Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Yahoo/Google Redirecting


  • This topic is locked This topic is locked
30 replies to this topic

#1 johndepere

johndepere

  • Members
  • 78 posts
  • OFFLINE
  •  
  • Local time:11:35 AM

Posted 19 April 2011 - 08:12 PM

I keep getting redirected when trying to search on the internet. I tried gmer and it started to run but then shut my computer down. It wouldn't give me the chance to uncheck the things listed in the help section. Attached are the two DDS files. Your help would be greatly appreciated. Thanks, John
Text
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by John McMorrow at 18:53:06.60 on Tue 04/19/2011
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_23
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.446.136 [GMT -5:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe -k itlsvc
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\lxdmcoms.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\Documents and Settings\John McMorrow\My Documents\My Music\Zune setup\ZuneBusEnum.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\John McMorrow\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.com/?rs=1
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [KBD] c:\hp\kbd\KBD.EXE
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: itlntfy - itlnfw32.dll
AppInit_DLLs: c:\windows\system32\bthci32.dll sifajade.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
LSA: Notification Packages = scecli bovekafu.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\johnmc~1\applic~1\mozilla\firefox\profiles\b8nbdsit.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2645238&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - ZoneAlarm Security Customized Web Search
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - prefs.js: keyword.URL - hxxps://www.mypoints.com/emp/u/mysearch.vm?st=mypWeb&fctb.dns=1&q=
FF - component: c:\documents and settings\john mcmorrow\application data\mozilla\firefox\profiles\b8nbdsit.default\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}\components\RadioWMPCoreGecko19.dll
FF - component: c:\documents and settings\john mcmorrow\application data\mozilla\firefox\profiles\b8nbdsit.default\extensions\engine@conduit.com\components\RadioWMPCoreGecko19.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPcol400.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - c:\program files\mozilla firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Swag Bucks Community Toolbar: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - %profile%\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
.
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R1 MpKsl8715c36e;MpKsl8715c36e;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{07033159-7e8e-4578-b8c5-dfd6b4ba0dcb}\MpKsl8715c36e.sys [2011-4-19 28752]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2009-9-15 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-9-15 67656]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2009/09/18 00:44:38];c:\program files\cyberlink\powerdvd9\000.fcl [2009-5-7 87536]
R2 itlperf;Intel CPU;c:\windows\system32\svchost.exe -k itlsvc [2006-2-28 14336]
S0 ntcdrdrv;ntcdrdrv;c:\windows\system32\drivers\ntcdrdrv.sys --> c:\windows\system32\drivers\ntcdrdrv.sys [?]
S1 MpKsl0f010b74;MpKsl0f010b74;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{05efddd2-377b-443b-9e6f-a55a89e59d92}\mpksl0f010b74.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{05efddd2-377b-443b-9e6f-a55a89e59d92}\MpKsl0f010b74.sys [?]
S1 MpKsl2ca5a098;MpKsl2ca5a098;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{17d1583a-45e9-4462-90a3-5022b04d0192}\mpksl2ca5a098.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{17d1583a-45e9-4462-90a3-5022b04d0192}\MpKsl2ca5a098.sys [?]
S1 MpKsl386d0aff;MpKsl386d0aff;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c5250355-ffa8-4dce-9e30-d12d05cbd3c9}\mpksl386d0aff.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c5250355-ffa8-4dce-9e30-d12d05cbd3c9}\MpKsl386d0aff.sys [?]
S1 MpKsl44ecdc4d;MpKsl44ecdc4d;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a920423c-8f8e-47a3-a647-20ee1f0954bb}\mpksl44ecdc4d.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a920423c-8f8e-47a3-a647-20ee1f0954bb}\MpKsl44ecdc4d.sys [?]
S1 MpKsl573beb85;MpKsl573beb85;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{96126ffa-b41d-4dae-93c4-ac39f0035676}\mpksl573beb85.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{96126ffa-b41d-4dae-93c4-ac39f0035676}\MpKsl573beb85.sys [?]
S1 MpKsl57f88940;MpKsl57f88940;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{acb91a84-5d2f-479f-8a82-0cf2bced48b4}\mpksl57f88940.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{acb91a84-5d2f-479f-8a82-0cf2bced48b4}\MpKsl57f88940.sys [?]
S1 MpKsl5ce9a7e0;MpKsl5ce9a7e0;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5ac3a0d0-bcc8-4c21-b9f1-48546a9ae1ad}\mpksl5ce9a7e0.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5ac3a0d0-bcc8-4c21-b9f1-48546a9ae1ad}\MpKsl5ce9a7e0.sys [?]
S1 MpKsl6d3e36a7;MpKsl6d3e36a7;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{483df6ff-94ed-444e-a31b-1ac1e63c4fce}\mpksl6d3e36a7.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{483df6ff-94ed-444e-a31b-1ac1e63c4fce}\MpKsl6d3e36a7.sys [?]
S1 MpKsl7fab8f15;MpKsl7fab8f15;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a3c06146-8631-4444-8c49-fa3222ebab45}\mpksl7fab8f15.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a3c06146-8631-4444-8c49-fa3222ebab45}\MpKsl7fab8f15.sys [?]
S1 MpKsl90b7953a;MpKsl90b7953a;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{38695dd5-4322-4cd2-8868-16e1cc83ba98}\mpksl90b7953a.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{38695dd5-4322-4cd2-8868-16e1cc83ba98}\MpKsl90b7953a.sys [?]
S1 MpKsl9c090978;MpKsl9c090978;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{cf3e1280-75a0-4247-a391-41c2fa66f8d8}\mpksl9c090978.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{cf3e1280-75a0-4247-a391-41c2fa66f8d8}\MpKsl9c090978.sys [?]
S1 MpKslb233c61c;MpKslb233c61c;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c49b6202-872c-49a1-b3ac-80df48d147c1}\mpkslb233c61c.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c49b6202-872c-49a1-b3ac-80df48d147c1}\MpKslb233c61c.sys [?]
S1 MpKslcf7307b5;MpKslcf7307b5;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{07033159-7e8e-4578-b8c5-dfd6b4ba0dcb}\mpkslcf7307b5.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{07033159-7e8e-4578-b8c5-dfd6b4ba0dcb}\MpKslcf7307b5.sys [?]
S1 MpKsle97056d8;MpKsle97056d8;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{67afdf85-a406-4d38-aca9-88e2fefe3d99}\mpksle97056d8.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{67afdf85-a406-4d38-aca9-88e2fefe3d99}\MpKsle97056d8.sys [?]
S1 MpKslecaad8aa;MpKslecaad8aa;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{dc697f2d-22f8-4c81-ac4b-c813ba0eeeba}\mpkslecaad8aa.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{dc697f2d-22f8-4c81-ac4b-c813ba0eeeba}\MpKslecaad8aa.sys [?]
S1 MpKslf3d9a833;MpKslf3d9a833;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1e67ed45-a757-48fb-a32b-b1d28d7e161a}\mpkslf3d9a833.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{1e67ed45-a757-48fb-a32b-b1d28d7e161a}\MpKslf3d9a833.sys [?]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-9-15 12872]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\documents and settings\john mcmorrow\my documents\my music\zune setup\WMZuneComm.exe [2010-11-11 268528]
.
=============== Created Last 30 ================
.
2011-04-19 23:07:22 28752 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{07033159-7e8e-4578-b8c5-dfd6b4ba0dcb}\MpKsl8715c36e.sys
2011-04-19 17:32:20 215040 ----a-w- c:\windows\system32\itlpfw32.dll
2011-04-18 14:35:20 6792528 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{07033159-7e8e-4578-b8c5-dfd6b4ba0dcb}\mpengine.dll
2011-04-14 14:50:41 828017 ----a-w- c:\documents and settings\all users\SPL2B.tmp
2011-04-13 22:26:13 1259362 ----a-w- c:\documents and settings\all users\SPL1C3.tmp
2011-03-24 15:35:10 -------- d-----w- c:\program files\iPod
2011-03-24 15:34:28 -------- d-----w- c:\program files\iTunes
2011-03-22 22:24:24 1024297 ----a-w- c:\documents and settings\all users\SPL17.tmp
.
==================== Find3M ====================
.
2011-03-19 18:30:42 1468106 ----a-w- c:\documents and settings\all users\SPL24.tmp
2011-03-07 05:33:50 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:45:07 434176 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21:11 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-18 21:36:58 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2011-02-17 15:32:34 398760 ----a-r- c:\windows\system32\cpnprt2.cid
2011-02-17 13:51:57 81920 ----a-w- c:\windows\system32\ieencode.dll
2011-02-17 13:51:57 667136 ----a-w- c:\windows\system32\wininet.dll
2011-02-17 13:51:57 61952 ----a-w- c:\windows\system32\tdc.ocx
2011-02-17 12:37:38 369664 ----a-w- c:\windows\system32\html.iec
2011-02-17 12:32:12 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56:39 290432 ----a-w- c:\windows\system32\atmfd.dll
2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33:55 978944 ----a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33:55 974848 ----a-w- c:\windows\system32\mfc42u.dll
2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 15:56:19 1968920 ----a-w- c:\documents and settings\all users\SPL1.tmp
2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-21 14:38:19 1968920 ----a-w- c:\documents and settings\all users\SPL78.tmp
2009-09-05 00:01:10 525656 ----a-w- c:\program files\DXSETUP.exe
2009-09-05 00:01:08 94024 ----a-w- c:\program files\DSETUP.dll
2009-09-05 00:01:08 1691464 ----a-w- c:\program files\dsetup32.dll
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: Maxtor_6L200M0 rev.BANC1G10 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x84E09EF0]<<
_asm { PUSH EBP; CALL 0x6; }
1 ntkrnlpa!IofCallDriver[0x804EE130] -> \Device\Harddisk0\DR0[0x84F39360]
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x84F2633B
user & kernel MBR OK
.
============= FINISH: 18:54:03.62 ===============

Attatchment
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_11-03-05.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 9/4/2009 10:41:13 AM
System Uptime: 4/19/2011 6:05:54 PM (0 hours ago)
.
Motherboard: ASUSTek Computer INC. | | Amberine M
Processor: AMD Athlon™ 64 Processor 3500+ | Socket 939 | 2188/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 186 GiB total, 15.673 GiB free.
D: is CDROM ()
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
J: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: SM Bus Controller
Device ID: PCI\VEN_1002&DEV_4372&SUBSYS_2A26103C&REV_11\3&61AAA01&0&A0
Manufacturer:
Name: SM Bus Controller
PNP Device ID: PCI\VEN_1002&DEV_4372&SUBSYS_2A26103C&REV_11\3&61AAA01&0&A0
Service:
.
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: PCI Modem
Device ID: PCI\VEN_1057&DEV_3052&SUBSYS_30201057&REV_04\4&1C88B56&0&48A4
Manufacturer:
Name: PCI Modem
PNP Device ID: PCI\VEN_1057&DEV_3052&SUBSYS_30201057&REV_04\4&1C88B56&0&48A4
Service:
.
==== System Restore Points ===================
.
RP263: 1/18/2011 7:37:27 PM - Software Distribution Service 3.0
RP264: 1/19/2011 8:20:41 PM - System Checkpoint
RP265: 1/20/2011 8:15:02 AM - Software Distribution Service 3.0
RP266: 1/21/2011 12:21:12 PM - System Checkpoint
RP267: 1/22/2011 1:46:02 PM - System Checkpoint
RP268: 1/22/2011 5:39:01 PM - Software Distribution Service 3.0
RP269: 1/23/2011 7:15:32 PM - Software Distribution Service 3.0
RP270: 1/24/2011 8:21:32 PM - Software Distribution Service 3.0
RP271: 1/26/2011 6:55:41 AM - Software Distribution Service 3.0
RP272: 2/8/2011 3:24:15 PM - Software Distribution Service 3.0
RP273: 2/9/2011 9:26:36 PM - Software Distribution Service 3.0
RP274: 2/10/2011 8:30:37 AM - Software Distribution Service 3.0
RP275: 2/11/2011 9:03:07 AM - System Checkpoint
RP276: 2/11/2011 7:56:33 PM - Software Distribution Service 3.0
RP277: 2/13/2011 10:49:23 AM - Software Distribution Service 3.0
RP278: 2/14/2011 11:06:46 AM - System Checkpoint
RP279: 2/14/2011 6:02:11 PM - Software Distribution Service 3.0
RP280: 2/15/2011 8:56:50 PM - Software Distribution Service 3.0
RP281: 2/17/2011 7:50:44 AM - Software Distribution Service 3.0
RP282: 2/18/2011 8:30:10 AM - Software Distribution Service 3.0
RP283: 2/19/2011 9:31:35 AM - Software Distribution Service 3.0
RP284: 2/19/2011 3:28:20 PM - Software Distribution Service 3.0
RP285: 2/20/2011 4:11:20 PM - System Checkpoint
RP286: 2/21/2011 1:31:01 PM - Software Distribution Service 3.0
RP287: 2/24/2011 3:28:57 PM - Software Distribution Service 3.0
RP288: 2/25/2011 4:41:19 PM - System Checkpoint
RP289: 2/25/2011 8:40:45 PM - Software Distribution Service 3.0
RP290: 2/27/2011 7:01:39 AM - Software Distribution Service 3.0
RP291: 2/28/2011 7:18:23 AM - System Checkpoint
RP292: 3/1/2011 7:21:33 AM - Software Distribution Service 3.0
RP293: 3/1/2011 8:05:22 PM - Installed Windows XP winusb0100.
RP294: 3/2/2011 8:52:18 PM - System Checkpoint
RP295: 3/2/2011 8:53:10 PM - Software Distribution Service 3.0
RP296: 3/4/2011 6:30:11 AM - Software Distribution Service 3.0
RP297: 3/5/2011 7:43:00 AM - Software Distribution Service 3.0
RP298: 3/9/2011 5:27:39 PM - Software Distribution Service 3.0
RP299: 3/9/2011 6:34:12 PM - Software Distribution Service 3.0
RP300: 3/10/2011 7:10:06 PM - Software Distribution Service 3.0
RP301: 3/12/2011 7:58:00 AM - Software Distribution Service 3.0
RP302: 3/13/2011 4:59:33 PM - Software Distribution Service 3.0
RP303: 3/13/2011 6:50:25 PM - Installed DirectX
RP304: 3/14/2011 8:52:28 PM - System Checkpoint
RP305: 3/15/2011 8:21:37 AM - Software Distribution Service 3.0
RP306: 3/18/2011 9:47:49 AM - Software Distribution Service 3.0
RP307: 3/19/2011 12:24:01 PM - Software Distribution Service 3.0
RP308: 3/20/2011 12:34:53 PM - System Checkpoint
RP309: 3/21/2011 10:39:42 AM - Software Distribution Service 3.0
RP310: 3/22/2011 4:54:10 PM - Software Distribution Service 3.0
RP311: 3/24/2011 8:12:13 AM - Software Distribution Service 3.0
RP312: 3/24/2011 10:00:23 AM - Software Distribution Service 3.0
RP313: 3/25/2011 9:40:03 AM - Software Distribution Service 3.0
RP314: 3/26/2011 12:12:37 PM - System Checkpoint
RP315: 3/26/2011 9:34:56 PM - Software Distribution Service 3.0
RP316: 3/27/2011 7:34:12 PM - Unsigned driver install
RP317: 3/28/2011 7:21:39 AM - Software Distribution Service 3.0
RP318: 3/31/2011 8:45:18 AM - Software Distribution Service 3.0
RP319: 4/2/2011 3:30:16 PM - Software Distribution Service 3.0
RP320: 4/3/2011 3:57:58 PM - System Checkpoint
RP321: 4/4/2011 7:27:48 AM - Software Distribution Service 3.0
RP322: 4/11/2011 7:50:40 AM - Software Distribution Service 3.0
RP323: 4/12/2011 9:54:09 AM - Software Distribution Service 3.0
RP324: 4/13/2011 10:29:48 AM - System Checkpoint
RP325: 4/13/2011 9:31:02 PM - Software Distribution Service 3.0
RP326: 4/14/2011 9:27:34 AM - Software Distribution Service 3.0
RP327: 4/15/2011 3:03:49 PM - Software Distribution Service 3.0
RP328: 4/16/2011 9:06:00 PM - System Checkpoint
RP329: 4/17/2011 5:32:58 AM - Software Distribution Service 3.0
RP330: 4/18/2011 9:35:04 AM - Software Distribution Service 3.0
RP331: 4/19/2011 6:34:55 PM - System Checkpoint
.
==== Installed Programs ======================
.
µTorrent
7-Zip 4.65
ABBYY FineReader 6.0 Sprint
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.2.6
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI Control Panel
ATI Display Driver
BC246T Advanced Virtual Control
Bonjour
Burger Shop 2 1.00
CCleaner (remove only)
Compatibility Pack for the 2007 Office system
Coupon Printer for Windows
CouponBar
CyberLink PowerDVD 9
DVDFab 7.0.8.0 (14/07/2010)
Enhanced Multimedia Keyboard Solution
Favorite Places
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Format 11 SDK (KB973442)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB932716-v2)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
ImageMixer3
Indeo® Software
InterActual Player
Internet Transporter - NCP Link
iTunes
Java Auto Updater
Java™ 6 Update 23
Lexmark 5000 Series
Magic 3D Coloring Book
Malwarebytes' Anti-Malware
Master of the Skies - The Red Ace
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Antimalware
Microsoft Application Error Reporting
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
Microsoft Office
Microsoft Security Client
Microsoft Security Essentials
Microsoft User-Mode Driver Framework Feature Pack 1.9
Microsoft Visual C++ 2005 Redistributable
Microsoft Windows XP Video Decoder Checkup Utility
Microsoft WinUsb 1.0
Monsters, Inc. Scare Island
Mozilla Firefox (3.6.16)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NCP Internet Transporter
Nero 7 Premium
neroxml
PowerDVD DX
QuickTime
Realtek AC'97 Audio
Recuva
ScanTool.net for Windows v1.20
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2183461)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360131)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2416400)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2482017)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2497640)
Security Update for Windows XP (KB2503658)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2506223)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2508272)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2510581)
Security Update for Windows XP (KB2511455)
Security Update for Windows XP (KB2524375)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371-v2)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972260)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974455)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB976325)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981349)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982381)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
Spider-Man Kellogg's Demo
SpywareBlaster 4.4
StartVADIS
SUPERAntiSpyware Free Edition
Suzuki Alstare Extreme Racing
SyncBack
The KMPlayer (remove only)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update for Windows XP (KB976749)
Update for Windows XP (KB978207)
Update for Windows XP (KB980182)
VADIS Application
VADIS Config
VC 9.0 Runtime
VLC media player 1.0.2
WebFldrs XP
Windows Driver Package - FTDI CDM Driver Package (02/17/2009 2.04.16)
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Media Format 11 runtime
Windows Media Player 11
Windows Mobile Device Updater Component
Windows XP Service Pack 3
Zune
Zune Language Pack (DEU)
Zune Language Pack (ESP)
Zune Language Pack (FRA)
Zune Language Pack (ITA)
Zune Language Pack (NLD)
Zune Language Pack (PTB)
Zune Language Pack (PTG)
.
==== Event Viewer Messages From Past Week ========
.
4/19/2011 8:27:31 AM, error: Dhcp [1002] - The IP address lease 174.103.202.4 for the Network Card with network address 0013D45DFEAE has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
4/19/2011 2:09:16 PM, error: Service Control Manager [7034] - The Google Update Service service terminated unexpectedly. It has done this 1 time(s).
4/19/2011 10:42:38 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.101.1703.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.6702.0 Error code: 0x8007041d Error description: The service did not respond to the start or control request in a timely fashion.
4/19/2011 10:41:38 AM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
4/19/2011 10:40:38 AM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
4/19/2011 10:39:37 AM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service winmgmt with arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
4/18/2011 3:04:03 PM, error: Print [6161] - The document Coupon Print 165130781 owned by John McMorrow failed to print on printer Lexmark 5000 Series. Data type: LEMF. Size of the spool file in bytes: 0. Number of bytes printed: 0. Total number of pages in the document: 1. Number of pages printed: 0. Client machine: \\SELF-0596411DBC. Win32 error code returned by the print processor: 123 (0x7b).
4/18/2011 11:35:16 AM, error: Print [6161] - The document SmartSource Coupon(s) owned by John McMorrow failed to print on printer Lexmark 5000 Series. Data type: LEMF. Size of the spool file in bytes: 1546931. Number of bytes printed: 1546931. Total number of pages in the document: 1. Number of pages printed: 0. Client machine: \\SELF-0596411DBC. Win32 error code returned by the print processor: 0 (0x0).
4/17/2011 5:21:34 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the lxdmCATSCustConnectService service to connect.
4/16/2011 8:38:17 PM, error: Print [6161] - The document Coupon Print 221505812 owned by John McMorrow failed to print on printer Lexmark 5000 Series. Data type: LEMF. Size of the spool file in bytes: 0. Number of bytes printed: 0. Total number of pages in the document: 1. Number of pages printed: 0. Client machine: \\SELF-0596411DBC. Win32 error code returned by the print processor: 123 (0x7b).

BC AdBot (Login to Remove)

 


#2 heir

heir

  • Malware Response Team
  • 763 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:35 PM

Posted 20 April 2011 - 04:08 AM

Hello John!

I tried gmer and it started to run but then shut my computer down. It wouldn't give me the chance to uncheck the things listed in the help section.

Let's try two other scanners

Step 1.
aswMBR:

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Posted Image

Click the "Scan" button to start scan


Posted Image

On completion of the scan click save log, save it to your desktop and post in your next reply


Step 2.
Rootkit UnHooker:

  • Please Download Rootkit Unhooker Save it to your desktop.
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers, Stealth. Uncheck the rest. then Click OK.
  • Wait till the scanner has finished and then click File, Save Report.
  • Save the report somewhere where you can find it. Click Close.
Copy the entire contents of the report and paste it in a reply here.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"


Step 3.
Things I would like to see in your reply:

  • The content of the log from aswMBR in step 1.
  • The content of the log from RKU in step 2.

