Infected machine, can't run any antivirus software, or install any. AVcare, b.exe.

throwway

New member
Main symptoms, spybot can not be launched, even from the .scrs, AVG doesn't run at startup, and can't be run, files can't be downloaded...pictures work, but movies, .exes .rar etc all never arrive in folder try to download them too and can't be found anywhere else. Google search results all redirect to spammy sites, when trying to visit a website am sometimes redirected to (corrupted) google search result for that URL, can't install new programs, some instability and slowdown....but not too much.
IE was also visiting websites in the background constantly, but I uninstalled AVcare from the add/remove programs and turned off some highly suspicious startup files and that has stopped.

I can't open spybot to do anything with tea timer, and can't get to hijackthis....and even if I could, suspect it wouldn't run.

Using Vista, have spybot&AVG installed and were up to date but completely inaccessable atm. Computer remains almost completely useable for non-web activities.

help? :)
 
Hi,

files can't be downloaded...pictures work, but movies, .exes .rar etc all never arrive in folder try to download them too and can't be found anywhere else.
I've seen this kind of symptoms occur in Vista with AVG installed. Could you uninstall it temporarily?

Download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    1. DDS.txt
    2. Attach.txt
  • Save both reports to your desktop. Post them back to your topic.

Download GMER here by clicking download exe -button and then saving it your desktop:
  • Double-click .exe that you downloaded
  • Click rootkit-tab and then scan.
  • Don't check
    Show All
    box while scanning in progress!
  • When scanning is ready, click Copy.
  • This copies log to clipboard
  • Post log in your reply.
 
Update

I uninstalled AVg but it didn't change the 'can't download' thing, I'll have to get those files on another PC and transfer...in the meantime don't think I've gone away, thanks for your help :)
 
logs

DDS (Ver_09-11-24.02) - NTFSx86
Run by Owner at 23:28:33.95 on 26/11/2009
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1498 [GMT 0:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Cable&Wireless\C&W_802.11g_Utility\C&WWLAN.exe
C:\Windows\system32\Taskmgr.exe
C:\Windows\system32\taskeng.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Owner\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.altavista.com/
uWindow Title =
uDefault_Page_URL = hxxp://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=5080820
mDefault_Page_URL = hxxp://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=5080820
uInternet Settings,ProxyOverride = <local>
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
StartupFolder: c:\users\owner\appdata\roaming\microsoft\windows\start menu\programs\startup\desk.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\cable&~1.lnk - c:\program files\cable&wireless\c&w_802.11g_utility\C&WWLAN.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: antimalwareguard.com
Trusted Zone: filesmonster.com
Trusted Zone: antimalwareguard.com
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
AppInit_DLLs: avgrsstx.dll
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\2esepl9x.trygain\

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-8-27 335240]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-8-27 297752]

=============== Created Last 30 ================

2009-11-18 14:30:18 175151692 ----a-w- c:\windows\MEMORY.DMP
2009-11-08 04:53:04 0 d-----w- c:\users\owner\Tracing
2009-11-08 04:52:20 0 d-----w- c:\program files\Microsoft
2009-11-08 04:51:56 0 d-----w- c:\program files\Windows Live SkyDrive
2009-11-08 04:50:36 0 d-----w- c:\program files\common files\Windows Live

==================== Find3M ====================

2009-09-30 17:13:42 70656 ----a-w- c:\windows\system32\drivers\rotscxqrvwipvj.sys
2009-09-30 11:02:37 44544 ----a-w- c:\windows\system32\rotscxitrpvrtw.dll
2008-10-28 18:09:46 51200 ----a-w- c:\windows\inf\infpub.dat
2008-10-28 18:09:46 143360 ----a-w- c:\windows\inf\infstrng.dat
2008-10-28 18:09:45 86016 ----a-w- c:\windows\inf\infstor.dat
2008-08-20 00:03:01 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2008-08-20 00:02:56 8192 --sha-w- c:\windows\users\default\NTUSER.DAT

============= FINISH: 23:29:21.39 ===============



GMER 1.0.15.15252 - http://www.gmer.net
Rootkit scan 2009-11-26 23:54:46
Windows 6.0.6001 Service Pack 1
Running: pjfdtibk.exe; Driver: C:\Users\Owner\AppData\Local\Temp\kglcypog.sys


---- Kernel code sections - GMER 1.0.15 ----

.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8B006000, 0x1F8CAC, 0xE8000020]

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Internet Explorer\iexplore.exe[3536] USER32.dll!DialogBoxIndirectParamW 7676BD25 5 Bytes JMP 71A25BF3 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3536] USER32.dll!DialogBoxParamW 76781FD5 5 Bytes JMP 71A25B7D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3536] USER32.dll!DialogBoxParamA 767A80B2 5 Bytes JMP 71A25BB8 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3536] USER32.dll!DialogBoxIndirectParamA 767A83DD 5 Bytes JMP 71A25C2E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3536] USER32.dll!MessageBoxIndirectA 767BD471 5 Bytes JMP 71A25B39 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3536] USER32.dll!MessageBoxIndirectW 767BD56B 5 Bytes JMP 71A25AF5 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3536] USER32.dll!MessageBoxExA 767BD5D1 5 Bytes JMP 71A25ABB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3536] USER32.dll!MessageBoxExW 767BD5F5 5 Bytes JMP 71A25A81 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- Services - GMER 1.0.15 ----

Service C:\Windows\system32\drivers\rotscxqrvwipvj.sys (*** hidden *** ) [SYSTEM] rotscxveufmtxr <-- ROOTKIT !!!
Service C:\Windows\system32\drivers\SKYNETqmipfqix.sys (*** hidden *** ) [SYSTEM] SKYNETcycuyxxw <-- ROOTKIT !!!
Service (*** hidden *** ) [SYSTEM] UACd.sys <-- ROOTKIT !!!

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxveufmtxr@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxveufmtxr@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxveufmtxr@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxveufmtxr@imagepath \systemroot\system32\drivers\rotscxqrvwipvj.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxveufmtxr\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxveufmtxr\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxveufmtxr\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxveufmtxr\modules@rotscxrk.sys \systemroot\system32\drivers\rotscxqrvwipvj.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\rotscxveufmtxr\modules@rotscxcmd.dll \systemroot\system32\rotscxitrpvrtw.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw@imagepath \systemroot\system32\drivers\SKYNETqmipfqix.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\main@aid 10002
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\main@sid 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\modules@SKYNETrk.sys \systemroot\system32\drivers\SKYNETqmipfqix.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\modules@SKYNETcmd.dll \systemroot\system32\SKYNETbajestwf.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\modules@SKYNETlog.dat \systemroot\system32\SKYNETbdexdosn.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\modules@SKYNETwsp.dll \systemroot\system32\SKYNETtnprdpbe.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETcycuyxxw\modules@SKYNET.dat \systemroot\system32\SKYNEThempttmt.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@imagepath
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@UACd
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@UACc
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacbbr
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacsr
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacmal
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacrem
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacmask
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@uacserf
Reg HKLM\SYSTEM\ControlSet003\Services\rotscxveufmtxr@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\rotscxveufmtxr@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\rotscxveufmtxr@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\rotscxveufmtxr@imagepath \systemroot\system32\drivers\rotscxqrvwipvj.sys
Reg HKLM\SYSTEM\ControlSet003\Services\rotscxveufmtxr\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\rotscxveufmtxr\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\rotscxveufmtxr\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\rotscxveufmtxr\modules@rotscxrk.sys \systemroot\system32\drivers\rotscxqrvwipvj.sys
Reg HKLM\SYSTEM\ControlSet003\Services\rotscxveufmtxr\modules@rotscxcmd.dll \systemroot\system32\rotscxitrpvrtw.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw@imagepath \systemroot\system32\drivers\SKYNETqmipfqix.sys
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\main@aid 10002
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\main@sid 1
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\modules@SKYNETrk.sys \systemroot\system32\drivers\SKYNETqmipfqix.sys
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\modules@SKYNETcmd.dll \systemroot\system32\SKYNETbajestwf.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\modules@SKYNETlog.dat \systemroot\system32\SKYNETbdexdosn.dat
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\modules@SKYNETwsp.dll \systemroot\system32\SKYNETtnprdpbe.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETcycuyxxw\modules@SKYNET.dat \systemroot\system32\SKYNEThempttmt.dat
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@imagepath
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@UACd
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@UACc
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacbbr
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacsr
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacmal
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacrem
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacmask
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules@uacserf

---- EOF - GMER 1.0.15 ----



Hope I'm not causing too much of a problem by posting this, but I can not attach it, neither the 'manage attachments' button nor the paperclip or the arrow next to it do anything when clicked.


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-11-24.02)

Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume3
Install Date: 19/08/2008 17:12:48
System Uptime: 22/11/2009 15:20:21 (104 hours ago)

Motherboard: Dell Inc. | | 0K216C
Processor: Intel(R) Core(TM)2 Duo CPU E7200 @ 2.53GHz | Socket 775 | 2534/266mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 456 GiB total, 91.599 GiB free.
D: is FIXED (NTFS) - 10 GiB total, 5.832 GiB free.
E: is CDROM (CDFS)

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP486: 06/11/2009 15:49:24 - Avg8 Update
RP488: 07/11/2009 18:03:13 - Scheduled Checkpoint
RP490: 10/11/2009 13:05:03 - Scheduled Checkpoint
RP492: 13/11/2009 00:47:38 - Scheduled Checkpoint
RP494: 14/11/2009 20:37:44 - Scheduled Checkpoint
RP496: 16/11/2009 22:44:22 - Scheduled Checkpoint
RP498: 17/11/2009 15:00:40 - Scheduled Checkpoint
RP500: 18/11/2009 19:56:42 - Scheduled Checkpoint
RP502: 19/11/2009 22:34:41 - Scheduled Checkpoint
RP504: 22/11/2009 14:26:42 - Removed AVG Free 8.5
RP506: 22/11/2009 14:27:34 - Removed AVG Free 8.5
RP508: 23/11/2009 16:19:14 - Scheduled Checkpoint
RP510: 24/11/2009 19:33:33 - Scheduled Checkpoint
RP512: 26/11/2009 16:56:50 - Avg8 Update

==== Installed Programs ======================

7-Zip 4.57
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.1.0
Apple Software Update
ATI Catalyst Control Center
µTorrent
AutoUpdate
AVG Free 8.5
Cable & Wireless 802.11g Series Wireless LAN USB
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center Localization Chinese Standard
Catalyst Control Center Localization Chinese Traditional
Catalyst Control Center Localization French
Catalyst Control Center Localization German
Catalyst Control Center Localization Hungarian
Catalyst Control Center Localization Italian
Catalyst Control Center Localization Japanese
Catalyst Control Center Localization Korean
Catalyst Control Center Localization Portuguese
Catalyst Control Center Localization Spanish
Catalyst Control Center Localization Turkish
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help English
CCC Help French
CCC Help German
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Portuguese
CCC Help Spanish
CCC Help Turkish
Company of Heroes - FAKEMSI
Company of Heroes - Opposing Fronts
Compatibility Pack for the 2007 Office system
Dawn of War - Soulstorm
Dell Getting Started Guide
Dell Support Center
Diablo II
DivX Converter
DivX Player
DivX Web Player
Dracula
EDocs
eMule
FlashDevelop 3.0.4
FLV Player 2.0 (build 25)
Free Music Zilla
Game Maker 7.0
Gmask 1.70 English
GOM Player
GoToAssist 8.0.0.514
Indeo® Software
Intel A/V Codecs V2.0
Intel(R) PRO Network Connections 12.1.11.0
Internet From BT
IrfanView (remove only)
Java(TM) 6 Update 5
Majesty
Medieval II Total War
Microsoft Age of Empires II
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
MinGW 5.1.4
Mozilla Firefox (3.0.15)
MSVCRT
Nephi Theora Decoder
Oblivion
Oblivion mod manager 1.1.12
Python 2.5 comtypes-0.5.2
Python 2.5 PIL-1.1.6
Python 2.5 psyco-1.6
Python 2.5 pywin32-212
Python 2.5.2
QuickTime
Real Alternative 1.8.2
RealPlayer
Realtek High Definition Audio Driver
Rome - Total War
SFX Compiler
Skins
Spybot - Search & Destroy
Steam
The Battle for Middle-earth (tm)
Warhammer 40,000: Dawn of War II
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Upload Tool
wxPython 2.8.7.1 (ansi) for Python 2.5
Yahoo! Messenger
Zip Password Finder
Zip Password Recovery - Ver: 1.42

==== End Of File ===========================
 
Hi,

Attaching logs to post as text is totally ok.

IMPORTANT I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

µTorrent
eMule


I'd like you to read this thread.

Please go to Control Panel > Programs and Features and uninstall the programs listed above (in red).


Empty Recycle Bin.

After that:


Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully first.


Please continue as follows:

  1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link
    Remember to re-enable them afterwards.

  2. Click Yes to allow ComboFix to continue scanning for malware.

When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New dds log.


A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.
 
Problem

I am sure I uninstalled (or tried to as the case seems) AVG earlier, but combofix has detected it running....and sure enough it is there still in program files (not showing as running anything in task manager though)....trying to uninstall it now just gives an unexpected error message and doesn't work.

Run combofix anyway as AVG doesn't appear to actually be running? delete AVG folder in program files and reboot? :confused:
 
Reporting

So turns out there's no way to cancel combofix, so had to run it anyway....which makes the warnings that I was doing it 'at my own risk' the program gives kinda redundant as it's too late by then....It all seemed to go okay until afterwards though.

Afterwards trying to open any file or run any program (although I only tried a couple) resulted in a 'illegal operation performed on a registry key marked for deletion' error....after restarting PC that seems to have gone, however there is no new DDS report, the old DDS.txt remains on the desktop....but I'm pretty sure it is still the old one, as it seems identical and has the date modified of a week ago...I'll attach it nevertheless, on the off chance...


combofix.txt

ComboFix 09-12-02.01 - Owner 02/12/2009 15:01.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1213 [GMT 0:00]
Running from: c:\users\Owner\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-1283296827-177754420-2501937510-500
c:\$recycle.bin\S-1-5-21-2773397201-2855733099-4214572315-500
c:\users\Apache\Desktop\AV Care.lnk
c:\windows\run.log
c:\windows\system32\drivers\rotscxqrvwipvj.sys
c:\windows\system32\drivers\SKYNETqmipfqix.sys
c:\windows\system32\drivers\UACd.sys
c:\windows\system32\drivers\ytasfwptdgwvxs.sys
c:\windows\system32\rotscxitrpvrtw.dll
c:\windows\system32\SKYNETbdexdosn.dat
c:\windows\system32\SKYNEThempttmt.dat
c:\windows\system32\UAChstrndiayr.db
c:\windows\system32\ytasfwuniywegf.dat

Infected copy of c:\windows\system32\cngaudit.dll was found and disinfected
Restored copy from - c:\windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_rotscxveufmtxr
-------\Legacy_SKYNETcycuyxxw
-------\Legacy_UACd.sys
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
-------\Service_rotscxveufmtxr
-------\Service_SKYNETcycuyxxw
-------\Service_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-11-02 to 2009-12-02 )))))))))))))))))))))))))))))))
.

2009-12-02 15:05 . 2009-12-02 15:10 -------- d-----w- c:\users\Owner\AppData\Local\temp
2009-12-02 15:05 . 2009-12-02 15:05 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-02 15:05 . 2009-12-02 15:05 -------- d-----w- c:\users\apache2triad.Shiny-PC\AppData\Local\temp
2009-12-02 15:05 . 2009-12-02 15:05 -------- d-----w- c:\users\Apache\AppData\Local\temp
2009-11-26 16:57 . 2009-11-06 15:49 2064152 ----a-w- c:\programdata\avg8\update\backup\avgcorex.dll
2009-11-26 16:57 . 2009-11-03 12:24 3513624 ----a-w- c:\programdata\avg8\update\backup\avgui.exe
2009-11-26 16:57 . 2009-11-03 12:24 2028312 ----a-w- c:\programdata\avg8\update\backup\avgtray.exe
2009-11-08 04:53 . 2009-11-16 13:29 -------- d-----w- c:\users\Owner\Tracing
2009-11-08 04:52 . 2009-11-08 04:52 -------- d-----w- c:\program files\Microsoft
2009-11-08 04:51 . 2009-11-08 04:51 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-11-08 04:50 . 2009-11-08 04:50 -------- d-----w- c:\program files\Common Files\Windows Live

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-02 13:54 . 2008-08-27 22:58 4096 d-----w- c:\programdata\avg8
2009-11-30 00:26 . 2009-09-20 18:42 0 ----a-w- c:\windows\win32k.sys
2009-11-24 01:37 . 2008-09-06 23:21 16384 d-----w- c:\program files\Diablo II
2009-11-19 16:55 . 2009-06-29 08:08 4096 d-----w- c:\program files\Free Music Zilla
2009-11-12 05:13 . 2009-04-18 02:35 -------- d-----w- c:\users\Owner\AppData\Roaming\IrfanView
2009-11-08 04:51 . 2008-08-28 00:17 4096 d-----w- c:\program files\Windows Live
2009-10-19 07:40 . 2009-10-19 07:40 -------- d-----w- c:\program files\Information Packaging
2009-10-19 07:29 . 2009-10-19 07:29 -------- d-----w- c:\program files\Datahjaelp
2009-10-19 07:10 . 2009-10-19 07:09 4096 d-----w- c:\program files\ZIP PASSWORD FINDER
2009-10-10 19:33 . 2009-10-10 19:32 4096 d-----w- c:\program files\FlashDevelop
2009-10-02 05:53 . 2009-10-24 18:42 47997 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desk.exe
2008-08-20 00:02 . 2008-08-20 00:02 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-12 185872]

c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
desk.exe [2009-10-2 47997]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Cable & Wireless 11g Wireless USB.lnk - c:\program files\Cable&Wireless\C&W_802.11g_Utility\C&WWLAN.exe [2008-10-28 438272]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-08-19 15:31 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Users^Owner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Free Music Zilla.lnk]
path=c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Free Music Zilla.lnk
backup=c:\windows\pss\Free Music Zilla.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1283296827-177754420-2501937510-1000]
"EnableNotificationsRef"=dword:00000001

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [27/08/2008 22:58 335240]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [27/08/2008 22:58 297752]
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.altavista.com/
uInternet Settings,ProxyOverride = <local>
Trusted Zone: filesmonster.com
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\d4tovtom.default\
FF - prefs.js: browser.startup.homepage - google.co.uk
.
- - - - ORPHANS REMOVED - - - -

AddRemove-RealJukebox 1.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
AddRemove-Steam App 15620 - c:\program files\Steam\steam.exe steam://uninstall/15620
AddRemove-{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1 - c:\program files\Spybot - Search & Destroy\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-02 15:10
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2009-12-02 15:13 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-02 15:12

Pre-Run: 101,515,718,656 bytes free
Post-Run: 102,191,656,960 bytes free

- - End Of File - - C14C195F17CB53B794CD5E6D7409AAF8


Old (I'm pretty sure) DDS

DDS (Ver_09-11-24.02) - NTFSx86
Run by Owner at 23:28:33.95 on 26/11/2009
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1498 [GMT 0:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Cable&Wireless\C&W_802.11g_Utility\C&WWLAN.exe
C:\Windows\system32\Taskmgr.exe
C:\Windows\system32\taskeng.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Owner\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.altavista.com/
uWindow Title =
uDefault_Page_URL = hxxp://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=5080820
mDefault_Page_URL = hxxp://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=5080820
uInternet Settings,ProxyOverride = <local>
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
StartupFolder: c:\users\owner\appdata\roaming\microsoft\windows\start menu\programs\startup\desk.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\cable&~1.lnk - c:\program files\cable&wireless\c&w_802.11g_utility\C&WWLAN.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: antimalwareguard.com
Trusted Zone: filesmonster.com
Trusted Zone: antimalwareguard.com
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
AppInit_DLLs: avgrsstx.dll
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\2esepl9x.trygain\

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-8-27 335240]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-8-27 297752]

=============== Created Last 30 ================

2009-11-18 14:30:18 175151692 ----a-w- c:\windows\MEMORY.DMP
2009-11-08 04:53:04 0 d-----w- c:\users\owner\Tracing
2009-11-08 04:52:20 0 d-----w- c:\program files\Microsoft
2009-11-08 04:51:56 0 d-----w- c:\program files\Windows Live SkyDrive
2009-11-08 04:50:36 0 d-----w- c:\program files\common files\Windows Live

==================== Find3M ====================

2009-09-30 17:13:42 70656 ----a-w- c:\windows\system32\drivers\rotscxqrvwipvj.sys
2009-09-30 11:02:37 44544 ----a-w- c:\windows\system32\rotscxitrpvrtw.dll
2008-10-28 18:09:46 51200 ----a-w- c:\windows\inf\infpub.dat
2008-10-28 18:09:46 143360 ----a-w- c:\windows\inf\infstrng.dat
2008-10-28 18:09:45 86016 ----a-w- c:\windows\inf\infstor.dat
2008-08-20 00:03:01 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2008-08-20 00:02:56 8192 --sha-w- c:\windows\users\default\NTUSER.DAT

============= FINISH: 23:29:21.39 ===============
 
Oh....well I feel stupid now :red:

Fresh one


DDS (Ver_09-11-24.02) - NTFSx86
Run by Owner at 20:53:22.84 on 02/12/2009
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1397 [GMT 0:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Cable&Wireless\C&W_802.11g_Utility\C&WWLAN.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Owner\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.altavista.com/
uInternet Settings,ProxyOverride = <local>
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
StartupFolder: c:\users\owner\appdata\roaming\microsoft\windows\start menu\programs\startup\desk.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\cable&~1.lnk - c:\program files\cable&wireless\c&w_802.11g_utility\C&WWLAN.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: filesmonster.com
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
AppInit_DLLs: c:\windows\system32\avgrsstx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\d4tovtom.default\
FF - prefs.js: browser.startup.homepage - google.co.uk

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-8-27 335240]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-8-27 297752]

=============== Created Last 30 ================

2009-12-02 15:00:36 98816 ----a-w- c:\windows\sed.exe
2009-12-02 15:00:36 77312 ----a-w- c:\windows\MBR.exe
2009-12-02 15:00:36 260608 ----a-w- c:\windows\PEV.exe
2009-12-02 15:00:36 161792 ----a-w- c:\windows\SWREG.exe
2009-11-18 14:30:18 175151692 ----a-w- c:\windows\MEMORY.DMP
2009-11-08 04:53:04 0 d-----w- c:\users\owner\Tracing
2009-11-08 04:52:20 0 d-----w- c:\program files\Microsoft
2009-11-08 04:51:56 0 d-----w- c:\program files\Windows Live SkyDrive
2009-11-08 04:50:36 0 d-----w- c:\program files\common files\Windows Live

==================== Find3M ====================

2008-10-28 18:09:46 51200 ----a-w- c:\windows\inf\infpub.dat
2008-10-28 18:09:46 143360 ----a-w- c:\windows\inf\infstrng.dat
2008-10-28 18:09:45 86016 ----a-w- c:\windows\inf\infstor.dat
2008-08-20 00:03:01 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2008-08-20 00:02:56 8192 --sha-w- c:\windows\users\default\NTUSER.DAT

============= FINISH: 20:53:55.33 ===============
 
Hi again :)

Open notepad and copy/paste the text in the quotebox below into it:

Code:
FileLook::
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desk.exe
DDS::
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
Rootkit::
c:\windows\win32k.sys


Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

CFScriptB-4.gif


Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.


Uninstall old Adobe Reader versions and get the latest one (9.2) here or get Foxit Reader here. Make sure you don't install toolbar if choose Foxit Reader! You may also check free readers introduced here.



Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 17.
  • Click the
    Download
    button to the right.
  • Select Windows on platform combobox and check the box that says:
    Accept License Agreement. Click continue.
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u17-windows-i586-p.exe to install the newest version. Uncheck Carbonite online backup trial if it's offered there.



Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.

Double-click ATF Cleaner.exe to open it

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Java Cache

*The other boxes are optional*
Then click the Empty Selected button.

If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

If you use Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.


Please run an online scan with Kaspersky Online Scanner as instructed in the screenshot here.


Post back its report, a fresh dds.txt log and above mentioned ComboFix resultant log. Any issues left?
 
reports

Done and done, yes the symptoms remain.

Fresh DDS

DDS (Ver_09-11-24.02) - NTFSx86
Run by Owner at 19:51:08.87 on 05/12/2009
Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_17
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1104 [GMT 0:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Cable&Wireless\C&W_802.11g_Utility\C&WWLAN.exe
C:\Windows\system32\Taskmgr.exe
C:\Windows\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Owner\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.altavista.com/
uInternet Settings,ProxyOverride = <local>
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\users\owner\appdata\roaming\microsoft\windows\start menu\programs\startup\desk.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\cable&~1.lnk - c:\program files\cable&wireless\c&w_802.11g_utility\C&WWLAN.exe
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: filesmonster.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
AppInit_DLLs: c:\windows\system32\avgrsstx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\d4tovtom.default\
FF - prefs.js: browser.startup.homepage - google.co.uk
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-8-27 335240]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-8-27 297752]

=============== Created Last 30 ================

2009-12-05 16:57:13 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-02 15:00:36 98816 ----a-w- c:\windows\sed.exe
2009-12-02 15:00:36 77312 ----a-w- c:\windows\MBR.exe
2009-12-02 15:00:36 260608 ----a-w- c:\windows\PEV.exe
2009-12-02 15:00:36 161792 ----a-w- c:\windows\SWREG.exe
2009-11-18 14:30:18 175151692 ----a-w- c:\windows\MEMORY.DMP
2009-11-08 04:53:04 0 d-----w- c:\users\owner\Tracing
2009-11-08 04:52:20 0 d-----w- c:\program files\Microsoft
2009-11-08 04:51:56 0 d-----w- c:\program files\Windows Live SkyDrive
2009-11-08 04:50:36 0 d-----w- c:\program files\common files\Windows Live

==================== Find3M ====================

2008-10-28 18:09:46 51200 ----a-w- c:\windows\inf\infpub.dat
2008-10-28 18:09:46 143360 ----a-w- c:\windows\inf\infstrng.dat
2008-10-28 18:09:45 86016 ----a-w- c:\windows\inf\infstor.dat
2008-08-20 00:03:01 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2008-08-20 00:02:56 8192 --sha-w- c:\windows\users\default\NTUSER.DAT

============= FINISH: 19:51:24.58 ===============

Combofix
ComboFix 09-12-02.01 - Owner 03/12/2009 17:53.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1560 [GMT 0:00]
Running from: c:\users\Owner\Desktop\ComboFix.exe
Command switches used :: c:\users\Owner\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2009-11-03 to 2009-12-03 )))))))))))))))))))))))))))))))
.

2009-12-03 17:57 . 2009-12-03 17:57 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-12-03 17:57 . 2009-12-03 17:57 -------- d-----w- c:\users\Owner\AppData\Local\temp
2009-12-03 17:57 . 2009-12-03 17:57 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-03 17:57 . 2009-12-03 17:57 -------- d-----w- c:\users\apache2triad\AppData\Local\temp
2009-12-03 17:57 . 2009-12-03 17:57 -------- d-----w- c:\users\apache2triad.Shiny-PC\AppData\Local\temp
2009-12-03 17:57 . 2009-12-03 17:57 -------- d-----w- c:\users\Apache\AppData\Local\temp
2009-11-26 16:57 . 2009-11-06 15:49 2064152 ----a-w- c:\programdata\avg8\update\backup\avgcorex.dll
2009-11-26 16:57 . 2009-11-03 12:24 3513624 ----a-w- c:\programdata\avg8\update\backup\avgui.exe
2009-11-26 16:57 . 2009-11-03 12:24 2028312 ----a-w- c:\programdata\avg8\update\backup\avgtray.exe
2009-11-08 04:53 . 2009-11-16 13:29 -------- d-----w- c:\users\Owner\Tracing
2009-11-08 04:52 . 2009-11-08 04:52 -------- d-----w- c:\program files\Microsoft
2009-11-08 04:51 . 2009-11-08 04:51 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-11-08 04:50 . 2009-11-08 04:50 -------- d-----w- c:\program files\Common Files\Windows Live

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-02 13:54 . 2008-08-27 22:58 4096 d-----w- c:\programdata\avg8
2009-11-30 00:26 . 2009-09-20 18:42 0 ----a-w- c:\windows\win32k.sys
2009-11-24 01:37 . 2008-09-06 23:21 16384 d-----w- c:\program files\Diablo II
2009-11-19 16:55 . 2009-06-29 08:08 4096 d-----w- c:\program files\Free Music Zilla
2009-11-12 05:13 . 2009-04-18 02:35 -------- d-----w- c:\users\Owner\AppData\Roaming\IrfanView
2009-11-08 04:51 . 2008-08-28 00:17 4096 d-----w- c:\program files\Windows Live
2009-10-19 07:40 . 2009-10-19 07:40 -------- d-----w- c:\program files\Information Packaging
2009-10-19 07:29 . 2009-10-19 07:29 -------- d-----w- c:\program files\Datahjaelp
2009-10-19 07:10 . 2009-10-19 07:09 4096 d-----w- c:\program files\ZIP PASSWORD FINDER
2009-10-10 19:33 . 2009-10-10 19:32 4096 d-----w- c:\program files\FlashDevelop
2009-10-02 05:53 . 2009-10-24 18:42 47997 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desk.exe
2008-08-20 00:02 . 2008-08-20 00:02 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

--- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desk.exe ---
Company: ------
File Description: ------
File Version: ------
Product Name: ------
Copyright: ------
Original Filename: ------
File size: 47997
Created time: 2009-10-24 18:42
Modified time: 2009-10-02 05:53
MD5: !HASH: COULD NOT OPEN FILE !!!!!
SHA1: !HASH: COULD NOT OPEN FILE !!!!!


((((((((((((((((((((((((((((( SnapShot@2009-12-02_15.10.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:58 . 2009-12-02 15:20 32478 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-12-02 15:20 70374 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-08-26 18:31 . 2009-12-02 15:20 8510 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1283296827-177754420-2501937510-1000_UserData.bin
- 2009-12-02 15:08 . 2009-12-02 15:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-12-03 17:59 . 2009-12-03 17:59 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-12-03 17:59 . 2009-12-03 17:59 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-12-02 15:08 . 2009-12-02 15:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-09-17 17:21 . 2009-12-03 13:07 233818 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S4.bin
+ 2006-11-02 10:33 . 2009-12-03 18:03 599942 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-12-02 13:50 599942 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-12-02 13:50 105448 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-12-03 18:03 105448 c:\windows\System32\perfc009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-12 185872]

c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
desk.exe [2009-10-2 47997]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Cable & Wireless 11g Wireless USB.lnk - c:\program files\Cable&Wireless\C&W_802.11g_Utility\C&WWLAN.exe [2008-10-28 438272]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-08-19 15:31 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Users^Owner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Free Music Zilla.lnk]
path=c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Free Music Zilla.lnk
backup=c:\windows\pss\Free Music Zilla.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1283296827-177754420-2501937510-1000]
"EnableNotificationsRef"=dword:00000001

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [27/08/2008 22:58 335240]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [27/08/2008 22:58 297752]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.altavista.com/
uInternet Settings,ProxyOverride = <local>
Trusted Zone: filesmonster.com
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\d4tovtom.default\
FF - prefs.js: browser.startup.homepage - google.co.uk
.

**************************************************************************
scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
.
**************************************************************************
.
Completion time: 2009-12-03 18:10 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-03 18:10
ComboFix2.txt 2009-12-02 15:13

Pre-Run: 101,930,250,240 bytes free
Post-Run: 101,731,139,584 bytes free

- - End Of File - - BCCED85371D1B36DACE75724FEBE24C9


KAS
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Saturday, December 5, 2009
Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Saturday, December 05, 2009 16:52:21
Records in database: 3333384
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\

Scan statistics:
Objects scanned: 153010
Threats found: 7
Infected objects found: 9
Suspicious objects found: 0
Scan duration: 01:44:41


File name / Threat / Threats count
C:\Qoobox\Quarantine\C\Windows\System32\cngaudit.dll.vir Infected: Trojan.Win32.Sirefef.a 1
C:\Qoobox\Quarantine\C\Windows\System32\drivers\UACd.sys.vir Infected: Rootkit.Win32.Agent.oxr 1
C:\Qoobox\Quarantine\C\Windows\System32\rotscxitrpvrtw.dll.vir Infected: Packed.Win32.TDSS.z 1
C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3E6NMF7H\pdf[1].pdf Infected: Exploit.JS.Pdfka.asa 1
C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\439TNEL3\index[2].htm Infected: Trojan-Downloader.JS.Kazmet.c 1
C:\Users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\78fcee10-69d611b8 Infected: Trojan-Downloader.Java.OpenConnection.at 1
C:\Users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\d1ed7d6-14333b8e Infected: Trojan-Downloader.Java.OpenConnection.at 1
C:\Users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\4839f1b9-5d176524 Infected: Trojan-Downloader.Java.OpenConnection.at 1
C:\Users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\345b85c8-60b85a07 Infected: Trojan-Downloader.Java.OpenStream.ad 1

Selected area has been scanned.
 
Hi,

Kindly list remaining symptoms.

Are you familiar with this file: c:\users\owner\appdata\roaming\microsoft\windows\start menu\programs\startup\desk.exe ?

AVG was running during previous ComboFix run. If you don't know how to disable it then uninstall temporarily with this.

Open notepad and copy/paste the text in the quotebox below into it:

Code:
File::
C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3E6NMF7H\pdf[1].pdf
C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\439TNEL3\index[2].htm
C:\Users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\78fcee10-69d611b8
C:\Users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\d1ed7d6-14333b8e
C:\Users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\4839f1b9-5d176524
C:\Users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\345b85c8-60b85a07
Rootkit::
c:\windows\win32k.sys


Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

CFScriptB-4.gif


Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.
 
Pleased to report that since running avgremover all symptoms have gone as far as I can tell, apart from spybot still will not run....and I'd rather not try reinstalling before I get the all clear as last time I got bsod.

I'm familiar with it only as something highly suspicious, I think I tried to turn it off in msconfig before I came here, but not sure of my memory.

Despite running AVGremover apparently successfully....looking in program files the AVG files had gone.....combofix still detected it as running and gave me warning messages.

ComboFix 09-12-02.01 - Owner 09/12/2009 14:59.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1506 [GMT 0:00]
Running from: c:\users\Owner\Desktop\ComboFix.exe
Command switches used :: c:\users\Owner\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
- REDUCED FUNCTIONALITY MODE -

FILE ::
"c:\users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3E6NMF7H\pdf[1].pdf"
"c:\users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\439TNEL3\index[2].htm"
"c:\users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\78fcee10-69d611b8"
"c:\users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\d1ed7d6-14333b8e"
"c:\users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\4839f1b9-5d176524"
"c:\users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\345b85c8-60b85a07"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\78fcee10-69d611b8
c:\users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\d1ed7d6-14333b8e
c:\users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\4839f1b9-5d176524
c:\users\Owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\345b85c8-60b85a07

.
((((((((((((((((((((((((( Files Created from 2009-11-09 to 2009-12-09 )))))))))))))))))))))))))))))))
.

2009-12-09 15:01 . 2009-12-09 15:05 -------- d-----w- c:\users\Owner\AppData\Local\temp
2009-12-09 15:01 . 2009-12-09 15:01 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-09 15:01 . 2009-12-09 15:01 -------- d-----w- c:\users\apache2triad.Shiny-PC\AppData\Local\temp
2009-12-09 15:01 . 2009-12-09 15:01 -------- d-----w- c:\users\Apache\AppData\Local\temp
2009-12-07 17:16 . 2009-12-07 17:18 -------- d-----w- c:\users\Owner\AppData\Local\Adobe
2009-12-06 16:36 . 2009-12-06 16:36 -------- d-----w- c:\users\Owner\AppData\Local\Apple Computer
2009-12-05 16:58 . 2009-12-05 16:58 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-05 16:57 . 2009-12-05 16:57 411368 ----a-w- c:\windows\system32\deploytk.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-09 13:36 . 2008-08-27 22:58 4096 d-----w- c:\programdata\avg8
2009-12-08 19:50 . 2008-09-06 23:21 16384 d-----w- c:\program files\Diablo II
2009-12-05 16:56 . 2008-08-19 15:21 4096 d-----w- c:\program files\Java
2009-11-30 00:26 . 2009-09-20 18:42 0 ----a-w- c:\windows\win32k.sys
2009-11-19 16:55 . 2009-06-29 08:08 4096 d-----w- c:\program files\Free Music Zilla
2009-11-12 05:13 . 2009-04-18 02:35 -------- d-----w- c:\users\Owner\AppData\Roaming\IrfanView
2009-11-08 04:52 . 2009-11-08 04:52 -------- d-----w- c:\program files\Microsoft
2009-11-08 04:51 . 2009-11-08 04:51 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-11-08 04:51 . 2008-08-28 00:17 4096 d-----w- c:\program files\Windows Live
2009-11-08 04:50 . 2009-11-08 04:50 -------- d-----w- c:\program files\Common Files\Windows Live
2009-10-19 07:40 . 2009-10-19 07:40 -------- d-----w- c:\program files\Information Packaging
2009-10-19 07:29 . 2009-10-19 07:29 -------- d-----w- c:\program files\Datahjaelp
2009-10-19 07:10 . 2009-10-19 07:09 4096 d-----w- c:\program files\ZIP PASSWORD FINDER
2009-10-10 19:33 . 2009-10-10 19:32 4096 d-----w- c:\program files\FlashDevelop
2009-10-02 05:53 . 2009-10-24 18:42 47997 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desk.exe
2008-08-20 00:02 . 2008-08-20 00:02 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((( SnapShot@2009-12-02_15.10.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:58 . 2009-12-09 15:06 33132 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-12-09 15:06 70414 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-08-26 18:31 . 2009-12-09 13:38 8930 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1283296827-177754420-2501937510-1000_UserData.bin
+ 2009-12-09 15:04 . 2009-12-09 15:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-12-02 15:08 . 2009-12-02 15:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-12-02 15:08 . 2009-12-02 15:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-12-09 15:04 . 2009-12-09 15:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-09-17 17:21 . 2009-12-09 10:26 234202 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S4.bin
+ 2006-11-02 10:33 . 2009-12-09 13:40 599942 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-12-02 13:50 599942 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-12-02 13:50 105448 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-12-09 13:40 105448 c:\windows\System32\perfc009.dat
+ 2009-12-05 16:57 . 2009-12-05 16:57 149280 c:\windows\System32\javaws.exe
+ 2009-12-05 16:57 . 2009-12-05 16:57 145184 c:\windows\System32\javaw.exe
+ 2009-12-05 16:57 . 2009-12-05 16:57 145184 c:\windows\System32\java.exe
+ 2008-02-03 23:12 . 2009-12-05 16:55 5813397 c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2006-11-02 10:22 . 2009-12-09 13:36 6291456 c:\windows\System32\SMI\Store\Machine\schema.dat
- 2006-11-02 10:22 . 2009-05-24 02:04 6291456 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2009-12-05 16:58 . 2009-12-05 16:58 3940352 c:\windows\Installer\9fb2400.msi
+ 2009-12-05 16:56 . 2009-12-05 16:56 1757696 c:\windows\Installer\9fb23fc.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-12 185872]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-05 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]

c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
desk.exe [2009-10-2 47997]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Cable & Wireless 11g Wireless USB.lnk - c:\program files\Cable&Wireless\C&W_802.11g_Utility\C&WWLAN.exe [2008-10-28 438272]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-08-19 15:31 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Users^Owner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Free Music Zilla.lnk]
path=c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Free Music Zilla.lnk
backup=c:\windows\pss\Free Music Zilla.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1283296827-177754420-2501937510-1000]
"EnableNotificationsRef"=dword:00000001


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{080ef108-6e09-11dd-b2de-806e6f6e6963}]
\shell\AutoRun\command - E:\Launch.exe
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.altavista.com/
uInternet Settings,ProxyOverride = <local>
Trusted Zone: filesmonster.com
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\d4tovtom.default\
FF - prefs.js: browser.startup.homepage - google.co.uk
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-09 15:05
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Internet Explorer\IEXPLORE.EXE
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2009-12-09 15:08 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-09 15:08
ComboFix2.txt 2009-12-03 18:10
ComboFix3.txt 2009-12-02 15:13

Pre-Run: 100,274,991,104 bytes free
Post-Run: 100,960,944,128 bytes free

- - End Of File - - 569D1AB2A8F3B9E94429DCBC2A6A7C89
 
Hi,

Upload c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desk.exe file to http://www.virustotal.com and post back the results.

Run ComboFix with the following script (let ComboFix update itself!):
Code:
Folder::
c:\programdata\avg8
SecCenter::
{17DDD097-36FF-435F-9E1B-52D74245D6BF}
{17DDD097-36FF-435F-9E1B-52D74245D6BF}
Rootkit::
c:\windows\win32k.sys

Post back the resultant log.

EDIT: I forgot to say that try to reinstall Spybot.
 
Last edited:
virustotal report

Antivirus Version Last Update Result
a-squared 4.5.0.41 2009.10.09 Trojan-Dropper.Win32.Decay!IK
AhnLab-V3 5.0.0.2 2009.10.09 -
AntiVir 7.9.1.35 2009.10.09 TR/Agent.ckat.1
Antiy-AVL 2.0.3.7 2009.10.09 Trojan/Win32.Agent.gen
Authentium 5.1.2.4 2009.10.10 -
Avast 4.8.1351.0 2009.10.09 Win32:NkCryptor
AVG 8.5.0.420 2009.10.04 PSW.Generic7.ACMC
BitDefender 7.2 2009.10.10 Trojan.Generic.2503197
CAT-QuickHeal 10.00 2009.10.09 -
ClamAV 0.94.1 2009.10.09 Trojan.Agent-123601
Comodo 2552 2009.10.09 -
DrWeb 5.0.0.12182 2009.10.10 Trojan.MulDrop.35597
eSafe 7.0.17.0 2009.10.08 -
eTrust-Vet 35.1.7060 2009.10.09 -
F-Prot 4.5.1.85 2009.10.10 W32/Dropper.AMXE
F-Secure 8.0.14470.0 2009.10.09 Trojan-Dropper.Win32.Decay.wn
Fortinet 3.120.0.0 2009.10.10 W32/BWP.WN!tr
GData 19 2009.10.10 Trojan.Generic.2503197
Ikarus T3.1.1.72.0 2009.10.09 Trojan-Dropper.Win32.Decay
Jiangmin 11.0.800 2009.10.08 Trojan/Agent.czhz
K7AntiVirus 7.10.866 2009.10.09 -
Kaspersky 7.0.0.125 2009.10.10 Trojan-Dropper.Win32.Decay.wn
McAfee 5766 2009.10.09 Downloader-BWP
McAfee+Artemis 5766 2009.10.09 Downloader-BWP
McAfee-GW-Edition 6.8.5 2009.10.10 Heuristic.BehavesLike.Win32.Backdoor.A
Microsoft 1.5101 2009.10.10 -
NOD32 4494 2009.10.09 a variant of Win32/Injector.ABX
Norman 6.01.09 2009.10.09 W32/Obfuscated.I!genr
nProtect 2009.1.8.0 2009.10.09 -
Panda 10.0.2.2 2009.10.09 Bck/Bifrost.gen
PCTools 4.4.2.0 2009.10.09 -
Prevx 3.0 2009.10.10 Medium Risk Malware
Rising 21.50.44.00 2009.10.09 Trojan.DL.Win32.FakeAV.dz
Sophos 4.45.0 2009.10.10 Mal/Behav-043
Sunbelt 3.2.1858.2 2009.10.10 -
Symantec 1.4.4.12 2009.10.10 Trojan Horse
TheHacker 6.5.0.2.035 2009.10.10 -
TrendMicro 8.950.0.1094 2009.10.09 -
VBA32 3.12.10.11 2009.10.09 -
ViRobot 2009.10.9.1978 2009.10.09 Trojan.Win32.Agent.59552
VirusBuster 4.6.5.0 2009.10.09 -
Additional information
File size: 47997 bytes
MD5 : 8e1ce69478e5837ce0caf93f5a0ef976
SHA1 : 3b40459fda674b8f83f8568c646fcdf208a253f2
SHA256: 67b6d9f78951f88f976616679ac188c47ad3ec79bae84427b0b00c4286ee5cfb
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x28A1
timedatestamp.....: 0x4AA00F3C (Thu Sep 3 20:47:24 2009)
machinetype.......: 0x14C (Intel I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x1F71 0x2000 6.24 fdaeb5c8bef2e800488534a425780ecc
.rdata 0x3000 0x8A2 0xA00 4.25 85260c4ba1963ec2e498d54df5b26522
.data 0x4000 0x4E0 0x200 4.56 d9a00ed31fcf47d7068e89d1ea171d69
.rsrc 0x5000 0x8892 0x8A00 7.87 a6b16a3c94a1685d4062d2314887cec9

( 2 imports )

> kernel32.dll: GetCurrentProcessId, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetStartupInfoA, InterlockedCompareExchange, Sleep, InterlockedExchange, VirtualProtect, LoadLibraryA, GetProcAddress, GetSystemTimeAsFileTime
> msvcr90.dll: __set_app_type, _crt_debugger_hook, _terminate@@YAXXZ, _unlock, _encode_pointer, _lock, _onexit, _decode_pointer, _except_handler4_common, _invoke_watson, _controlfp_s, __p__fmode, __p__commode, _adjust_fdiv, __setusermatherr, _configthreadlocale, _initterm_e, _initterm, _acmdln, exit, _ismbblead, _XcptFilter, _exit, _cexit, __getmainargs, _amsg_exit, __2@YAPAXI@Z, __dllonexit, __3@YAXPAX@Z, memcpy, __CxxFrameHandler3, memset

( 0 exports )

ssdeep: 768:ENykKeU1Vwlo4IMKAjmGtCzoKjobvuhqqQc33hSpjnkcWrrF5q3AOB:EPDldKAjmGtCz70vuRlw6X1OB
Prevx Info: http://info.prevx.com/aboutprogramtext.asp?PX5=2DD6F0527D6BDAE8BB6000241B807200732736AC
PEiD : -
RDS : NSRL Reference Data Set
-
 
and combofix

ComboFix 09-12-11.01 - Owner 11/12/2009 19:57:22.4.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1568 [GMT 0:00]
Running from: c:\users\Owner\Desktop\ComboFix.exe
Command switches used :: c:\users\Owner\Desktop\CFScript.txt
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\programdata\avg8
c:\programdata\avg8\srmcheck.tmp

.
((((((((((((((((((((((((( Files Created from 2009-11-11 to 2009-12-11 )))))))))))))))))))))))))))))))
.

2009-12-11 20:00 . 2009-12-11 20:09 -------- d-----w- c:\users\Owner\AppData\Local\temp
2009-12-11 20:00 . 2009-12-11 20:00 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-12-11 20:00 . 2009-12-11 20:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-11 20:00 . 2009-12-11 20:00 -------- d-----w- c:\users\apache2triad\AppData\Local\temp
2009-12-11 20:00 . 2009-12-11 20:00 -------- d-----w- c:\users\apache2triad.Shiny-PC\AppData\Local\temp
2009-12-11 20:00 . 2009-12-11 20:00 -------- d-----w- c:\users\Apache\AppData\Local\temp
2009-12-07 17:16 . 2009-12-07 17:18 -------- d-----w- c:\users\Owner\AppData\Local\Adobe
2009-12-06 16:36 . 2009-12-06 16:36 -------- d-----w- c:\users\Owner\AppData\Local\Apple Computer
2009-12-05 16:58 . 2009-12-05 16:58 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-05 16:57 . 2009-12-05 16:57 411368 ----a-w- c:\windows\system32\deploytk.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-08 19:50 . 2008-09-06 23:21 -------- d-----w- c:\program files\Diablo II
2009-12-05 16:56 . 2008-08-19 15:21 -------- d-----w- c:\program files\Java
2009-11-30 00:26 . 2009-09-20 18:42 0 ----a-w- c:\windows\win32k.sys
2009-11-19 16:55 . 2009-06-29 08:08 -------- d-----w- c:\program files\Free Music Zilla
2009-11-12 05:13 . 2009-04-18 02:35 -------- d-----w- c:\users\Owner\AppData\Roaming\IrfanView
2009-11-08 04:52 . 2009-11-08 04:52 -------- d-----w- c:\program files\Microsoft
2009-11-08 04:51 . 2009-11-08 04:51 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-11-08 04:51 . 2008-08-28 00:17 -------- d-----w- c:\program files\Windows Live
2009-11-08 04:50 . 2009-11-08 04:50 -------- d-----w- c:\program files\Common Files\Windows Live
2009-10-19 07:40 . 2009-10-19 07:40 -------- d-----w- c:\program files\Information Packaging
2009-10-19 07:29 . 2009-10-19 07:29 -------- d-----w- c:\program files\Datahjaelp
2009-10-19 07:10 . 2009-10-19 07:09 -------- d-----w- c:\program files\ZIP PASSWORD FINDER
2009-10-02 05:53 . 2009-10-24 18:42 47997 ----a-w- c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desk.exe
2008-08-20 00:02 . 2008-08-20 00:02 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((( SnapShot@2009-12-02_15.10.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:58 . 2009-12-09 15:06 33132 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-12-09 15:06 70414 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-08-26 18:31 . 2009-12-09 13:38 8930 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1283296827-177754420-2501937510-1000_UserData.bin
+ 2009-12-11 20:02 . 2009-12-11 20:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-12-02 15:08 . 2009-12-02 15:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-12-02 15:08 . 2009-12-02 15:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-12-11 20:02 . 2009-12-11 20:02 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-09-17 17:21 . 2009-12-11 12:53 234604 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S4.bin
+ 2006-11-02 10:33 . 2009-12-11 20:06 599942 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-12-02 13:50 599942 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-12-02 13:50 105448 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-12-11 20:06 105448 c:\windows\System32\perfc009.dat
+ 2009-12-05 16:57 . 2009-12-05 16:57 149280 c:\windows\System32\javaws.exe
+ 2009-12-05 16:57 . 2009-12-05 16:57 145184 c:\windows\System32\javaw.exe
+ 2009-12-05 16:57 . 2009-12-05 16:57 145184 c:\windows\System32\java.exe
+ 2008-02-03 23:12 . 2009-12-05 16:55 5813397 c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2006-11-02 10:22 . 2009-12-09 13:36 6291456 c:\windows\System32\SMI\Store\Machine\schema.dat
- 2006-11-02 10:22 . 2009-05-24 02:04 6291456 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2009-12-05 16:58 . 2009-12-05 16:58 3940352 c:\windows\Installer\9fb2400.msi
+ 2009-12-05 16:56 . 2009-12-05 16:56 1757696 c:\windows\Installer\9fb23fc.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-02-12 185872]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-05 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]

c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
desk.exe [2009-10-2 47997]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Cable & Wireless 11g Wireless USB.lnk - c:\program files\Cable&Wireless\C&W_802.11g_Utility\C&WWLAN.exe [2008-10-28 438272]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-08-19 15:31 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Users^Owner^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Free Music Zilla.lnk]
path=c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Free Music Zilla.lnk
backup=c:\windows\pss\Free Music Zilla.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dscactivate]
2008-03-11 11:44 16384 ----a-w- c:\program files\Dell Support Center\gs_agent\custom\dsca.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
2009-05-22 14:04 1217784 ----a-w- c:\program files\Steam\steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-02-12 01:26 185872 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-21 02:23 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1283296827-177754420-2501937510-1000]
"EnableNotificationsRef"=dword:00000001

.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.altavista.com/
uInternet Settings,ProxyOverride = <local>
Trusted Zone: filesmonster.com
FF - ProfilePath - c:\users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\d4tovtom.default\
FF - prefs.js: browser.startup.homepage - google.co.uk
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-AV Care - c:\program files\AV Care\AvCare.exe
MSConfigStartUp-AVG8_TRAY - c:\progra~1\AVG\AVG8\avgtray.exe
MSConfigStartUp-Monopod - c:\users\Owner\AppData\Local\Temp\e.exe
MSConfigStartUp-NordBull - c:\users\Owner\AppData\Local\Temp\b.exe
MSConfigStartUp-PopRock - c:\users\Owner\AppData\Local\Temp\b.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-11 20:09
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'Explorer.exe'(3524)
c:\windows\system32\ieframe.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
.
**************************************************************************
.
Completion time: 2009-12-11 20:11:33 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-11 20:11
ComboFix2.txt 2009-12-09 15:08
ComboFix3.txt 2009-12-03 18:10
ComboFix4.txt 2009-12-02 15:13

Pre-Run: 98,702,659,584 bytes free
Post-Run: 99,815,051,264 bytes free

- - End Of File - - 3FDC1B7D05EE3CC9FBD6C1E5B41E5840
 
Hi,

Disable Windows Defender and run ComboFix with this script (have internet connection enabled during the run):
Code:
http://forums.spybot.info/showthread.php?p=351198#post351198
Collect::
c:\users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\desk.exe
File::
c:\windows\win32k.sys

Post back the results.
 
Back
Top