-03-11 03:14:42 -------- d-----w- C:\WINDOWS\system32\GroupPolicy
2010-03-11 03:14:36 . 2010-03-11 03:17:54 -------- d-----w- C:\Documents and Settings\All Users\Application Data\SolidWorks
2010-03-11 03:14:34 . 2010-03-11 03:31:31 -------- d-----w- C:\Program Files\SolidWorks
2010-03-11 03:14:34 . 2010-03-11 03:14:37 -------- d-----w- C:\Program Files\Common Files\Solidworks Data
2010-03-11 03:13:54 . 2010-03-11 03:14:02 -------- d-----w- C:\Program Files\Windows Desktop Search
2010-03-10 05:08:16 . 2010-03-10 05:08:16 -------- d-----w- C:\Program Files\Sun
2010-03-08 03:42:10 . 2010-03-10 05:07:45 410976 ----a-w- C:\WINDOWS\system32\deploytk.dll
2010-03-08 03:27:20 . 2010-03-08 03:27:20 -------- d-----w- C:\Sun

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-04 02:07:57 . 2010-04-04 02:07:45 27648 ----a-w- C:\Documents and Settings\Steve\rundll32.exe
2010-04-04 02:07:55 . 2008-09-24 23:56:26 -------- d-----w- C:\Program Files\QuickTime
2010-04-04 02:07:46 . 2010-04-04 02:07:46 27648 ----a-w- C:\Documents and Settings\Steve\nwiz.exe
2010-04-04 02:07:45 . 2010-04-04 02:07:45 27648 ----a-w- C:\Documents and Settings\Steve\rundll32 .exe
2010-04-04 02:07:37 . 2010-04-04 02:07:37 27648 ----a-w- C:\Documents and Settings\Steve\ico.exe
2010-04-04 02:07:16 . 2008-07-09 13:07:43 -------- d-----w- C:\Program Files\Common Files\LightScribe
2010-04-04 00:47:13 . 2008-10-03 20:49:44 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Google Updater
2010-04-03 17:40:29 . 2010-02-19 04:08:27 -------- d-----w- C:\Program Files\Spybot - Search & Destroy
2010-04-02 22:26:19 . 2009-10-20 03:59:53 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2010-04-01 17:21:20 . 2008-07-09 20:11:22 27648 ----a-w- C:\WINDOWS\system32\nwiz.exe
2010-04-01 17:21:14 . 2008-07-09 13:03:49 27648 ----a-w- C:\WINDOWS\system32\ico.exe
2010-03-31 04:53:07 . 2004-08-12 13:55:51 95360 ------w- C:\WINDOWS\system32\drivers\atapi.sys
2010-03-31 00:58:36 . 2010-03-31 00:58:36 0 ---ha-w- C:\WINDOWS\system32\drivers\Msft_Kernel_WinUSB_01007.Wdf
2010-03-31 00:57:44 . 2010-03-31 00:57:44 0 ---ha-w- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2010-03-29 01:25:37 . 2010-03-25 11:44:24 664 ----a-w- C:\WINDOWS\system32\d3d9caps.dat
2010-03-28 21:45:34 . 2010-03-25 14:35:40 -------- d-----w- C:\Program Files\Malwarebytes' Anti-Malware
2010-03-26 23:24:38 . 2009-12-10 04:30:47 -------- d-----w- C:\Documents and Settings\All Users\Application Data\avg9
2010-03-26 01:45:29 . 2010-03-26 01:45:29 161296 ----a-w- C:\WINDOWS\system32\drivers\tmcomm.sys
2010-03-26 01:45:27 . 2010-02-22 04:56:43 -------- d---a-w- C:\Documents and Settings\All Users\Application Data\TEMP
2010-03-25 14:39:17 . 2010-03-25 14:39:17 -------- d-----w- C:\Program Files\Loaris
2010-03-25 14:22:03 . 2010-03-25 14:22:03 -------- d-----w- C:\Documents and Settings\All Users\Application Data\IObit
2010-03-25 14:22:01 . 2010-03-25 14:22:01 -------- d-----w- C:\Program Files\IObit
2010-03-25 05:21:17 . 2008-07-24 01:46:27 -------- d-----w- C:\Program Files\Common Files\AOL
2010-03-23 03:25:48 . 2008-12-17 01:44:19 -------- d-----w- C:\Documents and Settings\Steve\Application Data\LimeWire
2010-03-22 04:03:38 . 2008-12-17 01:43:21 -------- d-----w- C:\Program Files\LimeWire
2010-03-22 03:25:10 . 2008-07-12 04:28:01 -------- d-----w- C:\Program Files\Common Files\Adobe
2010-03-14 21:28:46 . 2009-12-10 04:31:31 242696 ----a-w- C:\WINDOWS\system32\drivers\avgtdix.sys
2010-03-14 21:28:44 . 2009-12-10 04:31:22 29512 ----a-w- C:\WINDOWS\system32\drivers\avgmfx86.sys