Please do not PM me asking for support. Post on the forums instead.
Please post the final results, good or bad. We like to know!
Posted Image
Unified Network of Instructors and Trained Eliminators
My help is always free, but if you want to donate to help me continue my fight against malware then click Posted Image


#3 johndepere

johndepere
  • Topic Starter

  • Members
  • 78 posts
  • OFFLINE
  •  
  • Local time:11:35 AM

Posted 20 April 2011 - 07:56 PM

Thank You for your quick reply and assistance. I have included the two log files that you have requested. I hope this helps.

aswMBR version 0.9.4 Copyright© 2011 AVAST Software
Run date: 2011-04-20 19:32:18
-----------------------------
19:32:18.234 OS Version: Windows 5.1.2600 Service Pack 3
19:32:18.234 Number of processors: 1 586 0x2F02
19:32:18.234 ComputerName: SELF-0596411DBC UserName: John McMorrow
19:32:19.453 Initialize success
19:32:28.109 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
19:32:28.109 Disk 0 Vendor: Maxtor_6L200M0 BANC1G10 Size: 190782MB BusType: 3
19:32:28.109 Device \Driver\atapi -> DriverStartIo 84f2633b
19:32:28.109 Disk 0 MBR read error
19:32:28.109 Disk 0 MBR scan
19:32:28.109 MBR BIOS signature not found 0
19:32:28.125 Disk 0 scanning sectors +390700800
19:32:28.125 Disk 0 scanning C:\WINDOWS\system32\drivers
19:32:37.265 Service scanning
19:32:38.875 Disk 0 trace - called modules:
19:32:38.875 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x84f264f0]<<
19:32:38.875 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x84f39360]
19:32:38.875 3 CLASSPNP.SYS[f757cfd7] -> nt!IofCallDriver -> \Device\00000075[0x84fcee98]
19:32:38.875 5 ACPI.sys[f73f3620] -> nt!IofCallDriver -> [0x84f60470]
19:32:39.390 \Driver\atapi[0x84eeba28] -> IRP_MJ_CREATE -> 0x84f264f0
19:32:39.390 Scan finished successfully


RkU Version: 3.8.388.590, Type LE (SR2)
==============================================
OS Name: Windows XP
Version 5.1.2600 (Service Pack 3)
Number of processors #1
==============================================
>Drivers
==============================================
0xF6395000 C:\WINDOWS\system32\drivers\ALCXWDM.SYS 3645440 bytes (Realtek Semiconductor Corp., Realtek AC'97 Audio Driver (WDM))
0xBF0BF000 C:\WINDOWS\System32\ati3duag.dll 2412544 bytes (ATI Technologies Inc. , ati3duag.dll)
0x804D7000 C:\WINDOWS\system32\ntkrnlpa.exe 2069376 bytes (Microsoft Corporation, NT Kernel & System)
0x804D7000 PnpManager 2069376 bytes
0x804D7000 RAW 2069376 bytes
0x804D7000 WMIxWDM 2069376 bytes
0xBF800000 Win32k 1859584 bytes
0xBF800000 C:\WINDOWS\System32\win32k.sys 1859584 bytes (Microsoft Corporation, Multi-User Win32 Driver)
0xF676A000 C:\WINDOWS\system32\DRIVERS\ati2mtag.sys 1368064 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Miniport Driver)
0xBF30C000 C:\WINDOWS\System32\ativvaxx.dll 602112 bytes (ATI Technologies Inc. , Radeon Video Acceleration Universal Driver)
0xF72A9000 Ntfs.sys 577536 bytes (Microsoft Corporation, NT File System Driver)
0xF620E000 C:\WINDOWS\System32\Drivers\wdf01000.sys 462848 bytes (Microsoft Corporation, Kernel Mode Driver Framework Runtime)
0xF1536000 C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 458752 bytes (Microsoft Corporation, Windows NT SMB Minirdr)
0xF627F000 C:\WINDOWS\system32\DRIVERS\update.sys 385024 bytes (Microsoft Corporation, Update Driver)
0xF1685000 C:\WINDOWS\system32\DRIVERS\tcpip.sys 364544 bytes (Microsoft Corporation, TCP/IP Protocol Driver)
0xB85FC000 C:\WINDOWS\system32\DRIVERS\srv.sys 360448 bytes (Microsoft Corporation, Server driver)
0xBF39F000 C:\WINDOWS\System32\ATMFD.DLL 290816 bytes (Adobe Systems Incorporated, Windows NT OpenType/Type 1 Font Driver)
0xB807A000 C:\WINDOWS\System32\Drivers\HTTP.sys 266240 bytes (Microsoft Corporation, HTTP Protocol Stack)
0xBF012000 C:\WINDOWS\System32\ati2dvag.dll 258048 bytes (ATI Technologies Inc., ATI Radeon WindowsNT Display Driver)
0xBF051000 C:\WINDOWS\System32\ati2cqag.dll 233472 bytes (ATI Technologies Inc., Central Memory Manager / Queue Server Module)
0xBF08A000 C:\WINDOWS\System32\atikvmag.dll 217088 bytes (ATI Technologies Inc., Virtual Command And Memory Manager)
0xF6305000 C:\WINDOWS\system32\DRIVERS\rdpdr.sys 196608 bytes (Microsoft Corporation, Microsoft RDP Device redirector)
0xF73ED000 ACPI.sys 188416 bytes (Microsoft Corporation, ACPI Driver for NT)
0xB86A4000 C:\WINDOWS\system32\DRIVERS\mrxdav.sys 184320 bytes (Microsoft Corporation, Windows NT WebDav Minirdr)
0xF727C000 NDIS.sys 184320 bytes (Microsoft Corporation, NDIS 5.1 wrapper driver)
0xB84F5000 C:\Program Files\CyberLink\PowerDVD9\000.fcl 180224 bytes (CyberLink Corp., -)
0xB7DFE000 C:\WINDOWS\system32\drivers\kmixer.sys 176128 bytes (Microsoft Corporation, Kernel Mode Audio Mixer)
0xF15A6000 C:\WINDOWS\system32\DRIVERS\rdbss.sys 176128 bytes (Microsoft Corporation, Redirected Drive Buffering SubSystem Driver)
0xF165D000 C:\WINDOWS\system32\DRIVERS\netbt.sys 163840 bytes (Microsoft Corporation, MBT Transport driver)
0xEBDF2000 C:\WINDOWS\system32\DRIVERS\MpFilter.sys 159744 bytes (Microsoft Corporation, Microsoft antimalware file system filter driver)
0xF7397000 dmio.sys 155648 bytes (Microsoft Corp., Veritas Software, NT Disk Manager I/O Driver)
0xF0BA8000 C:\WINDOWS\system32\DRIVERS\ipnat.sys 155648 bytes (Microsoft Corporation, IP Network Address Translator)
0xB7E29000 C:\WINDOWS\System32\Drivers\Fastfat.SYS 147456 bytes (Microsoft Corporation, Fast FAT File System Driver)
0xF6371000 C:\WINDOWS\system32\drivers\portcls.sys 147456 bytes (Microsoft Corporation, Port Class (Class Driver for Port/Miniport Devices))
0xF6732000 C:\WINDOWS\system32\DRIVERS\USBPORT.SYS 147456 bytes (Microsoft Corporation, USB 1.1 & 2.0 Port Driver)
0xF670F000 C:\WINDOWS\system32\DRIVERS\ks.sys 143360 bytes (Microsoft Corporation, Kernel CSA Library)
0xF163B000 C:\WINDOWS\System32\drivers\afd.sys 139264 bytes (Microsoft Corporation, Ancillary Function Driver for WinSock)
0xF1619000 C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys 139264 bytes (SUPERAdBlocker.com and SUPERAntiSpyware.com, SASKUTIL.SYS)
0x806D1000 ACPI_HAL 131840 bytes
0x806D1000 C:\WINDOWS\system32\hal.dll 131840 bytes (Microsoft Corporation, Hardware Abstraction Layer DLL)
0xF735F000 fltmgr.sys 131072 bytes (Microsoft Corporation, Microsoft Filesystem Filter Manager)
0xF73BD000 ftdisk.sys 126976 bytes (Microsoft Corporation, FT Disk Driver)
0xF7262000 Mup.sys 106496 bytes (Microsoft Corporation, Multiple UNC Provider driver)
0xF737F000 atapi.sys 98304 bytes (Microsoft Corporation, IDE/ATAPI Port Driver)
0xEBDDA000 C:\WINDOWS\System32\Drivers\dump_atapi.sys 98304 bytes
0xF7336000 KSecDD.sys 94208 bytes (Microsoft Corporation, Kernel Security Support Provider Interface)
0xF6346000 C:\WINDOWS\system32\DRIVERS\ndiswan.sys 94208 bytes (Microsoft Corporation, MS PPP Framing Driver (Strong Encryption))
0xB87E9000 C:\WINDOWS\system32\DRIVERS\WudfPf.sys 94208 bytes (Microsoft Corporation, Windows Driver Foundation - User-mode Driver Framework Platform Driver)
0xB856F000 C:\WINDOWS\system32\drivers\wdmaud.sys 86016 bytes (Microsoft Corporation, MMSYSTEM Wave/Midi API mapper)
0xF635D000 C:\WINDOWS\system32\DRIVERS\parport.sys 81920 bytes (Microsoft Corporation, Parallel Port Driver)
0xF6756000 C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS 81920 bytes (Microsoft Corporation, Video Port Driver)
0xF16DE000 C:\WINDOWS\system32\DRIVERS\ipsec.sys 77824 bytes (Microsoft Corporation, IPSec Driver)
0xBF000000 C:\WINDOWS\System32\drivers\dxg.sys 73728 bytes (Microsoft Corporation, DirectX Graphics Driver)
0xF734D000 sr.sys 73728 bytes (Microsoft Corporation, System Restore Filesystem Filter Driver)
0xF73DC000 pci.sys 69632 bytes (Microsoft Corporation, NT Plug and Play PCI Enumerator)
0xF6335000 C:\WINDOWS\system32\DRIVERS\psched.sys 69632 bytes (Microsoft Corporation, MS QoS Packet Scheduler)
0xEEAB9000 C:\WINDOWS\System32\Drivers\Cdfs.SYS 65536 bytes (Microsoft Corporation, CD-ROM File System Driver)
0xF75DC000 C:\WINDOWS\system32\DRIVERS\cdrom.sys 65536 bytes (Microsoft Corporation, SCSI CD-ROM Driver)
0xF760C000 C:\WINDOWS\system32\DRIVERS\nic1394.sys 65536 bytes (Microsoft Corporation, IEEE1394 Ndis Miniport and Call Manager)
0xF751C000 ohci1394.sys 65536 bytes (Microsoft Corporation, 1394 OpenHCI Port Driver)
0xEEB29000 C:\WINDOWS\system32\DRIVERS\arp1394.sys 61440 bytes (Microsoft Corporation, IP/1394 Arp Client)
0xF761C000 C:\WINDOWS\system32\drivers\drmk.sys 61440 bytes (Microsoft Corporation, Microsoft Kernel DRM Descrambler Filter)
0xF75FC000 C:\WINDOWS\system32\DRIVERS\redbook.sys 61440 bytes (Microsoft Corporation, Redbook Audio Filter Driver)
0xEBF14000 C:\WINDOWS\system32\drivers\sysaudio.sys 61440 bytes (Microsoft Corporation, System Audio WDM Filter)
0xF764C000 C:\WINDOWS\system32\DRIVERS\usbhub.sys 61440 bytes (Microsoft Corporation, Default Hub Driver for USB)
0xF752C000 C:\WINDOWS\system32\DRIVERS\1394BUS.SYS 57344 bytes (Microsoft Corporation, 1394 Bus Device Driver)
0xF6C14000 C:\WINDOWS\system32\DRIVERS\WDFLDR.SYS 57344 bytes (Microsoft Corporation, Kernel Mode Driver Framework Loader)
0xF757C000 C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS 53248 bytes (Microsoft Corporation, SCSI Class System Dll)
0xF6C94000 C:\WINDOWS\system32\DRIVERS\i8042prt.sys 53248 bytes (Microsoft Corporation, i8042 Port Driver)
0xF6C84000 C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 53248 bytes (Microsoft Corporation, RAS L2TP mini-port/call-manager driver)
0xF755C000 VolSnap.sys 53248 bytes (Microsoft Corporation, Volume Shadow Copy Driver)
0xF6C44000 C:\WINDOWS\System32\Drivers\pcouffin.sys 49152 bytes (VSO Software, low level access layer for CD/DVD/BD devices)
0xF6C64000 C:\WINDOWS\system32\DRIVERS\raspptp.sys 49152 bytes (Microsoft Corporation, Peer-to-Peer Tunneling Protocol)
0xEE9F0000 C:\WINDOWS\System32\Drivers\Fips.SYS 45056 bytes (Microsoft Corporation, FIPS Crypto Driver)
0xF75CC000 C:\WINDOWS\system32\DRIVERS\imapi.sys 45056 bytes (Microsoft Corporation, IMAPI Kernel Driver)
0xF754C000 MountMgr.sys 45056 bytes (Microsoft Corporation, Mount Manager)
0xF6C74000 C:\WINDOWS\system32\DRIVERS\raspppoe.sys 45056 bytes (Microsoft Corporation, RAS PPPoE mini-port/call-manager driver)
0xF6C24000 C:\WINDOWS\system32\DRIVERS\zumbus.sys 45056 bytes (Microsoft Corporation, Zune User-Mode Bus Enumerator)
0xF753C000 isapnp.sys 40960 bytes (Microsoft Corporation, PNP ISA Bus Driver)
0xF68B8000 C:\WINDOWS\System32\Drivers\NDProxy.SYS 40960 bytes (Microsoft Corporation, NDIS Proxy)
0xF6C34000 C:\WINDOWS\system32\DRIVERS\termdd.sys 40960 bytes (Microsoft Corporation, Terminal Server Driver)
0xB8173000 C:\DOCUME~1\JOHNMC~1\LOCALS~1\Temp\aswMBR.sys 36864 bytes
0xF756C000 disk.sys 36864 bytes (Microsoft Corporation, PnP Disk Driver)
0xF6C54000 C:\WINDOWS\system32\DRIVERS\msgpc.sys 36864 bytes (Microsoft Corporation, MS General Packet Classifier)
0xEEA00000 C:\WINDOWS\system32\DRIVERS\netbios.sys 36864 bytes (Microsoft Corporation, NetBIOS interface driver)
0xB820B000 C:\WINDOWS\System32\Drivers\Normandy.SYS 36864 bytes (RKU Driver)
0xF75BC000 C:\WINDOWS\system32\DRIVERS\processr.sys 36864 bytes (Microsoft Corporation, Processor Device Driver)
0xF758C000 PxHelp20.sys 36864 bytes (Sonic Solutions, Px Engine Device Driver for Windows 2000/XP)
0xEDE4A000 C:\WINDOWS\system32\DRIVERS\wanarp.sys 36864 bytes (Microsoft Corporation, MS Remote Access and Routing ARP Driver)
0xEE2CE000 C:\WINDOWS\System32\Drivers\Npfs.SYS 32768 bytes (Microsoft Corporation, NPFS Driver)
0xF7864000 C:\WINDOWS\system32\DRIVERS\usbehci.sys 32768 bytes (Microsoft Corporation, EHCI eUSB Miniport Driver)
0xF779C000 C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS 28672 bytes (Microsoft Corporation, PCI IDE Bus Driver Extension)
0xEE199000 C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 28672 bytes (Microsoft Corporation, USB Mass Storage Class Driver)
0xF786C000 C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 24576 bytes (GEAR Software Inc., CD DVD Filter)
0xF788C000 C:\WINDOWS\system32\DRIVERS\kbdclass.sys 24576 bytes (Microsoft Corporation, Keyboard Class Driver)
0xF787C000 C:\WINDOWS\system32\DRIVERS\mouclass.sys 24576 bytes (Microsoft Corporation, Mouse Class Driver)
0xF7874000 C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 24576 bytes (Realtek Semiconductor Corporation, Realtek RTL8139 NDIS 5.0 Driver)
0xEE2C6000 C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 24576 bytes (SUPERAdBlocker.com and SUPERAntiSpyware.com, SASDIFSV.SYS)
0xEE306000 C:\WINDOWS\System32\drivers\vga.sys 24576 bytes (Microsoft Corporation, VGA/Super VGA Video Driver)
0xEE2D6000 C:\WINDOWS\System32\Drivers\Msfs.SYS 20480 bytes (Microsoft Corporation, Mailslot driver)
0xF77A4000 PartMgr.sys 20480 bytes (Microsoft Corporation, Partition Manager)
0xF7884000 C:\WINDOWS\system32\DRIVERS\PS2.sys 20480 bytes (Hewlett-Packard Company, PS2 SYS)
0xF789C000 C:\WINDOWS\system32\DRIVERS\ptilink.sys 20480 bytes (Parallel Technologies, Inc., Parallel Technologies DirectParallel IO Library)
0xF78A4000 C:\WINDOWS\system32\DRIVERS\raspti.sys 20480 bytes (Microsoft Corporation, PTI DirectParallel® mini-port/call-manager driver)
0xF7894000 C:\WINDOWS\system32\DRIVERS\TDI.SYS 20480 bytes (Microsoft Corporation, TDI Wrapper)
0xF785C000 C:\WINDOWS\system32\DRIVERS\usbohci.sys 20480 bytes (Microsoft Corporation, OHCI USB Miniport Driver)
0xEE191000 C:\WINDOWS\System32\watchdog.sys 20480 bytes (Microsoft Corporation, Watchdog Driver)
0xEDF54000 C:\WINDOWS\System32\Drivers\ASPI32.SYS 16384 bytes (Adaptec, ASPI for WIN32 Kernel Driver)
0xF721E000 C:\WINDOWS\system32\DRIVERS\mssmbios.sys 16384 bytes (Microsoft Corporation, System Management BIOS Driver)
0xEC485000 C:\WINDOWS\system32\DRIVERS\ndisuio.sys 16384 bytes (Microsoft Corporation, NDIS User mode I/O Driver)
0xF7930000 C:\WINDOWS\system32\BOOTVID.dll 12288 bytes (Microsoft Corporation, VGA Boot Driver)
0xEE93C000 C:\WINDOWS\System32\drivers\Dxapi.sys 12288 bytes (Microsoft Corporation, DirectX API Driver)
0x84EE0000 C:\WINDOWS\system32\KDCOM.DLL 12288 bytes (Microsoft Corporation, Kernel Debugger HW Extension DLL)
0xF723A000 C:\WINDOWS\system32\DRIVERS\ndistapi.sys 12288 bytes (Microsoft Corporation, NDIS 3.0 connection wrapper driver)
0xEC475000 C:\WINDOWS\system32\DRIVERS\rasacd.sys 12288 bytes (Microsoft Corporation, RAS Automatic Connection Driver)
0xF7A92000 C:\WINDOWS\System32\Drivers\Beep.SYS 8192 bytes (Microsoft Corporation, BEEP Driver)
0xF7A1E000 dmload.sys 8192 bytes (Microsoft Corp., Veritas Software., NT Disk Manager Startup Driver)
0xF7ABA000 C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS 8192 bytes
0xF7A90000 C:\WINDOWS\System32\Drivers\Fs_Rec.SYS 8192 bytes (Microsoft Corporation, File System Recognizer Driver)
0xF7A94000 C:\WINDOWS\System32\Drivers\mnmdd.SYS 8192 bytes (Microsoft Corporation, Frame buffer simulator)
0xF7A7E000 C:\WINDOWS\System32\Drivers\ParVdm.SYS 8192 bytes (Microsoft Corporation, VDM Parallel Driver)
0xF7A96000 C:\WINDOWS\System32\DRIVERS\RDPCDD.sys 8192 bytes (Microsoft Corporation, RDP Miniport)
0xF7A5C000 C:\WINDOWS\system32\DRIVERS\swenum.sys 8192 bytes (Microsoft Corporation, Plug and Play Software Device Enumerator)
0xF7A64000 C:\WINDOWS\system32\DRIVERS\USBD.SYS 8192 bytes (Microsoft Corporation, Universal Serial Bus Driver)
0xF7A1C000 C:\WINDOWS\system32\DRIVERS\WMILIB.SYS 8192 bytes (Microsoft Corporation, WMILIB WMI support library Dll)
0xF7B43000 C:\WINDOWS\system32\DRIVERS\audstub.sys 4096 bytes (Microsoft Corporation, AudStub Driver)
0xF7BD3000 C:\WINDOWS\System32\Drivers\Cdr4_xp.SYS 4096 bytes (Sonic Solutions, CDR4 CD and DVD Place Holder Driver (see PxHelp))
0xEDEF3000 C:\WINDOWS\System32\Drivers\Cdralw2k.SYS 4096 bytes (Sonic Solutions, CDRAL Place Holder Driver (see PxHelp))
0xF7C5C000 C:\WINDOWS\System32\drivers\dxgthk.sys 4096 bytes (Microsoft Corporation, DirectX Graphics Driver Thunk)
0xEDEF2000 C:\WINDOWS\System32\Drivers\Null.SYS 4096 bytes (Microsoft Corporation, NULL Driver)
0xF7AE4000 pciide.sys 4096 bytes (Microsoft Corporation, Generic PCI IDE Bus Driver)
!!!!!!!!!!!Hidden driver: 0x84F2633B ?_empty_? 3269 bytes
==============================================
>Stealth
==============================================
0xF737F000 WARNING: suspicious driver modification [atapi.sys::0x84F2633B]

#4 heir

heir

  • Malware Response Team
  • 763 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:35 PM

Posted 21 April 2011 - 03:51 AM

Looks as there might be a Rootkit hiding in there.


We will begin with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Please include the C:\ComboFix.txt in your next reply for further review.

Please do not PM me asking for support. Post on the forums instead.
Please post the final results, good or bad. We like to know!
Posted Image
Unified Network of Instructors and Trained Eliminators
My help is always free, but if you want to donate to help me continue my fight against malware then click Posted Image


#5 johndepere

johndepere
  • Topic Starter

  • Members
  • 78 posts
  • OFFLINE
  •  
  • Local time:11:35 AM

Posted 21 April 2011 - 10:23 PM

Hello again, I have ran combo fix and included the results as per your request, also note that I did not have the recovery console installed as I do not have this computer on the net for obvious reasons, if this is a problem let me know and I will try to get it installed and run another scan. Thanks again for your help.


ComboFix 11-04-21.02 - John McMorrow 04/21/2011 21:45:14.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.446.124 [GMT -5:00]
Running from: c:\documents and settings\John McMorrow\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\John McMorrow\Application Data\Adobe\plugs
c:\documents and settings\John McMorrow\Application Data\Adobe\shed
c:\documents and settings\John McMorrow\Application Data\inst.exe
c:\documents and settings\John McMorrow\WINDOWS
c:\windows\system32\itlpfw32.dll
c:\windows\winhelp.ini
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ITLPERF
-------\Service_itlperf
.
.
((((((((((((((((((((((((( Files Created from 2011-03-22 to 2011-04-22 )))))))))))))))))))))))))))))))
.
.
2011-04-19 17:31 . 2011-04-19 17:31 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2011-04-19 16:40 . 2011-04-19 16:41 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Apple Computer
2011-04-19 16:40 . 2011-04-19 16:40 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2011-04-19 16:40 . 2011-04-19 16:40 -------- d-----w- c:\documents and settings\Default User\Application Data\Apple Computer
2011-04-19 16:37 . 2011-04-19 16:40 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\Apple Computer
2011-04-19 14:00 . 2011-04-19 14:04 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-04-18 14:35 . 2011-03-15 04:05 6792528 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{07033159-7E8E-4578-B8C5-DFD6B4BA0DCB}\mpengine.dll
2011-04-14 14:50 . 2011-04-14 14:50 828017 ----a-w- c:\documents and settings\All Users\SPL2B.tmp
2011-04-13 22:26 . 2011-04-13 22:26 1259362 ----a-w- c:\documents and settings\All Users\SPL1C3.tmp
2011-03-24 15:35 . 2011-03-24 15:35 -------- d-----w- c:\program files\iPod
2011-03-24 15:34 . 2011-03-24 15:36 -------- d-----w- c:\program files\iTunes
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-22 22:24 . 2011-03-22 22:24 1024297 ----a-w- c:\documents and settings\All Users\SPL17.tmp
2011-03-19 18:30 . 2011-03-19 18:30 1468106 ----a-w- c:\documents and settings\All Users\SPL24.tmp
2011-03-15 04:05 . 2011-01-03 02:29 6792528 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-03-07 05:33 . 2009-09-04 15:35 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:45 . 2006-02-28 12:00 434176 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2006-02-28 12:00 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-18 21:36 . 2010-01-26 18:49 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2011-02-18 21:36 . 2010-01-26 18:49 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2011-02-17 15:32 . 2010-02-02 03:51 398760 ----a-r- c:\windows\system32\cpnprt2.cid
2011-02-17 13:51 . 2006-02-28 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2011-02-17 13:51 . 2006-02-28 12:00 667136 ----a-w- c:\windows\system32\wininet.dll
2011-02-17 13:51 . 2006-02-28 12:00 61952 ----a-w- c:\windows\system32\tdc.ocx
2011-02-17 13:18 . 2006-02-28 12:00 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2006-02-28 12:00 357888 ----a-w- c:\windows\system32\drivers\srv.sys
2011-02-17 12:37 . 2006-02-28 12:00 369664 ----a-w- c:\windows\system32\html.iec
2011-02-17 12:32 . 2009-09-09 05:18 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56 . 2006-02-28 12:00 290432 ----a-w- c:\windows\system32\atmfd.dll
2011-02-09 13:53 . 2006-02-28 12:00 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2006-02-28 12:00 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33 . 2006-02-28 12:00 978944 ----a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33 . 2006-02-28 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2011-02-02 07:58 . 2009-09-04 15:33 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2009-09-04 15:33 677888 ----a-w- c:\windows\system32\mstsc.exe
2009-09-05 00:01 . 2009-09-05 00:01 525656 ----a-w- c:\program files\DXSETUP.exe
2009-09-05 00:01 . 2009-09-05 00:01 94024 ----a-w- c:\program files\DSETUP.dll
2009-09-05 00:01 . 2009-09-05 00:01 1691464 ----a-w- c:\program files\dsetup32.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-14 344064]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="userinit.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 20:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ImageMixer HDD Camera Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ImageMixer HDD Camera Monitor.lnk
backup=c:\windows\pss\ImageMixer HDD Camera Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office Fast Start.lnk
backup=c:\windows\pss\Microsoft Office Fast Start.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office Shortcut Bar.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office Shortcut Bar.lnk
backup=c:\windows\pss\Microsoft Office Shortcut Bar.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^John McMorrow^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\John McMorrow\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^John McMorrow^Start Menu^Programs^Startup^MagicDisc.lnk]
path=c:\documents and settings\John McMorrow\Start Menu\Programs\Startup\MagicDisc.lnk
backup=c:\windows\pss\MagicDisc.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 18:37 932288 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-22 05:05 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
2004-09-07 18:47 57344 ----a-w- c:\windows\ALCXMNTR.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDRegion]
2009-05-08 02:05 75048 ----a-w- c:\program files\CyberLink\Shared files\brs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-06-28 01:03 152872 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-03-07 20:33 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 5000 Series Fax Server]
2007-07-06 16:54 307888 ----a-w- c:\program files\Lexmark 5000 Series\fm3032.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdmamon]
2007-06-01 20:06 20480 ----a-w- c:\program files\Lexmark 5000 Series\lxdmamon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdmmon.exe]
2007-07-06 16:53 455344 ----a-w- c:\program files\Lexmark 5000 Series\lxdmmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MegaPanel]
2009-12-11 17:17 2113536 ----a-w- c:\program files\National Consumer Panel\NCP Internet Transporter\HSTrans.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 21:57 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVD9LanguageShortcut]
2009-04-27 22:50 50472 ------w- c:\program files\CyberLink\PowerDVD9\Language\Language.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
2009-02-05 03:26 128232 ------w- c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 22:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl9]
2009-04-28 01:41 87336 ------w- c:\program files\CyberLink\PowerDVD9\PDVD9Serv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-09-05 00:44 2424560 ----a-w- c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2010-05-17 01:28 322352 ----a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]
2010-11-11 19:55 159472 ----a-w- c:\documents and settings\John McMorrow\My Documents\My Music\Zune setup\ZuneLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Abbyy FineReader 6.0 Sprint\\Scan\\ScanMan6.exe"=
"c:\\Program Files\\Lexmark 5000 Series\\LXDMFax.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\WINDOWS\\system32\\lxdmcoms.exe"=
"c:\\Program Files\\Lexmark 5000 Series\\lxdmamon.exe"=
"c:\\Program Files\\Lexmark 5000 Series\\FRun.exe"=
"c:\\Program Files\\Lexmark 5000 Series\\lxdmmon.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdmpswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdmtime.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdmwbgw.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdmjswx.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [9/15/2009 11:42 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [9/15/2009 11:42 AM 67656]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2009/09/18 00:44];c:\program files\CyberLink\PowerDVD9\000.fcl [5/7/2009 9:05 PM 87536]
S0 ntcdrdrv;ntcdrdrv;c:\windows\system32\DRIVERS\ntcdrdrv.sys --> c:\windows\system32\DRIVERS\ntcdrdrv.sys [?]
S1 MpKsl0f010b74;MpKsl0f010b74;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{05EFDDD2-377B-443B-9E6F-A55A89E59D92}\MpKsl0f010b74.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{05EFDDD2-377B-443B-9E6F-A55A89E59D92}\MpKsl0f010b74.sys [?]
S1 MpKsl2ca5a098;MpKsl2ca5a098;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{17D1583A-45E9-4462-90A3-5022B04D0192}\MpKsl2ca5a098.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{17D1583A-45E9-4462-90A3-5022B04D0192}\MpKsl2ca5a098.sys [?]
S1 MpKsl386d0aff;MpKsl386d0aff;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C5250355-FFA8-4DCE-9E30-D12D05CBD3C9}\MpKsl386d0aff.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C5250355-FFA8-4DCE-9E30-D12D05CBD3C9}\MpKsl386d0aff.sys [?]
S1 MpKsl44ecdc4d;MpKsl44ecdc4d;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A920423C-8F8E-47A3-A647-20EE1F0954BB}\MpKsl44ecdc4d.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A920423C-8F8E-47A3-A647-20EE1F0954BB}\MpKsl44ecdc4d.sys [?]
S1 MpKsl573beb85;MpKsl573beb85;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{96126FFA-B41D-4DAE-93C4-AC39F0035676}\MpKsl573beb85.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{96126FFA-B41D-4DAE-93C4-AC39F0035676}\MpKsl573beb85.sys [?]
S1 MpKsl57f88940;MpKsl57f88940;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{ACB91A84-5D2F-479F-8A82-0CF2BCED48B4}\MpKsl57f88940.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{ACB91A84-5D2F-479F-8A82-0CF2BCED48B4}\MpKsl57f88940.sys [?]
S1 MpKsl5ce9a7e0;MpKsl5ce9a7e0;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5AC3A0D0-BCC8-4C21-B9F1-48546A9AE1AD}\MpKsl5ce9a7e0.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5AC3A0D0-BCC8-4C21-B9F1-48546A9AE1AD}\MpKsl5ce9a7e0.sys [?]
S1 MpKsl6d3e36a7;MpKsl6d3e36a7;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{483DF6FF-94ED-444E-A31B-1AC1E63C4FCE}\MpKsl6d3e36a7.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{483DF6FF-94ED-444E-A31B-1AC1E63C4FCE}\MpKsl6d3e36a7.sys [?]
S1 MpKsl7fab8f15;MpKsl7fab8f15;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A3C06146-8631-4444-8C49-FA3222EBAB45}\MpKsl7fab8f15.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A3C06146-8631-4444-8C49-FA3222EBAB45}\MpKsl7fab8f15.sys [?]
S1 MpKsl90b7953a;MpKsl90b7953a;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{38695DD5-4322-4CD2-8868-16E1CC83BA98}\MpKsl90b7953a.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{38695DD5-4322-4CD2-8868-16E1CC83BA98}\MpKsl90b7953a.sys [?]
S1 MpKsl9c090978;MpKsl9c090978;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CF3E1280-75A0-4247-A391-41C2FA66F8D8}\MpKsl9c090978.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CF3E1280-75A0-4247-A391-41C2FA66F8D8}\MpKsl9c090978.sys [?]
S1 MpKslb233c61c;MpKslb233c61c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C49B6202-872C-49A1-B3AC-80DF48D147C1}\MpKslb233c61c.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C49B6202-872C-49A1-B3AC-80DF48D147C1}\MpKslb233c61c.sys [?]
S1 MpKslcf7307b5;MpKslcf7307b5;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{07033159-7E8E-4578-B8C5-DFD6B4BA0DCB}\MpKslcf7307b5.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{07033159-7E8E-4578-B8C5-DFD6B4BA0DCB}\MpKslcf7307b5.sys [?]
S1 MpKsle97056d8;MpKsle97056d8;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{67AFDF85-A406-4D38-ACA9-88E2FEFE3D99}\MpKsle97056d8.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{67AFDF85-A406-4D38-ACA9-88E2FEFE3D99}\MpKsle97056d8.sys [?]
S1 MpKslecaad8aa;MpKslecaad8aa;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DC697F2D-22F8-4C81-AC4B-C813BA0EEEBA}\MpKslecaad8aa.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DC697F2D-22F8-4C81-AC4B-C813BA0EEEBA}\MpKslecaad8aa.sys [?]
S1 MpKslf3d9a833;MpKslf3d9a833;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1E67ED45-A757-48FB-A32B-B1D28D7E161A}\MpKslf3d9a833.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1E67ED45-A757-48FB-A32B-B1D28D7E161A}\MpKslf3d9a833.sys [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/15/2009 11:42 AM 12872]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\documents and settings\John McMorrow\My Documents\My Music\Zune setup\WMZuneComm.exe [11/11/2010 2:57 PM 268528]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5/5/2010 2:52 PM 691696]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
itlsvc REG_MULTI_SZ itlperf
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
.
2011-04-22 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 18:26]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/?rs=1
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\John McMorrow\Application Data\Mozilla\Firefox\Profiles\b8nbdsit.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2645238&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - ZoneAlarm Security Customized Web Search
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - prefs.js: keyword.URL - hxxps://www.mypoints.com/emp/u/mysearch.vm?st=mypWeb&fctb.dns=1&q=
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - c:\program files\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Swag Bucks Community Toolbar: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - %profile%\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - user.js: yahoo.homepage.dontask - true
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-ISW - c:\program files\CheckPoint\ZAForceField\ForceField.exe
MSConfigStartUp-TkBellExe - c:\program files\Common Files\Real\Update_OB\realsched.exe
AddRemove-Pixar's Monsters, Inc. Scare Island - c:\progra~1\DISNEY~1\MONSTE~1\DeIsL1.isu
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-21 21:57
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: Maxtor_6L200M0 rev.BANC1G10 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x84F1633B
user & kernel MBR OK
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\{B154377D-700F-42cc-9474-23858FBDF4BD}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD9\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1935655697-436374069-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(556)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(2764)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\lxdmcoms.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\documents and settings\John McMorrow\My Documents\My Music\Zune setup\ZuneBusEnum.exe
.
**************************************************************************
.
Completion time: 2011-04-21 22:04:04 - machine was rebooted
ComboFix-quarantined-files.txt 2011-04-22 03:03
.
Pre-Run: 16,903,360,512 bytes free
Post-Run: 17,265,324,032 bytes free
.
- - End Of File - - 8FBB48F912EC2FB8C922AE29666C72F7

#6 heir

heir

  • Malware Response Team
  • 763 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:35 PM

Posted 22 April 2011 - 04:51 AM

Hello again, I have ran combo fix and included the results as per your request, also note that I did not have the recovery console installed as I do not have this computer on the net for obvious reasons.

In this case it would have been OK.

As you don't have it connected to Internet I assume you transfer files to the computer using a flashdrive. This can result in that you infect other computers as some malware travels with flashdrives.

If you do this you need to protect you from it.

Do this fro your other "clean computer".

Download Flash_Disinfector.exe by sUBs from >here< and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection.


Now we'll install the Recovery console offline.

Download the tools needed to a flash drive or other removable media, and transfer them to the infected computer.


With malware infections being as they are today, it's strongly recommended to have the Windows Recovery Console pre-installed on your machine before doing any malware removal.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.


Go to Microsoft's website => http://support.microsoft.com/kb/310994

Scroll down to Step 1, and select the download that's appropriate for your Operating System. Download the file & save it as it's originally named.

Note: If you have SP3, use the SP2 package.


---------------------------------------------------------------------

Transfer all files you just downloaded, to the desktop of the infected computer.

--------------------------------------------------------------------


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

Posted Image


  • Drag the setup package onto ComboFix.exe and drop it.

  • Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console.


    Posted Image


  • At the next prompt, click 'Yes' to run the full ComboFix scan.

  • When the tool is finished, it will produce a report for you.
Please post the C:\ComboFix.txt in your next reply.

Please do not PM me asking for support. Post on the forums instead.
Please post the final results, good or bad. We like to know!
Posted Image
Unified Network of Instructors and Trained Eliminators
My help is always free, but if you want to donate to help me continue my fight against malware then click Posted Image


#7 johndepere

johndepere
  • Topic Starter

  • Members
  • 78 posts
  • OFFLINE
  •  
  • Local time:11:35 AM

Posted 22 April 2011 - 11:36 AM

Heir, I apologize for not having the recovery console installed prior to my last post (I did not think it was that important,and I guess I was just being lazy). At any rate it is installed now and have ran another combofix scan and included it it my reply. Thank You! John.



ComboFix 11-04-21.02 - John McMorrow 04/22/2011 11:00:51.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.446.228 [GMT -5:00]
Running from: c:\documents and settings\John McMorrow\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((( Files Created from 2011-03-22 to 2011-04-22 )))))))))))))))))))))))))))))))
.
.
2011-04-19 17:31 . 2011-04-19 17:31 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2011-04-19 16:40 . 2011-04-19 16:41 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Apple Computer
2011-04-19 16:40 . 2011-04-19 16:40 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2011-04-19 16:40 . 2011-04-19 16:40 -------- d-----w- c:\documents and settings\Default User\Application Data\Apple Computer
2011-04-19 16:37 . 2011-04-19 16:40 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\Apple Computer
2011-04-19 14:00 . 2011-04-19 14:04 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-04-18 14:35 . 2011-03-15 04:05 6792528 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{07033159-7E8E-4578-B8C5-DFD6B4BA0DCB}\mpengine.dll
2011-04-14 14:50 . 2011-04-14 14:50 828017 ----a-w- c:\documents and settings\All Users\SPL2B.tmp
2011-04-13 22:26 . 2011-04-13 22:26 1259362 ----a-w- c:\documents and settings\All Users\SPL1C3.tmp
2011-03-24 15:35 . 2011-03-24 15:35 -------- d-----w- c:\program files\iPod
2011-03-24 15:34 . 2011-03-24 15:36 -------- d-----w- c:\program files\iTunes
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-22 22:24 . 2011-03-22 22:24 1024297 ----a-w- c:\documents and settings\All Users\SPL17.tmp
2011-03-19 18:30 . 2011-03-19 18:30 1468106 ----a-w- c:\documents and settings\All Users\SPL24.tmp
2011-03-15 04:05 . 2011-01-03 02:29 6792528 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-03-07 05:33 . 2009-09-04 15:35 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:45 . 2006-02-28 12:00 434176 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2006-02-28 12:00 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-18 21:36 . 2010-01-26 18:49 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2011-02-18 21:36 . 2010-01-26 18:49 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2011-02-17 15:32 . 2010-02-02 03:51 398760 ----a-r- c:\windows\system32\cpnprt2.cid
2011-02-17 13:51 . 2006-02-28 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2011-02-17 13:51 . 2006-02-28 12:00 667136 ----a-w- c:\windows\system32\wininet.dll
2011-02-17 13:51 . 2006-02-28 12:00 61952 ----a-w- c:\windows\system32\tdc.ocx
2011-02-17 13:18 . 2006-02-28 12:00 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2006-02-28 12:00 357888 ----a-w- c:\windows\system32\drivers\srv.sys
2011-02-17 12:37 . 2006-02-28 12:00 369664 ----a-w- c:\windows\system32\html.iec
2011-02-17 12:32 . 2009-09-09 05:18 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56 . 2006-02-28 12:00 290432 ----a-w- c:\windows\system32\atmfd.dll
2011-02-09 13:53 . 2006-02-28 12:00 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2006-02-28 12:00 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33 . 2006-02-28 12:00 978944 ----a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33 . 2006-02-28 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2011-02-02 07:58 . 2009-09-04 15:33 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2009-09-04 15:33 677888 ----a-w- c:\windows\system32\mstsc.exe
2009-09-05 00:01 . 2009-09-05 00:01 525656 ----a-w- c:\program files\DXSETUP.exe
2009-09-05 00:01 . 2009-09-05 00:01 94024 ----a-w- c:\program files\DSETUP.dll
2009-09-05 00:01 . 2009-09-05 00:01 1691464 ----a-w- c:\program files\dsetup32.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-14 344064]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 20:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ImageMixer HDD Camera Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ImageMixer HDD Camera Monitor.lnk
backup=c:\windows\pss\ImageMixer HDD Camera Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office Fast Start.lnk
backup=c:\windows\pss\Microsoft Office Fast Start.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office Shortcut Bar.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office Shortcut Bar.lnk
backup=c:\windows\pss\Microsoft Office Shortcut Bar.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^John McMorrow^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\John McMorrow\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^John McMorrow^Start Menu^Programs^Startup^MagicDisc.lnk]
path=c:\documents and settings\John McMorrow\Start Menu\Programs\Startup\MagicDisc.lnk
backup=c:\windows\pss\MagicDisc.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 18:37 932288 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-22 05:05 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
2004-09-07 18:47 57344 ----a-w- c:\windows\ALCXMNTR.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDRegion]
2009-05-08 02:05 75048 ----a-w- c:\program files\CyberLink\Shared files\brs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-06-28 01:03 152872 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-03-07 20:33 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 5000 Series Fax Server]
2007-07-06 16:54 307888 ----a-w- c:\program files\Lexmark 5000 Series\fm3032.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdmamon]
2007-06-01 20:06 20480 ----a-w- c:\program files\Lexmark 5000 Series\lxdmamon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdmmon.exe]
2007-07-06 16:53 455344 ----a-w- c:\program files\Lexmark 5000 Series\lxdmmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MegaPanel]
2009-12-11 17:17 2113536 ----a-w- c:\program files\National Consumer Panel\NCP Internet Transporter\HSTrans.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 21:57 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVD9LanguageShortcut]
2009-04-27 22:50 50472 ------w- c:\program files\CyberLink\PowerDVD9\Language\Language.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
2009-02-05 03:26 128232 ------w- c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 22:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl9]
2009-04-28 01:41 87336 ------w- c:\program files\CyberLink\PowerDVD9\PDVD9Serv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-09-05 00:44 2424560 ----a-w- c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2010-05-17 01:28 322352 ----a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]
2010-11-11 19:55 159472 ----a-w- c:\documents and settings\John McMorrow\My Documents\My Music\Zune setup\ZuneLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Abbyy FineReader 6.0 Sprint\\Scan\\ScanMan6.exe"=
"c:\\Program Files\\Lexmark 5000 Series\\LXDMFax.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\WINDOWS\\system32\\lxdmcoms.exe"=
"c:\\Program Files\\Lexmark 5000 Series\\lxdmamon.exe"=
"c:\\Program Files\\Lexmark 5000 Series\\FRun.exe"=
"c:\\Program Files\\Lexmark 5000 Series\\lxdmmon.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdmpswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdmtime.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdmwbgw.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdmjswx.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [9/15/2009 11:42 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [9/15/2009 11:42 AM 67656]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2009/09/18 00:44];c:\program files\CyberLink\PowerDVD9\000.fcl [5/7/2009 9:05 PM 87536]
S0 ntcdrdrv;ntcdrdrv;c:\windows\system32\DRIVERS\ntcdrdrv.sys --> c:\windows\system32\DRIVERS\ntcdrdrv.sys [?]
S1 MpKsl0f010b74;MpKsl0f010b74;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{05EFDDD2-377B-443B-9E6F-A55A89E59D92}\MpKsl0f010b74.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{05EFDDD2-377B-443B-9E6F-A55A89E59D92}\MpKsl0f010b74.sys [?]
S1 MpKsl2ca5a098;MpKsl2ca5a098;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{17D1583A-45E9-4462-90A3-5022B04D0192}\MpKsl2ca5a098.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{17D1583A-45E9-4462-90A3-5022B04D0192}\MpKsl2ca5a098.sys [?]
S1 MpKsl386d0aff;MpKsl386d0aff;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C5250355-FFA8-4DCE-9E30-D12D05CBD3C9}\MpKsl386d0aff.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C5250355-FFA8-4DCE-9E30-D12D05CBD3C9}\MpKsl386d0aff.sys [?]
S1 MpKsl44ecdc4d;MpKsl44ecdc4d;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A920423C-8F8E-47A3-A647-20EE1F0954BB}\MpKsl44ecdc4d.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A920423C-8F8E-47A3-A647-20EE1F0954BB}\MpKsl44ecdc4d.sys [?]
S1 MpKsl573beb85;MpKsl573beb85;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{96126FFA-B41D-4DAE-93C4-AC39F0035676}\MpKsl573beb85.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{96126FFA-B41D-4DAE-93C4-AC39F0035676}\MpKsl573beb85.sys [?]
S1 MpKsl57f88940;MpKsl57f88940;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{ACB91A84-5D2F-479F-8A82-0CF2BCED48B4}\MpKsl57f88940.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{ACB91A84-5D2F-479F-8A82-0CF2BCED48B4}\MpKsl57f88940.sys [?]
S1 MpKsl5ce9a7e0;MpKsl5ce9a7e0;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5AC3A0D0-BCC8-4C21-B9F1-48546A9AE1AD}\MpKsl5ce9a7e0.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5AC3A0D0-BCC8-4C21-B9F1-48546A9AE1AD}\MpKsl5ce9a7e0.sys [?]
S1 MpKsl6d3e36a7;MpKsl6d3e36a7;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{483DF6FF-94ED-444E-A31B-1AC1E63C4FCE}\MpKsl6d3e36a7.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{483DF6FF-94ED-444E-A31B-1AC1E63C4FCE}\MpKsl6d3e36a7.sys [?]
S1 MpKsl7fab8f15;MpKsl7fab8f15;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A3C06146-8631-4444-8C49-FA3222EBAB45}\MpKsl7fab8f15.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A3C06146-8631-4444-8C49-FA3222EBAB45}\MpKsl7fab8f15.sys [?]
S1 MpKsl90b7953a;MpKsl90b7953a;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{38695DD5-4322-4CD2-8868-16E1CC83BA98}\MpKsl90b7953a.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{38695DD5-4322-4CD2-8868-16E1CC83BA98}\MpKsl90b7953a.sys [?]
S1 MpKsl9c090978;MpKsl9c090978;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CF3E1280-75A0-4247-A391-41C2FA66F8D8}\MpKsl9c090978.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CF3E1280-75A0-4247-A391-41C2FA66F8D8}\MpKsl9c090978.sys [?]
S1 MpKslb233c61c;MpKslb233c61c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C49B6202-872C-49A1-B3AC-80DF48D147C1}\MpKslb233c61c.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C49B6202-872C-49A1-B3AC-80DF48D147C1}\MpKslb233c61c.sys [?]
S1 MpKslcf7307b5;MpKslcf7307b5;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{07033159-7E8E-4578-B8C5-DFD6B4BA0DCB}\MpKslcf7307b5.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{07033159-7E8E-4578-B8C5-DFD6B4BA0DCB}\MpKslcf7307b5.sys [?]
S1 MpKsle97056d8;MpKsle97056d8;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{67AFDF85-A406-4D38-ACA9-88E2FEFE3D99}\MpKsle97056d8.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{67AFDF85-A406-4D38-ACA9-88E2FEFE3D99}\MpKsle97056d8.sys [?]
S1 MpKslecaad8aa;MpKslecaad8aa;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DC697F2D-22F8-4C81-AC4B-C813BA0EEEBA}\MpKslecaad8aa.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DC697F2D-22F8-4C81-AC4B-C813BA0EEEBA}\MpKslecaad8aa.sys [?]
S1 MpKslf3d9a833;MpKslf3d9a833;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1E67ED45-A757-48FB-A32B-B1D28D7E161A}\MpKslf3d9a833.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1E67ED45-A757-48FB-A32B-B1D28D7E161A}\MpKslf3d9a833.sys [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/15/2009 11:42 AM 12872]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\documents and settings\John McMorrow\My Documents\My Music\Zune setup\WMZuneComm.exe [11/11/2010 2:57 PM 268528]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5/5/2010 2:52 PM 691696]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
itlsvc REG_MULTI_SZ itlperf
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
.
2011-04-22 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 18:26]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/?rs=1
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\John McMorrow\Application Data\Mozilla\Firefox\Profiles\b8nbdsit.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2645238&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - ZoneAlarm Security Customized Web Search
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - prefs.js: keyword.URL - hxxps://www.mypoints.com/emp/u/mysearch.vm?st=mypWeb&fctb.dns=1&q=
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - c:\program files\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Swag Bucks Community Toolbar: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - %profile%\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - user.js: yahoo.homepage.dontask - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-22 11:10
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: Maxtor_6L200M0 rev.BANC1G10 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x84F4E33B
user & kernel MBR OK
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\{B154377D-700F-42cc-9474-23858FBDF4BD}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD9\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1935655697-436374069-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(560)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3752)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-04-22 11:13:28
ComboFix-quarantined-files.txt 2011-04-22 16:13
ComboFix2.txt 2011-04-22 03:04
.
Pre-Run: 17,013,116,928 bytes free
Post-Run: 17,049,837,568 bytes free
.
- - End Of File - - F901EACD680497798F15FE56580BDADB

#8 heir

heir

  • Malware Response Team
  • 763 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:35 PM

Posted 22 April 2011 - 03:43 PM

It reports that there is a device attached to your computer that's not functioning. Do you have a device attached that doesn't work?


Step 1.
Uninstall unwanted software:

Please go to Start > Control Panel > Add/Remove Programs and remove the following (if present):

µTorrent

Optional removals
µTorrent and P2P programs in general are legal themselves, but much of the content downloaded with them is downloaded illegally. They are also a great way to infect yourself with malware.
It's up to you if you want to remove the above programs, however I recommend you do.


Step 2.
CFScript:

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the codebox below into it:

File::
File::
c:\documents and settings\All Users\SPL2B.tmp
c:\documents and settings\All Users\SPL1C3.tmp
c:\documents and settings\All Users\SPL17.tmp
c:\documents and settings\All Users\SPL24.tmp
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000000
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\uTorrent\\uTorrent.exe"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
"itlsvc"=-

Save this as CFScript.txt, in the same location as ComboFix.exe


Posted Image

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.



Step 3.
Things I would like to see in your reply:

  • Which programs were uninstalled in step 1.
  • The content of C:\ComboFix.txt from step 2.
  • Information on how your computer is running now.

Please do not PM me asking for support. Post on the forums instead.
Please post the final results, good or bad. We like to know!
Posted Image
Unified Network of Instructors and Trained Eliminators
My help is always free, but if you want to donate to help me continue my fight against malware then click Posted Image


#9 johndepere

johndepere
  • Topic Starter

  • Members
  • 78 posts
  • OFFLINE
  •  
  • Local time:11:35 AM

Posted 23 April 2011 - 06:05 PM

Hello Heir,
I have deleted u torrent as per your request and ran combo fix with the attached txt. file and included the log. After this repair my browser is still slow and getting locked up, I am also getting this "mevio movie" page which I assume is an infection of some sort. Thanks again for your help. John.



ComboFix 11-04-21.02 - John McMorrow 04/23/2011 7:08.4.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.446.149 [GMT -5:00]
Running from: c:\documents and settings\John McMorrow\Desktop\ComboFix.exe
Command switches used :: J:\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((( Files Created from 2011-03-23 to 2011-04-23 )))))))))))))))))))))))))))))))
.
.
2011-04-19 17:31 . 2011-04-19 17:31 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2011-04-19 16:40 . 2011-04-19 16:41 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Apple Computer
2011-04-19 16:40 . 2011-04-19 16:40 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2011-04-19 16:40 . 2011-04-19 16:40 -------- d-----w- c:\documents and settings\Default User\Application Data\Apple Computer
2011-04-19 16:37 . 2011-04-19 16:40 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\Apple Computer
2011-04-19 14:00 . 2011-04-19 14:04 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-04-18 14:35 . 2011-03-15 04:05 6792528 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{07033159-7E8E-4578-B8C5-DFD6B4BA0DCB}\mpengine.dll
2011-04-14 14:50 . 2011-04-14 14:50 828017 ----a-w- c:\documents and settings\All Users\SPL2B.tmp
2011-04-13 22:26 . 2011-04-13 22:26 1259362 ----a-w- c:\documents and settings\All Users\SPL1C3.tmp
2011-03-24 15:35 . 2011-03-24 15:35 -------- d-----w- c:\program files\iPod
2011-03-24 15:34 . 2011-03-24 15:36 -------- d-----w- c:\program files\iTunes
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-22 22:24 . 2011-03-22 22:24 1024297 ----a-w- c:\documents and settings\All Users\SPL17.tmp
2011-03-19 18:30 . 2011-03-19 18:30 1468106 ----a-w- c:\documents and settings\All Users\SPL24.tmp
2011-03-15 04:05 . 2011-01-03 02:29 6792528 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-03-07 05:33 . 2009-09-04 15:35 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:45 . 2006-02-28 12:00 434176 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2006-02-28 12:00 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-18 21:36 . 2010-01-26 18:49 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2011-02-18 21:36 . 2010-01-26 18:49 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2011-02-17 15:32 . 2010-02-02 03:51 398760 ----a-r- c:\windows\system32\cpnprt2.cid
2011-02-17 13:51 . 2006-02-28 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2011-02-17 13:51 . 2006-02-28 12:00 667136 ----a-w- c:\windows\system32\wininet.dll
2011-02-17 13:51 . 2006-02-28 12:00 61952 ----a-w- c:\windows\system32\tdc.ocx
2011-02-17 13:18 . 2006-02-28 12:00 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2006-02-28 12:00 357888 ----a-w- c:\windows\system32\drivers\srv.sys
2011-02-17 12:37 . 2006-02-28 12:00 369664 ----a-w- c:\windows\system32\html.iec
2011-02-17 12:32 . 2009-09-09 05:18 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56 . 2006-02-28 12:00 290432 ----a-w- c:\windows\system32\atmfd.dll
2011-02-09 13:53 . 2006-02-28 12:00 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2006-02-28 12:00 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33 . 2006-02-28 12:00 978944 ----a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33 . 2006-02-28 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2011-02-02 07:58 . 2009-09-04 15:33 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2009-09-04 15:33 677888 ----a-w- c:\windows\system32\mstsc.exe
2009-09-05 00:01 . 2009-09-05 00:01 525656 ----a-w- c:\program files\DXSETUP.exe
2009-09-05 00:01 . 2009-09-05 00:01 94024 ----a-w- c:\program files\DSETUP.dll
2009-09-05 00:01 . 2009-09-05 00:01 1691464 ----a-w- c:\program files\dsetup32.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-04-22_15.37.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-04-23 12:01 . 2011-04-23 12:01 16384 c:\windows\Temp\Perflib_Perfdata_704.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-14 344064]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 20:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ImageMixer HDD Camera Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ImageMixer HDD Camera Monitor.lnk
backup=c:\windows\pss\ImageMixer HDD Camera Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office Fast Start.lnk
backup=c:\windows\pss\Microsoft Office Fast Start.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office Shortcut Bar.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office Shortcut Bar.lnk
backup=c:\windows\pss\Microsoft Office Shortcut Bar.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^John McMorrow^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\John McMorrow\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^John McMorrow^Start Menu^Programs^Startup^MagicDisc.lnk]
path=c:\documents and settings\John McMorrow\Start Menu\Programs\Startup\MagicDisc.lnk
backup=c:\windows\pss\MagicDisc.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 18:37 932288 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-22 05:05 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
2004-09-07 18:47 57344 ----a-w- c:\windows\ALCXMNTR.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDRegion]
2009-05-08 02:05 75048 ----a-w- c:\program files\CyberLink\Shared files\brs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-06-28 01:03 152872 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-03-07 20:33 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark 5000 Series Fax Server]
2007-07-06 16:54 307888 ----a-w- c:\program files\Lexmark 5000 Series\fm3032.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdmamon]
2007-06-01 20:06 20480 ----a-w- c:\program files\Lexmark 5000 Series\lxdmamon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdmmon.exe]
2007-07-06 16:53 455344 ----a-w- c:\program files\Lexmark 5000 Series\lxdmmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MegaPanel]
2009-12-11 17:17 2113536 ----a-w- c:\program files\National Consumer Panel\NCP Internet Transporter\HSTrans.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 21:57 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVD9LanguageShortcut]
2009-04-27 22:50 50472 ------w- c:\program files\CyberLink\PowerDVD9\Language\Language.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
2009-02-05 03:26 128232 ------w- c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 22:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl9]
2009-04-28 01:41 87336 ------w- c:\program files\CyberLink\PowerDVD9\PDVD9Serv.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-09-05 00:44 2424560 ----a-w- c:\program files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]
2010-11-11 19:55 159472 ----a-w- c:\documents and settings\John McMorrow\My Documents\My Music\Zune setup\ZuneLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Abbyy FineReader 6.0 Sprint\\Scan\\ScanMan6.exe"=
"c:\\Program Files\\Lexmark 5000 Series\\LXDMFax.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\WINDOWS\\system32\\lxdmcoms.exe"=
"c:\\Program Files\\Lexmark 5000 Series\\lxdmamon.exe"=
"c:\\Program Files\\Lexmark 5000 Series\\FRun.exe"=
"c:\\Program Files\\Lexmark 5000 Series\\lxdmmon.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdmpswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdmtime.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdmwbgw.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdmjswx.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [9/15/2009 11:42 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [9/15/2009 11:42 AM 67656]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2009/09/18 00:44];c:\program files\CyberLink\PowerDVD9\000.fcl [5/7/2009 9:05 PM 87536]
S0 ntcdrdrv;ntcdrdrv;c:\windows\system32\DRIVERS\ntcdrdrv.sys --> c:\windows\system32\DRIVERS\ntcdrdrv.sys [?]
S1 MpKsl0f010b74;MpKsl0f010b74;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{05EFDDD2-377B-443B-9E6F-A55A89E59D92}\MpKsl0f010b74.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{05EFDDD2-377B-443B-9E6F-A55A89E59D92}\MpKsl0f010b74.sys [?]
S1 MpKsl2ca5a098;MpKsl2ca5a098;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{17D1583A-45E9-4462-90A3-5022B04D0192}\MpKsl2ca5a098.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{17D1583A-45E9-4462-90A3-5022B04D0192}\MpKsl2ca5a098.sys [?]
S1 MpKsl386d0aff;MpKsl386d0aff;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C5250355-FFA8-4DCE-9E30-D12D05CBD3C9}\MpKsl386d0aff.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C5250355-FFA8-4DCE-9E30-D12D05CBD3C9}\MpKsl386d0aff.sys [?]
S1 MpKsl44ecdc4d;MpKsl44ecdc4d;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A920423C-8F8E-47A3-A647-20EE1F0954BB}\MpKsl44ecdc4d.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A920423C-8F8E-47A3-A647-20EE1F0954BB}\MpKsl44ecdc4d.sys [?]
S1 MpKsl573beb85;MpKsl573beb85;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{96126FFA-B41D-4DAE-93C4-AC39F0035676}\MpKsl573beb85.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{96126FFA-B41D-4DAE-93C4-AC39F0035676}\MpKsl573beb85.sys [?]
S1 MpKsl57f88940;MpKsl57f88940;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{ACB91A84-5D2F-479F-8A82-0CF2BCED48B4}\MpKsl57f88940.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{ACB91A84-5D2F-479F-8A82-0CF2BCED48B4}\MpKsl57f88940.sys [?]
S1 MpKsl5ce9a7e0;MpKsl5ce9a7e0;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5AC3A0D0-BCC8-4C21-B9F1-48546A9AE1AD}\MpKsl5ce9a7e0.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5AC3A0D0-BCC8-4C21-B9F1-48546A9AE1AD}\MpKsl5ce9a7e0.sys [?]
S1 MpKsl6d3e36a7;MpKsl6d3e36a7;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{483DF6FF-94ED-444E-A31B-1AC1E63C4FCE}\MpKsl6d3e36a7.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{483DF6FF-94ED-444E-A31B-1AC1E63C4FCE}\MpKsl6d3e36a7.sys [?]
S1 MpKsl7fab8f15;MpKsl7fab8f15;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A3C06146-8631-4444-8C49-FA3222EBAB45}\MpKsl7fab8f15.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A3C06146-8631-4444-8C49-FA3222EBAB45}\MpKsl7fab8f15.sys [?]
S1 MpKsl90b7953a;MpKsl90b7953a;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{38695DD5-4322-4CD2-8868-16E1CC83BA98}\MpKsl90b7953a.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{38695DD5-4322-4CD2-8868-16E1CC83BA98}\MpKsl90b7953a.sys [?]
S1 MpKsl9c090978;MpKsl9c090978;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CF3E1280-75A0-4247-A391-41C2FA66F8D8}\MpKsl9c090978.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CF3E1280-75A0-4247-A391-41C2FA66F8D8}\MpKsl9c090978.sys [?]
S1 MpKslb233c61c;MpKslb233c61c;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C49B6202-872C-49A1-B3AC-80DF48D147C1}\MpKslb233c61c.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C49B6202-872C-49A1-B3AC-80DF48D147C1}\MpKslb233c61c.sys [?]
S1 MpKslcf7307b5;MpKslcf7307b5;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{07033159-7E8E-4578-B8C5-DFD6B4BA0DCB}\MpKslcf7307b5.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{07033159-7E8E-4578-B8C5-DFD6B4BA0DCB}\MpKslcf7307b5.sys [?]
S1 MpKsle97056d8;MpKsle97056d8;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{67AFDF85-A406-4D38-ACA9-88E2FEFE3D99}\MpKsle97056d8.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{67AFDF85-A406-4D38-ACA9-88E2FEFE3D99}\MpKsle97056d8.sys [?]
S1 MpKslecaad8aa;MpKslecaad8aa;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DC697F2D-22F8-4C81-AC4B-C813BA0EEEBA}\MpKslecaad8aa.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{DC697F2D-22F8-4C81-AC4B-C813BA0EEEBA}\MpKslecaad8aa.sys [?]
S1 MpKslf3d9a833;MpKslf3d9a833;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1E67ED45-A757-48FB-A32B-B1D28D7E161A}\MpKslf3d9a833.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1E67ED45-A757-48FB-A32B-B1D28D7E161A}\MpKslf3d9a833.sys [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/15/2009 11:42 AM 12872]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\documents and settings\John McMorrow\My Documents\My Music\Zune setup\WMZuneComm.exe [11/11/2010 2:57 PM 268528]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5/5/2010 2:52 PM 691696]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
itlsvc REG_MULTI_SZ itlperf
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
.
2011-04-23 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 18:26]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/?rs=1
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\John McMorrow\Application Data\Mozilla\Firefox\Profiles\b8nbdsit.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2645238&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - ZoneAlarm Security Customized Web Search
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - prefs.js: keyword.URL - hxxps://www.mypoints.com/emp/u/mysearch.vm?st=mypWeb&fctb.dns=1&q=
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - c:\program files\Mozilla Firefox\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Swag Bucks Community Toolbar: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - %profile%\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - Ext: Conduit Engine : engine@conduit.com - %profile%\extensions\engine@conduit.com
FF - user.js: yahoo.homepage.dontask - true
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-uTorrent - c:\program files\uTorrent\uTorrent.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-04-23 07:18
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: Maxtor_6L200M0 rev.BANC1G10 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x84F1733B
user & kernel MBR OK
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\{B154377D-700F-42cc-9474-23858FBDF4BD}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD9\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1935655697-436374069-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(556)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3716)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-04-23 07:21:13
ComboFix-quarantined-files.txt 2011-04-23 12:21
ComboFix2.txt 2011-04-22 16:13
ComboFix3.txt 2011-04-22 03:04
.
Pre-Run: 17,254,805,504 bytes free
Post-Run: 17,243,860,992 bytes free
.
- - End Of File - - 0C50D4CD7862C98547793FA7B0A12311

#10 johndepere

johndepere
  • Topic Starter

  • Members
  • 78 posts
  • OFFLINE
  •  
  • Local time:11:35 AM

Posted 23 April 2011 - 06:32 PM

Heir,
I also got this error message while online (generic host process for win 32 services encountered a problem), I don't know if it helps but thought I would let you know about it.

#11 heir

heir

  • Malware Response Team
  • 763 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:35 PM

Posted 24 April 2011 - 10:04 AM

After all I'm suspecting that you MBR is infected.


We need to create a bootable CD with MBRTool on it. Goto this page to find out about MBRTool

Download MBRTool.exe and save it to your desktop.
Double-click MBRTool.exe to install it.
When you click Finish at the end of the installation "MBRTool Boootable Media Builder" will start.

  • Put a blank CD in your CD-ROM.
  • Select create Boot CD/DVD
  • Click Go >>
  • The CD will be created.

Put the CD in the CD-ROM on the infected computer.
Reboot the infected computer from the CD

You will be presented with this menu.
Posted Image


Select the Command Prompt
Then type in - MBRTool.exe /bck /dsk:0 /sec:10



Posted Image



Power down the machine, remove the CD and boot back to normal mode.


Open notepad and copy/paste the text in the codebox below into it:

@ECHO OFF
MBR -c 0 1 MBR0.dat
MBR -c 9 1 MBR9.dat
CLS
FC.EXE MBR0.dat MBR9.dat >NULL 2>&1 &&(
ECHO.MBR is identical - That's Good
DEL MBR0.dat MBR9.dat
)||ECHO.MBR is different - That's Bad
PAUSE


Save this as mbc.bat
Choose to "Save type as - All Files"
Save it on your desktop.
It should look like this: Posted Image
Double click on mbc.bat & allow it to run

Did it report it as Bad or Good?

Edited by heir, 24 April 2011 - 02:56 PM.
spelling

Please do not PM me asking for support. Post on the forums instead.
Please post the final results, good or bad. We like to know!
Posted Image
Unified Network of Instructors and Trained Eliminators
My help is always free, but if you want to donate to help me continue my fight against malware then click Posted Image


#12 johndepere

johndepere
  • Topic Starter

  • Members
  • 78 posts
  • OFFLINE
  •  
  • Local time:11:35 AM

Posted 25 April 2011 - 01:03 AM

Hello again, I could not get the MBRtool to work, I got the cd made ok but when I tried to boot the computer from the cd I got an error
message of bad or missing command interpreter and error cylinder 1023, I also tried to use the cmd prompt in the start/"run"/box but this returned an error of mbrtool is not recognized as internal or external command. Any help here would be greatly appreciated.

#13 heir

heir

  • Malware Response Team
  • 763 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:35 PM

Posted 25 April 2011 - 06:21 AM

I also tried to use the cmd prompt in the start/"run"/box but this returned an error of mbrtool is not recognized as internal or external command.

Thats not possible as the tool on the CD can only be run when the computer is booted from the CD.

I got the cd made ok but when I tried to boot the computer from the cd I got an error
message of bad or missing command interpreter and error cylinder 1023

Are you positively sure it booted from the CD?

Did you burn the CD on the infected computer?

Please do not PM me asking for support. Post on the forums instead.
Please post the final results, good or bad. We like to know!
Posted Image
Unified Network of Instructors and Trained Eliminators
My help is always free, but if you want to donate to help me continue my fight against malware then click Posted Image


#14 johndepere

johndepere
  • Topic Starter

  • Members
  • 78 posts
  • OFFLINE
  •  
  • Local time:11:35 AM

Posted 25 April 2011 - 09:44 AM

Heir, I made the cd on a clean computer the I put it in the infected one and powered it down,upon boot up I selected esc which got me in the select boot device screen,I then selected boot from cd after I hit enter the cd drive with the mbr tool started, I then was into a black screen with some info about free dos project and the author, I am never presented with the blue screen and command prompt option that you show on your post. On this black screen I get the 1023 error but under it I am able to type the mbr tool path that you posted. I then get a "bad or missing command interpreter,please enter full shell command". It is very possible that I am not doing something right, any help would be great. Thanks John.

#15 heir

heir

  • Malware Response Team
  • 763 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:06:35 PM

Posted 25 April 2011 - 10:13 AM

No, you have done things correctly. Seems there is some compatibility with the CD and your computer.

We're going to use another CD then. However I need some time to draw up the instructions. I'll get back to you.

Btw, can the infected computer be booted from an USB-stick as well?

Please do not PM me asking for support. Post on the forums instead.
Please post the final results, good or bad. We like to know!
Posted Image
Unified Network of Instructors and Trained Eliminators
My help is always free, but if you want to donate to help me continue my fight against malware then click Posted Image





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users