View Full Version : Notebook Infection

2011-10-24, 12:50
This notebook computer is infected and would not run anything until I ran rkill.exe.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Sue Sun at 5:32:05 on 2011-10-24
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.574 [GMT -4:00]
AV: Norton 360 *Enabled/Outdated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *Enabled*
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Lenovo\Energy Management\utility.exe
C:\Program Files\Lenovo\Energy Management\Energy Management.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\Norton 360\Engine\\ccSvcHst.exe
C:\Program Files\Norton 360\Engine\\ccSvcHst.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mWinlogon: Userinit=c:\windows\system32\userinit.exe
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\\coIEPlg.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [EnergyUtility] c:\program files\lenovo\energy management\utility.exe
mRun: [Energy Management] c:\program files\lenovo\energy management\Energy Management.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {036F8A56-0BC8-4607-8F98-D3231E6FF5ED} - hxxp://
DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} - hxxps://img.alipay.com/download/2121/aliedit.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1254507441546
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1254507421187
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
TCP: NameServer =,
TCP: Interfaces\{1CBCD7E4-5CB8-4BFC-8CC3-7A108954766D} : NameServer =,
TCP: Interfaces\{AE8E9B13-9F01-4855-8C5F-8AE7F146BE4F} : NameServer =,
TCP: Interfaces\{AE8E9B13-9F01-4855-8C5F-8AE7F146BE4F} : DhcpNameServer =
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\platform\puresp4.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\norton 360\engine\\CoIEPlg.dll
Notify: igfxcui - igfxdev.dll
Notify: PicNotify - PicNotify.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
============= SERVICES / DRIVERS ===============
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0308030.006\SymEFA.sys [2011-10-21 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0308030.006\BHDrvx86.sys [2011-10-21 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0308030.006\cchpx86.sys [2011-10-21 467592]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20110425.001\IDSXpx86.sys [2011-4-27 341944]
R2 DvmMDES;DeviceVM Meta Data Export Service;c:\qstart.sys\config\DVMExportService.exe [2008-12-1 307200]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-11-5 54752]
R2 N360;Norton 360;c:\program files\norton 360\engine\\ccSvcHst.exe [2011-10-21 117648]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\drivers\AcpiVpc.sys [2009-3-2 9472]
R3 Alidevice;Alidevice;c:\windows\system32\drivers\alidevice.sys [2008-7-13 6656]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-4-27 102448]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20110426.037\NAVENG.SYS [2011-4-27 86136]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20110426.037\NAVEX15.SYS [2011-4-27 1393144]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [2009-3-2 157696]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-3-2 1684736]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 PCD5SRVC{DF187064-5DA14001-05040000};PCD5SRVC{DF187064-5DA14001-05040000} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\pcdr5\PCD5SRVC.pkms [2008-5-7 21280]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\drivers\rts516xir.sys --> c:\windows\system32\drivers\Rts516xIR.sys [?]
=============== Created Last 30 ================
2011-10-21 19:59:02 89976 ----a-w- c:\windows\system32\drivers\n360\0308030.006\symfw.sys
2011-10-21 19:59:02 48760 ----a-w- c:\windows\system32\drivers\n360\0308030.006\symndisv.sys
2011-10-21 19:59:02 467592 ----a-w- c:\windows\system32\drivers\n360\0308030.006\cchpx86.sys
2011-10-21 19:59:02 43696 ----a-w- c:\windows\system32\drivers\n360\0308030.006\srtspx.sys
2011-10-21 19:59:02 36472 ----a-w- c:\windows\system32\drivers\n360\0308030.006\symndis.sys
2011-10-21 19:59:02 33144 ----a-w- c:\windows\system32\drivers\n360\0308030.006\symids.sys
2011-10-21 19:59:02 310320 ----a-w- c:\windows\system32\drivers\n360\0308030.006\SymEFA.sys
2011-10-21 19:59:02 308272 ----a-w- c:\windows\system32\drivers\n360\0308030.006\srtsp.sys
2011-10-21 19:59:02 259632 ----a-w- c:\windows\system32\drivers\n360\0308030.006\BHDrvx86.sys
2011-10-21 19:59:02 217464 ----a-w- c:\windows\system32\drivers\n360\0308030.006\symtdi.sys
2011-10-21 19:58:40 -------- d-----w- c:\windows\system32\drivers\n360\0308030.006
2011-10-20 05:04:20 -------- d--h--w- C:\dvmexp
2011-10-20 04:56:48 -------- d-----w- c:\windows\pss
==================== Find3M ====================
=================== ROOTKIT ====================
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD1600BEVS-08VAT2 rev.14.01A14 -> Harddisk0\DR0 -> \Device\Ide\IdePort1 P1T0L0-5
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x86ACCEC5]<<
_asm { PUSH EBP; MOV EBP, ESP; SUB ESP, 0x1c; PUSH EBX; PUSH ESI; MOV DWORD [EBP-0x4], 0x85005872; SUB DWORD [EBP-0x4], 0x8500512e; PUSH EDI; CALL 0xffffffffffffdf33; }
1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x86B72AB8]
3 CLASSPNP[0xF763DFD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> [0x86AA07D8]
[0x86B88B78] -> IRP_MJ_CREATE -> 0x86ACCEC5
kernel: MBR read successfully
_asm { JMP 0x10; }
detected disk devices:
\Device\Ide\IdeDeviceP1T0L0-5 -> \??\IDE#DiskWDC_WD1600BEVS-08VAT2___________________14.01A14#5&2e7347c&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
\Driver\atapi DriverStartIo -> 0x86ACCAEA
user & kernel MBR OK
sectors 312581806 (+255): user != kernel
Warning: possible TDL3 rootkit infection !
============= FINISH: 5:35:05.95 ===============

2011-10-24, 18:30
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
The fixes are specific to your problem and should only be used for the issues on this machine.
Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
It's often worth reading through these instructions and printing them for ease of reference.
If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.

Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")

Stay with this topic until I give you the all clean post.

I see that you have rkill.exe already on your system? Please run that and then do the following:

Please download TDSSKiller.zip (http://support.kaspersky.com/downloads/utils/tdsskiller.zip)

Extract it to your desktop
Double click TDSSKiller.exe
Press Start Scan

Only if Malicious objects are found then ensure Cure is selected
Then click Continue > Reboot now

Copy and paste the log in your next reply

A copy of the log will be saved automatically to the root of the drive (typically C:\)

2011-10-25, 10:47
Hi Jeff,

Thank you so much for your help.
1. Have not subscribed to the topic, as I have not found the "watch topic" button.
2. Computer was unable to browse the net, so I downloaded TDSSKiller.exe to a usb drive from another computer and copied it to the infected computer desk top.
3. TDSSKiller.exe found and cured one threat. See attached log.


2011-10-25, 14:44
Hi roger.f,

Have not subscribed to the topic, as I have not found the "watch topic" button. Sorry about that...go to the top of the page > press Topic Tools and you can subscribe to the topic there. :)

Great job running the TDSSKiller tool. You had a nasty rootkit on your system that has now been removed. Let's see what else was buried with it.

You will need an internet connection for the next part. Did you regain that after using TDSSKiller? If not use the USB drive that you used before to transfer this next tool. If you have questions be sure to ask. :)

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
Link 2 (http://www.infospyware.net/antimalware/combofix/)

* IMPORTANT !!! Save ComboFix.exe to your Desktop

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs (http://forums.whatthetech.com/How_to_Disable_your_Security_Programs_t96260.html)

Double click on ComboFix.exe & follow the prompts.

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

In your next reply let me know if you had any problems downloading and running ComboFix. If there were no problems, please post the log created by Combofix into your next reply.

2011-10-26, 11:36
Hi Jeff,

I am now able to access the internet. I downloaded combofix to the target machine and successfuly completed the combofix scan. See attached log.

Thanks, Roger

2011-10-26, 14:49
Hi Roger,

I am glad you have your internet connection back. :)

Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
TCP: NameServer =,
TCP: Interfaces\{1CBCD7E4-5CB8-4BFC-8CC3-7A108954766D} : NameServer =,
TCP: Interfaces\{AE8E9B13-9F01-4855-8C5F-8AE7F146BE4F} : NameServer =,

Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.


Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

2011-10-26, 23:08
Hi Jeff,
Requested task completed and new comboFix log attached.

2011-10-27, 03:21
Hi roger f,

If you don't mind would you please copy/paste the results into the replies. It helps me to read the more easily. Thank you. :)

Please download Malwarebytes' Anti-Malware (http://www.malwarebytes.org/mbam-download.php) to your desktop.

Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan as shown below.


When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.

The log can also be found here:
C:\Documents and Settings\<User name>\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

ESET Online Scanner
I'd like us to scan your machine with ESET Online Scan

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.

Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan (http://eset.com/onlinescan)
Click the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetOnline.png button.
For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
Click on http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetSmartInstall.png to download the ESET Smart Installer. Save it to your desktop.
Double click on the http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetSmartInstallDesktopIcon.png icon on your desktop.

Check http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetAcceptTerms.png
Click the Start button.
Accept any security warnings from your browser.
Check http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetScanArchives.png
Make sure that the option "Remove found threats" is Unchecked
Push the Start button.
ESET will then download updates for itself, install itself, and begin
scanning your computer. Please be patient as this can take some time.
When the scan completes, push http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetListThreats.png
Push http://billy-oneal.com/Canned%20Speeches/speechimages/eset/esetExport.png, and save the file to your desktop using a unique name, such as
ESETScan. Include the contents of this report in your next reply.
Push the Back button.
Push Finish


In your next reply please post the logs created by Malwarebytes and ESET online scanner.

2011-10-28, 07:33
Hey Jeff,

I tried to do all the procedures requested, but ran into issues as follows:
1. was able to open safer-networking forums from the target machine, but could not download malwarebytes through the target link.
2. Loaded the malwarebytes installation program onto a USB drive from another computer. Copied it to the target desktop. double clicked, installed and ran on target. Program successfully retrieved updates and successfully completed scan. clicked "show results and two Trojans were found. Clicked remove selected and program requested a reboot to complete the removal process. See log file.
3. When the target computer rebooted i got the message "No Bootable Partition in Table" and the computer hung. After pressing many keys and no activity, I pressed the on/off switch and the target computer successfully rebooted, but at this point there is no internet connectivity at all.
4. Tried to run ESET Online scanner after copying the installation program from another computer through the USB drive. Program produced the message "Can not get update. Is proxy configured?"

So what do I do now???

Thanks, Roger

Malwarebytes' Anti-Malware

Database version: 7622

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

10/27/2011 8:42:57 PM
mbam-log-2011-10-27 (20-42-57).txt

Scan type: Quick scan
Objects scanned: 162563
Time elapsed: 3 minute(s), 32 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1CBCD7E4-5CB8-4BFC-8CC3-7A108954766D}\NameServer (Trojan.DNSChanger) -> Bad: (, Good: () -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{AE8E9B13-9F01-4855-8C5F-8AE7F146BE4F}\NameServer (Trojan.DNSChanger) -> Bad: (, Good: () -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

2011-10-28, 09:14
Oops in addition to my response above. I noticed in the very first step you told me to run rkill.exe and then to run TDSSKiller. I neglected to run rkill.exe and went directly to TDSKiller. Do we need to go back and run rkill.exe now?

2011-10-28, 14:29
Hi roger,

No no don't worry about rkill right now. :)

Do an online scan with BitDefender QuickScan.
Please be patient as scanning may take some time. If you have problem running the scan, you might want to disable any real time protection that you have.

Click here (http://quickscan.bitdefender.com/) to go to BitDefender QuickScan page.
For Firefox users:
Click on Free Scan Now. You will be prompted to install a plug-in. Please Allow. In case you get stuck, please refresh the page to try again.
A Software Installation window will appear. Click Install Now and the plugin will be installed as an Add-on.
Restart Firefox when done. Go back to the BitDefender QuickScan page again and click on Free Scan Now and proceed accordingly.
For Internet Explorer users:
Click on Free Scan Now. You will be prompted to install an ActiveX control. Please install.
The page will refresh. Click on Free Scan Now again and proceed accordingly.
When scan has completed, click on View report and a Notepad log shall open.
If there are any infections found, you will get a warning and the link to the report will be displayed as the number of infections. Click on it.
Post back the contents of this report. It can also be found at C:\Documents and Settings\<username>\Application Data\QuickScan, <username> is the Windows log-in name.

2011-10-29, 04:31
After malwarebytes anti-malware removed the two Trojans the target computer will not go online at all. See my response above when I tried to run the ESET scanner. I am doing everything by loading the program on a USB drive on another computer. BitDefender would not allow me to load the program onto a USB drive. I think the Trojans were messing with the DNS mapping and when they were removed it messed up access to any internet location.


2011-10-29, 05:14
Hi roger,

Please do the following:

Hold down the Windows key and press R to open a run box
type the following text into the run box and press Enter


This will open your Command Prompt.

Copy/Paste the following bolded text into the command prompt and press Enter.

ipconfig /flushdns

Reboot your system and then test out the internet and let me know if it works now. :)

2011-10-29, 10:29
I performed the steps requested (ipconfig /flushDNS) and still no internet connectivity. Tried reconfiguring the ethernet interface which had no impact on the problem. The log below is from the internet repair tool.
Please advise what to do next.


Last diagnostic run time: 10/29/11 00:03:46 DNS Client Diagnostic
DNS - Not a home user scenario

info Using Web Proxy: no
info Resolving name ok for (www.microsoft.com): no
warn Unrecognized WinSock NSP: mdnsNSP
No DNS servers

action Automated repair: Renew IP address
action Releasing the current IP address...
action Successfully released the current IP address
action Renewing the IP address...
action Successfully renewed the current IP address
info Redirecting user to support call

Gateway Diagnostic

info The following proxy configuration is being used by IE: Automatically Detect Settings:Disabled Automatic Configuration Script: Proxy Server: Proxy Bypass list:
info This computer has the following default gateway entry(ies):
info This computer has the following IP address(es):
info The default gateway is in the same subnet as this computer
info The default gateway entry is a valid unicast address
info The default gateway address was resolved via ARP in 1 try(ies)
info The default gateway was reached via ICMP Ping in 1 try(ies)
warn Hostname www.microsoft.com could not be resolved (Error code 0x2afc). Could be either gateway or DNS issue
action Automated repair: Renew IP address
action Releasing the current IP address...
action Successfully released the current IP address
action Renewing the IP address...
action Successfully renewed the current IP address
info This computer has the following default gateway entry(ies):
info This computer has the following IP address(es):
info The default gateway is in the same subnet as this computer
info The default gateway entry is a valid unicast address
info The default gateway address was resolved via ARP in 1 try(ies)
info The default gateway was reached via ICMP Ping in 1 try(ies)
warn Hostname www.microsoft.com could not be resolved (Error code 0x2afc). Could be either gateway or DNS issue
action Automated repair: Reset network connection
action Disabling the network adapter
action Enabling the network adapter
info Network adapter successfully enabled
info This computer has the following default gateway entry(ies):
info This computer has the following IP address(es):
info The default gateway is in the same subnet as this computer
info The default gateway entry is a valid unicast address
info The default gateway address was resolved via ARP in 1 try(ies)
info The default gateway was reached via ICMP Ping in 1 try(ies)
warn Hostname www.microsoft.com could not be resolved (Error code 0x2afc). Could be either gateway or DNS issue
action Manual repair: Reboot modem
info This computer has the following default gateway entry(ies):
info This computer has the following IP address(es):
info The default gateway is in the same subnet as this computer
info The default gateway entry is a valid unicast address
info The default gateway address was resolved via ARP in 1 try(ies)
info The default gateway was reached via ICMP Ping in 1 try(ies)
warn Hostname www.microsoft.com could not be resolved (Error code 0x2afc). Could be either gateway or DNS issue
info Waiting some time for the modem/router to stabilize
action Automated repair: Renew IP address
action Releasing the current IP address...
action Successfully released the current IP address
action Renewing the IP address...
action Successfully renewed the current IP address
info This computer has the following default gateway entry(ies):
info This computer has the following IP address(es):
info The default gateway is in the same subnet as this computer
info The default gateway entry is a valid unicast address
info The default gateway address was resolved via ARP in 1 try(ies)
info The default gateway was reached via ICMP Ping in 1 try(ies)
warn Hostname www.microsoft.com could not be resolved (Error code 0x2afc). Could be either gateway or DNS issue
info Waiting some time for the modem/router to stabilize
action Automated repair: Renew IP address
action Releasing the current IP address...
action Successfully released the current IP address
action Renewing the IP address...
action Successfully renewed the current IP address
info This computer has the following default gateway entry(ies):
info This computer has the following IP address(es):
info The default gateway is in the same subnet as this computer
info The default gateway entry is a valid unicast address
info The default gateway address was resolved via ARP in 1 try(ies)
info The default gateway was reached via ICMP Ping in 1 try(ies)
warn Hostname www.microsoft.com could not be resolved (Error code 0x2afc). Could be either gateway or DNS issue
info Waiting some time for the modem/router to stabilize
action Automated repair: Renew IP address
action Releasing the current IP address...
action Successfully released the current IP address
action Renewing the IP address...
action Successfully renewed the current IP address
info This computer has the following default gateway entry(ies):
info This computer has the following IP address(es):
info The default gateway is in the same subnet as this computer
info The default gateway entry is a valid unicast address
info The default gateway address was resolved via ARP in 1 try(ies)
info The default gateway was reached via ICMP Ping in 1 try(ies)
warn Hostname www.microsoft.com could not be resolved (Error code 0x2afc). Could be either gateway or DNS issue
info Waiting some time for the modem/router to stabilize
action Automated repair: Renew IP address
action Releasing the current IP address...
action Successfully released the current IP address
action Renewing the IP address...
action Successfully renewed the current IP address
info This computer has the following default gateway entry(ies):
info This computer has the following IP address(es):
info The default gateway is in the same subnet as this computer
info The default gateway entry is a valid unicast address
info The default gateway address was resolved via ARP in 1 try(ies)
info The default gateway was reached via ICMP Ping in 1 try(ies)
warn Hostname www.microsoft.com could not be resolved (Error code 0x2afc). Could be either gateway or DNS issue
info Waiting some time for the modem/router to stabilize
action Automated repair: Renew IP address
action Releasing the current IP address...
action Successfully released the current IP address
action Renewing the IP address...
action Successfully renewed the current IP address
info This computer has the following default gateway entry(ies):
info This computer has the following IP address(es):
info The default gateway is in the same subnet as this computer
info The default gateway entry is a valid unicast address
info The default gateway address was resolved via ARP in 1 try(ies)
info The default gateway was reached via ICMP Ping in 1 try(ies)
warn Hostname www.microsoft.com could not be resolved (Error code 0x2afc). Could be either gateway or DNS issue

IP Layer Diagnostic
Corrupted IP routing table

info The default route is valid
info The loopback route is valid
info The local host route is valid
info The local subnet route is valid
Invalid ARP cache entries

action The ARP cache has been flushed

IP Configuration Diagnostic
Invalid IP address

info Valid IP address detected:

Wireless Diagnostic
Wireless - Service disabled

Wireless - User SSID

Wireless - First time setup

Wireless - Radio off

Wireless - Out of range

Wireless - Hardware issue

Wireless - Novice user

Wireless - Ad-hoc network

Wireless - Less preferred

Wireless - 802.1x enabled

Wireless - Configuration mismatch

Wireless - Low SNR

WinSock Diagnostic
WinSock status

info All base service provider entries are present in the Winsock catalog.
info The Winsock Service provider chains are valid.
info Provider entry MSAFD Tcpip [TCP/IP] passed the loopback communication test.
info Provider entry MSAFD Tcpip [UDP/IP] passed the loopback communication test.
info Provider entry RSVP UDP Service Provider passed the loopback communication test.
info Provider entry RSVP TCP Service Provider passed the loopback communication test.
info Connectivity is valid for all Winsock service providers.

Network Adapter Diagnostic
Network location detection

info Using home Internet connection
Network adapter identification

info Network connection: Name=Local Area Connection, Device=Broadcom NetLink (TM) Fast Ethernet, MediaType=LAN, SubMediaType=LAN
info Network connection: Name=Wireless Network Connection, Device=Broadcom 802.11g Network Adapter, MediaType=LAN, SubMediaType=WIRELESS
info Both Ethernet and Wireless connections available, prompting user for selection
action User input required: Select network connection
info Ethernet connection selected
Network adapter status

info Network connection status: Connected

HTTP, HTTPS, FTP Diagnostic
HTTP, HTTPS, FTP connectivity

warn HTTP: Error 12007 connecting to www.microsoft.com: The server name or address could not be resolved
warn HTTPS: Error 12007 connecting to www.microsoft.com: The server name or address could not be resolved
warn FTP (Passive): Error 12007 connecting to ftp.microsoft.com: The server name or address could not be resolved
warn HTTP: Error 12007 connecting to www.hotmail.com: The server name or address could not be resolved
warn HTTPS: Error 12007 connecting to www.passport.net: The server name or address could not be resolved
warn FTP (Active): Error 12007 connecting to ftp.microsoft.com: The server name or address could not be resolved
error Could not make an HTTP connection.
error Could not make an HTTPS connection.
error Could not make an FTP connection.

2011-10-29, 18:09
I forgot to tell you in the response above that the ethernet/local area network works fine. I can get to files on other computers etc. So the problem seems to be DNS.
Thanks, Roger

2011-10-29, 21:04
Hi roger,

Please do the following:

Hold down the Windows key and press R to open a run box
type the following text into the run box and press Enter


This will open your Command Prompt.
Copy/Paste the following bolded texts one at a time into the command prompt and press Enter after each line.

ipconfig /release

ipconfig /renew

ipconfig /flushdns

Reboot your system and then test out the internet and let me know if it works now.

2011-10-30, 02:09

1. All steps you requested were performed and still no internet connectivity.

2. I confirmed it is a DNS problem by doing the following:
a. ping www.computerworld.com - gave a response stating that
www.computerworld could not be located
b. ping - works just fine

3. I checked the Hosts File - Only one entry for the localhost

4. I checked all of the TCP/IP protocol settings and all were OK. I changed the DNS settings from "automatically locate DNS Server" to use the following DNS server IP addresses and That solved the problem I now have internet connection.

5. I changed the DNS settings back to "automatically locate DNS Server" and it still works. I still have internet connection.

6. At this point I went back and performed the steps you previously specified and I was unable to perform. First I ran the ESET Online scanner and if found and removed 11 threats. See log below.

7. Next I ran the BitDefender Online Scanner

Jeff, thank you so much for your help!

_____________________ESET LOG_______________________________
C:\Documents and Settings\All Users\Documents\Server\hlp.dat Win32/Bamital.DZ trojan cleaned by deleting - quarantined
C:\Documents and Settings\Sue Sun\Application Data\095805F9D442F3DDE53BF9241EFE39CB\enemies-names.txt Win32/Adware.AntimalwareDoctor.AE.Gen application cleaned by deleting - quarantined
C:\Documents and Settings\Sue Sun\Application Data\095805F9D442F3DDE53BF9241EFE39CB\local.ini Win32/Adware.AntimalwareDoctor.AE.Gen application cleaned by deleting - quarantined
C:\Documents and Settings\Sue Sun\Application Data\Novuux\syuvko.exe a variant of Win32/Kryptik.UPQ trojan cleaned by deleting - quarantined
C:\Documents and Settings\Sue Sun\Application Data\Sun\Java\Deployment\cache\6.0\17\5113d451-4b1da683 Java/TrojanDownloader.Agent.NCM trojan deleted - quarantined
C:\Documents and Settings\Sue Sun\Application Data\Sun\Java\Deployment\cache\6.0\44\7a59ecac-41edf390 Java/Exploit.Agent.NAO trojan deleted - quarantined
C:\Documents and Settings\Sue Sun\Desktop\null0.5675568113853517.exe a variant of Win32/Spy.Banker.VPB trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{4CC9AF0F-9A17-4C07-8BA6-240FC5CBECFE}\RP8\A0074281.ini Win32/Adware.AntimalwareDoctor.AE.Gen application cleaned by deleting - quarantined
C:\System Volume Information\_restore{4CC9AF0F-9A17-4C07-8BA6-240FC5CBECFE}\RP8\A0074282.exe a variant of Win32/Kryptik.UPQ trojan cleaned by deleting - quarantined
C:\System Volume Information\_restore{4CC9AF0F-9A17-4C07-8BA6-240FC5CBECFE}\RP8\A0074283.exe a variant of Win32/Spy.Banker.VPB trojan cleaned by deleting - quarantined
Operating memory a variant of Win32/Spy.Zbot.ZR trojan

__________________ BitDefinder Log _________________________

QuickScan Beta 32-bit v0.9.9.99
Scan date: Sat Oct 29 15:51:54 2011
Machine ID: 80F8A812

No infection found.

Bonjour 152 C:\Program Files\Bonjour\mDNSResponder.exe
DVMExport Application 172 C:\QSTART.SYS\config\DVMExportService.exe
Lenovo Power Management 1860 C:\Program Files\Lenovo\Energy Management\utility.exe
Lenovo Power Management Software 1868 C:\Program Files\Lenovo\Energy Management\Energy Management.exe
Microsoft Office Outlook 2007 with Busi 128 C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
Microsoft Search Client Server 3684 C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
Microsoft Search Enhancement Pack 436 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
Microsoft SQL Server 920 C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
Microsoft SQL Server 1000 C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
Microsoft® Windows® Operating System 1456 C:\WINDOWS\system32\spoolsv.exe
Microsoft® Windows® Operating System 3776 C:\WINDOWS\system32\wscntfy.exe
MobileDeviceService 2044 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
Pure Networks Platform 1112 C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
ThinkVantage System Update Service 1752 C:\Program Files\Lenovo\System Update\SUService.exe
ThinkVantage Technologies 1140 C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
tvtsched Module 1192 C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
Windows Live Toolbar 3340 C:\Program Files\Windows Live\Toolbar\wltuser.exe
(verified) Java(TM) Platform SE 6 U17 212 C:\Program Files\Java\jre6\bin\jqs.exe
(verified) Microsoft® Windows® Operating System 1728 C:\WINDOWS\explorer.exe
(verified) Microsoft® Windows® Operating System 3204 C:\WINDOWS\system32\alg.exe
(verified) Microsoft® Windows® Operating System 644 C:\WINDOWS\system32\csrss.exe
(verified) Microsoft® Windows® Operating System 1880 C:\WINDOWS\system32\ctfmon.exe
(verified) Microsoft® Windows® Operating System 724 C:\WINDOWS\system32\lsass.exe
(verified) Microsoft® Windows® Operating System 712 C:\WINDOWS\system32\services.exe
(verified) Microsoft® Windows® Operating System 580 C:\WINDOWS\system32\smss.exe
(verified) Microsoft® Windows® Operating System 892 C:\WINDOWS\system32\svchost.exe
(verified) Microsoft® Windows® Operating System 964 C:\WINDOWS\system32\svchost.exe
(verified) Microsoft® Windows® Operating System 1312 C:\WINDOWS\system32\svchost.exe
(verified) Microsoft® Windows® Operating System 1120 C:\WINDOWS\system32\svchost.exe
(verified) Microsoft® Windows® Operating System 1060 C:\WINDOWS\system32\svchost.exe
(verified) Microsoft® Windows® Operating System 2012 C:\WINDOWS\system32\svchost.exe
(verified) Microsoft® Windows® Operating System 3180 C:\WINDOWS\system32\svchost.exe
(verified) Microsoft® Windows® Operating System 1036 C:\WINDOWS\system32\svchost.exe
(verified) Microsoft® Windows® Operating System 668 C:\WINDOWS\system32\winlogon.exe
(verified) Windows® Internet Explorer 1324 C:\Program Files\Internet Explorer\iexplore.exe
(verified) Windows® Internet Explorer 1508 C:\Program Files\Internet Explorer\iexplore.exe
(verified) Windows® Internet Explorer 2756 C:\Program Files\Internet Explorer\iexplore.exe

Network activity
Process SeaPort.exe (436) connected on port 80 (HTTP) -->
Process iexplore.exe (1508) connected on port 80 (HTTP) -->
Process iexplore.exe (1508) connected on port 80 (HTTP) -->
Process iexplore.exe (1508) connected on port 443 (HTTP over SSL) -->
Process iexplore.exe (1508) connected on port 80 (HTTP) -->
Process iexplore.exe (1508) connected on port 80 (HTTP) -->
Process iexplore.exe (1508) connected on port 80 (HTTP) -->

Process svchost.exe (964) listens on ports: 135 (RPC)
Process explorer.exe (1728) listens on ports: 13193

Autoruns and critical files
Apple Software Update C:\Program Files\Apple Software Update\SoftwareUpdate.exe
GrooveShellExtensions Module C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Intel(R) Common User Interface C:\WINDOWS\system32\igfxdev.dll
Lenovo Power Management C:\Program Files\Lenovo\Energy Management\utility.exe
Lenovo Power Management Software C:\Program Files\Lenovo\Energy Management\Energy Management.exe
Microsoft® Windows® Operating System C:\WINDOWS\system32\CRYPT32.dll
Microsoft® Windows® Operating System C:\WINDOWS\system32\cryptnet.dll
Microsoft® Windows® Operating System C:\WINDOWS\system32\cscdll.dll
Microsoft® Windows® Operating System C:\WINDOWS\System32\dimsntfy.dll
Microsoft® Windows® Operating System C:\WINDOWS\System32\logon.scr
Microsoft® Windows® Operating System C:\WINDOWS\system32\SHELL32.dll
Microsoft® Windows® Operating System c:\windows\system32\userinit.exe
Microsoft® Windows® Operating System C:\WINDOWS\system32\WlNotify.dll
PicNotify.dll C:\WINDOWS\system32\PicNotify.dll
(verified) Microsoft® Windows® Operating System C:\WINDOWS\system32\BROWSEUI.dll
(verified) Microsoft® Windows® Operating System C:\WINDOWS\system32\ctfmon.exe
(verified) Microsoft® Windows® Operating System C:\WINDOWS\system32\logonui.exe
(verified) Microsoft® Windows® Operating System C:\WINDOWS\system32\sclgntfy.dll
(verified) Microsoft® Windows® Operating System C:\WINDOWS\system32\stobject.dll
(verified) Windows® Internet Explorer C:\WINDOWS\system32\msfeedssync.exe
(verified) Windows® Internet Explorer C:\WINDOWS\system32\webcheck.dll

Browser plugins
AcroIEHelper Library C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BitDefender QuickScan C:\WINDOWS\Downloaded Program Files\qsax.dll
Bonjour C:\Program Files\Bonjour\mdnsNSP.dll
CentraUpdaterAx Module C:\WINDOWS\Downloaded Program Files\CentraUpdaterAx.dll
Facebook Photo Uploader 5 C:\WINDOWS\Downloaded Program Files\PhotoUploader55.ocx
GrooveShellExtensions Module C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
Messenger C:\Program Files\Messenger\msmsgs.exe
Microsoft Search Enhancement Pack C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
Microsoft® Windows® Operating System C:\WINDOWS\system32\mswsock.dll
Microsoft® Windows® Operating System C:\WINDOWS\system32\rsvpsp.dll
Microsoft® Windows® Operating System C:\WINDOWS\System32\winrnr.dll
npitunes.dll C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
QuickTime Plug-in 7.6.8 C:\Program Files\Internet Explorer\plugins\npqtplugin.dll
QuickTime Plug-in 7.6.8 C:\Program Files\Internet Explorer\plugins\npqtplugin2.dll
QuickTime Plug-in 7.6.8 C:\Program Files\Internet Explorer\plugins\npqtplugin3.dll
QuickTime Plug-in 7.6.8 C:\Program Files\Internet Explorer\plugins\npqtplugin4.dll
QuickTime Plug-in 7.6.8 C:\Program Files\Internet Explorer\plugins\npqtplugin5.dll
QuickTime Plug-in 7.6.8 C:\Program Files\Internet Explorer\plugins\npqtplugin6.dll
QuickTime Plug-in 7.6.8 C:\Program Files\Internet Explorer\plugins\npqtplugin7.dll
Silverlight Plug-In c:\Program Files\Microsoft Silverlight\4.0.50917.0\npctrl.dll
Skype Toolbars C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Windows Live Toolbar C:\Program Files\Windows Live\Toolbar\wltcore.dll
Windows Presentation Foundation c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
Windows® Internet Explorer C:\WINDOWS\system32\IEFRAME.dll
(verified) Java(TM) Platform SE 6 U17 C:\Program Files\Java\jre6\bin\jp2ssv.dll
(verified) Java(TM) Platform SE 6 U17 C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
(verified) Microsoft Office Live Plug-in for Firef C:\Program Files\Microsoft\Office Live\npOLW.dll
(verified) Microsoft® Windows Live Login Helper C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
(verified) Microsoft® Windows® Operating System C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
(verified) NPSWF32.dll C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
(verified) Windows Live® Photo Gallery C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll

Missing files
File not found: C:\Documents and Settings\Sue Sun\Application Data\Novuux\syuvko.exe
--> HKCU\Software\Microsoft\Windows\CurrentVersion\Run\"{70CE64B4-566C-5328-E99A-5F4E91DBF3A1}"

MD5: 7b43567b4c32ad7aded537cd3b1342b9 C:\Program Files\Apple Software Update\SoftwareUpdate.exe
MD5: c69dbfa61fe3dea653a9b83c3a2b052b C:\Program Files\Bonjour\mdnsNSP.dll
MD5: f832f1505ad8b83474bd9a5b1b985e01 C:\Program Files\Bonjour\mDNSResponder.exe
MD5: c11f6a1f61481e24be3fdc06ea6f7d2a C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
MD5: dddd1d04d5f4360371bc99c7c476f70d C:\Program Files\Common Files\Apple\Apple Application Support\ASL.dll
MD5: cef20cb83b36ec2dbb99d38dc80fc826 C:\Program Files\Common Files\Apple\Apple Application Support\CoreFoundation.dll
MD5: f64a630c746dcefb640fe724f911d317 C:\Program Files\Common Files\Apple\Apple Application Support\libdispatch.dll
MD5: 018857ead9a077a56aedfc0e5ef7a24a C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
MD5: bc485253d079f28ba398294465d13a21 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService_main.dll
MD5: e9ea448f1174be4052416b62263ea4ee C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
MD5: 9626746a9b120d2ed537dd8d76278405 C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
MD5: 1f174a1bf0b7718ecb8d1821ad1d3166 C:\Program Files\Common Files\Pure Networks Shared\Platform\nmagnt.dll
MD5: 54e18addc60a2054cf99b2e847a6d378 C:\Program Files\Common Files\Pure Networks Shared\Platform\nmcore.dll
MD5: de35eff35c9eb0b381709cf979537e2a C:\Program Files\Common Files\Pure Networks Shared\Platform\nmrasv.dll
MD5: cd569fa91ec6f59d045c19d0d3850f44 C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
MD5: 75c1ca5b61414748ce9bcf3c7a52c39f C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvclb.dll
MD5: d0aa2987178aaf134d011c4cc7364b8b C:\Program Files\Common Files\Pure Networks Shared\Platform\upnpgw.dll
MD5: e55be7a502b3a78f32ba3a208f6874b7 C:\Program Files\Internet Explorer\plugins\npqtplugin.dll
MD5: e55be7a502b3a78f32ba3a208f6874b7 C:\Program Files\Internet Explorer\plugins\npqtplugin2.dll
MD5: e55be7a502b3a78f32ba3a208f6874b7 C:\Program Files\Internet Explorer\plugins\npqtplugin3.dll
MD5: e55be7a502b3a78f32ba3a208f6874b7 C:\Program Files\Internet Explorer\plugins\npqtplugin4.dll
MD5: e55be7a502b3a78f32ba3a208f6874b7 C:\Program Files\Internet Explorer\plugins\npqtplugin5.dll
MD5: e55be7a502b3a78f32ba3a208f6874b7 C:\Program Files\Internet Explorer\plugins\npqtplugin6.dll
MD5: e55be7a502b3a78f32ba3a208f6874b7 C:\Program Files\Internet Explorer\plugins\npqtplugin7.dll
MD5: 0ca8c2e721617aa2f923a8151c96fb33 C:\Program Files\iPod\bin\iPodService.exe
MD5: 2658ce01d183bc62e7c46a1c9969632e C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
MD5: fb3e8a1f954308516efb2a02f2707f72 C:\Program Files\Lenovo\Energy Management\Energy Management.exe
MD5: 7fc644a11016ea78ad828ae1b0b8e943 C:\Program Files\Lenovo\Energy Management\HookLib.dll
MD5: 70341604053816468d9b4ca0368544e3 C:\Program Files\Lenovo\Energy Management\kbdhook.dll
MD5: 286ca8c58ca1abf6f602395ebe0383d4 C:\Program Files\Lenovo\Energy Management\utility.exe
MD5: e2654a49f41be3be481f0fe1b938a82c C:\Program Files\Lenovo\System Update\SUService.exe
MD5: 23cf4e714152cf7d9f262597d58c6ea9 c:\program files\lenovo\system update\TvsuServiceCommon.dll
MD5: 3e930c641079443d4de036167a69caa2 C:\Program Files\Messenger\msmsgs.exe
MD5: 451b004c4ace3b84a75cb982627b5e0c C:\Program Files\Microsoft Office\Office12\1033\GrooveIntlResource.dll
MD5: 7df3047cf5dfa4468519a50eca2c31aa c:\Program Files\Microsoft Silverlight\4.0.50917.0\npctrl.dll
MD5: 6163664c7e9cd110af70180c126c3fdc C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
MD5: c06ea83f6fc2959e897c117255b6b1d5 c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe
MD5: b2ec3e1deac5f0a764bd3486d213a0af C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
MD5: d2f4f32b59440011174b4f8137af4e0c C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
MD5: 35ede451affbc6defe12ec0b7ca6926b c:\Program Files\Microsoft SQL Server\90\Shared\sqlwvss_xp.dll
MD5: 0deea33c7df8de7802c37651013e5830 C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
MD5: 4933e09ff7d394a366a81728e0e7f7c9 C:\Program Files\Microsoft\Search Enhancement Pack\SeaNote\SeaNote.dll
MD5: 696507a45cdad3a659ad7eda85038389 C:\Program Files\Microsoft\Search Enhancement Pack\Search Box Extension\srchbxex.dll
MD5: 590c4454a1d36f76da1f636fad139771 C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
MD5: d34bfdfec1041abae996d527169398b1 C:\Program Files\Skype\Toolbars\Shared\SkypePnr.dll
MD5: 50234d25e3490987060eedd8c2b4e4a5 C:\Program Files\Windows Live\Toolbar\en-us\wltcore.market.dll.mui
MD5: 256f246f2bf87cb5dcd780b6d5898463 C:\Program Files\Windows Live\Toolbar\en\wltcore.dll.mui
MD5: 731f05b5c01b3ca9b813561c0b90e722 C:\Program Files\Windows Live\Toolbar\wltuser.exe
MD5: 77a76c2da7c9431024b299ef7700dd4f C:\PROGRA~1\PCDR5\PCD5SRVC.pkms
MD5: f6b7c3e5749fe84e081860962dac9ea3 C:\QSTART.SYS\config\DVMExportService.exe
MD5: 310c15fd8358b2c4cd7a5b98a112883f C:\WINDOWS\AppPatch\AcGenral.DLL
MD5: 5780e648b6b4147d0435bbff49ec05a1 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\7bffd7ff2009f421fe5d229927588496\mscorlib.ni.dll
MD5: 65883ca415f8d44a634f2c27f2dca53c C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\bc1cf48ba7dc00f45d0e949c49ab677a\System.Management.ni.dll
MD5: 5c75f8b5c637fe020eaecc87079276c3 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8b000cc703c9d95593b516bf2c2ec316\System.ServiceProcess.ni.dll
MD5: f4292307eb1000ac4779fdccd1c08906 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\a6dbe24cbfe3ab6b318ed3095cc572d8\System.Xml.ni.dll
MD5: 3f64539841a4e243c93f415d3044afcd C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\08ffa4d388d5f007869aa7651c458e7c\System.ni.dll
MD5: 2fb28b49c6aa282c1822504f545ac836 C:\WINDOWS\Downloaded Program Files\CentraUpdaterAx.dll
MD5: 823451876778f382b23afe20ef2ddc20 C:\WINDOWS\Downloaded Program Files\qsax.dll
MD5: 9a2d686c89acc36e3aa7cde3d1c45c1a c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorie.dll
MD5: f282d4edd85d53e20d902cc92190c5f5 c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll
MD5: 35a936c7c029a5b705d3ffd40518d660 c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll
MD5: ab87eeffd18f2baafc274e7075ea6c67 c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
MD5: 9b9402da358403637833cb6cfaf2bb71 C:\WINDOWS\system32\3DImageRenderer.dll
MD5: b902839d070d702553f687bbc2db4224 C:\WINDOWS\system32\Apblend.dll
MD5: 01cfa88f8dee91ec9f8e0988f49d106e C:\WINDOWS\system32\AVICAP32.dll
MD5: 11be1b997a000bc0013de2c5debd3c16 C:\WINDOWS\system32\CamOpex.dll
MD5: ed0c0df222209e43ad9afbf3fe87dde0 C:\WINDOWS\system32\comsvcs.dll
MD5: 8fcf03e4d7be9b5587ccf11719959006 C:\WINDOWS\system32\corpol.dll
MD5: bdaaf79dd63f194434d31a74b9bb8b77 C:\WINDOWS\system32\CRYPT32.dll
MD5: c14350fc0d47d806699c4f907fc6785b C:\WINDOWS\system32\cryptnet.dll
MD5: 515a7fae2070c2b0242b2353443e2f11 C:\WINDOWS\system32\cscdll.dll
MD5: 0607cbc6fa20114cb491efe4b2f9efad C:\WINDOWS\system32\d3d9.dll
MD5: 56adb11f7d4d0816c0be1e701c1b5e52 C:\WINDOWS\system32\D3DIM700.DLL
MD5: 3ef18b78d17c962f2b71ac1cb7757684 C:\WINDOWS\system32\d3dx9_35.dll
MD5: 17790f357991f9359d4cdd734b5cd787 C:\WINDOWS\system32\DevIL.dll
MD5: e2092f0a1d7abc243f9c2362483d150d C:\WINDOWS\System32\dimsntfy.dll
MD5: 5d3fde8fb2801a2041d1b965372c4928 C:\WINDOWS\system32\DNSAPI.dll
MD5: 5508e9f55799c6551d54dfbc4a068b68 C:\WINDOWS\system32\DRIVERS\AcpiVpc.sys
MD5: f6af59d6eee5e1c304f7f73706ad11d8 C:\WINDOWS\system32\drivers\Ambfilt.sys
MD5: 58911390115465bf6d8048f21f48655a C:\WINDOWS\system32\DRIVERS\b57xp32.sys
MD5: cc03987ee5d0f956706b40d2f91f9e4f C:\WINDOWS\system32\DRIVERS\bcmwl5.sys
MD5: 51b327292408b5f3a42e295bce055859 C:\WINDOWS\system32\drivers\BVRPMPR5.SYS
MD5: 48846b31be5a4fa662ccfde7a1ba86b9 C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
MD5: 9fa7207d1b1adead88ae8eed9cdbbaa5 C:\WINDOWS\system32\drivers\Monfilt.sys
MD5: fa292805788528c083f416e151b60ab6 C:\WINDOWS\system32\drivers\PMEMNT.SYS
MD5: 36fcac4fa28b462ca867742dea59b0d0 C:\WINDOWS\system32\DRIVERS\pnarp.sys
MD5: 651d3abc1d82d61b6cfb40cb947b3db3 C:\WINDOWS\system32\DRIVERS\psadd.sys
MD5: d8ac00388262b1a4878a7ee12f31d376 C:\WINDOWS\system32\DRIVERS\purendis.sys
MD5: 42d9da46b6d1c40daab37947d8a4490b C:\WINDOWS\system32\drivers\RtkHDAud.sys
MD5: 4290417463801d31b7c6d1adb0f8bb4c C:\WINDOWS\System32\Drivers\RTS5121.sys
MD5: 6bd4fd6c3ee76c247ecaf484cb590b72 C:\WINDOWS\system32\DRIVERS\SynTP.sys
MD5: 5c2bdc152bbab34f36473deaf7713f22 C:\WINDOWS\System32\Drivers\usbaapl.sys
MD5: 2e229c47678c8d275ccba88704659de6 C:\WINDOWS\system32\DRMClien.DLL
MD5: f5b754cdea20bbb3a31e16a776ede6d6 c:\windows\system32\ESENT.dll
MD5: 5a1e8f35bfe9abbece2c0a6b924bc12e C:\WINDOWS\system32\facev.dll
MD5: 8a0a1bf9f06325eaf0b490c6fe64768e C:\WINDOWS\system32\FaceVerify.dll
MD5: 13401452b22bedbce4c34717577202a7 C:\WINDOWS\system32\FunFrm.dll
MD5: dcdec498688092defd9f1729f23e472a C:\WINDOWS\system32\IcnOvrly.dll
MD5: 1180852dbfadafc375dbba1f6b23eee7 C:\WINDOWS\system32\igfxdev.dll
MD5: 4c6d66c4ce9b695b4bd18254ad89971b C:\WINDOWS\system32\ILU.dll
MD5: 103b776b3e3cd44a2a0674fb605f60a2 C:\WINDOWS\system32\Image.dll
MD5: 9c4d358e47fcb6fcfd792abb843edf9c C:\WINDOWS\system32\inetcomm.dll
MD5: f1941197a42f9f373cc70042fc82c950 C:\WINDOWS\system32\ksproxy.ax
MD5: c9ef69b25dfa1c0e7932cb02fb8a7e91 C:\WINDOWS\system32\kswdmcap.ax
MD5: 9fad7dff67555ff1e06bc4a3893024a7 C:\WINDOWS\System32\logon.scr
MD5: e1d416a40a70c5e23c70d386804b05c9 C:\WINDOWS\system32\MainOp.dll
MD5: 2a63dafaf83f6324330310993f753e59 C:\WINDOWS\system32\Momo.dll
MD5: 3f790874a85819e94574f3e7af9c5806 C:\WINDOWS\system32\msctfime.ime
MD5: 855f6333e3a4dfc6f3c8b0520c261fcd C:\WINDOWS\system32\MSFTEDIT.DLL
MD5: d3f72d50de53f9f1f55240115af4d42e c:\windows\system32\msi.dll
MD5: c7e39ea41233e9f5b86c8da3a9f1e4a8 C:\WINDOWS\system32\mspmsnsv.dll
MD5: 832e4dd8964ab7acc880b2837cb1ed20 C:\WINDOWS\system32\mswsock.dll
MD5: 062f837c1fbdb6a0a75f82efc2ee8e74 c:\windows\system32\netshell.dll
MD5: 46f1a5b5b34fac59436ec62da5dd4407 C:\WINDOWS\system32\PicNotify.dll
MD5: 54b0324241bbf3642159918f9a4f16fb C:\WINDOWS\system32\qcap.dll
MD5: 0e07f36810f52b580b8a27e67d34d860 C:\WINDOWS\system32\qedit.dll
MD5: e9577ff6e48f530df43bf96dfb302688 C:\WINDOWS\system32\RPCRT4.dll
MD5: 72451fd61ddbb0a1fb071b7c3cde5594 C:\WINDOWS\system32\rsvpsp.dll
MD5: af296114ac11c5d668117127e8b51782 C:\WINDOWS\system32\SetDev.dll
MD5: 26cb10fa893f940ab09713ff46dcdade C:\WINDOWS\system32\SHDOCVW.dll
MD5: 60784f891563fb1b767f70117fc2428f C:\WINDOWS\system32\spoolsv.exe
MD5: 3caeae7608f1bd7ba873a3b02895b106 C:\WINDOWS\system32\sti.dll
MD5: 4763ce0b8cf4ca355db2fe6c74675db8 C:\WINDOWS\system32\twext.dll
MD5: a93aee1928a9d7ce3e16d24ec7380f89 c:\windows\system32\userinit.exe
MD5: 9e03dc5ab51cfd0190541ce2038d819d C:\WINDOWS\system32\USP10.dll
MD5: 94ba90c6af5c50ff5f7a6392514c4642 C:\WINDOWS\system32\vidcap.ax
MD5: 0ff0cd1cc8eb17d6234c5bcb5f9a0c5f C:\WINDOWS\system32\VideoOp.dll
MD5: d72b9ec3337b247a666f098f3d6b43de C:\WINDOWS\System32\winrnr.dll
MD5: 42b5427fac23bf6f1f31e466b7feb084 C:\WINDOWS\system32\winsrv.dll
MD5: 9eefe69139fdbb4a3c327630f8eb993a C:\WINDOWS\system32\wlanapi.dll
MD5: 2cc34e8bb667eef78899546e12649196 C:\WINDOWS\system32\WlNotify.dll
MD5: 3406c40e64755cc43919218af12a616d C:\WINDOWS\system32\WMASF.DLL
MD5: 812466cecd47ec365fe51ba23c7cd43b C:\WINDOWS\system32\wmidx.dll
MD5: f92e1076c42fcd6db3d72d8cfe9816d5 C:\WINDOWS\system32\wscntfy.exe
MD5: 16403217ab6fc5c30c14c6b12098ad4b C:\WINDOWS\system32\xpsp2res.dll
MD5: bd38d1ebe24a46bd3eda059560afba12 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll

No file uploaded.

Scan finished - communication took 2 sec
Total traffic - 0.01 MB sent, 0.60 KB recvd
Scanned 647 files and modules - 21 seconds


2011-10-30, 02:33
Hi roger,

You have an older version of Adobe Reader. You can download the current version HERE (http://www.adobe.com/products/acrobat/readstep2.html)

You may want to consider Foxit Reader (http://www.foxitsoftware.com/downloads/index.php) instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum (http://www.foxitsoftware.com/bbs/forumdisplay.php?f=3)

In either case you should uninstall Adobe Reader 8.1.4 first. Be sure to move any PDF documents to another folder first though.

Please download JavaRa (http://raproducts.org/click/click.php?id=1) to your desktop and unzip it to its own
Run JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista), pick the language of your choice and click Select. Then
click Remove Older Versions.
Accept any prompts.
Open JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista) again and select Search For Updates.
Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest
Java Runtime Environment (JRE) version for your computer.

Once you get that completed run DDS once more and post both of the logs so that we can get one more look. :)

2011-10-30, 09:38
Hi Jeff,

1. Requested actions performed (see DDS log below and attached). In addition the following was performed:

2. Windows security fixes installed.

3. Antivirus software installed

Thanks, Roger

___________ DDS Log ________________________
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Sue Sun at 0:23:14 on 2011-10-30
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.643 [GMT -4:00]
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Program Files\Lenovo\Energy Management\utility.exe
C:\Program Files\Lenovo\Energy Management\Energy Management.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
c:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
c:\program files\lenovo\system update\suservice.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [EnergyUtility] c:\program files\lenovo\energy management\utility.exe
mRun: [Energy Management] c:\program files\lenovo\energy management\Energy Management.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {036F8A56-0BC8-4607-8F98-D3231E6FF5ED} - hxxp://
DPF: {488A4255-3236-44B3-8F27-FA1AECAA8844} - hxxps://img.alipay.com/download/2121/aliedit.cab
DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} - hxxp://quickscan.bitdefender.com/qsax/qsax.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1254507441546
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1254507421187
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
TCP: DhcpNameServer =
TCP: Interfaces\{1CBCD7E4-5CB8-4BFC-8CC3-7A108954766D} : DhcpNameServer =
TCP: Interfaces\{AE8E9B13-9F01-4855-8C5F-8AE7F146BE4F} : DhcpNameServer =
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - c:\program files\common files\pure networks shared\platform\puresp4.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
Notify: PicNotify - PicNotify.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
============= SERVICES / DRIVERS ===============
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-10-30 442200]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-10-30 320856]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-10-30 20568]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-10-30 44768]
R2 DvmMDES;DeviceVM Meta Data Export Service;c:\qstart.sys\config\DVMExportService.exe [2008-12-1 307200]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-11-5 54752]
R3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\drivers\AcpiVpc.sys [2009-3-2 9472]
R3 Alidevice;Alidevice;c:\windows\system32\drivers\alidevice.sys [2008-7-13 6656]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [2009-3-2 157696]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-3-2 1684736]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 PCD5SRVC{DF187064-5DA14001-05040000};PCD5SRVC{DF187064-5DA14001-05040000} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\pcdr5\PCD5SRVC.pkms [2008-5-7 21280]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\drivers\rts516xir.sys --> c:\windows\system32\drivers\Rts516xIR.sys [?]
=============== Created Last 30 ================
2011-10-30 04:10:41 -------- d--h--w- C:\dvmexp
2011-10-30 04:01:19 442200 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-10-30 04:01:00 41184 ----a-w- c:\windows\avastSS.scr
2011-10-30 04:00:42 -------- d-----w- c:\program files\AVAST Software
2011-10-30 04:00:42 -------- d-----w- c:\documents and settings\all users\application data\AVAST Software
2011-10-30 03:54:17 -------- d-----w- c:\documents and settings\sue sun\local settings\application data\Sun
2011-10-30 02:37:14 544656 ----a-w- c:\windows\system32\deployJava1.dll
2011-10-30 02:37:14 128000 ----a-w- c:\windows\system32\javacpl.cpl
2011-10-29 21:24:06 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2011-10-29 21:22:37 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2011-10-29 21:22:35 954368 -c----w- c:\windows\system32\dllcache\mfc40.dll
2011-10-29 21:22:34 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2011-10-29 21:20:17 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2011-10-29 21:19:54 105472 -c----w- c:\windows\system32\dllcache\mup.sys
2011-10-29 21:16:45 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2011-10-29 21:16:26 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2011-10-29 19:51:43 -------- d-----w- c:\documents and settings\sue sun\application data\QuickScan
2011-10-28 01:09:40 -------- d-----w- c:\program files\ESET
2011-10-28 00:35:11 -------- d-----w- c:\documents and settings\sue sun\application data\Malwarebytes
2011-10-28 00:34:21 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-10-28 00:34:16 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-10-28 00:34:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-10-28 00:23:27 -------- d-----w- c:\documents and settings\sue sun\application data\Novuux
2011-10-28 00:23:27 -------- d-----w- c:\documents and settings\sue sun\application data\Evby
2011-10-26 05:19:01 -------- d-sha-r- C:\cmdcons
2011-10-26 05:17:09 98816 ----a-w- c:\windows\sed.exe
2011-10-26 05:17:09 518144 ----a-w- c:\windows\SWREG.exe
2011-10-26 05:17:09 256000 ----a-w- c:\windows\PEV.exe
2011-10-26 05:17:09 208896 ----a-w- c:\windows\MBR.exe
2011-10-20 04:56:48 -------- d-----w- c:\windows\pss
==================== Find3M ====================
2011-10-25 07:29:00 10240 ----a-w- c:\windows\system32\drivers\compbatt.sys
2011-09-26 15:41:20 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41:20 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41:14 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-09 09:12:13 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-06 13:20:51 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-08-22 23:48:55 916480 ----a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48:54 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48:54 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56:39 385024 ----a-w- c:\windows\system32\html.iec
2011-08-17 13:49:54 138496 ----a-w- c:\windows\system32\drivers\afd.sys
============= FINISH: 0:24:41.29 ===============

2011-10-30, 16:15

This infection appears to have been cleaned, but I can not give you any absolute guarantees. As a precaution, I would go ahead and change all of your passwords as this is especially important after an infection.

The following will implement some cleanup procedures as well as reset System Restore points:

Click Start > Run and copy/paste the following text into the Run box as shown and click OK.
Combofix /Uninstall
(Note: There is a space between the ..X and the /U that needs to be there.)


Any of the logs that you created for use in the forums or remaining tools that have not yet been removed can be deleted so they aren't cluttering up your desktop.

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer more secure - This can be done by following these simple instructions:

From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.
2. Enable Protected Mode in Internet Explorer. This helps Windows Vista users stay more protected from attack by running Internet Explorer with restricted privileges as well as reducing the ability to write, alter or destroy data on your system or install malicious code. To make sure this is running follow these steps:
Open Internet Explorer
Click on Tools > Internet Options
Press Security tab
Select Internet zone then place check next to Enable Protected Mode if not already done
Do the same for Local Intranet, Trusted Sites and Restricted Sites and then press Apply
Restart Internet Explorer and in the bottom right corner of your screen you will see Protected Mode: On showing you it is enabled.
3. Use and update an anti-virus software - I can not overemphasize the need for you to use and update your anti-virus application on a regular basis. With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

4. Firewall
Using a third-party firewall will allow you to give/deny access for applications that want to go online. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a firewall in its default configuration can lower your risk greatly. A tutorial on firewalls can be found here (http://www.bleepingcomputer.com/forums/tutorial60.html). **There are firewalls listed in this tutorial that could be downloaded and used but I would personally only recommend using one of the following two below:
Online Armor Free (http://download.cnet.com/Online-Armor-Free/3000-10435_4-10426782.html)
Agnitum Outpost Firewall Free (http://download.cnet.com/Agnitum-Outpost-Firewall-Free/3000-10435_4-10913746.html)

5. Make sure you keep your Windows OS current. Windows XP users can visit Windows update (http://v4.windowsupdate.microsoft.com/en/default.asp) regularly to download and install any critical updates and service packs. Windows Vista/7 users can open the Start menu > All Programs > Windows Update > Check for Updates (in left hand task pane) to update these systems. Without these you are leaving the back door open.

6. Consider a custom hosts file such as MVPS HOSTS (http://www.mvps.org/winhelp2002/hosts.htm). This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial by WinHelp2002 (http://www.mvps.org/winhelp2002/hosts.htm)
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

7. WOT (http://www.mywot.com/) (Web of Trust) As "Googling" is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites. WOT has an add-on available for Firefox, Internet Explorer as well as Google Chrome.

8.Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place? (http://www.geekstogo.com/forum/index.php?autocom=custom&page=How_did_I)

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

2011-11-01, 11:44

All actions performed. Thanks so much for your help.

I seem to be the goto guy for all of my friends when they get into trouble with their PC. I feel like I should get smarter in malware removal and not allways bother you guys. If you can point me in the right direction to get up to speed in correcting infections, I would greatly appreciate it. perhaps I can get the basics down and only bother you guys when I run up against something more difficult. Thanks again for all your help!!
Roger :thanks:

Bear in mind that most of the schools offer free training by volunteers to those who once trained will also volunteer in the forums.

2011-11-01, 13:50
Hi Roger,

I am glad that I was able to help.

If you can point me in the right direction to get up to speed in correcting infections, I would greatly appreciate it.There are many online training classrooms that you could apply to to try and learn more about malware removal. It takes time and dedication to complete but I have found it very rewarding. :) I will give you links to some below. I hope that helps.

What the Tech (http://forums.whatthetech.com/index.php?showtopic=80368)
Malware Removal (http://www.malwareremoval.com/university.php)
Geeks to Go (http://www.geekstogo.com/forum/forum-164/announcement-52-start-here-application-questions-and-instructions/)
Bleeping Computer (http://www.bleepingcomputer.com/forums/topic86678.html)

2011-11-01, 13:51
Since this issue appears to be resolved ... this Topic has been closed. Glad we could be of assistance.

If you are the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.