PDA

View Full Version : Spybot Not Updating



Elvis316
2009-08-15, 10:14
I previously had thread which I didn't reply and hence it was achieved.

http://forums.spybot.info/showthread.php?t=50343&page=3

As per the last message posted there I was supposed to download and run Malwarebytes and post a log of that. I ran the remove the "infected selected" option.



*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*


Malwarebytes' Anti-Malware 1.40
Database version: 2548
Windows 5.1.2600 Service Pack 3

15/08/2009 11:52:13
mbam-log-2009-08-15 (11-52-08).txt

Scan type: Full Scan (C:\|D:\|I:\|)
Objects scanned: 131336
Time elapsed: 25 minute(s), 0 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Spyware Guard 2008 (Rogue.SpywareGuard) -> No action taken.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\InternetConnection (Trojan.FakeAlert) -> No action taken.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Blade81
2009-08-18, 17:11
Log looks good. What are the remaining issues (if any)? Please post a fresh hjt log.

Elvis316
2009-08-19, 03:57
Problem is that I cannot open the Safernetwork website to download the latest updates for Spybot not can I run the updates from Spybot. At the same time, I am unable to open most of Anti-malware software websites.

Here is the HJT log


*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 05:52:54, on 19/08/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Etisalat Modem Protector\ModemProtectorService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Etisalat Modem Protector\Modem Protector.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Etisalat Modem Protector] C:\Program Files\Etisalat Modem Protector\Modem Protector.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\WECPUpdate.exe -s
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3094] cmd /c del "C:\WINDOWS\SchedLgU.Txt"
O4 - HKLM\..\RunOnce: [SpybotDeletingA6511] command /c del "C:\WINDOWS\SchedLgU.Txt"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB951] command /c del "C:\WINDOWS\SchedLgU.Txt"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2868] cmd /c del "C:\WINDOWS\SchedLgU.Txt"
O4 - HKLM\..\Policies\Explorer\Run: [] 
O4 - HKUS\S-1-5-19\..\RunOnce: [] (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [] (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [] (User 'Default user')
O4 - S-1-5-18 Startup: Shortcut to Local Area Connection.lnk = ? (User 'SYSTEM')
O4 - .DEFAULT Startup: Shortcut to Local Area Connection.lnk = ? (User 'Default user')
O4 - Startup: Shortcut to Local Area Connection.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1226583123390
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O21 - SSODL: InternetConnection - {B1A95BA3-3827-4F63-A75E-009E2B48A48F} - (no file)
O23 - Service: Ares Chatroom server (AresChatServer) - Unknown owner - C:\Program Files\Ares\chatServer.exe (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Modem Protector service (ModemProtectorService) - Unknown owner - C:\Program Files\Etisalat Modem Protector\ModemProtectorService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

--
End of file - 8145 bytes

Blade81
2009-08-19, 06:48
Ok. Please follow this set of instructions:

Download DDS and save it to your desktop from here (http://www.techsupportforum.com/sectools/sUBs/dds) or here (http://download.bleepingcomputer.com/sUBs/dds.scr) or here (http://www.forospyware.com/sUBs/dds).
Disable any script blocker, and then double click dds.scr to run the tool.
When done, DDS will open two (2) logs:
DDS.txt
Attach.txt

Save both reports to your desktop. Post them back to your topic.


Download GMER (http://www.gmer.net) here by clicking download exe -button and then saving it your desktop:
Double-click .exe that you downloaded
Click rootkit-tab and then scan.
Don't check
Show All
box while scanning in progress!
When scanning is ready, click Copy.
This copies log to clipboard
Post log in your reply.

Elvis316
2009-08-21, 06:46
DDS.txt

*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*


DDS (Ver_09-07-30.01) - NTFSx86
Run by Administrator at 8:24:38.90 on 21/08/2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.502.231 [GMT 4:00]

AV: Norton AntiVirus Online *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton AntiVirus Online *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Etisalat Modem Protector\ModemProtectorService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Etisalat Modem Protector\Modem Protector.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Internet Explorer\iexplore.exe
D:\dds.scr
C:\WINDOWS\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = about:blank
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [AlcoholAutomount] "c:\program files\alcohol soft\alcohol 120\axcmd.exe" /automount
uRun: [PC Suite Tray] "c:\program files\nokia\nokia pc suite 7\PCSuite.exe" -onlytray
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRunOnce: [SpybotDeletingB951] command /c del "c:\windows\SchedLgU.Txt"
uRunOnce: [SpybotDeletingD2868] cmd /c del "c:\windows\SchedLgU.Txt"
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe"
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [Etisalat Modem Protector] c:\program files\etisalat modem protector\Modem Protector.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [osCheck] "c:\program files\norton antivirus\osCheck.exe"
mRun: [SpybotSnD] "c:\program files\spybot - search & destroy\SpybotSD.exe"
mRun: [Media Codec Update Service] c:\program files\essentials codec pack\WECPUpdate.exe -s
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRunOnce: [SpybotDeletingC3094] cmd /c del "c:\windows\SchedLgU.Txt"
mRunOnce: [SpybotDeletingA6511] command /c del "c:\windows\SchedLgU.Txt"
dRunOnce: [<NO NAME>]
mExplorerRun: [<NO NAME>] 1 (0x1)
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\SHORTC~1.LNK -
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1226583123390
DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Notify: igfxcui - igfxdev.dll
SSODL: InternetConnection - {B1A95BA3-3827-4F63-A75E-009E2B48A48F} - No File

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\znic94gk.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ae/
FF - component: c:\program files\nokia\nokia pc suite 7\bkmrksync\components\BkMrkExt.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-2-27 101936]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090820.022\NAVENG.SYS [2009-8-21 87888]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090820.022\NAVEX15.SYS [2009-8-21 875728]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2007-8-30 23888]

=============== Created Last 30 ================

2009-08-15 11:10 <DIR> --d----- c:\docume~1\admini~1\applic~1\Malwarebytes
2009-08-15 11:10 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-15 11:10 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-15 11:10 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-08-15 11:10 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-08-07 13:46 <DIR> --d----- c:\docume~1\admini~1\applic~1\Symantec
2009-08-02 05:41 <DIR> --ds---- C:\ComboFix
2009-08-01 19:58 <DIR> -cd----- c:\windows\system32\dllcache\cache
2009-08-01 19:52 <DIR> a-dshr-- C:\cmdcons
2009-08-01 19:47 219,648 a------- c:\windows\PEV.exe
2009-08-01 19:47 161,792 a------- c:\windows\SWREG.exe
2009-08-01 19:47 98,816 a------- c:\windows\sed.exe
2009-07-29 05:35 <DIR> --d----- c:\program files\Trend Micro
2009-07-28 05:47 82 a------- c:\windows\wininit.ini

==================== Find3M ====================

2009-07-20 12:54 737,280 a------- c:\windows\iun6002.exe
2009-07-19 22:37 98,304 a------- c:\windows\system32\CmdLineExt.dll

============= FINISH: 8:25:34.31 ===============



Attach.txt

*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-07-30.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 10/9/2008 8:09:41 PM
System Uptime: 8/15/2009 1:07:21 PM (139 hours ago)

Motherboard: Dell Inc. | | 0JC474
Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz | Microprocessor | 2993/800mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 71 GiB total, 2.179 GiB free.
D: is FIXED (NTFS) - 149 GiB total, 55.742 GiB free.
E: is CDROM ()
F: is CDROM ()
G: is CDROM ()
H: is Removable
I: is FIXED (FAT32) - 466 GiB total, 207.791 GiB free.

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP203: 5/23/2009 8:32:52 AM - System Checkpoint
RP204: 5/24/2009 9:24:30 AM - System Checkpoint
RP205: 5/25/2009 10:06:12 AM - System Checkpoint
RP206: 5/26/2009 10:38:11 AM - System Checkpoint
RP207: 5/27/2009 2:02:21 PM - System Checkpoint
RP208: 5/28/2009 2:48:30 PM - System Checkpoint
RP209: 5/29/2009 2:58:14 PM - System Checkpoint
RP210: 5/30/2009 4:44:02 PM - System Checkpoint
RP211: 5/31/2009 6:35:21 PM - System Checkpoint
RP212: 6/1/2009 7:51:51 PM - System Checkpoint
RP213: 6/2/2009 9:37:39 PM - System Checkpoint
RP214: 6/3/2009 10:35:43 PM - System Checkpoint
RP215: 6/4/2009 11:15:23 PM - System Checkpoint
RP216: 6/6/2009 12:20:57 AM - System Checkpoint
RP217: 6/7/2009 12:31:58 AM - System Checkpoint
RP218: 6/8/2009 1:07:24 AM - System Checkpoint
RP219: 6/9/2009 2:07:30 AM - System Checkpoint
RP220: 6/10/2009 2:08:30 AM - System Checkpoint
RP221: 6/11/2009 3:07:31 AM - System Checkpoint
RP222: 6/12/2009 3:38:41 AM - System Checkpoint
RP223: 6/13/2009 4:43:26 AM - System Checkpoint
RP224: 6/14/2009 6:44:01 AM - System Checkpoint
RP225: 6/15/2009 7:30:34 AM - System Checkpoint
RP226: 6/16/2009 7:30:43 AM - System Checkpoint
RP227: 6/17/2009 8:31:47 AM - System Checkpoint
RP228: 6/18/2009 9:10:58 AM - System Checkpoint
RP229: 6/19/2009 9:12:02 AM - System Checkpoint
RP230: 6/20/2009 9:37:03 AM - System Checkpoint
RP231: 6/21/2009 11:24:05 AM - System Checkpoint
RP232: 6/22/2009 12:40:36 PM - System Checkpoint
RP233: 6/23/2009 5:47:23 PM - System Checkpoint
RP234: 6/24/2009 7:43:50 PM - System Checkpoint
RP235: 6/25/2009 11:01:49 PM - System Checkpoint
RP236: 6/26/2009 11:55:31 PM - System Checkpoint
RP237: 6/28/2009 12:11:22 AM - System Checkpoint
RP238: 6/29/2009 12:12:27 AM - System Checkpoint
RP239: 6/30/2009 1:12:30 AM - System Checkpoint
RP240: 7/1/2009 1:23:13 AM - System Checkpoint
RP241: 7/2/2009 2:16:16 AM - System Checkpoint
RP242: 7/3/2009 2:36:23 AM - System Checkpoint
RP243: 7/4/2009 3:18:09 AM - System Checkpoint
RP244: 7/5/2009 4:16:18 AM - System Checkpoint
RP245: 7/6/2009 5:16:16 AM - System Checkpoint
RP246: 7/7/2009 5:24:46 AM - System Checkpoint
RP247: 7/8/2009 6:17:11 AM - System Checkpoint
RP248: 7/9/2009 7:16:06 AM - System Checkpoint
RP249: 7/10/2009 8:16:10 AM - System Checkpoint
RP250: 7/11/2009 8:51:05 AM - System Checkpoint
RP251: 7/12/2009 10:21:36 AM - System Checkpoint
RP252: 7/13/2009 2:07:11 PM - System Checkpoint
RP253: 7/14/2009 5:41:18 PM - System Checkpoint
RP254: 7/15/2009 6:20:42 PM - System Checkpoint
RP255: 7/16/2009 8:16:00 PM - System Checkpoint
RP256: 7/17/2009 8:49:18 PM - System Checkpoint
RP257: 7/18/2009 7:36:39 PM - Installed Hitman Blood Money
RP258: 7/18/2009 7:52:32 PM - Installed DirectX
RP259: 7/18/2009 7:57:24 PM - Installed GameShadow
RP260: 7/19/2009 9:00:32 PM - System Checkpoint
RP261: 7/19/2009 10:40:42 PM - Installed Hitman Blood Money
RP262: 7/19/2009 10:41:31 PM - Removed GameShadow
RP263: 7/19/2009 10:43:23 PM - Removed Hitman Blood Money
RP264: 7/20/2009 10:41:45 PM - Installed Hitman Blood Money
RP265: 7/20/2009 10:51:17 PM - Installed DirectX
RP266: 7/20/2009 11:00:55 PM - Removed Hitman Blood Money
RP267: 7/21/2009 11:13:48 PM - System Checkpoint
RP268: 7/23/2009 12:57:21 AM - System Checkpoint
RP269: 7/24/2009 1:39:21 AM - System Checkpoint
RP270: 7/25/2009 2:13:41 AM - System Checkpoint
RP271: 7/26/2009 2:13:51 AM - System Checkpoint
RP272: 7/27/2009 3:13:48 AM - System Checkpoint
RP273: 7/28/2009 4:13:49 AM - System Checkpoint
RP274: 7/29/2009 5:22:37 AM - System Checkpoint
RP275: 7/30/2009 5:50:17 AM - System Checkpoint
RP276: 7/31/2009 6:50:10 AM - System Checkpoint
RP277: 8/1/2009 7:01:11 AM - System Checkpoint
RP278: 8/2/2009 7:01:45 AM - System Checkpoint
RP279: 8/3/2009 7:49:24 AM - System Checkpoint
RP280: 8/4/2009 8:49:26 AM - System Checkpoint
RP281: 8/5/2009 9:20:56 AM - System Checkpoint
RP282: 8/6/2009 9:49:21 AM - System Checkpoint
RP283: 8/7/2009 10:49:24 AM - System Checkpoint
RP284: 8/8/2009 10:52:58 AM - System Checkpoint
RP285: 8/9/2009 12:00:54 PM - System Checkpoint
RP286: 8/10/2009 12:30:20 PM - System Checkpoint
RP287: 8/11/2009 3:46:13 PM - System Checkpoint
RP288: 8/12/2009 3:59:56 PM - System Checkpoint
RP289: 8/13/2009 4:48:54 PM - System Checkpoint
RP290: 8/14/2009 5:50:38 PM - System Checkpoint
RP291: 8/15/2009 6:22:54 PM - System Checkpoint
RP292: 8/16/2009 7:11:42 PM - System Checkpoint
RP293: 8/17/2009 8:03:07 PM - System Checkpoint
RP294: 8/18/2009 8:12:45 PM - System Checkpoint
RP295: 8/19/2009 9:11:42 PM - System Checkpoint
RP296: 8/20/2009 9:35:39 PM - System Checkpoint

==== Installed Programs ======================

7-Zip 4.57
AAC Decoder
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.1.2
AppCore
ATI - Software Uninstall Utility
ATI Parental Control
AutoUpdate
Backspin Billiards
ccCommon
Component Framework
Conexant D850 56K V.9x DFVc Modem
Data Lifeguard Diagnostic for Windows
Dell Resource CD
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Version Checker
DivX Web Player
DVD Suite
ERUNT 1.1j
getPlus(R) for Adobe
H.264 Decoder
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix for Windows XP (KB952287)
Intel(R) Graphics Media Accelerator Driver
Intel(R) PRO Network Connections Drivers
Java(TM) 6 Update 13
LiveUpdate (Symantec Corporation)
Malwarebytes' Anti-Malware
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft Office Professional Edition 2003
Microsoft Visual C++ 2005 Redistributable
MKV Splitter
Modem Protector - Stops your PC calling unwanted numbers
Mozilla Firefox (3.0.13)
MSN
MSVC80_x86
MSXML 4.0 SP2 (KB954430)
Nero 7 Essentials
neroxml
Nokia Connectivity Cable Driver
Nokia PC Suite
Nokia Software Updater
Norton AntiVirus
Norton AntiVirus Help
Norton AntiVirus Online (Symantec Corporation)
Norton Protection Center
PC Connectivity Solution
PowerDVD
Security Update for Windows Media Player (KB952069)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB960714)
SigmaTel Audio
SPBBC 32bit
Spybot - Search & Destroy
Symantec Real Time Storage Protection Component
SymNet
Update for Windows XP (KB955839)
VC80CRTRedist - 8.0.50727.762
WebFldrs XP
Winamp
Windows Driver Package - Nokia Modem (05/22/2008 3.8)
Windows Driver Package - Nokia Modem (05/22/2008 7.00.0.1)
Windows Driver Package - Nokia Modem (06/01/2009 4.1)
Windows Driver Package - Nokia Modem (06/01/2009 7.01.0.3)
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
Windows Essentials Media Codec Pack 2.2
Windows Genuine Advantage Notifications (KB905474)
Windows Media Format Runtime
Windows XP Service Pack 3
Xvid 1.1.3 final uninstall

==== End Of File ===========================




GMER

*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*

GMER 1.0.15.15011 [gmer.exe] - http://www.gmer.net
Rootkit scan 2009-08-21 08:46:42
Windows 5.1.2600 Service Pack 3


---- System - GMER 1.0.15 ----

SSDT 82AFE008 ZwAlertResumeThread
SSDT 82B03008 ZwAlertThread
SSDT 82B42008 ZwAllocateVirtualMemory
SSDT 8294C408 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xAACB5020]
SSDT 82C2FCD8 ZwCreateMutant
SSDT 82B046A0 ZwCreateThread
SSDT 82C1E6E8 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xAACB52A0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xAACB5800]
SSDT spnt.sys ZwEnumerateKey [0xF8415CA2]
SSDT spnt.sys ZwEnumerateValueKey [0xF8416030]
SSDT 8293F380 ZwFreeVirtualMemory
SSDT 82C37200 ZwImpersonateAnonymousToken
SSDT 82ABB008 ZwImpersonateThread
SSDT 82AF26E0 ZwMapViewOfSection
SSDT 82C1A558 ZwOpenEvent
SSDT spnt.sys ZwOpenKey [0xF83F80C0]
SSDT 82A49290 ZwOpenProcessToken
SSDT 82C1E610 ZwOpenSection
SSDT 82AAAAF0 ZwOpenThreadToken
SSDT spnt.sys ZwQueryKey [0xF8416108]
SSDT spnt.sys ZwQueryValueKey [0xF8415F88]
SSDT 829C4140 ZwResumeThread
SSDT 82B8D008 ZwSetContextThread
SSDT 82AB1310 ZwSetInformationProcess
SSDT 82A8AED8 ZwSetInformationThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xAACB5A50]
SSDT 82C1D458 ZwSuspendProcess
SSDT 82B3C008 ZwSuspendThread
SSDT 82A76CD0 ZwTerminateProcess
SSDT 82B47008 ZwTerminateThread
SSDT 82A340F0 ZwUnmapViewOfSection
SSDT 82AB8008 ZwWriteVirtualMemory

INT 0x62 ? 82D74BF8
INT 0x63 ? 82D74BF8
INT 0x63 ? 82D74BF8
INT 0x63 ? 82D74BF8
INT 0x84 ? 82BE7BF8
INT 0x94 ? 82BE7BF8
INT 0xA4 ? 82BE7BF8
INT 0xB4 ? 82BE7BF8

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!ZwCallbackReturn + 2448 80501C80 4 Bytes CALL E2D2DE6B
? spnt.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload F80468AC 5 Bytes JMP 82BE71D8
.text a0p32s6r.SYS F7DCC384 1 Byte [20]
.text a0p32s6r.SYS F7DCC384 37 Bytes [20, 00, 00, 68, 00, 00, 00, ...]
.text a0p32s6r.SYS F7DCC3AA 24 Bytes [00, 00, 20, 00, 00, E0, 00, ...]
.text a0p32s6r.SYS F7DCC3C4 3 Bytes [00, 00, 00]
.text a0p32s6r.SYS F7DCC3C9 1 Byte [00]
.text ...
? C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\mc23.tmp The system cannot find the file specified. !

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe[828] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\hkcmd.exe[1044] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\system32\igfxpers.exe[1092] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F040F5A
.text C:\Program Files\Etisalat Modem Protector\Modem Protector.exe[1192] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\Explorer.EXE[1296] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F040F5A
.text ...
.text C:\WINDOWS\system32\ctfmon.exe[2080] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 5F00003D
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2196] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[2196] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 5F00003D
.text C:\Program Files\Internet Explorer\iexplore.exe[2576] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F040F5A
.text C:\Program Files\Internet Explorer\iexplore.exe[2576] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 5F00003D
.text C:\Program Files\PC Connectivity Solution\ServiceLayer.exe[3056] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 5F00003D
.text C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe[3116] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 5F00003D
.text C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe[3144] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 5F00003D
.text C:\WINDOWS\System32\svchost.exe[3228] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 5F00003D
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[3268] kernel32.dll!LoadLibraryExW 7C801AF5 6 Bytes JMP 5F040F5A
.text C:\Documents and Settings\Administrator\Desktop\gmer.exe[3268] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 5F00003D
.text C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe[3672] kernel32.dll!FreeLibrary + 15 7C80AC83 4 Bytes CALL 5F00003D

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F83F9040] spnt.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F83F913C] spnt.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F83F90BE] spnt.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F83F97FC] spnt.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F83F96D2] spnt.sys
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!KfAcquireSpinLock] 000000AD
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!READ_PORT_UCHAR] 000000D4
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!KeGetCurrentIrql] 000000A2
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!KfRaiseIrql] 000000AF
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!KfLowerIrql] 0000009C
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!HalGetInterruptVector] 000000A4
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!HalTranslateBusAddress] 00000072
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!KeStallExecutionProcessor] 000000C0
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!KfReleaseSpinLock] 000000B7
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 000000FD
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!READ_PORT_USHORT] 00000093
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 00000026
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[HAL.dll!WRITE_PORT_UCHAR] 00000036
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[WMILIB.SYS!WmiSystemControl] 000000F7
IAT \SystemRoot\System32\Drivers\a0p32s6r.SYS[WMILIB.SYS!WmiCompleteRequest] 000000CC

---- Devices - GMER 1.0.15 ----

Device 82D731F8
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
Device 82B14500
Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\NetBT \Device\NetBT_Tcpip_{5D9E4213-3B81-4EA4-8778-2B34842E2707} 825BA1F8
Device \Driver\usbehci \Device\USBPDO-0 82BB91F8
Device \Driver\usbuhci \Device\USBPDO-1 82BE61F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 82DE11F8
Device \Driver\dmio \Device\DmControl\DmConfig 82DE11F8
Device \Driver\dmio \Device\DmControl\DmPnP 82DE11F8
Device \Driver\dmio \Device\DmControl\DmInfo 82DE11F8
Device \Driver\usbuhci \Device\USBPDO-2 82BE61F8
Device \Driver\usbuhci \Device\USBPDO-3 82BE61F8
Device \Driver\usbuhci \Device\USBPDO-4 82BE61F8
Device \Driver\PCI_PNP0338 \Device\00000055 spnt.sys
Device \Driver\PCI_PNP0338 \Device\00000055 spnt.sys

AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\USBSTOR \Device\00000070 82905500
Device \Driver\Ftdisk \Device\HarddiskVolume1 82D751F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 82D751F8
Device \Driver\Cdrom \Device\CdRom0 82BA91F8
Device \Driver\Cdrom \Device\CdRom1 82BA91F8
Device \Driver\USBSTOR \Device\00000073 82905500
Device \Driver\Ftdisk \Device\HarddiskVolume3 82D751F8
Device \Driver\sptd \Device\3480291588 spnt.sys
Device \Driver\sptd \Device\3480291588 spnt.sys
Device \Driver\Ftdisk \Device\HarddiskVolume4 82D751F8
Device \Driver\Cdrom \Device\CdRom2 82BA91F8
Device \Driver\Ftdisk \Device\HarddiskVolume5 82D751F8
Device \Driver\USBSTOR \Device\00000075 82905500
Device \Driver\USBSTOR \Device\00000076 82905500
Device \Driver\NetBT \Device\NetBt_Wins_Export 825BA1F8
Device \Driver\NetBT \Device\NetbiosSmb 825BA1F8

AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device \Driver\usbuhci \Device\USBFDO-0 82BE61F8
Device \Driver\usbuhci \Device\USBFDO-1 82BE61F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 82B90500
Device \Driver\usbuhci \Device\USBFDO-2 82BE61F8
Device \Driver\usbuhci \Device\USBFDO-3 82BE61F8
Device \Driver\usbehci \Device\USBFDO-4 82BB91F8
Device \Driver\Ftdisk \Device\FtControl 82D751F8
Device \Driver\a0p32s6r \Device\Scsi\a0p32s6r1Port3Path0Target0Lun0 82AE4340
Device \Driver\a0p32s6r \Device\Scsi\a0p32s6r1 82AE4340

AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs 82B12500

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xAE 0x98 0xAE 0x7D ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xA4 0xAB 0xB8 0x77 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x1D 0xEF 0x70 0x92 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xAE 0x98 0xAE 0x7D ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xA4 0xAB 0xB8 0x77 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xBF 0x91 0xED 0xF7 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xAE 0x98 0xAE 0x7D ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xA4 0xAB 0xB8 0x77 ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x1D 0xEF 0x70 0x92 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{ECCEE0F8-2389-DBF0-CD44-27A089191EA6}

---- EOF - GMER 1.0.15 ----

Blade81
2009-08-21, 06:53
Hi,


Disable Spybot's TeaTimer to make sure it won't interfere with fixes. You can re-enable it when you're clean again:
Run Spybot-S&D in Advanced Mode
If it is not already set to do this, go to the Mode menu
select
Advanced Mode

On the left hand side, click on Tools
Then click on the Resident icon in the list
Uncheck
Resident TeaTimer
and OK any prompts.
Restart your computer

Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.

Please continue as follows:


Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link (http://www.bleepingcomputer.com/forums/topic114351.html)
Remember to re-enable them afterwards.


Click Yes to allow ComboFix to continue scanning for malware.


When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New dds.txt log.

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.

Elvis316
2009-08-21, 08:28
Combofix.log

*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*

ComboFix 09-08-10.06 - Administrator 21/08/2009 10:20.3.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.502.341 [GMT 4:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: Norton AntiVirus Online *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton AntiVirus Online *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
- REDUCED FUNCTIONALITY MODE -
.
The following files were disabled during the run:
c:\program files\Etisalat Modem Protector\RasHookAPI.dll


((((((((((((((((((((((((( Files Created from 2009-07-21 to 2009-08-21 )))))))))))))))))))))))))))))))
.

2009-07-29 01:35 . 2009-07-29 01:35 -------- d-----w- c:\program files\Trend Micro
2009-07-29 01:34 . 2009-07-29 01:34 -------- d-----w- c:\program files\ERUNT
2009-07-27 01:23 . 2009-07-28 01:24 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-21 06:17 . 2008-11-09 11:18 -------- d-----w- c:\program files\Etisalat Modem Protector
2009-08-15 07:10 . 2009-08-15 07:10 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-08-15 07:10 . 2009-08-15 07:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-15 07:10 . 2009-08-15 07:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-07 09:46 . 2009-08-07 09:46 -------- d-----w- c:\documents and settings\Administrator\Application Data\Symantec
2009-08-03 09:36 . 2009-08-15 07:10 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 09:36 . 2009-08-15 07:10 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-20 19:00 . 2008-10-09 17:07 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-20 08:54 . 2009-07-20 08:54 -------- d-----w- c:\program files\BFG
2009-07-20 08:54 . 2009-07-20 08:54 737280 ----a-w- c:\windows\iun6002.exe
2009-07-19 18:41 . 2009-07-18 15:57 -------- d-----w- c:\program files\GameShadow
2009-07-19 18:37 . 2009-07-19 18:37 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-07-17 14:32 . 2008-11-09 16:08 -------- d-----w- c:\program files\DivX
2009-07-17 14:31 . 2009-04-10 09:54 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-07-16 02:00 . 2008-11-09 11:40 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-07-16 01:57 . 2009-07-16 01:52 -------- d-----w- c:\program files\DIFX
2009-07-16 01:56 . 2009-07-16 01:56 -------- d-----w- c:\program files\Common Files\PCSuite
2009-07-16 01:56 . 2009-02-05 02:02 -------- d-----w- c:\program files\Common Files\Nokia
2009-07-16 01:56 . 2008-12-18 14:11 -------- d-----w- c:\program files\Nokia
2009-07-16 01:52 . 2009-07-16 01:52 -------- d-----w- c:\program files\PC Connectivity Solution
2009-07-16 01:49 . 2009-07-16 01:49 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\pcswpcsi.exe
2009-07-16 01:49 . 2009-07-16 01:49 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstCCD.exe
2009-07-16 01:49 . 2009-07-16 01:49 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-07-16 01:49 . 2009-07-16 01:49 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCS.exe
2009-07-16 01:48 . 2008-12-18 14:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-07-16 01:48 . 2009-07-16 01:50 33773208 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Nokia_PC_Suite_7_1_30_9_eng.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-08-01_15.57.51 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-21 06:12 . 2009-08-21 06:12 16384 c:\windows\Temp\Perflib_Perfdata_76c.dat
+ 2009-08-15 08:07 . 2005-10-20 08:02 163328 c:\windows\ERDNT\15-08-2009\ERDNT.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-11-14 4608]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-06-25 1414144]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 52256]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"Etisalat Modem Protector"="c:\program files\Etisalat Modem Protector\Modem Protector.exe" [2006-06-05 446464]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton AntiVirus\osCheck.exe" [2007-08-30 714608]
"SpybotSnD"="c:\program files\Spybot - Search & Destroy\SpybotSD.exe" [2008-07-07 4891472]
"Media Codec Update Service"="c:\program files\Essentials Codec Pack\WECPUpdate.exe" [2009-01-25 196608]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\Symantec Shared\\NPC\\npcLUStb.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [8/30/2007 4:45 AM 149352]
R2 ModemProtectorService;Modem Protector service;c:\program files\Etisalat Modem Protector\ModemProtectorService.exe [5/22/2006 5:33 PM 143360]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/27/2009 6:35 AM 101936]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [8/30/2007 4:46 AM 23888]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [11/13/2008 5:24 PM 33752]

--- Other Services/Drivers In Memory ---

*Deregistered* - mchInjDrv

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{353e4671-b216-11dd-8ad2-0016766db67a}]
\Shell\AutoRun\command - bar311.exe %1
\Shell\Explore\command - bar311.exe %1
\Shell\Open\command - bar311.exe %1
.
Contents of the 'Scheduled Tasks' folder

2009-08-15 c:\windows\Tasks\Norton AntiVirus Online - Run Full System Scan - Administrator.job
- c:\program files\Norton AntiVirus\Navw32.exe [2007-08-30 00:47]

2009-08-15 c:\windows\Tasks\Norton AntiVirus Online - Weekly Scan - Administrator.job
- c:\program files\Norton AntiVirus\Navw32.exe [2007-08-30 00:47]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\znic94gk.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ae/
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-21 10:21
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\mc21.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1292428093-651377827-725345543-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{ECCEE0F8-2389-DBF0-CD44-27A089191EA6}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3228)
c:\program files\Common Files\Symantec Shared\NPC\2.0\NPCEXT.dll
.
Completion time: 2009-08-21 10:23
ComboFix-quarantined-files.txt 2009-08-21 06:23
ComboFix2.txt 2009-08-02 02:06
ComboFix3.txt 2009-08-01 15:59

Pre-Run: 2,438,905,856 bytes free
Post-Run: 2,457,559,040 bytes free

151 --- E O F --- 2009-01-18 12:53



DDS.txt

*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*-*


DDS (Ver_09-07-30.01) - NTFSx86
Run by Administrator at 10:24:55.20 on 21/08/2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.502.280 [GMT 4:00]

AV: Norton AntiVirus Online *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton AntiVirus Online *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Etisalat Modem Protector\ModemProtectorService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Etisalat Modem Protector\Modem Protector.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
D:\dds.scr
C:\WINDOWS\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = about:blank
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll
uRun: [AlcoholAutomount] "c:\program files\alcohol soft\alcohol 120\axcmd.exe" /automount
uRun: [PC Suite Tray] "c:\program files\nokia\nokia pc suite 7\PCSuite.exe" -onlytray
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe"
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [Etisalat Modem Protector] c:\program files\etisalat modem protector\Modem Protector.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [osCheck] "c:\program files\norton antivirus\osCheck.exe"
mRun: [SpybotSnD] "c:\program files\spybot - search & destroy\SpybotSD.exe"
mRun: [Media Codec Update Service] c:\program files\essentials codec pack\WECPUpdate.exe -s
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\SHORTC~1.LNK -
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1226583123390
DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Notify: igfxcui - igfxdev.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\znic94gk.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ae/
FF - component: c:\program files\nokia\nokia pc suite 7\bkmrksync\components\BkMrkExt.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-30 149352]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-30 149352]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-30 149352]
R2 ModemProtectorService;Modem Protector service;c:\program files\etisalat modem protector\ModemProtectorService.exe [2006-5-22 143360]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-2-27 101936]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2007-8-30 23888]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2008-11-13 33752]
S3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090820.022\NAVENG.SYS [2009-8-21 87888]
S3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090820.022\NAVEX15.SYS [2009-8-21 875728]
S3 Symantec Core LC;Symantec Core LC;c:\progra~1\common~1\symant~1\ccpd-lc\symlcsvc.exe [2008-11-9 1251720]

=============== Created Last 30 ================

2009-08-21 10:19 216,064 a------- c:\windows\PEV.exe
2009-08-21 10:19 161,792 a------- c:\windows\SWREG.exe
2009-08-21 10:19 98,816 a------- c:\windows\sed.exe
2009-08-15 11:10 <DIR> --d----- c:\docume~1\admini~1\applic~1\Malwarebytes
2009-08-15 11:10 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-15 11:10 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-15 11:10 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-08-15 11:10 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-08-07 13:46 <DIR> --d----- c:\docume~1\admini~1\applic~1\Symantec
2009-08-01 19:58 <DIR> -cd----- c:\windows\system32\dllcache\cache
2009-08-01 19:52 <DIR> a-dshr-- C:\cmdcons
2009-07-29 05:35 <DIR> --d----- c:\program files\Trend Micro
2009-07-28 05:47 82 a------- c:\windows\wininit.ini

==================== Find3M ====================

2009-07-20 12:54 737,280 a------- c:\windows\iun6002.exe
2009-07-19 22:37 98,304 a------- c:\windows\system32\CmdLineExt.dll

============= FINISH: 10:25:19.67 ===============

Blade81
2009-08-21, 20:41
Hi again,

Open notepad and copy/paste the text in the quotebox below into it:



Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=-
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=-
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{353e4671-b216-11dd-8ad2-0016766db67a}]



Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe. Let ComboFix update itself.
Then post the resultant log.


Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.


Get update 9.1.3 for Adobe Reader here (http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Windows) or get Foxit Reader here (http://www.foxitsoftware.com/pdf/reader_2/down_reader.htm). Make sure you don't install toolbar if choose Foxit Reader! You may also check free readers introduced here (http://pdfreaders.org/).


Check here (http://www.adobe.com/software/flash/about/) to see if your Flash is up-to-date. If not, uninstall vulnerable versions by following instructions here (http://kb2.adobe.com/cps/141/tn_14157.html). Fresh version can be obtained here (http://get.adobe.com/flashplayer/).


Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...

Updating Java:

Download the latest version of Java Runtime Environment (JRE) 6 Update 16 (http://java.sun.com/javase/downloads/index.jsp).
Click the
Download
button to the right.
Select Windows on platform combobox and check the box that says:
Accept License Agreement. Click continue.

The page will refresh.
Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
Check any item with Java Runtime Environment (JRE or J2SE) in the name.
Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u16-windows-i586-p.exe to install the newest version. Uncheck Carbonite online backup trial if it's offered there.



Download ATF (Atribune Temp File) Cleaner© by Atribune (http://www.atribune.org/ccount/click.php?id=1) to your desktop.

Double-click ATF Cleaner.exe to open it

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache
*The other boxes are optional*
Then click the Empty Selected button.

If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

If you use Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.


Please run an online scan with Kaspersky Online Scanner (http://www.kaspersky.com/virusscanner) as instructed in the screenshot here (http://i275.photobucket.com/albums/jj285/Bleeping/KAS/KAS9.gif).


Post back its report, a fresh dds.txt log and above mentioned ComboFix resultant log.

Elvis316
2009-08-22, 05:34
Hey ... followed all the steps you said.
Did the CFScript thing, Updated Adobe reader and Flash, Updated Java, and also did the ATF cleaner.

However, I was unable to run the Kaspersky Online Virus Scan. It downloads all the updates and then an error message pops-up.

"Update has failed. Program cannot be started." And something that it requires uniterrupted Internet connection.

Anyways ... I have attached the DDS and Comboxfix log as you asked.


DDS log

*-*-*-*-*-*-*-*-*-*-*-*-*-*-*


DDS (Ver_09-07-30.01) - NTFSx86
Run by Administrator at 7:31:55.75 on 22/08/2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.502.178 [GMT 4:00]

AV: Norton AntiVirus Online *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton AntiVirus Online *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Etisalat Modem Protector\Modem Protector.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Etisalat Modem Protector\ModemProtectorService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Java\jre6\bin\java.exe
D:\dds.scr
C:\WINDOWS\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = about:blank
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll
uRun: [AlcoholAutomount] "c:\program files\alcohol soft\alcohol 120\axcmd.exe" /automount
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRunOnce: [SpybotDeletingB951] command /c del "c:\windows\SchedLgU.Txt"
uRunOnce: [SpybotDeletingD2868] cmd /c del "c:\windows\SchedLgU.Txt"
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe"
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [Etisalat Modem Protector] c:\program files\etisalat modem protector\Modem Protector.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [osCheck] "c:\program files\norton antivirus\osCheck.exe"
mRun: [SpybotSnD] "c:\program files\spybot - search & destroy\SpybotSD.exe"
mRun: [Media Codec Update Service] c:\program files\essentials codec pack\WECPUpdate.exe -s
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRunOnce: "c:\windows\system32\rundll32.exe" "tc:\docume~1\admini~1\locals~1\temp\nos_uninstall_Adobe.dll",Uninstall /Get1noarp
mRunOnce: [SpybotDeletingC3094] cmd /c del "c:\windows\SchedLgU.Txt"
mRunOnce: [SpybotDeletingA6511] command /c del "c:\windows\SchedLgU.Txt"
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\SHORTC~1.LNK -
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1226583123390
DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: igfxcui - igfxdev.dll
SSODL: InternetConnection - {B1A95BA3-3827-4F63-A75E-009E2B48A48F} - No File

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\znic94gk.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ae/
FF - component: c:\program files\nokia\nokia pc suite 7\bkmrksync\components\BkMrkExt.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-30 149352]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-30 149352]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-30 149352]
R2 ModemProtectorService;Modem Protector service;c:\program files\etisalat modem protector\ModemProtectorService.exe [2006-5-22 143360]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-2-27 101936]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090821.022\NAVENG.SYS [2009-8-22 87888]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090821.022\NAVEX15.SYS [2009-8-22 875728]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2007-8-30 23888]
S3 Symantec Core LC;Symantec Core LC;c:\progra~1\common~1\symant~1\ccpd-lc\symlcsvc.exe [2008-11-9 1251720]

=============== Created Last 30 ================

2009-08-22 07:14 73,728 a------- c:\windows\system32\javacpl.cpl
2009-08-22 07:03 <DIR> --d----- c:\windows\system32\appmgmt
2009-08-22 06:57 <DIR> --d----- c:\documents and settings\administrator\.SunDownloadManager
2009-08-21 10:19 228,864 a------- c:\windows\PEV.exe
2009-08-21 10:19 161,792 a------- c:\windows\SWREG.exe
2009-08-21 10:19 98,816 a------- c:\windows\sed.exe
2009-08-15 11:10 <DIR> --d----- c:\docume~1\admini~1\applic~1\Malwarebytes
2009-08-15 11:10 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-15 11:10 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-15 11:10 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-08-15 11:10 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-08-07 13:46 <DIR> --d----- c:\docume~1\admini~1\applic~1\Symantec
2009-08-01 19:58 <DIR> -cd----- c:\windows\system32\dllcache\cache
2009-08-01 19:52 <DIR> a-dshr-- C:\cmdcons
2009-07-29 05:35 <DIR> --d----- c:\program files\Trend Micro
2009-07-28 05:47 82 a------- c:\windows\wininit.ini

==================== Find3M ====================

2009-08-22 07:13 411,368 a------- c:\windows\system32\deploytk.dll
2009-07-20 12:54 737,280 a------- c:\windows\iun6002.exe
2009-07-19 22:37 98,304 a------- c:\windows\system32\CmdLineExt.dll

============= FINISH: 7:32:34.75 ===============



[U]Combofix log

*-*-*-*-*-*-*-*-*-*-*-*-*-*-*

ComboFix 09-08-21.01 - Administrator 22/08/2009 6:25.4.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.502.178 [GMT 4:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
AV: Norton AntiVirus Online *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton AntiVirus Online *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

D:\dds.pif

.
((((((((((((((((((((((((( Files Created from 2009-07-22 to 2009-08-22 )))))))))))))))))))))))))))))))
.

2009-08-15 07:10 . 2009-08-15 07:10 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-08-15 07:10 . 2009-08-03 09:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-15 07:10 . 2009-08-15 07:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-15 07:10 . 2009-08-03 09:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-15 07:10 . 2009-08-15 07:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-07 09:46 . 2009-08-07 09:46 -------- d-----w- c:\documents and settings\Administrator\Application Data\Symantec
2009-07-29 01:35 . 2009-07-29 01:35 -------- d-----w- c:\program files\Trend Micro
2009-07-29 01:34 . 2009-07-29 01:34 -------- d-----w- c:\program files\ERUNT
2009-07-27 01:23 . 2009-07-28 01:24 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-22 02:22 . 2008-11-09 11:18 -------- d-----w- c:\program files\Etisalat Modem Protector
2009-07-20 19:00 . 2008-10-09 17:07 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-20 08:54 . 2009-07-20 08:54 -------- d-----w- c:\program files\BFG
2009-07-20 08:54 . 2009-07-20 08:54 737280 ----a-w- c:\windows\iun6002.exe
2009-07-19 18:41 . 2009-07-18 15:57 -------- d-----w- c:\program files\GameShadow
2009-07-19 18:37 . 2009-07-19 18:37 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-07-17 14:32 . 2008-11-09 16:08 -------- d-----w- c:\program files\DivX
2009-07-17 14:31 . 2009-04-10 09:54 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-07-16 02:00 . 2008-11-09 11:40 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-07-16 01:57 . 2009-07-16 01:52 -------- d-----w- c:\program files\DIFX
2009-07-16 01:56 . 2009-07-16 01:56 -------- d-----w- c:\program files\Common Files\PCSuite
2009-07-16 01:56 . 2009-02-05 02:02 -------- d-----w- c:\program files\Common Files\Nokia
2009-07-16 01:56 . 2008-12-18 14:11 -------- d-----w- c:\program files\Nokia
2009-07-16 01:52 . 2009-07-16 01:52 -------- d-----w- c:\program files\PC Connectivity Solution
2009-07-16 01:49 . 2009-07-16 01:49 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\pcswpcsi.exe
2009-07-16 01:49 . 2009-07-16 01:49 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstCCD.exe
2009-07-16 01:49 . 2009-07-16 01:49 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-07-16 01:49 . 2009-07-16 01:49 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCS.exe
2009-07-16 01:48 . 2008-12-18 14:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-07-16 01:48 . 2009-07-16 01:50 33773208 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Nokia_PC_Suite_7_1_30_9_eng.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-08-01_15.57.51 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-21 06:12 . 2009-08-21 06:12 16384 c:\windows\Temp\Perflib_Perfdata_76c.dat
+ 2009-08-15 08:07 . 2005-10-20 08:02 163328 c:\windows\ERDNT\15-08-2009\ERDNT.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-11-14 4608]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-06-25 1414144]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 52256]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"Etisalat Modem Protector"="c:\program files\Etisalat Modem Protector\Modem Protector.exe" [2006-06-05 446464]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton AntiVirus\osCheck.exe" [2007-08-30 714608]
"SpybotSnD"="c:\program files\Spybot - Search & Destroy\SpybotSD.exe" [2008-07-07 4891472]
"Media Codec Update Service"="c:\program files\Essentials Codec Pack\WECPUpdate.exe" [2009-01-25 196608]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\Symantec Shared\\NPC\\npcLUStb.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [8/30/2007 4:45 AM 149352]
R2 ModemProtectorService;Modem Protector service;c:\program files\Etisalat Modem Protector\ModemProtectorService.exe [5/22/2006 5:33 PM 143360]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/27/2009 6:35 AM 101936]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [8/30/2007 4:46 AM 23888]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [11/13/2008 5:24 PM 33752]

--- Other Services/Drivers In Memory ---

*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder

2009-08-22 c:\windows\Tasks\Norton AntiVirus Online - Run Full System Scan - Administrator.job
- c:\program files\Norton AntiVirus\Navw32.exe [2007-08-30 00:47]

2009-08-21 c:\windows\Tasks\Norton AntiVirus Online - Weekly Scan - Administrator.job
- c:\program files\Norton AntiVirus\Navw32.exe [2007-08-30 00:47]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\znic94gk.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ae/
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-22 06:30
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\mc21.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1292428093-651377827-725345543-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{ECCEE0F8-2389-DBF0-CD44-27A089191EA6}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
Completion time: 2009-08-22 6:32
ComboFix-quarantined-files.txt 2009-08-22 02:32
ComboFix2.txt 2009-08-21 06:23
ComboFix3.txt 2009-08-02 02:06
ComboFix4.txt 2009-08-01 15:59

Pre-Run: 2,348,998,656 bytes free
Post-Run: 2,304,159,744 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
142 --- E O F --- 2009-01-18 12:53

Blade81
2009-08-22, 09:27
Hi,

Let's replace online scanner part with this one:

Download the latest version of Kaspersky Virus Removal Tool (ftp://downloads2.kaspersky-labs.com/devbuilds/AVPTool)

* Close all other applications and double-click and run the installer.
* When AVPTool starts, select all the scanable items except for CD-ROM drives and click the Scan button.
* If malware is detected, don't remove anything.
* After the scan finishes, don't neutralize anything.
* In the Scan window click the Reports button and select Save to file.
* Name the report AVPT.txt, and save it to the Desktop.
* Close AVPTool.
* You will be prompted if you want to uninstall the program; click Yes.
* You will then be prompted that to complete the uninstallation, the computer must be restarted. Select Yes to restart the system.
* Copy and paste the first part of the report (Detected) that you saved in your next reply. Do not include the longer list marked Events.

Elvis316
2009-08-22, 09:55
Tried access the Kaspersky ftp link ... but an error message pops up

"Windows cannot access this folder. Make sure you typed the file name correctly and that you have permission to access the folder

A connection with the server could not be established."

Blade81
2009-08-22, 10:27
Seems that AVP tool is offline. Maybe this one works

* Go here (http://www.eset.eu/online-scanner) to run an online scanner from ESET.
Tick the box next to YES, I accept the Terms of Use.
Click Start
When asked, allow the activex control to install
Click Start
Make sure that the option Remove found threats is UNchecked and the option Scan unwanted applications is checkmarked.
Click Scan
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
Copy and paste that log as a reply to this topic.

Elvis316
2009-08-22, 10:36
Nothing !!! :sad:

Clicked on "I accep terms" and then the screen goes blank ... no ActiveX control install comes up.

Blade81
2009-08-22, 10:41
Hi,

Try to get AVP tool here (http://devbuilds.kaspersky-labs.com/devbuilds/AVPTool/). And follow related instructions a few posts earlier (if you are able to access the site).

Elvis316
2009-08-22, 10:43
Unable to get on the website :sad:

Blade81
2009-08-22, 10:46
Try to access the site from here (http://anonymouse.org/).

Elvis316
2009-08-22, 10:48
Blocked by ISP

Blade81
2009-08-22, 11:01
Hi,

Upload these files to Virustotal (http://www.virustotal.com) and post back the results or links to the results:
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe


Disable Spybot's TeaTimer to make sure it won't interfere with fixes. You can re-enable it when you're clean again:
Run Spybot-S&D in Advanced Mode
If it is not already set to do this, go to the Mode menu
select
Advanced Mode

On the left hand side, click on Tools
Then click on the Resident icon in the list
Uncheck
Resident TeaTimer
and OK any prompts.
Restart your computer


Open notepad and copy/paste the text in the quotebox below into it:



DDS::
SSODL: InternetConnection - {B1A95BA3-3827-4F63-A75E-009E2B48A48F} - No File

Regnull::
[HKEY_USERS\S-1-5-21-1292428093-651377827-725345543-500\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{ECCEE0F8-2389-DBF0-CD44-27A089191EA6}*]



Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log & fresh dds.txt log. Still problem with Spybot updates?

Elvis316
2009-08-22, 11:26
Results from Virustotal

winlogon.exe
analisis/45377cb8e9f0120f836fc8261c711f7dbf7199117afb3652ebf100d5f0429b1e-1250907547

services.exe
analisis/22750b3829133d1d4bb3ce2fa6247be2373b5d15a6ed1c8a71673aa1ce7d9530-1250854410

lsass.exe
analisis/f7794b5d12dc5d820a162850f4388e2aa80426ad07cb221799cf941c682ab501-1250907687

svchost.exe
analisis/2910ebc692d833d949bfd56059e8106d324a276d5f165f874f3fb1b6c613cdd5-1250921492



Combofix log


ComboFix 09-08-21.02 - Administrator 22/08/2009 13:15.5.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.502.212 [GMT 4:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFscript.txt
AV: Norton AntiVirus Online *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton AntiVirus Online *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
/wow section - STAGE 7


((((((((((((((((((((((((( Files Created from 2009-07-22 to 2009-08-22 )))))))))))))))))))))))))))))))
.

2009-08-22 03:12 . 2009-08-22 03:12 -------- d-----w- c:\program files\Java
2009-08-22 02:57 . 2009-08-22 03:02 -------- d-----w- c:\documents and settings\Administrator\.SunDownloadManager
2009-08-15 07:10 . 2009-08-15 07:10 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-08-15 07:10 . 2009-08-03 09:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-15 07:10 . 2009-08-15 07:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-15 07:10 . 2009-08-03 09:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-15 07:10 . 2009-08-15 07:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-07 09:46 . 2009-08-07 09:46 -------- d-----w- c:\documents and settings\Administrator\Application Data\Symantec
2009-07-29 01:35 . 2009-07-29 01:35 -------- d-----w- c:\program files\Trend Micro
2009-07-29 01:34 . 2009-07-29 01:34 -------- d-----w- c:\program files\ERUNT
2009-07-27 01:23 . 2009-07-28 01:24 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-22 09:12 . 2008-11-09 11:18 -------- d-----w- c:\program files\Etisalat Modem Protector
2009-08-22 03:13 . 2009-03-26 07:48 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-22 03:07 . 2008-11-13 13:24 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-08-22 03:07 . 2008-11-13 13:24 -------- d-----w- c:\program files\NOS
2009-07-20 19:00 . 2008-10-09 17:07 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-20 08:54 . 2009-07-20 08:54 -------- d-----w- c:\program files\BFG
2009-07-20 08:54 . 2009-07-20 08:54 737280 ----a-w- c:\windows\iun6002.exe
2009-07-19 18:41 . 2009-07-18 15:57 -------- d-----w- c:\program files\GameShadow
2009-07-19 18:37 . 2009-07-19 18:37 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-07-17 14:32 . 2008-11-09 16:08 -------- d-----w- c:\program files\DivX
2009-07-17 14:31 . 2009-04-10 09:54 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-07-16 02:00 . 2008-11-09 11:40 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-07-16 01:57 . 2009-07-16 01:52 -------- d-----w- c:\program files\DIFX
2009-07-16 01:56 . 2009-07-16 01:56 -------- d-----w- c:\program files\Common Files\PCSuite
2009-07-16 01:56 . 2009-02-05 02:02 -------- d-----w- c:\program files\Common Files\Nokia
2009-07-16 01:56 . 2008-12-18 14:11 -------- d-----w- c:\program files\Nokia
2009-07-16 01:52 . 2009-07-16 01:52 -------- d-----w- c:\program files\PC Connectivity Solution
2009-07-16 01:49 . 2009-07-16 01:49 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\pcswpcsi.exe
2009-07-16 01:49 . 2009-07-16 01:49 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstCCD.exe
2009-07-16 01:49 . 2009-07-16 01:49 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-07-16 01:49 . 2009-07-16 01:49 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCS.exe
2009-07-16 01:48 . 2008-12-18 14:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-07-16 01:48 . 2009-07-16 01:50 33773208 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Nokia_PC_Suite_7_1_30_9_eng.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-08-01_15.57.51 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-22 03:14 . 2009-08-22 03:14 16384 c:\windows\Temp\Perflib_Perfdata_ffc.dat
+ 2008-11-09 16:08 . 2009-08-22 02:49 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
- 2008-11-09 16:08 . 2009-06-11 19:27 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-05-05 15:38 . 2009-08-22 02:46 88589 c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2009-07-18 03:21 . 2009-07-18 03:21 257440 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-07-18 03:12 . 2009-07-18 03:12 257440 c:\windows\system32\Macromed\Flash\FlashUtil10c.exe
+ 2009-08-22 03:14 . 2009-08-22 03:13 149280 c:\windows\system32\javaws.exe
+ 2009-08-22 03:14 . 2009-08-22 03:13 145184 c:\windows\system32\javaw.exe
+ 2009-08-22 03:14 . 2009-08-22 03:13 145184 c:\windows\system32\java.exe
+ 2009-08-22 02:43 . 2009-08-22 02:43 802304 c:\windows\Installer\4668ea6.msi
+ 2009-08-22 02:43 . 2009-08-22 02:43 295606 c:\windows\Installer\{AC76BA86-7AD7-5464-3428-900000000004}\ARPPRODUCTICON.exe
+ 2009-08-15 08:07 . 2005-10-20 08:02 163328 c:\windows\ERDNT\15-08-2009\ERDNT.EXE
+ 2009-06-12 09:05 . 2009-06-12 09:05 296336 c:\windows\Downloaded Program Files\rufsi.dll
+ 2009-07-18 03:21 . 2009-07-18 03:21 3883424 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2009-08-22 03:13 . 2009-08-22 03:13 1757696 c:\windows\Installer\5c435.msi
+ 2009-08-03 13:34 . 2009-08-03 13:34 1697792 c:\windows\Installer\4668e9f.msp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-11-14 4608]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 52256]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"Etisalat Modem Protector"="c:\program files\Etisalat Modem Protector\Modem Protector.exe" [2006-06-05 446464]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton AntiVirus\osCheck.exe" [2007-08-30 714608]
"SpybotSnD"="c:\program files\Spybot - Search & Destroy\SpybotSD.exe" [2008-07-07 4891472]
"Media Codec Update Service"="c:\program files\Essentials Codec Pack\WECPUpdate.exe" [2009-01-25 196608]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\Symantec Shared\\NPC\\npcLUStb.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [8/30/2007 4:45 AM 149352]
R2 ModemProtectorService;Modem Protector service;c:\program files\Etisalat Modem Protector\ModemProtectorService.exe [5/22/2006 5:33 PM 143360]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/27/2009 6:35 AM 101936]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [8/30/2007 4:46 AM 23888]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - JAVAQUICKSTARTERSERVICE
*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder

2009-08-22 c:\windows\Tasks\Norton AntiVirus Online - Run Full System Scan - Administrator.job
- c:\program files\Norton AntiVirus\Navw32.exe [2007-08-30 00:47]

2009-08-21 c:\windows\Tasks\Norton AntiVirus Online - Weekly Scan - Administrator.job
- c:\program files\Norton AntiVirus\Navw32.exe [2007-08-30 00:47]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\znic94gk.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ae/
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-22 13:19
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\mc23.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2612)
c:\program files\Microsoft Office\OFFICE11\msohev.dll
c:\program files\Common Files\Symantec Shared\NPC\2.0\NPCEXT.dll
.
Completion time: 2009-08-22 13:22
ComboFix-quarantined-files.txt 2009-08-22 09:21
ComboFix2.txt 2009-08-22 02:32
ComboFix3.txt 2009-08-21 06:23
ComboFix4.txt 2009-08-02 02:06
ComboFix5.txt 2009-08-22 09:14

Pre-Run: 2,213,855,232 bytes free
Post-Run: 2,182,463,488 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
180 --- E O F --- 2009-01-18 12:53



DDS.txt


DDS (Ver_09-07-30.01) - NTFSx86
Run by Administrator at 13:23:08.78 on 22/08/2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.502.132 [GMT 4:00]

AV: Norton AntiVirus Online *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton AntiVirus Online *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Etisalat Modem Protector\Modem Protector.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Etisalat Modem Protector\ModemProtectorService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\dds.scr

============== Pseudo HJT Report ===============

uStart Page = about:blank
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll
uRun: [AlcoholAutomount] "c:\program files\alcohol soft\alcohol 120\axcmd.exe" /automount
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRunOnce: [SpybotDeletingB951] command /c del "c:\windows\SchedLgU.Txt"
uRunOnce: [SpybotDeletingD2868] cmd /c del "c:\windows\SchedLgU.Txt"
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe"
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [Etisalat Modem Protector] c:\program files\etisalat modem protector\Modem Protector.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [osCheck] "c:\program files\norton antivirus\osCheck.exe"
mRun: [SpybotSnD] "c:\program files\spybot - search & destroy\SpybotSD.exe"
mRun: [Media Codec Update Service] c:\program files\essentials codec pack\WECPUpdate.exe -s
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRunOnce: [SpybotDeletingC3094] cmd /c del "c:\windows\SchedLgU.Txt"
mRunOnce: [SpybotDeletingA6511] command /c del "c:\windows\SchedLgU.Txt"
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\SHORTC~1.LNK -
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1226583123390
DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: igfxcui - igfxdev.dll
SSODL: InternetConnection - {B1A95BA3-3827-4F63-A75E-009E2B48A48F} - No File

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\znic94gk.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ae/
FF - component: c:\program files\nokia\nokia pc suite 7\bkmrksync\components\BkMrkExt.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-30 149352]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-30 149352]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-30 149352]
R2 ModemProtectorService;Modem Protector service;c:\program files\etisalat modem protector\ModemProtectorService.exe [2006-5-22 143360]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-2-27 101936]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090821.039\NAVENG.SYS [2009-8-22 87888]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090821.039\NAVEX15.SYS [2009-8-22 875728]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2007-8-30 23888]
S3 Symantec Core LC;Symantec Core LC;c:\progra~1\common~1\symant~1\ccpd-lc\symlcsvc.exe [2008-11-9 1251720]

=============== Created Last 30 ================

2009-08-22 07:14 73,728 a------- c:\windows\system32\javacpl.cpl
2009-08-22 07:03 <DIR> --d----- c:\windows\system32\appmgmt
2009-08-22 06:57 <DIR> --d----- c:\documents and settings\administrator\.SunDownloadManager
2009-08-21 10:19 228,864 a------- c:\windows\PEV.exe
2009-08-21 10:19 161,792 a------- c:\windows\SWREG.exe
2009-08-21 10:19 98,816 a------- c:\windows\sed.exe
2009-08-15 11:10 <DIR> --d----- c:\docume~1\admini~1\applic~1\Malwarebytes
2009-08-15 11:10 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-15 11:10 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-15 11:10 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-08-15 11:10 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-08-07 13:46 <DIR> --d----- c:\docume~1\admini~1\applic~1\Symantec
2009-08-01 19:58 <DIR> -cd----- c:\windows\system32\dllcache\cache
2009-08-01 19:52 <DIR> a-dshr-- C:\cmdcons
2009-07-29 05:35 <DIR> --d----- c:\program files\Trend Micro
2009-07-28 05:47 82 a------- c:\windows\wininit.ini

==================== Find3M ====================

2009-08-22 07:13 411,368 a------- c:\windows\system32\deploytk.dll
2009-07-20 12:54 737,280 a------- c:\windows\iun6002.exe
2009-07-19 22:37 98,304 a------- c:\windows\system32\CmdLineExt.dll

============= FINISH: 13:23:33.81 ===============

Blade81
2009-08-22, 16:59
Hi,

Were there any hits for those four files in Virustotal scan? Those you posted don't have link to the results included.

Also, you didn't disable TeaTimer before running ComboFix. Please disable it and then run ComboFix again with that script. Have Norton disabled too.

Elvis316
2009-08-24, 04:00
Ohh ... Sorry about that. I think now the links should work.
There were hits on the winlogon.exe and lsass.exe

winlogon.exe
http://www.virustotal.com/analisis/45377cb8e9f0120f836fc8261c711f7dbf7199117afb3652ebf100d5f0429b1e-1250907547

services.exe
http://www.virustotal.com/analisis/22750b3829133d1d4bb3ce2fa6247be2373b5d15a6ed1c8a71673aa1ce7d9530-1250854410

lsass.exe
http://www.virustotal.com/analisis/f7794b5d12dc5d820a162850f4388e2aa80426ad07cb221799cf941c682ab501-1250907687

svchost.exe
http://www.virustotal.com/analisis/2910ebc692d833d949bfd56059e8106d324a276d5f165f874f3fb1b6c613cdd5-1250921492



Comboxfix Log

ComboFix 09-08-22.06 - Administrator 24/08/2009 5:46.6.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.502.226 [GMT 4:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFscript.txt
AV: Norton AntiVirus Online *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton AntiVirus Online *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-07-24 to 2009-08-24 )))))))))))))))))))))))))))))))
.

2009-08-22 03:12 . 2009-08-22 03:12 -------- d-----w- c:\program files\Java
2009-08-22 02:57 . 2009-08-22 03:02 -------- d-----w- c:\documents and settings\Administrator\.SunDownloadManager
2009-08-15 07:10 . 2009-08-15 07:10 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-08-15 07:10 . 2009-08-03 09:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-15 07:10 . 2009-08-15 07:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-15 07:10 . 2009-08-03 09:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-15 07:10 . 2009-08-15 07:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-07 09:46 . 2009-08-07 09:46 -------- d-----w- c:\documents and settings\Administrator\Application Data\Symantec
2009-07-29 01:35 . 2009-07-29 01:35 -------- d-----w- c:\program files\Trend Micro
2009-07-29 01:34 . 2009-07-29 01:34 -------- d-----w- c:\program files\ERUNT
2009-07-27 01:23 . 2009-07-28 01:24 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-22 09:12 . 2008-11-09 11:18 -------- d-----w- c:\program files\Etisalat Modem Protector
2009-08-22 03:13 . 2009-03-26 07:48 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-22 03:07 . 2008-11-13 13:24 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-08-22 03:07 . 2008-11-13 13:24 -------- d-----w- c:\program files\NOS
2009-07-20 19:00 . 2008-10-09 17:07 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-20 08:54 . 2009-07-20 08:54 -------- d-----w- c:\program files\BFG
2009-07-20 08:54 . 2009-07-20 08:54 737280 ----a-w- c:\windows\iun6002.exe
2009-07-19 18:41 . 2009-07-18 15:57 -------- d-----w- c:\program files\GameShadow
2009-07-19 18:37 . 2009-07-19 18:37 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-07-17 14:32 . 2008-11-09 16:08 -------- d-----w- c:\program files\DivX
2009-07-17 14:31 . 2009-04-10 09:54 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-07-16 02:00 . 2008-11-09 11:40 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-07-16 01:57 . 2009-07-16 01:52 -------- d-----w- c:\program files\DIFX
2009-07-16 01:56 . 2009-07-16 01:56 -------- d-----w- c:\program files\Common Files\PCSuite
2009-07-16 01:56 . 2009-02-05 02:02 -------- d-----w- c:\program files\Common Files\Nokia
2009-07-16 01:56 . 2008-12-18 14:11 -------- d-----w- c:\program files\Nokia
2009-07-16 01:52 . 2009-07-16 01:52 -------- d-----w- c:\program files\PC Connectivity Solution
2009-07-16 01:49 . 2009-07-16 01:49 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\pcswpcsi.exe
2009-07-16 01:49 . 2009-07-16 01:49 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstCCD.exe
2009-07-16 01:49 . 2009-07-16 01:49 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-07-16 01:49 . 2009-07-16 01:49 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCS.exe
2009-07-16 01:48 . 2008-12-18 14:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-07-16 01:48 . 2009-07-16 01:50 33773208 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Nokia_PC_Suite_7_1_30_9_eng.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-08-01_15.57.51 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-22 03:14 . 2009-08-22 03:14 16384 c:\windows\Temp\Perflib_Perfdata_ffc.dat
+ 2008-11-09 16:08 . 2009-08-22 02:49 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
- 2008-11-09 16:08 . 2009-06-11 19:27 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-05-05 15:38 . 2009-08-22 02:46 88589 c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2009-07-18 03:21 . 2009-07-18 03:21 257440 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-07-18 03:12 . 2009-07-18 03:12 257440 c:\windows\system32\Macromed\Flash\FlashUtil10c.exe
+ 2009-08-22 03:14 . 2009-08-22 03:13 149280 c:\windows\system32\javaws.exe
+ 2009-08-22 03:14 . 2009-08-22 03:13 145184 c:\windows\system32\javaw.exe
+ 2009-08-22 03:14 . 2009-08-22 03:13 145184 c:\windows\system32\java.exe
+ 2009-08-22 02:43 . 2009-08-22 02:43 802304 c:\windows\Installer\4668ea6.msi
+ 2009-08-22 02:43 . 2009-08-22 02:43 295606 c:\windows\Installer\{AC76BA86-7AD7-5464-3428-900000000004}\ARPPRODUCTICON.exe
+ 2009-08-15 08:07 . 2005-10-20 08:02 163328 c:\windows\ERDNT\15-08-2009\ERDNT.EXE
+ 2009-06-12 09:05 . 2009-06-12 09:05 296336 c:\windows\Downloaded Program Files\rufsi.dll
+ 2009-07-18 03:21 . 2009-07-18 03:21 3883424 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2009-08-22 03:13 . 2009-08-22 03:13 1757696 c:\windows\Installer\5c435.msi
+ 2009-08-03 13:34 . 2009-08-03 13:34 1697792 c:\windows\Installer\4668e9f.msp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-11-14 4608]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-03-14 71216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-08 52256]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"Etisalat Modem Protector"="c:\program files\Etisalat Modem Protector\Modem Protector.exe" [2006-06-05 446464]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton AntiVirus\osCheck.exe" [2007-08-30 714608]
"SpybotSnD"="c:\program files\Spybot - Search & Destroy\SpybotSD.exe" [2008-07-07 4891472]
"Media Codec Update Service"="c:\program files\Essentials Codec Pack\WECPUpdate.exe" [2009-01-25 196608]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\Symantec Shared\\NPC\\npcLUStb.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [8/30/2007 4:45 AM 149352]
R2 ModemProtectorService;Modem Protector service;c:\program files\Etisalat Modem Protector\ModemProtectorService.exe [5/22/2006 5:33 PM 143360]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/27/2009 6:35 AM 101936]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [8/30/2007 4:46 AM 23888]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - JAVAQUICKSTARTERSERVICE
*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder

2009-08-22 c:\windows\Tasks\Norton AntiVirus Online - Run Full System Scan - Administrator.job
- c:\program files\Norton AntiVirus\Navw32.exe [2007-08-30 00:47]

2009-08-21 c:\windows\Tasks\Norton AntiVirus Online - Weekly Scan - Administrator.job
- c:\program files\Norton AntiVirus\Navw32.exe [2007-08-30 00:47]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\znic94gk.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ae/
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-24 05:52
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\mc23.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2560)
c:\program files\Microsoft Office\OFFICE11\msohev.dll
c:\program files\Common Files\Symantec Shared\NPC\2.0\NPCEXT.dll
.
Completion time: 2009-08-24 5:54
ComboFix-quarantined-files.txt 2009-08-24 01:54
ComboFix2.txt 2009-08-22 09:22
ComboFix3.txt 2009-08-22 02:32
ComboFix4.txt 2009-08-21 06:23
ComboFix5.txt 2009-08-24 01:45

Pre-Run: 2,128,572,416 bytes free
Post-Run: 2,103,812,096 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
179 --- E O F --- 2009-01-18 12:53

Blade81
2009-08-24, 07:23
Post a fresh dds log too, please. Still issues with Spybot? If you do, uninstall the version you have and then get the one here (http://www.safer-networking.org/en/mirrors/index.html).

Elvis316
2009-08-24, 11:35
Dont want to unistall spybot as I cannot download it from website.
I still cannot access safer-networking website.

DDS.log


DDS (Ver_09-07-30.01) - NTFSx86
Run by Administrator at 13:33:31.04 on 24/08/2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.502.141 [GMT 4:00]

AV: Norton AntiVirus Online *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton AntiVirus Online *enabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Etisalat Modem Protector\Modem Protector.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Etisalat Modem Protector\ModemProtectorService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\dds.scr

============== Pseudo HJT Report ===============

uStart Page = about:blank
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll
uRun: [AlcoholAutomount] "c:\program files\alcohol soft\alcohol 120\axcmd.exe" /automount
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe"
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [Etisalat Modem Protector] c:\program files\etisalat modem protector\Modem Protector.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [osCheck] "c:\program files\norton antivirus\osCheck.exe"
mRun: [SpybotSnD] "c:\program files\spybot - search & destroy\SpybotSD.exe"
mRun: [Media Codec Update Service] c:\program files\essentials codec pack\WECPUpdate.exe -s
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\SHORTC~1.LNK -
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1226583123390
DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: igfxcui - igfxdev.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\znic94gk.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ae/
FF - component: c:\program files\nokia\nokia pc suite 7\bkmrksync\components\BkMrkExt.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-30 149352]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-30 149352]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\common files\symantec shared\CCSVCHST.EXE [2007-8-30 149352]
R2 ModemProtectorService;Modem Protector service;c:\program files\etisalat modem protector\ModemProtectorService.exe [2006-5-22 143360]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-2-27 101936]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090823.021\NAVENG.SYS [2009-8-24 87888]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090823.021\NAVEX15.SYS [2009-8-24 875728]
R3 Symantec Core LC;Symantec Core LC;c:\progra~1\common~1\symant~1\ccpd-lc\symlcsvc.exe [2008-11-9 1251720]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2007-8-30 23888]

=============== Created Last 30 ================

2009-08-22 07:14 73,728 a------- c:\windows\system32\javacpl.cpl
2009-08-22 07:03 <DIR> --d----- c:\windows\system32\appmgmt
2009-08-22 06:57 <DIR> --d----- c:\documents and settings\administrator\.SunDownloadManager
2009-08-21 10:19 229,376 a------- c:\windows\PEV.exe
2009-08-21 10:19 161,792 a------- c:\windows\SWREG.exe
2009-08-21 10:19 98,816 a------- c:\windows\sed.exe
2009-08-15 11:10 <DIR> --d----- c:\docume~1\admini~1\applic~1\Malwarebytes
2009-08-15 11:10 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-15 11:10 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-15 11:10 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-08-15 11:10 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-08-07 13:46 <DIR> --d----- c:\docume~1\admini~1\applic~1\Symantec
2009-08-01 19:58 <DIR> -cd----- c:\windows\system32\dllcache\cache
2009-08-01 19:52 <DIR> a-dshr-- C:\cmdcons
2009-07-29 05:35 <DIR> --d----- c:\program files\Trend Micro
2009-07-28 05:47 82 a------- c:\windows\wininit.ini

==================== Find3M ====================

2009-08-22 07:13 411,368 a------- c:\windows\system32\deploytk.dll
2009-07-20 12:54 737,280 a------- c:\windows\iun6002.exe
2009-07-19 22:37 98,304 a------- c:\windows\system32\CmdLineExt.dll

============= FINISH: 13:34:09.14 ===============

Blade81
2009-08-24, 17:34
Hi,

Do you own any other systems? If you do, are you able to access Safer Networking on those?

If you don't have any other systems, could you take your system to your friend's place for example to see if you're able to access the site there?

Elvis316
2009-08-25, 06:01
Do you want me to download Spybot from another PC and install here ????

No, I dont own any other systems.
I will try and take it to a friends place and see if it works there.

Blade81
2009-08-25, 07:29
I just want to find out if it's network or computer specific issue. Trying the system in your friend's place may help to limit possible reasons. Test also accessing Safer Networking site from your friend's system.

Elvis316
2009-08-29, 16:50
Hey ... took my PC to a freinds place and tried accessing the safer-networking website ... and it works !!!! Uninstalled and downloaded the latest Spybot and updates. Tried access other sites too and it was all working fine.

So I guess ... its a networking problem !!!

Now what ??

Blade81
2009-08-29, 16:56
Hi,

What is your internet service provider and does your friend have that too?

Elvis316
2009-08-30, 03:45
Intenret service provider is Etisalat and my friend also uses the same.
It the only service provider here.

And he uses the same modem too.

Blade81
2009-08-30, 10:20
Let's see what kind of results we get with this..

Please run Notepad (start > All Programs > Accessories > Notepad) and copy and paste the text in the quote box into a new file:



@echo off
>Log1.txt (
ipconfig /all
nslookup google.com
ping -n 2 google.com
route print
)
start Log1.txt
del %0



Go to the File menu at the top of the Notepad and select Save as.
Select save in: desktop
Fill in File name: test.bat
Save as type: All file types (*.*)
Click save.
Close the Notepad.
Locate and double-click tast.bat on the desktop.
A notepad opens, copy and paste the content it (log1.txt) to your reply.

Elvis316
2009-08-30, 10:29
Windows IP Configuration



Host Name . . . . . . . . . . . . : etc

Primary Dns Suffix . . . . . . . :

Node Type . . . . . . . . . . . . : Unknown

IP Routing Enabled. . . . . . . . : No

WINS Proxy Enabled. . . . . . . . : No



Ethernet adapter Local Area Connection:



Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : Intel(R) PRO/100 VE Network Connection

Physical Address. . . . . . . . . : 00-16-76-6D-B6-7A

Dhcp Enabled. . . . . . . . . . . : Yes

Autoconfiguration Enabled . . . . : Yes

IP Address. . . . . . . . . . . . : 192.168.1.4

Subnet Mask . . . . . . . . . . . : 255.255.255.0

IP Address. . . . . . . . . . . . : fe80::216:76ff:fe6d:b67a%4

Default Gateway . . . . . . . . . : 192.168.1.1

DHCP Server . . . . . . . . . . . : 192.168.1.1

DNS Servers . . . . . . . . . . . : 192.168.1.1

fec0:0:0:ffff::1%1

fec0:0:0:ffff::2%1

fec0:0:0:ffff::3%1

Lease Obtained. . . . . . . . . . : 30 August 2009 12:00:51

Lease Expires . . . . . . . . . . : 30 August 2009 13:00:51



Tunnel adapter Teredo Tunneling Pseudo-Interface:



Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface

Physical Address. . . . . . . . . : 00-00-FB-E9-A3-9E-97-37

Dhcp Enabled. . . . . . . . . . . : No

IP Address. . . . . . . . . . . . : 2001:0:4137:9e50:0:fbe9:a39e:9737

IP Address. . . . . . . . . . . . : fe80::ffff:ffff:fffd%5

Default Gateway . . . . . . . . . : ::

NetBIOS over Tcpip. . . . . . . . : Disabled



Tunnel adapter Automatic Tunneling Pseudo-Interface:



Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : Automatic Tunneling Pseudo-Interface

Physical Address. . . . . . . . . : C0-A8-01-04

Dhcp Enabled. . . . . . . . . . . : No

IP Address. . . . . . . . . . . . : fe80::5efe:192.168.1.4%2

Default Gateway . . . . . . . . . :

DNS Servers . . . . . . . . . . . : fec0:0:0:ffff::1%1

fec0:0:0:ffff::2%1

fec0:0:0:ffff::3%1

NetBIOS over Tcpip. . . . . . . . : Disabled

Server: mygateway1.ar7
Address: 192.168.1.1

Name: google.com
Addresses: 74.125.45.100, 74.125.67.100, 74.125.127.100



Pinging google.com [74.125.45.100] with 32 bytes of data:



Reply from 74.125.45.100: bytes=32 time=301ms TTL=49

Reply from 74.125.45.100: bytes=32 time=330ms TTL=49



Ping statistics for 74.125.45.100:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 301ms, Maximum = 330ms, Average = 315ms

===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...00 16 76 6d b6 7a ...... Intel(R) PRO/100 VE Network Connection - Packet Scheduler Miniport
===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.4 20
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
192.168.1.0 255.255.255.0 192.168.1.4 192.168.1.4 20
192.168.1.4 255.255.255.255 127.0.0.1 127.0.0.1 20
192.168.1.255 255.255.255.255 192.168.1.4 192.168.1.4 20
224.0.0.0 240.0.0.0 192.168.1.4 192.168.1.4 20
255.255.255.255 255.255.255.255 192.168.1.4 192.168.1.4 1
Default Gateway: 192.168.1.1
===========================================================================
Persistent Routes:
None

Blade81
2009-08-30, 10:52
That looked ok. Your operator seems to practice some kind of Internet censoring and I believe it blocks Spybot also. Unfortunately, there's not much I can do to help with that :sad:. Can't either explain how things work from your friend's place.

Blade81
2009-09-06, 22:11
Due to inactivity, this thread will now be closed.

Note:If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread. Please do not add any logs that might have been requested in the closed topic, you would be starting fresh.

If it has been less than four days since your last response and you need the thread re-opened, please send me or MOD a private message (pm). A valid, working link to the closed topic is required.