Page 1 of 3 123 LastLast
Results 1 to 10 of 29

Thread: Infected with crez

  1. #1
    Member
    Join Date
    Jul 2009
    Posts
    57

    Default Infected with crez

    My other computer is infected and I've disconnected it from the internet. I'm using a "clean" computer to communicate with the forum.

    A Kaspersky scan says I have crez.

    A Malware scan says I have Trojan.TDSS.

    I'll attach the logs from both the Kaspersky scan and the Malware scan along with a Hijackthis report in subsequent posts.

    I'm almost certain I got the virus trying to help my wife download and display a troublesome .doc file. Word crashed several times trying to display the file. When I used Textpad to display the contents I saw it was loaded with .dll files. About an hour later Windows Antivirus Pro warnings began popping up. I used TaskMaster to stop svchast.exe and then manually removed all files associated with Windows Antivirus Pro. I then used Malware to remove some other threats, but I can't get rid of the stuff in the root.

    I need help. Thanks in advance.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 1:01:36 PM, on 8/5/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16850)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\PC Tools Firewall Plus\FWService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\ps2.exe
    C:\WINDOWS\LTMSG.exe
    C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
    C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cust...ch/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - (no file)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [vptray] "C:\Program Files\Symantec AntiVirus\VPTray.exe"
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
    O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
    O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [WUAppSetup] C:\Program Files\Common Files\logishrd\WUApp32.exe -v 0x046d -p 0x0991 -f video -m logitech -d 11.80.1048.0 (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
    O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
    O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
    O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
    O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} - https://www.windowsonecare.com/insta...SSWebAgent.CAB
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1126369175812
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/game...ploader_v5.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - PC Tools - C:\Program Files\PC Tools Firewall Plus\FWService.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe

    --
    End of file - 9404 bytes

    Wednesday, August 5, 2009
    Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
    Kaspersky Online Scanner version: 7.0.26.13
    Program database last update: Wednesday, August 05, 2009 10:00:43
    Records in database: 2582302


    Scan settings
    Scan using the following database extended
    Scan archives yes
    Scan mail databases yes

    Scan area Critical Areas
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup
    C:\Documents and Settings\Owner\Start Menu\Programs\Startup
    C:\Program Files
    C:\WINDOWS

    Scan statistics
    Files scanned 108733
    Threat name 1
    Infected objects 32
    Suspicious objects 0
    Duration of the scan 02:22:38

    File name Threat name Threats count
    globalroot\systemroot\system32\geyekrntdhjbap.dll/globalroot\systemroot\system32\geyekrntdhjbap.dll Infected: Trojan.Win32.Agent.crez 32

    The selected area was scanned.

    Malwarebytes' Anti-Malware 1.40
    Database version: 2551
    Windows 5.1.2600 Service Pack 3

    8/5/2009 1:12:08 PM
    mbam-log-2009-08-05 (13-11-55).txt

    Scan type: Quick Scan
    Objects scanned: 103408
    Time elapsed: 7 minute(s), 33 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 1
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 1

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (Trojan.TDSS) -> No action taken.

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (Trojan.TDSS) -> No action taken.
    Last edited by tashi; 2009-08-09 at 17:52. Reason: Merged 4 posts as per forum FAQ

  2. #2
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    Download DDS and save it to your desktop from here or here or here.
    Disable any script blocker, and then double click dds.scr to run the tool.
    • When done, DDS will open two (2) logs:
      1. DDS.txt
      2. Attach.txt
    • Save both reports to your desktop. Post them back to your topic.


    Download GMER here by clicking download exe -button and then saving it your desktop:
    • Double-click .exe that you downloaded
    • Click rootkit-tab and then scan.
    • Don't check
      Show All
      box while scanning in progress!
    • When scanning is ready, click Copy.
    • This copies log to clipboard
    • Post log in your reply.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  3. #3
    Member
    Join Date
    Jul 2009
    Posts
    57

    Default Dds#1

    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-07-30.01)

    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume2
    Install Date: 5/31/2004 6:32:25 PM
    System Uptime: 8/8/2009 10:22:01 PM (15 hours ago)

    Motherboard: ASUSTeK Computer INC. | | A7N8X-LA
    Processor: AMD Athlon(tm) XP 2800+ | Socket A | 2079/166mhz

    ==== Disk Partitions =========================

    A: is Removable
    C: is FIXED (NTFS) - 109 GiB total, 81.565 GiB free.
    D: is FIXED (FAT32) - 6 GiB total, 0.557 GiB free.
    E: is CDROM ()
    J: is CDROM ()
    K: is Removable
    L: is Removable
    M: is Removable
    N: is Removable
    Y: is NetworkDisk (NTFS) - 74 GiB total, 59.055 GiB free.
    Z: is NetworkDisk (NTFS) - 74 GiB total, 59.055 GiB free.

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP1794: 7/19/2009 7:24:17 AM - Installed BotHunter.
    RP1795: 7/19/2009 7:24:18 AM - System Checkpoint
    RP1796: 7/19/2009 7:24:20 AM - System Checkpoint
    RP1797: 7/19/2009 7:24:22 AM - System Checkpoint
    RP1798: 7/19/2009 7:24:24 AM - System Checkpoint

    ==== Installed Programs ======================


    7-Zip 3.13
    Adobe Acrobat 7.0 Professional
    Adobe Anchor Service CS3
    Adobe Asset Services CS3
    Adobe Bridge CS3
    Adobe Bridge Start Meeting
    Adobe Camera Raw 4.0
    Adobe CMaps
    Adobe Default Language CS3
    Adobe Device Central CS3
    Adobe Dreamweaver CS3
    Adobe ExtendScript Toolkit 2
    Adobe Extension Manager CS3
    Adobe Flash Player 10 Plugin
    Adobe Flash Player 9
    Adobe Flash Player ActiveX
    Adobe Help Viewer CS3
    Adobe PDF Library Files
    Adobe Reader 8.1.1
    Adobe Setup
    Adobe SVG Viewer 3.0
    Adobe Type Support
    Adobe Update Manager CS3
    Adobe Version Cue CS3 Client
    Advanced Port Scanner v1.2
    ArcSoft ShowBiz 2
    Audacity 1.2.3
    avast! Antivirus
    AXIS Media Control
    B2 Spice A_D v4 Pro
    CCleaner (remove only)
    Color LaserJet 2600n
    Compatibility Pack for the 2007 Office system
    Critical Update for Windows Media Player 11 (KB959772)
    EAGLE 4.11
    FileZilla Client 3.2.2.1
    Free Solitaire
    FreeRIP v2.942
    GoToMeeting 4.0.0.320
    HijackThis 2.0.2
    Hotfix for Windows Internet Explorer 7 (KB947864)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB952287)
    HP OfficeJet Series 700 (Remove Only)
    HP Photo & Imaging 3.0
    HPIZ Fix2
    hpmdtab
    HpSdpAppCoreApp
    HPSystemDiagnostics
    Intel(R) Extreme Graphics Driver
    InterVideo WinDVD Player
    Java 2 Runtime Environment, SE v1.4.1_02
    Java Web Start
    Java(TM) 6 Update 13
    Java(TM) 6 Update 6
    Java(TM) 6 Update 7
    KBD
    Logitech High Quality Video
    Logitech QuickCam Driver Package
    Macromedia Shockwave Player
    Malwarebytes' Anti-Malware
    MDI2PDF 2.4
    Memories Disc Creator 2.0
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Data Access Components KB870669
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office Live Meeting 2007
    Microsoft Office XP Professional with FrontPage
    Microsoft Plus! Digital Media Edition
    Microsoft Project 2000 SR-1
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual J# .NET Redistributable Package 1.1
    Microsoft Works 7.0
    Move Networks Media Player for Internet Explorer
    Mozilla Firefox (3.0.13)
    Mozilla Thunderbird (1.5)
    MSXML 4.0 SP2 (KB925672)
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 Parser and SDK
    Multimedia Card Reader
    NVIDIA Drivers
    NVIDIA Ethernet Driver
    NVIDIA Gart Driver
    NVIDIA Windows 2000/XP Display Drivers
    Palm Desktop
    PC Tools Firewall Plus 5.0
    Pdf995 (installed by TaxCut)
    PdfEdit995 (installed by TaxCut)
    PhotoGallery
    Photosmart 140,240,7200,7600,7700,7900 Series
    PrintScreen
    PS2
    PSShortcutsP
    Python 2.2 combined Win32 extensions
    Python 2.2.1
    QFolder
    Quicken 2008
    QuickProjects
    QuickTime
    RealOne Player
    RecordNow!
    S3Display
    S3Gamma2
    S3Info2
    S3Overlay
    Security Update for CAPICOM (KB931906)
    Security Update for Step By Step Interactive Training (KB923723)
    Security Update for Windows Internet Explorer 7 (KB928090)
    Security Update for Windows Internet Explorer 7 (KB929969)
    Security Update for Windows Internet Explorer 7 (KB931768)
    Security Update for Windows Internet Explorer 7 (KB933566)
    Security Update for Windows Internet Explorer 7 (KB937143)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB939653)
    Security Update for Windows Internet Explorer 7 (KB942615)
    Security Update for Windows Internet Explorer 7 (KB944533)
    Security Update for Windows Internet Explorer 7 (KB950759)
    Security Update for Windows Internet Explorer 7 (KB953838)
    Security Update for Windows Internet Explorer 7 (KB956390)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Internet Explorer 7 (KB960714)
    Security Update for Windows Internet Explorer 7 (KB961260)
    Security Update for Windows Internet Explorer 7 (KB963027)
    Security Update for Windows Internet Explorer 7 (KB969897)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows Media Player 9 (KB917734)
    Security Update for Windows Media Player 9 (KB936782)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB938464-v2)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB970238)
    SigmaTel MSCN Audio Player
    SimpleOCR 3.1
    SkinsHP1
    SkinsHP2
    Skype web features
    Skype™ 4.1
    SPSS 12.0.1 for Windows
    Spybot - Search & Destroy
    TaxCut Deluxe 2005
    TaxCut Pennsylvania 2006
    TaxCut Pennsylvania 2007
    TaxCut Pennsylvania 2008
    TaxCut Premium + State + Efile 2008
    TaxCut Premium + State 2007
    TaxCut Premium 2006
    TextPad 5
    TrayApp
    Trillian
    Unload
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    VideoCacheView
    VLC media player 0.9.8a
    WAV MP3 Converter 2.3 build 679
    Waver Version 2.95
    WebFldrs XP
    Windows Internet Explorer 7
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Service Pack 3
    WinPcap 4.0.2
    Yahoo! Toolbar

    ==== Event Viewer Messages From Past Week ========

    8/6/2009 5:00:00 AM, error: Schedule [7901] - The At6.job command failed to start due to the following error: %%2147942402
    8/6/2009 4:00:00 AM, error: Schedule [7901] - The At5.job command failed to start due to the following error: %%2147942402
    8/6/2009 3:00:00 AM, error: Schedule [7901] - The At4.job command failed to start due to the following error: %%2147942402
    8/6/2009 2:00:00 AM, error: Schedule [7901] - The At3.job command failed to start due to the following error: %%2147942402
    8/5/2009 12:52:00 AM, error: Schedule [7901] - The At1.job command failed to start due to the following error: %%2147942402
    8/5/2009 1:00:00 AM, error: Schedule [7901] - The At2.job command failed to start due to the following error: %%2147942402
    8/4/2009 9:54:26 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
    8/4/2009 9:21:32 PM, error: Service Control Manager [7034] - The AntipyPro_12 service terminated unexpectedly. It has done this 1 time(s).
    8/4/2009 9:00:00 PM, error: Schedule [7901] - The At22.job command failed to start due to the following error: %%2147942402
    8/4/2009 9:00:00 AM, error: Schedule [7901] - The At10.job command failed to start due to the following error: %%2147942402
    8/4/2009 8:00:00 PM, error: Schedule [7901] - The At21.job command failed to start due to the following error: %%2147942402
    8/4/2009 8:00:00 AM, error: Schedule [7901] - The At9.job command failed to start due to the following error: %%2147942402
    8/4/2009 6:00:00 PM, error: Schedule [7901] - The At19.job command failed to start due to the following error: %%2147942402
    8/4/2009 5:00:00 PM, error: Schedule [7901] - The At18.job command failed to start due to the following error: %%2147942402
    8/4/2009 12:00:00 PM, error: Schedule [7901] - The At13.job command failed to start due to the following error: %%2147942402
    8/4/2009 11:00:00 PM, error: Schedule [7901] - The At24.job command failed to start due to the following error: %%2147942402
    8/4/2009 10:00:00 PM, error: Schedule [7901] - The At23.job command failed to start due to the following error: %%2147942402
    8/4/2009 10:00:00 AM, error: Schedule [7901] - The At11.job command failed to start due to the following error: %%2147942402
    8/2/2009 7:04:12 PM, error: Service Control Manager [7034] - The Adobe LM Service service terminated unexpectedly. It has done this 1 time(s).
    8/2/2009 7:01:04 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
    8/2/2009 7:00:00 PM, error: Schedule [7901] - The At20.job command failed to start due to the following error: %%2147942402
    8/2/2009 7:00:00 AM, error: Schedule [7901] - The At8.job command failed to start due to the following error: %%2147942402
    8/2/2009 6:26:19 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
    8/2/2009 6:00:00 AM, error: Schedule [7901] - The At7.job command failed to start due to the following error: %%2147942402
    8/2/2009 4:00:00 PM, error: Schedule [7901] - The At17.job command failed to start due to the following error: %%2147942402
    8/2/2009 3:00:00 PM, error: Schedule [7901] - The At16.job command failed to start due to the following error: %%2147942402
    8/2/2009 2:00:00 PM, error: Schedule [7901] - The At15.job command failed to start due to the following error: %%2147942402
    8/2/2009 11:11:46 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
    8/2/2009 11:11:18 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
    8/2/2009 11:00:00 AM, error: Schedule [7901] - The At12.job command failed to start due to the following error: %%2147942402
    8/2/2009 1:00:00 PM, error: Schedule [7901] - The At14.job command failed to start due to the following error: %%2147942402

    ==== End Of File ===========================

  4. #4
    Member
    Join Date
    Jul 2009
    Posts
    57

    Default Dds #2

    DDS (Ver_09-07-30.01) - NTFSx86
    Run by Owner at 13:33:21.15 on Sun 08/09/2009
    Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_13
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.959.348 [GMT -4:00]

    AV: avast! antivirus 4.8.1335 [VPS 090808-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
    FW: PC Tools Firewall Plus *enabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\PC Tools Firewall Plus\FWService.exe
    C:\WINDOWS\System32\svchost.exe -k imgsvc
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\ps2.exe
    C:\WINDOWS\LTMSG.exe
    C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
    C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
    C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Documents and Settings\Owner\My Documents\Downloads\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.yahoo.com/
    uSearch Page = hxxp://www.google.com
    uSearch Bar = hxxp://www.google.com/ie
    uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
    mStart Page = hxxp://www.google.com
    mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
    mSearch Page = hxxp://www.google.com
    mDefault_Search_Url = hxxp://www.google.com/ie
    uInternet Connection Wizard,ShellNext = iexplore
    uInternet Settings,ProxyOverride = localhost;*.local
    uSearchAssistant = hxxp://www.google.com
    uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
    mSearchAssistant = hxxp://www.google.com
    BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
    BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
    TB: HP View: {b2847e28-5d7d-4deb-8b67-05d28bcf79f5} -
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
    TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
    TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
    EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
    EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
    EB: {8F4902B6-6C04-4ade-8052-AA58578A21BD} - No File
    EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
    uRun: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [FreeRAM XP] "c:\program files\yourware solutions\freeram xp pro\FreeRAM XP Pro.exe" -win
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [AlcxMonitor] ALCXMNTR.EXE
    mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
    mRun: [vptray] "c:\program files\symantec antivirus\VPTray.exe"
    mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [PS2] c:\windows\system32\ps2.exe
    mRun: [LTMSG] LTMSG.exe 7
    mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
    mRun: [Acrobat Assistant 7.0] "c:\program files\adobe\acrobat 7.0\distillr\Acrotray.exe"
    mRun: [<NO NAME>]
    mRun: [00PCTFW] "c:\program files\pc tools firewall plus\FirewallGUI.exe" -s
    dRunOnce: [RunNarrator] Narrator.exe
    dRunOnce: [WUAppSetup] c:\program files\common files\logishrd\WUApp32.exe -v 0x046d -p 0x0991 -f video -m logitech -d 11.80.1048.0
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-7760-000000000002}\SC_Acrobat.exe
    IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
    IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
    Trusted Zone: troweprice.com\www3
    DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
    DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
    DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
    DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} - hxxps://www.windowsonecare.com/install/cli/0.8.0794.48/WinSSWebAgent.CAB
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1126369175812
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38138.8417361111
    DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.4/jinstall-14_02-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://download.games.yahoo.com/games/popcap/zuma/popcaploader_v5.cab
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
    Notify: igfxcui - igfxsrvc.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\ar174uw8.default\
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
    FF - plugin: c:\program files\real\realone player\netscape6\nppl3260.dll
    FF - plugin: c:\program files\real\realone player\netscape6\nprjplug.dll
    FF - plugin: c:\program files\real\realone player\netscape6\nprpjplug.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

    ============= SERVICES / DRIVERS ===============

    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-7-24 114768]
    R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2009-8-4 159600]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-7-24 20560]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-7-24 138680]
    R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [2009-8-4 73840]
    R2 PCToolsFirewallPlus;PC Tools Firewall Plus;c:\program files\pc tools firewall plus\FWService.exe [2009-8-4 146800]
    R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-7-24 254040]
    R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-7-24 352920]
    R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [2009-8-4 95640]
    S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-6 34064]

    =============== Created Last 30 ================

    2009-08-04 23:49 <DIR> --d----- c:\docume~1\owner\applic~1\PCToolsFirewallPlus
    2009-08-04 23:47 130,424 a------- c:\windows\system32\drivers\PCTCore.sys
    2009-08-04 23:47 73,840 a------- c:\windows\system32\drivers\PCTAppEvent.sys
    2009-08-04 23:47 159,600 a------- c:\windows\system32\drivers\pctgntdi.sys
    2009-08-04 23:46 97,408 a------- c:\windows\system32\drivers\pctfw.sys
    2009-08-04 23:46 <DIR> --d----- c:\program files\common files\PC Tools
    2009-08-04 23:46 95,640 a------- c:\windows\system32\drivers\pctplfw.sys
    2009-08-04 23:46 <DIR> --d----- c:\program files\PC Tools Firewall Plus
    2009-08-04 22:58 <DIR> --d----- c:\program files\Sunbelt Software
    2009-08-04 16:47 <DIR> a-d----- c:\windows\system32\images
    2009-08-02 13:36 <DIR> --d----- c:\program files\common files\Adobe Systems Shared
    2009-07-30 14:16 28 a------- c:\windows\pdf995.ini
    2009-07-27 06:30 627,864 a----r-- c:\windows\system32\drivers\lvrs.sys
    2009-07-27 06:30 25,974 a----r-- c:\windows\system32\Repository.reg
    2009-07-27 06:30 0 a------- c:\windows\system32\drivers\lvuvc.hs
    2009-07-27 06:29 4,658,584 a----r-- c:\windows\system32\drivers\lvuvc.sys
    2009-07-27 06:29 490,008 a----r-- c:\windows\system32\LVUI2.dll
    2009-07-27 06:29 465,432 a----r-- c:\windows\system32\LVUI2RC.dll
    2009-07-27 06:29 416,280 a----r-- c:\windows\system32\lvcodec2.dll
    2009-07-27 06:29 195,096 a----r-- c:\windows\system32\lvci11801048.dll
    2009-07-27 06:29 66,482 a----r-- c:\windows\system32\lvcoinst.ini
    2009-07-27 06:29 41,752 a----r-- c:\windows\system32\drivers\LVUSBSta.sys
    2009-07-27 06:29 0 a------- c:\windows\system32\drivers\logiflt.iad
    2009-07-27 06:29 23,832 a----r-- c:\windows\system32\drivers\lvuvcflt.sys
    2009-07-20 16:07 <DIR> --d----- c:\documents and settings\owner\DoctorWeb
    2009-07-20 15:40 <DIR> --ds---- C:\Killz2
    2009-07-20 15:40 389,120 a------- c:\windows\system32\CF15915.exe
    2009-07-20 14:34 <DIR> --ds---- C:\Killz
    2009-07-20 14:34 389,120 a------- c:\windows\system32\CF3046.exe
    2009-07-20 13:49 389,120 a------- c:\windows\system32\CF26899.exe
    2009-07-20 13:04 389,120 a------- c:\windows\system32\CF18111.exe
    2009-07-20 13:00 389,120 a------- c:\windows\system32\CF17373.exe
    2009-07-20 12:56 389,120 a------- c:\windows\system32\CF16540.exe
    2009-07-20 06:22 <DIR> --ds---- C:\ComboFix
    2009-07-20 06:22 389,120 a------- c:\windows\system32\CF4933.exe
    2009-07-20 06:18 389,120 a------- c:\windows\system32\CF4169.exe
    2009-07-19 18:25 389,120 a------- c:\windows\system32\CF28399.exe
    2009-07-19 18:25 389,120 a------- c:\windows\system32\CF28233.exe
    2009-07-19 16:12 389,120 a------- c:\windows\system32\CF2271.exe
    2009-07-19 15:39 389,120 a------- c:\windows\system32\CF28652.exe
    2009-07-19 15:28 389,120 a------- c:\windows\system32\CF26353.exe
    2009-07-19 15:26 389,120 a------- c:\windows\system32\CF26072.exe
    2009-07-19 15:04 219,648 a------- c:\windows\PEV.exe
    2009-07-19 15:04 161,792 a------- c:\windows\SWREG.exe
    2009-07-19 15:04 98,816 a------- c:\windows\sed.exe
    2009-07-19 15:03 389,120 a------- c:\windows\system32\CF20527.exe
    2009-07-15 14:26 <DIR> --d----- C:\_OTM
    2009-07-13 16:00 <DIR> --d----- c:\documents and settings\owner\.SunDownloadManager
    2009-07-13 15:20 <DIR> --d----- c:\program files\Trend Micro
    2009-07-13 15:03 <DIR> --d----- c:\docume~1\owner\applic~1\SRI
    2009-07-12 14:50 <DIR> --d----- c:\docume~1\owner\applic~1\Malwarebytes
    2009-07-12 14:50 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-07-12 14:50 19,096 a------- c:\windows\system32\drivers\mbam.sys
    2009-07-12 14:50 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
    2009-07-12 14:50 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
    2009-07-11 08:31 179 a------- c:\windows\system\hpsysdrv .DAT
    2009-07-10 15:56 <DIR> --d----- c:\temp\FR90PE

    ==================== Find3M ====================

    2009-05-10 20:49 34,720 a------- c:\docume~1\owner\applic~1\GDIPFONTCACHEV1.DAT
    2009-05-06 17:07 60,744 a------- c:\documents and settings\owner\g2mdlhlpx.exe
    2007-05-03 22:14 839 a------- c:\docume~1\owner\applic~1\waver_2.95.dat
    2007-02-03 14:36 439,296 a------- c:\documents and settings\owner\GoToAssist_phone__317_en.exe
    2006-12-04 16:30 389,120 a------- c:\documents and settings\owner\remote.exe
    2004-01-01 23:43 0 a--sh--- c:\windows\sminst\HPCD.sys
    2008-09-13 11:59 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091320080914\index.dat

    ============= FINISH: 13:35:42.84 ===============

  5. #5
    Member
    Join Date
    Jul 2009
    Posts
    57

    Default GMER log

    GMER 1.0.15.15020 [o1fpslkm.exe] - http://www.gmer.net
    Rootkit scan 2009-08-09 13:50:48
    Windows 5.1.2600 Service Pack 3


    ---- System - GMER 1.0.15 ----

    Code 85460010 ZwEnumerateKey
    Code 85454010 ZwFlushInstructionCache
    Code 85504196 ZwSaveKey
    Code 85307EFE ZwSaveKeyEx
    Code 8550282E IofCallDriver
    Code 8555D9F6 IofCompleteRequest

    ---- Kernel code sections - GMER 1.0.15 ----

    .text ntoskrnl.exe!IofCallDriver 804E37C5 5 Bytes JMP 85502833
    .text ntoskrnl.exe!IofCompleteRequest 804E3BF6 5 Bytes JMP 8555D9FB
    PAGE ntoskrnl.exe!ZwEnumerateKey 80570D64 5 Bytes JMP 85460014
    PAGE ntoskrnl.exe!ZwFlushInstructionCache 80577693 5 Bytes JMP 85454014
    PAGE ntoskrnl.exe!ZwSaveKey 8064ED72 5 Bytes JMP 8550419A
    PAGE ntoskrnl.exe!ZwSaveKeyEx 8064EE5D 5 Bytes JMP 85307F02
    ? System32\Drivers\hiber_WMILIB.SYS The system cannot find the path specified. !

