ranger200
2009-09-09, 00:03
Hi,
according to Spybot s&d, i've been infected with this virus, and Spybot can't remove it.
I have looked in this forum and understand I should generate the 2 following logfiles (HJT and GMER)
Any help highly appreciated, thank you!
--- HJT START ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:52:37, on 08-09-2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\win\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Creative\Shared Files\CTAudSvc.exe
C:\win\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\svchost.exe
C:\win\AVG\AVG8\avgrsx.exe
C:\win\AVG\AVG8\avgnsx.exe
C:\win\MozyHome\mozybackup.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\win\AVG\AVG8\avgtray.exe
C:\win\VMware\VMware Workstation\vmware-tray.exe
C:\Programmer\Java\jre6\bin\jusched.exe
C:\win\RETROS~1\RETROS~1.0\RetroExpress.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Programmer\Windows Media Player\WMPNSCFG.exe
C:\win\MozyHome\mozystat.exe
C:\WINDOWS\system32\wuauclt.exe
C:\win\Lavasoft\Ad-Aware\AAWTray.exe
C:\win\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\win\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\win\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre6\bin\ssv.dll
O2 - BHO: Tunebite_WebRipPlugin Class - {AA102584-3B97-47e7-B9BC-75D54C110A7D} - C:\win\Tunebite\plugins\IE\TB_WebRipIePlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmer\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmer\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\win\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [vmware-tray] "C:\win\VMware\VMware Workstation\vmware-tray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RetroExpress] C:\win\RETROS~1\RETROS~1.0\RetroExpress.exe /h
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] C:\Programmer\NVIDIA Corporation\nView\nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Programmer\Fælles filer\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Programmer\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: MozyHome Status.lnk = C:\win\MozyHome\mozystat.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\win\MSOFFI~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\win\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\win\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\win\vmware\vmware workstation\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\win\vmware\vmware workstation\vsocklib.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1222708757281
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1228058690390
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} (IPSUploader4 Control) - https://asp.photoprintit.de/microsite/10021/defaults/activex/ips/IPSUploader4.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15108/CTPID.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\win\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\win\AVG\AVG8\avgwdsvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Programmer\Fælles filer\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Programmer\Creative\Shared Files\CTAudSvc.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Programmer\Fælles filer\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\win\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: MozyHome Backup Service (mozybackup) - Mozy, Inc. - C:\win\MozyHome\mozybackup.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\win\VMware\VMware Workstation\vmware-ufad.exe
--
End of file - 7876 bytes
--- HJT END ---
--- GMER START ---
GMER 1.0.15.15077 [gmer.exe] - http://www.gmer.net
Rootkit scan 2009-09-08 22:46:42
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
Code 8A6CDD30 ZwEnumerateKey
Code 8A6CDCF8 ZwFlushInstructionCache
Code 8A725566 IofCallDriver
Code 8A6C81D6 IofCompleteRequest
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!IofCallDriver 804E13A7 5 Bytes JMP 8A72556B
.text ntoskrnl.exe!IofCompleteRequest 804E17BD 5 Bytes JMP 8A6C81DB
PAGE ntoskrnl.exe!ZwEnumerateKey 80578E14 5 Bytes JMP 8A6CDD34
PAGE ntoskrnl.exe!ZwFlushInstructionCache 80587BFB 5 Bytes JMP 8A6CDCFC
PAGE ntoskrnl.exe!ZwSaveKey 8065616E 5 Bytes JMP 8A6CDF42
PAGE ntoskrnl.exe!ZwSaveKeyEx 80656259 5 Bytes JMP 8A6CF522
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\Explorer.EXE[1076] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00BC000A
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 VMkbd.sys (VMware keyboard filter driver (32-bit)/VMware, Inc.)
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\drivers\kbiwkmbwwosrtu.sys (*** hidden *** ) [SYSTEM] kbiwkmknmetjlq <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq@imagepath \systemroot\system32\drivers\kbiwkmbwwosrtu.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\main@aid 10002
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\main@sid 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmbwwosrtu.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmiqdxjrru.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmayjnovxd.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmupqowyro.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\modules@kbiwkm.dat \systemroot\system32\kbiwkmjpyxmtkj.dat
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq@imagepath \systemroot\system32\drivers\kbiwkmbwwosrtu.sys
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\main@aid 10002
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\main@sid 1
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmbwwosrtu.sys
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmiqdxjrru.dll
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmayjnovxd.dat
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmupqowyro.dll
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\modules@kbiwkm.dat \systemroot\system32\kbiwkmjpyxmtkj.dat
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\system32\drivers\kbiwkmbwwosrtu.sys 70144 bytes executable <-- ROOTKIT !!!
File C:\WINDOWS\system32\kbiwkmayjnovxd.dat 51805 bytes
File C:\WINDOWS\system32\kbiwkmiqdxjrru.dll 44544 bytes executable
File C:\WINDOWS\system32\kbiwkmjpyxmtkj.dat 43 bytes
File C:\WINDOWS\system32\kbiwkmupqowyro.dll 19968 bytes executable
---- EOF - GMER 1.0.15 ----
--- GMER END ---
Thanks again!
according to Spybot s&d, i've been infected with this virus, and Spybot can't remove it.
I have looked in this forum and understand I should generate the 2 following logfiles (HJT and GMER)
Any help highly appreciated, thank you!
--- HJT START ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:52:37, on 08-09-2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\win\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmer\Creative\Shared Files\CTAudSvc.exe
C:\win\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\svchost.exe
C:\win\AVG\AVG8\avgrsx.exe
C:\win\AVG\AVG8\avgnsx.exe
C:\win\MozyHome\mozybackup.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\win\AVG\AVG8\avgtray.exe
C:\win\VMware\VMware Workstation\vmware-tray.exe
C:\Programmer\Java\jre6\bin\jusched.exe
C:\win\RETROS~1\RETROS~1.0\RetroExpress.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Programmer\Windows Media Player\WMPNSCFG.exe
C:\win\MozyHome\mozystat.exe
C:\WINDOWS\system32\wuauclt.exe
C:\win\Lavasoft\Ad-Aware\AAWTray.exe
C:\win\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmer\Fælles filer\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\win\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\win\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmer\Java\jre6\bin\ssv.dll
O2 - BHO: Tunebite_WebRipPlugin Class - {AA102584-3B97-47e7-B9BC-75D54C110A7D} - C:\win\Tunebite\plugins\IE\TB_WebRipIePlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmer\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmer\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\win\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [vmware-tray] "C:\win\VMware\VMware Workstation\vmware-tray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmer\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RetroExpress] C:\win\RETROS~1\RETROS~1.0\RetroExpress.exe /h
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] C:\Programmer\NVIDIA Corporation\nView\nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Programmer\Fælles filer\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmer\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Programmer\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: MozyHome Status.lnk = C:\win\MozyHome\mozystat.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\win\MSOFFI~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\win\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\win\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\win\vmware\vmware workstation\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\win\vmware\vmware workstation\vsocklib.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.9.113.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6662.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1222708757281
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1228058690390
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} (IPSUploader4 Control) - https://asp.photoprintit.de/microsite/10021/defaults/activex/ips/IPSUploader4.cab
O16 - DPF: {D216644A-C6DB-49D9-BBCF-D38FE7991BF2} (Util Class) - https://udstedelse.certifikat.tdc.dk/csp/authenticode/tdccsp-0506.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15108/CTPID.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\win\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\win\AVG\AVG8\avgwdsvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Programmer\Fælles filer\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Programmer\Creative\Shared Files\CTAudSvc.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Programmer\Fælles filer\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\win\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: MozyHome Backup Service (mozybackup) - Mozy, Inc. - C:\win\MozyHome\mozybackup.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - C:\win\VMware\VMware Workstation\vmware-ufad.exe
--
End of file - 7876 bytes
--- HJT END ---
--- GMER START ---
GMER 1.0.15.15077 [gmer.exe] - http://www.gmer.net
Rootkit scan 2009-09-08 22:46:42
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
Code 8A6CDD30 ZwEnumerateKey
Code 8A6CDCF8 ZwFlushInstructionCache
Code 8A725566 IofCallDriver
Code 8A6C81D6 IofCompleteRequest
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!IofCallDriver 804E13A7 5 Bytes JMP 8A72556B
.text ntoskrnl.exe!IofCompleteRequest 804E17BD 5 Bytes JMP 8A6C81DB
PAGE ntoskrnl.exe!ZwEnumerateKey 80578E14 5 Bytes JMP 8A6CDD34
PAGE ntoskrnl.exe!ZwFlushInstructionCache 80587BFB 5 Bytes JMP 8A6CDCFC
PAGE ntoskrnl.exe!ZwSaveKey 8065616E 5 Bytes JMP 8A6CDF42
PAGE ntoskrnl.exe!ZwSaveKeyEx 80656259 5 Bytes JMP 8A6CF522
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\Explorer.EXE[1076] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00BC000A
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 VMkbd.sys (VMware keyboard filter driver (32-bit)/VMware, Inc.)
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\drivers\kbiwkmbwwosrtu.sys (*** hidden *** ) [SYSTEM] kbiwkmknmetjlq <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq@imagepath \systemroot\system32\drivers\kbiwkmbwwosrtu.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\main@aid 10002
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\main@sid 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmbwwosrtu.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmiqdxjrru.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmayjnovxd.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmupqowyro.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmknmetjlq\modules@kbiwkm.dat \systemroot\system32\kbiwkmjpyxmtkj.dat
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq@imagepath \systemroot\system32\drivers\kbiwkmbwwosrtu.sys
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\main@aid 10002
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\main@sid 1
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\main\injector@* kbiwkmwsp.dll
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmbwwosrtu.sys
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmiqdxjrru.dll
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmayjnovxd.dat
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmupqowyro.dll
Reg HKLM\SYSTEM\ControlSet003\Services\kbiwkmknmetjlq\modules@kbiwkm.dat \systemroot\system32\kbiwkmjpyxmtkj.dat
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\system32\drivers\kbiwkmbwwosrtu.sys 70144 bytes executable <-- ROOTKIT !!!
File C:\WINDOWS\system32\kbiwkmayjnovxd.dat 51805 bytes
File C:\WINDOWS\system32\kbiwkmiqdxjrru.dll 44544 bytes executable
File C:\WINDOWS\system32\kbiwkmjpyxmtkj.dat 43 bytes
File C:\WINDOWS\system32\kbiwkmupqowyro.dll 19968 bytes executable
---- EOF - GMER 1.0.15 ----
--- GMER END ---
Thanks again!