DDS (Ver_09-07-30.01) - NTFSx86
Run by Chaos Productions at 13:56:01.69 on 21/09/2009
Internet Explorer: 7.0.6000.16386
Microsoft® Windows Vista™ Ultimate 6.0.6000.0.1252.2.1033.18.2037.1171 [GMT -4:00]
SP: Windows Defender *disabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\explorer.exe
C:\Users\Chaos Productions\Desktop\New Folder (2)\Core Temp.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Chaos Productions\Desktop\dds.scr
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://forums.spybot.info/showthread.php?p=337619
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
mPolicies-system: EnableLUA = 0 (0x0)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
STS: RspyramiEve.Rspyrami: {06bae9ef-082f-4d2c-b706-de967ffa43f1} - c:\windows\system32\rspyrami.dll
============= SERVICES / DRIVERS ===============
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2008-8-11 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2009-9-19 47640]
R2 TeamViewer4;TeamViewer 4;c:\program files\teamviewer\version4\TeamViewer_Service.exe [2009-8-24 185640]
R3 netr28u;Belkin USB Wireless LAN Card Driver for Vista;c:\windows\system32\drivers\netr28u.sys [2007-8-16 552448]
R3 VST_DPV;VST_DPV;c:\windows\system32\drivers\VSTDPV3.SYS [2006-11-2 987648]
R3 VSTHWBS2;VSTHWBS2;c:\windows\system32\drivers\VSTBS23.SYS [2006-11-2 251904]
=============== Created Last 30 ================
2009-09-19 01:15 <DIR> --d----- c:\program files\Essentials Codec Pack
2009-09-19 01:08 <DIR> --d----- c:\programdata\VistaCodecPack
2009-09-19 01:08 <DIR> --d----- c:\progra~2\VistaCodecPack
2009-09-19 01:04 <DIR> --d----- c:\program files\Fusion Media Player
2009-09-19 00:56 <DIR> --d----- c:\program files\common files\PX Storage Engine
2009-09-19 00:55 <DIR> --d----- c:\program files\DivX
2009-09-19 00:55 <DIR> --d----- c:\program files\common files\DivX Shared
2009-09-19 00:37 <DIR> --d----- c:\programdata\LogMeIn
2009-09-19 00:37 <DIR> --d----- c:\progra~2\LogMeIn
2009-09-19 00:37 28,984 a------- c:\windows\system32\LMIport.dll
2009-09-19 00:37 83,288 a------- c:\windows\system32\LMIRfsClientNP.dll
2009-09-19 00:37 47,640 a------- c:\windows\system32\drivers\LMIRfsDriver.sys
2009-09-19 00:37 87,352 a------- c:\windows\system32\LMIinit.dll
2009-09-19 00:37 <DIR> --d----- c:\program files\LogMeIn
2009-09-19 00:20 <DIR> --d----- c:\program files\VistaCodecPack
2009-09-17 16:10 <DIR> --d----- c:\users\chaosp~1\appdata\roaming\Malwarebytes
2009-09-17 16:10 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-17 16:10 19,160 a------- c:\windows\system32\drivers\mbam.sys
2009-09-17 16:10 <DIR> --d----- c:\programdata\Malwarebytes
2009-09-17 16:10 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-09-17 16:10 <DIR> --d----- c:\progra~2\Malwarebytes
2009-09-11 19:39 <DIR> --d----- c:\program files\Gravity
2009-09-11 19:38 65,536 a------- c:\windows\IFinst27.exe
2009-09-10 22:35 <DIR> --d----- c:\program files\common files\Windows Live
2009-09-10 22:28 <DIR> --d----- c:\program files\Belkin
2009-09-10 22:28 <DIR> --dsh--- c:\windows\Installer
2009-09-10 22:28 <DIR> --d----- c:\windows\{7B355114-7439-42B6-AB50-516834796D4D}
2009-09-10 22:07 <DIR> --d----- c:\users\chaosp~1\appdata\roaming\TeamViewer
2009-09-10 22:07 <DIR> --d----- c:\program files\TeamViewer
2009-09-10 22:07 <DIR> --d----- c:\users\chaos productions\temp
2009-09-10 21:58 <DIR> --d----- c:\program files\AhnLab
2009-09-10 21:35 249,273,812 a------- c:\windows\MEMORY.DMP
2009-09-10 21:31 <DIR> --d----- c:\windows\Panther
2009-09-10 21:12 <DIR> --d----- C:\Windows.old
2009-09-10 20:59 <DIR> --d----- c:\users\Chaos Productions
2009-09-10 19:41 1,524,736 a------- c:\windows\system32\wucltux.dll
2009-09-10 19:40 83,456 a------- c:\windows\system32\wudriver.dll
2009-09-10 19:40 162,064 a------- c:\windows\system32\wuwebv.dll
2009-09-10 19:40 31,232 a------- c:\windows\system32\wuapp.exe
2009-09-10 17:07 8,192 a--s-r-- C:\BOOTSECT.BAK
==================== Find3M ====================
2009-09-21 13:54 51,200 a------- c:\windows\inf\infpub.dat
2009-09-10 22:29 86,016 a------- c:\windows\inf\infstrng.dat
2009-09-10 22:29 86,016 a------- c:\windows\inf\infstor.dat
2009-07-13 20:15 90,112 a------- c:\windows\system32\dpl100.dll
2009-07-13 20:15 685,056 a------- c:\windows\system32\DivX.dll
2006-11-02 08:49 174 a--sh--- c:\program files\desktop.ini
2006-11-02 08:40 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 08:40 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 08:40 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 08:40 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 06:32 665,600 a------- c:\windows\inf\drvindex.dat
2006-11-02 05:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 05:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 05:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 05:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat
2001-03-30 12:24 32,768 a--shr-- c:\windows\system32\eahdc.dll
2001-03-30 12:24 372,736 a--shr-- c:\windows\system32\rspyrami.dll
============= FINISH: 13:56:31.29 ===============
ComboFix 09-09-20.04 - Chaos Productions 21/09/2009 14:04.1.2 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6000.0.1252.2.1033.18.2037.1194 [GMT -4:00]
Running from: c:\users\Chaos Productions\Desktop\ComboFix.exe
SP: Windows Defender *disabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-51003140-4199384537-3980697693-500
.
