Results 1 to 9 of 9

Thread: Win32.TDSS.rtk (Resolved)

  1. #1
    Junior Member
    Join Date
    Aug 2009
    Posts
    5

    Default Win32.TDSS.rtk (Resolved)

    I need some help with this particular issue. I am "the computer guy" to my friends. Those of you who have a truck will understand when you have friends who want to move. My friend brought over his PC. It was loaded with viruses/ spyware. I was able to remove all but Win32.TDSS.rtk. I can't get the PC to boot to safe-mode without BSOD. I have been reading forums on this issue. I can't get Combofix to run even though the file is originally saved as a different name. I can get spybot to run but it just detects the same files over and over again. They are cleaned and are then recreated again on restart. I have "windows updates" that are asking to be installed. I had the PC clean earlier and when I finally installed the updates is when the Win32.TDSS.rtk problem started. Now I have more updates being asked to be installed on shutdown. I have run Germ.exe, the app tells me "GMER has found system modification, which might have caused by ROOTKIT activity." I'm then asked to do an extended scan which confirms this. I have run Norton 2009, Avira and malwarebytes without any of them finding anything. Spybot is the only app which will find Win32.TDSS.rtk. Please help!

    I forgot to put this in:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:36:01 AM, on 8/27/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\runservice.exe
    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\WINDOWS\stsystra.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\DellSupport\DSAgnt.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\Temp\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=6070713
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.comcast.net/toolbar2.0/search/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=6070713
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/JOEMIL~1/LOCALS~1/Temp/msohtmlclip1/01/clip_image001.jpg

    --
    End of file - 9685 bytes

    GMER 1.0.15.15077 [gmer.exe] - http://www.gmer.net
    Rootkit scan 2009-08-27 08:56:21
    Windows 5.1.2600 Service Pack 3


    ---- System - GMER 1.0.15 ----

    Code 8957B1C0 ZwEnumerateKey
    Code 89A75308 ZwFlushInstructionCache
    Code 89A0D726 ZwSaveKey
    Code 895803D6 ZwSaveKeyEx
    Code 894A73CE IofCallDriver
    Code 896383CE IofCompleteRequest

    ---- Kernel code sections - GMER 1.0.15 ----

    .text ntkrnlpa.exe!IofCallDriver 804EF1A6 5 Bytes JMP 894A73D3
    .text ntkrnlpa.exe!IofCompleteRequest 804EF236 5 Bytes JMP 896383D3
    PAGE ntkrnlpa.exe!ZwFlushInstructionCache 805B6812 5 Bytes JMP 89A7530C
    PAGE ntkrnlpa.exe!ZwEnumerateKey 80623FF0 5 Bytes JMP 8957B1C4
    PAGE ntkrnlpa.exe!ZwSaveKey 80625264 5 Bytes JMP 89A0D72A
    PAGE ntkrnlpa.exe!ZwSaveKeyEx 8062534A 5 Bytes JMP 895803DA

    ---- User code sections - GMER 1.0.15 ----

    .text C:\WINDOWS\Explorer.EXE[1548] ntdll.dll!LdrLoadDll 7C9163C3 5 Bytes JMP 00C7000A
    .text C:\WINDOWS\system32\SearchIndexer.exe[2716] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)

    ---- Devices - GMER 1.0.15 ----

    Device \FileSystem\Fastfat \Fat A6D25D20

    AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

    Device \FileSystem\Cdfs \Cdfs DLAIFS_M.SYS (Drive Letter Access Component/Sonic Solutions)

    ---- Services - GMER 1.0.15 ----

    Service C:\WINDOWS\system32\drivers\kbiwkmdvpumpaq.sys (*** hidden *** ) [SYSTEM] kbiwkmecitqlxo <-- ROOTKIT !!!
    Service system32\drivers\UACwcesqnoeon.sys (*** hidden *** ) [DISABLED] UACd.sys <-- ROOTKIT !!!

    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmecitqlxo
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmecitqlxo@start 1
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmecitqlxo@type 1
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmecitqlxo@group file system
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmecitqlxo@imagepath \systemroot\system32\drivers\kbiwkmdvpumpaq.sys
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmecitqlxo\main
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmecitqlxo\main@aid 10096
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmecitqlxo\main@sid 0
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmecitqlxo\main\delete
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmecitqlxo\main\injector
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmecitqlxo\main\injector@* kbiwkmwsp.dll
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmecitqlxo\main\tasks
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmecitqlxo\modules
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmecitqlxo\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmdvpumpaq.sys
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmecitqlxo\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmjixgnwec.dll
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmecitqlxo\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmvpeomtvp.dat
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmecitqlxo\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmoptwbbfq.dll
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmecitqlxo\modules@kbiwkm.dat \systemroot\system32\kbiwkmjyuhhlxj.dat
    Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@start 4
    Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@type 1
    Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@imagepath \systemroot\system32\drivers\UACwcesqnoeon.sys
    Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys@group file system
    Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules
    Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@UACd
    Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules@UACc
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmecitqlxo (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmecitqlxo@start 1
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmecitqlxo@type 1
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmecitqlxo@group file system
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmecitqlxo@imagepath \systemroot\system32\drivers\kbiwkmdvpumpaq.sys
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmecitqlxo\main (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmecitqlxo\main@aid 10096
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmecitqlxo\main@sid 0
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmecitqlxo\main\delete (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmecitqlxo\main\injector (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmecitqlxo\main\injector@* kbiwkmwsp.dll
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmecitqlxo\main\tasks (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmecitqlxo\modules (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmecitqlxo\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmdvpumpaq.sys
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmecitqlxo\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmjixgnwec.dll
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmecitqlxo\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmvpeomtvp.dat
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmecitqlxo\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmoptwbbfq.dll
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmecitqlxo\modules@kbiwkm.dat \systemroot\system32\kbiwkmjyuhhlxj.dat
    Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys@start 1
    Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys@type 1
    Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys@imagepath \systemroot\system32\drivers\UACwcesqnoeon.sys
    Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys@group file system
    Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys\modules (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys\modules@UACd
    Reg HKLM\SYSTEM\ControlSet002\Services\UACd.sys\modules@UACc

    ---- EOF - GMER 1.0.15 ----

    ========================================
    "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance)
    Last edited by tashi; 2009-08-27 at 18:54. Reason: Merged 3 posts as per forum FAQ, provided link. ;-)

  2. #2
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Manchester UK
    Posts
    3,425

    Default

    Please note that all instructions given are customised for this computer only,
    the tools used may cause damage if used on a computer with different infections.

    If you think you have similar problems, please post a log in the HJT forum and wait for help.


    Hello and welcome to the forums

    My name is Katana and I will be helping you to remove any infection(s) that you may have.

    Please observe these rules while we work:
    1. Please Read All Instructions Carefully
    2. If you don't understand something, stop and ask! Don't keep going on.
    3. Please do not run any other tools or scans whilst I am helping you
    4. Failure to reply within 5 days will result in the topic being closed.
    5. Please continue to respond until I give you the "All Clear"
      (Just because you can't see a problem doesn't mean it isn't there)

    If you can do those few things, everything should go smoothly

    Some of the logs I request will be quite large, You may need to split them over a couple of replies.

    Please Note, your security programs may give warnings for some of the tools I will ask you to use.
    Be assured, any links I give are safe

    ----------------------------------------------------------------------------------------



    We need to use GMER to delete a service and remove the file:
    • Open the gmer folder and double click gmer.exe to run the program
    • On starting GMER will run a short scan, allow it to complete this, then click No if it asks you to run a full scan.

    • Click on the > > > tab to open the menus

    • Click on the Services tab

    • Scroll down until you find the following Service (Note: This may be highlighted in red)

      kbiwkmecitqlxo
      UACd.sys
    • Click on the Service Name to Highlight it, then right click and choose Delete...
    • Click OK at the first confirmation dialog to remove the service
    • Click OK to the second confirmation dialog to remove the file
    • Click OK to exit the program

    Let me know of any problems you encountered.



    Download and Run ComboFix
    Please delete the copy of ComboFix that you have and download an updated copy from one of the links below
    • Please visit this webpage for instructions on using ComboFix:
      http://www.bleepingcomputer.com/comb...o-use-combofix

      ComboFix.exe
      ComboFix.exe
    • You must download it to and run it from your Desktop
    • Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
    • Double click combofix.exe & follow the prompts.
    • When finished, it will produce a log. Please save that log to post in your next reply
    • Re-enable all the programs that were disabled during the running of ComboFix..


    Note:
    Do not mouse-click combofix's window while it is running. That may cause it to stall.

    CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
    ComboFix SHOULD NOT be used unless requested by a forum helper



    ----------------------------------------------------------------------------------------
    Logs/Information to Post in Reply
    Please post the following logs/Information in your reply
    Some of the logs I request will be quite large, You may need to split them over a couple of replies.
    • Combofix Log
    • How are things running now ?
    Microsoft MVP Consumer Security 2009 -2010
    If we have helped, please consider a donation
    THESE INSTRUCTIONS ARE FOR THIS USER ONLY

  3. #3
    Junior Member
    Join Date
    Aug 2009
    Posts
    5

    Default Combo fix log

    I would like to start off saying, thank you for your time and your patience. Your help if very much appreciated.
    I ran GMER and deleted kbiwkmecitqlxo. I then went to delete uacd.sys, there was an error stating uacd.sys was unable to be found, there is currently no trace of that file. The PC then BSOD'd, upon each restart many dos windows run and the file starting in kbiw is recreated. I deleted the file several times but upon closing GMER and reopening, the file would already have been recreated with another name starting in kbiw.

    Combofix found rootkit C:\windows\system32\drivers\kbiwkmdvpumpaq.sys and needed to reboot. Combo log follows:
    ------------------------------------

    ComboFix 09-08-28.01 - Joe Miller 08/28/2009 18:11.2.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1613 [GMT -6:00]
    Running from: c:\documents and settings\Joe Miller\Desktop\ComboFix.exe
    AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
    FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_kbiwkmecitqlxo
    -------\Service_kbiwkmecitqlxo


    ((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-29 )))))))))))))))))))))))))))))))
    .

    2009-08-26 22:56 . 2009-08-26 22:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
    2009-08-26 22:55 . 2009-08-26 22:56 20597104 ----a-w- c:\temp\aaw2007.exe
    2009-08-26 21:44 . 2009-08-26 21:44 -------- d-----w- c:\documents and settings\Joe Miller\Application Data\Malwarebytes
    2009-08-26 21:03 . 2009-08-26 21:03 -------- d-----w- c:\documents and settings\Joe Miller\Local Settings\Application Data\Symantec
    2009-08-26 20:52 . 2009-08-27 14:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
    2009-08-26 17:20 . 2006-05-24 19:36 110592 ----a-w- c:\documents and settings\Administrator\Application Data\U3\temp\cleanup.exe
    2009-08-26 17:12 . 2009-08-26 17:12 -------- d-----w- c:\windows\NU_DATA
    2009-08-26 16:50 . 2009-08-26 17:20 -------- d-----w- c:\documents and settings\Administrator\Application Data\U3
    2009-08-26 04:40 . 2009-08-03 19:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-08-26 04:40 . 2009-08-26 04:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-08-26 04:40 . 2009-08-26 04:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2009-08-26 04:40 . 2009-08-03 19:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
    2009-08-26 04:31 . 2009-08-26 04:31 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
    2009-08-26 04:29 . 2009-08-26 04:29 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
    2009-08-26 02:49 . 2009-08-27 14:36 -------- d-----w- C:\Temp
    2009-08-26 02:46 . 2009-08-26 16:40 -------- d-----w- c:\documents and settings\Administrator\Application Data\COMCASTTOOLBAR
    2009-08-26 02:41 . 2009-08-26 02:41 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\SupportSoft
    2009-08-26 02:41 . 2007-05-24 06:28 -------- d--h--r- c:\documents and settings\Administrator\Application Data\yahoo!
    2009-08-26 02:40 . 2009-08-26 02:40 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
    2009-08-26 01:42 . 2009-08-27 14:18 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
    2009-08-25 18:10 . 2006-05-24 19:36 110592 ----a-w- c:\documents and settings\Joe Miller\Application Data\U3\temp\cleanup.exe
    2009-08-25 03:29 . 2009-08-25 03:29 -------- d-----w- c:\documents and settings\Joe Miller\Application Data\Windows Search
    2009-08-25 03:07 . 2009-08-25 18:10 -------- d-----w- c:\documents and settings\Joe Miller\Application Data\U3
    2009-08-25 02:22 . 2009-08-27 17:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-08-25 02:22 . 2009-08-26 05:41 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2009-08-25 01:56 . 2009-08-25 01:51 401720 ----a-w- c:\temp\HiJackThis.exe
    2009-08-23 07:52 . 2009-08-23 07:52 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
    2009-08-22 09:04 . 2009-08-22 09:04 -------- d-----w- C:\37dfd81f3793542348a5c3d991d17d8c
    2009-08-22 09:04 . 2009-08-22 09:15 -------- d-----w- c:\windows\SxsCaPendDel
    2009-08-13 05:33 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
    2009-08-05 09:01 . 2009-08-05 09:01 204800 ------w- c:\windows\system32\dllcache\mswebdvd.dll
    2009-08-03 21:07 . 2009-08-03 21:07 403816 ----a-w- c:\windows\system32\OGACheckControl.dll
    2009-08-03 21:07 . 2009-08-03 21:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll
    2009-08-03 21:07 . 2009-08-03 21:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-08-29 00:16 . 2007-08-13 04:02 1433 --sha-w- c:\windows\system32\mmf.sys
    2009-08-28 20:19 . 2007-07-13 13:56 34704 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-08-27 14:23 . 2007-09-30 22:36 -------- d-----w- c:\program files\Common Files\AVSMedia
    2009-08-27 14:23 . 2007-09-30 22:36 -------- d-----w- c:\program files\AVS4YOU
    2009-08-27 14:18 . 2007-07-13 13:48 -------- d-----w- c:\program files\Symantec
    2009-08-27 14:18 . 2007-07-13 13:48 -------- d-----w- c:\program files\Common Files\Symantec Shared
    2009-08-27 02:54 . 2007-07-13 13:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
    2009-08-26 01:41 . 2007-10-19 00:59 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
    2009-08-13 09:02 . 2007-07-13 13:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
    2009-08-08 23:49 . 2008-12-18 12:43 -------- d-----w- c:\program files\Microsoft Silverlight
    2009-08-05 09:01 . 2004-08-11 22:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
    2009-08-02 01:36 . 2008-12-18 02:16 -------- d-----w- c:\documents and settings\Joe Miller\Application Data\Apple Computer
    2009-07-28 22:33 . 2007-05-24 06:04 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
    2009-07-17 19:01 . 2004-08-11 22:00 58880 ----a-w- c:\windows\system32\atl.dll
    2009-07-14 05:43 . 2004-08-11 22:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
    2009-07-12 23:42 . 2009-07-11 18:43 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
    2009-07-12 23:42 . 2009-07-11 18:43 -------- d-----w- c:\program files\NOS
    2009-07-11 18:44 . 2009-07-11 18:44 1914000 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe
    2009-07-03 17:09 . 2004-08-11 22:00 915456 ------w- c:\windows\system32\wininet.dll
    2009-06-25 08:25 . 2004-08-11 22:00 54272 ----a-w- c:\windows\system32\wdigest.dll
    2009-06-25 08:25 . 2004-08-11 22:00 56832 ----a-w- c:\windows\system32\secur32.dll
    2009-06-25 08:25 . 2004-08-11 22:00 147456 ----a-w- c:\windows\system32\schannel.dll
    2009-06-25 08:25 . 2004-08-11 22:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
    2009-06-25 08:25 . 2004-08-11 22:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
    2009-06-25 08:25 . 2004-08-11 22:00 301568 ----a-w- c:\windows\system32\kerberos.dll
    2009-06-24 11:18 . 2004-08-11 22:00 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
    2009-06-23 17:06 . 2009-07-22 00:26 245408 ----a-w- c:\documents and settings\Joe Miller\Application Data\Mozilla\Firefox\Profiles\t4mmaz3m.default\extensions\LogMeInClient@logmein.com\plugins\unicows.dll
    2009-06-16 14:36 . 2004-08-11 22:00 119808 ----a-w- c:\windows\system32\t2embed.dll
    2009-06-16 14:36 . 2004-08-11 22:00 81920 ----a-w- c:\windows\system32\fontsub.dll
    2009-06-12 12:31 . 2004-08-11 22:00 80896 ----a-w- c:\windows\system32\tlntsess.exe
    2009-06-12 12:31 . 2004-08-11 22:00 76288 ----a-w- c:\windows\system32\telnet.exe
    2009-06-10 15:19 . 2004-08-11 22:11 2066432 ----a-w- c:\windows\system32\mstscax.dll
    2009-06-10 14:13 . 2004-08-11 22:00 84992 ----a-w- c:\windows\system32\avifil32.dll
    2009-06-10 06:14 . 2004-08-11 22:00 132096 ----a-w- c:\windows\system32\wkssvc.dll
    2009-06-03 19:09 . 2004-08-11 22:00 1291264 ----a-w- c:\windows\system32\quartz.dll
    2009-03-27 17:19 . 2007-08-21 16:54 168 --sh--r- c:\windows\system32\F59B479F8E.sys
    2009-03-27 18:47 . 2007-08-21 16:54 5174 --sha-w- c:\windows\system32\KGyGaAvL.sys
    .

    ((((((((((((((((((((((((((((( SnapShot@2009-08-28_20.43.12 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2009-08-29 00:16 . 2009-08-29 00:16 16384 c:\windows\temp\Perflib_Perfdata_7a4.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-17 8491008]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-15 136600]
    "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 151552]
    "DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
    "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2008-10-24 79136]
    "Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-13 517768]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
    "SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-07-24 282624]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
    @="FSFilter Activity Monitor"

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
    backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
    path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
    backup=c:\windows\pss\Windows Search.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^Joe Miller^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
    path=c:\documents and settings\Joe Miller\Start Menu\Programs\Startup\PowerReg Scheduler.exe
    backup=c:\windows\pss\PowerReg Scheduler.exeStartup

    [HKLM\~\startupfolder\C:^Documents and Settings^Joe Miller^Start Menu^Programs^Startup^Registration Chessmaster® Grandmaster Edition .LNK]
    path=c:\documents and settings\Joe Miller\Start Menu\Programs\Startup\Registration Chessmaster® Grandmaster Edition .LNK
    backup=c:\windows\pss\Registration Chessmaster® Grandmaster Edition .LNKStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
    "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\WiLife Command Center\\Werks.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=

    R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [5/24/2007 12:04 AM 108289]
    R2 LicCtrlService;LicCtrl Service;c:\windows\Runservice.exe [8/12/2007 10:02 PM 2560]
    S3 A_USBETHMP;USB PowerPacket Network Adapter;c:\windows\system32\drivers\usbethmp.sys [4/7/2008 8:05 PM 14342]
    S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [7/13/2007 7:53 AM 29744]
    S3 WLRAWMp50x86;WLRAWMp50x86 NDIS Protocol Driver;c:\windows\system32\drivers\WLRAWMp50x86.sys [4/7/2008 8:07 PM 26752]
    S3 WLRAWSp50x86;WLRAWSp50x86 NDIS Protocol Driver;c:\windows\system32\drivers\WLRAWSp50x86.sys [4/7/2008 8:07 PM 25472]

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
    "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
    .
    Contents of the 'Scheduled Tasks' folder

    2009-08-27 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

    2009-08-29 c:\windows\Tasks\OGALogon.job
    - c:\windows\system32\OGAEXEC.exe [2009-08-03 21:07]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.comcast.net/
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    mWindow Title = Windows Internet Explorer provided by Comcast
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    FF - ProfilePath - c:\documents and settings\Joe Miller\Application Data\Mozilla\Firefox\Profiles\t4mmaz3m.default\
    FF - plugin: c:\documents and settings\Joe Miller\Application Data\Mozilla\Firefox\Profiles\t4mmaz3m.default\extensions\LogMeInClient@logmein.com\plugins\npRACtrl.dll
    FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

    ---- FIREFOX POLICIES ----
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
    c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
    c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
    c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
    c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-08-28 18:16
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \103076C71E8172E2]
    "1"=hex:f3,63,02,17,10,0f,8c,72,44,b1,bf,31,22,25,c4,7d,41,89,c7,a7,5f,90,bb,
    a2
    "2"=hex:05,42,30,42,a7,15,e9,31,44,4c,e8,ce,26,93,4c,ff,dc,fd,7a,28,38,0d,79,
    b8
    "3"=hex:f3,63,02,17,10,0f,8c,72,44,b1,bf,31,22,25,c4,7d,38,a8,bc,ca,16,d6,08,
    eb,9c,8b,9c,0d,35,8b,99,e4,25,24,80,ac,1f,d3,6a,72

    [HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \103076C71E8172E2\103076C71E8172E2]
    "1"=hex:33,08,da,55,f6,12,dc,ab,f4,e9,74,73,21,3e,6a,85,2f,ad,11,35,1e,74,d2,
    f6,85,c6,80,d5,b6,ed,0d,87
    "2"=hex:56,f3,50,11,98,55,25,42

    [HKEY_LOCAL_MACHINE\software\LicCtrl\LicCtrl\LicCtrl\LicCtrl*lkzs$i&#&y@^t! #^$ g9^$&pgb SDB36o \103076C71E8172E2\AAEBAA674720777F98D3CB19E52B3725]
    "1"=hex:33,08,da,55,f6,12,dc,ab,f4,e9,74,73,21,3e,6a,85,2f,ad,11,35,1e,74,d2,
    f6,85,c6,80,d5,b6,ed,0d,87
    "2"=hex:56,f3,50,11,98,55,25,42
    "3"=hex:79,31,eb,03,96,3a,5d,99,e3,99,57,f1,5b,87,1b,98,93,9a,63,bb,27,18,45,
    96,3b,3d,36,d0,aa,b6,65,d1,3f,f6,67,1d,df,0d,40,eb,d3,22,6d,0f,38,95,6e,f8,\
    "4"=hex:2f,ad,a2,e7,8a,bf,05,5e
    "5"=hex:bf,e5,23,7b,b0,66,d6,fc,b8,e8,6b,a0,96,52,f7,32,80,09,8f,24,b7,b3,55,
    1a,98,d1,47,16,02,43,61,1c,b9,d5,8f,2a,7b,81,b1,fb,95,22,f8,b3,2c,53,9d,ae,\
    "6"=hex:33,08,da,55,f6,12,dc,ab,f4,e9,74,73,21,3e,6a,85,2f,ad,11,35,1e,74,d2,
    f6,2e,2b,e0,1b,c2,9e,49,42,53,a9,a5,ab,d9,82,65,c7,aa,4b,84,16,df,84,04,20,\
    "7"=hex:33,08,da,55,f6,12,dc,ab,f4,e9,74,73,21,3e,6a,85,2f,ad,11,35,1e,74,d2,
    f6,d6,93,62,58,16,ac,98,9d,fb,96,15,df,14,58,40,fd,da,1c,0b,31,a3,58,f4,6f,\
    "8"=hex:9d,9e,b2,b9,a7,a5,f4,ae,4d,29,c2,a3,c0,78,c4,c5,86,15,ba,ba,a8,7c,30,
    6e,e7,be,f3,4e,5c,b8,67,18,68,d2,34,71,6e,be,6a,68,12,55,ff,37,2b,86,ac,b7,\
    "9"=hex:81,20,8f,ab,28,6a,52,9c
    "18"=hex:4b,72,8f,bc,6c,3f,e4,15
    "10"=hex:81,20,8f,ab,28,6a,52,9c
    "11"=hex:81,20,8f,ab,28,6a,52,9c
    "12"=hex:59,9a,7a,d5,fc,e1,e2,d7,0e,20,9f,3f,b7,36,9c,df,76,ee,7f,56,52,8a,bc,
    c7,2b,b2,a0,90,25,a1,a3,2b,40,90,2d,2a,97,af,89,c6,6c,85,1d,6a,6e,4b,db,a4,\
    "13"=hex:cc,74,6c,f9,42,a3,ba,6e,b0,08,a9,6c,cf,bc,67,0d,01,18,46,b9,73,cc,86,
    60
    "14"=hex:83,34,31,f7,8e,d5,03,43,c8,8e,e9,f6,fc,e8,bb,e7,f8,34,65,93,0a,d3,2c,
    14
    "24"=hex:81,20,8f,ab,28,6a,52,9c
    "26"=hex:81,20,8f,ab,28,6a,52,9c
    "27"=hex:81,20,8f,ab,28,6a,52,9c
    "19"=hex:64,ef,a4,34,f2,d0,45,21,fd,5a,9d,22,a1,ba,80,f7
    "22"=hex:81,20,8f,ab,28,6a,52,9c
    "15"=hex:a8,a3,24,fa,5b,5d,d5,aa,fe,3f,78,92,2a,f7,c6,6c,25,30,16,3d,61,16,e6,
    7b,7e,f1,22,07,8a,ba,6d,7a,85,79,2b,18,b4,0d,ff,47,e5,17,fc,8a,cb,50,b8,ee,\
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'explorer.exe'(984)
    c:\windows\system32\WININET.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\windows\system32\nvsvc32.exe
    c:\program files\Comcast\Desktop Doctor\bin\sprtsvc.exe
    c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    c:\windows\system32\searchindexer.exe
    c:\program files\iPod\bin\iPodService.exe
    .
    **************************************************************************
    .
    Completion time: 2009-08-29 18:20 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-08-29 00:20

    Pre-Run: 81,998,839,808 bytes free
    Post-Run: 82,016,346,112 bytes free

    303 --- E O F --- 2009-08-28 09:00

  4. #4
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Manchester UK
    Posts
    3,425

    Default

    Looking better


    ----------------------------------------------------------------------------------------
    Step 1

    Malwarebytes' Anti-Malware

    Please download Malwarebytes' Anti-Malware to your desktop.

    • Double-click mbam-setup.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to
      • Update Malwarebytes' Anti-Malware
      • and Launch Malwarebytes' Anti-Malware
    • then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform full scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When completed, a log will open in Notepad. please copy and paste the log into your next reply
    • If requested, please reboot
      • If you accidently close it, the log file is saved here and will be named like this:
      • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt


    Malwarebytes' Anti-Malware

    Please download Malwarebytes' Anti-Malware to your desktop.

    • Double-click mbam-setup.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to
      • Update Malwarebytes' Anti-Malware
      • and Launch Malwarebytes' Anti-Malware
    • then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform full scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When completed, a log will open in Notepad. please copy and paste the log into your next reply
    • If requested, please reboot
      • If you accidently close it, the log file is saved here and will be named like this:
      • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt


    Download and Run RSIT
    • Please download Random's System Information Tool by random/random from here and save it to your desktop.
    • Double click on RSIT.exe to run RSIT.
    • Click Continue at the disclaimer screen.
    • Once it has finished, two logs will open:
      • log.txt will be opened maximized.
      • info.txt will be opened minimized.
    • Please post the contents of both log.txt and info.txt.
      ( They can also be found in the C:\RSIT folder )



    ----------------------------------------------------------------------------------------
    Logs/Information to Post in Reply
    Please post the following logs/Information in your reply
    Some of the logs I request will be quite large, You may need to split them over a couple of replies.
    • MalwareBytes Log
    • RSIT Logs
    • How are things running now ?
    Microsoft MVP Consumer Security 2009 -2010
    If we have helped, please consider a donation
    THESE INSTRUCTIONS ARE FOR THIS USER ONLY

  5. #5
    Junior Member
    Join Date
    Aug 2009
    Posts
    5

    Default Rsit and mbam logs

    It looks like mbam updated to the point of being able to detect/ clean the virus. I'm running a second check now to see if RDSS is redetected. I'll post back in 2 hours when the second scan is done.

    Logfile of random's system information tool 1.06 (written by random/random)
    Run by Joe Miller at 2009-08-29 16:16:15
    Microsoft Windows XP Professional Service Pack 3
    System drive C: has 78 GB (52%) free of 149 GB
    Total RAM: 2046 MB (82% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 4:16:20 PM, on 8/29/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\WINDOWS\stsystra.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Common Files\Symantec

    Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\Apple\Mobile Device

    Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\runservice.exe
    C:\Program Files\Common Files\Symantec

    Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Documents and Settings\Joe Miller\Desktop\RSIT.exe
    C:\Temp\Joe Miller.exe
    C:\WINDOWS\system32\wuauclt.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

    http://www.comcast.net/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

    http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

    http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =

    http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com

    /ext/search/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

    http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

    http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL =

    http://www.google.com/ig/dell?hl=en&...us&ibd=6070713
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88}

    - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} -

    C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper -

    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat

    7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} -

    C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
    O2 - BHO: Yahoo! IE Services Button -

    {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program

    Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} -

    C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: Java(tm) Plug-In SSV Helper -

    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program

    Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Browser Address Error Redirector -

    {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper -

    {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program

    Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} -

    C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} -

    C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} -

    C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE

    C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program

    Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage

    Manager\Iaanotif.exe
    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    O4 - HKLM\..\Run: [ISUSPM Startup]

    C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common

    Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common

    Files\Symantec

    Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m

    "C:\Program Files\Common Files\Symantec

    Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe"

    /startup
    O8 - Extra context menu item: E&xport to Microsoft Excel -

    res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}

    - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -

    C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -

    C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} -

    C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -

    {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network

    Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

    C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger -

    {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

    Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine

    Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) -

    C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -

    http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer

    Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira

    GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH -

    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common

    Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation -

    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program

    Files\Bonjour\mDNSResponder.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program

    Files\DellSupport\brkrsvc.exe
    O23 - Service: Google Desktop Manager 5.7.806.10245

    (GoogleDesktopManager-061008-081103) - Google - C:\Program

    Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel

    Corporation - C:\Program Files\Intel\Intel Matrix Storage

    Manager\Iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision

    Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel

    32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program

    Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun

    Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner -

    C:\WINDOWS\runservice.exe
    O23 - Service: LiveUpdate - Symantec Corporation -

    C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation -

    C:\Program Files\Common Files\Symantec

    Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -

    C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2)

    - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop

    Doctor\bin\sprtsvc.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common

    Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O24 - Desktop Component 0: (no name) -

    file:///C:/DOCUME~1/JOEMIL~1/LOCALS~1/Temp/msohtmlclip1/01/clip_image001.jp

    g

    --
    End of file - 8786 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    C:\WINDOWS\tasks\OGALogon.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brow

    ser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    &Yahoo! Toolbar Helper - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll

    [2007-05-30 808472]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brow

    ser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat

    7.0\ActiveX\AcroIEHelper.dll [2006-01-12 63128]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brow

    ser Helper Objects\{4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29}]
    Comcast Toolbar - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL [2006-11-07 1821184]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brow

    ser Helper Objects\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}]
    Yahoo! IE Services Button - C:\Program Files\Yahoo!\Common\yiesrvc.dll

    [2006-10-31 198136]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brow

    ser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}]
    DriveLetterAccess - C:\WINDOWS\System32\DLA\DLASHX_W.DLL [2005-09-08

    110652]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brow

    ser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll

    [2008-12-15 320920]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brow

    ser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
    CBrowserHelperObject Object - C:\Program Files\BAE\BAE.dll [2006-12-08

    98304]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brow

    ser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll

    [2008-12-15 34816]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Brow

    ser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
    JQSIEStartDetectorImpl Class - C:\Program

    Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-12-15 73728]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar -

    C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2007-05-30 808472]
    {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - Comcast Toolbar -

    C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL [2006-11-07 1821184]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-09-17 8491008]
    "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-15

    136600]
    "SigmatelSysTrayApp"=C:\WINDOWS\stsystra.exe [2006-07-24 282624]
    "IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe

    [2006-07-06 151552]
    "DLA"=C:\WINDOWS\System32\DLA\DLACTRLW.EXE [2005-09-08 122940]
    "ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe

    [2004-07-27 221184]
    "ISUSScheduler"=C:\Program Files\Common

    Files\InstallShield\UpdateService\issch.exe [2008-10-24 79136]
    "Symantec PIF AlertEng"=C:\Program Files\Common Files\Symantec

    Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe [2007-03-12

    517768]
    "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-11-20 290088]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "DellSupport"=C:\Program Files\DellSupport\DSAgnt.exe [2007-03-15 460784]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared

    tools\msconfig\startupreg\avgnt]
    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared

    tools\msconfig\startupreg\Corel Photo Downloader]
    C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe

    [2006-08-14 462336]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared

    tools\msconfig\startupreg\DMXLauncher]
    C:\Program Files\Dell\Media Experience\DMXLauncher.exe [2005-10-05 94208]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared

    tools\msconfig\startupreg\Google Desktop Search]
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-06

    29744]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared

    tools\msconfig\startupreg\MSMSGS]
    C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared

    tools\msconfig\startupreg\QuickTime Task]
    C:\Program Files\QuickTime\qttask.exe [2008-11-04 413696]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared

    tools\msconfig\startupreg\RealTray]
    C:\Program Files\Real\RealPlayer\RealPlay.exe [2007-07-13 26112]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared

    tools\msconfig\startupreg\Search Protection]
    C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared

    tools\msconfig\startupreg\swg]
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared

    tools\msconfig\startupreg\winupdate.exe]
    C:\WINDOWS\system32\winupdate.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared

    tools\msconfig\startupreg\Yahoo! Pager]
    C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [2007-08-30 4670704]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared

    tools\msconfig\startupreg\YSearchProtection]
    C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared

    tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start

    Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [2005-09-23 29696]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared

    tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start

    Menu^Programs^Startup^Windows Search.lnk]
    C:\PROGRA~1\WINDOW~4\WINDOW~1.EXE [2008-05-26 123904]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared

    tools\msconfig\startupfolder\C:^Documents and Settings^Joe Miller^Start

    Menu^Programs^Startup^PowerReg Scheduler.exe]
    C:\Documents and Settings\Joe Miller\Start Menu\Programs\Startup\PowerReg

    Scheduler.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared

    tools\msconfig\startupfolder\C:^Documents and Settings^Joe Miller^Start

    Menu^Programs^Startup^Registration Chessmaster® Grandmaster Edition .LNK]
    C:\PROGRA~1\Ubisoft\CHESSM~1\Register\REGIST~1.EXE [2003-11-06 864256]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows

    NT\CurrentVersion\Winlogon\Notify\WgaLogon]
    C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceO

    bjectDelayLoad]
    WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} -

    C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shel

    lExecuteHooks]
    "{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop

    Search\MSNLNamespaceMgr.dll [2009-05-24 304128]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEF

    A.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SymEF

    A.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e

    09be-1e45-494b-9174-d7385b45bbf5}]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Syst

    em]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explo

    rer]
    "NoDriveTypeAutoRun"=323
    "NoDriveAutoRun"=67108863
    "NoDrives"=0

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\expl

    orer]
    "NoDriveAutoRun"=
    "NoDriveTypeAutoRun"=
    "NoDrives"=
    "HonorAutoRunSetting"=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\paramete

    rs\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@x

    psp2res.dll,-22019"
    "C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program

    Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office

    Outlook"
    "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program

    Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
    "C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program

    Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network

    Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\Program Files\WiLife Command Center\Werks.exe"="C:\Program Files\WiLife

    Command Center\Werks.exe:*:Enabled:WiLife Command Center"
    "C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program

    Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
    "C:\Program Files\iTunes\iTunes.exe"="C:\Program

    Files\iTunes\iTunes.exe:*:Enabled:iTunes"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\paramete

    rs\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@x

    psp2res.dll,-22019"
    "C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe"="C:\Program

    Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL"
    "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"="C:\Program

    Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL"
    "C:\Program Files\America Online 9.0\waol.exe"="C:\Program Files\America

    Online 9.0\waol.exe:*:Enabled:AOL"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network

    Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mount

    points2\{8fc4829a-9252-11de-bea2-0019d1e2c1a8}]
    shell\AutoRun\command - G:\StartPortableApps.exe


    ======List of files/folders created in the last 1 months======

    2009-08-29 16:16:15 ----D---- C:\rsit
    2009-08-28 18:20:08 ----A---- C:\ComboFix.txt
    2009-08-28 18:14:36 ----D---- C:\WINDOWS\temp
    2009-08-28 14:24:26 ----A---- C:\Boot.bak
    2009-08-28 14:24:19 ----RASHD---- C:\cmdcons
    2009-08-28 14:23:06 ----A---- C:\WINDOWS\zip.exe
    2009-08-28 14:23:06 ----A---- C:\WINDOWS\SWXCACLS.exe
    2009-08-28 14:23:06 ----A---- C:\WINDOWS\SWSC.exe
    2009-08-28 14:23:06 ----A---- C:\WINDOWS\SWREG.exe
    2009-08-28 14:23:06 ----A---- C:\WINDOWS\sed.exe
    2009-08-28 14:23:06 ----A---- C:\WINDOWS\PEV.exe
    2009-08-28 14:23:06 ----A---- C:\WINDOWS\NIRCMD.exe
    2009-08-28 14:23:06 ----A---- C:\WINDOWS\grep.exe
    2009-08-28 14:23:01 ----D---- C:\WINDOWS\ERDNT
    2009-08-28 14:12:28 ----D---- C:\Qoobox
    2009-08-26 16:56:29 ----D---- C:\Documents and Settings\All

    Users\Application Data\Lavasoft
    2009-08-26 15:44:31 ----D---- C:\Documents and Settings\Joe

    Miller\Application Data\Malwarebytes
    2009-08-26 14:52:43 ----D---- C:\Documents and Settings\All

    Users\Application Data\Norton
    2009-08-26 11:12:27 ----D---- C:\WINDOWS\NU_DATA
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\zh-TW
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\zh-HK
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\tr-TR
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\sv-SE
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\pt-BR
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\nl-NL
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\nb-NO
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\ko-KR
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\it-IT
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\he-IL
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\fr-FR
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\fi-FI
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\es-ES
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\el-GR
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\de-DE
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\da-DK
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\ar-SA
    2009-08-25 22:40:24 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
    2009-08-25 22:40:24 ----D---- C:\Documents and Settings\All

    Users\Application Data\Malwarebytes
    2009-08-25 22:29:55 ----HDC---- C:\WINDOWS\$NtUninstallKB970653-v3$
    2009-08-25 20:49:09 ----D---- C:\Temp
    2009-08-25 19:42:11 ----D---- C:\Documents and Settings\All

    Users\Application Data\NortonInstaller
    2009-08-25 19:35:45 ----SHD---- C:\WINDOWS\CSC
    2009-08-24 21:29:35 ----D---- C:\Documents and Settings\Joe

    Miller\Application Data\Windows Search
    2009-08-24 21:07:10 ----D---- C:\Documents and Settings\Joe

    Miller\Application Data\U3
    2009-08-24 20:22:30 ----D---- C:\Program Files\Spybot - Search & Destroy
    2009-08-24 20:22:30 ----D---- C:\Documents and Settings\All

    Users\Application Data\Spybot - Search & Destroy
    2009-08-24 20:16:10 ----D---- C:\WINDOWS\pss
    2009-08-24 20:09:34 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
    2009-08-23 02:09:09 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
    2009-08-22 03:04:38 ----D---- C:\37dfd81f3793542348a5c3d991d17d8c
    2009-08-22 03:04:29 ----D---- C:\WINDOWS\SxsCaPendDel
    2009-08-13 03:03:10 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
    2009-08-13 03:03:05 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
    2009-08-13 03:03:01 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$
    2009-08-13 03:02:56 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
    2009-08-13 03:02:51 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
    2009-08-13 03:02:23 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
    2009-08-13 03:02:18 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
    2009-08-13 03:02:11 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
    2009-08-13 03:00:23 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
    2009-08-03 15:07:42 ----A---- C:\WINDOWS\system32\OGAEXEC.exe
    2009-08-03 15:07:42 ----A---- C:\WINDOWS\system32\OGACheckControl.dll
    2009-08-03 15:07:42 ----A---- C:\WINDOWS\system32\OGAAddin.dll

    ======List of files/folders modified in the last 1 months======

    2009-08-29 16:15:41 ----D---- C:\WINDOWS\system32\CatRoot2
    2009-08-29 16:15:12 ----D---- C:\WINDOWS\system32\drivers
    2009-08-29 16:15:12 ----D---- C:\WINDOWS
    2009-08-29 16:14:14 ----A---- C:\WINDOWS\SchedLgU.Txt
    2009-08-29 16:14:05 ----D---- C:\WINDOWS\Prefetch
    2009-08-29 15:20:57 ----D---- C:\Program Files\Mozilla Firefox
    2009-08-29 03:00:23 ----HD---- C:\WINDOWS\inf
    2009-08-29 03:00:22 ----D---- C:\WINDOWS\system32\CatRoot
    2009-08-28 18:20:10 ----D---- C:\WINDOWS\system32
    2009-08-28 18:16:26 ----A---- C:\WINDOWS\system.ini
    2009-08-28 18:14:46 ----D---- C:\WINDOWS\system32\config
    2009-08-28 18:13:46 ----D---- C:\WINDOWS\AppPatch
    2009-08-28 18:13:46 ----D---- C:\Program Files\Common Files
    2009-08-28 14:57:40 ----D---- C:\WINDOWS\Minidump
    2009-08-28 14:47:01 ----RSHD---- C:\WINDOWS\system32\dllcache
    2009-08-28 14:35:26 ----SHD---- C:\WINDOWS\Installer
    2009-08-28 14:24:26 ----RASH---- C:\boot.ini
    2009-08-28 14:23:05 ----SHD---- C:\System Volume Information
    2009-08-28 14:23:05 ----D---- C:\WINDOWS\system32\Restore
    2009-08-28 14:13:46 ----A---- C:\WINDOWS\win.ini
    2009-08-27 22:35:09 ----A---- C:\WINDOWS\wininit.ini
    2009-08-27 08:35:09 ----RD---- C:\Program Files
    2009-08-27 08:23:47 ----RSD---- C:\WINDOWS\Fonts
    2009-08-27 08:23:46 ----D---- C:\Program Files\Common Files\AVSMedia
    2009-08-27 08:23:42 ----D---- C:\Program Files\AVS4YOU
    2009-08-27 08:18:29 ----D---- C:\Program Files\Symantec
    2009-08-27 08:18:29 ----D---- C:\Program Files\Common Files\Symantec Shared
    2009-08-26 20:54:20 ----D---- C:\Documents and Settings\All

    Users\Application Data\Symantec
    2009-08-26 03:00:24 ----SD---- C:\WINDOWS\Tasks
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\en-US
    2009-08-25 23:58:53 ----D---- C:\WINDOWS\Microsoft.NET
    2009-08-25 23:38:05 ----D---- C:\WINDOWS\network diagnostic
    2009-08-25 22:28:42 ----D---- C:\WINDOWS\WinSxS
    2009-08-25 20:40:58 ----A---- C:\WINDOWS\OEWABLog.txt
    2009-08-25 19:41:27 ----D---- C:\Documents and Settings\All

    Users\Application Data\McAfee
    2009-08-24 20:09:39 ----A---- C:\WINDOWS\imsins.BAK
    2009-08-23 09:15:05 ----HD---- C:\WINDOWS\$hf_mig$
    2009-08-22 03:23:10 ----RSD---- C:\WINDOWS\assembly
    2009-08-22 03:08:32 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
    2009-08-22 03:05:20 ----D---- C:\WINDOWS\system32\XPSViewer
    2009-08-22 03:02:31 ----D---- C:\Program Files\Internet Explorer
    2009-08-13 03:09:33 ----D---- C:\Program Files\Outlook Express
    2009-08-13 03:02:46 ----D---- C:\Documents and Settings\All

    Users\Application Data\Microsoft Help
    2009-08-08 17:49:50 ----D---- C:\Program Files\Microsoft Silverlight
    2009-08-05 03:01:48 ----A---- C:\WINDOWS\system32\mswebdvd.dll
    2009-08-01 19:36:03 ----D---- C:\Documents and Settings\Joe

    Miller\Application Data\Apple Computer
    2009-07-30 03:00:44 ----D---- C:\WINDOWS\ie8updates

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto,

    3=Demand, 4=Disabled)======

    R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
    R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
    R1 DLACDBHM;DLACDBHM; C:\WINDOWS\System32\Drivers\DLACDBHM.SYS [2005-08-25

    5628]
    R1 DLARTL_N;DLARTL_N; C:\WINDOWS\System32\Drivers\DLARTL_N.SYS [2005-08-25

    22684]
    R1 intelppm;Intel Processor Driver;

    C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
    R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
    R2 ASCTRM;ASCTRM; C:\WINDOWS\system32\drivers\ASCTRM.sys [2007-07-13 8552]
    R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-07-28

    55656]
    R2 DLABOIOM;DLABOIOM; C:\WINDOWS\System32\DLA\DLABOIOM.SYS [2005-09-08

    25628]
    R2 DLADResN;DLADResN; C:\WINDOWS\System32\DLA\DLADResN.SYS [2005-09-08

    2496]
    R2 DLAIFS_M;DLAIFS_M; C:\WINDOWS\System32\DLA\DLAIFS_M.SYS [2005-09-08

    86524]
    R2 DLAOPIOM;DLAOPIOM; C:\WINDOWS\System32\DLA\DLAOPIOM.SYS [2005-09-08

    14684]
    R2 DLAPoolM;DLAPoolM; C:\WINDOWS\System32\DLA\DLAPoolM.SYS [2005-09-08

    6364]
    R2 DLAUDF_M;DLAUDF_M; C:\WINDOWS\System32\DLA\DLAUDF_M.SYS [2005-09-08

    87036]
    R2 DLAUDFAM;DLAUDFAM; C:\WINDOWS\System32\DLA\DLAUDFAM.SYS [2005-09-08

    94332]
    R2 DRVNDDM;DRVNDDM; C:\WINDOWS\System32\Drivers\DRVNDDM.SYS [2005-08-12

    40544]
    R2 dsunidrv;DellSupport UniDriver; C:\WINDOWS\system32\DRIVERS\dsunidrv.sys

    [2007-02-25 5376]
    R2 symlcbrd;symlcbrd; \??\C:\WINDOWS\system32\drivers\symlcbrd.sys []
    R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver;

    C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2006-07-19 230400]
    R3 GEARAspiWDM;GEAR ASPI Filter Driver;

    C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2008-04-17 15464]
    R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio;

    C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
    R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-09-17 6853088]
    R3 STHDA;SigmaTel High Definition Audio CODEC;

    C:\WINDOWS\system32\drivers\sthda.sys [2006-07-24 1156648]
    R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver;

    C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
    R3 usbhub;Microsoft USB Standard Hub Driver;

    C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
    R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver;

    C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
    S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys

    [2008-04-13 14592]
    S3 A_USBETHMP;USB PowerPacket Network Adapter;

    C:\WINDOWS\System32\Drivers\usbethmp.sys [2007-10-26 14342]
    S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
    S3 DSproct;DSproct; \??\C:\Program

    Files\DellSupport\GTAction\triggers\DSproct.sys []
    S3 E100B;Intel(R) PRO Adapter Driver;

    C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-17 117760]
    S3 HidUsb;Microsoft HID Class Driver;

    C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
    S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys

    [2001-08-17 12160]
    S3 NAL;Nal Service ; \??\C:\WINDOWS\system32\Drivers\iqvw32.sys []
    S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys

    [2008-04-13 15104]
    S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

    [2008-04-13 26368]
    S3 wanatw;WAN Miniport (ATW); C:\WINDOWS\system32\DRIVERS\wanatw4.sys []
    S3 WLRAWMp50x86;WLRAWMp50x86 NDIS Protocol Driver;

    C:\WINDOWS\System32\Drivers\WLRAWMp50x86.sys [2007-10-26 26752]
    S3 WLRAWSp50x86;WLRAWSp50x86 NDIS Protocol Driver;

    C:\WINDOWS\System32\Drivers\WLRAWSp50x86.sys [2007-10-26 25472]
    S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform

    Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
    S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector;

    C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
    S4 agp440;Intel AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agp440.sys

    [2008-04-13 42368]
    S4 agpCPQ;Compaq AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys

    [2008-04-13 44928]
    S4 alim1541;ALI AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\alim1541.sys

    [2008-04-13 42752]
    S4 amdagp;AMD AGP Bus Filter Driver; C:\WINDOWS\system32\DRIVERS\amdagp.sys

    [2008-04-13 43008]
    S4 atapi;Standard IDE/ESDI Hard Disk Controller;

    C:\WINDOWS\system32\DRIVERS\atapi.sys [2008-04-13 96512]
    S4 cbidf;cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
    S4 IntelIde;IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [2008-04-13

    5504]
    S4 sisagp;SIS AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\sisagp.sys

    [2008-04-13 40960]
    S4 viaagp;VIA AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\viaagp.sys

    [2008-04-13 42240]
    S4 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment;

    C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto,

    3=Demand, 4=Disabled)======

    R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program

    Files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
    R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common

    Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

    [2008-11-07 132424]
    R2 Automatic LiveUpdate Scheduler;Automatic LiveUpdate Scheduler;

    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2006-07-25

    100032]
    R2 Bonjour Service;Bonjour Service; C:\Program

    Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
    R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program

    Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe [2006-07-06 90112]
    R2 JavaQuickStarterService;Java Quick Starter; C:\Program

    Files\Java\jre6\bin\jqs.exe [2008-12-15 152984]
    R2 LicCtrlService;LicCtrl Service; C:\WINDOWS\runservice.exe [2007-08-12

    2560]
    R2 LiveUpdate Notice Service;LiveUpdate Notice Service; C:\Program

    Files\Common Files\Symantec

    Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe [2007-03-12

    517768]
    R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe

    [2007-09-17 155716]
    R2 sprtsvc_ddoctorv2;SupportSoft Sprocket Service (ddoctorv2); C:\Program

    Files\Comcast\Desktop Doctor\bin\sprtsvc.exe [2008-04-24 202560]
    R2 Symantec Core LC;Symantec Core LC; C:\Program Files\Common

    Files\Symantec Shared\CCPD-LC\symlcsvc.exe [2007-09-19 1247600]
    R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe

    [2008-05-26 439808]
    R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe

    [2008-11-20 536872]
    S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-13 267776]
    S3 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir

    Desktop\avguard.exe [2009-07-21 185089]
    S3 aspnet_state;ASP.NET State Service;

    C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25

    34312]
    S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service

    v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe

    [2008-07-25 69632]
    S3 DSBrokerService;DSBrokerService; C:\Program

    Files\DellSupport\brkrsvc.exe [2007-03-19 70656]
    S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0;

    c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe

    [2008-07-29 46104]
    S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;

    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-06

    29744]
    S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common

    Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
    S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows

    Communication Foundation\infocard.exe [2008-07-29 881664]
    S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

    [2006-07-25 2119360]
    S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common

    Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
    S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft

    Shared\Source Engine\OSE.EXE [2006-10-26 145184]
    S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program

    Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
    S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework;

    C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
    S4 NetTcpPortSharing;Net.Tcp Port Sharing Service;

    C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication

    Foundation\SMSvcHost.exe [2008-07-29 132096]

    -----------------EOF-----------------

    Malwarebytes' Anti-Malware 1.40
    Database version: 2713
    Windows 5.1.2600 Service Pack 3

    8/29/2009 4:13:30 PM
    mbam-log-2009-08-29 (16-13-30).txt

    Scan type: Full Scan (C:\|)
    Objects scanned: 215055
    Time elapsed: 37 minute(s), 6 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 20

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Qoobox\Quarantine\C\WINDOWS\system32\kbiwkmbciobvxx.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\kbiwkmgbxouqxt.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\kbiwkmieogrodi.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\kbiwkmivximnti.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\kbiwkmjixgnwec.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\kbiwkmmspymcvp.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\kbiwkmohroqvpn.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\kbiwkmoptwbbfq.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\kbiwkmvnsixgew.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\kbiwkmyctfhwhe.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1\A0000041.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1\A0000042.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1\A0000043.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1\A0000044.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1\A0000045.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1\A0000046.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1\A0000047.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1\A0000048.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1\A0000049.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1\A0000050.dll (Trojan.TDSS) -> Quarantined and deleted successfully.

  6. #6
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Manchester UK
    Posts
    3,425

    Default

    Please can you post the contents of C:\RSIT\Info.txt along with the following


    Kaspersky Online Scanner .
    Your Antivirus and/or Antispyware may give a warning during the scan. This is perfectly normal
    NOTE:- This scan is best done from IE (Internet Explorer)

    NOTE:- Vista users should start IE by Start(Vista Orb) >> Internet Explorer >> Right-Click Run As Admin
    Go Here http://www.kaspersky.com/kos/eng/par...avwebscan.html

    Read the Requirements and limitations before you click Accept.
    Once the database has downloaded, click My Computer in the left pane
    Now go and put the kettle on !
    When the scan has completed, click Save Report As...
    Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
    Click Save - by default the file will be saved to your Desktop, but you can change this if you wish.


    **Note**

    To optimize scanning time and produce a more sensible report for review:
    • Close any open programs.
    • Turn off the real-time scanner of all antivirus or antispyware programs while performing the online scan.

    Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.



    How are things running now, any problems still ?
    Microsoft MVP Consumer Security 2009 -2010
    If we have helped, please consider a donation
    THESE INSTRUCTIONS ARE FOR THIS USER ONLY

  7. #7
    Junior Member
    Join Date
    Aug 2009
    Posts
    5

    Default problem solved

    I ran scans with spybot and malwarebytes, each came up with nothing. I noticed no further problem. I returned the PC to my friend. I have asked him to forward me the log from the initial scan of rsit. Thank you for your help!

  8. #8
    Junior Member
    Join Date
    Aug 2009
    Posts
    5

    Default rsit

    Kaspersky Online Scanner came up clean. Here is the last rsit log.

    Logfile of random's system information tool 1.06 (written by random/random)
    Run by Joe Miller at 2009-08-29 16:16:15
    Microsoft Windows XP Professional Service Pack 3
    System drive C: has 78 GB (52%) free of 149 GB
    Total RAM: 2046 MB (82% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 4:16:20 PM, on 8/29/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\WINDOWS\stsystra.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\runservice.exe
    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\SearchIndexer.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Documents and Settings\Joe Miller\Desktop\RSIT.exe
    C:\Temp\Joe Miller.exe
    C:\WINDOWS\system32\wuauclt.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://www.google.com/ig/dell?hl=en&...us&ibd=6070713
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
    O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/JOEMIL~1/LOCALS~1/Temp/msohtmlclip1/01/clip_image001.jpg

    --
    End of file - 8786 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    C:\WINDOWS\tasks\OGALogon.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    &Yahoo! Toolbar Helper - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2007-05-30 808472]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-01-12 63128]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29}]
    Comcast Toolbar - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL [2006-11-07 1821184]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}]
    Yahoo! IE Services Button - C:\Program Files\Yahoo!\Common\yiesrvc.dll [2006-10-31 198136]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}]
    DriveLetterAccess - C:\WINDOWS\System32\DLA\DLASHX_W.DLL [2005-09-08 110652]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-15 320920]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
    CBrowserHelperObject Object - C:\Program Files\BAE\BAE.dll [2006-12-08 98304]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
    Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-15 34816]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
    JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-12-15 73728]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2007-05-30 808472]
    {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - Comcast Toolbar - C:\PROGRA~1\COMCAS~1\COMCAS~1.DLL [2006-11-07 1821184]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-09-17 8491008]
    "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-15 136600]
    "SigmatelSysTrayApp"=C:\WINDOWS\stsystra.exe [2006-07-24 282624]
    "IAAnotif"=C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [2006-07-06 151552]
    "DLA"=C:\WINDOWS\System32\DLA\DLACTRLW.EXE [2005-09-08 122940]
    "ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-07-27 221184]
    "ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2008-10-24 79136]
    "Symantec PIF AlertEng"=C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe [2007-03-12 517768]
    "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-11-20 290088]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "DellSupport"=C:\Program Files\DellSupport\DSAgnt.exe [2007-03-15 460784]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader]
    C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe [2006-08-14 462336]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
    C:\Program Files\Dell\Media Experience\DMXLauncher.exe [2005-10-05 94208]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-06 29744]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    C:\Program Files\QuickTime\qttask.exe [2008-11-04 413696]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
    C:\Program Files\Real\RealPlayer\RealPlay.exe [2007-07-13 26112]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Search Protection]
    C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winupdate.exe]
    C:\WINDOWS\system32\winupdate.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
    C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [2007-08-30 4670704]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
    C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    C:\PROGRA~1\Adobe\ACROBA~1.0\Reader\READER~1.EXE [2005-09-23 29696]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
    C:\PROGRA~1\WINDOW~4\WINDOW~1.EXE [2008-05-26 123904]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Joe Miller^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
    C:\Documents and Settings\Joe Miller\Start Menu\Programs\Startup\PowerReg Scheduler.exe []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Joe Miller^Start Menu^Programs^Startup^Registration Chessmaster® Grandmaster Edition .LNK]
    C:\PROGRA~1\Ubisoft\CHESSM~1\Register\REGIST~1.EXE [2003-11-06 864256]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
    C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SymEFA.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=323
    "NoDriveAutoRun"=67108863
    "NoDrives"=0

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveAutoRun"=
    "NoDriveTypeAutoRun"=
    "NoDrives"=
    "HonorAutoRunSetting"=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
    "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
    "C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\Program Files\WiLife Command Center\Werks.exe"="C:\Program Files\WiLife Command Center\Werks.exe:*:Enabled:WiLife Command Center"
    "C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
    "C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe"="C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL"
    "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL"
    "C:\Program Files\America Online 9.0\waol.exe"="C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL"
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8fc4829a-9252-11de-bea2-0019d1e2c1a8}]
    shell\AutoRun\command - G:\StartPortableApps.exe


    ======List of files/folders created in the last 1 months======

    2009-08-29 16:16:15 ----D---- C:\rsit
    2009-08-28 18:20:08 ----A---- C:\ComboFix.txt
    2009-08-28 18:14:36 ----D---- C:\WINDOWS\temp
    2009-08-28 14:24:26 ----A---- C:\Boot.bak
    2009-08-28 14:24:19 ----RASHD---- C:\cmdcons
    2009-08-28 14:23:06 ----A---- C:\WINDOWS\zip.exe
    2009-08-28 14:23:06 ----A---- C:\WINDOWS\SWXCACLS.exe
    2009-08-28 14:23:06 ----A---- C:\WINDOWS\SWSC.exe
    2009-08-28 14:23:06 ----A---- C:\WINDOWS\SWREG.exe
    2009-08-28 14:23:06 ----A---- C:\WINDOWS\sed.exe
    2009-08-28 14:23:06 ----A---- C:\WINDOWS\PEV.exe
    2009-08-28 14:23:06 ----A---- C:\WINDOWS\NIRCMD.exe
    2009-08-28 14:23:06 ----A---- C:\WINDOWS\grep.exe
    2009-08-28 14:23:01 ----D---- C:\WINDOWS\ERDNT
    2009-08-28 14:12:28 ----D---- C:\Qoobox
    2009-08-26 16:56:29 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
    2009-08-26 15:44:31 ----D---- C:\Documents and Settings\Joe Miller\Application Data\Malwarebytes
    2009-08-26 14:52:43 ----D---- C:\Documents and Settings\All Users\Application Data\Norton
    2009-08-26 11:12:27 ----D---- C:\WINDOWS\NU_DATA
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\zh-TW
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\zh-HK
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\tr-TR
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\sv-SE
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\pt-BR
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\nl-NL
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\nb-NO
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\ko-KR
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\it-IT
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\he-IL
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\fr-FR
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\fi-FI
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\es-ES
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\el-GR
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\de-DE
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\da-DK
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\ar-SA
    2009-08-25 22:40:24 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
    2009-08-25 22:40:24 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2009-08-25 22:29:55 ----HDC---- C:\WINDOWS\$NtUninstallKB970653-v3$
    2009-08-25 20:49:09 ----D---- C:\Temp
    2009-08-25 19:42:11 ----D---- C:\Documents and Settings\All Users\Application Data\NortonInstaller
    2009-08-25 19:35:45 ----SHD---- C:\WINDOWS\CSC
    2009-08-24 21:29:35 ----D---- C:\Documents and Settings\Joe Miller\Application Data\Windows Search
    2009-08-24 21:07:10 ----D---- C:\Documents and Settings\Joe Miller\Application Data\U3
    2009-08-24 20:22:30 ----D---- C:\Program Files\Spybot - Search & Destroy
    2009-08-24 20:22:30 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2009-08-24 20:16:10 ----D---- C:\WINDOWS\pss
    2009-08-24 20:09:34 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
    2009-08-23 02:09:09 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
    2009-08-22 03:04:38 ----D---- C:\37dfd81f3793542348a5c3d991d17d8c
    2009-08-22 03:04:29 ----D---- C:\WINDOWS\SxsCaPendDel
    2009-08-13 03:03:10 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
    2009-08-13 03:03:05 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
    2009-08-13 03:03:01 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$
    2009-08-13 03:02:56 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
    2009-08-13 03:02:51 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
    2009-08-13 03:02:23 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
    2009-08-13 03:02:18 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
    2009-08-13 03:02:11 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
    2009-08-13 03:00:23 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
    2009-08-03 15:07:42 ----A---- C:\WINDOWS\system32\OGAEXEC.exe
    2009-08-03 15:07:42 ----A---- C:\WINDOWS\system32\OGACheckControl.dll
    2009-08-03 15:07:42 ----A---- C:\WINDOWS\system32\OGAAddin.dll

    ======List of files/folders modified in the last 1 months======

    2009-08-29 16:15:41 ----D---- C:\WINDOWS\system32\CatRoot2
    2009-08-29 16:15:12 ----D---- C:\WINDOWS\system32\drivers
    2009-08-29 16:15:12 ----D---- C:\WINDOWS
    2009-08-29 16:14:14 ----A---- C:\WINDOWS\SchedLgU.Txt
    2009-08-29 16:14:05 ----D---- C:\WINDOWS\Prefetch
    2009-08-29 15:20:57 ----D---- C:\Program Files\Mozilla Firefox
    2009-08-29 03:00:23 ----HD---- C:\WINDOWS\inf
    2009-08-29 03:00:22 ----D---- C:\WINDOWS\system32\CatRoot
    2009-08-28 18:20:10 ----D---- C:\WINDOWS\system32
    2009-08-28 18:16:26 ----A---- C:\WINDOWS\system.ini
    2009-08-28 18:14:46 ----D---- C:\WINDOWS\system32\config
    2009-08-28 18:13:46 ----D---- C:\WINDOWS\AppPatch
    2009-08-28 18:13:46 ----D---- C:\Program Files\Common Files
    2009-08-28 14:57:40 ----D---- C:\WINDOWS\Minidump
    2009-08-28 14:47:01 ----RSHD---- C:\WINDOWS\system32\dllcache
    2009-08-28 14:35:26 ----SHD---- C:\WINDOWS\Installer
    2009-08-28 14:24:26 ----RASH---- C:\boot.ini
    2009-08-28 14:23:05 ----SHD---- C:\System Volume Information
    2009-08-28 14:23:05 ----D---- C:\WINDOWS\system32\Restore
    2009-08-28 14:13:46 ----A---- C:\WINDOWS\win.ini
    2009-08-27 22:35:09 ----A---- C:\WINDOWS\wininit.ini
    2009-08-27 08:35:09 ----RD---- C:\Program Files
    2009-08-27 08:23:47 ----RSD---- C:\WINDOWS\Fonts
    2009-08-27 08:23:46 ----D---- C:\Program Files\Common Files\AVSMedia
    2009-08-27 08:23:42 ----D---- C:\Program Files\AVS4YOU
    2009-08-27 08:18:29 ----D---- C:\Program Files\Symantec
    2009-08-27 08:18:29 ----D---- C:\Program Files\Common Files\Symantec Shared
    2009-08-26 20:54:20 ----D---- C:\Documents and Settings\All Users\Application Data\Symantec
    2009-08-26 03:00:24 ----SD---- C:\WINDOWS\Tasks
    2009-08-26 03:00:23 ----D---- C:\WINDOWS\system32\en-US
    2009-08-25 23:58:53 ----D---- C:\WINDOWS\Microsoft.NET
    2009-08-25 23:38:05 ----D---- C:\WINDOWS\network diagnostic
    2009-08-25 22:28:42 ----D---- C:\WINDOWS\WinSxS
    2009-08-25 20:40:58 ----A---- C:\WINDOWS\OEWABLog.txt
    2009-08-25 19:41:27 ----D---- C:\Documents and Settings\All Users\Application Data\McAfee
    2009-08-24 20:09:39 ----A---- C:\WINDOWS\imsins.BAK
    2009-08-23 09:15:05 ----HD---- C:\WINDOWS\$hf_mig$
    2009-08-22 03:23:10 ----RSD---- C:\WINDOWS\assembly
    2009-08-22 03:08:32 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
    2009-08-22 03:05:20 ----D---- C:\WINDOWS\system32\XPSViewer
    2009-08-22 03:02:31 ----D---- C:\Program Files\Internet Explorer
    2009-08-13 03:09:33 ----D---- C:\Program Files\Outlook Express
    2009-08-13 03:02:46 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
    2009-08-08 17:49:50 ----D---- C:\Program Files\Microsoft Silverlight
    2009-08-05 03:01:48 ----A---- C:\WINDOWS\system32\mswebdvd.dll
    2009-08-01 19:36:03 ----D---- C:\Documents and Settings\Joe Miller\Application Data\Apple Computer
    2009-07-30 03:00:44 ----D---- C:\WINDOWS\ie8updates

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys []
    R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
    R1 DLACDBHM;DLACDBHM; C:\WINDOWS\System32\Drivers\DLACDBHM.SYS [2005-08-25 5628]
    R1 DLARTL_N;DLARTL_N; C:\WINDOWS\System32\Drivers\DLARTL_N.SYS [2005-08-25 22684]
    R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
    R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
    R2 ASCTRM;ASCTRM; C:\WINDOWS\system32\drivers\ASCTRM.sys [2007-07-13 8552]
    R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2009-07-28 55656]
    R2 DLABOIOM;DLABOIOM; C:\WINDOWS\System32\DLA\DLABOIOM.SYS [2005-09-08 25628]
    R2 DLADResN;DLADResN; C:\WINDOWS\System32\DLA\DLADResN.SYS [2005-09-08 2496]
    R2 DLAIFS_M;DLAIFS_M; C:\WINDOWS\System32\DLA\DLAIFS_M.SYS [2005-09-08 86524]
    R2 DLAOPIOM;DLAOPIOM; C:\WINDOWS\System32\DLA\DLAOPIOM.SYS [2005-09-08 14684]
    R2 DLAPoolM;DLAPoolM; C:\WINDOWS\System32\DLA\DLAPoolM.SYS [2005-09-08 6364]
    R2 DLAUDF_M;DLAUDF_M; C:\WINDOWS\System32\DLA\DLAUDF_M.SYS [2005-09-08 87036]
    R2 DLAUDFAM;DLAUDFAM; C:\WINDOWS\System32\DLA\DLAUDFAM.SYS [2005-09-08 94332]
    R2 DRVNDDM;DRVNDDM; C:\WINDOWS\System32\Drivers\DRVNDDM.SYS [2005-08-12 40544]
    R2 dsunidrv;DellSupport UniDriver; C:\WINDOWS\system32\DRIVERS\dsunidrv.sys [2007-02-25 5376]
    R2 symlcbrd;symlcbrd; \??\C:\WINDOWS\system32\drivers\symlcbrd.sys []
    R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e1e5132.sys [2006-07-19 230400]
    R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2008-04-17 15464]
    R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
    R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-09-17 6853088]
    R3 STHDA;SigmaTel High Definition Audio CODEC; C:\WINDOWS\system32\drivers\sthda.sys [2006-07-24 1156648]
    R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
    R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
    R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
    S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
    S3 A_USBETHMP;USB PowerPacket Network Adapter; C:\WINDOWS\System32\Drivers\usbethmp.sys [2007-10-26 14342]
    S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
    S3 DSproct;DSproct; \??\C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys []
    S3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-17 117760]
    S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
    S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
    S3 NAL;Nal Service ; \??\C:\WINDOWS\system32\Drivers\iqvw32.sys []
    S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
    S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
    S3 wanatw;WAN Miniport (ATW); C:\WINDOWS\system32\DRIVERS\wanatw4.sys []
    S3 WLRAWMp50x86;WLRAWMp50x86 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\WLRAWMp50x86.sys [2007-10-26 26752]
    S3 WLRAWSp50x86;WLRAWSp50x86 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\WLRAWSp50x86.sys [2007-10-26 25472]
    S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
    S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
    S4 agp440;Intel AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
    S4 agpCPQ;Compaq AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2008-04-13 44928]
    S4 alim1541;ALI AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\alim1541.sys [2008-04-13 42752]
    S4 amdagp;AMD AGP Bus Filter Driver; C:\WINDOWS\system32\DRIVERS\amdagp.sys [2008-04-13 43008]
    S4 atapi;Standard IDE/ESDI Hard Disk Controller; C:\WINDOWS\system32\DRIVERS\atapi.sys [2008-04-13 96512]
    S4 cbidf;cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
    S4 IntelIde;IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [2008-04-13 5504]
    S4 sisagp;SIS AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\sisagp.sys [2008-04-13 40960]
    S4 viaagp;VIA AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2008-04-13 42240]
    S4 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
    R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-11-07 132424]
    R2 Automatic LiveUpdate Scheduler;Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2006-07-25 100032]
    R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
    R2 IAANTMON;Intel(R) Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe [2006-07-06 90112]
    R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-12-15 152984]
    R2 LicCtrlService;LicCtrl Service; C:\WINDOWS\runservice.exe [2007-08-12 2560]
    R2 LiveUpdate Notice Service;LiveUpdate Notice Service; C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe [2007-03-12 517768]
    R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-09-17 155716]
    R2 sprtsvc_ddoctorv2;SupportSoft Sprocket Service (ddoctorv2); C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe [2008-04-24 202560]
    R2 Symantec Core LC;Symantec Core LC; C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe [2007-09-19 1247600]
    R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
    R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-11-20 536872]
    S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-13 267776]
    S3 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-07-21 185089]
    S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
    S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
    S3 DSBrokerService;DSBrokerService; C:\Program Files\DellSupport\brkrsvc.exe [2007-03-19 70656]
    S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
    S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-06 29744]
    S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
    S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
    S3 LiveUpdate;LiveUpdate; C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE [2006-07-25 2119360]
    S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
    S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
    S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
    S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
    S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

    -----------------EOF-----------------

  9. #9
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Manchester UK
    Posts
    3,425

    Default

    Congratulations your logs look clean

    Let's see if I can help you keep it that way

    First lets tidy up



    Uninstall Combofix
    • This will clear your System Volume Information restore points and remove all the infected files that were quarantined
    • Click START then RUN
    • Now type Combofix /u in the runbox and click OK. Note the space between the X and the /U, it needs to be there.




    OTCleanup
    Please download OTCleanup from HERE
    Click the OTC.exe icon and then click the CleanUp button.
    If you get any pop ups asking if it is OK let the program proceed. At the end the program will ask to let it reboot the computer. Let it do so.
    Let me know if there were any problems with OT CleanIt




    You can also delete any logs we have produced and any other tools we have downloaded.

    ----------------------------------------------------------- -----------------------------------------------------------

    The following is some info to help you stay safe and clean.


    You may already have some of the following programs, but I include the full list for the benefit of all the other people who will be reading this thread in the future.
    ( Vista users must ensure that any programs are Vista compatible BEFORE installing )

    Online Scanners
    I would recommend a scan at one or more of the following sites at least once a month.

    http://www.pandasecurity.com/activescan
    http://www.kaspersky.com/kos/eng/par...avwebscan.html

    !!! Make sure that all your programs are updated !!!
    Secunia Software Inspector does all the work for you, .... see HERE for details

    AntiSpyware
    • AntiSpyware is not the same thing as Antivirus.
      Different AntiSpyware programs detect different things, so in this case it is recommended that you have more than one.
      You should only have one running all the time, the other/s should be used "on demand" on a regular basis.
      Most of the programs in this list have a free (for Home Users ) and paid versions,
      it is worth paying for one and having "realtime" protection, unless you intend to do a manual scan often.
    • Spybot - Search & Destroy <<< A must have program
      • It includes host protection and registry protection
      • A hosts file is a bit like a phone book, it points to the actual numeric address (i.e. the IP address) from the human friendly name of a website. This feature can be used to block malicious websites
    • MalwareBytes Anti-malware <<< A New and effective program
    • a-squared Free <<< A good "realtime" or "on demand" scanner
    • superantispyware <<< A good "realtime" or "on demand" scanner


    Prevention
    • These programs don't detect malware, they help stop it getting on your machine in the first place.
      Each does a different job, so you can have more than one
    • Winpatrol
      • An excellent startup manager and then some !!
      • Notifies you if programs are added to startup
      • Allows delayed startup
      • A must have addition
    • SpywareBlaster 4.0
      • SpywareBlaster sets killbits in the registry to prevent known malicious activex controls from installing themselves on your computer.
    • SpywareGuard 2.2
      • SpywareGuard provides real-time protection against spyware.
      • Not required if you have other "realtime" antispyware or Winpatrol
    • ZonedOut
      • Formerly known as IE-SPYAD, adds a long list of sites and domains associated with known advertisers and marketers to the Restricted sites zone of Internet Explorer.
    • MVPS HOSTS
      • This little program packs a powerful punch as it blocks ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
      • For information on how to download and install, please read this tutorial by WinHelp2002.
      • Not required if you are using other host file protections


    Internet Browsers
    • Microsoft has worked hard to make IE.7 a more secure browser, unfortunately whilst it is still the leading browser of choice it will always be under attack from the bad guys.
      Using a different web browser can help stop malware getting on your machine.
      • Make your Internet Explorer more secure - This can be done by following these simple instructions:
        1. From within Internet Explorer click on the Tools menu and then click on Options.
        2. Click once on the Security tab
        3. Click once on the Internet icon so it becomes highlighted.
        4. Click once on the Custom Level button.
          • Change the Download signed ActiveX controls to Prompt
          • Change the Download unsigned ActiveX controls to Disable
          • Change the Initialise and script ActiveX controls not marked as safe to Disable
          • Change the Installation of desktop items to Prompt
          • Change the Launching programs and files in an IFRAME to Prompt
          • Change the Navigate sub-frames across different domains to Prompt
          • When all these settings have been made, click on the OK button.
          • If it prompts you as to whether or not you want to save the settings, press the Yes button.
        5. Next press the Apply button and then the OK to exit the Internet Properties page.

      If you are still using IE6 then either update, or get one of the following.
      • FireFox
        • With many addons available that make customization easy this is a very popular choice
        • NoScript and AdBlockPlus addons are essential
      • Opera
        • Another popular alternative
      • Netscape
        • Another popular alternative
        • Also has Addons available


    Cleaning Temporary Internet Files and Tracking Cookies
    • Temporary Internet Files are mainly the files that are downloaded when you open a web page.
      Unfortunately, if the site you visit is of a dubious nature or has been hacked, they can also be an entry point for malware.
      It is a good idea to empty the Temporary Internet Files folder on a regular basis.

      Tracking Cookies are files that websites use to monitor which sites you visit and how often.
      A lot of Antispyware scanners pick up these tracking cookies and flag them as unwanted.
      CAUTION :- If you delete all your cookies you will lose any autologin information for sites that you visit, and will need your passwords

      Both of these can be cleaned manually, but a quicker option is to use a program
    • ATF Cleaner
      • Free and very simple to use
    • CCleaner
      • Free and very flexible, you can chose which cookies to keep


    Also PLEASE read this article.....So How Did I Get Infected In The First Place

    The last and most important thing I can tell you is UPDATE.
    If you don't update your security programs (Antivirus, Antispyware even Windows) then you are at risk.
    Malware changes on a day to day basis. You should update every week at the very least.

    If you follow this advice then (with a bit of luck) you will never have to hear from me again :D


    If you could post back one more time to let me know everything is OK, then I can have this thread archived.

    Happy surfing K'
    Microsoft MVP Consumer Security 2009 -2010
    If we have helped, please consider a donation
    THESE INSTRUCTIONS ARE FOR THIS USER ONLY

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •