John Bradford
New member
Hello there,
I need help, please, with my machine Windows XP IE7 that, each time I turn the machine off to shut it down, it goes wild for about two minutes, like accelerating and noisy before it goes off. Also, when I try to open CNN video, it takes up most cpu, and clumsily display the video, erratically. I ran the Registry Booster and Spybot but to no avail. There must be something like Malwares somewhere out there. Enclosed herewith the DDS (pasted below) with zipped Attach file. Your help is very much valued.
John
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.5730.11
Run by Administrator at 7:49:29 on 2012-07-25
Microsoft Windows XP Professional 5.1.2600.3.932.81.1041.18.2047.1377 [GMT 9:00]
.
AV: Avira Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\program files\real\realplayer\update\realsched.exe
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\B's Recorder GOLD8\bgsvc.exe
C:\Program files\B.H.A\Common\bgsvcg.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Blaze Media Pro\NMSAccess32.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\conime.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.jp/
uInternet Settings,ProxyOverride = localhost
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy 2\SDHelper.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: {5c8b2a36-3db1-42a4-a3cb-d426709bbfeb} - PCTools Site Guard
BHO: Programme d'aide de l'Assistant de connexion Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll
BHO: {b56a7d7d-6927-48c8-a975-17df180c71ac} - PCTools Browser Monitor
BHO: Fire-Trust SiteHound: {c86ae9c0-0909-4ddc-b661-c1afb9f5ae53} - CPub Object
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
TB: SiteHound: {73f7f495-a325-4c52-be48-5f97fa511e89} -
TB: {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No File
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [SetRefresh] c:\program files\compaq\setrefresh\SetRefresh.exe
mRun: [IMJPMIG9.0] c:\progra~1\common~1\micros~1\ime\imjp9\IMJPMIG.EXE /Preload /Migration32
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe"
dRun: [ctfmon.exe] ctfmon.exe
StartupFolder: c:\docume~1\admini~1\ベター~1\プロバ~1\ベター~1\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\admini~1\ベター~1\プロバ~1\ベター~1\mailwa~1.lnk - c:\program files\firetrust\mailwasher pro\MailWasher.exe
IE: &Yahoo! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm
IE: Google 検索(&G) - c:\program files\google\GoogleToolbar2.dll/cmsearch.html
IE: Microsoft Excel にエクスポート(&X) - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\yahoo!\Common/ycsms.htm
IE: このページのキャッシュ - c:\program files\google\GoogleToolbar2.dll/cmcache.html
IE: リンク元 - c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
IE: 翻訳(&T) - c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
IE: 関連ページ - c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - c:\program files\yahoo!\messenger\YahooMessenger.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0\bin\npjpi150.dll
IE: {11316B13-33F0-4C9F-BD55-09994CCFA8EB} - {73F7F495-A325-4C52-BE48-5F97FA511E89}
IE: {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - {A1EDC4A1-940F-48E0-8DFD-E38F1D501021}
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
DPF: {0CBF7EDC-17EC-442C-8AE9-5E804707B6CA} - hxxp://dist.cdnetworks.co.jp/cdndist/neffy/Neffy.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/9/b/d/9bdc68ef-6a9f-4505-8fb8-d0d2d160e512/LegitCheckControl.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {D74527B1-D405-4673-8A30-1A9B346AADF2} - hxxp://viewer.zooma.jp/viewer/mamoViewer.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.11.1
TCP: Interfaces\{1125DF7F-68D8-4B8A-BF25-7918E0D8D2E2} : DhcpNameServer = 192.168.11.1
Notify: igfxcui - igfxdev.dll
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.98.9.3 pop.jcom.home.ne.jp.b9
Hosts: 127.98.9.4 smtp.jcom.home.ne.jp.b9
Hosts: 127.98.9.1 pop.ksrzu1.kt.home.ne.jp.b9
Hosts: 127.98.9.2 pop.mail.yahoo.com.b9
.
============= SERVICES / DRIVERS ===============
.
R0 BsStor;B.H.A Storage Helper Driver;c:\windows\system32\drivers\bsstor.sys [2012-6-21 17192]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2011-12-15 36000]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-12-15 86224]
R2 AntiVirService;Avira Realtime Protection;c:\program files\avira\antivir desktop\avguard.exe [2011-12-15 110032]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-12-15 83392]
R2 bgsvc;B's Recorder GOLD Service;c:\program files\b's recorder gold8\bgsvc.exe [2006-11-20 81920]
R2 bgsvcg;B's Recorder GOLD General Service;c:\program files\b.h.a\common\bgsvcg.exe [2007-12-21 145256]
R2 BsUDF;BsUDF;c:\windows\system32\drivers\BsUDF.sys [2012-6-21 196000]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\spybot - search & destroy 2\SDFSSvc.exe [2012-7-21 1122296]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\spybot - search & destroy 2\SDUpdSvc.exe [2012-7-21 838136]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-5 250056]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2011-6-9 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2011-6-9 8456]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
.
=============== Created Last 30 ================
.
2012-07-21 03:26:14 15224 ----a-w- c:\windows\system32\sdnclean.exe
2012-07-21 03:26:10 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2012-07-19 22:48:05 -------- d-----w- c:\documents and settings\all users\application data\AJSystems
2012-07-19 22:48:01 -------- d-----w- c:\program files\ezBackup5
2012-07-16 10:34:39 -------- d-----w- c:\windows\system32\appmgmt
2012-07-11 23:00:03 -------- d-----w- c:\program files\CrystalDiskInfo
.
==================== Find3M ====================
.
2012-07-12 07:04:22 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-12 07:04:22 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-13 13:55:12 1865728 ----a-w- c:\windows\system32\win32k.sys
2012-06-06 19:57:40 499712 ----a-w- c:\windows\system32\msvcp71.dll
2012-06-06 19:57:40 348160 ----a-w- c:\windows\system32\msvcr71.dll
2012-06-05 15:49:29 1372672 ------w- c:\windows\system32\msxml6.dll
2012-06-05 15:49:29 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32:11 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 06:19:48 18456 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 06:19:38 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 06:19:34 14360 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 06:19:34 13848 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 06:19:34 12824 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 06:18:58 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-06-02 06:18:58 214256 ----a-w- c:\windows\system32\muweb.dll
2012-06-02 06:18:58 15088 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:21:57 593920 ----a-w- c:\windows\system32\crypt32.dll
2012-05-15 15:36:59 832512 ----a-w- c:\windows\system32\wininet.dll
2012-05-08 11:19:23 83392 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-05-05 03:14:34 2148352 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-05 03:14:33 2026496 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:47:09 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: SAMSUNG_HD160JJ/P rev.ZM100-34 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-2b
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; MOV CX, 0x4; MOV BP, 0x7be; CMP BYTE [BP+0x0], 0x0; }
user != kernel MBR !!!
.
============= FINISH: 7:55:31.01 ===============
I need help, please, with my machine Windows XP IE7 that, each time I turn the machine off to shut it down, it goes wild for about two minutes, like accelerating and noisy before it goes off. Also, when I try to open CNN video, it takes up most cpu, and clumsily display the video, erratically. I ran the Registry Booster and Spybot but to no avail. There must be something like Malwares somewhere out there. Enclosed herewith the DDS (pasted below) with zipped Attach file. Your help is very much valued.
John
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.5730.11
Run by Administrator at 7:49:29 on 2012-07-25
Microsoft Windows XP Professional 5.1.2600.3.932.81.1041.18.2047.1377 [GMT 9:00]
.
AV: Avira Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\program files\real\realplayer\update\realsched.exe
C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\B's Recorder GOLD8\bgsvc.exe
C:\Program files\B.H.A\Common\bgsvcg.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Blaze Media Pro\NMSAccess32.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\conime.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.jp/
uInternet Settings,ProxyOverride = localhost
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy 2\SDHelper.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: {5c8b2a36-3db1-42a4-a3cb-d426709bbfeb} - PCTools Site Guard
BHO: Programme d'aide de l'Assistant de connexion Windows Live: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll
BHO: {b56a7d7d-6927-48c8-a975-17df180c71ac} - PCTools Browser Monitor
BHO: Fire-Trust SiteHound: {c86ae9c0-0909-4ddc-b661-c1afb9f5ae53} - CPub Object
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
TB: SiteHound: {73f7f495-a325-4c52-be48-5f97fa511e89} -
TB: {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No File
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [SetRefresh] c:\program files\compaq\setrefresh\SetRefresh.exe
mRun: [IMJPMIG9.0] c:\progra~1\common~1\micros~1\ime\imjp9\IMJPMIG.EXE /Preload /Migration32
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SDTray] "c:\program files\spybot - search & destroy 2\SDTray.exe"
dRun: [ctfmon.exe] ctfmon.exe
StartupFolder: c:\docume~1\admini~1\ベター~1\プロバ~1\ベター~1\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\admini~1\ベター~1\プロバ~1\ベター~1\mailwa~1.lnk - c:\program files\firetrust\mailwasher pro\MailWasher.exe
IE: &Yahoo! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm
IE: Google 検索(&G) - c:\program files\google\GoogleToolbar2.dll/cmsearch.html
IE: Microsoft Excel にエクスポート(&X) - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\yahoo!\Common/ycsms.htm
IE: このページのキャッシュ - c:\program files\google\GoogleToolbar2.dll/cmcache.html
IE: リンク元 - c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
IE: 翻訳(&T) - c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
IE: 関連ページ - c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - c:\program files\yahoo!\messenger\YahooMessenger.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0\bin\npjpi150.dll
IE: {11316B13-33F0-4C9F-BD55-09994CCFA8EB} - {73F7F495-A325-4C52-BE48-5F97FA511E89}
IE: {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - {A1EDC4A1-940F-48E0-8DFD-E38F1D501021}
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy 2\SDHelper.dll
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
DPF: {0CBF7EDC-17EC-442C-8AE9-5E804707B6CA} - hxxp://dist.cdnetworks.co.jp/cdndist/neffy/Neffy.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/9/b/d/9bdc68ef-6a9f-4505-8fb8-d0d2d160e512/LegitCheckControl.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {D74527B1-D405-4673-8A30-1A9B346AADF2} - hxxp://viewer.zooma.jp/viewer/mamoViewer.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.11.1
TCP: Interfaces\{1125DF7F-68D8-4B8A-BF25-7918E0D8D2E2} : DhcpNameServer = 192.168.11.1
Notify: igfxcui - igfxdev.dll
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.98.9.3 pop.jcom.home.ne.jp.b9
Hosts: 127.98.9.4 smtp.jcom.home.ne.jp.b9
Hosts: 127.98.9.1 pop.ksrzu1.kt.home.ne.jp.b9
Hosts: 127.98.9.2 pop.mail.yahoo.com.b9
.
============= SERVICES / DRIVERS ===============
.
R0 BsStor;B.H.A Storage Helper Driver;c:\windows\system32\drivers\bsstor.sys [2012-6-21 17192]
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2011-12-15 36000]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-12-15 86224]
R2 AntiVirService;Avira Realtime Protection;c:\program files\avira\antivir desktop\avguard.exe [2011-12-15 110032]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-12-15 83392]
R2 bgsvc;B's Recorder GOLD Service;c:\program files\b's recorder gold8\bgsvc.exe [2006-11-20 81920]
R2 bgsvcg;B's Recorder GOLD General Service;c:\program files\b.h.a\common\bgsvcg.exe [2007-12-21 145256]
R2 BsUDF;BsUDF;c:\windows\system32\drivers\BsUDF.sys [2012-6-21 196000]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\spybot - search & destroy 2\SDFSSvc.exe [2012-7-21 1122296]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\spybot - search & destroy 2\SDUpdSvc.exe [2012-7-21 838136]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-5 250056]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2011-6-9 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2011-6-9 8456]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
.
=============== Created Last 30 ================
.
2012-07-21 03:26:14 15224 ----a-w- c:\windows\system32\sdnclean.exe
2012-07-21 03:26:10 -------- d-----w- c:\program files\Spybot - Search & Destroy 2
2012-07-19 22:48:05 -------- d-----w- c:\documents and settings\all users\application data\AJSystems
2012-07-19 22:48:01 -------- d-----w- c:\program files\ezBackup5
2012-07-16 10:34:39 -------- d-----w- c:\windows\system32\appmgmt
2012-07-11 23:00:03 -------- d-----w- c:\program files\CrystalDiskInfo
.
==================== Find3M ====================
.
2012-07-12 07:04:22 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-12 07:04:22 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-13 13:55:12 1865728 ----a-w- c:\windows\system32\win32k.sys
2012-06-06 19:57:40 499712 ----a-w- c:\windows\system32\msvcp71.dll
2012-06-06 19:57:40 348160 ----a-w- c:\windows\system32\msvcr71.dll
2012-06-05 15:49:29 1372672 ------w- c:\windows\system32\msxml6.dll
2012-06-05 15:49:29 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32:11 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 06:19:48 18456 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 06:19:38 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 06:19:34 14360 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 06:19:34 13848 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 06:19:34 12824 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 06:18:58 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-06-02 06:18:58 214256 ----a-w- c:\windows\system32\muweb.dll
2012-06-02 06:18:58 15088 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:21:57 593920 ----a-w- c:\windows\system32\crypt32.dll
2012-05-15 15:36:59 832512 ----a-w- c:\windows\system32\wininet.dll
2012-05-08 11:19:23 83392 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-05-05 03:14:34 2148352 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-05-05 03:14:33 2026496 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:47:09 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: SAMSUNG_HD160JJ/P rev.ZM100-34 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-2b
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; MOV CX, 0x4; MOV BP, 0x7be; CMP BYTE [BP+0x0], 0x0; }
user != kernel MBR !!!
.
============= FINISH: 7:55:31.01 ===============