((((((((((((((((((((((((( Files Created from 2009-08-21 to 2009-09-21 )))))))))))))))))))))))))))))))
.
2009-09-21 18:09 . 2009-09-21 18:09 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-09-19 05:15 . 2009-09-19 05:15 -------- d-----w- c:\users\Chaos Productions\AppData\Roaming\Media Player Classic
2009-09-19 05:15 . 2009-09-19 05:15 -------- d-----w- c:\program files\Essentials Codec Pack
2009-09-19 05:08 . 2009-09-19 05:08 -------- d-----w- c:\programdata\VistaCodecPack
2009-09-19 05:04 . 2009-09-19 05:04 -------- d-----w- c:\program files\Fusion Media Player
2009-09-19 04:56 . 2009-09-19 04:57 -------- d-----w- c:\users\Chaos Productions\AppData\Roaming\DivX
2009-09-19 04:56 . 2009-09-19 04:56 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2009-09-19 04:55 . 2009-09-19 05:06 -------- d-----w- c:\program files\DivX
2009-09-19 04:55 . 2009-09-19 04:56 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-09-19 04:37 . 2009-09-19 04:37 -------- d-----w- c:\users\Chaos Productions\AppData\Local\LogMeIn
2009-09-19 04:37 . 2009-09-19 04:37 -------- d-----w- c:\programdata\LogMeIn
2009-09-19 04:37 . 2009-09-05 18:23 28984 ----a-w- c:\windows\system32\LMIport.dll
2009-09-19 04:37 . 2009-09-05 18:23 83288 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2009-09-19 04:37 . 2008-08-11 19:41 47640 ----a-w- c:\windows\system32\drivers\LMIRfsDriver.sys
2009-09-19 04:37 . 2009-09-05 18:23 87352 ----a-w- c:\windows\system32\LMIinit.dll
2009-09-19 04:37 . 2009-09-21 04:00 -------- d-----w- c:\program files\LogMeIn
2009-09-19 04:32 . 2009-09-19 04:35 -------- d-----w- c:\users\Chaos Productions\AppData\Local\Deployment
2009-09-19 04:32 . 2009-09-19 04:32 -------- d-----w- c:\users\Chaos Productions\AppData\Local\Apps
2009-09-19 04:20 . 2009-09-19 04:20 -------- d-----w- c:\program files\VistaCodecPack
2009-09-17 20:10 . 2009-09-17 20:10 -------- d-----w- c:\users\Chaos Productions\AppData\Roaming\Malwarebytes
2009-09-17 20:10 . 2009-09-10 21:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-17 20:10 . 2009-09-17 20:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-17 20:10 . 2009-09-17 20:10 -------- d-----w- c:\programdata\Malwarebytes
2009-09-17 20:10 . 2009-09-10 21:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-11 23:39 . 2009-09-11 23:39 -------- d-----w- c:\program files\Gravity
2009-09-11 23:38 . 2009-09-11 23:50 65536 ----a-w- c:\windows\IFinst27.exe
2009-09-11 02:35 . 2009-09-11 02:35 -------- d-----w- c:\program files\Common Files\Windows Live
2009-09-11 02:29 . 2009-09-11 02:29 -------- d-----w- c:\program files\InstallShield Installation Information
2009-09-11 02:28 . 2009-09-11 02:28 -------- d-----w- c:\program files\Belkin
2009-09-11 02:28 . 2009-09-11 02:28 552 ----a-w- c:\users\Chaos Productions\AppData\Local\d3d8caps.dat
2009-09-11 02:28 . 2009-09-19 05:15 -------- d-sh--w- c:\windows\Installer
2009-09-11 02:28 . 2009-09-11 02:28 -------- d-----w- c:\windows\{7B355114-7439-42B6-AB50-516834796D4D}
2009-09-11 02:07 . 2009-09-11 02:07 -------- d-----w- c:\users\Chaos Productions\AppData\Roaming\TeamViewer
2009-09-11 02:07 . 2009-09-11 02:07 -------- d-----w- c:\program files\TeamViewer
2009-09-11 02:07 . 2009-09-11 02:07 -------- d-----w- c:\users\Chaos Productions\temp
2009-09-11 01:58 . 2009-09-11 01:58 -------- d-----w- c:\program files\AhnLab
2009-09-11 01:31 . 2009-09-11 00:51 -------- d-----w- c:\windows\Panther
2009-09-11 01:12 . 2009-09-11 01:51 -------- d-----w- C:\Windows.old
2009-09-11 00:41 . 2009-09-11 00:54 -------- d-----w- c:\windows\Debug
2009-09-10 23:54 . 2009-09-10 23:54 -------- d-----w- c:\windows\system32\Macromed
2009-09-10 23:43 . 2009-09-10 23:43 -------- d-----w- c:\users\Chaos Productions\AppData\Local\WindowsUpdate
2009-09-10 23:41 . 2009-09-10 23:41 51224 ----a-w- c:\windows\system32\wuauclt.exe
2009-09-10 23:41 . 2009-09-10 23:41 43544 ----a-w- c:\windows\system32\wups2.dll
2009-09-10 23:41 . 2009-09-10 23:41 1809944 ----a-w- c:\windows\system32\wuaueng.dll
2009-09-10 23:41 . 2009-09-10 23:41 1524736 ----a-w- c:\windows\system32\wucltux.dll
2009-09-10 23:40 . 2009-09-10 23:40 83456 ----a-w- c:\windows\system32\wudriver.dll
2009-09-10 23:40 . 2009-09-10 23:40 561688 ----a-w- c:\windows\system32\wuapi.dll
2009-09-10 23:40 . 2009-09-10 23:40 34328 ----a-w- c:\windows\system32\wups.dll
2009-09-10 23:40 . 2009-09-10 23:40 31232 ----a-w- c:\windows\system32\wuapp.exe
2009-09-10 23:40 . 2009-09-10 23:40 162064 ----a-w- c:\windows\system32\wuwebv.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-19 05:15 . 2009-09-11 00:59 680 ----a-w- c:\users\Chaos Productions\AppData\Local\d3d9caps.dat
2009-09-11 00:59 . 2009-09-11 00:59 48600 ----a-w- c:\users\Chaos Productions\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-14 00:15 . 2009-07-14 00:15 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-07-14 00:15 . 2009-07-14 00:15 685056 ----a-w- c:\windows\system32\DivX.dll
2001-03-30 16:24 . 2001-03-30 16:24 32768 --sha-r- c:\windows\System32\eahdc.dll
2001-03-30 16:24 . 2001-03-30 16:24 372736 --sha-r- c:\windows\System32\rspyrami.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2006-11-02 1196032]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"WindowsWelcomeCenter"="oobefldr.dll" - c:\windows\System32\oobefldr.dll [2006-11-02 2159104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-02 1004136]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-08-11 63048]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{06BAE9EF-082F-4D2C-B706-DE967FFA43F1}"= "c:\windows\system32\rspyrami.dll" [2001-03-30 372736]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{4863346F-60A0-44B6-8151-08DB57EBC2F8}"= UDP:c:\program files\TeamViewer\Version4\TeamViewer.exe:Teamviewer Remote Control Application
"{07CA59A3-B8CE-4117-9CBC-38A2088A3A97}"= TCP:c:\program files\TeamViewer\Version4\TeamViewer.exe:Teamviewer Remote Control Application
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [11/08/2008 3:41 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\System32\drivers\LMIRfsDriver.sys [19/09/2009 12:37 AM 47640]
R2 TeamViewer4;TeamViewer 4;c:\program files\TeamViewer\Version4\TeamViewer_Service.exe [24/08/2009 10:51 AM 185640]
R3 netr28u;Belkin USB Wireless LAN Card Driver for Vista;c:\windows\System32\drivers\netr28u.sys [16/08/2007 4:49 AM 552448]
R3 VST_DPV;VST_DPV;c:\windows\System32\drivers\VSTDPV3.SYS [02/11/2006 6:25 AM 987648]
R3 VSTHWBS2;VSTHWBS2;c:\windows\System32\drivers\VSTBS23.SYS [02/11/2006 6:25 AM 251904]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - BITS
*NewlyCreated* - LMIINFO
*NewlyCreated* - LMIRFSDRIVER
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://forums.spybot.info/showthread.php?p=337619
.
- - - - ORPHANS REMOVED - - - -
AddRemove-HijackThis - c:\users\Chaos Productions\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZLP77YRP\HijackThis.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-21 14:09
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(4624)
c:\windows\system32\rspyrami.dll
c:\windows\system32\MSVBVM60.DLL
.
Completion time: 2009-09-21 14:10
ComboFix-quarantined-files.txt 2009-09-21 18:10
Pre-Run: 92,655,448,064 bytes free
Post-Run: 92,676,677,632 bytes free
140
when i upgraded my computer my graphics card like uninstalled or something but my computer has a bunch of driver stuff missing i was wondering if when your done helping me remove the malware, you wouldent mind helping me fix my drivers?