2010-03-14 21:28:39 . 2009-12-10 04:31:32 25096 ----a-w- C:\WINDOWS\system32\drivers\AVGIDSxx.sys
2010-03-14 21:28:05 . 2009-12-10 04:31:26 216200 ----a-w- C:\WINDOWS\system32\drivers\avgldx86.sys
2010-03-14 21:28:02 . 2009-12-10 04:31:32 52872 ----a-w- C:\WINDOWS\system32\drivers\avgrkx86.sys
2010-03-12 05:16:19 . 2008-07-09 16:53:20 86928 ----a-w- C:\Documents and Settings\Steve\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-10 05:07:41 . 2008-09-02 02:18:52 -------- d-----w- C:\Program Files\Java
2010-03-03 03:48:57 . 2010-03-03 03:48:57 -------- d-----w- C:\Program Files\ESET
2010-03-03 03:39:54 . 2008-07-24 01:46:44 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Viewpoint
2010-03-01 23:47:43 . 2010-03-01 23:47:43 -------- d-----w- C:\Documents and Settings\Steve\Application Data\Malwarebytes
2010-03-01 23:47:38 . 2010-03-01 23:47:38 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-03-01 23:40:29 . 2009-09-07 01:31:00 227 ----a-w- C:\WINDOWS\system.tmp
2010-02-26 06:12:23 . 2004-08-12 14:09:30 662016 ----a-w- C:\WINDOWS\system32\wininet.dll
2010-02-26 06:12:17 . 2004-08-12 13:58:00 81920 ----a-w- C:\WINDOWS\system32\ieencode.dll
2010-02-22 05:17:52 . 2010-02-22 05:17:48 -------- d-----w- C:\Program Files\Quick Startup
2010-02-22 05:17:48 . 2010-02-22 05:17:48 -------- d-----w- C:\Documents and Settings\Steve\Application Data\GlarySoft
2010-02-22 04:55:23 . 2010-02-22 04:55:13 -------- d-----w- C:\Program Files\Trojan Remover
2010-02-22 04:55:13 . 2010-02-22 04:55:13 -------- d-----w- C:\Documents and Settings\Steve\Application Data\Simply Super Software
2010-02-22 04:55:13 . 2010-02-22 04:55:13 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2010-02-22 04:31:10 . 2010-02-22 04:31:11 95024 ----a-w- C:\WINDOWS\system32\drivers\SBREDrv.sys
2010-02-22 04:31:01 . 2010-03-25 05:02:36 15880 ----a-w- C:\WINDOWS\system32\lsdelete.exe
2010-02-22 04:20:43 . 2010-02-22 03:05:55 -------- d-----w- C:\Program Files\Lavasoft
2010-02-22 04:20:41 . 2010-02-22 04:20:40 -------- dc-h--w- C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-02-22 03:12:37 . 2010-02-22 03:05:55 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Lavasoft
2010-02-19 04:08:52 . 2010-02-19 04:08:27 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-19 04:05:59 . 2010-02-19 04:05:59 -------- d-----w- C:\Program Files\Trend Micro
2010-02-19 00:14:26 . 2010-02-04 00:02:22 -------- d-----w- C:\Program Files\SpeedFan
2010-02-05 04:28:04 . 2008-09-23 02:50:34 -------- d-----w- C:\Documents and Settings\Steve\Application Data\U3
2010-02-05 03:25:31 . 2010-02-05 03:23:55 -------- d-----w- C:\Program Files\iTunes
2010-02-05 03:24:02 . 2010-02-05 03:24:02 -------- d-----w- C:\Program Files\iPod
2010-02-05 03:23:59 . 2008-07-18 20:54:45 -------- d-----w- C:\Program Files\Common Files\Apple
2010-02-04 15:53:02 . 2010-02-22 03:12:38 64288 ----a-w- C:\WINDOWS\system32\drivers\Lbd.sys
2010-02-04 01:37:07 . 2008-10-03 20:49:42 -------- d-----w- C:\Program Files\Google
2010-02-04 01:33:50 . 2008-08-21 04:04:57 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Skype
2010-02-04 01:32:31 . 2008-10-07 19:09:18 -------- d-----w- C:\Program Files\Maxthon
2010-02-04 01:28:05 . 2009-03-17 02:26:49 -------- d-----w- C:\Program Files\1&1
2010-02-04 00:49:18 . 2008-08-21 04:07:40 -------- d-----w- C:\Documents and Settings\Steve\Application Data\skypePM
2010-02-04 00:43:38 . 2010-02-04 00:43:37 -------- d-----w- C:\Program Files\CpuIdle
2010-02-04 00:43:37 . 2010-02-04 00:43:37 4484 ----a-w- C:\WINDOWS\system32\drivers\cpuidlep.sys
.


#11 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:03:10 PM

Posted 04 April 2010 - 12:55 PM

Hi,

Please delete your copy of Combofix and download a fresh one.


  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop and make sure TDSSKiller.exe (the contents of the zipped file) is on the Desktop itself, not within a folder on the desktop.
  • Go to Start > Run (Or you can hold down your Windows key and press R) and copy and paste the following into the text field. (make sure you include the quote marks) Then press OK.

    "%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v

  • If it says "Hidden service detected" DO NOT type anything in. Just press Enter on your keyboard to not do anything to the file.
  • When it is done, a log file should be created on your C: drive called "TDSSKiller.txt" please copy and paste the contents of that file here.





1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

QUOTE
KillAll::

Folder::
C:\Documents and Settings\Steve\Local Settings\Application Data\wxphqgwoy
C:\Documents and Settings\Steve\Local Settings\Application Data\nipsxdsoy
C:\Documents and Settings\Steve\Local Settings\Application Data\wvhryvhiq
C:\Documents and Settings\Steve\Local Settings\Application Data\toggormwt
C:\Documents and Settings\Steve\Local Settings\Application Data\kaogoxxeb
C:\Documents and Settings\Steve\Local Settings\Application Data\jnccdfmvo
File::
C:\WINDOWS\system32\winupd01.exe
C:\Documents and Settings\Steve\rundll32.exe
C:\Documents and Settings\Steve\nwiz.exe
C:\Documents and Settings\Steve\rundll32 .exe
C:\Documents and Settings\Steve\ico.exe
C:\WINDOWS\system.tmp


Save this as CFScript.txt, in the same location as ComboFix.exe




Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#12 Starion89

Starion89
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Local time:10:10 AM

Posted 04 April 2010 - 09:29 PM

Tom,

I ran them both. The computer seems to be running faster, but there are still minor issues such as on startup I still get messages such as

* Error loading tesiliva.dll
*indofffsssd.exe has encountered a problem and needs to close...

Also, sites like docs.google.com still don't work. That may be the virus, it may not be but it was working fine for me before all this garbage started dry.gif

Can't thank you enough for your time

TDSSKiller Log:

21:57:26:781 4900 TDSS rootkit removing tool 2.2.8.1 Mar 22 2010 10:43:04
21:57:26:796 4900 ================================================================================
21:57:26:796 4900 SystemInfo:

21:57:26:796 4900 OS Version: 5.1.2600 ServicePack: 2.0
21:57:26:796 4900 Product type: Workstation
21:57:26:796 4900 ComputerName: STEVE-LAPTOP
21:57:26:796 4900 UserName: Steve
21:57:26:796 4900 Windows directory: C:\WINDOWS
21:57:26:796 4900 Processor architecture: Intel x86
21:57:26:796 4900 Number of processors: 2
21:57:26:796 4900 Page size: 0x1000
21:57:26:796 4900 Boot type: Normal boot
21:57:26:796 4900 ================================================================================
21:57:26:843 4900 UnloadDriverW: NtUnloadDriver error 2
21:57:26:843 4900 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
21:57:27:187 4900 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
21:57:27:187 4900 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
21:57:27:187 4900 wfopen_ex: Trying to KLMD file open
21:57:27:187 4900 wfopen_ex: File opened ok (Flags 2)
21:57:27:187 4900 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
21:57:27:187 4900 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
21:57:27:187 4900 wfopen_ex: Trying to KLMD file open
21:57:27:187 4900 wfopen_ex: File opened ok (Flags 2)
21:57:27:187 4900 Initialize success
21:57:27:187 4900
21:57:27:187 4900 Scanning Services ...
21:57:28:062 4900 Raw services enum returned 369 services
21:57:28:078 4900
21:57:28:078 4900 Scanning Kernel memory ...
21:57:28:078 4900 Devices to scan: 3
21:57:28:078 4900
21:57:28:078 4900 Driver Name: Disk
21:57:28:078 4900 IRP_MJ_CREATE : BA8EEC30
21:57:28:078 4900 IRP_MJ_CREATE_NAMED_PIPE : 804F4544
21:57:28:078 4900 IRP_MJ_CLOSE : BA8EEC30
21:57:28:078 4900 IRP_MJ_READ : BA8E8D9B
21:57:28:078 4900 IRP_MJ_WRITE : BA8E8D9B
21:57:28:078 4900 IRP_MJ_QUERY_INFORMATION : 804F4544
21:57:28:078 4900 IRP_MJ_SET_INFORMATION : 804F4544
21:57:28:078 4900 IRP_MJ_QUERY_EA : 804F4544
21:57:28:093 4900 IRP_MJ_SET_EA : 804F4544
21:57:28:093 4900 IRP_MJ_FLUSH_BUFFERS : BA8E9366
21:57:28:093 4900 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4544
21:57:28:093 4900 IRP_MJ_SET_VOLUME_INFORMATION : 804F4544
21:57:28:093 4900 IRP_MJ_DIRECTORY_CONTROL : 804F4544
21:57:28:093 4900 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4544
21:57:28:093 4900 IRP_MJ_DEVICE_CONTROL : BA8E944D
21:57:28:093 4900 IRP_MJ_INTERNAL_DEVICE_CONTROL : BA8ECFC3
21:57:28:093 4900 IRP_MJ_SHUTDOWN : BA8E9366
21:57:28:093 4900 IRP_MJ_LOCK_CONTROL : 804F4544
21:57:28:093 4900 IRP_MJ_CLEANUP : 804F4544
21:57:28:093 4900 IRP_MJ_CREATE_MAILSLOT : 804F4544
21:57:28:093 4900 IRP_MJ_QUERY_SECURITY : 804F4544
21:57:28:093 4900 IRP_MJ_SET_SECURITY : 804F4544
21:57:28:093 4900 IRP_MJ_POWER : BA8EAEF3
21:57:28:093 4900 IRP_MJ_SYSTEM_CONTROL : BA8EFA24
21:57:28:093 4900 IRP_MJ_DEVICE_CHANGE : 804F4544
21:57:28:093 4900 IRP_MJ_QUERY_QUOTA : 804F4544
21:57:28:093 4900 IRP_MJ_SET_QUOTA : 804F4544
21:57:28:125 4900 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
21:57:28:140 4900
21:57:28:140 4900 Driver Name: Disk
21:57:28:140 4900 IRP_MJ_CREATE : BA8EEC30
21:57:28:140 4900 IRP_MJ_CREATE_NAMED_PIPE : 804F4544
21:57:28:140 4900 IRP_MJ_CLOSE : BA8EEC30
21:57:28:140 4900 IRP_MJ_READ : BA8E8D9B
21:57:28:140 4900 IRP_MJ_WRITE : BA8E8D9B
21:57:28:140 4900 IRP_MJ_QUERY_INFORMATION : 804F4544
21:57:28:140 4900 IRP_MJ_SET_INFORMATION : 804F4544
21:57:28:140 4900 IRP_MJ_QUERY_EA : 804F4544
21:57:28:140 4900 IRP_MJ_SET_EA : 804F4544
21:57:28:140 4900 IRP_MJ_FLUSH_BUFFERS : BA8E9366
21:57:28:140 4900 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4544
21:57:28:140 4900 IRP_MJ_SET_VOLUME_INFORMATION : 804F4544
21:57:28:140 4900 IRP_MJ_DIRECTORY_CONTROL : 804F4544
21:57:28:140 4900 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4544
21:57:28:140 4900 IRP_MJ_DEVICE_CONTROL : BA8E944D
21:57:28:140 4900 IRP_MJ_INTERNAL_DEVICE_CONTROL : BA8ECFC3
21:57:28:140 4900 IRP_MJ_SHUTDOWN : BA8E9366
21:57:28:140 4900 IRP_MJ_LOCK_CONTROL : 804F4544
21:57:28:140 4900 IRP_MJ_CLEANUP : 804F4544
21:57:28:140 4900 IRP_MJ_CREATE_MAILSLOT : 804F4544
21:57:28:140 4900 IRP_MJ_QUERY_SECURITY : 804F4544
21:57:28:140 4900 IRP_MJ_SET_SECURITY : 804F4544
21:57:28:140 4900 IRP_MJ_POWER : BA8EAEF3
21:57:28:140 4900 IRP_MJ_SYSTEM_CONTROL : BA8EFA24
21:57:28:140 4900 IRP_MJ_DEVICE_CHANGE : 804F4544
21:57:28:140 4900 IRP_MJ_QUERY_QUOTA : 804F4544
21:57:28:140 4900 IRP_MJ_SET_QUOTA : 804F4544
21:57:28:203 4900 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
21:57:28:203 4900
21:57:28:203 4900 Driver Name: atapi
21:57:28:203 4900 IRP_MJ_CREATE : BA73B572
21:57:28:203 4900 IRP_MJ_CREATE_NAMED_PIPE : 804F4544
21:57:28:203 4900 IRP_MJ_CLOSE : BA73B572
21:57:28:203 4900 IRP_MJ_READ : 804F4544
21:57:28:203 4900 IRP_MJ_WRITE : 804F4544
21:57:28:203 4900 IRP_MJ_QUERY_INFORMATION : 804F4544
21:57:28:203 4900 IRP_MJ_SET_INFORMATION : 804F4544
21:57:28:203 4900 IRP_MJ_QUERY_EA : 804F4544
21:57:28:203 4900 IRP_MJ_SET_EA : 804F4544
21:57:28:203 4900 IRP_MJ_FLUSH_BUFFERS : 804F4544
21:57:28:203 4900 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4544
21:57:28:203 4900 IRP_MJ_SET_VOLUME_INFORMATION : 804F4544
21:57:28:203 4900 IRP_MJ_DIRECTORY_CONTROL : 804F4544
21:57:28:203 4900 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4544
21:57:28:203 4900 IRP_MJ_DEVICE_CONTROL : BA73B592
21:57:28:203 4900 IRP_MJ_INTERNAL_DEVICE_CONTROL : BA7377B4
21:57:28:203 4900 IRP_MJ_SHUTDOWN : 804F4544
21:57:28:203 4900 IRP_MJ_LOCK_CONTROL : 804F4544
21:57:28:203 4900 IRP_MJ_CLEANUP : 804F4544
21:57:28:203 4900 IRP_MJ_CREATE_MAILSLOT : 804F4544
21:57:28:203 4900 IRP_MJ_QUERY_SECURITY : 804F4544
21:57:28:203 4900 IRP_MJ_SET_SECURITY : 804F4544
21:57:28:203 4900 IRP_MJ_POWER : BA73B5BC
21:57:28:203 4900 IRP_MJ_SYSTEM_CONTROL : BA742164
21:57:28:203 4900 IRP_MJ_DEVICE_CHANGE : 804F4544
21:57:28:203 4900 IRP_MJ_QUERY_QUOTA : 804F4544
21:57:28:203 4900 IRP_MJ_SET_QUOTA : 804F4544
21:57:28:250 4900 C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: 1
21:57:28:250 4900
21:57:28:250 4900 Completed
21:57:28:250 4900
21:57:28:250 4900 Results:
21:57:28:250 4900 Memory objects infected / cured / cured on reboot: 0 / 0 / 0
21:57:28:250 4900 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
21:57:28:250 4900 File objects infected / cured / cured on reboot: 0 / 0 / 0
21:57:28:250 4900
21:57:28:250 4900 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
21:57:28:250 4900 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
21:57:28:250 4900 KLMD(ARK) unloaded successfully


ComboFix Log:

ComboFix 10-04-03.02 - Steve 04/04/2010 22:03:27.8.2 - x86
Running from: C:\Documents and Settings\Steve\Desktop\Schrauber.exe
Command switches used :: C:\Documents and Settings\Steve\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: ZoneAlarm Security Suite Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
* Created a new restore point

FILE ::
"C:\Documents and Settings\Steve\ico.exe"
"C:\Documents and Settings\Steve\nwiz.exe"
"C:\Documents and Settings\Steve\rundll32 .exe"
"C:\Documents and Settings\Steve\rundll32.exe"
"C:\WINDOWS\system.tmp"
"C:\WINDOWS\system32\winupd01.exe"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Steve\ico.exe
C:\Documents and Settings\Steve\Local Settings\Application Data\jnccdfmvo
C:\Documents and Settings\Steve\Local Settings\Application Data\jnccdfmvo\nuoxpietssd .exe
C:\Documents and Settings\Steve\Local Settings\Application Data\jnccdfmvo\nuoxpietssd.exe
C:\Documents and Settings\Steve\Local Settings\Application Data\kaogoxxeb
C:\Documents and Settings\Steve\Local Settings\Application Data\kaogoxxeb\smkhuxxtssd .exe
C:\Documents and Settings\Steve\Local Settings\Application Data\kaogoxxeb\smkhuxxtssd.exe
C:\Documents and Settings\Steve\Local Settings\Application Data\nipsxdsoy
C:\Documents and Settings\Steve\Local Settings\Application Data\nipsxdsoy\mowcqfatssd .exe
C:\Documents and Settings\Steve\Local Settings\Application Data\nipsxdsoy\mowcqfatssd.exe
C:\Documents and Settings\Steve\Local Settings\Application Data\toggormwt
C:\Documents and Settings\Steve\Local Settings\Application Data\toggormwt\stfkatotssd .exe
C:\Documents and Settings\Steve\Local Settings\Application Data\toggormwt\stfkatotssd.exe
C:\Documents and Settings\Steve\Local Settings\Application Data\wvhryvhiq
C:\Documents and Settings\Steve\Local Settings\Application Data\wvhryvhiq\mvrfvbqtssd .exe
C:\Documents and Settings\Steve\Local Settings\Application Data\wvhryvhiq\mvrfvbqtssd.exe
C:\Documents and Settings\Steve\Local Settings\Application Data\wxphqgwoy
C:\Documents and Settings\Steve\Local Settings\Application Data\wxphqgwoy\oklmkcptssd .exe
C:\Documents and Settings\Steve\Local Settings\Application Data\wxphqgwoy\oklmkcptssd.exe
C:\Documents and Settings\Steve\nwiz.exe
C:\Documents and Settings\Steve\rundll32 .exe
C:\Documents and Settings\Steve\rundll32.exe
C:\Program Files\Internet Explorer\js.mui
C:\Program Files\Internet Explorer\wmpscfgs.exe
C:\WINDOWS\system.tmp
C:\WINDOWS\system32\winupd01.exe
.
---- Previous Run -------
.
C:\Documents and Settings\Steve\ico .exe
C:\Documents and Settings\Steve\ico.exe
C:\Documents and Settings\Steve\nwiz .exe
C:\Documents and Settings\Steve\nwiz.exe
C:\Documents and Settings\Steve\rundll32 .exe
C:\Documents and Settings\Steve\rundll32.exe
C:\Program Files\Internet Explorer\js.mui
C:\Program Files\Internet Explorer\wmpscfgs.exe
C:\WINDOWS\system32\ctfmon .exe

.



#13 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:03:10 PM

Posted 05 April 2010 - 11:17 PM

This last logfile from Combofix seems incomplete, please have a look for C:\Combofix.txt and post it again.
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#14 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:03:10 PM

Posted 11 April 2010 - 08:14 AM

Due to the lack of feedback, this topic is now closed.
If you need this topic reopened, please PM a staff member and we will reopen it for you (include the address of this thread in your request). This applies to the original topic starter only. Everyone else with similar problems, please start a new topic.
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#15 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:03:10 PM

Posted 11 April 2010 - 11:21 PM

Reopened by user request.
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users