Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Pretty bad Malware problem


  • Please log in to reply

#31
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
I'd like you to rename the GMER file and try the scan again. Armodeluxe and Kimberly have been kind enough to take a look at your problem and have pointed me in the right direction, hopefully! I'll post the instructions again to save you having to read back through the thread.

Note: You can rename gmer.exe to anything you like as long as you keep the .exe ending.

Download gmer.zip from here and save it to your Desktop.
You will need to unzip it before you run it.

To do this: Right click on the zipped folder and from the menu that appears, click on Extract All...
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish


Double click gmer.exe to begin:
  • Select the Rootkit Tab at the top.
  • Click the Scan button on the right.
  • When the scan has completed, click the Copy button underneath - this will save the report to your Clipboard.
  • Paste it into Notepad (Start > All Programs > Accessories > Notepad) and save it somewhere convenient.
  • Repeat this for the Autostart Tab.
Copy and paste both reports into your next reply - you may need to post them seperately.

Avast doesn't seem to like the PandaScan - if you can get it to run OK, do so. The detection is a false positive.
If you can't get that scan to run, do this one instead:

IMPORTANT - A new version of the Kaspersky Online Scanner was released on August 8, 2006. If you have installed a previous version then you need to go to Add/Remove Programs and remove any entries for Kaspersky Online Scanner before you proceed.
* Close all Internet Explorer windows before doing this.

Go here and click the Kaspersky Online Scanner button.
  • Read the Requirements and limitations before you click Accept.
  • Allow the ActiveX download if necessary.
  • Once the database has downloaded click Next.
  • Click Scan Settings and change the "Scan using the following antivirus database" from standard to extended and then click OK.
  • Click on "My Computer" and then put the kettle on!
  • When the scan has completed, click Save Report As...
  • Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
  • Click Save - by default the file will be saved to your Desktop, but you can change this if you wish.
Copy and paste the report into your next reply.

All being well, one quick fix and you should be done after this.
  • 0

Advertisements


#32
bobletman

bobletman

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 143 posts
Ok I managed to do everything here you go.

here is the gmer scan (rootkit)

GMER 1.0.12.12011 - http://www.gmer.net
Rootkit scan 2006-11-30 17:37:25
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.12 ----

SSDT sptd.sys ZwCreateKey
SSDT sptd.sys ZwEnumerateKey
SSDT sptd.sys ZwEnumerateValueKey
SSDT sptd.sys ZwOpenKey
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT sptd.sys ZwQueryKey
SSDT sptd.sys ZwQueryValueKey
SSDT sptd.sys ZwSetValueKey
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess

---- Kernel code sections - GMER 1.0.12 ----

.text USBPORT.SYS!DllUnload F760B62C 5 Bytes JMP 821AA748

---- User code sections - GMER 1.0.12 ----

.text C:\WINDOWS\system32\winlogon.exe[604] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00C84831
.text C:\WINDOWS\system32\winlogon.exe[604] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 00C84A44
.text C:\WINDOWS\system32\winlogon.exe[604] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00C84B61
.text C:\WINDOWS\system32\winlogon.exe[604] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00C84946
.text C:\WINDOWS\explorer.exe[2796] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00B44831
.text C:\WINDOWS\explorer.exe[2796] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 00B44A44
.text C:\WINDOWS\explorer.exe[2796] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00B44B61
.text C:\WINDOWS\explorer.exe[2796] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00B44946
.text C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[2984] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00B84831
.text C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[2984] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 00B84A44
.text C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[2984] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00B84B61
.text C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[2984] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00B84946
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[3004] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00884831
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[3004] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 00884A44
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[3004] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00884B61
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[3004] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00884946
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3016] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00954831
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3016] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 00954A44
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3016] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00954B61
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3016] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00954946
.text C:\WINDOWS\agrsmmsg.exe[3024] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00934831
.text C:\WINDOWS\agrsmmsg.exe[3024] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 00934A44
.text C:\WINDOWS\agrsmmsg.exe[3024] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00934B61
.text C:\WINDOWS\agrsmmsg.exe[3024] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00934946
.text C:\Program Files\TOSHIBA\Tvs\TvsTray.exe[3036] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 008B4831
.text C:\Program Files\TOSHIBA\Tvs\TvsTray.exe[3036] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 008B4A44
.text C:\Program Files\TOSHIBA\Tvs\TvsTray.exe[3036] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 008B4B61
.text C:\Program Files\TOSHIBA\Tvs\TvsTray.exe[3036] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 008B4946
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[3044] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 008C4831
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[3044] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 008C4A44
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[3044] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 008C4B61
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[3044] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 008C4946
.text C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe[3100] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 009B4831
.text C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe[3100] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 009B4A44
.text C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe[3100] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 009B4B61
.text C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe[3100] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 009B4946
.text C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe[3172] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00D14831
.text C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe[3172] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 00D14A44
.text C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe[3172] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00D14B61
.text C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe[3172] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00D14946
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[3184] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00954831
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[3184] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 00954A44
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[3184] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00954B61
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[3184] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00954946
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[3228] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 008C4831
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[3228] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 008C4A44
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[3228] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 008C4B61
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[3228] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 008C4946
.text C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe[3368] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 01144831
.text C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe[3368] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 01144A44
.text C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe[3368] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 01144B61
.text C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe[3368] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 01144946
.text C:\Program Files\Common Files\Logitech\QCDriver3\LVComS.exe[3384] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00934831
.text C:\Program Files\Common Files\Logitech\QCDriver3\LVComS.exe[3384] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 00934A44
.text C:\Program Files\Common Files\Logitech\QCDriver3\LVComS.exe[3384] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00934B61
.text C:\Program Files\Common Files\Logitech\QCDriver3\LVComS.exe[3384] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00934946
.text C:\Program Files\QuickTime\qttask.exe[3424] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 008D4831
.text C:\Program Files\QuickTime\qttask.exe[3424] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 008D4A44
.text C:\Program Files\QuickTime\qttask.exe[3424] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 008D4B61
.text C:\Program Files\QuickTime\qttask.exe[3424] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 008D4946
.text C:\Program Files\iTunes\iTunesHelper.exe[3452] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 003D4831
.text C:\Program Files\iTunes\iTunesHelper.exe[3452] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 003D4A44
.text C:\Program Files\iTunes\iTunesHelper.exe[3452] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 003D4B61
.text C:\Program Files\iTunes\iTunesHelper.exe[3452] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 003D4946
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[3468] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00F44831
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[3468] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 00F44A44
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[3468] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00F44B61
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[3468] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00F44946
.text C:\Program Files\PowerISO\PWRISOVM.EXE[3520] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 008E4831
.text C:\Program Files\PowerISO\PWRISOVM.EXE[3520] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 008E4A44
.text C:\Program Files\PowerISO\PWRISOVM.EXE[3520] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 008E4B61
.text C:\Program Files\PowerISO\PWRISOVM.EXE[3520] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 008E4946
.text C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3536] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 008A4831
.text C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3536] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 008A4A44
.text C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3536] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 008A4B61
.text C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3536] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 008A4946
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[3600] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00894831
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[3600] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 00894A44
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[3600] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00894B61
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[3600] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00894946
.text C:\Program Files\Outlook Express\msimn.exe[3604] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 007B4831
.text C:\Program Files\Outlook Express\msimn.exe[3604] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 007B4A44
.text C:\Program Files\Outlook Express\msimn.exe[3604] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 007B4B61
.text C:\Program Files\Outlook Express\msimn.exe[3604] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 007B4946
.text C:\WINDOWS\system32\ctfmon.exe[3632] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 008E4831
.text C:\WINDOWS\system32\ctfmon.exe[3632] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 008E4A44
.text C:\WINDOWS\system32\ctfmon.exe[3632] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 008E4B61
.text C:\WINDOWS\system32\ctfmon.exe[3632] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 008E4946
.text C:\WINDOWS\system32\RAMASST.exe[3708] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 008C4831
.text C:\WINDOWS\system32\RAMASST.exe[3708] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 008C4A44
.text C:\WINDOWS\system32\RAMASST.exe[3708] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 008C4B61
.text C:\WINDOWS\system32\RAMASST.exe[3708] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 008C4946

---- Devices - GMER 1.0.12 ----

Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 823C11D8
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_CREATE 8167F980
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_CLOSE 8167F980
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_READ 8167F980
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_WRITE 8167F980
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_QUERY_INFORMATION 8167F980
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_SET_INFORMATION 8167F980
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_QUERY_VOLUME_INFORMATION 8167F980
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_DIRECTORY_CONTROL 8167F980
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_FILE_SYSTEM_CONTROL [F29929BA] tfsnifs.sys
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_DEVICE_CONTROL 8167F980
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_LOCK_CONTROL 8167F980
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_CLEANUP 8167F980
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_PNP 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_CREATE 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_CLOSE 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_READ 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_WRITE 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_QUERY_INFORMATION 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_SET_INFORMATION 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_QUERY_VOLUME_INFORMATION 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_DIRECTORY_CONTROL 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_FILE_SYSTEM_CONTROL [F29929BA] tfsnifs.sys
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_DEVICE_CONTROL 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_LOCK_CONTROL 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_CLEANUP 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_PNP 8167F980
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CREATE 8217A1D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CLOSE 8217A1D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_DEVICE_CONTROL 8217A1D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL
  • 0

#33
bobletman

bobletman

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 143 posts
ok some of it got cut of im gonna try and post it in 3 different areas.
  • 0

#34
bobletman

bobletman

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 143 posts
GMER 1.0.12.12011 - http://www.gmer.net
Rootkit scan 2006-11-30 17:37:25
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.12 ----
SSDT sptd.sys ZwCreateKey
SSDT sptd.sys ZwEnumerateKey
SSDT sptd.sys ZwEnumerateValueKey
SSDT sptd.sys ZwOpenKey
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT sptd.sys ZwQueryKey
SSDT sptd.sys ZwQueryValueKey
SSDT sptd.sys ZwSetValueKey
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess

---- Kernel code sections - GMER 1.0.12 ----

.text USBPORT.SYS!DllUnload F760B62C 5 Bytes JMP 821AA748

---- User code sections - GMER 1.0.12 ----

.text C:\WINDOWS\system32\winlogon.exe[604] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00C84831
.text C:\WINDOWS\system32\winlogon.exe[604] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 00C84A44
.text C:\WINDOWS\system32\winlogon.exe[604] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00C84B61
.text C:\WINDOWS\system32\winlogon.exe[604] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00C84946
.text C:\WINDOWS\explorer.exe[2796] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00B44831
.text C:\WINDOWS\explorer.exe[2796] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 00B44A44
.text C:\WINDOWS\explorer.exe[2796] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00B44B61
.text C:\WINDOWS\explorer.exe[2796] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00B44946
.text C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[2984] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00B84831
.text C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[2984] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 00B84A44
.text C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[2984] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00B84B61
.text C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe[2984] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00B84946
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[3004] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00884831
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[3004] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 00884A44
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[3004] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00884B61
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[3004] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00884946
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3016] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00954831
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3016] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 00954A44
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3016] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00954B61
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[3016] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00954946
.text C:\WINDOWS\agrsmmsg.exe[3024] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00934831
.text C:\WINDOWS\agrsmmsg.exe[3024] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 00934A44
.text C:\WINDOWS\agrsmmsg.exe[3024] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00934B61
.text C:\WINDOWS\agrsmmsg.exe[3024] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00934946
.text C:\Program Files\TOSHIBA\Tvs\TvsTray.exe[3036] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 008B4831
.text C:\Program Files\TOSHIBA\Tvs\TvsTray.exe[3036] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 008B4A44
.text C:\Program Files\TOSHIBA\Tvs\TvsTray.exe[3036] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 008B4B61
.text C:\Program Files\TOSHIBA\Tvs\TvsTray.exe[3036] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 008B4946
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[3044] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 008C4831
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[3044] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 008C4A44
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[3044] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 008C4B61
.text C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe[3044] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 008C4946
.text C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe[3100] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 009B4831
.text C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe[3100] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 009B4A44
.text C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe[3100] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 009B4B61
.text C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe[3100] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 009B4946
.text C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe[3172] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00D14831
.text C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe[3172] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 00D14A44
.text C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe[3172] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00D14B61
.text C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe[3172] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00D14946
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[3184] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00954831
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[3184] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 00954A44
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[3184] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00954B61
.text C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe[3184] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00954946
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[3228] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 008C4831
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[3228] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 008C4A44
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[3228] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 008C4B61
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[3228] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 008C4946
.text C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe[3368] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 01144831
.text C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe[3368] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 01144A44
.text C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe[3368] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 01144B61
.text C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe[3368] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 01144946
.text C:\Program Files\Common Files\Logitech\QCDriver3\LVComS.exe[3384] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00934831
.text C:\Program Files\Common Files\Logitech\QCDriver3\LVComS.exe[3384] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 00934A44
.text C:\Program Files\Common Files\Logitech\QCDriver3\LVComS.exe[3384] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00934B61
.text C:\Program Files\Common Files\Logitech\QCDriver3\LVComS.exe[3384] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00934946
.text C:\Program Files\QuickTime\qttask.exe[3424] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 008D4831
.text C:\Program Files\QuickTime\qttask.exe[3424] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 008D4A44
.text C:\Program Files\QuickTime\qttask.exe[3424] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 008D4B61
.text C:\Program Files\QuickTime\qttask.exe[3424] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 008D4946
.text C:\Program Files\iTunes\iTunesHelper.exe[3452] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 003D4831
.text C:\Program Files\iTunes\iTunesHelper.exe[3452] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 003D4A44
.text C:\Program Files\iTunes\iTunesHelper.exe[3452] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 003D4B61
.text C:\Program Files\iTunes\iTunesHelper.exe[3452] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 003D4946
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[3468] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00F44831
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[3468] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 00F44A44
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[3468] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00F44B61
.text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[3468] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00F44946
.text C:\Program Files\PowerISO\PWRISOVM.EXE[3520] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 008E4831
.text C:\Program Files\PowerISO\PWRISOVM.EXE[3520] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 008E4A44
.text C:\Program Files\PowerISO\PWRISOVM.EXE[3520] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 008E4B61
.text C:\Program Files\PowerISO\PWRISOVM.EXE[3520] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 008E4946
.text C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3536] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 008A4831
.text C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3536] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 008A4A44
.text C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3536] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 008A4B61
.text C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe[3536] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 008A4946
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[3600] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 00894831
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[3600] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 00894A44
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[3600] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 00894B61
.text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[3600] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 00894946
.text C:\Program Files\Outlook Express\msimn.exe[3604] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 007B4831
.text C:\Program Files\Outlook Express\msimn.exe[3604] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 007B4A44
.text C:\Program Files\Outlook Express\msimn.exe[3604] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 007B4B61
.text C:\Program Files\Outlook Express\msimn.exe[3604] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 007B4946
.text C:\WINDOWS\system32\ctfmon.exe[3632] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 008E4831
.text C:\WINDOWS\system32\ctfmon.exe[3632] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 008E4A44
.text C:\WINDOWS\system32\ctfmon.exe[3632] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 008E4B61
.text C:\WINDOWS\system32\ctfmon.exe[3632] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 008E4946
.text C:\WINDOWS\system32\RAMASST.exe[3708] ntdll.dll!NtCreateThread 7C90D7D2 5 Bytes JMP 008C4831
.text C:\WINDOWS\system32\RAMASST.exe[3708] ntdll.dll!NtDeleteValueKey 7C90D8CE 5 Bytes JMP 008C4A44
.text C:\WINDOWS\system32\RAMASST.exe[3708] ntdll.dll!NtQueryDirectoryFile 7C90DF5E 5 Bytes JMP 008C4B61
.text C:\WINDOWS\system32\RAMASST.exe[3708] ntdll.dll!NtSetValueKey 7C90E7BC 5 Bytes JMP 008C4946

---- Devices - GMER 1.0.12 ----

Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 823C11D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 823C11D8
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_CREATE 8167F980
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_CLOSE 8167F980
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_READ 8167F980
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_WRITE 8167F980
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_QUERY_INFORMATION 8167F980
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_SET_INFORMATION 8167F980
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_QUERY_VOLUME_INFORMATION 8167F980
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_DIRECTORY_CONTROL 8167F980
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_FILE_SYSTEM_CONTROL [F29929BA] tfsnifs.sys
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_DEVICE_CONTROL 8167F980
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_LOCK_CONTROL 8167F980
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_CLEANUP 8167F980
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_PNP 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_CREATE 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_CLOSE 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_READ 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_WRITE 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_QUERY_INFORMATION 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_SET_INFORMATION 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_QUERY_VOLUME_INFORMATION 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_DIRECTORY_CONTROL 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_FILE_SYSTEM_CONTROL [F29929BA] tfsnifs.sys
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_DEVICE_CONTROL 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_LOCK_CONTROL 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_CLEANUP 8167F980
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_PNP 8167F980
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CREATE 8217A1D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_CLOSE 8217A1D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_DEVICE_CONTROL 8217A1D8
Device \Driver\usbuhci \Device\USBPDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL
  • 0

#35
bobletman

bobletman

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 143 posts
here is the rest of root kit

Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_POWER 8217A1D8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_SYSTEM_CONTROL 8217A1D8
Device \Driver\usbuhci \Device\USBFDO-0 IRP_MJ_PNP 8217A1D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_CREATE 8217A1D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_CLOSE 8217A1D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_DEVICE_CONTROL 8217A1D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8217A1D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_POWER 8217A1D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_SYSTEM_CONTROL 8217A1D8
Device \Driver\usbuhci \Device\USBFDO-1 IRP_MJ_PNP 8217A1D8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSE 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FILE_SYSTEM_CONTROL 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CONTROL 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_INTERNAL_DEVICE_CONTROL 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SHUTDOWN 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_LOCK_CONTROL 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLEANUP 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_MAILSLOT 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_SECURITY 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_SECURITY 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_POWER 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SYSTEM_CONTROL 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CHANGE 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_QUOTA 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_QUOTA 8167E980
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP 8167E980
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_CREATE 8217A1D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_CLOSE 8217A1D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_DEVICE_CONTROL 8217A1D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 8217A1D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_POWER 8217A1D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_SYSTEM_CONTROL 8217A1D8
Device \Driver\usbuhci \Device\USBFDO-2 IRP_MJ_PNP 8217A1D8
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLOSE 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_WRITE 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_INFORMATION 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_EA 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_EA 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SHUTDOWN 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLEANUP 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_SECURITY 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_POWER 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_QUOTA 8167E980
Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP 8167E980
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_CREATE 8217A1D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_CLOSE 8217A1D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_DEVICE_CONTROL 8217A1D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 8217A1D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_POWER 8217A1D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_SYSTEM_CONTROL 8217A1D8
Device \Driver\usbuhci \Device\USBFDO-3 IRP_MJ_PNP 8217A1D8
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_CREATE 821737C0
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_CLOSE 821737C0
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_DEVICE_CONTROL 821737C0
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_INTERNAL_DEVICE_CONTROL 821737C0
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_POWER 821737C0
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_SYSTEM_CONTROL 821737C0
Device \Driver\usbehci \Device\USBFDO-4 IRP_MJ_PNP 821737C0
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CREATE 823531D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_READ 823531D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_WRITE 823531D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_FLUSH_BUFFERS 823531D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_DEVICE_CONTROL 823531D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_INTERNAL_DEVICE_CONTROL 823531D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SHUTDOWN 823531D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CLEANUP 823531D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_POWER 823531D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SYSTEM_CONTROL 823531D8
Device \Driver\Ftdisk \Device\FtControl IRP_MJ_PNP 823531D8
Device \Driver\a78lfkzl \Device\Scsi\a78lfkzl1Port2Path0Target0Lun0 IRP_MJ_CREATE 820DD980
Device \Driver\a78lfkzl \Device\Scsi\a78lfkzl1Port2Path0Target0Lun0 IRP_MJ_CLOSE 820DD980
Device \Driver\a78lfkzl \Device\Scsi\a78lfkzl1Port2Path0Target0Lun0 IRP_MJ_DEVICE_CONTROL 820DD980
Device \Driver\a78lfkzl \Device\Scsi\a78lfkzl1Port2Path0Target0Lun0 IRP_MJ_INTERNAL_DEVICE_CONTROL 820DD980
Device \Driver\a78lfkzl \Device\Scsi\a78lfkzl1Port2Path0Target0Lun0 IRP_MJ_POWER 820DD980
Device \Driver\a78lfkzl \Device\Scsi\a78lfkzl1Port2Path0Target0Lun0 IRP_MJ_SYSTEM_CONTROL 820DD980
Device \Driver\a78lfkzl \Device\Scsi\a78lfkzl1Port2Path0Target0Lun0 IRP_MJ_PNP 820DD980
Device \Driver\a78lfkzl \Device\Scsi\a78lfkzl1 IRP_MJ_CREATE 820DD980
Device \Driver\a78lfkzl \Device\Scsi\a78lfkzl1 IRP_MJ_CLOSE 820DD980
Device \Driver\a78lfkzl \Device\Scsi\a78lfkzl1 IRP_MJ_DEVICE_CONTROL 820DD980
Device \Driver\a78lfkzl \Device\Scsi\a78lfkzl1 IRP_MJ_INTERNAL_DEVICE_CONTROL 820DD980
Device \Driver\a78lfkzl \Device\Scsi\a78lfkzl1 IRP_MJ_POWER 820DD980
Device \Driver\a78lfkzl \Device\Scsi\a78lfkzl1 IRP_MJ_SYSTEM_CONTROL 820DD980
Device \Driver\a78lfkzl \Device\Scsi\a78lfkzl1 IRP_MJ_PNP 820DD980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE 81EFF980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLOSE 81EFF980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ 81EFF980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_INFORMATION 81EFF980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_SET_INFORMATION 81EFF980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_VOLUME_INFORMATION 81EFF980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_DIRECTORY_CONTROL 81EFF980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL 81EFF980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_DEVICE_CONTROL 81EFF980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_SHUTDOWN 81EFF980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_LOCK_CONTROL 81EFF980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLEANUP 81EFF980
Device \FileSystem\Cdfs \Cdfs IRP_MJ_PNP 81EFF980

---- Files - GMER 1.0.12 ----

ADS C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
ADS C:\Documents and Settings\TEMP\Local Settings\Application Data\Microsoft\Messenger\[email protected]\SharingMetadata\[email protected]\DfsrPrivate\Staging\CS{5C216FAD-664F-7C4D-4BC5-6A081DE8A3E7}\01\10-{5C216FAD-664F-7C4D-4BC5-6A081DE8A3E7}-v1-{5A57FDA6-2738-4879-9719-DC33EE9EFC5F}-v10-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS

---- EOF - GMER 1.0.12 ----
  • 0

#36
bobletman

bobletman

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 143 posts
GMER 1.0.12.12011 - http://www.gmer.net
Autostart scan 2006-11-30 17:38:03
Windows 5.1.2600 Service Pack 2


HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon >>>
@UserinitC:\WINDOWS\system32\userinit.exe, = C:\WINDOWS\system32\userinit.exe,
@Systemkdbhp.exe = kdbhp.exe
@UIHostC:\Documents and Settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe = C:\Documents and Settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon@DLLName = WgaLogon.dll

HKLM\SYSTEM\CurrentControlSet\Services\ >>>
aswUpdSv /*avast! iAVS4 Control Service*/@ = "C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"
avast! Antivirus /*avast! Antivirus*/@ = "C:\Program Files\Alwil Software\Avast4\ashServ.exe"
AVG Anti-Spyware Guard /*AVG Anti-Spyware Guard*/@ = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
CFSvcs /*ConfigFree Service*/@ = C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
DVD-RAM_Service /*DVD-RAM_Service*/@ = C:\WINDOWS\system32\DVDRAMSV.exe
NVSvc /*NVIDIA Display Driver Service*/@ = %SystemRoot%\system32\nvsvc32.exe
SoundMAX Agent Service (default) /*SoundMAX Agent Service*/@ = C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
Spooler /*Print Spooler*/@ = %SystemRoot%\system32\spoolsv.exe
TAPPSRV /*TOSHIBA Application Service*/@ = "C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe"

HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@SoundMAXPnPC:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe = C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
@SoundMAXC:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray /*file not found*/ = C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray /*file not found*/
@SynTPLprC:\Program Files\Synaptics\SynTP\SynTPLpr.exe = C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
@SynTPEnhC:\Program Files\Synaptics\SynTP\SynTPEnh.exe = C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
@AGRSMMSGAGRSMMSG.exe = AGRSMMSG.exe
@TvsC:\Program Files\Toshiba\Tvs\TvsTray.exe = C:\Program Files\Toshiba\Tvs\TvsTray.exe
@SmoothViewC:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe = C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
@PadTouchC:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe = C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
@THotkeyC:\Program Files\Toshiba\Toshiba Applet\thotkey.exe = C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
@TFncKyTFncKy.exe /*file not found*/ = TFncKy.exe /*file not found*/
@nwiznwiz.exe /install = nwiz.exe /install
@TPSMainTPSMain.exe = TPSMain.exe
@avast!C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe = C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
@CFSServ.exeCFSServ.exe -NoClient /*file not found*/ = CFSServ.exe -NoClient /*file not found*/
@LVCOMSC:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE = C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
@NvCplDaemonRUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
@SunJavaUpdateSched"C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe" = "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
@QuickTime Task"C:\Program Files\QuickTime\qttask.exe" -atboottime = "C:\Program Files\QuickTime\qttask.exe" -atboottime
@iTunesHelper"C:\Program Files\iTunes\iTunesHelper.exe" = "C:\Program Files\iTunes\iTunesHelper.exe"
@SpyHunter /*file not found*/ = /*file not found*/
@!AVG Anti-Spyware"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
@PWRISOVM.EXEC:\Program Files\PowerISO\PWRISOVM.EXE = C:\Program Files\PowerISO\PWRISOVM.EXE

HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@TOSCDSPDC:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe = C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
@ctfmon.exeC:\WINDOWS\system32\ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad@UPnPMonitor = C:\WINDOWS\system32\upnpui.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks@{57B86673-276A-48B2-BAE7-C6DBB3020EB8} = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Display Panning CPL Extension*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Previous Versions Property Page*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Previous Versions*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{30D02401-6A81-11d0-8274-00C04FD5AE38} /*IE Search Band*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} /*Shell DocObject Viewer*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FBF23B40-E3F0-101B-8488-00AA003E56F8} /*InternetShortcut*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3C374A40-BAE4-11CF-BF7D-00AA006946EE} /*Microsoft Url History Service*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FF393560-C2A7-11CF-BFF4-444553540000} /*History*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{7BD29E00-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{7BD29E01-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{CFBFAE00-17A6-11D0-99CB-00C04FD64497} /*Microsoft Url Search Hook*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3DC7A020-0ACD-11CF-A9BB-00AA004AE837} /*The Internet*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{871C5380-42A0-1069-A2EA-08002B30309D} /*Internet Name Space*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/C:\WINDOWS\system32\extmgr.dll = C:\WINDOWS\system32\extmgr.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Web Folders*/C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Program Files\Microsoft Office\OFFICE11\msohev.dll = C:\Program Files\Microsoft Office\OFFICE11\msohev.dll
@{2F603045-309F-11CF-9774-0020AFD0CFF6} /*Synaptics Control Panel*/C:\Program Files\Synaptics\SynTP\SynTPCpl.dll = C:\Program Files\Synaptics\SynTP\SynTPCpl.dll
@{DEE12703-6333-4D4E-8F34-738C4DCC2E04} /*RecordNow! SendToExt*/C:\Program Files\Sonic\RecordNow!\shlext.dll = C:\Program Files\Sonic\RecordNow!\shlext.dll
@{5CA3D70E-1895-11CF-8E15-001234567890} /*DriveLetterAccess*/(null) =
@{A70C977A-BF00-412C-90B7-034C51DA2439} /*NvCpl DesktopContext Class*/C:\WINDOWS\system32\nvcpl.dll = C:\WINDOWS\system32\nvcpl.dll
@{FFB699E0-306A-11d3-8BD1-00104B6F7516} /*Play on my TV helper*/C:\WINDOWS\system32\nvcpl.dll = C:\WINDOWS\system32\nvcpl.dll
@{1CDB2949-8F65-4355-8456-263E7C208A5D} /*Desktop Explorer*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{1E9B04FB-F9E5-4718-997B-B8DA88302A47} /*Desktop Explorer Menu*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{1E9B04FB-F9E5-4718-997B-B8DA88302A48} /*nView Desktop Context Menu*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{472083B0-C522-11CF-8763-00608CC02F24} /*avast*/C:\Program Files\Alwil Software\Avast4\ashShell.dll = C:\Program Files\Alwil Software\Avast4\ashShell.dll
@{e57ce731-33e8-4c51-8354-bb4de9d215d1} /*Universal Plug and Play Devices*/C:\WINDOWS\system32\upnpui.dll = C:\WINDOWS\system32\upnpui.dll
@{EBDF1F20-C829-11D1-8233-FF20AF3E97A9} /*TrojanHunter Menu Shell Extension*/C:\PROGRA~1\TROJAN~1.6\contmenu.dll = C:\PROGRA~1\TROJAN~1.6\contmenu.dll
@{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} /*Shell Extensions for RealOne Player*/C:\Program Files\Real\RealPlayer\rpshell.dll = C:\Program Files\Real\RealPlayer\rpshell.dll
@{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} /*Messenger Sharing Folders*/C:\Program Files\MSN Messenger\fsshext.8.0.0812.00.dll = C:\Program Files\MSN Messenger\fsshext.8.0.0812.00.dll
@{35786D3C-B075-49b9-88DD-029876E11C01} /*Portable Devices*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8} /*Portable Devices Menu*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/C:\Program Files\WinRAR\rarext.dll = C:\Program Files\WinRAR\rarext.dll
@{44440D00-FF19-4AFC-B765-9A0970567D97} /*TuneUp Theme Extension*/%SystemRoot%\system32\uxtuneup.dll = %SystemRoot%\system32\uxtuneup.dll
@{4858E7D9-8E12-45a3-B6A3-1CD128C9D403} /*TuneUp Shredder Shell Extension*/C:\PROGRA~1\TUNEUP~1\SDShelEx-win32.dll = C:\PROGRA~1\TUNEUP~1\SDShelEx-win32.dll
@{07C45BB1-4A8C-4642-A1F5-237E7215FF66} /*IE Microsoft BrowserBand*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{1C1EDB47-CE22-4bbb-B608-77B48F83C823} /*IE Fade Task*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{205D7A97-F16D-4691-86EF-F3075DCCA57D} /*IE Menu Desk Bar*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3028902F-6374-48b2-8DC6-9725E775B926} /*IE AutoComplete*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{43886CD5-6529-41c4-A707-7B3C92C05E68} /*IE Navigation Bar*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{44C76ECD-F7FA-411c-9929-1B77BA77F524} /*IE Menu Site*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{4B78D326-D922-44f9-AF2A-07805C2A3560} /*IE Menu Band*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6038EF75-ABFC-4e59-AB6F-12D397F6568D} /*IE Microsoft History AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE} /*IE Tracking Shell Menu*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6CF48EF8-44CD-45d2-8832-A16EA016311B} /*IE IShellFolderBand*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{73CFD649-CD48-4fd8-A272-2070EA56526B} /*IE BandProxy*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8} /*IE MRU AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E} /*IE RSS Feeder Folder*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{9D958C62-3954-4b44-8FAB-C4670C1DB4C2} /*IE Microsoft Shell Folder AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{B31C5FAE-961F-415b-BAF0-E697A5178B94} /*IE Microsoft Multiple AutoComplete List Container*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{BC476F4C-D9D7-4100-8D4E-E043F6DEC409} /*Microsoft Browser Architecture*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A} /*IE Shell Rebar BandSite*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{E6EE9AAC-F76B-4947-8260-A9F136138E11} /*IE Shell Band Site Menu*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{F2CF5485-4E02-4f68-819C-B92DE9277049} /*&Links*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E} /*IE Registry Tree Options Utility*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} /*IE User Assist*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FDE7673D-2E19-4145-8376-BBD58C4BC7BA} /*IE Custom MRU AutoCompleted List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} /*iTunes*/C:\Program Files\iTunes\iTunesMiniPlayer.dll = C:\Program Files\iTunes\iTunesMiniPlayer.dll
@{967B2D40-8B7D-4127-9049-61EA0C2C6DCE} /*PowerISO*/C:\Program Files\PowerISO\PWRISOSH.DLL = C:\Program Files\PowerISO\PWRISOSH.DLL

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
avast@{472083B0-C522-11CF-8763-00608CC02F24} = C:\Program Files\Alwil Software\Avast4\ashShell.dll
AVG Anti-Spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll
PowerISO@{967B2D40-8B7D-4127-9049-61EA0C2C6DCE} = C:\Program Files\PowerISO\PWRISOSH.DLL
tosAACFShlExt@{5a900bf8-09f0-4d1d-bb42-47617ee2eedc} = C:\Program Files\TOSHIBA\ConfigFree\CFShlExt.dll
TrojanHunter@{EBDF1F20-C829-11D1-8233-FF20AF3E97A9} = C:\PROGRA~1\TROJAN~1.6\contmenu.dll
TuneUp Shredder Shell Extension@{4858E7D9-8E12-45a3-B6A3-1CD128C9D403} = C:\PROGRA~1\TUNEUP~1\SDShelEx-win32.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll

HKLM\Software\Classes\*\shellex\ContextMenuHandlers@{EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208} = C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
AVG Anti-Spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll
PowerISO@{967B2D40-8B7D-4127-9049-61EA0C2C6DCE} = C:\Program Files\PowerISO\PWRISOSH.DLL
tosAACFShlExt@{5a900bf8-09f0-4d1d-bb42-47617ee2eedc} = C:\Program Files\TOSHIBA\ConfigFree\CFShlExt.dll
TrojanHunter@{EBDF1F20-C829-11D1-8233-FF20AF3E97A9} = C:\PROGRA~1\TROJAN~1.6\contmenu.dll
TuneUp Shredder Shell Extension@{4858E7D9-8E12-45a3-B6A3-1CD128C9D403} = C:\PROGRA~1\TUNEUP~1\SDShelEx-win32.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
avast@{472083B0-C522-11CF-8763-00608CC02F24} = C:\Program Files\Alwil Software\Avast4\ashShell.dll
PowerISO@{967B2D40-8B7D-4127-9049-61EA0C2C6DCE} = C:\Program Files\PowerISO\PWRISOSH.DLL
TrojanHunter@{EBDF1F20-C829-11D1-8233-FF20AF3E97A9} = C:\PROGRA~1\TROJAN~1.6\contmenu.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers@{EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208} = C:\Program Files\Nero\Nero 7\Nero BackItUp\NBShell.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll = C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
@{A491D208-B353-490F-B81A-A8A3DC97042D}C:\WINDOWS\system32\smiehlp.dll = C:\WINDOWS\system32\smiehlp.dll

HKCU\Control Panel\[email protected] = C:\WINDOWS\system32\logon.scr

HKLM\Software\Microsoft\Internet Explorer\Plugins\Extension\.spop@Location = C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://go.microsoft.com/fwlink/?LinkId=69157 = http://go.microsoft....k/?LinkId=69157
@Start Pagehttp://go.microsoft.com/fwlink/?LinkId=69157 = http://go.microsoft....k/?LinkId=69157
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm

HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome = http://www.microsoft...p...&ar=msnhome
@Local PageC:\windows\system32\blank.htm = C:\windows\system32\blank.htm

HKLM\Software\Classes\PROTOCOLS\Filter\text/xml@CLSID = C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL

HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
its@CLSID = C:\WINDOWS\system32\itss.dll
livecall@CLSID = C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
mhtml@CLSID = %SystemRoot%\system32\inetcomm.dll
ms-its@CLSID = C:\WINDOWS\system32\itss.dll
ms-itss@CLSID = C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL
msnim@CLSID = C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
mso-offdap11@CLSID = C:\PROGRA~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll

HKLM\Software\Classes\PROTOCOLS\Handler\wia@CLSID = C:\WINDOWS\system32\wiascr.dll

C:\Documents and Settings\All Users\Start Menu\Programs\Startup = RAMASST.lnk

---- EOF - GMER 1.0.12 ----
  • 0

#37
bobletman

bobletman

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 143 posts
Incident Status Location

Potentially unwanted tool:application/zango Not disinfected HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{99410cde-6f16-42ce-9d49-3807f78f0287}
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Nada\Application Data\Mozilla\Firefox\Profiles\fw27u3gs.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Nada\Application Data\Mozilla\Firefox\Profiles\fw27u3gs.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Nada\Application Data\Mozilla\Firefox\Profiles\fw27u3gs.default\cookies.txt[.overture.com/]
Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\Nada\Application Data\Mozilla\Firefox\Profiles\fw27u3gs.default\cookies.txt[.clickbank.net/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Nada\Application Data\Mozilla\Firefox\Profiles\fw27u3gs.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Nada\Application Data\Mozilla\Firefox\Profiles\fw27u3gs.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Nada\Application Data\Mozilla\Firefox\Profiles\fw27u3gs.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Nada\Application Data\Mozilla\Firefox\Profiles\fw27u3gs.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt[.com.com/]
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt[.cs.sexcounter.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt[.toplist.cz/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt[.club.cdfreaks.com/]
Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt[.cdfreaks.com/]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt[.revenue.net/]
Spyware:Cookie/Entrepreneur Not disinfected C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt[.entrepreneur.com/]
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt[.yadro.ru/]
Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt[stat.onestat.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Casinotropez Not disinfected C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt[.casinotropez.com/]
Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt[.i.screensavers.com/]
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt[www.burstbeacon.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt[.apmebf.com/]
Adware:Adware/Look2Me Not disinfected C:\Documents and Settings\TEMP\Desktop\Help is on the way\Kill2me\Kill2Me.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\TEMP\Desktop\Help is on the way\SmitfraudFix\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\TEMP\Desktop\Help is on the way\smitRem\Process.exe
Potentially unwanted tool:Application/Zango Not disinfected C:\Program Files\Mozilla Firefox\plugins\npclntax.dll
Potentially unwanted tool:Application/Processor Not disinfected C:\RECYCLER\S-1-5-21-1152713964-3414026295-223834222-1006\Dc29\SmitfraudFix\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\RECYCLER\S-1-5-21-1152713964-3414026295-223834222-1006\Dc5.zip[SmitfraudFix/Process.exe]
Possible Virus. Not disinfected C:\sUBs\TSF\swreg.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe
  • 0

#38
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.

Preparation

1) Download the trial version of AVG Anti-Spyware from here and save it to your Desktop.

If you already have this program installed, skip to Updating AVG Anti-Spyware: below.

Double click the avgas-setup file to begin installation and follow the prompts.
When the program has been installed, and you click the Finish button, AVG A-S will open.

* Please note that this program was formerly known as Ewido anti-spyware 4.0.
Taken from the Ewido website -

ewido anti-spyware 4.0 will now continue under the new product name AVG Anti-Spyware 7.5. AVG Anti-Spyware 7.5 contains the same ewido technology, but with some further enhanced features:

Highly improved cleaning
Lower resource usage
Additional languages supported

All current licenses for ewido anti-spyware 4.0 will continue to be valid, and users can change over to the new AVG Anti-Spyware 7.5 for free.

  • Updating AVG Anti-Spyware:

    By default AVG A-S is configured to update automatically so, if you have an active internet connection, it should do so following installation. If you are unsure whether or not it has done so, do the following:
  • Click the Update icon at the top and under "Manual Update" - click the Start update button.
  • Either AVG A-S will update or inform you that no update was available.
  • If you cannot access the internet with the infected PC, or you are having problems updating, you can download the signatures file from here.
    Once you have installed AVG A-S, double click avgas-signatures-current.exe to update it.

    Disabling the Resident Shield:
  • By default the Resident Shield is active but as it may interfere with the process of cleaning your PC, it will need to be disabled.
    (When the PC has been cleaned you can activate the shield again, if you wish.)
  • Click the Shield icon at the top and under "Resident shield is..." - click active.
  • This should now change to inactive.

    Changing Recommended Actions
  • Click the Scanner icon at the top and then click the Settings Tab.
  • Under "How to act?" click Recommended actions and select "Quarantine" from the menu.
You can now close AVG A-S.

AVG A-S is designed to be used to both scan for and remove malicious files and also to run in real-time alongside, but not replace, your existing anti-virus program to give an added layer of protection.
Both the Resident Shield and Automatic Updates will only be available for the thirty day trial period, after that AVG A-S will revert to a stand-alone scanner which you can keep and manually update for free and use in a similar way to Ad-Aware SE Personal, Spybot S&D etc.
Should you wish to benefit from the real-time protection, you will need to upgrade the program. To do this, simply open it and click on the Buy now button.


2) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "4" and then <ENTER> to check for updates.
Don't forget to allow SmiUpdate.exe access through your firewall.
Once it has updated, or if there are no updates available, close the window and the folder.

3) You will need to know how to boot into Safe Mode.
Instructions can be found here.

4) You will need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **

5) Log off from the internet and disconnect your modem cable for the duration of the fix.

Removal

1) Boot into Safe Mode.

2) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "2" and then <ENTER> to start the cleaning process.
  • Wait for the tool to complete and disk cleanup to finish.
  • You will be prompted "Registry cleaning - Do you want to clean the registry ? Press "Y" and then <ENTER>.
  • The tool will also check if wininet.dll is infected. You may be prompted to "Replace infected file ?" - press "Y" and then <ENTER>.
Your PC now needs to be rebooted - if this does not happen automatically, you will need to do so manually. Either way, your PC will need to be booted back INTO SAFE MODE.

3) Navigate to the C:\Windows\Temp folder and delete all the files that you find there.
Do this for all Usernames.

4) Navigate to C:\Documents and Settings\Username\Local Settings\Temp and delete all the files that you find there.
Do this for all Usernames.

5) Go to Start > Control Panel > Internet Options and under Temporary Internet files, click on Delete Files...
Check the box to the left of 'Delete all offline content' and then click on OK.

6) Go to Start > Control Panel > Display.
Select the Desktop Tab, click on Customise Desktop... and then select the Web Tab.
Under Web pages: you may see a checked entry called Security info - or similar. Highlight this entry and then click the Delete button.
Finally click OK > Apply > OK.

7) Empty the Recycle Bin.

8) Ensure that ALL open Windows / Programs / Folders are closed and then run AVG A-S.
  • If it is not already selected, click the Scanner icon at the top and then select the Scan Tab.
  • Click "Complete System Scan"
  • While the scan is in progress the PC should be left otherwise idle - so if you fancy a cuppa, now's the time to put the kettle on!
  • When the scan has completed, any threats that AVG A-S has detected will be displayed.
  • Click the Apply all actions button at the bottom.
  • When AVG A-S has finished, it will display the message "All actions have been applied".

    Saving a report:
  • Click the Save Report button at the bottom left and the "Reports" window will open.
  • The content of the scan report will be displayed in the right hand pane and a copy will be automatically saved as Report-Scan-date-time.txt into the C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports folder.
  • You will need to post a copy of this report into your next reply, so if it is more convenient, you can save another copy of this report elsewhere:
    Click the Save report as button and select a destination by clicking the down arrow to the right of the Save in: text box and then click Save.
Close AVG A-S.

9) Reboot into Normal Mode.

10) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "3" and then <ENTER> to "Delete Trusted Zone".
When prompted "Restore Trusted Zone ?", press "Y" and then <ENTER>.

* Please Note: If you use SpywareBlaster and/or IE/Spyads, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE/Spyads, run the batch file and reinstall the protection *

Will you then post the following:
  • A new HJT log,
  • The AVG A-S log,
  • The text file rapport.txt that will be found in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.
    For most, this file can be found by double-clicking My Computer and then Local Disk (C:)
  • A description of how your PC is behaving.
This fix is based on a canned speech supplied by Kimberly.
  • 0

#39
bobletman

bobletman

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 143 posts
Here is a hijack this log

Logfile of HijackThis v1.99.1
Scan saved at 5:15:09 PM, on 03/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\WINDOWS\system32\TPSMain.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\TOSHIBA\ConfigFree\CFXFER.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\TEMP\Desktop\HijackThis.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: IeHelper Class - {A491D208-B353-490F-B81A-A8A3DC97042D} - C:\WINDOWS\system32\smiehlp.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
  • 0

#40
bobletman

bobletman

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 143 posts
This is the avg scan

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 3:45:19 PM 03/12/2006

+ Scan result:



C:\Program Files\MySpyProtector -> Adware.MySpyProtector : Cleaned with backup (quarantined).
C:\Program Files\MySpyProtector\Spyware Remover.ini -> Adware.MySpyProtector : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{9F6D27BD-8333-4C91-A655-AFB30354E2FB}\RP420\A0360388.exe -> Backdoor.Theef.111 : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{9F6D27BD-8333-4C91-A655-AFB30354E2FB}\RP379\A0305632.exe -> Dialer.CapreDeam.p : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{9F6D27BD-8333-4C91-A655-AFB30354E2FB}\RP420\A0360353.exe -> Downloader.Zlob.aty : Cleaned with backup (quarantined).
:mozilla.20:C:\Documents and Settings\Nada\Application Data\Mozilla\Firefox\Profiles\fw27u3gs.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.55:C:\Documents and Settings\Nada\Application Data\Mozilla\Firefox\Profiles\fw27u3gs.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.226:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.227:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.235:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.236:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.237:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.246:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.386:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.231:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.239:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.240:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.135:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.136:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.137:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.138:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.139:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.140:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.362:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned.
:mozilla.363:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned.
:mozilla.364:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned.
:mozilla.365:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned.
:mozilla.366:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned.
:mozilla.37:C:\Documents and Settings\Nada\Application Data\Mozilla\Firefox\Profiles\fw27u3gs.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned.
:mozilla.244:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned.
:mozilla.245:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned.
:mozilla.210:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.211:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.213:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.214:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.302:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.303:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.599:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.600:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.120:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.18:C:\Documents and Settings\Nada\Application Data\Mozilla\Firefox\Profiles\fw27u3gs.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.131:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.132:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.133:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.134:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.507:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.673:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.441:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Ivwbox : Cleaned.
:mozilla.40:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.333:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.334:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.335:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.336:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.337:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.30:C:\Documents and Settings\Nada\Application Data\Mozilla\Firefox\Profiles\fw27u3gs.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.31:C:\Documents and Settings\Nada\Application Data\Mozilla\Firefox\Profiles\fw27u3gs.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.481:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.482:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.483:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.484:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.485:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.318:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.45:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.46:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.47:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.48:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.49:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.50:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.51:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.52:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.53:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.54:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.55:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.56:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.57:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.58:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.59:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.60:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.61:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.62:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.63:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.64:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.65:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.66:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.67:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.68:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.69:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.70:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.71:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.72:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.73:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.74:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.75:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.76:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.77:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.78:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.79:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.80:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.81:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.82:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.83:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.84:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.85:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.86:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.10:C:\Documents and Settings\Nada\Application Data\Mozilla\Firefox\Profiles\fw27u3gs.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.7:C:\Documents and Settings\Nada\Application Data\Mozilla\Firefox\Profiles\fw27u3gs.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.9:C:\Documents and Settings\Nada\Application Data\Mozilla\Firefox\Profiles\fw27u3gs.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.187:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.188:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.189:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.190:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.192:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.193:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.39:C:\Documents and Settings\Nada\Application Data\Mozilla\Firefox\Profiles\fw27u3gs.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.40:C:\Documents and Settings\Nada\Application Data\Mozilla\Firefox\Profiles\fw27u3gs.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.228:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.229:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.230:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.35:C:\Documents and Settings\Nada\Application Data\Mozilla\Firefox\Profiles\fw27u3gs.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.36:C:\Documents and Settings\Nada\Application Data\Mozilla\Firefox\Profiles\fw27u3gs.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.328:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.349:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.350:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.351:C:\Documents and Settings\TEMP\Application Data\Mozilla\Firefox\Profiles\ke6ml5zp.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.


::Report end
  • 0

Advertisements


#41
bobletman

bobletman

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 143 posts
Here is the rapport file. My laptop is a bit slower at times. Sometimes when im using firefox and i try swithing between tabs it lags a bit or when i go to a different web page shockwave gives me an error says it performed a illegal action other then that its pretty good.


Scan done at 13:14:25.20, 03/12/2006
Run from C:\Documents and Settings\TEMP\Desktop\Help is on the way\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"="kdbhp.exe"

»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» Reboot

C:\WINDOWS\system32\kdbhp.exe Deleted

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» End
  • 0

#42
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
The following steps will serve as a spring clean for your PC. Not all of them will be of benefit to your PC as this is a general post, but the overall effect should be positive.

1) Go to Start > Control Panel > Add/Remove Programs and remove any programs that you no longer use and then reboot your PC.

2) Download ATF Cleaner by Atribune from here and save it to your Desktop.
Double click ATF-Cleaner.exe to run the program.
Check the boxes to the left of:Windows Temp
Current User Temp
All Users Temp
Temporary Internet Files
Java Cache

The rest are optional - if you want to remove the lot, check "Select All".
Finally click Empty Selected. When you get the "Done Cleaning" message, click OK.

If you use the Firefox or Opera browsers, you can use this program as a quick way to tidy those up as well.

When you have finished, click on the Exit button in the Main menu.

For Technical Support, double-click the e-mail address located at the bottom of each menu.

Please Note: This program is for Windows XP and Windows 2000 only.

3) Double click My Computer.
Right click the disc drive you wish to check.
Click Properties.
In the Properties dialog box, click the Tools Tab.
Under Error-checking, click the Check Now button.
In the "Check Disc Local Disk (C:)" dialog box, check both Automatically fix file system errors and Scan for and attempt recovery of bad sectors, and then click Start.

This will look for and attempt to repair any errors that your hard drive has.

4) Go to Start > Run, enter sfc /scannow ( note the space between the "c" and "/" ) and click on OK.

This will look for and attempt to replace any corrupt system files that can be found. There are backups of some of these files on your PC and Windows will check for a copy here first. If you are prompted to insert your Windows XP disc, do so. If you don't have this disc and are asked for it, you will have to cancel at this point.

For details on the System File Checker, click here.

5) Defragment your hard drive. A tutorial for disc defragmentation is available here.

6) Download and run StartUp Inspector.
This program will help you to decide exactly what programs you disable from running at startup.
The Readme.txt file included has instructions on how to use it.

Let me know how you get on.
  • 0

#43
bobletman

bobletman

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 143 posts
should i delete the quarantined viruses and if I should does it matter if I do it in safe mode.
  • 0

#44
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
If you mean the things that AVG A-S found, no. They don't pose a risk in Quarantine and I like to keep them around just in case it turns out that there have been false positive detections. This doesn't happen very often, but it does happen.
  • 0

#45
bobletman

bobletman

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 143 posts
should i do another scan using avg
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP