Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

NASTY ROOKIT VIRUS! OUCH!


  • This topic is locked This topic is locked
18 replies to this topic

#1 drukore

drukore

  • Members
  • 42 posts
  • OFFLINE
  •  
  • Local time:03:06 PM

Posted 11 March 2012 - 10:26 PM

Hey!

I was instructed by a mod to run DDS and GMER because of a Rootkit they found. Below are the logs. I await your instructions! Thanks!!

Attached Files



BC AdBot (Login to Remove)

 


#2 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:04:06 PM

Posted 12 March 2012 - 02:22 AM

Hello and Welcome to the forums!

My name is Gringo and I'll be glad to help you with your computer problems.

Somethings to remember while we are working together.

  • Do not run any other tool untill instructed to do so!
  • please Do not Attach logs or put in code boxes.
  • Tell me about any problems that have occurred during the fix.
  • Tell me of any other symptoms you may be having as these can help also.
  • Do not run anything while running a fix.
  • Do not run any other tool untill instructed to do so!


Click on the Watch Topic Button and select Immediate Notification and click on proceed, this will help you to get notified faster when I have replied and make the cleaning process faster.

Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Run Combofix:

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<

Combofix may need to reboot your computer more than once to do its job this is normal.

You can download Combofix from one of these links.
Link 1
Link 2
Link 3
1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#3 drukore

drukore
  • Topic Starter

  • Members
  • 42 posts
  • OFFLINE
  •  
  • Local time:03:06 PM

Posted 12 March 2012 - 08:27 PM

Here is the reply...not sure how it's running yet...did we get it?

ComboFix 12-03-12.02 - Andru Brozovich 03/12/2012 18:08:24.5.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2046.1628 [GMT -7:00]
Running from: c:\documents and settings\Andru Brozovich\My Documents\Downloads\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Andru Brozovich\Application Data\Mozilla\Firefox\Profiles\clygxa2x.default\searchplugins\bing-zugo.xml
c:\documents and settings\NetworkService\Application Data\Sun\Sun\klzgc.dll
c:\windows\$NtUninstallKB51737$
c:\windows\$NtUninstallKB51737$\2054353806
c:\windows\$NtUninstallKB51737$\4151786862\@
c:\windows\$NtUninstallKB51737$\4151786862\cfg.ini
c:\windows\$NtUninstallKB51737$\4151786862\Desktop.ini
c:\windows\$NtUninstallKB51737$\4151786862\L\odetmngk
c:\windows\$NtUninstallKB51737$\4151786862\oemid
c:\windows\$NtUninstallKB51737$\4151786862\U\00000001.@
c:\windows\$NtUninstallKB51737$\4151786862\U\00000002.@
c:\windows\$NtUninstallKB51737$\4151786862\U\00000004.@
c:\windows\$NtUninstallKB51737$\4151786862\U\80000000.@
c:\windows\$NtUninstallKB51737$\4151786862\U\80000004.@
c:\windows\$NtUninstallKB51737$\4151786862\U\80000032.@
c:\windows\$NtUninstallKB51737$\4151786862\version
c:\windows\system32\dds_trash_log.cmd
c:\windows\system32\SETA1F.tmp
c:\windows\system32\SETA24.tmp
c:\windows\system32\SETA2B.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NETWORKLOG
-------\Service_NetworkLog
.
.
((((((((((((((((((((((((( Files Created from 2012-02-13 to 2012-03-13 )))))))))))))))))))))))))))))))
.
.
2012-03-12 03:47 . 2012-03-12 03:47 -------- d-----w- c:\documents and settings\Andru Brozovich\Application Data\FixTDSS
2012-03-12 03:47 . 2012-03-12 03:47 26872 ----a-w- c:\windows\system32\drivers\FixTDSS.sys
2012-03-10 19:01 . 2012-03-10 19:01 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2012-03-10 19:01 . 2012-03-10 19:01 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2012-03-10 17:47 . 2012-03-10 17:47 -------- d-----w- c:\documents and settings\Andru Brozovich\Application Data\SUPERAntiSpyware.com
2012-03-10 17:46 . 2012-03-10 17:47 -------- d-----w- c:\program files\SUPERAntiSpyware
2012-03-10 17:46 . 2012-03-10 17:46 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2012-03-10 06:41 . 2012-03-10 16:35 -------- d-----w- c:\documents and settings\Andru Brozovich\Application Data\Amazon
2012-03-10 06:40 . 2012-03-10 16:35 -------- d-----w- c:\program files\Amazon
2012-03-04 19:54 . 2012-03-04 19:54 -------- d-s---w- c:\documents and settings\LocalService\UserData
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-03-11 05:43 . 2011-11-17 04:06 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2006-11-16 00:40 . 2011-03-06 00:56 20668485 ----a-w- c:\program files\Battery 3.exe
2001-11-05 16:30 . 2011-03-06 00:56 165376 ----a-w- c:\program files\UNWISE.EXE
2012-01-08 05:29 . 2011-05-08 06:01 121816 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-10-28_19.48.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-01-11 07:03 . 2011-01-11 07:03 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_189d6662\vcomp.dll
+ 2011-01-11 06:32 . 2011-01-11 06:32 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_3dcd24cb\mfc80KOR.dll
+ 2011-01-11 06:32 . 2011-01-11 06:32 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_3dcd24cb\mfc80JPN.dll
+ 2011-01-11 06:32 . 2011-01-11 06:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_3dcd24cb\mfc80ITA.dll
+ 2011-01-11 06:32 . 2011-01-11 06:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_3dcd24cb\mfc80FRA.dll
+ 2011-01-11 06:32 . 2011-01-11 06:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_3dcd24cb\mfc80ESP.dll
+ 2011-01-11 06:32 . 2011-01-11 06:32 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_3dcd24cb\mfc80ENU.dll
+ 2011-01-11 06:32 . 2011-01-11 06:32 65536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_3dcd24cb\mfc80DEU.dll
+ 2011-01-11 06:32 . 2011-01-11 06:32 45056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_3dcd24cb\mfc80CHT.dll
+ 2011-01-11 06:32 . 2011-01-11 06:32 40960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_3dcd24cb\mfc80CHS.dll
+ 2011-01-11 12:05 . 2011-01-11 12:05 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_e87e0bcd\mfcm80u.dll
+ 2011-01-11 12:23 . 2011-01-11 12:23 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_e87e0bcd\mfcm80.dll
+ 2011-01-11 05:21 . 2011-01-11 05:21 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_7837863c\ATL80.dll
+ 2012-03-13 01:19 . 2012-03-13 01:19 16384 c:\windows\temp\Perflib_Perfdata_53c.dat
+ 2011-03-13 03:49 . 2007-11-30 11:18 17272 c:\windows\system32\spmsg.dll
- 2011-03-13 03:49 . 2008-07-09 07:38 17272 c:\windows\system32\spmsg.dll
+ 2004-08-10 17:51 . 2012-03-11 16:38 71732 c:\windows\system32\perfc009.dat
- 2004-08-10 17:51 . 2011-06-05 02:42 71732 c:\windows\system32\perfc009.dat
+ 2006-04-20 16:52 . 2005-10-15 01:49 94208 c:\windows\system32\igfxtray.exe
+ 2006-04-20 16:52 . 2005-10-15 01:46 57344 c:\windows\system32\igfxsrvc.dll
+ 2006-04-20 16:52 . 2005-10-15 01:50 94208 c:\windows\system32\igfxext.exe
+ 2006-04-20 16:52 . 2005-10-15 01:50 40960 c:\windows\system32\igfxexps.dll
+ 2006-04-20 16:52 . 2005-10-15 01:46 86016 c:\windows\system32\igfxdo.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuTRK.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuTHA.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuSVE.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuRUS.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuPTG.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuPTB.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuPLK.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuNOR.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuNLD.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuKOR.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuJPN.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuITA.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuHUN.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuHEB.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuFRC.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuFRA.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuFIN.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuESP.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuENG.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuELL.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuDEU.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuDAN.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuCSY.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuCHT.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuCHS.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuARB.dll
+ 2006-04-20 16:52 . 2005-10-15 01:51 40960 c:\windows\system32\ialmuARA.dll
+ 2006-04-20 16:52 . 2005-10-15 02:06 36990 c:\windows\system32\ialmrnt5.dll
+ 2006-04-20 16:52 . 2005-10-15 02:06 49152 c:\windows\system32\ialmrem.dll
+ 2006-04-20 16:52 . 2005-10-15 02:06 61440 c:\windows\system32\iAlmCoIn_v4410.dll
+ 2006-04-20 16:52 . 2005-10-15 01:46 77824 c:\windows\system32\hkcmd.exe
+ 2006-04-20 16:52 . 2005-10-15 01:45 73728 c:\windows\system32\hccutils.dll
- 2011-09-10 19:20 . 2009-05-18 20:17 26600 c:\windows\system32\DRVSTORE\GEARAspiWD_3B7AACF0636A2C042EB7AD2AFF76D37B27BDD28C\x86\GEARAspiWDM.sys
+ 2011-11-13 17:10 . 2009-05-18 21:17 26600 c:\windows\system32\DRVSTORE\GEARAspiWD_3B7AACF0636A2C042EB7AD2AFF76D37B27BDD28C\x86\GEARAspiWDM.sys
+ 2012-01-08 05:28 . 2011-06-21 19:24 32768 c:\windows\system32\drivers\sp_rsdrv2.sys
+ 2012-01-17 03:31 . 2011-12-10 23:24 20464 c:\windows\system32\drivers\mbam.sys
+ 2011-11-13 17:10 . 2009-05-18 21:17 26600 c:\windows\system32\drivers\GEARAspiWDM.sys
- 2011-09-10 19:20 . 2009-05-18 20:17 26600 c:\windows\system32\drivers\GEARAspiWDM.sys
+ 2004-08-10 17:51 . 2005-06-10 23:53 57856 c:\windows\system32\dllcache\spoolsv.exe
+ 2011-11-17 04:05 . 2005-10-12 23:12 22752 c:\windows\$hf_mig$\KB915865\update\spcustom.dll
+ 2011-11-17 04:05 . 2005-10-12 23:12 14048 c:\windows\$hf_mig$\KB915865\spmsg.dll
+ 2011-01-11 12:27 . 2011-01-11 12:27 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_179798c8\msvcr80.dll
+ 2011-01-11 12:24 . 2011-01-11 12:24 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_179798c8\msvcp80.dll
+ 2011-01-11 12:08 . 2011-01-11 12:08 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_179798c8\msvcm80.dll
+ 2011-11-17 04:05 . 2006-07-21 05:06 121856 c:\windows\system32\xmllite.dll
+ 2012-01-17 02:11 . 2012-01-17 02:12 336672 c:\windows\system32\Restore\rstrlog.dat
+ 2004-08-10 17:51 . 2012-03-11 16:38 442466 c:\windows\system32\perfh009.dat
- 2004-08-10 17:51 . 2011-06-05 02:42 442466 c:\windows\system32\perfh009.dat
+ 2011-11-17 04:06 . 2011-11-17 04:06 247968 c:\windows\system32\Macromed\Flash\FlashUtil11c_ActiveX.exe
+ 2011-11-17 04:06 . 2011-11-17 04:06 335520 c:\windows\system32\Macromed\Flash\FlashUtil11c_ActiveX.dll
+ 2006-04-20 16:52 . 2005-10-15 01:59 524288 c:\windows\system32\igldev32.dll
+ 2006-04-20 16:52 . 2005-10-15 01:50 114688 c:\windows\system32\igfxzoom.exe
+ 2006-04-20 16:52 . 2005-10-15 01:46 159744 c:\windows\system32\igfxsrvc.exe
+ 2006-04-20 16:52 . 2005-10-15 01:49 147456 c:\windows\system32\igfxpph.dll
+ 2006-04-20 16:52 . 2005-10-15 01:50 114688 c:\windows\system32\igfxpers.exe
+ 2006-04-20 16:52 . 2005-10-15 01:45 135168 c:\windows\system32\igfxdev.dll
+ 2006-04-20 16:52 . 2005-10-15 01:49 446464 c:\windows\system32\igfxcfg.exe
+ 2006-04-20 16:52 . 2005-10-15 01:51 114688 c:\windows\system32\ialmudlg.exe
+ 2006-04-20 16:52 . 2005-10-15 02:06 118395 c:\windows\system32\ialmdnt5.dll
+ 2006-04-20 16:52 . 2005-10-15 02:06 213274 c:\windows\system32\ialmdev5.dll
+ 2006-04-20 16:52 . 2005-10-15 02:14 901242 c:\windows\system32\ialmdd5.dll
- 2011-09-10 19:20 . 2008-04-17 19:12 107368 c:\windows\system32\GEARAspi.dll
+ 2011-11-13 17:10 . 2008-04-17 20:12 107368 c:\windows\system32\GEARAspi.dll
- 2011-09-10 19:20 . 2008-04-17 19:12 107368 c:\windows\system32\DRVSTORE\GEARAspiWD_3B7AACF0636A2C042EB7AD2AFF76D37B27BDD28C\x86\GEARAspi.dll
+ 2011-11-13 17:10 . 2008-04-17 20:12 107368 c:\windows\system32\DRVSTORE\GEARAspiWD_3B7AACF0636A2C042EB7AD2AFF76D37B27BDD28C\x86\GEARAspi.dll
+ 2011-11-17 04:05 . 2011-11-17 04:05 459264 c:\windows\Installer\47ccf124.msi
+ 2011-10-29 17:07 . 2011-10-29 17:07 795648 c:\windows\Installer\1e574df.msi
+ 2011-10-29 17:02 . 2011-10-29 17:02 301568 c:\windows\Installer\1e56c17.msi
+ 2011-11-13 17:10 . 2011-11-13 17:10 380928 c:\windows\Installer\{69995C7A-062A-4A90-A4DF-8C22895DF522}\iTunesIco.exe
- 2011-09-10 19:20 . 2011-09-10 19:20 380928 c:\windows\Installer\{69995C7A-062A-4A90-A4DF-8C22895DF522}\iTunesIco.exe
+ 2011-11-17 04:05 . 2005-10-12 23:12 371424 c:\windows\$NtUninstallKB915865$\spuninst\updspapi.dll
+ 2011-11-17 04:05 . 2005-10-12 23:12 213216 c:\windows\$NtUninstallKB915865$\spuninst\spuninst.exe
+ 2011-11-17 04:05 . 2005-10-12 23:12 371424 c:\windows\$hf_mig$\KB915865\update\updspapi.dll
+ 2011-11-17 04:05 . 2005-10-12 23:12 716000 c:\windows\$hf_mig$\KB915865\update\update.exe
+ 2011-11-17 04:05 . 2005-10-12 23:12 213216 c:\windows\$hf_mig$\KB915865\spuninst.exe
+ 2011-11-17 04:05 . 2006-07-21 05:07 121856 c:\windows\$hf_mig$\KB915865\SP2QFE\xmllite.dll
+ 2011-01-11 06:50 . 2011-01-11 06:50 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_e87e0bcd\mfc80u.dll
+ 2011-01-11 06:50 . 2011-01-11 06:50 1101824 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.5592_x-ww_e87e0bcd\mfc80.dll
+ 2006-04-20 16:52 . 2005-10-15 01:57 2310144 c:\windows\system32\iglicd32.dll
+ 2006-04-20 16:52 . 2005-10-15 01:49 1503232 c:\windows\system32\igfxress.dll
+ 2004-08-10 17:57 . 2011-12-25 05:38 3502496 c:\windows\system32\FNTCACHE.DAT
+ 2006-04-20 16:52 . 2005-10-15 02:15 1302812 c:\windows\system32\drivers\ialmnt5.sys
+ 2011-11-13 17:10 . 2011-11-13 17:10 5467136 c:\windows\Installer\35fe23bd.msi
+ 2011-03-03 20:49 . 2012-02-16 11:00 52550552 c:\windows\system32\MRT.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2005-05-15 332800]
