Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Who can help remover this evil thing....


  • This topic is locked This topic is locked
3 replies to this topic

#1 leechie

leechie

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Franeker, The Netherlands
  • Local time:05:50 PM

Posted 04 October 2010 - 01:48 PM

Who can help remover this evil thing....

Attached File  rsvepifhsys.png   26.51KB   9 downloads

DDS:


DDS (Ver_10-03-17.01) - NTFSx86
Run by Monique at 20:06:18,08 on ma 04-10-2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.31.1043.18.3327.2079 [GMT 2:00]


============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\amBX\System\amBX_Service.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\amBX\Device Drivers\Philips USB\USB Drivers\x86\Philips_amBX_USB_HAL_x86.exe
C:\Windows\system32\IoctlSvc.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\msi\OSD hot keys\WMI_Hook_Service.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\Explorer.exe
C:\Users\Monique\AppData\Local\Temp\TeamViewer\Version5\TeamViewer.exe
C:\Windows\system32\msiexec.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Users\Monique\AppData\Local\Temp\Rar$EX00.073\gmer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Monique\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TWDU0JHZ\dds[1].scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.nl/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No File
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No File
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xporteren naar Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\canon\easy-webprint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\canon\easy-webprint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\canon\easy-webprint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\canon\easy-webprint\Resource.dll/RC_Print.html
IE: {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/1346-72745-17534-1/4
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mif5ba~1\office12\ONBttnIE.dll
IE: {27FD17FB-CF63-486b-B2BE-8D8781CBEA01} - {27FD17FB-CF63-486b-B2BE-8D8781CBEA01}
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mif5ba~1\office12\REFIEBAR.DLL
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/m3/photouploadcontrol/VistaMSNPUpldnl-nl.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

============= SERVICES / DRIVERS ===============

R0 nvamacpi;NVIDIA Away Mode System;c:\windows\system32\drivers\nvamacpi.sys [2009-8-19 24608]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-3-25 151216]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 amBX Service;amBX Service;c:\program files\ambx\system\amBX_Service.exe [2010-3-3 599552]
R2 Philips amBX USB HAL;Philips amBX USB HAL;c:\program files\ambx\device drivers\philips usb\usb drivers\x86\Philips_amBX_USB_HAL_x86.exe [2010-3-3 540672]
R2 WMI_Hook_Service;WMI_Hook_Service;c:\program files\msi\osd hot keys\WMI_Hook_Service.exe [2009-9-4 101176]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-3-25 42368]
R3 NxpCap;CTX capture service;c:\windows\system32\drivers\NxpCap.sys [2009-8-19 1488096]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-8-19 167936]
R3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\drivers\rtl8192se.sys [2009-8-19 842752]
S1 agbaiqbq;agbaiqbq;c:\windows\system32\drivers\agbaiqbq.sys [2010-10-4 41680]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 MSIDriver_IO_2;MSIDriver_IO_2;c:\program files\msi\osd hot keys\MSI_MAINSYS.sys [2009-8-25 26936]
S3 WatAdminSvc;Windows Activation Technologies-service;c:\windows\system32\wat\WatAdminSvc.exe [2010-6-7 1343400]

=============== Created Last 30 ================

2010-10-04 18:00:59 0 d-----w- c:\program files\Trend Micro
2010-10-04 17:48:39 0 d-sh--w- C:\$RECYCLE.BIN
2010-10-04 17:34:44 41680 ----a-w- c:\windows\system32\drivers\agbaiqbq.sys
2010-10-04 17:06:26 98816 ----a-w- c:\windows\sed.exe
2010-10-04 17:06:26 77312 ----a-w- c:\windows\MBR.exe
2010-10-04 17:06:26 256512 ----a-w- c:\windows\PEV.exe
2010-10-04 17:06:26 161792 ----a-w- c:\windows\SWREG.exe
2010-10-04 16:57:06 41680 ----a-w- c:\windows\system32\drivers\biuxppig.sys
2010-10-04 16:51:55 41680 ----a-w- c:\windows\system32\drivers\vjdmayww.sys
2010-10-04 16:13:18 41680 ----a-w- c:\windows\system32\drivers\tunijiar.sys
2010-10-04 15:55:33 41680 ----a-w- c:\windows\system32\drivers\eismscaz.sys
2010-10-04 15:18:31 0 d-----w- c:\program files\Microsoft Security Essentials
2010-10-04 15:12:26 0 d-----w- c:\windows\pss
2010-10-04 14:40:02 0 d-----w- c:\program files\QS
2010-09-29 21:41:56 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2010-09-29 21:41:56 146304 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2010-09-29 12:59:25 842240 ----a-w- c:\windows\system32\drivers\rsvepifh.sys
2010-09-21 15:36:27 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdRapi2_01_00_00.Wdf
2010-09-21 15:35:42 0 d-----w- c:\windows\WindowsMobile
2010-09-16 09:03:21 316928 ----a-w- c:\windows\system32\spoolsv.exe

==================== Find3M ====================

2010-10-04 17:17:27 691490 ----a-w- c:\windows\system32\perfh013.dat
2010-10-04 17:17:27 684756 ----a-w- c:\windows\system32\perfh00C.dat
2010-10-04 17:17:27 679812 ----a-w- c:\windows\system32\perfh010.dat
2010-10-04 17:17:27 633338 ----a-w- c:\windows\system32\perfh007.dat
2010-10-04 17:17:27 130026 ----a-w- c:\windows\system32\perfc013.dat
2010-10-04 17:17:27 126872 ----a-w- c:\windows\system32\perfc00C.dat
2010-10-04 17:17:27 125730 ----a-w- c:\windows\system32\perfc007.dat
2010-10-04 17:17:27 123808 ----a-w- c:\windows\system32\perfc010.dat
2010-07-29 06:30:49 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30:34 82944 ----a-w- c:\windows\system32\iccvid.dll
2009-08-14 00:19:04 43068 ----a-w- c:\windows\inf\perflib\0413\perfd.dat
2009-08-14 00:19:04 43068 ----a-w- c:\windows\inf\perflib\0413\perfc.dat
2009-08-14 00:19:04 341322 ----a-w- c:\windows\inf\perflib\0413\perfi.dat
2009-08-14 00:19:04 341322 ----a-w- c:\windows\inf\perflib\0413\perfh.dat
2009-08-14 00:14:32 37534 ----a-w- c:\windows\inf\perflib\0410\perfd.dat
2009-08-14 00:14:32 37534 ----a-w- c:\windows\inf\perflib\0410\perfc.dat
2009-08-14 00:14:32 335478 ----a-w- c:\windows\inf\perflib\0410\perfi.dat
2009-08-14 00:14:32 335478 ----a-w- c:\windows\inf\perflib\0410\perfh.dat
2009-08-14 00:10:08 38160 ----a-w- c:\windows\inf\perflib\040c\perfd.dat
2009-08-14 00:10:08 38160 ----a-w- c:\windows\inf\perflib\040c\perfc.dat
2009-08-14 00:10:08 344522 ----a-w- c:\windows\inf\perflib\040c\perfi.dat
2009-08-14 00:10:08 344522 ----a-w- c:\windows\inf\perflib\040c\perfh.dat
2009-08-14 00:05:43 38104 ----a-w- c:\windows\inf\perflib\0407\perfd.dat
2009-08-14 00:05:43 38104 ----a-w- c:\windows\inf\perflib\0407\perfc.dat
2009-08-14 00:05:43 295922 ----a-w- c:\windows\inf\perflib\0407\perfi.dat
2009-08-14 00:05:43 295922 ----a-w- c:\windows\inf\perflib\0407\perfh.dat
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 --sha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2010-01-23 13:56:44 16384 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2010-01-23 13:56:44 32768 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2010-01-23 13:56:44 16384 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\cookies\index.dat
2010-01-23 13:56:44 245760 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 20:06:33,99 ===============


Hijack This:


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:03:53, on 4-10-2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Windows\Explorer.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - (no file)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: (no name) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - (no file)
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: eBay.nl - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/1346-72745-17534-1/4 (file missing)
O9 - Extra 'Tools' menuitem: eBay.nl - {0B65DCC9-1740-43dc-B19C-4F309FB6A6CA} - http://rover.ebay.com/rover/1/1346-72745-17534-1/4 (file missing)
O9 - Extra button: In weblog opnemen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &In weblog opnemen met Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Verzenden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Verz&enden naar OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: BullGuard - {27FD17FB-CF63-486b-B2BE-8D8781CBEA01} - (no file)
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIF5BA~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx1.hotmail.com/mail/w4/m3/photoup...NPUpldnl-nl.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - (no file)
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - (no file)
O23 - Service: amBX Service - amBX - C:\Program Files\amBX\System\amBX_Service.exe
O23 - Service: Mobiel Apple apparaat (Apple Mobile Device) - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour-service (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod-service (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Philips amBX USB HAL - Philips - C:\Program Files\amBX\Device Drivers\Philips USB\USB Drivers\x86\Philips_amBX_USB_HAL_x86.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: WMI_Hook_Service - MICRO-STAR INT'L,.LTD. - C:\Program Files\msi\OSD hot keys\WMI_Hook_Service.exe

--
End of file - 7251 bytes

GMER:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-10-04 20:46:28
Windows 6.1.7600
Running: gmer.exe; Driver: C:\Users\Monique\AppData\Local\Temp\kxrdifod.sys


---- System - GMER 1.0.15 ----

INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8382FAF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8382F104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8382F3F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 838182D8
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83817898
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8382F1DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8382F958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8382F6F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8382FF2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 838301A8

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 83448599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 8346CF52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
? System32\Drivers\rsvepifh.sys Een apparaat dat op het systeem is aangesloten, werkt niet. !
.text peauth.sys 9D94BC9D 28 Bytes [5E, 58, CA, 9D, 7A, F6, 49, ...]
.text peauth.sys 9D94BCC1 28 Bytes [5E, 58, CA, 9D, 7A, F6, 49, ...]
PAGE peauth.sys 9D951B9B 72 Bytes [27, D2, 0F, 44, D4, 6B, 8E, ...]
PAGE peauth.sys 9D951BEC 111 Bytes [10, 06, B4, 98, C6, AB, A4, ...]
PAGE peauth.sys 9D95202C 102 Bytes [01, A1, FD, A4, 49, CF, 62, ...]
? C:\Windows\system32\Drivers\PROCEXP113.SYS Het systeem kan het opgegeven bestand niet vinden. !
? C:\Users\Monique\AppData\Local\Temp\catchme.sys Het systeem kan het opgegeven bestand niet vinden. !
? C:\Users\Monique\AppData\Local\Temp\mbr.sys Het systeem kan het opgegeven bestand niet vinden. !

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!CreateDialogParamW 76C49BFF 5 Bytes JMP 68DDC570 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!EnableWindow 76C4A72E 5 Bytes JMP 68DDC4EB C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!GetAsyncKeyState 76C4C09A 5 Bytes JMP 68D9D6E9 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!UnhookWindowsHookEx 76C4CC7B 5 Bytes JMP 68E9835E C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!CallNextHookEx 76C4CC8F 5 Bytes JMP 68E79D5C C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!CreateWindowExW 76C50E51 5 Bytes JMP 68E88157 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!SetWindowsHookExW 76C5210A 5 Bytes JMP 68E34633 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!GetKeyState 76C54FDA 5 Bytes JMP 68DDD762 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!IsDialogMessageW 76C56F06 5 Bytes JMP 68DA4284 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!CreateDialogParamA 76C63E79 5 Bytes JMP 68FB0571 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!IsDialogMessage 76C6407A 5 Bytes JMP 68FAFE12 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!CreateDialogIndirectParamA 76C69110 5 Bytes JMP 68FB05A8 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!CreateDialogIndirectParamW 76C708AD 5 Bytes JMP 68FB05DF C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!DialogBoxIndirectParamW 76C74AA7 5 Bytes JMP 68FAF970 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!EndDialog 76C7555C 5 Bytes JMP 68DA5AE9 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!DialogBoxParamW 76C7564A 5 Bytes JMP 68DA4BA7 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!SetKeyboardState 76C76B52 5 Bytes JMP 68FB0177 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!SendInput 76C77055 5 Bytes JMP 68FB0D3C C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!SetCursorPos 76C8C1D8 5 Bytes JMP 68FB0D94 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!DialogBoxParamA 76C8CF6A 5 Bytes JMP 68FAF90D C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!DialogBoxIndirectParamA 76C8D29C 5 Bytes JMP 68FAF9D3 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!MessageBoxIndirectA 76C9E8C9 5 Bytes JMP 68FAF8A2 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!MessageBoxIndirectW 76C9E9C3 5 Bytes JMP 68FAF837 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!MessageBoxExA 76C9EA29 5 Bytes JMP 68FAF7D5 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!MessageBoxExW 76C9EA4D 5 Bytes JMP 68FAF773 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] USER32.dll!keybd_event 76C9EC9B 5 Bytes JMP 68FB10C7 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] SHELL32.dll!SHChangeNotification_Lock + 45BA 7584B440 4 Bytes [11, 36, 69, 6F]
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] SHELL32.dll!SHChangeNotification_Lock + 45C2 7584B448 8 Bytes [5F, 35, 69, 6F, D0, 73, 68, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] ole32.dll!OleLoadFromStream 76D15B88 5 Bytes JMP 68FAFCCE C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] ole32.dll!CoCreateInstance 76D657FC 5 Bytes JMP 68E88C45 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] ws2_32.DLL!closesocket 755C3BED 5 Bytes JMP 6C1B41DF C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] ws2_32.DLL!socket 755C3F00 5 Bytes JMP 6C1B354C C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] ws2_32.DLL!recv 755C47DF 5 Bytes JMP 6C1B4549 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] ws2_32.DLL!connect 755C48BE 5 Bytes JMP 6C1B35DC C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] ws2_32.DLL!getaddrinfo 755C6737 5 Bytes JMP 6C1B3704 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3216] ws2_32.DLL!send 755CC4C8 5 Bytes JMP 6C1B3B92 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5876] USER32.dll!CreateWindowExW 76C50E51 5 Bytes JMP 68E88157 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5876] USER32.dll!DialogBoxIndirectParamW 76C74AA7 5 Bytes JMP 68FAF970 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5876] USER32.dll!DialogBoxParamW 76C7564A 5 Bytes JMP 68DA4BA7 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5876] USER32.dll!DialogBoxParamA 76C8CF6A 5 Bytes JMP 68FAF90D C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5876] USER32.dll!DialogBoxIndirectParamA 76C8D29C 5 Bytes JMP 68FAF9D3 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5876] USER32.dll!MessageBoxIndirectA 76C9E8C9 5 Bytes JMP 68FAF8A2 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5876] USER32.dll!MessageBoxIndirectW 76C9E9C3 5 Bytes JMP 68FAF837 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5876] USER32.dll!MessageBoxExA 76C9EA29 5 Bytes JMP 68FAF7D5 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[5876] USER32.dll!MessageBoxExW 76C9EA4D 5 Bytes JMP 68FAF773 C:\Windows\system32\IEFRAME.dll (Internetbrowser/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 87C1B178
Device \Driver\ACPI_HAL \Device\00000047 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume5 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\000b0d4b2db7
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\000b0d4b2e3c
Reg HKLM\SYSTEM\CurrentControlSet\services\rsvepifh@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\services\rsvepifh@Start 0
Reg HKLM\SYSTEM\CurrentControlSet\services\rsvepifh@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\services\rsvepifh@Group Boot Bus Extender
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\000b0d4b2db7 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\000b0d4b2e3c (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\rsvepifh@Type 1
Reg HKLM\SYSTEM\ControlSet002\services\rsvepifh@Start 0
Reg HKLM\SYSTEM\ControlSet002\services\rsvepifh@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet002\services\rsvepifh@Group Boot Bus Extender

---- EOF - GMER 1.0.15 ----


Already lots of thx!!



When your LIFE is in DARKNESS, PRAY GOD and asks him to free you from Darkness.
Even after you pray, if U R still in Darkness.......Please PAY the ELECTRICITY BILL.

BC AdBot (Login to Remove)

 


#2 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:50 AM

Posted 11 October 2010 - 11:30 PM

Hello and Welcome to the forums!

My name is Gringo and I'll be glad to help you with your computer problems.

Somethings to remember while we are working together.
  1. Do not run any other tool untill instructed to do so!
  2. Please Do not Attach logs or put in code boxes.
  3. Tell me about any problems that have occurred during the fix.
  4. Tell me of any other symptoms you may be having as these can help also.
  5. Do not run anything while running a fix.

In the upper right hand corner of the topic you will see a button called Options. If you click on this in the drop-down menu you can choose Track this topic. By doing this and then choosing Immediate E-Mail notification and then clicking on Proceed you will be advised when we respond to your topic and facilitate the cleaning of your machine.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

In order for me to see the status of the infection I will need a new set of logs to start with.

Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

DeFogger:
    Please download DeFogger to your desktop.

    Double click DeFogger to run the tool.
    • The application window will appear
    • Click the Disable button to disable your CD Emulation drivers
    • Click Yes to continue
    • A 'Finished!' message will appear
    • Click OK
    • DeFogger may ask you to reboot the machine, if it does - click OK
    Do not re-enable these drivers until otherwise instructed.

Download DDS:
    Please download DDS by sUBs from one of the links below and save it to your desktop:


    Download DDS and save it to your desktop

    Link1
    Link2
    Link3

    Please disable any anti-malware program that will block scripts from running before running DDS.
    • Double-Click on dds.scr and a command window will appear. This is normal.
    • Shortly after two logs will appear:
      • DDS.txt
      • Attach.txt
    • A window will open instructing you save & post the logs
    • Save the logs to a convenient place such as your desktop
    • Copy the contents of both logs & post in your next reply

Scan With RKUnHooker
  • Please Download Rootkit Unhooker Save it to your desktop.
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers, Stealth,. Uncheck the rest. then Click OK.
  • Wait till the scanner has finished and then click File, Save Report.
  • Save the report somewhere where you can find it. Click Close.
Copy the entire contents of the report and paste it in a reply here.

Note** you may get this warning it is ok, just ignore

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"


information and logs:
    In your next post I need the following
      1.logs from DDS
      2.log from RKUnHooker
      3.let me know of any problems you may have had

Gringo


I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#3 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:50 AM

Posted 14 October 2010 - 11:34 PM

Hello

three day bump

It has been Three days since my last post.
  • do you still need help with this?
  • do you need more time?
  • are you having problems following my instructions?
  • if after 48hrs you have not replied to this thread then it will have to be closed!

Gringo



I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#4 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:11:50 AM

Posted 17 October 2010 - 11:41 PM

Due to lack of feedback, this topic is now Closed

If you need this topic reopened, please send me a PM.
Please include the address of this thread in your request.
This applies only to the original topic starter.

Everyone else please start a new topic.

The fixes and advice in this thread are for this machine only.
Do not apply the instructions from this thread to your own machine.
Please start a new thread describing your issue and someone will be along to assist you.


With Regards,
Gringo


I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users