Herokazz
2010-07-28, 22:43
Hi folk
I have a serious virus on my computer. :(
I have reviewed this tread: http://forums.spybot.info/showthread.php?t=22288
It is the same with my computer im sure. And im affraid I tried to fix the problem my self without your guidence. I ran Combofix a few times as explained in the above thread. It helped a bit. Now i can access my Harddrives.
But im sure the infiction is not entirely gone yet.
I have read your the what-to-do-to-make-a-thread thread.
Here is the DDS and Attach notepads:
DDS:
DDS (Ver_10-03-17.01) - NTFSx86
Run by Administrator at 21:25:52,62 on 28-07-2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3199.2665 [GMT 2:00]
============== Running Processes ===============
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Documents and Settings\Administrator\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Hentede filer\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [DigidesignMMERefresh] c:\program files\digidesign\drivers\MMERefresh.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
dRunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\administrator\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
uPolicies-explorer: NoResolveTrack = 1 (0x1)
uPolicies-explorer: NoInstrumentation = 1 (0x1)
mPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
dPolicies-explorer: NoResolveTrack = 1 (0x1)
dPolicies-explorer: NoInstrumentation = 1 (0x1)
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\yxs7w191.default\
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-7-28 216400]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-7-28 29584]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-7-28 243024]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-7-28 921440]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-7-28 308136]
R2 DigiNet;Digidesign Ethernet Support;c:\windows\system32\drivers\diginet.sys [2010-4-20 16400]
R2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32mpcoinst,serviceStartProc --> RUNDLL32.EXE ykx32mpcoinst,serviceStartProc [?]
R3 dalwdmservice;dal service;c:\windows\system32\drivers\Dalwdm.sys [2010-4-20 85008]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-4-20 1684736]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\manycam.sys --> c:\windows\system32\drivers\ManyCam.sys [?]
=============== Created Last 30 ================
2010-07-28 19:04:03 0 d-----w- c:\windows\system32\xircom
2010-07-28 19:04:03 0 d-----w- c:\windows\system32\wbem\snmp
2010-07-28 18:58:05 0 d-----w- C:\ComboFix
2010-07-28 18:37:54 0 d-----w- c:\program files\Trend Micro
2010-07-28 18:30:47 98816 ----a-w- c:\windows\sed.exe
2010-07-28 18:30:47 77312 ----a-w- c:\windows\MBR.exe
2010-07-28 18:30:47 256512 ----a-w- c:\windows\PEV.exe
2010-07-28 18:30:47 161792 ----a-w- c:\windows\SWREG.exe
2010-07-28 17:48:26 0 d-----w- C:\$AVG
2010-07-28 17:42:24 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-28 17:42:23 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-28 17:42:19 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-07-28 17:42:17 0 d-----w- c:\windows\system32\drivers\Avg
2010-07-28 17:40:29 0 d-----w- c:\program files\AVG
2010-07-28 17:40:18 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9
2010-07-27 13:50:57 0 d-----w- c:\program files\FXpansion
2010-07-27 13:35:47 0 d-----w- c:\program files\VstPlugins
2010-07-27 13:35:47 0 d-----w- c:\program files\Toontrack
2010-07-27 13:28:14 0 d-----w- c:\program files\XLN Audio
2010-07-14 09:02:15 116224 --sh--r- C:\i8gcgmg.exe
2010-07-13 11:36:54 393216 ----a-w- c:\windows\system32\NI_IRC_1_2.dll
2010-07-13 11:36:49 61440 ----a-w- c:\windows\system32\NI_DFD_1_5.dll
2010-07-13 11:36:49 1870336 ----a-w- c:\windows\system32\bconvert.dll
2010-07-13 11:36:49 0 d-----w- c:\program files\Native Instruments
2010-07-13 11:36:49 0 d-----w- c:\program files\common files\Native Instruments
2010-07-13 08:34:02 116736 --sh--r- C:\r3x0k.exe
==================== Find3M ====================
============= FINISH: 21:26:12,20 ===============
Attach:
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-03-17.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 20-04-2010 08:49:35
System Uptime: 28-07-2010 21:03:24 (0 hours ago)
Motherboard: ASUSTeK Computer INC. | | P5W DH Deluxe
Processor: Intel(R) Core(TM)2 Duo CPU E6750 @ 2.66GHz | LGA 775 | 2667/333mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 298 GiB total, 281,246 GiB free.
D: is FIXED (NTFS) - 79 GiB total, 30,529 GiB free.
E: is FIXED (NTFS) - 387 GiB total, 264,547 GiB free.
F: is Removable
G: is Removable
H: is Removable
I: is Removable
J: is CDROM ()
K: is FIXED (NTFS) - 233 GiB total, 15,808 GiB free.
L: is CDROM ()
M: is FIXED (NTFS) - 466 GiB total, 146,036 GiB free.
==== Disabled Device Manager Items =============
Class GUID:
Description: USB Device
Device ID: USB\VID_0763&PID_1014\7&213E136A&0&2
Manufacturer:
Name: USB Device
PNP Device ID: USB\VID_0763&PID_1014\7&213E136A&0&2
Service:
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: RTL8187_Wireless
Device ID: USB\VID_0BDA&PID_8187\0015AF22D622
Manufacturer:
Name: RTL8187_Wireless
PNP Device ID: USB\VID_0BDA&PID_8187\0015AF22D622
Service:
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description:
Device ID: ACPI\ATK0110\1010110
Manufacturer:
Name:
PNP Device ID: ACPI\ATK0110\1010110
Service:
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: SM Bus Controller
Device ID: PCI\VEN_8086&DEV_27DA&SUBSYS_81791043&REV_01\3&11583659&0&FB
Manufacturer:
Name: SM Bus Controller
PNP Device ID: PCI\VEN_8086&DEV_27DA&SUBSYS_81791043&REV_01\3&11583659&0&FB
Service:
==== System Restore Points ===================
RP1: 28-07-2010 20:10:16 - System Checkpoint
RP2: 28-07-2010 20:37:53 - Installed HiJackThis
==== Installed Programs ======================
µTorrent
Addictive Drums
Adobe Anchor Service CS4
Adobe Bridge CS4
Adobe CMaps CS4
Adobe Color - Photoshop Specific CS4
Adobe Color EU Extra Settings CS4
Adobe Color JA Extra Settings CS4
Adobe Color NA Recommended Settings CS4
Adobe Color Video Profiles CS CS4
Adobe CSI CS4
Adobe Default Language CS4
Adobe Dreamweaver CS4
Adobe ExtendScript Toolkit CS4
Adobe Flash Player 10 Plugin
Adobe Fonts All
Adobe Linguistics CS4
Adobe Output Module
Adobe PDF Library Files CS4
Adobe Photoshop CS4
Adobe Photoshop CS4 Support
Adobe Reader 9.3.3 - Dansk
Adobe Search for Help
Adobe Service Manager Extension
Adobe Setup
Adobe Type Support CS4
Adobe Update Manager CS4
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS4
AdobeColorCommonSetCMYK
AdobeColorCommonSetRGB
Antares Auto-Tune Evo RTAS
Antares Autotune VST RTAS TDM v5.08
Apple Application Support
Apple Software Update
AVG Free 9.0
Connect
Digidesign Audio Drivers 8.0.3
Digidesign ElevenRack Driver 1.0.8 (x86)
Digidesign MP3 Option 8.0
Digidesign Music Production Toolkit 7.4
Digidesign Pro Tools Creative Collection 8.0.3
Digidesign Pro Tools LE 8.0.3
Dropbox
ERUNT 1.1j
EZdrummer
EZXNashville
EZXPercussion
Free DigiRack Plug-Ins 8.0.3
HiJackThis
Interlok driver setup x32
Java Auto Updater
Java(TM) 6 Update 20
kuler
Marvell Miniport Driver
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (3.6.8)
Native.Instruments Battery v3.0.1.005 VSTi DXi RTAS
NVIDIA Drivers
NVIDIA PhysX
OpenOffice.org 3.2
PDF Settings CS4
Photoshop Camera Raw
QuickTime
Realtek High Definition Audio Driver
SSH Secure Shell
Suite Shared Configuration CS4
TL Space Native 7.4
UltraISO Premium V9.35
VLC media player 1.0.5
Vst To Rtas Adapter V2.11
Waves Mercury Bundle
WebFldrs XP
Winamp
Winamp Detector Plug-in
Windows Internet Explorer 8
Windows Media Format Runtime
WinRAR archiver
==== Event Viewer Messages From Past Week ========
22-07-2010 12:06:21, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC80.DebugCRT. Reference error message: The referenced assembly is not installed on your system. .
22-07-2010 12:06:21, error: SideBySide [59] - Generate Activation Context failed for c:\Program Files\Common Files\Digidesign\DAE\Controllers\C24_Resource804.dll. Reference error message: The operation completed successfully. .
22-07-2010 12:06:21, error: SideBySide [59] - Generate Activation Context failed for c:\Program Files\Common Files\Digidesign\DAE\Controllers\C24_Resource412.dll. Reference error message: The operation completed successfully. .
22-07-2010 12:06:21, error: SideBySide [59] - Generate Activation Context failed for c:\Program Files\Common Files\Digidesign\DAE\Controllers\C24_Resource411.dll. Reference error message: The operation completed successfully. .
22-07-2010 12:06:21, error: SideBySide [59] - Generate Activation Context failed for c:\Program Files\Common Files\Digidesign\DAE\Controllers\C24_Resource404.dll. Reference error message: The operation completed successfully. .
22-07-2010 12:06:21, error: SideBySide [59] - Generate Activation Context failed for c:\Program Files\Common Files\Digidesign\DAE\Controllers\003_Resource804.dll. Reference error message: The operation completed successfully. .
22-07-2010 12:06:21, error: SideBySide [59] - Generate Activation Context failed for c:\Program Files\Common Files\Digidesign\DAE\Controllers\003_Resource412.dll. Reference error message: The operation completed successfully. .
22-07-2010 12:06:21, error: SideBySide [59] - Generate Activation Context failed for c:\Program Files\Common Files\Digidesign\DAE\Controllers\003_Resource404.dll. Reference error message: The operation completed successfully. .
22-07-2010 12:06:21, error: SideBySide [32] - Dependent Assembly Microsoft.VC80.DebugCRT could not be found and Last Error was The referenced assembly is not installed on your system.
==== End Of File ===========================
I have a serious virus on my computer. :(
I have reviewed this tread: http://forums.spybot.info/showthread.php?t=22288
It is the same with my computer im sure. And im affraid I tried to fix the problem my self without your guidence. I ran Combofix a few times as explained in the above thread. It helped a bit. Now i can access my Harddrives.
But im sure the infiction is not entirely gone yet.
I have read your the what-to-do-to-make-a-thread thread.
Here is the DDS and Attach notepads:
DDS:
DDS (Ver_10-03-17.01) - NTFSx86
Run by Administrator at 21:25:52,62 on 28-07-2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3199.2665 [GMT 2:00]
============== Running Processes ===============
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Documents and Settings\Administrator\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Hentede filer\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [DigidesignMMERefresh] c:\program files\digidesign\drivers\MMERefresh.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
dRunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\administrator\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
uPolicies-explorer: NoResolveTrack = 1 (0x1)
uPolicies-explorer: NoInstrumentation = 1 (0x1)
mPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
dPolicies-explorer: NoResolveTrack = 1 (0x1)
dPolicies-explorer: NoInstrumentation = 1 (0x1)
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\yxs7w191.default\
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".dk");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-7-28 216400]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-7-28 29584]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-7-28 243024]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-7-28 921440]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-7-28 308136]
R2 DigiNet;Digidesign Ethernet Support;c:\windows\system32\drivers\diginet.sys [2010-4-20 16400]
R2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32mpcoinst,serviceStartProc --> RUNDLL32.EXE ykx32mpcoinst,serviceStartProc [?]
R3 dalwdmservice;dal service;c:\windows\system32\drivers\Dalwdm.sys [2010-4-20 85008]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-4-20 1684736]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\manycam.sys --> c:\windows\system32\drivers\ManyCam.sys [?]
=============== Created Last 30 ================
2010-07-28 19:04:03 0 d-----w- c:\windows\system32\xircom
2010-07-28 19:04:03 0 d-----w- c:\windows\system32\wbem\snmp
2010-07-28 18:58:05 0 d-----w- C:\ComboFix
2010-07-28 18:37:54 0 d-----w- c:\program files\Trend Micro
2010-07-28 18:30:47 98816 ----a-w- c:\windows\sed.exe
2010-07-28 18:30:47 77312 ----a-w- c:\windows\MBR.exe
2010-07-28 18:30:47 256512 ----a-w- c:\windows\PEV.exe
2010-07-28 18:30:47 161792 ----a-w- c:\windows\SWREG.exe
2010-07-28 17:48:26 0 d-----w- C:\$AVG
2010-07-28 17:42:24 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-28 17:42:23 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-28 17:42:19 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-07-28 17:42:17 0 d-----w- c:\windows\system32\drivers\Avg
2010-07-28 17:40:29 0 d-----w- c:\program files\AVG
2010-07-28 17:40:18 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9
2010-07-27 13:50:57 0 d-----w- c:\program files\FXpansion
2010-07-27 13:35:47 0 d-----w- c:\program files\VstPlugins
2010-07-27 13:35:47 0 d-----w- c:\program files\Toontrack
2010-07-27 13:28:14 0 d-----w- c:\program files\XLN Audio
2010-07-14 09:02:15 116224 --sh--r- C:\i8gcgmg.exe
2010-07-13 11:36:54 393216 ----a-w- c:\windows\system32\NI_IRC_1_2.dll
2010-07-13 11:36:49 61440 ----a-w- c:\windows\system32\NI_DFD_1_5.dll
2010-07-13 11:36:49 1870336 ----a-w- c:\windows\system32\bconvert.dll
2010-07-13 11:36:49 0 d-----w- c:\program files\Native Instruments
2010-07-13 11:36:49 0 d-----w- c:\program files\common files\Native Instruments
2010-07-13 08:34:02 116736 --sh--r- C:\r3x0k.exe
==================== Find3M ====================
============= FINISH: 21:26:12,20 ===============
Attach:
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-03-17.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 20-04-2010 08:49:35
System Uptime: 28-07-2010 21:03:24 (0 hours ago)
Motherboard: ASUSTeK Computer INC. | | P5W DH Deluxe
Processor: Intel(R) Core(TM)2 Duo CPU E6750 @ 2.66GHz | LGA 775 | 2667/333mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 298 GiB total, 281,246 GiB free.
D: is FIXED (NTFS) - 79 GiB total, 30,529 GiB free.
E: is FIXED (NTFS) - 387 GiB total, 264,547 GiB free.
F: is Removable
G: is Removable
H: is Removable
I: is Removable
J: is CDROM ()
K: is FIXED (NTFS) - 233 GiB total, 15,808 GiB free.
L: is CDROM ()
M: is FIXED (NTFS) - 466 GiB total, 146,036 GiB free.
==== Disabled Device Manager Items =============
Class GUID:
Description: USB Device
Device ID: USB\VID_0763&PID_1014\7&213E136A&0&2
Manufacturer:
Name: USB Device
PNP Device ID: USB\VID_0763&PID_1014\7&213E136A&0&2
Service:
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: RTL8187_Wireless
Device ID: USB\VID_0BDA&PID_8187\0015AF22D622
Manufacturer:
Name: RTL8187_Wireless
PNP Device ID: USB\VID_0BDA&PID_8187\0015AF22D622
Service:
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description:
Device ID: ACPI\ATK0110\1010110
Manufacturer:
Name:
PNP Device ID: ACPI\ATK0110\1010110
Service:
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: SM Bus Controller
Device ID: PCI\VEN_8086&DEV_27DA&SUBSYS_81791043&REV_01\3&11583659&0&FB
Manufacturer:
Name: SM Bus Controller
PNP Device ID: PCI\VEN_8086&DEV_27DA&SUBSYS_81791043&REV_01\3&11583659&0&FB
Service:
==== System Restore Points ===================
RP1: 28-07-2010 20:10:16 - System Checkpoint
RP2: 28-07-2010 20:37:53 - Installed HiJackThis
==== Installed Programs ======================
µTorrent
Addictive Drums
Adobe Anchor Service CS4
Adobe Bridge CS4
Adobe CMaps CS4
Adobe Color - Photoshop Specific CS4
Adobe Color EU Extra Settings CS4
Adobe Color JA Extra Settings CS4
Adobe Color NA Recommended Settings CS4
Adobe Color Video Profiles CS CS4
Adobe CSI CS4
Adobe Default Language CS4
Adobe Dreamweaver CS4
Adobe ExtendScript Toolkit CS4
Adobe Flash Player 10 Plugin
Adobe Fonts All
Adobe Linguistics CS4
Adobe Output Module
Adobe PDF Library Files CS4
Adobe Photoshop CS4
Adobe Photoshop CS4 Support
Adobe Reader 9.3.3 - Dansk
Adobe Search for Help
Adobe Service Manager Extension
Adobe Setup
Adobe Type Support CS4
Adobe Update Manager CS4
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS4
AdobeColorCommonSetCMYK
AdobeColorCommonSetRGB
Antares Auto-Tune Evo RTAS
Antares Autotune VST RTAS TDM v5.08
Apple Application Support
Apple Software Update
AVG Free 9.0
Connect
Digidesign Audio Drivers 8.0.3
Digidesign ElevenRack Driver 1.0.8 (x86)
Digidesign MP3 Option 8.0
Digidesign Music Production Toolkit 7.4
Digidesign Pro Tools Creative Collection 8.0.3
Digidesign Pro Tools LE 8.0.3
Dropbox
ERUNT 1.1j
EZdrummer
EZXNashville
EZXPercussion
Free DigiRack Plug-Ins 8.0.3
HiJackThis
Interlok driver setup x32
Java Auto Updater
Java(TM) 6 Update 20
kuler
Marvell Miniport Driver
Microsoft Silverlight
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (3.6.8)
Native.Instruments Battery v3.0.1.005 VSTi DXi RTAS
NVIDIA Drivers
NVIDIA PhysX
OpenOffice.org 3.2
PDF Settings CS4
Photoshop Camera Raw
QuickTime
Realtek High Definition Audio Driver
SSH Secure Shell
Suite Shared Configuration CS4
TL Space Native 7.4
UltraISO Premium V9.35
VLC media player 1.0.5
Vst To Rtas Adapter V2.11
Waves Mercury Bundle
WebFldrs XP
Winamp
Winamp Detector Plug-in
Windows Internet Explorer 8
Windows Media Format Runtime
WinRAR archiver
==== Event Viewer Messages From Past Week ========
22-07-2010 12:06:21, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC80.DebugCRT. Reference error message: The referenced assembly is not installed on your system. .
22-07-2010 12:06:21, error: SideBySide [59] - Generate Activation Context failed for c:\Program Files\Common Files\Digidesign\DAE\Controllers\C24_Resource804.dll. Reference error message: The operation completed successfully. .
22-07-2010 12:06:21, error: SideBySide [59] - Generate Activation Context failed for c:\Program Files\Common Files\Digidesign\DAE\Controllers\C24_Resource412.dll. Reference error message: The operation completed successfully. .
22-07-2010 12:06:21, error: SideBySide [59] - Generate Activation Context failed for c:\Program Files\Common Files\Digidesign\DAE\Controllers\C24_Resource411.dll. Reference error message: The operation completed successfully. .
22-07-2010 12:06:21, error: SideBySide [59] - Generate Activation Context failed for c:\Program Files\Common Files\Digidesign\DAE\Controllers\C24_Resource404.dll. Reference error message: The operation completed successfully. .
22-07-2010 12:06:21, error: SideBySide [59] - Generate Activation Context failed for c:\Program Files\Common Files\Digidesign\DAE\Controllers\003_Resource804.dll. Reference error message: The operation completed successfully. .
22-07-2010 12:06:21, error: SideBySide [59] - Generate Activation Context failed for c:\Program Files\Common Files\Digidesign\DAE\Controllers\003_Resource412.dll. Reference error message: The operation completed successfully. .
22-07-2010 12:06:21, error: SideBySide [59] - Generate Activation Context failed for c:\Program Files\Common Files\Digidesign\DAE\Controllers\003_Resource404.dll. Reference error message: The operation completed successfully. .
22-07-2010 12:06:21, error: SideBySide [32] - Dependent Assembly Microsoft.VC80.DebugCRT could not be found and Last Error was The referenced assembly is not installed on your system.
==== End Of File ===========================