"SetDefaultMIDI"="MIDIDef.exe" [2005-05-24 25088]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-03-07 3905920]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 339968]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"CTHelper"="CTHELPER.EXE" [2005-05-24 16384]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-06 421888]
"SpywareTerminatorShield"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2012-02-20 2786480]
"SpywareTerminatorUpdater"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2012-02-20 3669680]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872]
.
c:\documents and settings\Andru Brozovich\Start Menu\Programs\Startup\
Seagate Product Registration.lnk - c:\documents and settings\Andru Brozovich\Application Data\Leadertech\PowerRegister\Seagate Product Registration.exe [2011-3-8 1731736]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
"SpywareTerminatorUpdate"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe"
"AdobeBridge"=
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"MSKDetectorExe"=c:\program files\McAfee\SpamKiller\MSKDetct.exe /uninstall
"RealTray"=c:\program files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
"SwitchBoard"=c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
"WinampAgent"="c:\program files\Winamp\winampa.exe"
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"Memeo AutoSync"=c:\program files\Memeo\AutoSync\MemeoLauncher2.exe --silent
"Memeo Instant Backup"=c:\program files\Memeo\AutoBackup\MemeoLauncher2.exe --silent --no_ui
"Seagate Dashboard"=c:\program files\Seagate\Seagate Dashboard\MemeoLauncher.exe --silent --no_ui
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\SoulseekNS\\slsk.exe"=
"c:\\Program Files\\Trillian\\trillian.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminator.exe"=
"c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"18959:TCP"= 18959:TCP:BitComet 18959 TCP
"18959:UDP"= 18959:UDP:BitComet 18959 UDP
.
R0 FixTDSS;TDSS Fixtool driver;c:\windows\system32\drivers\FixTDSS.sys [3/11/2012 8:47 PM 26872]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 9:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 2:55 PM 67664]
R1 sp_rsdrv2;Spyware Terminator 2012 Realtime Shield Driver;c:\windows\system32\drivers\sp_rsdrv2.sys [1/7/2012 10:28 PM 32768]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 4:38 PM 116608]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [1/16/2012 8:31 PM 652360]
R2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\Memeo\AutoBackup\MemeoBackgroundService.exe [7/8/2010 11:21 AM 25824]
R2 NIHardwareService;NIHardwareService;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [10/12/2011 2:50 AM 4176896]
R2 SeagateDashboardService;Seagate Dashboard Service;c:\program files\Seagate\Seagate Dashboard\SeagateDashboardService.exe [7/6/2010 12:32 PM 14088]
R2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service;c:\program files\Spyware Terminator\st_rsser.exe [1/7/2012 10:28 PM 482992]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [1/16/2012 8:31 PM 20464]
S3 L6PODHD3;Service - Line 6 POD HD300;c:\windows\system32\drivers\L6PODHD3.sys [10/4/2011 8:48 PM 580480]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 5:49 AM 227232]
S3 MobileAdapter;Mobile Adapter USB Modem and USB Serial;c:\windows\system32\drivers\qscnusb.sys [6/4/2011 7:40 PM 103552]
S3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 2:37 PM 517096]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ksthunk
hprfdev
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-02 00:57]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.crawler.com/homepage.aspx?tbid=60076
mStart Page = hxxp://www.dell.com
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Crawler Search - tbr:iemenu
Trusted Zone: line6.net
TCP: DhcpNameServer = 192.168.15.1
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\ctbr.dll
FF - ProfilePath - c:\documents and settings\Andru Brozovich\Application Data\Mozilla\Firefox\Profiles\clygxa2x.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://www.startnow.com/s/?src=addrbar&provider=Bing&provider_code=Z064&partner_id=284&product_id=379&affiliate_id=&channel=sonic&toolbar_id=200&toolbar_version=2.0&install_country=US&install_date=20110626&user_guid=C2B3EE1591564F7ABBFA178987603701&machine_id=06056fe9b5fb585ce2a37accd6cb75bd&browser=FF&os=win&os_version=5.1-x86-SP2&q=
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-03-12 18:21
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-3127288448-3616656131-18243365-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.**$%%]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-3127288448-3616656131-18243365-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.**$%%\OpenWithList]
@Class="Shell"
.
[HKEY_USERS\S-1-5-21-3127288448-3616656131-18243365-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.****%\OpenWithList]
@Class="Shell"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(436)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
- - - - - - - > 'explorer.exe'(3832)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\ctagent.dll
c:\program files\SUPERAntiSpyware\SASSEH.DLL
c:\windows\system32\browselc.dll
c:\progra~1\SPYBOT~1\SDHelper.dll
c:\windows\System32\DLA\DLASHX_W.DLL
c:\windows\system32\DLAAPI_W.DLL
c:\windows\System32\DLA\DLACResW.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wscntfy.exe
c:\windows\stsystra.exe
c:\windows\CTHELPER.EXE
c:\program files\Creative Professional\Digital Audio System\E-MU PatchMix DSP\EmuPatchMixDSP.exe
c:\program files\Spyware Terminator\SpywareTerminator.exe
.
**************************************************************************
.
Completion time: 2012-03-12 18:26:53 - machine was rebooted
ComboFix-quarantined-files.txt 2012-03-13 01:26
ComboFix2.txt 2011-11-03 06:23
ComboFix3.txt 2011-11-03 02:42
ComboFix4.txt 2011-10-30 04:02
ComboFix5.txt 2012-03-13 00:58
.
Pre-Run: 96,077,279,232 bytes free
Post-Run: 96,279,326,720 bytes free
.
- - End Of File - - C60A23962A293A696F60251AE3F76FB7

#4 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:04:06 PM

Posted 12 March 2012 - 08:43 PM

Greetings

I want you to run these next,

tdsskiller:

Please read carefully and follow these steps.
  • Download TDSSKiller and save it to your Desktop.
  • doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • it will ask to download extra definitions - ALLOW IT
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.

If you have any problems running either one come back and let me know

please reply with the reports from TDSSKiller and aswMBR

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#5 drukore

drukore
  • Topic Starter

  • Members
  • 42 posts
  • OFFLINE
  •  
  • Local time:03:06 PM

Posted 12 March 2012 - 11:39 PM

what should I do when MBR finds something? fix it or leave it?

#6 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:04:06 PM

Posted 12 March 2012 - 11:43 PM

leave it and send me the report


gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#7 drukore

drukore
  • Topic Starter

  • Members
  • 42 posts
  • OFFLINE
  •  
  • Local time:03:06 PM

Posted 13 March 2012 - 07:40 AM

The first program found something and deleted the rootkit file. Attached is the second report.

#8 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:04:06 PM

Posted 13 March 2012 - 08:07 AM

there is no report


gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#9 drukore

drukore
  • Topic Starter

  • Members
  • 42 posts
  • OFFLINE
  •  
  • Local time:03:06 PM

Posted 14 March 2012 - 12:50 PM

aswMBR version 0.9.9.1649 Copyright© 2011 AVAST Software
Run date: 2012-03-12 21:29:18
-----------------------------
21:29:18.718 OS Version: Windows 5.1.2600 Service Pack 2
21:29:18.718 Number of processors: 2 586 0x403
21:29:18.718 ComputerName: KORE1 UserName:
21:29:19.250 Initialize success
21:33:37.875 AVAST engine defs: 12031200
21:36:14.250 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-17
21:36:14.250 Disk 0 Vendor: ST3250824AS 3.ADH Size: 238418MB BusType: 3
21:36:14.265 Disk 0 MBR read successfully
21:36:14.265 Disk 0 MBR scan
21:36:14.312 Disk 0 unknown MBR code
21:36:14.328 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 47 MB offset 63
21:36:14.343 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 234997 MB offset 96390
21:36:14.359 Disk 0 Partition 3 00 DB CP/M / CTOS Dell 8.0 3365 MB offset 481371660
21:36:14.375 Disk 0 scanning sectors +488263545
21:36:14.468 Disk 0 scanning C:\WINDOWS\system32\drivers
21:36:24.078 Service scanning
21:36:40.625 Modules scanning
21:36:45.937 Module: C:\WINDOWS\System32\DLA\DLADResN.SYS **SUSPICIOUS**
21:36:47.000 Disk 0 trace - called modules:
21:36:47.015 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
21:36:47.015 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a60fab8]
21:36:47.015 3 CLASSPNP.SYS[ba0e905b] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-17[0x8a612d98]
21:36:47.531 AVAST engine scan C:\WINDOWS
21:36:59.312 AVAST engine scan C:\WINDOWS\system32
21:39:48.468 AVAST engine scan C:\WINDOWS\system32\drivers
21:40:15.312 AVAST engine scan C:\Documents and Settings\Andru Brozovich
22:24:29.437 AVAST engine scan C:\Documents and Settings\All Users
22:30:35.468 Scan finished successfully
05:38:58.531 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Andru Brozovich\Desktop\MBR.dat"
05:38:58.531 The log file has been saved successfully to "C:\Documents and Settings\Andru Brozovich\Desktop\aswMBR.txt"

#10 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:04:06 PM

Posted 14 March 2012 - 12:55 PM

Greetings

At this time I would like you to run this script for me and it is a good time to check out the computer to see if there is anything else that needs to be addressed.

:Run CFScript:

Open Notepad and copy/paste the text in the box into the window:

ClearJavaCache::

KillAll::

Firefox::
FF - ProfilePath - c:\documents and settings\Andru Brozovich\Application Data\Mozilla\Firefox\Profiles\clygxa2x.default\
FF - prefs.js: keyword.URL - hxxp://www.startnow.com/s/?src=addrbar&provider=Bing&provider_code=Z064&partner_id=284&product_id=379&affiliate_id=&channel=sonic&toolbar_id=200&toolbar_version=2.0&install_country=US&install_date=20110626&user_guid=C2B3EE1591564F7ABBFA178987603701&machine_id=06056fe9b5fb585ce2a37accd6cb75bd&browser=FF&os=win&os_version=5.1-x86-SP2&q=

Save it to your desktop as CFScript.txt

Refering to the picture above, drag CFScript.txt into ComboFix.exe
Posted Image
This will let ComboFix run again.
Restart if you have to.
Save the produced logfile to your desktop.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following

  • report from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now after running the script?

Gringo

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#11 drukore

drukore
  • Topic Starter

  • Members
  • 42 posts
  • OFFLINE
  •  
  • Local time:03:06 PM

Posted 15 March 2012 - 07:51 AM

had trouble running this...going to try again.

#12 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:04:06 PM

Posted 15 March 2012 - 08:04 AM

Hello

Ok lets try this, I want you to run the combofix script in safe mode but it is very important that when combofix reboots the computer for you to direct it back into safe mode so it can finish the scan.

Boot into Safe Mode

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.

after combofix has finished its scan please post the report back here.

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#13 drukore

drukore
  • Topic Starter

  • Members
  • 42 posts
  • OFFLINE
  •  
  • Local time:03:06 PM

Posted 16 March 2012 - 12:14 AM

here is the report

ComboFix 12-03-12.02 - Andru Brozovich 03/15/2012 21:58:23.6.2 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.2046.1625 [GMT -7:00]
Running from: C:\Documents and Settings\Andru Brozovich\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Andru Brozovich\Desktop\CFScript.txt


((((((((((((((((((((((((( Files Created from 2012-02-16 to 2012-03-16 )))))))))))))))))))))))))))))))


2012-03-12 03:47:22 . 2012-03-12 03:47:22 -------- d-----w- C:\Documents and Settings\Andru Brozovich\Application Data\FixTDSS
2012-03-12 03:47:21 . 2012-03-12 03:47:21 26872 ----a-w- C:\WINDOWS\system32\drivers\FixTDSS.sys
2012-03-10 19:01:25 . 2012-03-10 19:01:25 -------- d-----w- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Temp
2012-03-10 19:01:25 . 2012-03-10 19:01:25 -------- d-----w- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
2012-03-10 17:47:50 . 2012-03-10 17:47:50 -------- d-----w- C:\Documents and Settings\Andru Brozovich\Application Data\SUPERAntiSpyware.com
2012-03-10 17:46:53 . 2012-03-10 17:47:50 -------- d-----w- C:\Program Files\SUPERAntiSpyware
2012-03-10 17:46:53 . 2012-03-10 17:46:53 -------- d-----w- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2012-03-10 06:41:49 . 2012-03-10 16:35:14 -------- d-----w- C:\Documents and Settings\Andru Brozovich\Application Data\Amazon
2012-03-10 06:40:59 . 2012-03-10 16:35:14 -------- d-----w- C:\Program Files\Amazon
2012-03-04 19:54:09 . 2012-03-04 19:54:09 -------- d-s---w- C:\Documents and Settings\LocalService\UserData
.


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2012-03-11 05:43:05 . 2011-11-17 04:06:47 414368 ----a-w- C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2006-11-16 00:40:56 . 2011-03-06 00:56:55 20668485 ----a-w- C:\Program Files\Battery 3.exe
2001-11-05 16:30:50 . 2011-03-06 00:56:51 165376 ----a-w- C:\Program Files\UNWISE.EXE
2012-01-08 05:29:42 . 2011-05-08 06:01:07 121816 ----a-w- C:\Program Files\mozilla firefox\components\browsercomps.dll


((((((((((((((((((((((((((((( SnapShot_2012-03-13_01.21.08 )))))))))))))))))))))))))))))))))))))))))

+ 2012-03-16 05:08:27 . 2012-03-16 05:08:27 16384 C:\WINDOWS\temp\Perflib_Perfdata_530.dat
+ 2011-03-03 20:49:03 . 2012-03-14 10:00:37 54215544 C:\WINDOWS\system32\MRT.exe

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" [2005-05-15 07:04:12 332800]
"SetDefaultMIDI"="MIDIDef.exe" [2005-05-24 08:17:46 25088]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-03-07 21:27:25 3905920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 04:20:44 339968]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 02:05:00 344064]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 08:12:00 94208]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 15:44:02 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 15:44:02 81920]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 10:20:00 122940]
"CTHelper"="CTHELPER.EXE" [2005-05-24 08:28:18 16384]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-11 09:00:00 90112]
"DivXUpdate"="C:\Program Files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 18:56:16 1230704]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2011-07-06 01:36:48 421888]
"SpywareTerminatorShield"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2012-02-20 15:04:20 2786480]
"SpywareTerminatorUpdater"="C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2012-02-20 15:04:30 3669680]
"Malwarebytes' Anti-Malware"="C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 22:53:18 460872]

C:\Documents and Settings\Andru Brozovich\Start Menu\Programs\Startup\
Seagate Product Registration.lnk - C:\Documents and Settings\Andru Brozovich\Application Data\Leadertech\PowerRegister\Seagate Product Registration.exe [2011-3-8 1731736]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 00:02:18 113024]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54:14 551296 ----a-w- C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
"SpywareTerminatorUpdate"="C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
"AdobeBridge"=

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"MSKDetectorExe"=C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
"RealTray"=C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
"SwitchBoard"=C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
"WinampAgent"="C:\Program Files\Winamp\winampa.exe"
"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe"
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"AdobeAAMUpdater-1.0"="C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
"AdobeCS5ServiceManager"="C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"Malwarebytes' Anti-Malware"="C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
"Memeo AutoSync"=C:\Program Files\Memeo\AutoSync\MemeoLauncher2.exe --silent
"Memeo Instant Backup"=C:\Program Files\Memeo\AutoBackup\MemeoLauncher2.exe --silent --no_ui
"Seagate Dashboard"=C:\Program Files\Seagate\Seagate Dashboard\MemeoLauncher.exe --silent --no_ui

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\SoulseekNS\\slsk.exe"=
"C:\\Program Files\\Trillian\\trillian.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Spyware Terminator\\SpywareTerminator.exe"=
"C:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"18959:TCP"= 18959:TCP:BitComet 18959 TCP
"18959:UDP"= 18959:UDP:BitComet 18959 UDP

R0 FixTDSS;TDSS Fixtool driver;C:\WINDOWS\system32\drivers\FixTDSS.sys [3/11/2012 8:47:21 PM 26872]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 9:27:02 AM 12880]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 2:55:22 PM 67664]
R1 sp_rsdrv2;Spyware Terminator 2012 Realtime Shield Driver;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [1/7/2012 10:28:27 PM 32768]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore.exe [8/11/2011 4:38:07 PM 116608]
R2 MBAMService;MBAMService;C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [1/16/2012 8:31:05 PM 652360]
R2 MemeoBackgroundService;MemeoBackgroundService;C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe [7/8/2010 11:21:52 AM 25824]
R2 NIHardwareService;NIHardwareService;C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [10/12/2011 2:50:29 AM 4176896]
R2 SeagateDashboardService;Seagate Dashboard Service;C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe [7/6/2010 12:32:04 PM 14088]
R2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service;C:\Program Files\Spyware Terminator\st_rsser.exe [1/7/2012 10:28:24 PM 482992]
R3 MBAMProtector;MBAMProtector;C:\WINDOWS\system32\drivers\mbam.sys [1/16/2012 8:31:04 PM 20464]
S3 L6PODHD3;Service - Line 6 POD HD300;C:\WINDOWS\system32\drivers\L6PODHD3.sys [10/4/2011 8:48:15 PM 580480]
S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 5:49:20 AM 227232]
S3 MobileAdapter;Mobile Adapter USB Modem and USB Serial;C:\WINDOWS\system32\drivers\qscnusb.sys [6/4/2011 7:40:27 PM 103552]
S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2/19/2010 2:37:14 PM 517096]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ksthunk
hprfdev

Contents of the 'Scheduled Tasks' folder

2012-03-08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-02 00:57:16 . 2011-06-02 00:57:16]


------- Supplementary Scan -------

uStart Page = hxxp://www.crawler.com/homepage.aspx?tbid=60076
mStart Page = hxxp://www.dell.com
IE: &D&ownload &with BitComet - C:\Program Files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all with BitComet - C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
IE: Crawler Search - tbr:iemenu
Trusted Zone: line6.net
TCP: DhcpNameServer = 192.168.15.1
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
FF - ProfilePath - C:\Documents and Settings\Andru Brozovich\Application Data\Mozilla\Firefox\Profiles\clygxa2x.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.com
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true

#14 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:04:06 PM

Posted 16 March 2012 - 12:35 AM

Hello

:P2P Warning!:

IMPORTANT I notice there are signs of one or more P2P (Person to Person) File Sharing Programs on your computer.

Please note that as long as you are using any form of Peer-to-Peer networking and downloading files from non-documented sources, you can expect infestations of malware to occur
Once upon a time, P2P file sharing was fairly safe. That is no longer true. P2P programs form a direct conduit on to your computer, their security measures are easily circumvented and malware writers are increasingly exploiting them to spread their wares on to your computer. Further to that, if your P2P program is not configured correctly, your computer may be sharing more files than you realise. There have been cases where people's passwords, address books and other personal, private, and financial details have been exposed to a file sharing network by a badly configured program.

Please read these short reports on the dangers of peer-2-peer programs and file sharing.

FBI Cyber Education Letter
File sharing infects 500,000 computers
USAToday
infoworld


These logs are looking allot better. But we still have some work to do.

Please print out these instructions, or copy them to a Notepad file. It will make it easier for you to follow the instructions and complete all of the necessary steps..

uninstall some programs

NOTE** Because of the cleanup process some of the programs I have listed may not be in add/remove anymore this is fine just move to the next item on the list.

You can remove these programs using add/remove or you can use the free uninstaller from Revo (Revo does allot better of a job)

Programs to remove

Java 2 Runtime Environment, SE v1.4.2_03
Java™ 6 Update 24
McAfee Security Scan Plus
SoulSeek 157 NS 13e
[/list]


  • Please download and install Revo Uninstaller Free
  • Double click Revo Uninstaller to run it.
  • From the list of programs double click on The Program to remove
  • When prompted if you want to uninstall click Yes.
  • Be sure the Moderate option is selected then click Next.
  • The program will run, If prompted again click Yes
  • when the built-in uninstaller is finished click on Next.
  • Once the program has searched for leftovers click Next.
  • Check/tick the bolded items only on the list then click Delete
  • when prompted click on Yes and then on next.
  • put a check on any folders that are found and select delete
  • when prompted select yes then on next
  • Once done click Finish.
.



Install Java:

Please go here to install Java

  • click on the Free Java Download Button
  • click on Agree and start Free download
  • click on Run
  • click on run again
  • click on install
  • when install is complete click on close

Clean Out Temp Files

  • This small application you may want to keep and use once a week to keep the computer clean.

    Download CCleaner from here http://www.ccleaner.com/

  • Run the installer to install the application.
  • When it gives you the option to install Yahoo toolbar uncheck the box next to it.
  • Run CCleaner. (make sure under Windows tab all the boxes of Internet Explorer and Windows explorer are checked. Under System check Empty Recycle Bin and Temporary Files. Under Application tab all the boxes should be checked).
  • Click Run Cleaner.
  • Close CCleaner.

: Malwarebytes' Anti-Malware :

  • I would like you to rerun MBAM
  • Double-click mbam icon
  • go to the update tab at the top
  • click on check for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is Checked (ticked) except items in the C:\System Volume Information folder and click on Remove Selected.
  • When completed, a log will open in Notepad. please copy and paste the log into your next reply
  • If you accidentally close it, the log file is saved here and will be named like this:
  • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.


Download HijackThis

If you have any problems running Hijackthis see NOTE** below (Host file not read, blank notepad ...)

  • Go Here to download HijackThis Installer
  • Save HijackThis Installer to your desktop.
  • Double-click on the HijackThis Installer icon on your desktop. (Vista and Win 7 right click and run as admin)
  • By default it will install to C:\Program Files\Trend Micro\HijackThis .
  • Click on Install.
  • It will create a HijackThis icon on the desktop.
  • Once installed it will launch Hijackthis.
  • Click on the Do a system scan and save a log file button. It will scan and the log should open in notepad.
  • Click on Edit > Select All then click on Edit > Copy to copy the entire contents of the log.
  • Come back here to this thread and Paste the log in your next reply.
  • DO NOT use the Analyze This button its findings are dangerous if misinterpreted.
  • DO NOT have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.

NOTE**
sometimes we have to run it like this To run HijackThis as an administrator, right-click HijackThis.exe
(located: C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe)<--32bit
(located: C:\Program Files(86)\Trend Micro\HiJackThis\HiJackThis.exe)<--64bit
and select to run as administrator

"information and logs"

  • In your next post I need the following

  • Log From MBAM
  • report from Hijackthis
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#15 drukore

drukore
  • Topic Starter

  • Members
  • 42 posts
  • OFFLINE
  •  
  • Local time:03:06 PM

Posted 16 March 2012 - 09:14 PM

MBAM didn't find anything. Here is the hijack report:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:11:30 PM, on 3/16/2012
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe
C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe
C:\Program Files\Spyware Terminator\st_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Creative Professional\Digital Audio System\E-MU PatchMix DSP\EmuPatchMixDSP.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.crawler.com/homepage.aspx?tbid=60076
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60076
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60076
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O2 - BHO: Increase performance and video formats for your HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Use the DivX Plus Web Player to watch web videos with less interruptions and smoother playback on supported sites - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SpywareTerminatorShield] C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
O4 - HKLM\..\Run: [SpywareTerminatorUpdater] C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: Seagate Product Registration.lnk = C:\Documents and Settings\Andru Brozovich\Application Data\Leadertech\PowerRegister\Seagate Product Registration.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.line6.net
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: MemeoBackgroundService - Memeo - C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NIHardwareService - Native Instruments GmbH - C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
O23 - Service: Seagate Dashboard Service (SeagateDashboardService) - Memeo - C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe
O23 - Service: Spyware Terminator 2012 Realtime Shield Service (ST2012_Svc) - Crawler.com - C:\Program Files\Spyware Terminator\st_rsser.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe

--
End of file - 9068 bytes




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users