    ---- User code sections - GMER 1.0.15 ----

    .text C:\WINDOWS\system32\notepad.exe[236] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 008D000A
    .text C:\WINDOWS\System32\svchost.exe[444] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0066000A
    .text C:\Documents and Settings\Owner\My Documents\Downloads\o1fpslkm.exe[556] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 003A000A
    .text C:\WINDOWS\system32\notepad.exe[800] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 008D000A
    .text C:\WINDOWS\system32\winlogon.exe[1088] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 0062000A
    .text ...

    ---- Devices - GMER 1.0.15 ----

    AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
    AttachedDevice \Driver\Tcpip \Device\Ip pctgntdi.sys (PC Tools Generic TDI Driver/PC Tools)
    AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
    AttachedDevice \Driver\Tcpip \Device\Tcp pctgntdi.sys (PC Tools Generic TDI Driver/PC Tools)
    AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
    AttachedDevice \Driver\Tcpip \Device\Udp pctgntdi.sys (PC Tools Generic TDI Driver/PC Tools)
    AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
    AttachedDevice \Driver\Tcpip \Device\RawIp pctgntdi.sys (PC Tools Generic TDI Driver/PC Tools)
    AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
    AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
    AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
    ---- Processes - GMER 1.0.15 ----

    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\Program Files\Alwil Software\Avast4\ashServ.exe [192] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\WINDOWS\system32\notepad.exe [236] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [444] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\WINDOWS\system32\spoolsv.exe [544] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\Documents and Settings\Owner\My Documents\Downloads\o1fpslkm.exe [556] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\WINDOWS\system32\notepad.exe [800] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\WINDOWS\Explorer.EXE [968] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\WINDOWS\system32\winlogon.exe [1088] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\WINDOWS\system32\services.exe [1136] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\WINDOWS\system32\lsass.exe [1148] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1432] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [1516] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\Program Files\Bonjour\mDNSResponder.exe [1552] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [1576] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\Program Files\Java\jre6\bin\jqs.exe [1636] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [1660] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\WINDOWS\system32\wscntfy.exe [1676] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\Program Files\Java\jre6\bin\jusched.exe [1808] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\WINDOWS\System32\nvsvc32.exe [1812] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\Program Files\PC Tools Firewall Plus\FWService.exe [1868] 0x006D0000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1968] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [1988] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2032] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\Program Files\Mozilla Firefox\firefox.exe [2252] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\WINDOWS\system32\ps2.exe [2280] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\WINDOWS\LTMSG.exe [2344] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [2452] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe [2480] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe [2564] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\Program Files\Messenger\msmsgs.exe [2584] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\WINDOWS\System32\alg.exe [2688] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2696] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\WINDOWS\system32\rundll32.exe [2812] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\WINDOWS\system32\ctfmon.exe [2940] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [3444] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [3480] 0x10000000
    Library \\?\globalroot\systemroot\system32\geyekrntdhjbap.dll (*** hidden *** ) @ C:\Program Files\Common Files\Real\Update_OB\realsched.exe [4024] 0x10000000

    ---- Services - GMER 1.0.15 ----

    Service C:\WINDOWS\system32\drivers\geyekrhosdrufy.sys (*** hidden *** ) [SYSTEM] geyekrwqboeteh <-- ROOTKIT !!!

    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekrwqboeteh
    Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekrwqboeteh@start 1
    Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekrwqboeteh@type 1
    Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekrwqboeteh@group file system
    Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekrwqboeteh@imagepath \systemroot\system32\drivers\geyekrhosdrufy.sys
    Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekrwqboeteh\main
    Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekrwqboeteh\main@aid 10096
    Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekrwqboeteh\main@sid 0
    Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekrwqboeteh\main@cmddelay 14400
    Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekrwqboeteh\main\delete
    Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekrwqboeteh\main\injector
    Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekrwqboeteh\main\injector@* geyekrwsp.dll
    Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekrwqboeteh\main\tasks
    Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekrwqboeteh\modules
    Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekrwqboeteh\modules@geyekrrk.sys \systemroot\system32\drivers\geyekrhosdrufy.sys
    Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekrwqboeteh\modules@geyekrcmd.dll \systemroot\system32\geyekrlnmlrdbp.dll
    Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekrwqboeteh\modules@geyekrlog.dat \systemroot\system32\geyekrkpvqrqak.dat
    Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekrwqboeteh\modules@geyekrwsp.dll \systemroot\system32\geyekrntdhjbap.dll
    Reg HKLM\SYSTEM\CurrentControlSet\Services\geyekrwqboeteh\modules@geyekr.dat \systemroot\system32\geyekrultowqus.dat
    Reg HKLM\SYSTEM\ControlSet003\Services\geyekrwqboeteh (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\geyekrwqboeteh@start 1
    Reg HKLM\SYSTEM\ControlSet003\Services\geyekrwqboeteh@type 1
    Reg HKLM\SYSTEM\ControlSet003\Services\geyekrwqboeteh@group file system
    Reg HKLM\SYSTEM\ControlSet003\Services\geyekrwqboeteh@imagepath \systemroot\system32\drivers\geyekrhosdrufy.sys
    Reg HKLM\SYSTEM\ControlSet003\Services\geyekrwqboeteh\main (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\geyekrwqboeteh\main@aid 10096
    Reg HKLM\SYSTEM\ControlSet003\Services\geyekrwqboeteh\main@sid 0
    Reg HKLM\SYSTEM\ControlSet003\Services\geyekrwqboeteh\main@cmddelay 14400
    Reg HKLM\SYSTEM\ControlSet003\Services\geyekrwqboeteh\main\delete (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\geyekrwqboeteh\main\injector (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\geyekrwqboeteh\main\injector@* geyekrwsp.dll
    Reg HKLM\SYSTEM\ControlSet003\Services\geyekrwqboeteh\main\tasks (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\geyekrwqboeteh\modules (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet003\Services\geyekrwqboeteh\modules@geyekrrk.sys \systemroot\system32\drivers\geyekrhosdrufy.sys
    Reg HKLM\SYSTEM\ControlSet003\Services\geyekrwqboeteh\modules@geyekrcmd.dll \systemroot\system32\geyekrlnmlrdbp.dll
    Reg HKLM\SYSTEM\ControlSet003\Services\geyekrwqboeteh\modules@geyekrlog.dat \systemroot\system32\geyekrkpvqrqak.dat
    Reg HKLM\SYSTEM\ControlSet003\Services\geyekrwqboeteh\modules@geyekrwsp.dll \systemroot\system32\geyekrntdhjbap.dll
    Reg HKLM\SYSTEM\ControlSet003\Services\geyekrwqboeteh\modules@geyekr.dat \systemroot\system32\geyekrultowqus.dat
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
    Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@LoadAppInit_DLLs 1

    ---- Files - GMER 1.0.15 ----

    File C:\hp\KBD\STATIC\ES_NI\Collab 0 bytes
    File C:\hp\KBD\STATIC\ES_NI\JSADM.exv 1158 bytes
    File C:\hp\KBD\STATIC\ES_NI\organizer70 0 bytes
    File C:\hp\KBD\STATIC\ES_NI\Preferences 0 bytes
    File C:\hp\KBD\STATIC\ES_NI\Sunroomcomputer.err 0 bytes
    File C:\hp\KBD\STATIC\ES_NI\Updater 0 bytes
    File C:\hp\KBD\STATIC\ES_NI\UserCache.bin 28714 bytes

    ---- EOF - GMER 1.0.15 ----

  6. #6
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    Disable Spybot's TeaTimer to make sure it won't interfere with fixes. You can re-enable it when you're clean again:
    • Run Spybot-S&D in Advanced Mode
    • If it is not already set to do this, go to the Mode menu
      select
      Advanced Mode
    • On the left hand side, click on Tools
    • Then click on the Resident icon in the list
    • Uncheck
      Resident TeaTimer
      and OK any prompts.
    • Restart your computer



    Please visit this webpage for download links, and instructions for running ComboFix tool:

    http://www.bleepingcomputer.com/comb...o-use-combofix

    Please ensure you read this guide carefully and install the Recovery Console first.

    The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

    Once installed, you should see a blue screen prompt that says:

    The Recovery Console was successfully installed.

    Please continue as follows:

    1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
      Remember to re-enable them afterwards.

    2. Click Yes to allow ComboFix to continue scanning for malware.


    When the tool is finished, it will produce a report for you.

    Please include the following reports for further review, and so we may continue cleansing the system:

    C:\ComboFix.txt
    New dds.txt log.


    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  7. #7
    Member
    Join Date
    Jul 2009
    Posts
    57

    Default Combo Fix Log

    ComboFix 09-08-09.03 - Owner 08/09/2009 15:12.1.1 - NTFSx86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.959.673 [GMT -4:00]
    Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
    AV: avast! antivirus 4.8.1335 [VPS 090808-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
    FW: PC Tools Firewall Plus *disabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\desktop.ini
    c:\windows\Installer\115bc5.msi
    c:\windows\Installer\119f04.msi
    c:\windows\Installer\128cb.msi
    c:\windows\Installer\128d9.msi
    c:\windows\Installer\2c6a672.msi
    c:\windows\Installer\2c6a679.msi
    c:\windows\Installer\326d917.msi
    c:\windows\Installer\4c96ef.msp
    c:\windows\Installer\4c972d.msp
    c:\windows\Installer\678a778.msp
    c:\windows\Installer\bc0c2.msi
    c:\windows\Installer\bc0c9.msi
    c:\windows\system\hpsysdrv .DAT
    c:\windows\system\hpsysdrv .exe
    c:\windows\system32\ctfmon .exe
    c:\windows\system32\drivers\geyekrhosdrufy.sys
    c:\windows\system32\geyekrkpvqrqak.dat
    c:\windows\system32\geyekrlnmlrdbp.dll
    c:\windows\system32\geyekrntdhjbap.dll
    c:\windows\system32\geyekrultowqus.dat
    c:\windows\system32\hkcmd .exe
    c:\windows\system32\hphmon05 .exe
    c:\windows\system32\iAlmcoin.dll
    c:\windows\system32\Ijl11.dll
    D:\Autorun.inf

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Service_geyekrwqboeteh
    -------\Legacy_geyekrwqboeteh


    ((((((((((((((((((((((((( Files Created from 2009-07-09 to 2009-08-09 )))))))))))))))))))))))))))))))
    .

    2009-08-05 03:49 . 2009-08-05 03:49 -------- d-----w- c:\documents and settings\Owner\Application Data\PCToolsFirewallPlus
    2009-08-05 03:47 . 2009-03-06 20:45 130424 ----a-w- c:\windows\system32\drivers\PCTCore.sys
    2009-08-05 03:47 . 2008-12-18 16:16 73840 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
    2009-08-05 03:47 . 2008-12-11 12:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
    2009-08-05 03:47 . 2009-08-09 19:09 -------- d---a-w- c:\docume~1\ALLUSE~1\APPLIC~1\TEMP
    2009-08-05 03:46 . 2009-08-05 03:47 -------- d-----w- c:\program files\Common Files\PC Tools
    2009-08-05 03:46 . 2008-09-22 15:29 97408 ----a-w- c:\windows\system32\drivers\pctfw.sys
    2009-08-05 03:46 . 2009-01-21 13:38 95640 ----a-w- c:\windows\system32\drivers\pctplfw.sys
    2009-08-05 03:46 . 2009-08-05 03:51 -------- d-----w- c:\program files\PC Tools Firewall Plus
    2009-08-05 02:58 . 2009-08-05 02:58 -------- d-----w- c:\program files\Sunbelt Software
    2009-08-04 20:47 . 2008-11-27 22:47 -------- d---a-w- c:\windows\system32\images
    2009-08-02 18:16 . 2009-08-02 18:16 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Adobe Systems
    2009-08-02 17:36 . 2009-08-02 17:36 -------- d-----w- c:\program files\Common Files\Adobe Systems Shared
    2009-07-30 18:16 . 2009-07-30 18:16 -------- d-----w- c:\documents and settings\Owner\Application Data\pdf995
    2009-07-27 10:30 . 2008-07-26 15:25 627864 ----a-r- c:\windows\system32\drivers\lvrs.sys
    2009-07-27 10:30 . 2008-07-26 14:46 25974 ----a-r- c:\windows\system32\Repository.reg
    2009-07-27 10:29 . 2008-07-26 15:26 4658584 ----a-r- c:\windows\system32\drivers\lvuvc.sys
    2009-07-27 10:29 . 2008-07-26 15:26 465432 ----a-r- c:\windows\system32\LVUI2RC.dll
    2009-07-27 10:29 . 2008-07-26 15:26 41752 ----a-r- c:\windows\system32\drivers\LVUSBSta.sys
    2009-07-27 10:29 . 2008-07-26 15:26 490008 ----a-r- c:\windows\system32\LVUI2.dll
    2009-07-27 10:29 . 2008-07-26 15:23 195096 ----a-r- c:\windows\system32\lvci11801048.dll
    2009-07-27 10:29 . 2008-07-26 15:23 416280 ----a-r- c:\windows\system32\lvcodec2.dll
    2009-07-27 10:29 . 2008-07-26 15:26 23832 ----a-r- c:\windows\system32\drivers\lvuvcflt.sys
    2009-07-27 10:26 . 2009-07-27 10:29 -------- d-----w- c:\program files\Common Files\LogiShrd
    2009-07-24 11:06 . 2009-02-05 20:06 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
    2009-07-24 11:06 . 2009-02-05 20:06 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
    2009-07-24 11:06 . 2009-02-05 20:05 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
    2009-07-24 11:06 . 2009-02-05 20:04 97480 ----a-w- c:\windows\system32\AvastSS.scr
    2009-07-24 11:06 . 2009-02-05 20:08 93296 ----a-w- c:\windows\system32\drivers\aswmon.sys
    2009-07-24 11:06 . 2009-02-05 20:08 94032 ----a-w- c:\windows\system32\drivers\aswmon2.sys
    2009-07-24 11:06 . 2009-02-05 20:07 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
    2009-07-24 11:06 . 2009-02-05 20:07 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
    2009-07-24 11:05 . 2009-02-05 20:11 1256296 ----a-w- c:\windows\system32\aswBoot.exe
    2009-07-24 11:05 . 2009-07-24 11:05 -------- d-----w- c:\program files\Alwil Software
    2009-07-20 20:07 . 2009-07-20 20:07 -------- d-----w- c:\documents and settings\Owner\DoctorWeb
    2009-07-20 19:40 . 2009-07-20 19:40 -------- d-s---w- C:\Killz2
    2009-07-20 18:34 . 2009-07-20 18:35 -------- d-s---w- C:\Killz
    2009-07-19 01:44 . 2009-07-19 01:44 -------- d-----w- c:\documents and settings\NetworkService\Application Data\AdobeUM
    2009-07-10 19:56 . 2009-07-10 19:59 -------- d-----w- c:\temp\FR90PE

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-08-09 14:31 . 2007-02-24 18:50 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\pdf995
    2009-08-05 03:03 . 2009-06-30 00:57 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
    2009-08-05 02:46 . 2009-06-30 00:57 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2009-08-05 01:33 . 2009-07-12 18:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2009-08-03 17:36 . 2009-07-12 18:50 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-08-03 17:36 . 2009-07-12 18:50 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
    2009-08-02 23:43 . 2003-08-23 14:12 34720 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-08-02 22:54 . 2007-08-21 17:46 -------- d-----w- c:\documents and settings\Owner\Application Data\Skype
    2009-08-02 20:08 . 2009-07-06 19:16 -------- d-----w- c:\documents and settings\Owner\Application Data\skypePM
    2009-08-02 19:07 . 2009-07-27 10:30 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
    2009-08-02 19:07 . 2009-07-27 10:29 0 ----a-w- c:\windows\system32\drivers\logiflt.iad
    2009-08-02 17:32 . 2003-12-07 20:42 -------- d-----w- c:\program files\Common Files\Adobe
    2009-07-30 18:16 . 2008-02-26 20:55 -------- d-----w- c:\documents and settings\Owner\Application Data\TaxCut
    2009-07-20 22:50 . 2003-12-06 21:36 -------- d-----w- c:\program files\Multimedia Card Reader
    2009-07-19 19:56 . 2003-08-29 03:15 -------- d-----w- c:\program files\Common Files\Symantec Shared
    2009-07-19 19:21 . 2003-08-29 03:16 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Symantec
    2009-07-19 19:20 . 2007-08-09 15:25 -------- d-----w- c:\program files\Symantec AntiVirus
    2009-07-13 19:20 . 2009-07-13 19:20 -------- d-----w- c:\program files\Trend Micro
    2009-07-13 19:03 . 2009-07-13 19:03 -------- d-----w- c:\documents and settings\Owner\Application Data\SRI
    2009-07-12 18:50 . 2009-07-12 18:50 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
    2009-07-12 18:50 . 2009-07-12 18:50 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Malwarebytes
    2009-07-10 18:36 . 2003-08-23 14:19 -------- d--h--w- c:\program files\InstallShield Installation Information
    2009-07-06 19:16 . 2009-07-06 19:16 56 ---ha-w- c:\windows\system32\ezsidmv.dat
    2009-07-06 19:10 . 2005-09-23 22:59 -------- d-----r- c:\program files\Skype
    2009-07-06 19:09 . 2009-07-06 19:09 -------- d-----w- c:\program files\Common Files\Skype
    2009-07-06 19:09 . 2007-08-21 17:43 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Skype
    2009-06-25 19:55 . 2009-06-25 19:55 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\Applications
    2009-06-10 12:25 . 2009-06-10 12:25 152576 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
    2009-05-15 00:00 . 2008-03-30 20:33 72435 ----a-w- c:\windows\Fonts\AdobeFnt09.lst
    2004-01-02 03:43 . 2004-01-02 01:43 0 --sha-w- c:\windows\SMINST\HPCD.sys
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "FreeRAM XP"="c:\program files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" [2006-03-23 1591808]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
    "NVIEW"="nview.dll" - c:\windows\system32\nview.dll [2003-05-03 835654]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-05-03 4640768]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2003-08-23 151597]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
    "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
    "Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-03-08 77824]
    "PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
    "Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 483328]
    "00PCTFW"="c:\program files\PC Tools Firewall Plus\FirewallGUI.exe" [2009-02-23 2652056]
    "AlcxMonitor"="ALCXMNTR.EXE" - c:\windows\ALCXMNTR.EXE [2004-09-07 57344]
    "LTMSG"="LTMSG.exe" - c:\windows\ltmsg.exe [2003-07-14 40960]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "WUAppSetup"="c:\program files\Common Files\logishrd\WUApp32.exe" [2008-07-26 439568]
    "RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2008-04-14 53760]

    c:\documents and settings\Default User\Start Menu\Programs\Startup\
    AutoTBar.exe [2003-6-18 53248]
    mod_sm.lnk - c:\hp\bin\cloaker.exe [1999-11-7 27136]

    c:\docume~1\ALLUSE~1\STARTM~1\Programs\Startup\
    Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2009-8-2 25214]

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\WINDOWS\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=

    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [7/24/2009 7:06 AM 114768]
    R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [8/4/2009 11:47 PM 159600]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [7/24/2009 7:06 AM 20560]
    R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [8/4/2009 11:47 PM 73840]
    R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [8/4/2009 11:46 PM 95640]
    S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [11/6/2007 4:22 PM 34064]
    .
    - - - - ORPHANS REMOVED - - - -

    HKLM-Run-vptray - c:\program files\Symantec AntiVirus\VPTray.exe
    HKLM-Run-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
    Notify-NavLogon - (no file)


    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.yahoo.com/
    uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
    mStart Page = hxxp://www.google.com
    mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
    uInternet Connection Wizard,ShellNext = iexplore
    uInternet Settings,ProxyOverride = localhost;*.local
    uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
    IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    Trusted Zone: troweprice.com\www3
    DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
    DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    FF - ProfilePath - c:\docume~1\Owner\APPLIC~1\Mozilla\Firefox\Profiles\ar174uw8.default\
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
    FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nppl3260.dll
    FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprjplug.dll
    FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprpjplug.dll
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-08-09 15:30
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_USERS\S-1-5-21-150215941-2398108347-2696384825-1003\Software\Microsoft\SystemCertificates\AddressBook*]
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)
    .
    Completion time: 2009-08-09 15:34
    ComboFix-quarantined-files.txt 2009-08-09 19:33

    Pre-Run: 87,485,337,600 bytes free
    Post-Run: 87,585,939,456 bytes free

    208 --- E O F --- 2009-06-10 10:58

  8. #8
    Member
    Join Date
    Jul 2009
    Posts
    57

    Default Dds#1

    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-07-30.01)

    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume2
    Install Date: 5/31/2004 6:32:25 PM
    System Uptime: 8/9/2009 3:55:19 PM (1 hours ago)

    Motherboard: ASUSTeK Computer INC. | | A7N8X-LA
    Processor: AMD Athlon(tm) XP 2800+ | Socket A | 2079/166mhz

    ==== Disk Partitions =========================

    A: is Removable
    C: is FIXED (NTFS) - 109 GiB total, 81.591 GiB free.
    D: is FIXED (FAT32) - 6 GiB total, 0.557 GiB free.
    E: is CDROM ()
    J: is CDROM ()
    K: is Removable
    L: is Removable
    M: is Removable
    N: is Removable
    Y: is NetworkDisk (NTFS) - 74 GiB total, 59.055 GiB free.
    Z: is NetworkDisk (NTFS) - 74 GiB total, 59.055 GiB free.

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP1794: 7/19/2009 7:24:17 AM - Installed BotHunter.
    RP1795: 7/19/2009 7:24:18 AM - System Checkpoint
    RP1796: 7/19/2009 7:24:20 AM - System Checkpoint
    RP1797: 7/19/2009 7:24:22 AM - System Checkpoint
    RP1798: 7/19/2009 7:24:24 AM - System Checkpoint
    RP1799: 8/9/2009 3:12:17 PM - ComboFix created restore point

    ==== Installed Programs ======================


    7-Zip 3.13
    Adobe Acrobat 7.0 Professional
    Adobe Anchor Service CS3
    Adobe Asset Services CS3
    Adobe Bridge CS3
    Adobe Bridge Start Meeting
    Adobe Camera Raw 4.0
    Adobe CMaps
    Adobe Default Language CS3
    Adobe Device Central CS3
    Adobe Dreamweaver CS3
    Adobe ExtendScript Toolkit 2
    Adobe Extension Manager CS3
    Adobe Flash Player 10 Plugin
    Adobe Flash Player ActiveX
    Adobe Help Viewer CS3
    Adobe PDF Library Files
    Adobe Reader 8.1.1
    Adobe Setup
    Adobe SVG Viewer 3.0
    Adobe Type Support
    Adobe Update Manager CS3
    Adobe Version Cue CS3 Client
    Advanced Port Scanner v1.2
    ArcSoft ShowBiz 2
    Audacity 1.2.3
    avast! Antivirus
    AXIS Media Control
    B2 Spice A_D v4 Pro
    CCleaner (remove only)
    Color LaserJet 2600n
    Compatibility Pack for the 2007 Office system
    Critical Update for Windows Media Player 11 (KB959772)
    EAGLE 4.11
    FileZilla Client 3.2.2.1
    Free Solitaire
    FreeRIP v2.942
    GoToMeeting 4.0.0.320
    HijackThis 2.0.2
    Hotfix for Windows Internet Explorer 7 (KB947864)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB952287)
    HP Photo & Imaging 3.0
    HPIZ Fix2
    hpmdtab
    HpSdpAppCoreApp
    HPSystemDiagnostics
    Intel(R) Extreme Graphics Driver
    InterVideo WinDVD Player
    Java 2 Runtime Environment, SE v1.4.1_02
    Java Web Start
    Java(TM) 6 Update 13
    Java(TM) 6 Update 6
    Java(TM) 6 Update 7
    Logitech High Quality Video
    Logitech QuickCam Driver Package
    Macromedia Shockwave Player
    Malwarebytes' Anti-Malware
    MDI2PDF 2.4
    Memories Disc Creator 2.0
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Data Access Components KB870669
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office Live Meeting 2007
    Microsoft Office XP Professional with FrontPage
    Microsoft Plus! Digital Media Edition
    Microsoft Project 2000 SR-1
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual J# .NET Redistributable Package 1.1
    Microsoft Works 7.0
    Move Networks Media Player for Internet Explorer
    Mozilla Firefox (3.0.13)
    Mozilla Thunderbird (1.5)
    MSXML 4.0 SP2 (KB925672)
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 Parser and SDK
    Multimedia Card Reader
    NVIDIA Drivers
    NVIDIA Ethernet Driver
    NVIDIA Gart Driver
    NVIDIA Windows 2000/XP Display Drivers
    PC Tools Firewall Plus 5.0
    Pdf995 (installed by TaxCut)
    PdfEdit995 (installed by TaxCut)
    PhotoGallery
    Photosmart 140,240,7200,7600,7700,7900 Series
    PrintScreen
    PS2
    PSShortcutsP
    Python 2.2 combined Win32 extensions
    Python 2.2.1
    QFolder
    Quicken 2008
    QuickProjects
    QuickTime
    RealOne Player
    RecordNow!
    S3Display
    S3Gamma2
    S3Info2
    S3Overlay
    Security Update for CAPICOM (KB931906)
    Security Update for Step By Step Interactive Training (KB923723)
    Security Update for Windows Internet Explorer 7 (KB928090)
    Security Update for Windows Internet Explorer 7 (KB929969)
    Security Update for Windows Internet Explorer 7 (KB931768)
    Security Update for Windows Internet Explorer 7 (KB933566)
    Security Update for Windows Internet Explorer 7 (KB937143)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB939653)
    Security Update for Windows Internet Explorer 7 (KB942615)
    Security Update for Windows Internet Explorer 7 (KB944533)
    Security Update for Windows Internet Explorer 7 (KB950759)
    Security Update for Windows Internet Explorer 7 (KB953838)
    Security Update for Windows Internet Explorer 7 (KB956390)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Internet Explorer 7 (KB960714)
    Security Update for Windows Internet Explorer 7 (KB961260)
    Security Update for Windows Internet Explorer 7 (KB963027)
    Security Update for Windows Internet Explorer 7 (KB969897)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows Media Player 9 (KB917734)
    Security Update for Windows Media Player 9 (KB936782)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB938464-v2)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB970238)
    SigmaTel MSCN Audio Player
    SimpleOCR 3.1
    SkinsHP1
    SkinsHP2
    Skype web features
    Skype™ 4.1
    SPSS 12.0.1 for Windows
    Spybot - Search & Destroy
    TaxCut Deluxe 2005
    TaxCut Pennsylvania 2006
    TaxCut Pennsylvania 2007
    TaxCut Pennsylvania 2008
    TaxCut Premium + State + Efile 2008
    TaxCut Premium + State 2007
    TaxCut Premium 2006
    TextPad 5
    TrayApp
    Trillian
    Unload
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    VideoCacheView
    VLC media player 0.9.8a
    WAV MP3 Converter 2.3 build 679
    Waver Version 2.95
    WebFldrs XP
    Windows Internet Explorer 7
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Service Pack 3
    WinPcap 4.0.2
    Yahoo! Toolbar

    ==== Event Viewer Messages From Past Week ========

    8/9/2009 3:01:38 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect.
    8/9/2009 1:57:30 PM, error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume C:.
    8/6/2009 5:00:00 AM, error: Schedule [7901] - The At6.job command failed to start due to the following error: %%2147942402
    8/6/2009 4:00:00 AM, error: Schedule [7901] - The At5.job command failed to start due to the following error: %%2147942402
    8/6/2009 3:00:00 AM, error: Schedule [7901] - The At4.job command failed to start due to the following error: %%2147942402
    8/6/2009 2:00:00 AM, error: Schedule [7901] - The At3.job command failed to start due to the following error: %%2147942402
    8/5/2009 12:52:00 AM, error: Schedule [7901] - The At1.job command failed to start due to the following error: %%2147942402
    8/5/2009 1:00:00 AM, error: Schedule [7901] - The At2.job command failed to start due to the following error: %%2147942402
    8/4/2009 9:54:26 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found.
    8/4/2009 9:21:32 PM, error: Service Control Manager [7034] - The AntipyPro_12 service terminated unexpectedly. It has done this 1 time(s).
    8/4/2009 9:00:00 PM, error: Schedule [7901] - The At22.job command failed to start due to the following error: %%2147942402
    8/4/2009 9:00:00 AM, error: Schedule [7901] - The At10.job command failed to start due to the following error: %%2147942402
    8/4/2009 8:00:00 PM, error: Schedule [7901] - The At21.job command failed to start due to the following error: %%2147942402
    8/4/2009 8:00:00 AM, error: Schedule [7901] - The At9.job command failed to start due to the following error: %%2147942402
    8/4/2009 6:00:00 PM, error: Schedule [7901] - The At19.job command failed to start due to the following error: %%2147942402
    8/4/2009 5:00:00 PM, error: Schedule [7901] - The At18.job command failed to start due to the following error: %%2147942402
    8/4/2009 12:00:00 PM, error: Schedule [7901] - The At13.job command failed to start due to the following error: %%2147942402
    8/4/2009 11:00:00 PM, error: Schedule [7901] - The At24.job command failed to start due to the following error: %%2147942402
    8/4/2009 10:00:00 PM, error: Schedule [7901] - The At23.job command failed to start due to the following error: %%2147942402
    8/4/2009 10:00:00 AM, error: Schedule [7901] - The At11.job command failed to start due to the following error: %%2147942402
    8/2/2009 7:04:12 PM, error: Service Control Manager [7034] - The Adobe LM Service service terminated unexpectedly. It has done this 1 time(s).
    8/2/2009 7:01:04 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
    8/2/2009 7:00:00 PM, error: Schedule [7901] - The At20.job command failed to start due to the following error: %%2147942402
    8/2/2009 7:00:00 AM, error: Schedule [7901] - The At8.job command failed to start due to the following error: %%2147942402
    8/2/2009 6:26:19 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
    8/2/2009 6:00:00 AM, error: Schedule [7901] - The At7.job command failed to start due to the following error: %%2147942402
    8/2/2009 4:00:00 PM, error: Schedule [7901] - The At17.job command failed to start due to the following error: %%2147942402
    8/2/2009 3:00:00 PM, error: Schedule [7901] - The At16.job command failed to start due to the following error: %%2147942402
    8/2/2009 2:00:00 PM, error: Schedule [7901] - The At15.job command failed to start due to the following error: %%2147942402
    8/2/2009 11:11:46 AM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.
    8/2/2009 11:11:18 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
    8/2/2009 11:00:00 AM, error: Schedule [7901] - The At12.job command failed to start due to the following error: %%2147942402
    8/2/2009 1:00:00 PM, error: Schedule [7901] - The At14.job command failed to start due to the following error: %%2147942402

    ==== End Of File ===========================

  9. #9
    Member
    Join Date
    Jul 2009
    Posts
    57

    Default Dds #2

    DDS (Ver_09-07-30.01) - NTFSx86
    Run by Owner at 16:44:54.34 on Sun 08/09/2009
    Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_13
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.959.575 [GMT -4:00]

    AV: avast! antivirus 4.8.1335 [VPS 090808-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
    FW: PC Tools Firewall Plus *enabled* {ABBD5028-5A95-4B6D-996E-98D64AE88D52}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\PC Tools Firewall Plus\FWService.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\svchost.exe -k imgsvc
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\ps2.exe
    C:\WINDOWS\LTMSG.exe
    C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
    C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
    C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Owner\My Documents\Downloads\dds.scr
    C:\WINDOWS\system32\ctfmon.exe

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.yahoo.com/
    uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
    mStart Page = hxxp://www.google.com
    mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
    uInternet Connection Wizard,ShellNext = iexplore
    uInternet Settings,ProxyOverride = localhost;*.local
    uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
    BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
    TB: HP View: {b2847e28-5d7d-4deb-8b67-05d28bcf79f5} -
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
    TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
    TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
    EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
    EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
    uRun: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
    uRun: [FreeRAM XP] "c:\program files\yourware solutions\freeram xp pro\FreeRAM XP Pro.exe" -win
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [AlcxMonitor] ALCXMNTR.EXE
    mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
    mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [PS2] c:\windows\system32\ps2.exe
    mRun: [LTMSG] LTMSG.exe 7
    mRun: [Acrobat Assistant 7.0] "c:\program files\adobe\acrobat 7.0\distillr\Acrotray.exe"
    mRun: [00PCTFW] "c:\program files\pc tools firewall plus\FirewallGUI.exe" -s
    dRunOnce: [RunNarrator] Narrator.exe
    dRunOnce: [WUAppSetup] c:\program files\common files\logishrd\WUApp32.exe -v 0x046d -p 0x0991 -f video -m logitech -d 11.80.1048.0
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-7760-000000000002}\SC_Acrobat.exe
    IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
    IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    Trusted Zone: troweprice.com\www3
    DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
    DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
    DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
    DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} - hxxps://www.windowsonecare.com/install/cli/0.8.0794.48/WinSSWebAgent.CAB
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1126369175812
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38138.8417361111
    DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.4/jinstall-14_02-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
    Notify: igfxcui - igfxsrvc.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\ar174uw8.default\
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
    FF - plugin: c:\program files\real\realone player\netscape6\nppl3260.dll
    FF - plugin: c:\program files\real\realone player\netscape6\nprjplug.dll
    FF - plugin: c:\program files\real\realone player\netscape6\nprpjplug.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

    ============= SERVICES / DRIVERS ===============


    =============== Created Last 30 ================

    2009-08-09 15:32 <DIR> -cd----- c:\windows\system32\dllcache\cache
    2009-08-04 23:49 <DIR> --d----- c:\docume~1\owner\applic~1\PCToolsFirewallPlus
    2009-08-04 23:47 130,424 a------- c:\windows\system32\drivers\PCTCore.sys
    2009-08-04 23:47 73,840 a------- c:\windows\system32\drivers\PCTAppEvent.sys
    2009-08-04 23:47 159,600 a------- c:\windows\system32\drivers\pctgntdi.sys
    2009-08-04 23:46 97,408 a------- c:\windows\system32\drivers\pctfw.sys
    2009-08-04 23:46 <DIR> --d----- c:\program files\common files\PC Tools
    2009-08-04 23:46 95,640 a------- c:\windows\system32\drivers\pctplfw.sys
    2009-08-04 23:46 <DIR> --d----- c:\program files\PC Tools Firewall Plus
    2009-08-04 22:58 <DIR> --d----- c:\program files\Sunbelt Software
    2009-08-04 16:47 <DIR> a-d----- c:\windows\system32\images
    2009-08-02 13:36 <DIR> --d----- c:\program files\common files\Adobe Systems Shared
    2009-07-30 14:16 28 a------- c:\windows\pdf995.ini
    2009-07-27 06:30 627,864 a----r-- c:\windows\system32\drivers\lvrs.sys
    2009-07-27 06:30 25,974 a----r-- c:\windows\system32\Repository.reg
    2009-07-27 06:30 0 a------- c:\windows\system32\drivers\lvuvc.hs
    2009-07-27 06:29 4,658,584 a----r-- c:\windows\system32\drivers\lvuvc.sys
    2009-07-27 06:29 490,008 a----r-- c:\windows\system32\LVUI2.dll
    2009-07-27 06:29 465,432 a----r-- c:\windows\system32\LVUI2RC.dll
    2009-07-27 06:29 416,280 a----r-- c:\windows\system32\lvcodec2.dll
    2009-07-27 06:29 195,096 a----r-- c:\windows\system32\lvci11801048.dll
    2009-07-27 06:29 66,482 a----r-- c:\windows\system32\lvcoinst.ini
    2009-07-27 06:29 41,752 a----r-- c:\windows\system32\drivers\LVUSBSta.sys
    2009-07-27 06:29 0 a------- c:\windows\system32\drivers\logiflt.iad
    2009-07-27 06:29 23,832 a----r-- c:\windows\system32\drivers\lvuvcflt.sys
    2009-07-20 16:07 <DIR> --d----- c:\documents and settings\owner\DoctorWeb
    2009-07-20 15:40 <DIR> --ds---- C:\Killz2
    2009-07-20 14:34 <DIR> --ds---- C:\Killz
    2009-07-19 15:04 216,064 a------- c:\windows\PEV.exe
    2009-07-19 15:04 161,792 a------- c:\windows\SWREG.exe
    2009-07-19 15:04 98,816 a------- c:\windows\sed.exe
    2009-07-15 14:26 <DIR> --d----- C:\_OTM
    2009-07-13 16:00 <DIR> --d----- c:\documents and settings\owner\.SunDownloadManager
    2009-07-13 15:20 <DIR> --d----- c:\program files\Trend Micro
    2009-07-13 15:03 <DIR> --d----- c:\docume~1\owner\applic~1\SRI
    2009-07-12 14:50 <DIR> --d----- c:\docume~1\owner\applic~1\Malwarebytes
    2009-07-12 14:50 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-07-12 14:50 19,096 a------- c:\windows\system32\drivers\mbam.sys
    2009-07-12 14:50 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
    2009-07-12 14:50 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes

    ==================== Find3M ====================

    2009-05-10 20:49 34,720 a------- c:\docume~1\owner\applic~1\GDIPFONTCACHEV1.DAT
    2009-05-06 17:07 60,744 a------- c:\documents and settings\owner\g2mdlhlpx.exe
    2007-05-03 22:14 839 a------- c:\docume~1\owner\applic~1\waver_2.95.dat
    2007-02-03 14:36 439,296 a------- c:\documents and settings\owner\GoToAssist_phone__317_en.exe
    2006-12-04 16:30 389,120 a------- c:\documents and settings\owner\remote.exe
    2004-01-01 23:43 0 a--sh--- c:\windows\sminst\HPCD.sys
    2008-09-13 11:59 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091320080914\index.dat

    ============= FINISH: 16:46:21.95 ===============

  10. #10
    Member
    Join Date
    Jul 2009
    Posts
    57

    Default A Few Questions

    Blade,

    Thanks for your help!

    1. How do you guys get funded to do this very important work?

    2. I do many financial transactions with this computer, however, I stopped all financial transactions when the first indication of trouble appeared (Windows Antivirus screen). I've read other threads where the virus many not be detectable with any antivirus tool and the advice was to wipe the disk clean and reload the operating system from scratch. Can you give me an indication of how big a risk I'm taking by continuing with financial transactions on this computer?

    3. Google searches were being redirected in Firefox. Has Combofix stopped that problem?

    Thanks,

    Noise

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •