Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

cdrom.sys infected Rootkit.Kobcka.Patched.Gen


  • This topic is locked This topic is locked
38 replies to this topic

#1 cdromsysinfect

cdromsysinfect

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Local time:03:55 AM

Posted 15 May 2010 - 01:58 AM

Started with Defender, Telus Antivirus eventually killed that, but cannot remove the rootkit.

I ran DDS and GMER twice, the second time GMER didn't catch the root kit. The DDS logs are from the second pass. The second GMER log is attached as ark2.txt.
Please have a look and advise what I can do. thanks



DDS (Ver_10-03-17.01) - NTFSx86
Run by Owner at 19:06:45.35 on Fri 05/14/2010
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.447.220 [GMT -7:00]

AV: TELUS security services Anti-Virus *On-access scanning disabled* (Updated) {5B5A3BD7-8573-4672-AEA8-C9BB713B6755}
FW: TELUS security services Firewall *disabled* {80593BF4-D969-4EC5-ADAE-A22F2DFC7A22}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\TELUS\TELUS security services\Fws.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\TELUS\TELUS security services\AVG\Identity Protection\agent\Bin\AVGIDSAgent.exe
C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
C:\Program Files\TELUS\TELUS security advisor\ServicepointService.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\ltmoh\Ltmoh.exe
svchost.exe
C:\Program Files\Logitech\SetPointP\SetPoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
C:\Program Files\TELUS\TELUS security advisor\Tsa.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Owner\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.ca/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
{b524c853-68cd-7838-3c6c-5a20f8bb5a35}
uRun: [RegistryMechanic] c:\program files\registry mechanic\RegMech.exe /S
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [LtMoh] c:\program files\ltmoh\Ltmoh.exe
mRun: [EvtMgr6] c:\program files\logitech\setpointp\SetPoint.exe /launchGaming
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [Regedit32] c:\windows\system32\regedit.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} - hxxp://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9}
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6087.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1269715061671
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1269816630625
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54}
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
LSA: Notification Packages = msuinfa.dll

============= SERVICES / DRIVERS ===============

R0 RadialpointIDSEH;RadialpointIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-3-28 25608]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\common files\pc tools\smonitor\StartManSvc.exe [2010-5-11 632792]
R2 RadialpointIDSAgent;RadialpointIDSAgent;c:\program files\telus\telus security services\avg\identity protection\agent\bin\AVGIDSAgent.exe [2010-3-28 5832712]
R2 ServicepointService;ServicepointService;c:\program files\telus\telus security advisor\ServicepointService.exe [2010-3-28 668912]
R3 RadialpointIDSDriver;RadialpointIDSDriver;c:\program files\telus\telus security services\avg\identity protection\agent\drivers\AVGIDSDriver.sys [2010-3-28 122376]
R3 RadialpointIDSFilter;RadialpointIDSFilter;c:\program files\telus\telus security services\avg\identity protection\agent\drivers\AVGIDSfilter.sys [2010-3-28 30216]
R3 RadialpointIDSShim;RadialpointIDSShim;c:\program files\telus\telus security services\avg\identity protection\agent\drivers\AVGIDSShim.sys [2010-3-28 25736]
S2 Radialpoint Security Services;TELUS security services;c:\program files\telus\telus security services\RpsSecurityAwareR.exe [2009-12-14 165408]

=============== Created Last 30 ================

2010-05-12 06:08:09 0 ----a-w- c:\documents and settings\owner\defogger_reenable
2010-05-12 05:20:31 0 d-----w- c:\docume~1\owner\applic~1\Registry Mechanic
2010-05-12 04:51:28 880640 ----a-w- c:\windows\system32\UniBox10.ocx
2010-05-12 04:51:28 212992 ----a-w- c:\windows\system32\UniBoxVB12.ocx
2010-05-12 04:51:28 1101824 ----a-w- c:\windows\system32\UniBox210.ocx
2010-05-12 04:51:23 0 d-----w- c:\program files\common files\PC Tools
2010-05-12 03:54:42 6656 ----a-w- c:\windows\system32\CNMVS58.DLL
2010-05-12 03:54:42 105984 ----a-w- c:\windows\system32\CNMLM58.DLL
2010-05-12 03:54:39 86016 ----a-w- c:\windows\system32\CNMCP58.exe
2010-05-12 03:54:36 0 d--h--w- C:\BJPrinter
2010-05-12 03:26:30 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2010-05-12 03:26:30 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-05-09 17:11:42 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-05-09 17:11:42 16736 ----a-w- c:\windows\system32\mucltui.dll.mui
2010-05-09 04:00:45 0 d-----w- c:\program files\InterVideo

==================== Find3M ====================

2010-05-13 04:32:02 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2010-03-28 23:56:12 4146 ----a-w- c:\windows\SEC13C5.tmp
2010-03-28 23:47:59 98240 ----a-w- c:\windows\system32\drivers\cdrom.sys
2010-03-28 18:15:39 53192 ----a-w- c:\windows\system32\drivers\rp_skt32.sys
2010-03-28 18:15:23 48384 ----a-w- c:\windows\system32\drivers\rp_pkt32.sys
2010-03-24 05:51:48 12784 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-03-20 21:15:17 4 ----a-w- c:\docume~1\owner\applic~1\avdrn.dat
2010-03-20 05:17:58 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf

============= FINISH: 19:07:10.71 ===============




Attached Files



BC AdBot (Login to Remove)

 


#2 mpascal

mpascal

    Math Nerd


  • Members
  • 1,653 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Canada
  • Local time:05:55 AM

Posted 15 May 2010 - 03:35 PM

Hi cdromsysinfect,

Welcome to Bleeping Computer.

My name is mpascal, and I will be helping you fix your problem.

Before we begin, I would like to make a few things clear so that we can fix your problem as efficiently as possible:
  • Be sure to follow all my instructions carefully! If there is anything you don''t understand, don''t hesitate to ask.
  • Please do not do anything or perform other steps unless I have asked you to do so.
  • Please make sure you post all logs I ask you to, and make sure that the entire log gets posted.
  • Don't attach any logs unless asked. Posting them in the forums will make them easier to analyze.
  • If you are unsure of how to reply, or need help with anything regarding the website, please look here.
STEP 1 - MBAM

Please download Malwarebytes Anti-Malware (v1.44) and save it to your desktop.MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.
  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
    For instructions with screenshots, please refer to the How to use Malwarebytes' Anti-Malware Guide.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

STEP 2 - OTL

Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • In the Custom Scans box, copy and paste the following:
    CODE
    netsvcs
    safebootminimal
    %SYSTEMDRIVE%\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of the files, and post it with your next reply.

STEP 3 - Reply

Please reply with the following logs:
  • MBAM Log
  • OTL Log

Posted Image

Stay with your topic! Topics that go 4 days without a reply will be closed. PM me to reopen.

Please don't PM asking for support. Post on the forums instead.

My help is free, but if you wish to donate and help continue my fight against malware, click here: Posted Image


#3 cdromsysinfect

cdromsysinfect
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Local time:03:55 AM

Posted 15 May 2010 - 10:14 PM

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4105

Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

5/15/2010 7:18:16 PM
mbam-log-2010-05-15 (19-18-16).txt

Scan type: Quick scan
Objects scanned: 124229
Time elapsed: 8 minute(s), 31 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 2
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\Software\timesink, inc. (AdWare.TimeSink) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\timesink, inc. (AdWare.TimeSink) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cdrom (Trojan.Patched) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\regedit32 (Trojan.Agent) -> Delete on reboot.
HKEY_CLASSES_ROOT\.exe\shell\open\command\(default) (Hijack.ExeFile) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\dllcache\cdrom.sys (Trojan.Patched) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\cdrom.sys (Trojan.Patched) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\oashdihasidhasuidhiasdhiashdiuasdhasd (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\config\systemprofile\oashdihasidhasuidhiasdhiashdiuasdhasd (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\Owner\Application Data\avdrn.dat (Malware.Trace) -> Quarantined and deleted successfully.




OTL logfile created on: 5/15/2010 7:27:14 PM - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

447.00 Mb Total Physical Memory | 263.00 Mb Available Physical Memory | 59.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.88 Gb Total Space | 46.94 Gb Free Space | 84.00% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OWNER-E981C7C7F
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
PRC - C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe (Logitech, Inc.)
PRC - C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\TELUS\TELUS security services\Fws.exe (TELUS)
PRC - C:\Program Files\TELUS\TELUS security advisor\ServicepointService.exe (Radialpoint Inc.)
PRC - C:\Program Files\TELUS\TELUS security advisor\Tsa.exe (TELUS)
PRC - C:\Program Files\TELUS\TELUS security services\AVG\Identity Protection\agent\bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ltmoh\ltmoh.exe (Agere Systems)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (PCToolsSSDMonitorSvc) -- C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
SRV - (LBTServ) -- C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (Radialpoint Security Services) -- C:\Program Files\TELUS\TELUS security services\RpsSecurityAwareR.exe (TELUS)
SRV - (RP_FWS) -- C:\Program Files\TELUS\TELUS security services\Fws.exe (TELUS)
SRV - (ServicepointService) -- C:\Program Files\TELUS\TELUS security advisor\ServicepointService.exe (Radialpoint Inc.)
SRV - (RadialpointIDSAgent) -- C:\Program Files\TELUS\TELUS security services\AVG\Identity Protection\agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (scan) -- C:\Program Files\TELUS\TELUS security services\BitDefender\scan.dll (S.C. BitDefender S.R.L)
SRV - (PDEngine) -- C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe (Raxco Software, Inc.)
SRV - (PDAgent) -- C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe (Raxco Software, Inc.)


========== Driver Services (SafeList) ==========

DRV - (RPSKT) Security Services Driver (x86) -- C:\WINDOWS\system32\drivers\rp_skt32.sys (Radialpoint Inc.)
DRV - (Trufos) -- C:\Program Files\TELUS\TELUS security services\BitDefender\trufos.sys (BitDefender S.R.L.)
DRV - (Profos) -- C:\Program Files\TELUS\TELUS security services\BitDefender\profos.sys (BitDefender S.R.L.)
DRV - (LUsbFilt) -- C:\WINDOWS\system32\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV - (LMouFilt) -- C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) -- C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (RadialpointIDSDriver) -- C:\Program Files\TELUS\TELUS security services\AVG\Identity Protection\agent\drivers\AVGIDSDriver.sys (AVG Technologies )
DRV - (RadialpointIDSFilter) -- C:\Program Files\TELUS\TELUS security services\AVG\Identity Protection\agent\drivers\AVGIDSfilter.sys (AVG Technologies )
DRV - (RadialpointIDSShim) -- C:\Program Files\TELUS\TELUS security services\AVG\Identity Protection\agent\drivers\AVGIDSShim.sys (AVG Technologies )
DRV - (RadialpointIDSEH) -- C:\WINDOWS\system32\drivers\AVGIDSEH.sys (AVG Technologies )
DRV - (bdfsfltr) -- C:\WINDOWS\system32\drivers\bdfsfltr.sys (BitDefender S.R.L. Bucharest, ROMANIA)
DRV - (DefragFS) -- C:\WINDOWS\system32\drivers\DefragFs.sys (Raxco Software, Inc.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) -- C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (AR5211) -- C:\WINDOWS\system32\drivers\ar5211.sys (Atheros Communications, Inc.)
DRV - (ESDCR) -- C:\WINDOWS\system32\drivers\ESD7SK.sys (ENE Technology Inc.)
DRV - (EMSCR) -- C:\WINDOWS\system32\drivers\EMS7SK.sys (ENE Technology Inc.)
DRV - (ESMCR) -- C:\WINDOWS\system32\drivers\ESM7SK.sys (ENE Technology Inc.)
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (AgereSoftModem) -- C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ALCXSENS) -- C:\WINDOWS\system32\drivers\ALCXSENS.SYS (Sensaura Ltd)
DRV - (caboagp) -- C:\WINDOWS\system32\DRIVERS\atisgkaf.sys (ATI Technologies Inc.)
DRV - (SMCIRDA) -- C:\WINDOWS\system32\drivers\smcirda.sys (SMC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF - HKLM\software\mozilla\Firefox\Extensions\\{6454152D-AF36-4C5F-A6C4-C7DF61D063AB}: C:\Documents and Settings\Owner\Local Settings\Application Data\{6454152D-AF36-4C5F-A6C4-C7DF61D063AB} [2010/03/20 14:19:09 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B88A0904-8385-4095-BB15-F3784491B035}: C:\Documents and Settings\Administrator\Local Settings\Application Data\{B88A0904-8385-4095-BB15-F3784491B035} [2010/03/21 23:08:00 | 000,000,000 | ---D | M]


O1 HOSTS File: ([2004/08/04 05:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {b524c853-68cd-7838-3c6c-5a20f8bb5a35} - Reg Error: Value error. File not found
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [LtMoh] C:\Program Files\ltmoh\ltmoh.exe (Agere Systems)
O4 - HKCU..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe (PC Tools)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe File not found
O16 - DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} http://www.logitech.com/devicedetector/plu...Detection32.cab (Device Detection)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} Reg Error: Key error. (SpinTop DRM Control)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/...lscbase6087.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/...b?1269715061671 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu...b?1269816630625 (MUWebControl Class)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} Reg Error: Key error. (ArmHelper Control)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - Unable to open key or key not present!
O32 - AutoRun File - [2008/06/04 15:55:50 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (PDBoot.exe) - C:\WINDOWS\System32\PDBoot.exe (Raxco Software, Inc.)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = secfile] -- Reg Error: Value error. File not found
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2008/06/04 15:55:19 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: Radialpoint Security Services - C:\Program Files\TELUS\TELUS security services\RpsSecurityAwareR.exe (TELUS)
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sermouse.sys - Driver
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vds - Service
SafeBootMin: vga.sys - Driver
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
Unable to start service SrService!

========== Files/Folders - Created Within 30 Days ==========

[2010/05/15 19:19:12 | 000,570,880 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/05/15 18:31:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2010/05/15 18:31:46 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/05/15 18:31:45 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/05/15 18:31:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/05/15 18:31:44 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/05/15 18:28:13 | 006,153,376 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Owner\Desktop\mbam-setup.exe
[2010/05/11 22:20:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\Registry Mechanic
[2010/05/11 22:04:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\PC Tools - Reg Mechanic subscription_files
[2010/05/11 21:51:28 | 001,101,824 | ---- | C] (Woodbury Associates Limited) -- C:\WINDOWS\System32\UniBox210.ocx
[2010/05/11 21:51:28 | 000,880,640 | ---- | C] (Woodbury Associates Limited) -- C:\WINDOWS\System32\UniBox10.ocx
[2010/05/11 21:51:28 | 000,212,992 | ---- | C] (Woodbury Associates Limited) -- C:\WINDOWS\System32\UniBoxVB12.ocx
[2010/05/11 21:51:23 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2010/05/11 21:51:14 | 000,000,000 | ---D | C] -- C:\Program Files\Registry Mechanic
[2010/05/11 21:50:38 | 010,239,072 | ---- | C] (PC Tools ) -- C:\Documents and Settings\Owner\Desktop\rminstall.exe
[2010/05/11 20:54:42 | 000,105,984 | ---- | C] (CANON INC.) -- C:\WINDOWS\System32\CNMLM58.DLL
[2010/05/11 20:54:39 | 000,086,016 | ---- | C] (CANON INC.) -- C:\WINDOWS\System32\CNMCP58.exe
[2010/05/11 20:54:36 | 000,000,000 | -H-D | C] -- C:\BJPrinter
[2010/05/11 20:54:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\i560xp173eusZ
[2010/05/11 20:26:30 | 000,025,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbprint.sys
[2010/05/11 06:44:46 | 024,044,340 | ---- | C] (Radialpoint Inc. ) -- C:\Documents and Settings\Owner\Desktop\Radialpoint_SC25_setup.exe
[2010/05/09 10:11:42 | 000,274,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll
[2010/05/09 10:11:42 | 000,016,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll.mui
[2010/05/08 21:00:45 | 000,000,000 | ---D | C] -- C:\Program Files\InterVideo
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/05/15 19:20:52 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/05/15 19:20:50 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/05/15 19:19:50 | 002,097,152 | ---- | M] () -- C:\Documents and Settings\Owner\ntuser.dat
[2010/05/15 19:19:50 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Owner\ntuser.ini
[2010/05/15 19:19:43 | 007,728,710 | -H-- | M] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2010/05/15 19:19:14 | 000,570,880 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/05/15 18:31:49 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/05/15 18:28:24 | 006,153,376 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Owner\Desktop\mbam-setup.exe
[2010/05/14 19:09:12 | 000,002,225 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Attach.zip
[2010/05/12 21:32:02 | 000,016,400 | ---- | M] (Logitech, Inc.) -- C:\WINDOWS\System32\drivers\LNonPnP.sys
[2010/05/11 23:17:21 | 000,293,376 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\gmer.exe
[2010/05/11 23:16:55 | 000,284,915 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\gmer.zip
[2010/05/11 23:09:41 | 000,525,824 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\dds.scr
[2010/05/11 23:08:09 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Owner\defogger_reenable
[2010/05/11 23:07:37 | 000,050,477 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Defogger.exe
[2010/05/11 22:20:59 | 002,781,184 | ---- | M] () -- C:\Documents and Settings\Owner\ntuser.dat.rmbak
[2010/05/11 22:04:18 | 000,039,337 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\PC Tools - Reg Mechanic subscription.htm
[2010/05/11 21:50:38 | 010,239,072 | ---- | M] (PC Tools ) -- C:\Documents and Settings\Owner\Desktop\rminstall.exe
[2010/05/11 20:53:55 | 003,091,456 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\i560xp173eusZ.exe
[2010/05/11 06:44:47 | 024,044,340 | ---- | M] (Radialpoint Inc. ) -- C:\Documents and Settings\Owner\Desktop\Radialpoint_SC25_setup.exe
[2010/05/11 06:00:09 | 000,000,069 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\stinger.opt
[2010/05/10 20:45:42 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/05/09 22:04:10 | 000,001,938 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Scrabble Complete.lnk
[2010/05/08 15:56:10 | 000,002,486 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/05/08 15:56:10 | 000,000,262 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/05/08 15:56:10 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2010/05/08 15:55:29 | 000,312,172 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/05/08 15:55:29 | 000,040,394 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/05/08 15:55:28 | 000,356,120 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/05/15 18:31:49 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/05/12 20:01:16 | 000,002,225 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Attach.zip
[2010/05/11 23:16:52 | 000,284,915 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\gmer.zip
[2010/05/11 23:09:38 | 000,525,824 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\dds.scr
[2010/05/11 23:08:09 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Owner\defogger_reenable
[2010/05/11 23:07:37 | 000,050,477 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Defogger.exe
[2010/05/11 22:20:28 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\Owner\S-1-5-21-2052111302-1960408961-682003330-1003.rrr.LOG
[2010/05/11 22:04:06 | 000,039,337 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\PC Tools - Reg Mechanic subscription.htm
[2010/05/11 20:54:42 | 000,006,656 | ---- | C] () -- C:\WINDOWS\System32\CNMVS58.DLL
[2010/05/11 20:53:45 | 003,091,456 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\i560xp173eusZ.exe
[2010/05/11 06:00:09 | 000,000,069 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\stinger.opt
[2010/05/09 22:04:10 | 000,001,938 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Scrabble Complete.lnk
[2010/03/28 16:31:48 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
[2010/03/28 16:29:53 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2009/10/21 14:20:08 | 000,005,504 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen_x86.sys
[2008/12/26 17:18:25 | 000,189,952 | ---- | C] () -- C:\WINDOWS\Qcard32.dll
[2008/06/04 16:53:51 | 000,128,113 | ---- | C] () -- C:\WINDOWS\System32\csellang.ini
[2008/06/04 16:53:51 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\csellang.dll
[2008/06/04 16:53:51 | 000,010,165 | ---- | C] () -- C:\WINDOWS\System32\tosmreg.ini
[2008/06/04 16:53:51 | 000,007,671 | ---- | C] () -- C:\WINDOWS\System32\cseltbl.ini
[2008/06/04 16:44:17 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2008/06/04 16:43:45 | 000,356,352 | ---- | C] () -- C:\WINDOWS\System32\EMCRI.dll
[2004/04/21 22:58:26 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\ati2evxx.dll

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2008/06/04 15:55:50 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2010/05/08 15:56:10 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2008/06/04 15:55:50 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2008/06/04 15:55:50 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2008/06/04 15:55:50 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004/08/04 05:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2010/03/28 21:25:32 | 000,250,032 | ---- | M] () -- C:\ntldr
[2010/05/15 19:20:47 | 704,643,072 | -HS- | M] () -- C:\pagefile.sys
[2010/03/24 22:32:58 | 000,000,284 | ---- | M] () -- C:\pctlsp.log
[2009/01/29 17:36:52 | 000,000,211 | ---- | M] () -- C:\Shortcut to CD Drive.lnk

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2008/06/04 07:41:51 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2008/06/04 07:41:51 | 000,634,880 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2008/06/04 07:41:50 | 000,884,736 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\drivers\*.sys /90 >
[2010/05/12 21:32:02 | 000,016,400 | ---- | M] (Logitech, Inc.) -- C:\WINDOWS\system32\drivers\LNonPnP.sys
[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
[2010/03/28 11:15:23 | 000,048,384 | ---- | M] (Radialpoint, Inc.) -- C:\WINDOWS\system32\drivers\rp_pkt32.sys
[2010/03/28 11:15:39 | 000,053,192 | ---- | M] (Radialpoint Inc.) -- C:\WINDOWS\system32\drivers\rp_skt32.sys

========== Alternate Data Streams ==========

@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7E95B6FD
@Alternate Data Stream - 152 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:2D5907B8
< End of report >





OTL Extras logfile created on: 5/15/2010 7:27:14 PM - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

447.00 Mb Total Physical Memory | 263.00 Mb Available Physical Memory | 59.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.88 Gb Total Space | 46.94 Gb Free Space | 84.00% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: OWNER-E981C7C7F
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.exe [@ = secfile] -- Reg Error: Value error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.exe [@ = exefile] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 1
"FirewallOverride" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\dplaysvr.exe" = C:\WINDOWS\system32\dplaysvr.exe:*:Disabled:Microsoft DirectPlay Helper -- (Microsoft Corporation)
"C:\Program Files\Infogrames Interactive\Scrabble Complete\ScrabbleComplete.exe" = C:\Program Files\Infogrames Interactive\Scrabble Complete\ScrabbleComplete.exe:*:Enabled:Scrabble Complete -- (Infogrames Interactive)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{073CAD7E-FE3B-47E0-96B6-F3B8CD803775}" = RPS RpsCore
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{6421F085-1FAA-DE13-D02A-CFB412C522A4}" = Acrobat.com
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7B738CD9-D107-48C7-8E65-2E6639A39C8D}" = PerfectDisk 10 Professional
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B88DD94-1AAE-41C4-BD95-2D8737D5E9E2}" = Watson
"{A17FD8C6-1AC2-46E7-AD0A-70C602C3504D}" = Hoyle Friday Night Poker
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A43BF6A5-D5F0-4AAA-BF41-65995063EC44}" = MSXML 6.0 Parser
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{B36649A3-D0DD-4706-B042-F5B384529C7A}" = Scrabble Complete
"{B44AA698-B221-4B3B-8CA5-E65EF6A5AF26}" = Hoyle Card Games 2005
"{B86B0252-83FA-434B-B8B3-996F2D367991}" = TELUS security services
"{C1939820-A945-11D4-86F6-0001031E5712}" = InterVideo WinDVD
"{CEA0BA90-DED4-169F-BA18-D9F57E43E6AD}" = Deal or No Deal
"{EA1A6A54-0CD8-4A26-8B47-DA9654D35B4B}" = RPS PerfectDiskStub
"{EA93D23C-5470-42AB-88B3-7CBF0D14E14D}" = RPS CRT
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"31" = 31
"3D Maze Man Special Edition" = 3D Maze Man Special Edition
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"BUGS" = BUGS
"CANONBJ_Deinstall_CNMCP58.DLL" = Canon i560
"Chinese Checkers Special Edition" = Chinese Checkers Special Edition
"Chomper 3D" = Chomper 3D
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Crazy Drake Special Edition" = Crazy Drake Special Edition
"Crazy Puzzle Special Edition" = Crazy Puzzle Special Edition
"Demonstar Special Edition" = Demonstar Special Edition
"Dweebs Special Edition" = Dweebs Special Edition
"Extreme Bugs Special Edition" = Extreme Bugs Special Edition
"Galactic Invasion Special Edition" = Galactic Invasion Special Edition
"Galaxy of Games Red" = Galaxy of Games Red
"HeavyGearUninstallKey" = Heavy Gear
"Jewel Jam Special Edition" = Jewel Jam Special Edition
"Ludo Safari Special Edition" = Ludo Safari Special Edition
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Memory Match" = Memory Match
"Mini Golf Master Special Edition" = Mini Golf Master Special Edition
"Moon Buggy" = Moon Buggy
"Moonshot" = Moonshot
"Nebulae Fighter Special Edition" = Nebulae Fighter Special Edition
"Playground Special Edition" = Playground Special Edition
"RadialpointClientGateway_is1" = TELUS security advisor 3.5.12
"Raptor Special Edition" = Raptor Special Edition
"Registry Mechanic_is1" = Registry Mechanic 9.0
"Solitaire 25 Volume 3" = Solitaire 25 Volume 3
"Solitary Confinement" = Solitary Confinement
"SP6" = Logitech SetPoint 6.0
"Speedy Eggbert Special Edition" = Speedy Eggbert Special Edition
"Star Miner Special Edition" = Star Miner Special Edition
"Tachyon" = Tachyon
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"US Slots" = US Slots
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"Wendys Word Game Special Edition" = Wendys Word Game Special Edition
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows XP Service Pack" = Windows XP Service Pack 3

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 3/29/2010 12:44:46 AM | Computer Name = OWNER-E981C7C7F | Source = Ci | ID = 4124
Description = Content index on c:\system volume information\catalog.wci is corrupt.
Please shutdown and restart the Indexing Service (cisvc).

Error - 3/29/2010 12:44:46 AM | Computer Name = OWNER-E981C7C7F | Source = Ci | ID = 4126
Description = Cleaning up corrupt content index metadata on c:\system volume information\catalog.wci.
Index will be automatically restored by refiltering all documents.

Error - 3/31/2010 1:10:33 PM | Computer Name = OWNER-E981C7C7F | Source = Application Error | ID = 1000
Description = Faulting application scrabblecomplete.exe, version 1.0.0.0, faulting
module binkw32.dll, version 1.5.10.0, fault address 0x0001fecd.

Error - 3/31/2010 1:10:49 PM | Computer Name = OWNER-E981C7C7F | Source = Ci | ID = 4126
Description = Cleaning up corrupt content index metadata on c:\system volume information\catalog.wci.
Index will be automatically restored by refiltering all documents.

Error - 5/9/2010 12:17:42 AM | Computer Name = OWNER-E981C7C7F | Source = Application Error | ID = 1005
Description = Windows cannot access the file D:\Setup.exe for one of the following
reasons: there is a problem with the network connection, the disk that the file
is stored on, or the storage drivers installed on this computer; or the disk is
missing. Windows closed the program Setup.exe because of this error. Program: Setup.exe
File:
D:\Setup.exe The error value is listed in the Additional Data section. User Action
1.
Open the file again. This situation might be a temporary problem that corrects
itself when the program runs again. 2. If the file still cannot be accessed and -
It is on the network, your network administrator should verify that there is not
a problem with the network and that the server can be contacted. - It is on a removable
disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted
into the computer. 3. Check and repair the file system by running CHKDSK. To run
CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt,
type CHKDSK /F, and then press ENTER. 4. If the problem persists, restore the file
from a backup copy. 5. Determine whether other files on the same disk can be opened.
If not, the disk might be damaged. If it is a hard disk, contact your administrator
or computer hardware vendor for further assistance. Additional Data Error value:
C000009A Disk type: 5

Error - 5/9/2010 12:17:52 AM | Computer Name = OWNER-E981C7C7F | Source = Application Error | ID = 1000
Description = Faulting application Setup.exe, version 6.31.100.1190, faulting module
Setup.exe, version 6.31.100.1190, fault address 0x0000661c.

Error - 5/12/2010 1:13:38 AM | Computer Name = OWNER-E981C7C7F | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 6.0.2900.2180, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 5/12/2010 1:13:54 AM | Computer Name = OWNER-E981C7C7F | Source = Application Hang | ID = 1001
Description = Fault bucket 126637809.

Error - 5/12/2010 1:30:33 AM | Computer Name = OWNER-E981C7C7F | Source = Application Error | ID = 1000
Description = Faulting application scrabblecomplete.exe, version 1.0.0.0, faulting
module binkw32.dll, version 1.5.10.0, fault address 0x0001fecd.

Error - 5/12/2010 1:30:42 AM | Computer Name = OWNER-E981C7C7F | Source = Application Error | ID = 1001
Description = Fault bucket 130521022.

[ System Events ]
Error - 5/11/2010 9:55:40 AM | Computer Name = OWNER-E981C7C7F | Source = Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver service which
failed to start because of the following error: %%31

Error - 5/11/2010 9:55:40 AM | Computer Name = OWNER-E981C7C7F | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD bdfsfltr Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip WS2IFSL

Error - 5/11/2010 9:57:36 AM | Computer Name = OWNER-E981C7C7F | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 5/12/2010 5:08:04 AM | Computer Name = OWNER-E981C7C7F | Source = DCOM | ID = 10010
Description = The server {73E709EA-5D93-4B2E-BBB0-99B7938DA9E4} did not register
with DCOM within the required timeout.

Error - 5/12/2010 11:26:21 PM | Computer Name = OWNER-E981C7C7F | Source = DCOM | ID = 10010
Description = The server {73E709EA-5D93-4B2E-BBB0-99B7938DA9E4} did not register
with DCOM within the required timeout.

Error - 5/12/2010 11:54:27 PM | Computer Name = OWNER-E981C7C7F | Source = DCOM | ID = 10010
Description = The server {73E709EA-5D93-4B2E-BBB0-99B7938DA9E4} did not register
with DCOM within the required timeout.

Error - 5/13/2010 1:36:10 AM | Computer Name = OWNER-E981C7C7F | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the ShellHWDetection service.

Error - 5/13/2010 6:06:23 AM | Computer Name = OWNER-E981C7C7F | Source = DCOM | ID = 10010
Description = The server {73E709EA-5D93-4B2E-BBB0-99B7938DA9E4} did not register
with DCOM within the required timeout.

Error - 5/15/2010 10:27:43 PM | Computer Name = OWNER-E981C7C7F | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 5/15/2010 10:27:43 PM | Computer Name = OWNER-E981C7C7F | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2


< End of report >












#4 mpascal

mpascal

    Math Nerd


  • Members
  • 1,653 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Canada
  • Local time:05:55 AM

Posted 15 May 2010 - 11:44 PM

Hi there,

Can you rescan with GMER and post the log here?

Posted Image

Stay with your topic! Topics that go 4 days without a reply will be closed. PM me to reopen.

Please don't PM asking for support. Post on the forums instead.

My help is free, but if you wish to donate and help continue my fight against malware, click here: Posted Image


#5 cdromsysinfect

cdromsysinfect
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Local time:03:55 AM

Posted 17 May 2010 - 12:48 AM

I tried twice, both times the PC blue screened and rebooted, the second time GMER ran for more than 8 hours before rebooting. The blue screen went by too fast for me to catch any details. Ill try again overnight. Should I disable the Antivirus?

#6 mpascal

mpascal

    Math Nerd


  • Members
  • 1,653 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Canada
  • Local time:05:55 AM

Posted 17 May 2010 - 08:05 AM

Yes, try disabling the antivirus. If that doesn't work, try scanning with only Modules and Sections checked.

Posted Image

Stay with your topic! Topics that go 4 days without a reply will be closed. PM me to reopen.

Please don't PM asking for support. Post on the forums instead.

My help is free, but if you wish to donate and help continue my fight against malware, click here: Posted Image


#7 cdromsysinfect

cdromsysinfect
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Local time:03:55 AM

Posted 18 May 2010 - 02:02 AM

Had trouble keeping the laptop running. Heat problems I think, the fan sounds odd.
I disabled all startup items using MSconfig, as well as all services by PC Tools Registry mechanic and Telus Security firewall and antivirus components, also including one called ServicepointService that seems to be related to a suite of games installed on this PC.


I got the "GMER detected system mod's caused by rootkit activity" message at the end of the scan.
Here is the log.

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-17 23:21:45
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\kwkdipow.sys

Looks like we're in different time zones. I'm in B.C. so not sure when you will see this.
Talk to you tomorrow.

Thanks.
---- Kernel code sections - GMER 1.0.15 ----

init C:\WINDOWS\system32\drivers\ALCXSENS.SYS entry point in "init" section [0xF6B8E510]

---- Devices - GMER 1.0.15 ----

AttachedDevice \Driver\Tcpip \Device\Ip rp_skt32.sys (Radialpoint Filter/Radialpoint Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp rp_skt32.sys (Radialpoint Filter/Radialpoint Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp rp_skt32.sys (Radialpoint Filter/Radialpoint Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp rp_skt32.sys (Radialpoint Filter/Radialpoint Inc.)

---- Modules - GMER 1.0.15 ----

Module (noname) (*** hidden *** ) 00C00000-017AB000 (12234752 bytes)

---- EOF - GMER 1.0.15 ----

#8 mpascal

mpascal

    Math Nerd


  • Members
  • 1,653 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Canada
  • Local time:05:55 AM

Posted 18 May 2010 - 12:02 PM

Hi there,

We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Please include the C:\ComboFix.txt in your next reply for further review.

Posted Image

Stay with your topic! Topics that go 4 days without a reply will be closed. PM me to reopen.

Please don't PM asking for support. Post on the forums instead.

My help is free, but if you wish to donate and help continue my fight against malware, click here: Posted Image


#9 cdromsysinfect

cdromsysinfect
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Local time:03:55 AM

Posted 18 May 2010 - 09:47 PM

here we go, I still had all startup items and services disabled in msconfig.

ComboFix 10-05-17.01 - Owner 05/18/2010 19:32:22.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.447.149 [GMT -7:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: TELUS security services Anti-Virus *On-access scanning disabled* (Updated) {5B5A3BD7-8573-4672-AEA8-C9BB713B6755}
FW: TELUS security services Firewall *disabled* {80593BF4-D969-4EC5-ADAE-A22F2DFC7A22}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator\Local Settings\Application Data\{B88A0904-8385-4095-BB15-F3784491B035}
c:\documents and settings\Administrator\Local Settings\Application Data\{B88A0904-8385-4095-BB15-F3784491B035}\chrome\content\_cfg.js
c:\documents and settings\Administrator\Local Settings\Application Data\{B88A0904-8385-4095-BB15-F3784491B035}\chrome\content\overlay.xul
c:\documents and settings\Administrator\Local Settings\Application Data\{B88A0904-8385-4095-BB15-F3784491B035}\install.rdf
c:\documents and settings\Owner\Local Settings\Application Data\{6454152D-AF36-4C5F-A6C4-C7DF61D063AB}
c:\documents and settings\Owner\Local Settings\Application Data\{6454152D-AF36-4C5F-A6C4-C7DF61D063AB}\chrome.manifest
c:\documents and settings\Owner\Local Settings\Application Data\{6454152D-AF36-4C5F-A6C4-C7DF61D063AB}\chrome\content\_cfg.js
c:\documents and settings\Owner\Local Settings\Application Data\{6454152D-AF36-4C5F-A6C4-C7DF61D063AB}\chrome\content\overlay.xul
c:\documents and settings\Owner\Local Settings\Application Data\{6454152D-AF36-4C5F-A6C4-C7DF61D063AB}\install.rdf
c:\documents and settings\Owner\Local Settings\Temporary Internet Files\1qCIgd52.jpg
c:\documents and settings\Owner\Local Settings\Temporary Internet Files\1UBdeKnm7.jpg
c:\documents and settings\Owner\Local Settings\Temporary Internet Files\AJ87whd0T.jpg
c:\documents and settings\Owner\Local Settings\Temporary Internet Files\j0ceJ6l55.jpg
c:\windows\SET1A5.tmp
c:\windows\system32\winlogon.bak

c:\windows\system32\drivers\cdrom.sys was missing
Restored copy from - c:\windows\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\cdrom.sys

.
((((((((((((((((((((((((( Files Created from 2010-04-19 to 2010-05-19 )))))))))))))))))))))))))))))))
.

2010-05-19 02:36 . 2008-04-13 18:40 62976 -c--a-w- c:\windows\system32\dllcache\cdrom.sys
2010-05-19 02:36 . 2008-04-13 18:40 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2010-05-16 01:31 . 2010-05-16 01:31 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2010-05-16 01:31 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-16 01:31 . 2010-05-16 01:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-05-16 01:31 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-16 01:31 . 2010-05-16 01:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-12 05:20 . 2010-05-12 05:28 -------- d-----w- c:\documents and settings\Owner\Application Data\Registry Mechanic
2010-05-12 04:51 . 2010-05-12 04:51 -------- d-----w- c:\program files\Common Files\PC Tools
2010-05-12 03:54 . 2004-06-10 21:00 6656 ----a-w- c:\windows\system32\CNMVS58.DLL
2010-05-12 03:54 . 2004-06-10 21:00 48640 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP58.DLL
2010-05-12 03:54 . 2004-06-10 21:00 16384 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD58.DLL
2010-05-12 03:54 . 2004-06-10 21:00 105984 ----a-w- c:\windows\system32\CNMLM58.DLL
2010-05-12 03:54 . 2004-06-10 02:33 86016 ----a-w- c:\windows\system32\CNMCP58.exe
2010-05-12 03:54 . 2010-05-12 03:54 -------- d-----w- C:\BJPrinter
2010-05-12 03:26 . 2004-08-04 06:01 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2010-05-12 03:26 . 2004-08-04 06:01 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-05-09 17:11 . 2009-08-07 02:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-05-09 04:00 . 2010-05-09 04:00 -------- d-----w- c:\program files\InterVideo

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-16 16:11 . 2008-12-30 19:56 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-05-13 04:32 . 2010-03-20 05:17 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2010-05-10 05:02 . 2008-06-04 23:44 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-05-09 16:29 . 2010-03-29 05:18 -------- d-----w- c:\documents and settings\All Users\Application Data\avG
2010-03-29 04:25 . 2008-06-04 22:55 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-03-28 23:56 . 2010-03-28 23:56 4146 ----a-w- c:\windows\SEC13C5.tmp
2010-03-28 18:18 . 2010-03-27 18:50 -------- d-----w- c:\documents and settings\Owner\Application Data\TELUS
2010-03-28 18:15 . 2010-03-28 18:15 53192 ----a-w- c:\windows\system32\drivers\rp_skt32.sys
2010-03-28 18:15 . 2010-03-28 18:15 48384 ----a-w- c:\windows\system32\drivers\rp_pkt32.sys
2010-03-28 18:15 . 2010-03-28 18:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Raxco
2010-03-28 18:15 . 2010-03-28 18:15 -------- d-----w- c:\program files\Raxco
2010-03-28 18:14 . 2010-03-28 18:12 -------- d-----w- c:\program files\TELUS
2010-03-28 18:13 . 2010-03-27 18:50 -------- d-----w- c:\documents and settings\All Users\Application Data\TELUS
2010-03-28 17:09 . 2010-03-27 18:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Radialpoint
2010-03-28 16:49 . 2010-03-28 06:56 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-03-28 07:02 . 2010-03-28 07:01 -------- d-----w- c:\program files\Common Files\Adobe
2010-03-28 06:59 . 2010-03-28 06:59 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-03-28 06:57 . 2010-03-28 06:57 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-03-28 04:23 . 2010-03-28 03:24 -------- d-----w- c:\program files\Windows Live Safety Center
2010-03-28 02:23 . 2008-06-04 23:44 -------- d-----w- c:\program files\Common Files\InstallShield
2010-03-27 18:52 . 2010-03-27 18:52 -------- d-----w- c:\program files\MSXML 6.0
2010-03-27 04:27 . 2010-03-21 22:43 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2010-03-25 04:55 . 2010-03-20 21:19 0 ----a-w- c:\windows\Xjevocetuwef.bin
2010-03-24 05:51 . 2010-03-24 05:51 12784 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-03-22 01:54 . 2010-03-22 01:54 -------- d-----w- c:\documents and settings\Administrator\Application Data\PC Tools
2010-03-22 00:24 . 2010-03-20 21:19 120 ----a-w- c:\windows\Lhibebag.dat
2010-03-20 21:15 . 2008-06-04 23:58 12784 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-20 21:15 . 2010-03-20 21:15 16 ----a-w- c:\documents and settings\NetworkService\Application Data\jasltw.dat
2010-03-20 05:18 . 2010-03-20 05:16 -------- d-----w- c:\documents and settings\Owner\Application Data\Logitech
2010-03-20 05:18 . 2010-03-20 05:18 -------- d-----w- c:\documents and settings\Owner\Application Data\Leadertech
2010-03-20 05:18 . 2010-03-20 05:18 53248 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2010-03-20 05:18 . 2010-03-20 05:16 -------- d-----w- c:\program files\Common Files\LogiShrd
2010-03-20 05:18 . 2010-03-20 05:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Logishrd
2010-03-20 05:17 . 2010-03-20 05:17 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01009_Coinstaller_Critical.Wdf
2010-03-20 05:17 . 2010-03-20 05:17 -------- d-----w- c:\program files\Logitech
2010-03-20 05:16 . 2010-03-20 05:16 -------- d-----w- c:\documents and settings\Owner\Application Data\Logishrd
.

------- Sigcheck -------

[-] 2008-06-04 . 6225F14B8CE08CCBA8B25AD27843C674 . 502272 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\winlogon.exe
[-] 2008-06-04 . 6225F14B8CE08CCBA8B25AD27843C674 . 502272 . . [5.1.2600.2180] . . c:\windows\system32\winlogon.exe
[7] 2008-04-14 . ED0EF0A136DEC83DF69F04118870003E . 507904 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\winlogon.exe
[7] 2008-04-14 . ED0EF0A136DEC83DF69F04118870003E . 507904 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2010-01-29 21:17 64592 ----a-w- c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Radialpoint Security Services]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\syncman

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 09:57 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
2004-02-20 22:00 88363 ----a-w- c:\windows\agrsmmsg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2004-04-22 04:10 335872 ----a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EvtMgr6]
2010-01-27 11:30 1312848 ----a-w- c:\program files\Logitech\SetPointP\SetPoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
2003-09-26 22:43 184320 ------w- c:\program files\ltmoh\ltmoh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tsa.exe]
2009-12-15 02:34 4277488 ----a-w- c:\program files\TELUS\TELUS security advisor\Tsa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ServicepointService"=2 (0x2)
"RP_FWS"=2 (0x2)
"RadialpointIDSAgent"=2 (0x2)
"Radialpoint Security Services"=2 (0x2)
"PDEngine"=3 (0x3)
"PDAgent"=3 (0x3)
"PCToolsSSDMonitorSvc"=2 (0x2)
"LBTServ"=3 (0x3)
"Ati HotKey Poller"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Infogrames Interactive\\Scrabble Complete\\ScrabbleComplete.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R0 RadialpointIDSEH;RadialpointIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [3/28/2010 11:16 AM 25608]
S3 RadialpointIDSDriver;RadialpointIDSDriver;c:\program files\TELUS\TELUS security services\AVG\Identity Protection\agent\drivers\AVGIDSDriver.sys [3/28/2010 11:16 AM 122376]
S3 RadialpointIDSFilter;RadialpointIDSFilter;c:\program files\TELUS\TELUS security services\AVG\Identity Protection\agent\drivers\AVGIDSfilter.sys [3/28/2010 11:16 AM 30216]
S3 RadialpointIDSShim;RadialpointIDSShim;c:\program files\TELUS\TELUS security services\AVG\Identity Protection\agent\drivers\AVGIDSShim.sys [3/28/2010 11:16 AM 25736]
S4 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [5/11/2010 9:51 PM 632792]
S4 Radialpoint Security Services;TELUS security services;c:\program files\TELUS\TELUS security services\RpsSecurityAwareR.exe [12/14/2009 11:26 PM 165408]
S4 RadialpointIDSAgent;RadialpointIDSAgent;c:\program files\TELUS\TELUS security services\AVG\Identity Protection\agent\bin\AVGIDSAgent.exe [3/28/2010 11:16 AM 5832712]
S4 ServicepointService;ServicepointService;c:\program files\TELUS\TELUS security advisor\ServicepointService.exe [3/28/2010 11:12 AM 668912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan sysagent
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} - hxxp://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab
.
- - - - ORPHANS REMOVED - - - -

BHO-{b524c853-68cd-7838-3c6c-5a20f8bb5a35} - (no file)
Notify-dimsntfy - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-18 19:38
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(832)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
.
Completion time: 2010-05-18 19:41:14 - machine was rebooted
ComboFix-quarantined-files.txt 2010-05-19 02:41

Pre-Run: 50,695,622,656 bytes free
Post-Run: 50,865,520,640 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - B16DB4FCE1D43E991057355E6311B010


#10 mpascal

mpascal

    Math Nerd


  • Members
  • 1,653 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Canada
  • Local time:05:55 AM

Posted 19 May 2010 - 12:37 AM

Hi there,

Close any open browsers, and close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Open notepad and copy/paste the text in the codebox below into it:

CODE
File::
2010-03-25 04:55 . 2010-03-20 21:19 0 ----a-w- c:\windows\Xjevocetuwef.bin
2010-03-22 00:24 . 2010-03-20 21:19 120 ----a-w- c:\windows\Lhibebag.dat
2010-03-20 21:15 . 2010-03-20 21:15 16 ----a-w- c:\documents and settings\NetworkService\Application Data\jasltw.dat
  • Save this as CFScript.txt, in the same location as ComboFix.exe


Refering to the picture above, drag CFScript into ComboFix.exe.

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Posted Image

Stay with your topic! Topics that go 4 days without a reply will be closed. PM me to reopen.

Please don't PM asking for support. Post on the forums instead.

My help is free, but if you wish to donate and help continue my fight against malware, click here: Posted Image


#11 cdromsysinfect

cdromsysinfect
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Local time:03:55 AM

Posted 19 May 2010 - 09:11 AM

Good morning, thanks for your promptness.
Combofix asked if I wanted to update, I chose no.

Here is the log.


ComboFix 10-05-17.01 - Owner 05/19/2010 7:03.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.447.256 [GMT -7:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: TELUS security services Anti-Virus *On-access scanning disabled* (Updated) {5B5A3BD7-8573-4672-AEA8-C9BB713B6755}
FW: TELUS security services Firewall *disabled* {80593BF4-D969-4EC5-ADAE-A22F2DFC7A22}
.

((((((((((((((((((((((((( Files Created from 2010-04-19 to 2010-05-19 )))))))))))))))))))))))))))))))
.

2010-05-19 02:36 . 2008-04-13 18:40 62976 -c--a-w- c:\windows\system32\dllcache\cdrom.sys
2010-05-19 02:36 . 2008-04-13 18:40 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2010-05-16 01:31 . 2010-05-16 01:31 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2010-05-16 01:31 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-16 01:31 . 2010-05-16 01:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-05-16 01:31 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-16 01:31 . 2010-05-16 01:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-12 05:20 . 2010-05-12 05:28 -------- d-----w- c:\documents and settings\Owner\Application Data\Registry Mechanic
2010-05-12 04:51 . 2010-05-12 04:51 -------- d-----w- c:\program files\Common Files\PC Tools
2010-05-12 03:54 . 2004-06-10 21:00 6656 ----a-w- c:\windows\system32\CNMVS58.DLL
2010-05-12 03:54 . 2004-06-10 21:00 48640 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP58.DLL
2010-05-12 03:54 . 2004-06-10 21:00 16384 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD58.DLL
2010-05-12 03:54 . 2004-06-10 21:00 105984 ----a-w- c:\windows\system32\CNMLM58.DLL
2010-05-12 03:54 . 2004-06-10 02:33 86016 ----a-w- c:\windows\system32\CNMCP58.exe
2010-05-12 03:54 . 2010-05-12 03:54 -------- d-----w- C:\BJPrinter
2010-05-12 03:26 . 2004-08-04 06:01 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2010-05-12 03:26 . 2004-08-04 06:01 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-05-09 17:11 . 2009-08-07 02:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-05-09 04:00 . 2010-05-09 04:00 -------- d-----w- c:\program files\InterVideo

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-16 16:11 . 2008-12-30 19:56 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-05-13 04:32 . 2010-03-20 05:17 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2010-05-10 05:02 . 2008-06-04 23:44 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-05-09 16:29 . 2010-03-29 05:18 -------- d-----w- c:\documents and settings\All Users\Application Data\avG
2010-03-29 04:25 . 2008-06-04 22:55 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-03-28 23:56 . 2010-03-28 23:56 4146 ----a-w- c:\windows\SEC13C5.tmp
2010-03-28 18:18 . 2010-03-27 18:50 -------- d-----w- c:\documents and settings\Owner\Application Data\TELUS
2010-03-28 18:15 . 2010-03-28 18:15 53192 ----a-w- c:\windows\system32\drivers\rp_skt32.sys
2010-03-28 18:15 . 2010-03-28 18:15 48384 ----a-w- c:\windows\system32\drivers\rp_pkt32.sys
2010-03-28 18:15 . 2010-03-28 18:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Raxco
2010-03-28 18:15 . 2010-03-28 18:15 -------- d-----w- c:\program files\Raxco
2010-03-28 18:14 . 2010-03-28 18:12 -------- d-----w- c:\program files\TELUS
2010-03-28 18:13 . 2010-03-27 18:50 -------- d-----w- c:\documents and settings\All Users\Application Data\TELUS
2010-03-28 17:09 . 2010-03-27 18:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Radialpoint
2010-03-28 16:49 . 2010-03-28 06:56 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-03-28 07:02 . 2010-03-28 07:01 -------- d-----w- c:\program files\Common Files\Adobe
2010-03-28 06:59 . 2010-03-28 06:59 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-03-28 06:57 . 2010-03-28 06:57 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-03-28 04:23 . 2010-03-28 03:24 -------- d-----w- c:\program files\Windows Live Safety Center
2010-03-28 02:23 . 2008-06-04 23:44 -------- d-----w- c:\program files\Common Files\InstallShield
2010-03-27 18:52 . 2010-03-27 18:52 -------- d-----w- c:\program files\MSXML 6.0
2010-03-27 04:27 . 2010-03-21 22:43 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2010-03-25 04:55 . 2010-03-20 21:19 0 ----a-w- c:\windows\Xjevocetuwef.bin
2010-03-24 05:51 . 2010-03-24 05:51 12784 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-03-22 01:54 . 2010-03-22 01:54 -------- d-----w- c:\documents and settings\Administrator\Application Data\PC Tools
2010-03-22 00:24 . 2010-03-20 21:19 120 ----a-w- c:\windows\Lhibebag.dat
2010-03-20 21:15 . 2008-06-04 23:58 12784 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-20 21:15 . 2010-03-20 21:15 16 ----a-w- c:\documents and settings\NetworkService\Application Data\jasltw.dat
2010-03-20 05:18 . 2010-03-20 05:18 53248 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
.

------- Sigcheck -------

[-] 2008-06-04 . 6225F14B8CE08CCBA8B25AD27843C674 . 502272 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\winlogon.exe
[-] 2008-06-04 . 6225F14B8CE08CCBA8B25AD27843C674 . 502272 . . [5.1.2600.2180] . . c:\windows\system32\winlogon.exe
[7] 2008-04-14 . ED0EF0A136DEC83DF69F04118870003E . 507904 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\2d8407673ea9865ef7cd775540e3a36b\winlogon.exe
[7] 2008-04-14 . ED0EF0A136DEC83DF69F04118870003E . 507904 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2010-01-29 21:17 64592 ----a-w- c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Radialpoint Security Services]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 09:57 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
2004-02-20 22:00 88363 ----a-w- c:\windows\agrsmmsg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2004-04-22 04:10 335872 ----a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EvtMgr6]
2010-01-27 11:30 1312848 ----a-w- c:\program files\Logitech\SetPointP\SetPoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
2003-09-26 22:43 184320 ------w- c:\program files\ltmoh\ltmoh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tsa.exe]
2009-12-15 02:34 4277488 ----a-w- c:\program files\TELUS\TELUS security advisor\Tsa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ServicepointService"=2 (0x2)
"RP_FWS"=2 (0x2)
"RadialpointIDSAgent"=2 (0x2)
"Radialpoint Security Services"=2 (0x2)
"PDEngine"=3 (0x3)
"PDAgent"=3 (0x3)
"PCToolsSSDMonitorSvc"=2 (0x2)
"LBTServ"=3 (0x3)
"Ati HotKey Poller"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Infogrames Interactive\\Scrabble Complete\\ScrabbleComplete.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R0 RadialpointIDSEH;RadialpointIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [3/28/2010 11:16 AM 25608]
S3 RadialpointIDSDriver;RadialpointIDSDriver;c:\program files\TELUS\TELUS security services\AVG\Identity Protection\agent\drivers\AVGIDSDriver.sys [3/28/2010 11:16 AM 122376]
S3 RadialpointIDSFilter;RadialpointIDSFilter;c:\program files\TELUS\TELUS security services\AVG\Identity Protection\agent\drivers\AVGIDSfilter.sys [3/28/2010 11:16 AM 30216]
S3 RadialpointIDSShim;RadialpointIDSShim;c:\program files\TELUS\TELUS security services\AVG\Identity Protection\agent\drivers\AVGIDSShim.sys [3/28/2010 11:16 AM 25736]
S4 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [5/11/2010 9:51 PM 632792]
S4 Radialpoint Security Services;TELUS security services;c:\program files\TELUS\TELUS security services\RpsSecurityAwareR.exe [12/14/2009 11:26 PM 165408]
S4 RadialpointIDSAgent;RadialpointIDSAgent;c:\program files\TELUS\TELUS security services\AVG\Identity Protection\agent\bin\AVGIDSAgent.exe [3/28/2010 11:16 AM 5832712]
S4 ServicepointService;ServicepointService;c:\program files\TELUS\TELUS security advisor\ServicepointService.exe [3/28/2010 11:12 AM 668912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan sysagent
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} - hxxp://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab
.

**************************************************************************
scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(828)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll

- - - - - - - > 'explorer.exe'(1296)
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
Completion time: 2010-05-19 07:10:22
ComboFix-quarantined-files.txt 2010-05-19 14:10
ComboFix2.txt 2010-05-19 02:41

Pre-Run: 50,858,565,632 bytes free
Post-Run: 50,839,158,784 bytes free

- - End Of File - - 411FD00FCD1A6FC31747C204C242DAC3


#12 mpascal

mpascal

    Math Nerd


  • Members
  • 1,653 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Canada
  • Local time:05:55 AM

Posted 20 May 2010 - 03:46 PM

Hi there,

Close any open browsers, and close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Open notepad and copy/paste the text in the codebox below into it:

CODE
FCopy::
c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\winlogon.exe | c:\windows\system32\winlogon.exe
c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\winlogon.exe | c:\windows\$NtServicePackUninstall$\winlogon.exe
  • Save this as CFScript.txt, in the same location as ComboFix.exe


Refering to the picture above, drag CFScript into ComboFix.exe.

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Posted Image

Stay with your topic! Topics that go 4 days without a reply will be closed. PM me to reopen.

Please don't PM asking for support. Post on the forums instead.

My help is free, but if you wish to donate and help continue my fight against malware, click here: Posted Image


#13 cdromsysinfect

cdromsysinfect
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Local time:03:55 AM

Posted 20 May 2010 - 03:50 PM

Will do tonite and post, tomorrow I am away on business until Tuesday (25th) night so, you will not hear from me after tonight until the 25th.

#14 cdromsysinfect

cdromsysinfect
  • Topic Starter

  • Members
  • 21 posts
  • OFFLINE
  •  
  • Local time:03:55 AM

Posted 20 May 2010 - 08:46 PM

ComboFix 10-05-17.01 - Owner 05/20/2010 18:21:42.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.447.255 [GMT -7:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: TELUS security services Anti-Virus *On-access scanning disabled* (Updated) {5B5A3BD7-8573-4672-AEA8-C9BB713B6755}
FW: TELUS security services Firewall *disabled* {80593BF4-D969-4EC5-ADAE-A22F2DFC7A22}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
--------------- FCopy ---------------

c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\winlogon.exe --> c:\windows\system32\winlogon.exe
c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\winlogon.exe --> c:\windows\$NtServicePackUninstall$\winlogon.exe
.
((((((((((((((((((((((((( Files Created from 2010-04-21 to 2010-05-21 )))))))))))))))))))))))))))))))
.

2010-05-19 02:36 . 2008-04-13 18:40 62976 -c--a-w- c:\windows\system32\dllcache\cdrom.sys
2010-05-19 02:36 . 2008-04-13 18:40 62976 ----a-w- c:\windows\system32\drivers\cdrom.sys
2010-05-16 01:31 . 2010-05-16 01:31 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2010-05-16 01:31 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-16 01:31 . 2010-05-16 01:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-05-16 01:31 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-16 01:31 . 2010-05-16 01:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-12 05:20 . 2010-05-12 05:28 -------- d-----w- c:\documents and settings\Owner\Application Data\Registry Mechanic
2010-05-12 04:51 . 2010-05-12 04:51 -------- d-----w- c:\program files\Common Files\PC Tools
2010-05-12 03:54 . 2004-06-10 21:00 6656 ----a-w- c:\windows\system32\CNMVS58.DLL
2010-05-12 03:54 . 2004-06-10 21:00 48640 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP58.DLL
2010-05-12 03:54 . 2004-06-10 21:00 16384 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD58.DLL
2010-05-12 03:54 . 2004-06-10 21:00 105984 ----a-w- c:\windows\system32\CNMLM58.DLL
2010-05-12 03:54 . 2004-06-10 02:33 86016 ----a-w- c:\windows\system32\CNMCP58.exe
2010-05-12 03:54 . 2010-05-12 03:54 -------- d-----w- C:\BJPrinter
2010-05-12 03:26 . 2004-08-04 06:01 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2010-05-12 03:26 . 2004-08-04 06:01 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2010-05-09 17:11 . 2009-08-07 02:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-05-09 04:00 . 2010-05-09 04:00 -------- d-----w- c:\program files\InterVideo

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-16 16:11 . 2008-12-30 19:56 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-05-13 04:32 . 2010-03-20 05:17 16400 ----a-w- c:\windows\system32\drivers\LNonPnP.sys
2010-05-10 05:02 . 2008-06-04 23:44 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-05-09 16:29 . 2010-03-29 05:18 -------- d-----w- c:\documents and settings\All Users\Application Data\avG
2010-03-29 04:25 . 2008-06-04 22:55 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-03-28 23:56 . 2010-03-28 23:56 4146 ----a-w- c:\windows\SEC13C5.tmp
2010-03-28 18:18 . 2010-03-27 18:50 -------- d-----w- c:\documents and settings\Owner\Application Data\TELUS
2010-03-28 18:15 . 2010-03-28 18:15 53192 ----a-w- c:\windows\system32\drivers\rp_skt32.sys
2010-03-28 18:15 . 2010-03-28 18:15 48384 ----a-w- c:\windows\system32\drivers\rp_pkt32.sys
2010-03-28 18:15 . 2010-03-28 18:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Raxco
2010-03-28 18:15 . 2010-03-28 18:15 -------- d-----w- c:\program files\Raxco
2010-03-28 18:14 . 2010-03-28 18:12 -------- d-----w- c:\program files\TELUS
2010-03-28 18:13 . 2010-03-27 18:50 -------- d-----w- c:\documents and settings\All Users\Application Data\TELUS
2010-03-28 17:09 . 2010-03-27 18:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Radialpoint
2010-03-28 16:49 . 2010-03-28 06:56 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-03-28 07:02 . 2010-03-28 07:01 -------- d-----w- c:\program files\Common Files\Adobe
2010-03-28 06:59 . 2010-03-28 06:59 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-03-28 06:57 . 2010-03-28 06:57 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-03-28 04:23 . 2010-03-28 03:24 -------- d-----w- c:\program files\Windows Live Safety Center
2010-03-28 02:23 . 2008-06-04 23:44 -------- d-----w- c:\program files\Common Files\InstallShield
2010-03-27 18:52 . 2010-03-27 18:52 -------- d-----w- c:\program files\MSXML 6.0
2010-03-27 04:27 . 2010-03-21 22:43 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2010-03-25 04:55 . 2010-03-20 21:19 0 ----a-w- c:\windows\Xjevocetuwef.bin
2010-03-24 05:51 . 2010-03-24 05:51 12784 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-03-22 01:54 . 2010-03-22 01:54 -------- d-----w- c:\documents and settings\Administrator\Application Data\PC Tools
2010-03-22 00:24 . 2010-03-20 21:19 120 ----a-w- c:\windows\Lhibebag.dat
2010-03-20 21:15 . 2008-06-04 23:58 12784 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-20 21:15 . 2010-03-20 21:15 16 ----a-w- c:\documents and settings\NetworkService\Application Data\jasltw.dat
2010-03-20 05:18 . 2010-03-20 05:18 53248 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
.

((((((((((((((((((((((((((((( SnapShot@2010-05-19_02.38.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-28 23:30 . 2008-04-14 00:12 507904 c:\windows\system32\dllcache\winlogon.exe
+ 2010-03-28 23:30 . 2008-04-14 00:12 507904 c:\windows\$NtServicePackUninstall$\winlogon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2010-01-29 21:17 64592 ----a-w- c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Radialpoint Security Services]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-03-24 18:17 952768 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 09:57 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
2004-02-20 22:00 88363 ----a-w- c:\windows\agrsmmsg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2004-04-22 04:10 335872 ----a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EvtMgr6]
2010-01-27 11:30 1312848 ----a-w- c:\program files\Logitech\SetPointP\SetPoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
2003-09-26 22:43 184320 ------w- c:\program files\ltmoh\ltmoh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tsa.exe]
2009-12-15 02:34 4277488 ----a-w- c:\program files\TELUS\TELUS security advisor\Tsa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ServicepointService"=2 (0x2)
"RP_FWS"=2 (0x2)
"RadialpointIDSAgent"=2 (0x2)
"Radialpoint Security Services"=2 (0x2)
"PDEngine"=3 (0x3)
"PDAgent"=3 (0x3)
"PCToolsSSDMonitorSvc"=2 (0x2)
"LBTServ"=3 (0x3)
"Ati HotKey Poller"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Infogrames Interactive\\Scrabble Complete\\ScrabbleComplete.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R0 RadialpointIDSEH;RadialpointIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [3/28/2010 11:16 AM 25608]
S3 RadialpointIDSDriver;RadialpointIDSDriver;c:\program files\TELUS\TELUS security services\AVG\Identity Protection\agent\drivers\AVGIDSDriver.sys [3/28/2010 11:16 AM 122376]
S3 RadialpointIDSFilter;RadialpointIDSFilter;c:\program files\TELUS\TELUS security services\AVG\Identity Protection\agent\drivers\AVGIDSfilter.sys [3/28/2010 11:16 AM 30216]
S3 RadialpointIDSShim;RadialpointIDSShim;c:\program files\TELUS\TELUS security services\AVG\Identity Protection\agent\drivers\AVGIDSShim.sys [3/28/2010 11:16 AM 25736]
S4 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [5/11/2010 9:51 PM 632792]
S4 Radialpoint Security Services;TELUS security services;c:\program files\TELUS\TELUS security services\RpsSecurityAwareR.exe [12/14/2009 11:26 PM 165408]
S4 RadialpointIDSAgent;RadialpointIDSAgent;c:\program files\TELUS\TELUS security services\AVG\Identity Protection\agent\bin\AVGIDSAgent.exe [3/28/2010 11:16 AM 5832712]
S4 ServicepointService;ServicepointService;c:\program files\TELUS\TELUS security advisor\ServicepointService.exe [3/28/2010 11:12 AM 668912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan sysagent
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
DPF: {0067DBFC-A752-458C-AE6E-B9C7E63D4824} - hxxp://www.logitech.com/devicedetector/plugins/LogitechDeviceDetection32.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-20 18:26
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(828)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll

- - - - - - - > 'explorer.exe'(364)
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
Completion time: 2010-05-20 18:28:23
ComboFix-quarantined-files.txt 2010-05-21 01:28
ComboFix2.txt 2010-05-19 14:10
ComboFix3.txt 2010-05-19 02:41

Pre-Run: 50,830,082,048 bytes free
Post-Run: 50,811,240,448 bytes free

- - End Of File - - BFA4A3D07AF5EDE50F38B097EC0D4583


#15 mpascal

mpascal

    Math Nerd


  • Members
  • 1,653 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Canada
  • Local time:05:55 AM

Posted 21 May 2010 - 11:20 PM

Hi there,

Close any open browsers, and close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Open notepad and copy/paste the text in the codebox below into it:

CODE
File::
c:\documents and settings\NetworkService\Application Data\jasltw.dat
c:\windows\Lhibebag.dat
c:\windows\Xjevocetuwef.bin

Folder::

Registry::

Driver::
  • Save this as CFScript.txt, in the same location as ComboFix.exe


Refering to the picture above, drag CFScript into ComboFix.exe.

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Posted Image

Stay with your topic! Topics that go 4 days without a reply will be closed. PM me to reopen.

Please don't PM asking for support. Post on the forums instead.

My help is free, but if you wish to donate and help continue my fight against malware, click here: Posted Image





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users