1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

C:\WINDOWS\system32\ntload.sys

Discussion in 'Malware and Virus Removal Archive' started by ragidy, 2008/03/09.

  1. 2008/03/09
    ragidy

    ragidy Inactive Thread Starter

    Joined:
    2008/03/08
    Messages:
    3
    Likes Received:
    0
    Every time I star my PC Avast shows this virus with a message saying a sample of Win32:NTRootKit-B has been found

    C:\WINDOWS\system32\ntload.sys
    Win32:NTRootKit-B [Trj]

    I've done a DSS and a HJT scan heres the log;

    Deckard's System Scanner v20071014.68
    Run by David on 2008-03-09 18:14:48
    Computer is in Normal Mode.
    --------------------------------------------------------------------------------

    -- System Restore --------------------------------------------------------------

    Failed to create restore point; System Restore is disabled (service is not running).


    -- Last 5 Restore Point(s) --
    40: 2008-02-13 13:50:06 UTC - RP145 - Software Distribution Service 3.0
    39: 2008-02-05 19:22:03 UTC - RP144 - Installed Device Package
    38: 2008-01-16 20:11:25 UTC - RP143 - Installed Enemy Territory - QUAKE Wars(TM) 1.4 Patch
    37: 2008-01-10 22:29:17 UTC - RP142 - Installed Enemy Territory - QUAKE Wars(TM) 1.2 Patch
    36: 2008-01-10 22:19:48 UTC - RP141 - Installed Enemy Territory - QUAKE Wars(TM) 1.1 Patch


    -- First Restore Point --
    1: 2007-08-15 17:10:45 UTC - RP106 - Software Distribution Service 3.0


    Backed up registry hives.
    Performed disk cleanup.



    -- HijackThis (run as David.exe) -----------------------------------------------

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 18:17:08, on 09/03/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16608)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
    C:\WINDOWS\system32\lxdccoms.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Creative\DVDAudio\CTDVDDET.EXE
    C:\Program Files\Creative\Surround Mixer\CTSysVol.exe
    C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
    C:\WINDOWS\CTHELPER.EXE
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
    C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe
    C:\Program Files\btbb_wcm\McciTrayApp.exe
    C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\PROGRA~1\Yahoo!\browser\ycommon.exe
    C:\Program Files\Lexmark 1300 Series\lxdcamon.exe
    C:\Program Files\Minimizor\Minimizor.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\drivers\svchost.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
    C:\Documents and Settings\David\Desktop\dss.exe
    C:\PROGRA~1\TRENDM~1\HIJACK~1\David.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/...b/*http://uk.docs.yahoo.com/info/bt_side.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sp/*http://uk.search.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/...b/*http://uk.docs.yahoo.com/info/bt_side.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    R3 - Default URLSearchHook is missing
    F3 - REG:win.ini: run= "C:\WINDOWS\system32\winupdate.exe "
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\DVDAudio\CTDVDDET.EXE "
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Surround Mixer\CTSysVol.exe /r
    O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll "
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE "
    O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
    O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe
    O4 - HKLM\..\Run: [btbb_wcm_McciTrayApp] C:\Program Files\btbb_wcm\McciTrayApp.exe
    O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe "
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe "
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [lxdcmon.exe] "C:\Program Files\Lexmark 1300 Series\lxdcmon.exe "
    O4 - HKLM\..\Run: [lxdcamon] "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe "
    O4 - HKLM\..\Run: [LXDCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll,_RunDLLEntry@16
    O4 - HKLM\..\Run: [Minimizor] C:\Program Files\Minimizor\Minimizor.exe
    O4 - HKCU\..\Run: [eyeBeam SIP Client] "C:\Program Files\BT Broadband Talk Softphone\BTSoftphone.exe "
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SVCHOST.EXE] C:\WINDOWS\system32\drivers\svchost.exe
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
    O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
    O4 - Global Startup: BT Broadband Desktop Help.lnk = C:\Program Files\BT Home Hub\Help\bin\matcli.exe
    O4 - Global Startup: Logitech SetPoint.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
    O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
    O16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) - http://cdn1.acclaimdownloads.com/solidstateion.cab
    O23 - Service: Active Common Service - Unknown owner - C:\WINDOWS\system32\commserv.exe (file missing)
    O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Autodesk Licensing Service - Unknown owner - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: lxdc_device - - C:\WINDOWS\system32\lxdccoms.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

    --
    End of file - 10170 bytes

    -- File Associations -----------------------------------------------------------

    All associations okay.


    -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

    R3 MRENDIS5 (MRENDIS5 NDIS Protocol Driver) - c:\program files\common files\motive\mrendis5.sys <Not Verified; Motive, Inc.; Motive Rawether for Windows>

    S3 dump_wmimmc - c:\program files\acclaim\2moons\bin\gameguard\dump_wmimmc.sys (file missing)
    S3 NPPTNT2 - c:\windows\system32\npptnt2.sys <Not Verified; INCA Internet Co., Ltd.; nProtect NPSC Kernel Mode Driver for NT>
    S3 ntload (ntload v0.1) - c:\windows\system32\ntload.sys (file missing)
    S3 TVICHW32 - c:\windows\system32\drivers\tvichw32.sys <Not Verified; EnTech Taiwan; TVicHW32 Generic Device Driver for Windows 95/98/ME/NT/2000/2003/XP/XP64>


    -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

    R2 Autodesk Licensing Service - "c:\program files\common files\autodesk shared\service\adskscsrv.exe "
    R2 CCALib8 (Canon Camera Access Library 8) - c:\program files\canon\cal\calmain.exe <Not Verified; Canon Inc.; >

    S2 Active Common Service - c:\windows\system32\commserv.exe (file missing)
    S3 YPCService - c:\windows\system32\ypcser~1.exe <Not Verified; Yahoo! Inc.; YPCService Module>


    -- Device Manager: Disabled ----------------------------------------------------

    No disabled devices found.


    -- Files created between 2008-02-09 and 2008-03-09 -----------------------------

    2008-02-26 11:14:44 0 d-------- C:\Program Files\Trend Micro
    2008-02-25 21:14:18 0 d-------- C:\Documents and Settings\David\Application Data\Uniblue
    2008-02-24 22:00:19 87040 --a------ C:\WINDOWS\system32\winupdate.exe
    2008-02-24 21:59:58 87040 --a------ C:\WINDOWS\e01.exe
    2008-02-24 21:59:55 22608 --a------ C:\WINDOWS\system32\drivers\svchost.exe
    2008-02-15 19:57:09 0 d-------- C:\Program Files\Minimizor


    -- Find3M Report ---------------------------------------------------------------

    2008-03-09 18:10:53 0 d-------- C:\Program Files\Lx_cats
    2008-03-09 18:08:49 0 d-------- C:\Documents and Settings\David\Application Data\Xfire
    2008-03-08 15:39:41 0 d-------- C:\Documents and Settings\David\Application Data\NoNameScript
    2008-03-08 13:44:25 0 d-------- C:\Program Files\mIRC
    2008-03-07 19:08:52 0 d-------- C:\Documents and Settings\David\Application Data\U3
    2008-03-06 22:41:53 0 d---s---- C:\Program Files\Xfire
    2008-02-26 13:14:07 0 d-------- C:\Documents and Settings\David\Application Data\Adobe
    2008-02-15 21:51:23 0 d-------- C:\Documents and Settings\David\Application Data\Yahoo!
    2008-02-10 17:33:17 0 d-------- C:\Program Files\id Software
    2008-02-01 21:38:40 0 d-------- C:\Documents and Settings\David\Application Data\uTorrent
    2008-01-20 18:38:32 2384 --a------ C:\WINDOWS\mozver.dat
    2008-01-16 20:15:43 0 d--h----- C:\Program Files\InstallShield Installation Information
    2008-01-09 21:38:26 0 d-------- C:\Documents and Settings\David\Application Data\Starware353
    2008-01-09 19:30:54 0 d-------- C:\Program Files\VideoLAN


    -- Registry Dump ---------------------------------------------------------------

    *Note* empty entries & legit default entries are not shown


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTDVDDET "= "C:\Program Files\Creative\DVDAudio\CTDVDDET.EXE" [18/06/2003 01:00]
    "CTSysVol "= "C:\Program Files\Creative\Surround Mixer\CTSysVol.exe" [15/02/2005 16:10]
    "AudioDrvEmulator "= "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" [16/06/2005 18:25]
    "CTHelper "= "CTHELPER.EXE" [18/06/2005 06:01 C:\WINDOWS\CTHELPER.EXE]
    "UpdReg "= "C:\WINDOWS\UpdReg.EXE" [11/05/2000 01:00]
    "NvCplDaemon "= "C:\WINDOWS\system32\NvCpl.dll" [13/07/2007 07:34]
    "nwiz "= "nwiz.exe" [13/07/2007 07:34 C:\WINDOWS\system32\nwiz.exe]
    "avast! "= "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [04/12/2007 13:00]
    "Logitech Hardware Abstraction Layer "= "C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE" [19/07/2006 11:03]
    "Omnipage "= "C:\Program Files\ScanSoft\OmniPageSE\opware32.exe" [03/06/2002 11:38]
    "Motive SmartBridge "= "C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe" [06/02/2006 18:52]
    "btbb_wcm_McciTrayApp "= "C:\Program Files\btbb_wcm\McciTrayApp.exe" [29/12/2005 10:22]
    "YBrowser "= "C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [09/12/2003 12:03]
    "QuickTime Task "= "C:\Program Files\QuickTime\qttask.exe" [25/10/2006 18:58]
    "iTunesHelper "= "C:\Program Files\iTunes\iTunesHelper.exe" [30/10/2006 09:36]
    "SunJavaUpdateSched "= "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [12/07/2007 03:00]
    "NvMediaCenter "= "C:\WINDOWS\system32\NvMcTray.dll" [13/07/2007 07:34]
    "@ "=" " []
    "Kernel and Hardware Abstraction Layer "= "KHALMNPR.EXE" [19/07/2006 11:03 C:\WINDOWS\KHALMNPR.Exe]
    "lxdcmon.exe "= "C:\Program Files\Lexmark 1300 Series\lxdcmon.exe" []
    "lxdcamon "= "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe" [05/02/2007 23:32]
    "LXDCCATS "= "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll" [22/01/2007 22:05]
    "Minimizor "= "C:\Program Files\Minimizor\Minimizor.exe" [31/12/2007 18:34]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "eyeBeam SIP Client "= "C:\Program Files\BT Broadband Talk Softphone\BTSoftphone.exe" [31/07/2006 20:00]
    "ctfmon.exe "= "C:\WINDOWS\system32\ctfmon.exe" [04/08/2004 00:56]
    "@ "=" " []
    "SVCHOST.EXE "= "C:\WINDOWS\system32\drivers\svchost.exe" [24/02/2008 21:59]
    "Uniblue RegistryBooster 2 "= "C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" []

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [19/04/2007 20:55:55]
    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [23/10/2006 01:48:20]
    Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [23/10/2006 00:01:50]
    BT Broadband Desktop Help.lnk - C:\Program Files\BT Home Hub\Help\bin\matcli.exe [02/03/2007 18:11:40]
    Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [30/04/2007 13:37:18]
    Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [13/02/2001 02:01:04]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
    @= "Service "

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
    @= "Volume shadow copy "


    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f6619869-c8ba-11db-9e03-806d6172696f}]
    AutoRun\command- D:\Autorun.exe root.ini




    -- End of Deckard's System Scanner: finished at 2008-03-09 18:17:33 ------------
     
  2. 2008/03/09
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Welcome to WindowsBBS ragidy :)

    Download ComboFix by sUBs from here, saving the file to your desktop.

    It's best disable realtime protection applications as they sometime interfere with the tool. Check this link for your applicable programs.

    • Close all open programs and windows
    • Double click combofix.exe and follow the prompts.
    • It may reboot your computer and resume running when you logon. Wait for it to complete. When finished, it will open a log for you. Post that log and a new HijackThis log in your next reply.
    Note: Do not mouseclick combofix's window while its running. That may cause it to stall
     

  3. to hide this advert.

  4. 2008/03/09
    ragidy

    ragidy Inactive Thread Starter

    Joined:
    2008/03/08
    Messages:
    3
    Likes Received:
    0
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:34:03, on 09/03/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16608)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
    C:\WINDOWS\system32\lxdccoms.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\CF3354.exe
    C:\Program Files\Creative\DVDAudio\CTDVDDET.EXE
    C:\Program Files\Creative\Surround Mixer\CTSysVol.exe
    C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
    C:\WINDOWS\CTHELPER.EXE
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
    C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe
    C:\Program Files\btbb_wcm\McciTrayApp.exe
    C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\PROGRA~1\Yahoo!\browser\ycommon.exe
    C:\Program Files\Lexmark 1300 Series\lxdcamon.exe
    C:\Program Files\Minimizor\Minimizor.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    C:\Program Files\BT Home Hub\Help\bin\mpbtn.exe
    C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/...b/*http://uk.docs.yahoo.com/info/bt_side.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\DVDAudio\CTDVDDET.EXE "
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Surround Mixer\CTSysVol.exe /r
    O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll "
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE "
    O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
    O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe
    O4 - HKLM\..\Run: [btbb_wcm_McciTrayApp] C:\Program Files\btbb_wcm\McciTrayApp.exe
    O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe "
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe "
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [lxdcmon.exe] "C:\Program Files\Lexmark 1300 Series\lxdcmon.exe "
    O4 - HKLM\..\Run: [lxdcamon] "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe "
    O4 - HKLM\..\Run: [LXDCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll,_RunDLLEntry@16
    O4 - HKLM\..\Run: [Minimizor] C:\Program Files\Minimizor\Minimizor.exe
    O4 - HKCU\..\Run: [eyeBeam SIP Client] "C:\Program Files\BT Broadband Talk Softphone\BTSoftphone.exe "
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SVCHOST.EXE] C:\WINDOWS\system32\drivers\svchost.exe
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
    O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
    O4 - Global Startup: BT Broadband Desktop Help.lnk = C:\Program Files\BT Home Hub\Help\bin\matcli.exe
    O4 - Global Startup: Logitech SetPoint.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: BT Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
    O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
    O16 - DPF: {BD08A9D5-0E5C-4F42-99A3-C0CB5E860557} (CSolidBrowserObj Object) - http://cdn1.acclaimdownloads.com/solidstateion.cab
    O23 - Service: Active Common Service - Unknown owner - C:\WINDOWS\system32\commserv.exe (file missing)
    O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Autodesk Licensing Service - Unknown owner - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: lxdc_device - - C:\WINDOWS\system32\lxdccoms.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE

    --
    End of file - 9753 bytes
    ---------------------------------------------------------

    ComboFix 08-03-09.1 - David 2008-03-09 21:22:00.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.737 [GMT 0:00]
    Running from: C:\Documents and Settings\David\Desktop\Downloads\Firefox\ComboFix.exe
    * Created a new restore point

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Documents and Settings\All Users\Application Data\Starware353
    C:\Documents and Settings\All Users\Application Data\Starware353\buttons\448_button_1b_def.bmp
    C:\Documents and Settings\All Users\Application Data\Starware353\buttons\448_button_1b_over.bmp
    C:\Documents and Settings\All Users\Application Data\Starware353\buttons\450_button_1b_def.bmp
    C:\Documents and Settings\All Users\Application Data\Starware353\buttons\Button_60.bmp
    C:\Documents and Settings\All Users\Application Data\Starware353\buttons\Button_70.bmp
    C:\Documents and Settings\All Users\Application Data\Starware353\buttons\Button_80.bmp
    C:\Documents and Settings\All Users\Application Data\Starware353\buttons\FindIt.bmp
    C:\Documents and Settings\All Users\Application Data\Starware353\buttons\FindItHot.bmp
    C:\Documents and Settings\All Users\Application Data\Starware353\buttons\findithotxp.png
    C:\Documents and Settings\All Users\Application Data\Starware353\buttons\finditxp.png
    C:\Documents and Settings\All Users\Application Data\Starware353\buttons\logo.bmp
    C:\Documents and Settings\All Users\Application Data\Starware353\buttons\logoxp.bmp
    C:\Documents and Settings\All Users\Application Data\Starware353\buttons\Reference.bmp
    C:\Documents and Settings\All Users\Application Data\Starware353\buttons\ReferenceHot.bmp
    C:\Documents and Settings\All Users\Application Data\Starware353\buttons\referencehotxp.png
    C:\Documents and Settings\All Users\Application Data\Starware353\buttons\referencexp.png
    C:\Documents and Settings\All Users\Application Data\Starware353\buttons\Weather.bmp
    C:\Documents and Settings\All Users\Application Data\Starware353\buttons\WeatherHot.bmp
    C:\Documents and Settings\All Users\Application Data\Starware353\buttons\weatherhotxp.png
    C:\Documents and Settings\All Users\Application Data\Starware353\buttons\weatherxp.png
    C:\Documents and Settings\All Users\Application Data\Starware353\contexts\error.xml
    C:\Documents and Settings\All Users\Application Data\Starware353\contexts\Related.xml
    C:\Documents and Settings\All Users\Application Data\Starware353\contexts\Travel.xml
    C:\Documents and Settings\All Users\Application Data\Starware353\images\walertXP.bmp
    C:\Documents and Settings\All Users\Application Data\Starware353\SimpleUpdate\ProductMessagingConfig.xml
    C:\Documents and Settings\All Users\Application Data\Starware353\SimpleUpdate\ProductMessagingConfig.xml.backup
    C:\Documents and Settings\All Users\Application Data\Starware353\SimpleUpdate\SimpleUpdateConfig.xml
    C:\Documents and Settings\All Users\Application Data\Starware353\SimpleUpdate\SimpleUpdateConfig.xml.backup
    C:\Documents and Settings\All Users\Application Data\Starware353\SimpleUpdate\TimerManagerConfig.xml
    C:\Documents and Settings\All Users\Application Data\Starware353\SimpleUpdate\TimerManagerConfig.xml.backup
    C:\Documents and Settings\David\Application Data\Starware353
    C:\Documents and Settings\David\Application Data\Starware353\BrowserSearch\BrowserSearch.xml
    C:\Documents and Settings\David\Application Data\Starware353\BrowserSearch\BrowserSearch.xml.backup
    C:\Documents and Settings\David\Application Data\Starware353\Button_6\Button_6Options.xml
    C:\Documents and Settings\David\Application Data\Starware353\Button_6\Button_6Options.xml.backup
    C:\Documents and Settings\David\Application Data\Starware353\Button_7\Button_7Options.xml
    C:\Documents and Settings\David\Application Data\Starware353\Button_7\Button_7Options.xml.backup
    C:\Documents and Settings\David\Application Data\Starware353\Button_8\Button_8Options.xml
    C:\Documents and Settings\David\Application Data\Starware353\Button_8\Button_8Options.xml.backup
    C:\Documents and Settings\David\Application Data\Starware353\Configurator\Configurator.xml
    C:\Documents and Settings\David\Application Data\Starware353\Configurator\Configurator.xml.backup
    C:\Documents and Settings\David\Application Data\Starware353\ErrorSearch\ErrorSearchOptions.xml
    C:\Documents and Settings\David\Application Data\Starware353\ErrorSearch\ErrorSearchOptions.xml.backup
    C:\Documents and Settings\David\Application Data\Starware353\Layouts\ToolbarLayout.xml
    C:\Documents and Settings\David\Application Data\Starware353\Layouts\ToolbarLayout.xml.backup
    C:\Documents and Settings\David\Application Data\Starware353\Manager\ManagerOptions.xml
    C:\Documents and Settings\David\Application Data\Starware353\Manager\ManagerOptions.xml.backup
    C:\Documents and Settings\David\Application Data\Starware353\Recipe_RSS\Recipe_RSSOptions.xml
    C:\Documents and Settings\David\Application Data\Starware353\Recipe_RSS\Recipe_RSSOptions.xml.backup
    C:\Documents and Settings\David\Application Data\Starware353\Reference\ReferenceOptions.xml
    C:\Documents and Settings\David\Application Data\Starware353\Reference\ReferenceOptions.xml.backup
    C:\Documents and Settings\David\Application Data\Starware353\RelatedSearch\RelatedSearchOptions.xml
    C:\Documents and Settings\David\Application Data\Starware353\RelatedSearch\RelatedSearchOptions.xml.backup
    C:\Documents and Settings\David\Application Data\Starware353\Search_Recipes\Search_RecipesOptions.xml
    C:\Documents and Settings\David\Application Data\Starware353\Search_Recipes\Search_RecipesOptions.xml.backup
    C:\Documents and Settings\David\Application Data\Starware353\Toolbar\TBProductsOptions.xml
    C:\Documents and Settings\David\Application Data\Starware353\Toolbar\TBProductsOptions.xml.backup
    C:\Documents and Settings\David\Application Data\Starware353\ToolbarLogo\ToolbarLogoOptions.xml
    C:\Documents and Settings\David\Application Data\Starware353\ToolbarLogo\ToolbarLogoOptions.xml.backup
    C:\Documents and Settings\David\Application Data\Starware353\ToolbarSearch\ToolbarSearchOptions.xml
    C:\Documents and Settings\David\Application Data\Starware353\ToolbarSearch\ToolbarSearchOptions.xml.backup
    C:\Documents and Settings\David\Application Data\Starware353\TravelSearch\TravelSearchOptions.xml
    C:\Documents and Settings\David\Application Data\Starware353\TravelSearch\TravelSearchOptions.xml.backup
    C:\Documents and Settings\David\Application Data\Starware353\Weather\AlertArchive.xml
    C:\Documents and Settings\David\Application Data\Starware353\Weather\WeatherOptions.xml
    C:\Documents and Settings\David\Application Data\Starware353\Weather\WeatherOptions.xml.backup
    C:\Documents and Settings\Dorthy\Application Data\Starware353
    C:\Documents and Settings\Dorthy\Application Data\Starware353\BrowserSearch\BrowserSearch.xml
    C:\Documents and Settings\Dorthy\Application Data\Starware353\BrowserSearch\BrowserSearch.xml.backup
    C:\Documents and Settings\Dorthy\Application Data\Starware353\Button_6\Button_6Options.xml
    C:\Documents and Settings\Dorthy\Application Data\Starware353\Button_6\Button_6Options.xml.backup
    C:\Documents and Settings\Dorthy\Application Data\Starware353\Button_7\Button_7Options.xml
    C:\Documents and Settings\Dorthy\Application Data\Starware353\Button_7\Button_7Options.xml.backup
    C:\Documents and Settings\Dorthy\Application Data\Starware353\Button_8\Button_8Options.xml
    C:\Documents and Settings\Dorthy\Application Data\Starware353\Button_8\Button_8Options.xml.backup
    C:\Documents and Settings\Dorthy\Application Data\Starware353\Configurator\Configurator.xml
    C:\Documents and Settings\Dorthy\Application Data\Starware353\Configurator\Configurator.xml.backup
    C:\Documents and Settings\Dorthy\Application Data\Starware353\ErrorSearch\ErrorSearchOptions.xml
    C:\Documents and Settings\Dorthy\Application Data\Starware353\ErrorSearch\ErrorSearchOptions.xml.backup
    C:\Documents and Settings\Dorthy\Application Data\Starware353\Layouts\ToolbarLayout.xml
    C:\Documents and Settings\Dorthy\Application Data\Starware353\Layouts\ToolbarLayout.xml.backup
    C:\Documents and Settings\Dorthy\Application Data\Starware353\Manager\ManagerOptions.xml
    C:\Documents and Settings\Dorthy\Application Data\Starware353\Manager\ManagerOptions.xml.backup
    C:\Documents and Settings\Dorthy\Application Data\Starware353\Recipe_RSS\Recipe_RSSOptions.xml
    C:\Documents and Settings\Dorthy\Application Data\Starware353\Recipe_RSS\Recipe_RSSOptions.xml.backup
    C:\Documents and Settings\Dorthy\Application Data\Starware353\Reference\ReferenceOptions.xml
    C:\Documents and Settings\Dorthy\Application Data\Starware353\Reference\ReferenceOptions.xml.backup
    C:\Documents and Settings\Dorthy\Application Data\Starware353\RelatedSearch\RelatedSearchOptions.xml
    C:\Documents and Settings\Dorthy\Application Data\Starware353\RelatedSearch\RelatedSearchOptions.xml.backup
    C:\Documents and Settings\Dorthy\Application Data\Starware353\Search_Recipes\Search_RecipesOptions.xml
    C:\Documents and Settings\Dorthy\Application Data\Starware353\Search_Recipes\Search_RecipesOptions.xml.backup
    C:\Documents and Settings\Dorthy\Application Data\Starware353\Toolbar\TBProductsOptions.xml
    C:\Documents and Settings\Dorthy\Application Data\Starware353\Toolbar\TBProductsOptions.xml.backup
    C:\Documents and Settings\Dorthy\Application Data\Starware353\ToolbarLogo\ToolbarLogoOptions.xml
    C:\Documents and Settings\Dorthy\Application Data\Starware353\ToolbarLogo\ToolbarLogoOptions.xml.backup
    C:\Documents and Settings\Dorthy\Application Data\Starware353\ToolbarSearch\ToolbarSearchOptions.xml
    C:\Documents and Settings\Dorthy\Application Data\Starware353\ToolbarSearch\ToolbarSearchOptions.xml.backup
    C:\Documents and Settings\Dorthy\Application Data\Starware353\TravelSearch\TravelSearchOptions.xml
    C:\Documents and Settings\Dorthy\Application Data\Starware353\TravelSearch\TravelSearchOptions.xml.backup
    C:\Documents and Settings\Dorthy\Application Data\Starware353\Weather\AlertArchive.xml
    C:\Documents and Settings\Dorthy\Application Data\Starware353\Weather\WeatherOptions.xml
    C:\Documents and Settings\Dorthy\Application Data\Starware353\Weather\WeatherOptions.xml.backup
    C:\WINDOWS\system32\drivers\svchost.exe
    C:\WINDOWS\system32\winupdate.exe

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\ntload


    ((((((((((((((((((((((((( Files Created from 2008-02-09 to 2008-03-09 )))))))))))))))))))))))))))))))
    .

    2008-03-01 20:09 . 2008-03-01 20:09 <DIR> d-------- C:\Deckard
    2008-02-26 11:14 . 2008-02-26 11:14 <DIR> d-------- C:\Program Files\Trend Micro
    2008-02-25 21:14 . 2008-02-25 21:14 <DIR> d-------- C:\Documents and Settings\David\Application Data\Uniblue
    2008-02-24 21:59 . 2008-02-24 21:59 87,040 --a------ C:\WINDOWS\e01.exe
    2008-02-21 01:57 . 2008-02-21 01:57 54,608 --a------ C:\WINDOWS\system32\xfcodec.dll
    2008-02-15 19:57 . 2008-02-15 19:57 <DIR> d-------- C:\Program Files\Minimizor

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-03-09 21:28 --------- d-----w C:\Program Files\Lx_cats
    2008-03-09 21:20 --------- d-----w C:\Documents and Settings\David\Application Data\Xfire
    2008-03-09 20:56 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
    2008-03-09 20:33 --------- d-----w C:\Program Files\mIRC
    2008-03-09 20:33 --------- d-----w C:\Documents and Settings\David\Application Data\NoNameScript
    2008-03-07 19:08 --------- d-----w C:\Documents and Settings\David\Application Data\U3
    2008-03-06 22:41 --------- d-s---w C:\Program Files\Xfire
    2008-02-15 21:51 --------- d-----w C:\Documents and Settings\David\Application Data\Yahoo!
    2008-02-10 17:33 --------- d-----w C:\Program Files\id Software
    2008-02-01 21:38 --------- d-----w C:\Documents and Settings\David\Application Data\uTorrent
    2008-01-16 20:15 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-01-10 21:43 22,328 ----a-w C:\Documents and Settings\David\Application Data\PnkBstrK.sys
    2008-01-09 19:30 --------- d-----w C:\Program Files\VideoLAN
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "eyeBeam SIP Client "= "C:\Program Files\BT Broadband Talk Softphone\BTSoftphone.exe" [2006-07-31 20:00 19857408]
    "ctfmon.exe "= "C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
    "SVCHOST.EXE "= "C:\WINDOWS\system32\drivers\svchost.exe" [ ]
    "Uniblue RegistryBooster 2 "= "C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTDVDDET "= "C:\Program Files\Creative\DVDAudio\CTDVDDET.EXE" [2003-06-18 01:00 45056]
    "CTSysVol "= "C:\Program Files\Creative\Surround Mixer\CTSysVol.exe" [2005-02-15 16:10 57344]
    "AudioDrvEmulator "= "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-16 18:25 49152]
    "CTHelper "= "CTHELPER.EXE" [2005-06-18 06:01 16384 C:\WINDOWS\CTHELPER.EXE]
    "UpdReg "= "C:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00 90112]
    "NvCplDaemon "= "C:\WINDOWS\system32\NvCpl.dll" [2007-07-13 07:34 8466432]
    "nwiz "= "nwiz.exe" [2007-07-13 07:34 1626112 C:\WINDOWS\system32\nwiz.exe]
    "avast! "= "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 13:00 79224]
    "Logitech Hardware Abstraction Layer "= "C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE" [2006-07-19 11:03 94208]
    "Omnipage "= "C:\Program Files\ScanSoft\OmniPageSE\opware32.exe" [2002-06-03 11:38 49152]
    "Motive SmartBridge "= "C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe" [2006-02-06 18:52 462935]
    "btbb_wcm_McciTrayApp "= "C:\Program Files\btbb_wcm\McciTrayApp.exe" [2005-12-29 10:22 543232]
    "YBrowser "= "C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2003-12-09 12:03 57344]
    "QuickTime Task "= "C:\Program Files\QuickTime\qttask.exe" [2006-10-25 18:58 282624]
    "iTunesHelper "= "C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36 256576]
    "SunJavaUpdateSched "= "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00 132496]
    "NvMediaCenter "= "C:\WINDOWS\system32\NvMcTray.dll" [2007-07-13 07:34 81920]
    "Kernel and Hardware Abstraction Layer "= "KHALMNPR.EXE" [2006-07-19 11:03 94208 C:\WINDOWS\KHALMNPR.Exe]
    "lxdcmon.exe "= "C:\Program Files\Lexmark 1300 Series\lxdcmon.exe" [ ]
    "lxdcamon "= "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe" [2007-02-05 23:32 20480]
    "LXDCCATS "= "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll" [2007-01-22 22:05 102400]
    "Minimizor "= "C:\Program Files\Minimizor\Minimizor.exe" [2007-12-31 18:34 546304]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE "= "C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:56 15360]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-04-19 20:55:55 113664]
    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 01:48:20 40048]
    Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 00:01:50 734872]
    BT Broadband Desktop Help.lnk - C:\Program Files\BT Home Hub\Help\bin\matcli.exe [2007-03-02 18:11:40 217088]
    Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-04-30 13:37:18 671744]
    Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "C:\\Program Files\\Yahoo!\\Messenger\\ypager.exe "=
    "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe "=
    "C:\\Program Files\\Xfire\\xfire.exe "=
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe "=
    "C:\\Program Files\\MSN Messenger\\livecall.exe "=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe "=
    "C:\\Program Files\\mIRC\\mirc.exe "=
    "C:\\Program Files\\Wolfenstein - Enemy Territory\\ETDED.exe "=
    "C:\\Program Files\\BT Home Hub\\Help\\SmartBridge\\BTHelpNotifier.exe "=
    "C:\\Program Files\\LimeWire\\LimeWire.exe "=
    "C:\\WINDOWS\\system32\\lxdccoms.exe "=
    "C:\\Program Files\\Lexmark 1300 Series\\lxdcamon.exe "=
    "C:\\Program Files\\Lexmark 1300 Series\\App4R.exe "=
    "C:\\WINDOWS\\system32\\PnkBstrA.exe "=
    "C:\\WINDOWS\\system32\\PnkBstrB.exe "=
    "C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe "=
    "C:\\Program Files\\3DSMax\\3dsmax.exe "=
    "C:\\Program Files\\backburner 2\\monitor.exe "=
    "C:\\Program Files\\backburner 2\\manager.exe "=
    "C:\\Program Files\\backburner 2\\server.exe "=
    "C:\\Program Files\\uTorrent\\uTorrent.exe "=
    "C:\\Program Files\\iTunes\\iTunes.exe "=
    "F:\\Program Files\\2.55.exe "=
    "C:\\Program Files\\id Software\\Enemy Territory - QUAKE Wars\\etqwded.exe "=
    "C:\\Program Files\\id Software\\Enemy Territory - QUAKE Wars\\etqw.exe "=
    "F:\\Home\\game\\metin2.bin "=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "9842:TCP "= 9842:TCP:*:Disabled:SolidNetworkManager
    "9842:UDP "= 9842:UDP:*:Disabled:SolidNetworkManager

    R2 lxdc_device;lxdc_device;C:\WINDOWS\system32\lxdccoms.exe [2007-02-12 23:56]
    S2 Active Common Service;Active Common Service;C:\WINDOWS\system32\commserv.exe []
    S3 dump_wmimmc;dump_wmimmc;C:\Program Files\Acclaim\2Moons\bin\GameGuard\dump_wmimmc.sys []

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f6619869-c8ba-11db-9e03-806d6172696f}]
    \Shell\AutoRun\command - D:\Autorun.exe root.ini

    .
    **************************************************************************

    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-03-09 21:28:09
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\PROGRA~1\Yahoo!\browser\ycommon.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\BT Home Hub\Help\bin\mpbtn.exe
    .
    **************************************************************************
    .
    Completion time: 2008-03-09 21:32:09 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-03-09 21:32:06
    .
    2008-02-13 13:51:41 --- E O F ---
     
  5. 2008/03/09
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Did you knowingly disable System Restore?

    Highlight and copy the contents of the code box below and paste it into a blank notepad, then save it to your desktop as;

    Filename: CFScript.txt
    Save As Type: All Files (*.*)

    Code:
    File::
    C:\WINDOWS\e01.exe
    C:\WINDOWS\system32\ntload.sys
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
     "SVCHOST.EXE "=-
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f6619869-c8ba-11db-9e03-806d6172696f}]
    Driver::
    Active Common Service
    
    Close all other windows and programs. Now drag the CFScript.txt onto ComboFix.exe and drop it, using the left mouse button. Combofix should run and may reboot the computer when it's done. A log will open when it's complete. Post the contents of that log.

    Please do not click on the ComboFix window while it is running a scan. This can cause it to stall.
     
  6. 2008/03/09
    ragidy

    ragidy Inactive Thread Starter

    Joined:
    2008/03/08
    Messages:
    3
    Likes Received:
    0
    No, i didn't knowingly disbale the System Restore

    heres the log;

    ComboFix 08-03-09.1 - David 2008-03-09 22:29:08.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.707 [GMT 0:00]
    Running from: C:\Documents and Settings\David\Desktop\ComboFix.exe
    Command switches used :: C:\Documents and Settings\David\Desktop\CFScript.txt
    * Created a new restore point

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

    FILE ::
    C:\WINDOWS\e01.exe
    C:\WINDOWS\system32\ntload.sys
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\WINDOWS\e01.exe

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\LEGACY_ACTIVE_COMMON_SERVICE
    -------\Active Common Service


    ((((((((((((((((((((((((( Files Created from 2008-02-09 to 2008-03-09 )))))))))))))))))))))))))))))))
    .

    2008-03-01 20:09 . 2008-03-01 20:09 <DIR> d-------- C:\Deckard
    2008-02-26 11:14 . 2008-02-26 11:14 <DIR> d-------- C:\Program Files\Trend Micro
    2008-02-25 21:14 . 2008-02-25 21:14 <DIR> d-------- C:\Documents and Settings\David\Application Data\Uniblue
    2008-02-21 01:57 . 2008-02-21 01:57 54,608 --a------ C:\WINDOWS\system32\xfcodec.dll
    2008-02-15 19:57 . 2008-02-15 19:57 <DIR> d-------- C:\Program Files\Minimizor

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-03-09 22:33 --------- d-----w C:\Program Files\Lx_cats
    2008-03-09 22:24 --------- d-----w C:\Documents and Settings\David\Application Data\Xfire
    2008-03-09 22:01 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
    2008-03-09 20:33 --------- d-----w C:\Program Files\mIRC
    2008-03-09 20:33 --------- d-----w C:\Documents and Settings\David\Application Data\NoNameScript
    2008-03-07 19:08 --------- d-----w C:\Documents and Settings\David\Application Data\U3
    2008-03-06 22:41 --------- d-s---w C:\Program Files\Xfire
    2008-02-15 21:51 --------- d-----w C:\Documents and Settings\David\Application Data\Yahoo!
    2008-02-10 17:33 --------- d-----w C:\Program Files\id Software
    2008-02-01 21:38 --------- d-----w C:\Documents and Settings\David\Application Data\uTorrent
    2008-01-16 20:15 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-01-10 21:43 22,328 ----a-w C:\Documents and Settings\David\Application Data\PnkBstrK.sys
    2008-01-09 19:30 --------- d-----w C:\Program Files\VideoLAN
    .

    ((((((((((((((((((((((((((((( snapshot@2008-03-09_21.31.57.25 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2008-03-09 20:56:25 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
    + 2008-03-09 22:01:51 107,832 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
    - 2008-03-09 21:27:37 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_514.dat
    + 2008-03-09 22:33:07 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_514.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "eyeBeam SIP Client "= "C:\Program Files\BT Broadband Talk Softphone\BTSoftphone.exe" [2006-07-31 20:00 19857408]
    "ctfmon.exe "= "C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
    "Uniblue RegistryBooster 2 "= "C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTDVDDET "= "C:\Program Files\Creative\DVDAudio\CTDVDDET.EXE" [2003-06-18 01:00 45056]
    "CTSysVol "= "C:\Program Files\Creative\Surround Mixer\CTSysVol.exe" [2005-02-15 16:10 57344]
    "AudioDrvEmulator "= "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-06-16 18:25 49152]
    "CTHelper "= "CTHELPER.EXE" [2005-06-18 06:01 16384 C:\WINDOWS\CTHELPER.EXE]
    "UpdReg "= "C:\WINDOWS\UpdReg.EXE" [2000-05-11 01:00 90112]
    "NvCplDaemon "= "C:\WINDOWS\system32\NvCpl.dll" [2007-07-13 07:34 8466432]
    "nwiz "= "nwiz.exe" [2007-07-13 07:34 1626112 C:\WINDOWS\system32\nwiz.exe]
    "avast! "= "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 13:00 79224]
    "Logitech Hardware Abstraction Layer "= "C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE" [2006-07-19 11:03 94208]
    "Omnipage "= "C:\Program Files\ScanSoft\OmniPageSE\opware32.exe" [2002-06-03 11:38 49152]
    "Motive SmartBridge "= "C:\PROGRA~1\BTHOME~1\Help\SMARTB~1\BTHelpNotifier.exe" [2006-02-06 18:52 462935]
    "btbb_wcm_McciTrayApp "= "C:\Program Files\btbb_wcm\McciTrayApp.exe" [2005-12-29 10:22 543232]
    "YBrowser "= "C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe" [2003-12-09 12:03 57344]
    "QuickTime Task "= "C:\Program Files\QuickTime\qttask.exe" [2006-10-25 18:58 282624]
    "iTunesHelper "= "C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36 256576]
    "SunJavaUpdateSched "= "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00 132496]
    "NvMediaCenter "= "C:\WINDOWS\system32\NvMcTray.dll" [2007-07-13 07:34 81920]
    "Kernel and Hardware Abstraction Layer "= "KHALMNPR.EXE" [2006-07-19 11:03 94208 C:\WINDOWS\KHALMNPR.Exe]
    "lxdcmon.exe "= "C:\Program Files\Lexmark 1300 Series\lxdcmon.exe" [ ]
    "lxdcamon "= "C:\Program Files\Lexmark 1300 Series\lxdcamon.exe" [2007-02-05 23:32 20480]
    "LXDCCATS "= "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll" [2007-01-22 22:05 102400]
    "Minimizor "= "C:\Program Files\Minimizor\Minimizor.exe" [2007-12-31 18:34 546304]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE "= "C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:56 15360]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-04-19 20:55:55 113664]
    Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 01:48:20 40048]
    Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 00:01:50 734872]
    BT Broadband Desktop Help.lnk - C:\Program Files\BT Home Hub\Help\bin\matcli.exe [2007-03-02 18:11:40 217088]
    Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-04-30 13:37:18 671744]
    Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 02:01:04 83360]

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe "=
    "C:\\Program Files\\Yahoo!\\Messenger\\ypager.exe "=
    "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe "=
    "C:\\Program Files\\Xfire\\xfire.exe "=
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe "=
    "C:\\Program Files\\MSN Messenger\\livecall.exe "=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe "=
    "C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe "=
    "C:\\Program Files\\mIRC\\mirc.exe "=
    "C:\\Program Files\\Wolfenstein - Enemy Territory\\ETDED.exe "=
    "C:\\Program Files\\BT Home Hub\\Help\\SmartBridge\\BTHelpNotifier.exe "=
    "C:\\Program Files\\LimeWire\\LimeWire.exe "=
    "C:\\WINDOWS\\system32\\lxdccoms.exe "=
    "C:\\Program Files\\Lexmark 1300 Series\\lxdcamon.exe "=
    "C:\\Program Files\\Lexmark 1300 Series\\App4R.exe "=
    "C:\\WINDOWS\\system32\\PnkBstrA.exe "=
    "C:\\WINDOWS\\system32\\PnkBstrB.exe "=
    "C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe "=
    "C:\\Program Files\\3DSMax\\3dsmax.exe "=
    "C:\\Program Files\\backburner 2\\monitor.exe "=
    "C:\\Program Files\\backburner 2\\manager.exe "=
    "C:\\Program Files\\backburner 2\\server.exe "=
    "C:\\Program Files\\uTorrent\\uTorrent.exe "=
    "C:\\Program Files\\iTunes\\iTunes.exe "=
    "F:\\Program Files\\2.55.exe "=
    "C:\\Program Files\\id Software\\Enemy Territory - QUAKE Wars\\etqwded.exe "=
    "C:\\Program Files\\id Software\\Enemy Territory - QUAKE Wars\\etqw.exe "=
    "F:\\Home\\game\\metin2.bin "=
    "F:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe "=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "9842:TCP "= 9842:TCP:*:Disabled:SolidNetworkManager
    "9842:UDP "= 9842:UDP:*:Disabled:SolidNetworkManager

    R2 lxdc_device;lxdc_device;C:\WINDOWS\system32\lxdccoms.exe [2007-02-12 23:56]
    S3 dump_wmimmc;dump_wmimmc;C:\Program Files\Acclaim\2Moons\bin\GameGuard\dump_wmimmc.sys []

    .
    **************************************************************************

    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-03-09 22:33:27
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\PROGRA~1\Yahoo!\browser\ycommon.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\BT Home Hub\Help\bin\mpbtn.exe
    .
    **************************************************************************
    .
    Completion time: 2008-03-09 22:35:56 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-03-09 22:35:54
    ComboFix2.txt 2008-03-09 21:32:09
    .
    2008-02-13 13:51:41 --- E O F ---
     
  7. 2008/03/09
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    That log looks good. Is avast still showing the message?

    Lets see if we can get the System Restore service running. Click Start>Run and type (or copy and paste) the following command, then hit enter.

    sc config srservice start= auto

    Then run this command.

    sc start srservice

    Now, click Start>Run and type cmd then hit enter to open a command window. Type sc query srservice and hit enter. Does it show the service as running or stopped?
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.