http://www.bleepingcomputer.com/forums/t/324213/need-help-please/
DDS (Ver_10-03-17.01) - NTFSx86
Run by Stephen at 10:22:59.74 on Wed 06/16/2010
Internet Explorer: 8.0.6001.18928 BrowserJavaVersion: 1.6.0_17
============== Running Processes ===============
C:Windowssystem32wininit.exe
C:Windowssystem32lsm.exe
C:Program FilesMicrosoft Security EssentialsMsMpEng.exe
C:Windowssystem32Ati2evxx.exe
C:Windowssystem32SLsvc.exe
C:Windowssystem32Ati2evxx.exe
C:WindowsSystem32spoolsv.exe
C:Windowssystem32Dwm.exe
C:WindowsExplorer.EXE
C:WindowsRtHDVCpl.exe
C:Program FilesPure NetworksNetwork Magicnmapp.exe
C:Program FilesMicrosoft Security Essentialsmsseces.exe
C:Windowsehomeehtray.exe
C:Program FilesPando NetworksMedia BoosterPMB.exe
C:Program FilesJavajre6binjqs.exe
C:Program FilesPure NetworksNetwork Magicnmsrvc.exe
C:Program FilesATI TechnologiesATI.ACECore-StaticMOM.exe
C:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSVC.EXE
C:Windowssystem32SearchIndexer.exe
C:Program FilesCommon FilesMicrosoft SharedWindows LiveWLIDSvcM.exe
C:Windowsehomeehmsas.exe
C:Program FilesWindows Media Playerwmpnscfg.exe
C:Program FilesWindows Media Playerwmpnetwk.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Program FilesATI TechnologiesATI.ACECore-StaticCCC.exe
C:Windowssystem32SearchProtocolHost.exe
C:Windowssystem32SearchFilterHost.exe
C:Program FilesMicrosoft Security EssentialsMpCmdRun.exe
C:UsersStephenDesktopdds.scr
C:Windowssystem32svchost.exe -k DcomLaunch
C:Windowssystem32svchost.exe -k rpcss
C:WindowsSystem32svchost.exe -k LocalServiceNetworkRestricted
C:WindowsSystem32svchost.exe -k LocalSystemNetworkRestricted
C:Windowssystem32svchost.exe -k GPSvcGroup
C:Windowssystem32svchost.exe -k LocalService
C:Windowssystem32svchost.exe -k NetworkService
C:Windowssystem32svchost.exe -k LocalServiceNoNetwork
C:Windowssystem32svchost.exe -k NetworkServiceNetworkRestricted
C:Windowssystem32svchost.exe -k imgsvc
C:WindowsSystem32svchost.exe -k WerSvcGroup
============== Pseudo HJT Report ===============
uInternet Settings,ProxyServer = http=127.0.0.1:49750
uInternet Settings,ProxyOverride =
BHO: ContributeBHO Class: {074c1dc5-9320-4a9a-947d-c042949c6216} - c:program filesadobe/Adobe Contribute CS4/contributeieplugin.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:program filescommon filesadobeacrobatactivexAcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:program filesavgavg8avgssie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:program filescommon filesmicrosoft sharedwindows liveWindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:program filescommon filesadobeacrobatactivexAcroIEFavClient.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:program filesgooglegoogletoolbarnotifier5.1.1309.3572swg.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:program filesjavajre6libdeployjqsiejqs_plugin.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:program filescommon filesadobeacrobatactivexAcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:program filescommon filesadobeacrobatactivexAcroIEFavClient.dll
TB: Contribute Toolbar: {517bdde4-e3a7-4570-b21e-2b52b6139fc7} - c:program filesadobe/Adobe Contribute CS4/contributeieplugin.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
uRun: [ctfmon.exe] c:windowssystem32ctfmon.exe
uRun: [Sidebar] c:program fileswindows sidebarsidebar.exe /autoRun
uRun: [ehTray.exe] c:windowsehomeehTray.exe
uRun: [Auto EPSON Stylus Photo R280 Series on CHANG-PC] c:windowssystem32spooldriversw32x863e_faticka.exe /fu "c:windowstempE_SD9.tmp" /EF "HKCU"
uRun: [Google Update] "c:usersstephenappdatalocalgoogleupdateGoogleUpdate.exe" /c
uRun: [Pando Media Booster] c:program filespando networksmedia boosterPMB.exe
uRun: [WMPNSCFG] c:program fileswindows media playerWMPNSCFG.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [Skytel] Skytel.exe
mRun: [Adobe Acrobat Speed Launcher] "c:program filesadobeacrobat 9.0acrobatAcrobat_sl.exe"
mRun: [
mRun: [StartCCC] "c:program filesati technologiesati.acecore-staticCLIStart.exe" MSRun
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [nmapp] "c:program filespure networksnetwork magicnmapp.exe" -autorun -nosplash
mRun: [Alcmtr] ALCMTR.EXE
mRun: [AdobeCS4ServiceManager] "c:program filescommon filesadobecs4servicemanagerCS4ServiceManager.exe" -launchedbylogin
mRun: [MSSE] "c:program filesmicrosoft security essentialsmsseces.exe" -hide -runkey
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Append Link Target to Existing PDF - c:program filescommon filesadobeacrobatactivexAcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:program filescommon filesadobeacrobatactivexAcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:program filescommon filesadobeacrobatactivexAcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:program filescommon filesadobeacrobatactivexAcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-06-16 10:32:24
Windows 6.0.6002 Service Pack 2
Running: szz7bbvt.exe; Driver: C:UsersStephenAppDataLocalTempkwndrpog.sys
---- System - GMER 1.0.15 ----
SSDT ??C:Program FilesSUPERAntiSpywareSASKUTIL.SYS ZwTerminateProcess [0x9073C620]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 621 81EBDD84 4 Bytes [20, C6, 73, 90] {AND DH, AL; JAE 0xffffffffffffff94}
.text C:Windowssystem32DRIVERSatikmdag.sys section is writeable [0x8F609000, 0x23097E, 0xE8000020]
.text C:Windowssystem32DRIVERSatksgt.sys section is writeable [0xA540E300, 0x3AE88, 0xE8000020]
.text C:Windowssystem32DRIVERSlirsgt.sys section is writeable [0xA5451300, 0x1B7E, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:WindowsExplorer.EXE[2140] ntdll.dll!NtProtectVirtualMemory 77404D34 5 Bytes JMP 007D000A
.text C:WindowsExplorer.EXE[2140] ntdll.dll!NtWriteVirtualMemory 77405674 5 Bytes JMP 007E000A
.text C:WindowsExplorer.EXE[2140] ntdll.dll!KiUserExceptionDispatcher 77405DC8 5 Bytes JMP 007C000A
.text C:Program FilesMozilla Firefoxfirefox.exe[3916] ntdll.dll!NtProtectVirtualMemory 77404D34 5 Bytes JMP 002C000A
.text C:Program FilesMozilla Firefoxfirefox.exe[3916] ntdll.dll!NtWriteVirtualMemory 77405674 5 Bytes JMP 002D000A
.text C:Program FilesMozilla Firefoxfirefox.exe[3916] ntdll.dll!KiUserExceptionDispatcher 77405DC8 5 Bytes JMP 002B000A
---- Registry - GMER 1.0.15 ----
Reg HKLMSYSTEMCurrentControlSetServicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLMSYSTEMCurrentControlSetServicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:Program FilesDAEMON Tools Lite
Reg HKLMSYSTEMCurrentControlSetServicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLMSYSTEMCurrentControlSetServicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xD3 0x09 0x41 0x46 ...
Reg HKLMSYSTEMCurrentControlSetServicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CEC00000001
Reg HKLMSYSTEMCurrentControlSetServicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CEC00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLMSYSTEMCurrentControlSetServicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CEC00000001@hdf12 0x62 0xCF 0x0C 0xC4 ...
Reg HKLMSYSTEMCurrentControlSetServicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CEC00000001gdq0
Reg HKLMSYSTEMCurrentControlSetServicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CEC00000001gdq0@hdf12 0xE4 0x17 0xFB 0x10 ...
Reg HKLMSYSTEMControlSet002ServicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLMSYSTEMControlSet002ServicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:Program FilesDAEMON Tools Lite
Reg HKLMSYSTEMControlSet002ServicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLMSYSTEMControlSet002ServicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xD3 0x09 0x41 0x46 ...
Reg HKLMSYSTEMControlSet002ServicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CEC00000001 (not active ControlSet)
Reg HKLMSYSTEMControlSet002ServicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CEC00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLMSYSTEMControlSet002ServicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CEC00000001@hdf12 0x62 0xCF 0x0C 0xC4 ...
Reg HKLMSYSTEMControlSet002ServicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CEC00000001gdq0 (not active ControlSet)
Reg HKLMSYSTEMControlSet002ServicessptdCfg14919EA49A8F3B4AA3CF1058D9A64CEC00000001gdq0@hdf12 0xE4 0x17 0xFB 0x10 ...

Edited by ssp0929, 16 June 2010 - 03:47 PM.