1,105,546 Community Members

ping.exe using all the cpu usage

Member Avatar
stevensan1983
Newbie Poster
5 posts since Jan 2012
Reputation Points: 0 [?]
Q&As Helped to Solve: 0 [?]
Skill Endorsements: 0 [?]
 
0
 

I am in need of help ping.exe keeps running and using up all of my cpu i have tried to start in safe mode and delet this item but it replaced itself upon restarting in normal mode i have ran all the scans so far malware bytes is currently running as its the last scan i have to do posting results as follows. NOTE i have been ending process tree on ping.exe entire time so i dont get 100% cpu usage. and the first scan i ran was windows melicious software tool it found something did something and restarted do not have a log of it.

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_25
Run by stevensan1983 at 11:01:07 on 2012-01-02
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.3070.1496 [GMT -6:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Lavasoft\Ad-Aware\AWSC.exe
C:\Program Files\Lavasoft\Ad-Aware\AWSC.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\RocketFish\RF7.1\Volume Panel\VolPanlu.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Lavasoft\Ad-Aware\AWSC.exe
C:\Program Files\Lavasoft\Ad-Aware\AWSC.exe
C:\Windows\System32\ping.exe
C:\Windows\system32\Taskmgr.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.hotspotshield.com/g/?c=h
uURLSearchHooks: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - c:\program files\bittorrentbar\tbBitT.dll
mURLSearchHooks: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - c:\program files\bittorrentbar\tbBitT.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
BHO: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - c:\program files\bittorrentbar\tbBitT.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
TB: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - c:\program files\bittorrentbar\tbBitT.dll
TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
mRun: [VolPanel] "c:\program files\rocketfish\rf7.1\volume panel\VolPanlu.exe" /r
mRun: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Conime] %windir%\system32\conime.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
uPolicies-explorer: HideSCAHealth = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.0.1 205.171.3.25
TCP: Interfaces\{836F6CAD-66F8-46DE-BDB9-954BD07E74E8} : DhcpNameServer = 192.168.0.1 205.171.3.25
TCP: Interfaces\{C9D08C66-8C92-4206-8173-2CC27910BE31} : DhcpNameServer = 192.168.0.1 205.171.3.25
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\stevensan1983\appdata\roaming\mozilla\firefox\profiles\0ngwn008.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2956065&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Hotspot Shield Private Search
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://search.hotspotshield.com/g/results.php?c=s&q=
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\stevensan1983\appdata\local\facebook\video\skype\npFacebookVideoCalling.dll
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
.
R0 amacpi;Microsoft Away Mode System;c:\windows\system32\drivers\null.sys [2008-1-20 4608]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-10-11 64512]
R0 nvamacpi;NVIDIA Away Mode System;c:\windows\system32\drivers\nvamacpi.sys [2009-11-24 24680]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165648]
R1 MpKsl718b8e61;MpKsl718b8e61;c:\windows\system32\mpenginestore\MpKsl718b8e61.sys [2012-1-2 28752]
R2 AERTFilters;Andrea RT Filters Service;c:\program files\realtek\audio\hda\AERTSrv.exe [2011-5-8 81920]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R3 WMP110v2;Linksys WMP110 RangePlus Wireless PCI Adapter Driver for Windows Vista;c:\windows\system32\drivers\WMP110v2.sys [2011-5-8 338432]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 hshld;Hotspot Shield Service;c:\program files\hotspot shield\bin\openvpnas.exe --> c:\program files\hotspot shield\bin\openvpnas.exe [?]
S2 HssWd;Hotspot Shield Monitoring Service;c:\program files\hotspot shield\bin\hsswd.exe -product hss --> c:\program files\hotspot shield\bin\hsswd.exe -product HSS [?]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-8-18 2152152]
S2 SPService;SPService;c:\windows\system32\svchost.exe -k netsvc [2008-1-20 21504]
S3 BTWAMPFL;btwampfl;c:\windows\system32\drivers\btwampfl.sys [2011-8-6 301608]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\drivers\btwl2cap.sys [2011-8-6 33320]
S3 CEDRIVER60;CEDRIVER60;c:\program files\cheat engine 6\dbk32.sys [2011-5-9 62336]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2011-5-8 79360]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2011-5-23 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-22 1493352]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2011-8-18 15232]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 65024]
S3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2011-4-27 208944]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\zune\WMZuneComm.exe [2011-8-5 268512]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
.
=============== Created Last 30 ================
.
2012-01-02 11:31:44 -------- d-----w- c:\program files\Microsoft Games
2012-01-02 08:47:34 -------- d-----w- c:\windows\system32\MpEngineStore
2012-01-02 08:08:19 -------- d-----w- C:\TDSSKiller_Quarantine
2012-01-02 07:23:52 -------- d-----w- C:\backup
2011-12-31 04:24:52 -------- d-----w- c:\windows\system32\wbem\Logs
2011-12-25 22:57:04 -------- d-----w- c:\windows\Downloaded Program Files
2011-12-25 18:52:17 56200 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{59d5ada5-f826-4f52-a33b-0c53f3f3cff8}\offreg.dll
2011-12-25 13:47:54 6823496 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{59d5ada5-f826-4f52-a33b-0c53f3f3cff8}\mpengine.dll
2011-12-14 10:01:39 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-12-14 10:01:39 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-12-14 10:01:37 429056 ----a-w- c:\windows\system32\EncDec.dll
2011-12-14 10:01:36 2043904 ----a-w- c:\windows\system32\win32k.sys
2011-12-14 10:01:35 49152 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-14 10:01:34 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2011-12-14 10:01:31 2048 ----a-w- c:\windows\system32\tzres.dll
.
==================== Find3M ====================
.
2011-11-22 09:51:55 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-03 22:47:42 1798144 ----a-w- c:\windows\system32\jscript9.dll
2011-11-03 22:40:21 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-11-03 22:39:47 1127424 ----a-w- c:\windows\system32\wininet.dll
2011-11-03 22:31:57 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-10-11 08:17:32 16432 ----a-w- c:\windows\system32\lsdelete.exe
.
============= FINISH: 11:01:42.03 ===============


.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Business
Boot Device: \Device\HarddiskVolume1
Install Date: 5/7/2011 10:16:29 PM
System Uptime: 1/2/2012 6:05:55 AM (5 hours ago)
.
Motherboard: Dell Inc. | | 0RY206
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 4400+ | Socket AM2 | 2310/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 149 GiB total, 40.745 GiB free.
E: is Removable
F: is Removable
G: is Removable
H: is Removable
I: is Removable
J: is FIXED (NTFS) - 298 GiB total, 188.095 GiB free.
K: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
.
==== Installed Programs ======================
.
32 bit Windows Card Reader Driver
Ad-Aware
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader 8.3.1
Adobe Shockwave Player 11.5
ATI Catalyst Install Manager
BioShock
BitTorrent
BitTorrentBar Toolbar
CABAL Online (NA - Global)
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center HydraVision Full
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
CDDRV_Installer
Cheat Engine 6.0
Conduit Engine
Creative MediaSource 5
Curse Client
D3DX10
Dell Driver Download Manager
DVDx 4.0
Facebook Video Calling 1.0.0.8953
Fraps
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
IZArc 4.1.6
Java Auto Updater
Java(TM) 6 Update 25
Junk Mail filter update
KhalInstallWrapper
Linksys WMP110 RangePlus Wireless PCI Adapter Driver - WMP110
Logitech SetPoint
LogMeIn
magicJack
magicJack Outlook Add-In 1.0.3.521
Mesh Runtime
Messenger Companion
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Antimalware
Microsoft Application Error Reporting
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Mozilla Firefox 8.0 (x86 en-US)
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Mumble 1.2.3
nProtect Security Platform
NVIDIA Away Mode Driver
NVIDIA Drivers
ParetoLogic PC Health Advisor
PerformanceTest v7.0
PowerDVD DX
PreReq
Realtek High Definition Audio Driver
RocketFish 7.1
Roxio Creator Audio
Roxio Creator Copy
Roxio Creator Data
Roxio Creator DE 10.3
Roxio Creator Tools
Roxio Express Labeler 3
Roxio Update Manager
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Segoe UI
Skins
Skype™ 5.5
Speccy
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Ventrilo Client
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
VLC media player 1.1.11
WIDCOMM Bluetooth Software
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live Messenger Companion Core
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Mobile Device Updater Component
World of Warcraft
World of Warcraft Public Test
Yahoo! Messenger
Yahoo! Software Update
Yahoo! Toolbar
Zune
Zune Language Pack (CHS)
Zune Language Pack (CHT)
Zune Language Pack (CSY)
Zune Language Pack (DAN)
Zune Language Pack (DEU)
Zune Language Pack (ELL)
Zune Language Pack (ESP)
Zune Language Pack (FIN)
Zune Language Pack (FRA)
Zune Language Pack (HUN)
Zune Language Pack (IND)
Zune Language Pack (ITA)
Zune Language Pack (JPN)
Zune Language Pack (KOR)
Zune Language Pack (MSL)
Zune Language Pack (NLD)
Zune Language Pack (NOR)
Zune Language Pack (PLK)
Zune Language Pack (PTB)
Zune Language Pack (PTG)
Zune Language Pack (RUS)
Zune Language Pack (SVE)
.
==== Event Viewer Messages From Past Week ========
.
1/2/2012 6:13:37 AM, Error: Microsoft-Windows-WMPNSS-Service [14325] - Service 'WMPNetworkSvc' did not start correctly because QueryService encountered error '0x80070424'. In Windows Media Player, turn off media sharing, and then turn it back on.
1/2/2012 6:08:16 AM, Error: Microsoft-Windows-Dhcp-Client [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 001AA06AD34A. The following error occurred: The semaphore timeout period has expired.. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
1/2/2012 6:07:03 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: cdrom Null TKFWFV
1/2/2012 6:07:03 AM, Error: Service Control Manager [7023] - The SPService service terminated with the following error: The specified module could not be found.
1/2/2012 6:07:03 AM, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.
1/2/2012 6:07:03 AM, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.
1/2/2012 6:07:03 AM, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.
1/2/2012 6:07:03 AM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
1/2/2012 6:07:03 AM, Error: Service Control Manager [7000] - The Hotspot Shield Service service failed to start due to the following error: The system cannot find the file specified.
1/2/2012 6:07:03 AM, Error: Service Control Manager [7000] - The Hotspot Shield Routing Service service failed to start due to the following error: The system cannot find the file specified.
1/2/2012 6:07:03 AM, Error: Service Control Manager [7000] - The Hotspot Shield Monitoring Service service failed to start due to the following error: The system cannot find the file specified.
.
==== End Of File ===========================


GMER ONE
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2012-01-02 11:14:45
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\00000064 ST316081 rev.4.AA
Running: w0rve4bz.exe; Driver: C:\Users\STEVEN~1\AppData\Local\Temp\pxryapog.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----


GMER TWO
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-01-02 12:22:43
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\00000064 ST316081 rev.4.AA
Running: w0rve4bz.exe; Driver: C:\Users\STEVEN~1\AppData\Local\Temp\pxryapog.sys


---- Kernel code sections - GMER 1.0.15 ----

.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8EA0B000, 0x267978, 0xE8000020]
? C:\Users\STEVEN~1\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Mozilla Firefox\firefox.exe[1136] ntdll.dll!NtProtectVirtualMemory 77BE4B84 5 Bytes JMP 0070000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[1136] ntdll.dll!NtWriteVirtualMemory 77BE54C4 5 Bytes JMP 0071000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[1136] ntdll.dll!KiUserExceptionDispatcher 77BE5BF8 5 Bytes JMP 006F000A
.text C:\Windows\system32\svchost.exe[1408] ntdll.dll!NtProtectVirtualMemory 77BE4B84 5 Bytes JMP 0049000A
.text C:\Windows\system32\svchost.exe[1408] ntdll.dll!NtWriteVirtualMemory 77BE54C4 5 Bytes JMP 004A000A
.text C:\Windows\system32\svchost.exe[1408] ntdll.dll!KiUserExceptionDispatcher 77BE5BF8 5 Bytes JMP 0044000A
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2852] USER32.dll!SetWindowLongA 76ABE7CD 5 Bytes JMP 628DC350 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2852] USER32.dll!SetWindowLongW 76AC13B4 5 Bytes JMP 628DC2E2 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2852] USER32.dll!GetWindowInfo 76AC428E 5 Bytes JMP 6268E363 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2852] USER32.dll!TrackPopupMenu 76AD14F3 5 Bytes JMP 6268E91C C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Windows\System32\ping.exe[5496] ntdll.dll!NtCreateProcess 77BE42E4 5 Bytes JMP 0091000A
.text C:\Windows\System32\ping.exe[5496] ntdll.dll!NtCreateProcessEx 77BE42F4 5 Bytes JMP 0092000A
.text C:\Windows\System32\ping.exe[5496] ntdll.dll!NtProtectVirtualMemory 77BE4B84 5 Bytes JMP 0080000A
.text C:\Windows\System32\ping.exe[5496] ntdll.dll!NtWriteVirtualMemory 77BE54C4 5 Bytes JMP 0081000A
.text C:\Windows\System32\ping.exe[5496] ntdll.dll!NtCreateUserProcess 77BE5654 5 Bytes JMP 0093000A
.text C:\Windows\System32\ping.exe[5496] ntdll.dll!KiUserExceptionDispatcher 77BE5BF8 5 Bytes JMP 007F000A
.text C:\Windows\System32\ping.exe[5496] USER32.dll!WindowFromPoint 76AB884F 5 Bytes JMP 00A0000A
.text C:\Windows\System32\ping.exe[5496] USER32.dll!GetForegroundWindow 76AC32C4 5 Bytes JMP 00A1000A
.text C:\Windows\System32\ping.exe[5496] USER32.dll!GetCursorPos 76AD0B88 5 Bytes JMP 009F000A
.text C:\Windows\System32\ping.exe[5496] ole32.dll!CoCreateInstance 76629F3E 5 Bytes JMP 009A000A

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0002721c5790 (not active ControlSet)
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0002721c5790

---- Files - GMER 1.0.15 ----

File C:\Program Files\Malwarebytes' Anti-Malware 0 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon 0 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\chameleon.chm 191200 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\firefox.com 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\firefox.exe 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\firefox.pif 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\firefox.scr 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\mbam-chameleon.com 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\mbam-chameleon.exe 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\mbam-chameleon.pif 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\mbam-chameleon.scr 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\mbam-killer.exe 984648 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\rundll32.exe 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\changes.rtf 1699 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages 0 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\hebrew.lng 18372 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\arabic.lng 20716 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\bosnian.lng 25860 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\bulgarian.lng 26296 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\catalan.lng 26822 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\chineseSI.lng 10480 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\chineseTR.lng 11384 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\croatian.lng 25546 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\czech.lng 23540 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\danish.lng 25384 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\dutch.lng 26816 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\english.lng 23390 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\estonian.lng 24112 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\finnish.lng 24580 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\french.lng 28342 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\german.lng 28506 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\hungarian.lng 27124 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\italian.lng 26812 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\latvian.lng 25804 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\lithuanian.lng 26666 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\macedonian.lng 27830 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\norwegian.lng 23864 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\polish.lng 25304 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\portugueseBR.lng 27330 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\portuguesePT.lng 27628 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\romanian.lng 26914 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\russian.lng 25952 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\serbian.lng 25606 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\slovak.lng 24392 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\slovenian.lng 23622 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\spanish.lng 28542 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\swedish.lng 24782 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\thai.lng 24952 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\turkish.lng 24640 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\vietnamese.lng 28118 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\license.txt 11141 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\mbam.chm 409786 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\mbam.dll 472136 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe 981680 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\mbamcore.dll 1080904 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll 78920 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe 460872 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\mbamnet.dll 2227784 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\mbampt.exe 39496 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 652872 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\ssubtmr6.dll 46416 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\unins000.dat 10209 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe 709968 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\unins000.msg 10498 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\vbalsgrid6.ocx 496976 bytes executable
File C:\Windows\$NtUninstallKB16587$\2617564367 0 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\@ 2048 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\bckfg.tmp 863 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\cfg.ini 208 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\Desktop.ini 4608 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\keywords 145 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\kwrd.dll 223744 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\L 0 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\L\vhtmwbun 66560 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\lsflt7.ver 5176 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\U 0 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\U\00000001.@ 2048 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\U\00000002.@ 224768 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\U\00000004.@ 1024 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\U\80000000.@ 11264 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\U\80000004.@ 12800 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\U\80000032.@ 77312 bytes
File C:\Windows\$NtUninstallKB16587$\362233610 0 bytes

---- EOF - GMER 1.0.15 ----

Member Avatar
jholland1964
Posting Expert
5,610 posts since Jul 2008
Reputation Points: 650 [?]
Q&As Helped to Solve: 343 [?]
Skill Endorsements: 3 [?]
Team Colleague
Featured
 
0
 

You have two anti-virus programs on there:
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated*
AV: Microsoft Security Essentials *Disabled/Updated*

Your log shows the TDSKiller was run, do you have a log?

We need a log from MBA-M, Fully updated Full Scan.

Member Avatar
stevensan1983
Newbie Poster
5 posts since Jan 2012
Reputation Points: 0 [?]
Q&As Helped to Solve: 0 [?]
Skill Endorsements: 0 [?]
 
0
 

these are the only logs i have posted as follows

i dont have a tdskiller log as comp auto restarted as my brother told me

DDS

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_25
Run by stevensan1983 at 11:01:07 on 2012-01-02
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.3070.1496 [GMT -6:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Lavasoft\Ad-Aware\AWSC.exe
C:\Program Files\Lavasoft\Ad-Aware\AWSC.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\RocketFish\RF7.1\Volume Panel\VolPanlu.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Lavasoft\Ad-Aware\AWSC.exe
C:\Program Files\Lavasoft\Ad-Aware\AWSC.exe
C:\Windows\System32\ping.exe
C:\Windows\system32\Taskmgr.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.hotspotshield.com/g/?c=h
uURLSearchHooks: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - c:\program files\bittorrentbar\tbBitT.dll
mURLSearchHooks: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - c:\program files\bittorrentbar\tbBitT.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
BHO: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - c:\program files\bittorrentbar\tbBitT.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
TB: BitTorrentBar Toolbar: {88c7f2aa-f93f-432c-8f0e-b7d85967a527} - c:\program files\bittorrentbar\tbBitT.dll
TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn0\yt.dll
mRun: [VolPanel] "c:\program files\rocketfish\rf7.1\volume panel\VolPanlu.exe" /r
mRun: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [Conime] %windir%\system32\conime.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
uPolicies-explorer: HideSCAHealth = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.0.1 205.171.3.25
TCP: Interfaces\{836F6CAD-66F8-46DE-BDB9-954BD07E74E8} : DhcpNameServer = 192.168.0.1 205.171.3.25
TCP: Interfaces\{C9D08C66-8C92-4206-8173-2CC27910BE31} : DhcpNameServer = 192.168.0.1 205.171.3.25
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\stevensan1983\appdata\roaming\mozilla\firefox\profiles\0ngwn008.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2956065&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Hotspot Shield Private Search
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://search.hotspotshield.com/g/results.php?c=s&q=
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\stevensan1983\appdata\local\facebook\video\skype\npFacebookVideoCalling.dll
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
.
R0 amacpi;Microsoft Away Mode System;c:\windows\system32\drivers\null.sys [2008-1-20 4608]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2011-10-11 64512]
R0 nvamacpi;NVIDIA Away Mode System;c:\windows\system32\drivers\nvamacpi.sys [2009-11-24 24680]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165648]
R1 MpKsl718b8e61;MpKsl718b8e61;c:\windows\system32\mpenginestore\MpKsl718b8e61.sys [2012-1-2 28752]
R2 AERTFilters;Andrea RT Filters Service;c:\program files\realtek\audio\hda\AERTSrv.exe [2011-5-8 81920]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R3 WMP110v2;Linksys WMP110 RangePlus Wireless PCI Adapter Driver for Windows Vista;c:\windows\system32\drivers\WMP110v2.sys [2011-5-8 338432]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 hshld;Hotspot Shield Service;c:\program files\hotspot shield\bin\openvpnas.exe --> c:\program files\hotspot shield\bin\openvpnas.exe [?]
S2 HssWd;Hotspot Shield Monitoring Service;c:\program files\hotspot shield\bin\hsswd.exe -product hss --> c:\program files\hotspot shield\bin\hsswd.exe -product HSS [?]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2011-8-18 2152152]
S2 SPService;SPService;c:\windows\system32\svchost.exe -k netsvc [2008-1-20 21504]
S3 BTWAMPFL;btwampfl;c:\windows\system32\drivers\btwampfl.sys [2011-8-6 301608]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\drivers\btwl2cap.sys [2011-8-6 33320]
S3 CEDRIVER60;CEDRIVER60;c:\program files\cheat engine 6\dbk32.sys [2011-5-9 62336]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\common files\creative labs shared\service\CTAELicensing.exe [2011-5-8 79360]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2011-5-23 39272]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-22 1493352]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2011-8-18 15232]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2010-10-24 43392]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 65024]
S3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2011-4-27 208944]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\zune\WMZuneComm.exe [2011-8-5 268512]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040]
.
=============== Created Last 30 ================
.
2012-01-02 11:31:44 -------- d-----w- c:\program files\Microsoft Games
2012-01-02 08:47:34 -------- d-----w- c:\windows\system32\MpEngineStore
2012-01-02 08:08:19 -------- d-----w- C:\TDSSKiller_Quarantine
2012-01-02 07:23:52 -------- d-----w- C:\backup
2011-12-31 04:24:52 -------- d-----w- c:\windows\system32\wbem\Logs
2011-12-25 22:57:04 -------- d-----w- c:\windows\Downloaded Program Files
2011-12-25 18:52:17 56200 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{59d5ada5-f826-4f52-a33b-0c53f3f3cff8}\offreg.dll
2011-12-25 13:47:54 6823496 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{59d5ada5-f826-4f52-a33b-0c53f3f3cff8}\mpengine.dll
2011-12-14 10:01:39 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-12-14 10:01:39 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-12-14 10:01:37 429056 ----a-w- c:\windows\system32\EncDec.dll
2011-12-14 10:01:36 2043904 ----a-w- c:\windows\system32\win32k.sys
2011-12-14 10:01:35 49152 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-14 10:01:34 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2011-12-14 10:01:31 2048 ----a-w- c:\windows\system32\tzres.dll
.
==================== Find3M ====================
.
2011-11-22 09:51:55 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-03 22:47:42 1798144 ----a-w- c:\windows\system32\jscript9.dll
2011-11-03 22:40:21 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-11-03 22:39:47 1127424 ----a-w- c:\windows\system32\wininet.dll
2011-11-03 22:31:57 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-10-11 08:17:32 16432 ----a-w- c:\windows\system32\lsdelete.exe
.
============= FINISH: 11:01:42.03 ===============

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Business
Boot Device: \Device\HarddiskVolume1
Install Date: 5/7/2011 10:16:29 PM
System Uptime: 1/2/2012 6:05:55 AM (5 hours ago)
.
Motherboard: Dell Inc. | | 0RY206
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 4400+ | Socket AM2 | 2310/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 149 GiB total, 40.745 GiB free.
E: is Removable
F: is Removable
G: is Removable
H: is Removable
I: is Removable
J: is FIXED (NTFS) - 298 GiB total, 188.095 GiB free.
K: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
.
==== Installed Programs ======================
.
32 bit Windows Card Reader Driver
Ad-Aware
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader 8.3.1
Adobe Shockwave Player 11.5
ATI Catalyst Install Manager
BioShock
BitTorrent
BitTorrentBar Toolbar
CABAL Online (NA - Global)
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center HydraVision Full
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
CDDRV_Installer
Cheat Engine 6.0
Conduit Engine
Creative MediaSource 5
Curse Client
D3DX10
Dell Driver Download Manager
DVDx 4.0
Facebook Video Calling 1.0.0.8953
Fraps
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
IZArc 4.1.6
Java Auto Updater
Java(TM) 6 Update 25
Junk Mail filter update
KhalInstallWrapper
Linksys WMP110 RangePlus Wireless PCI Adapter Driver - WMP110
Logitech SetPoint
LogMeIn
magicJack
magicJack Outlook Add-In 1.0.3.521
Mesh Runtime
Messenger Companion
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Antimalware
Microsoft Application Error Reporting
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable - KB2467175
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Mozilla Firefox 8.0 (x86 en-US)
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Mumble 1.2.3
nProtect Security Platform
NVIDIA Away Mode Driver
NVIDIA Drivers
ParetoLogic PC Health Advisor
PerformanceTest v7.0
PowerDVD DX
PreReq
Realtek High Definition Audio Driver
RocketFish 7.1
Roxio Creator Audio
Roxio Creator Copy
Roxio Creator Data
Roxio Creator DE 10.3
Roxio Creator Tools
Roxio Express Labeler 3
Roxio Update Manager
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Segoe UI
Skins
Skype™ 5.5
Speccy
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Ventrilo Client
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
VLC media player 1.1.11
WIDCOMM Bluetooth Software
Windows Live Communications Platform
Windows Live Essentials
Windows Live Family Safety
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live Messenger Companion Core
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
Windows Mobile Device Updater Component
World of Warcraft
World of Warcraft Public Test
Yahoo! Messenger
Yahoo! Software Update
Yahoo! Toolbar
Zune
Zune Language Pack (CHS)
Zune Language Pack (CHT)
Zune Language Pack (CSY)
Zune Language Pack (DAN)
Zune Language Pack (DEU)
Zune Language Pack (ELL)
Zune Language Pack (ESP)
Zune Language Pack (FIN)
Zune Language Pack (FRA)
Zune Language Pack (HUN)
Zune Language Pack (IND)
Zune Language Pack (ITA)
Zune Language Pack (JPN)
Zune Language Pack (KOR)
Zune Language Pack (MSL)
Zune Language Pack (NLD)
Zune Language Pack (NOR)
Zune Language Pack (PLK)
Zune Language Pack (PTB)
Zune Language Pack (PTG)
Zune Language Pack (RUS)
Zune Language Pack (SVE)
.
==== Event Viewer Messages From Past Week ========
.
1/2/2012 6:13:37 AM, Error: Microsoft-Windows-WMPNSS-Service [14325] - Service 'WMPNetworkSvc' did not start correctly because QueryService encountered error '0x80070424'. In Windows Media Player, turn off media sharing, and then turn it back on.
1/2/2012 6:08:16 AM, Error: Microsoft-Windows-Dhcp-Client [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 001AA06AD34A. The following error occurred: The semaphore timeout period has expired.. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
1/2/2012 6:07:03 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: cdrom Null TKFWFV
1/2/2012 6:07:03 AM, Error: Service Control Manager [7023] - The SPService service terminated with the following error: The specified module could not be found.
1/2/2012 6:07:03 AM, Error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: The specified service does not exist as an installed service.
1/2/2012 6:07:03 AM, Error: Service Control Manager [7003] - The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.
1/2/2012 6:07:03 AM, Error: Service Control Manager [7003] - The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.
1/2/2012 6:07:03 AM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
1/2/2012 6:07:03 AM, Error: Service Control Manager [7000] - The Hotspot Shield Service service failed to start due to the following error: The system cannot find the file specified.
1/2/2012 6:07:03 AM, Error: Service Control Manager [7000] - The Hotspot Shield Routing Service service failed to start due to the following error: The system cannot find the file specified.
1/2/2012 6:07:03 AM, Error: Service Control Manager [7000] - The Hotspot Shield Monitoring Service service failed to start due to the following error: The system cannot find the file specified.
.
==== End Of File ===========================

GMER ONE

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit quick scan 2012-01-02 11:14:45
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\00000064 ST316081 rev.4.AA
Running: w0rve4bz.exe; Driver: C:\Users\STEVEN~1\AppData\Local\Temp\pxryapog.sys


---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----


GMER TWO

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-01-02 12:22:43
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\00000064 ST316081 rev.4.AA
Running: w0rve4bz.exe; Driver: C:\Users\STEVEN~1\AppData\Local\Temp\pxryapog.sys


---- Kernel code sections - GMER 1.0.15 ----

.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8EA0B000, 0x267978, 0xE8000020]
? C:\Users\STEVEN~1\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Mozilla Firefox\firefox.exe[1136] ntdll.dll!NtProtectVirtualMemory 77BE4B84 5 Bytes JMP 0070000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[1136] ntdll.dll!NtWriteVirtualMemory 77BE54C4 5 Bytes JMP 0071000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[1136] ntdll.dll!KiUserExceptionDispatcher 77BE5BF8 5 Bytes JMP 006F000A
.text C:\Windows\system32\svchost.exe[1408] ntdll.dll!NtProtectVirtualMemory 77BE4B84 5 Bytes JMP 0049000A
.text C:\Windows\system32\svchost.exe[1408] ntdll.dll!NtWriteVirtualMemory 77BE54C4 5 Bytes JMP 004A000A
.text C:\Windows\system32\svchost.exe[1408] ntdll.dll!KiUserExceptionDispatcher 77BE5BF8 5 Bytes JMP 0044000A
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2852] USER32.dll!SetWindowLongA 76ABE7CD 5 Bytes JMP 628DC350 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2852] USER32.dll!SetWindowLongW 76AC13B4 5 Bytes JMP 628DC2E2 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2852] USER32.dll!GetWindowInfo 76AC428E 5 Bytes JMP 6268E363 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[2852] USER32.dll!TrackPopupMenu 76AD14F3 5 Bytes JMP 6268E91C C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
.text C:\Windows\System32\ping.exe[5496] ntdll.dll!NtCreateProcess 77BE42E4 5 Bytes JMP 0091000A
.text C:\Windows\System32\ping.exe[5496] ntdll.dll!NtCreateProcessEx 77BE42F4 5 Bytes JMP 0092000A
.text C:\Windows\System32\ping.exe[5496] ntdll.dll!NtProtectVirtualMemory 77BE4B84 5 Bytes JMP 0080000A
.text C:\Windows\System32\ping.exe[5496] ntdll.dll!NtWriteVirtualMemory 77BE54C4 5 Bytes JMP 0081000A
.text C:\Windows\System32\ping.exe[5496] ntdll.dll!NtCreateUserProcess 77BE5654 5 Bytes JMP 0093000A
.text C:\Windows\System32\ping.exe[5496] ntdll.dll!KiUserExceptionDispatcher 77BE5BF8 5 Bytes JMP 007F000A
.text C:\Windows\System32\ping.exe[5496] USER32.dll!WindowFromPoint 76AB884F 5 Bytes JMP 00A0000A
.text C:\Windows\System32\ping.exe[5496] USER32.dll!GetForegroundWindow 76AC32C4 5 Bytes JMP 00A1000A
.text C:\Windows\System32\ping.exe[5496] USER32.dll!GetCursorPos 76AD0B88 5 Bytes JMP 009F000A
.text C:\Windows\System32\ping.exe[5496] ole32.dll!CoCreateInstance 76629F3E 5 Bytes JMP 009A000A

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0002721c5790 (not active ControlSet)
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0002721c5790

---- Files - GMER 1.0.15 ----

File C:\Program Files\Malwarebytes' Anti-Malware 0 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon 0 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\chameleon.chm 191200 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\firefox.com 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\firefox.exe 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\firefox.pif 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\firefox.scr 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\mbam-chameleon.com 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\mbam-chameleon.exe 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\mbam-chameleon.pif 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\mbam-chameleon.scr 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\mbam-killer.exe 984648 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\rundll32.exe 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe 182856 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\changes.rtf 1699 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages 0 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\hebrew.lng 18372 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\arabic.lng 20716 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\bosnian.lng 25860 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\bulgarian.lng 26296 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\catalan.lng 26822 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\chineseSI.lng 10480 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\chineseTR.lng 11384 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\croatian.lng 25546 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\czech.lng 23540 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\danish.lng 25384 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\dutch.lng 26816 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\english.lng 23390 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\estonian.lng 24112 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\finnish.lng 24580 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\french.lng 28342 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\german.lng 28506 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\hungarian.lng 27124 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\italian.lng 26812 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\latvian.lng 25804 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\lithuanian.lng 26666 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\macedonian.lng 27830 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\norwegian.lng 23864 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\polish.lng 25304 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\portugueseBR.lng 27330 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\portuguesePT.lng 27628 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\romanian.lng 26914 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\russian.lng 25952 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\serbian.lng 25606 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\slovak.lng 24392 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\slovenian.lng 23622 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\spanish.lng 28542 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\swedish.lng 24782 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\thai.lng 24952 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\turkish.lng 24640 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\Languages\vietnamese.lng 28118 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\license.txt 11141 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\mbam.chm 409786 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\mbam.dll 472136 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe 981680 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\mbamcore.dll 1080904 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll 78920 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe 460872 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\mbamnet.dll 2227784 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\mbampt.exe 39496 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 652872 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\ssubtmr6.dll 46416 bytes executable
File C:\Program Files\Malwarebytes' Anti-Malware\unins000.dat 10209 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe 709968 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\unins000.msg 10498 bytes
File C:\Program Files\Malwarebytes' Anti-Malware\vbalsgrid6.ocx 496976 bytes executable
File C:\Windows\$NtUninstallKB16587$\2617564367 0 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\@ 2048 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\bckfg.tmp 863 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\cfg.ini 208 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\Desktop.ini 4608 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\keywords 145 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\kwrd.dll 223744 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\L 0 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\L\vhtmwbun 66560 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\lsflt7.ver 5176 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\U 0 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\U\00000001.@ 2048 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\U\00000002.@ 224768 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\U\00000004.@ 1024 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\U\80000000.@ 11264 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\U\80000004.@ 12800 bytes
File C:\Windows\$NtUninstallKB16587$\2617564367\U\80000032.@ 77312 bytes
File C:\Windows\$NtUninstallKB16587$\362233610 0 bytes

---- EOF - GMER 1.0.15 ----


COMBO FIX

ComboFix 12-01-02.01 - stevensan1983 01/02/2012 18:17:20.1.2 - x86
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.3070.2157 [GMT -6:00]
Running from: c:\users\stevensan1983\Desktop\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\$NtUninstallKB16587$
c:\windows\$NtUninstallKB16587$\2617564367\@
c:\windows\$NtUninstallKB16587$\2617564367\bckfg.tmp
c:\windows\$NtUninstallKB16587$\2617564367\cfg.ini
c:\windows\$NtUninstallKB16587$\2617564367\Desktop.ini
c:\windows\$NtUninstallKB16587$\2617564367\keywords
c:\windows\$NtUninstallKB16587$\2617564367\kwrd.dll
c:\windows\$NtUninstallKB16587$\2617564367\L\vhtmwbun
c:\windows\$NtUninstallKB16587$\2617564367\lsflt7.ver
c:\windows\$NtUninstallKB16587$\2617564367\U\00000001.@
c:\windows\$NtUninstallKB16587$\2617564367\U\00000002.@
c:\windows\$NtUninstallKB16587$\2617564367\U\00000004.@
c:\windows\$NtUninstallKB16587$\2617564367\U\80000000.@
c:\windows\$NtUninstallKB16587$\2617564367\U\80000004.@
c:\windows\$NtUninstallKB16587$\2617564367\U\80000032.@
c:\windows\$NtUninstallKB16587$\362233610
c:\windows\bwUnin-8.1.1.50-8876480SL.exe
c:\windows\system32\tmpA469.tmp
c:\windows\system32\tmpA525.tmp
.
Infected copy of c:\windows\system32\drivers\smb.sys was found and disinfected
Restored copy from - The cat found it :)
.
((((((((((((((((((((((((( Files Created from 2011-12-03 to 2012-01-03 )))))))))))))))))))))))))))))))
.
.
2012-01-02 17:21 . 2012-01-02 17:21 -------- d-----w- c:\users\stevensan1983\AppData\Roaming\Malwarebytes
2012-01-02 17:21 . 2012-01-02 17:21 -------- d-----w- c:\programdata\Malwarebytes
2012-01-02 17:21 . 2012-01-02 17:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-01-02 17:21 . 2011-12-10 21:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-01-02 11:31 . 2012-01-02 11:31 -------- d-----w- c:\program files\Microsoft Games
2012-01-02 08:47 . 2012-01-02 18:54 -------- d-----w- c:\windows\system32\MpEngineStore
2012-01-02 08:08 . 2012-01-02 08:08 -------- d-----w- C:\TDSSKiller_Quarantine
2012-01-02 07:23 . 2012-01-02 07:24 -------- d-----w- C:\backup
2011-12-31 04:24 . 2011-12-31 04:25 -------- d-----w- c:\windows\system32\wbem\Logs
2011-12-31 04:24 . 2012-01-02 08:46 -------- d-----w- c:\windows\Debug
2011-12-25 22:57 . 2011-12-25 22:57 -------- d-----w- c:\windows\Downloaded Program Files
2011-12-25 18:52 . 2011-12-25 19:42 56200 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{59D5ADA5-F826-4F52-A33B-0C53F3F3CFF8}\offreg.dll
2011-12-25 13:47 . 2011-11-21 10:47 6823496 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{59D5ADA5-F826-4F52-A33B-0C53F3F3CFF8}\mpengine.dll
2011-12-14 10:01 . 2011-10-27 08:01 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-12-14 10:01 . 2011-10-27 08:01 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-12-14 10:01 . 2011-10-14 16:02 429056 ----a-w- c:\windows\system32\EncDec.dll
2011-12-14 10:01 . 2011-11-23 13:37 2043904 ----a-w- c:\windows\system32\win32k.sys
2011-12-14 10:01 . 2011-10-25 15:56 49152 ----a-w- c:\windows\system32\csrsrv.dll
2011-12-14 10:01 . 2011-11-08 12:10 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-12-14 10:01 . 2011-11-08 14:42 2048 ----a-w- c:\windows\system32\tzres.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-22 09:51 . 2011-05-15 21:07 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-21 10:47 . 2011-05-10 00:59 6823496 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-10-11 13:54 . 2011-10-11 13:55 703824 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{61B90A9B-4618-4555-B1FC-123D24F8E589}\gapaengine.dll
2011-10-11 08:17 . 2011-10-13 11:02 16432 ----a-w- c:\windows\system32\lsdelete.exe
2011-11-10 05:50 . 2011-05-08 18:01 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files\BitTorrentBar\tbBitT.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2010-12-09 17:51 3911776 ----a-w- c:\program files\ConduitEngine\ConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
2010-12-09 17:51 3911776 ----a-w- c:\program files\BitTorrentBar\tbBitT.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{88c7f2aa-f93f-432c-8f0e-b7d85967a527}"= "c:\program files\BitTorrentBar\tbBitT.dll" [2010-12-09 3911776]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\ConduitEngine.dll" [2010-12-09 3911776]
.
[HKEY_CLASSES_ROOT\clsid\{88c7f2aa-f93f-432c-8f0e-b7d85967a527}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VolPanel"="c:\program files\RocketFish\RF7.1\Volume Panel\VolPanlu.exe" [2008-11-25 237693]
"P17RunE"="P17RunE.dll" [2008-03-28 14848]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-02-11 61440]
"Conime"="c:\windows\system32\conime.exe" [2009-04-11 69120]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-08-31 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-24 460872]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
R1 MpKsl05e6d156;MpKsl05e6d156;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{53845928-87C0-4184-8BE8-7A1F3C7D5EB7}\MpKsl05e6d156.sys [x]
R1 MpKsl3944bb57;MpKsl3944bb57;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{63A9A96B-2E08-4B2F-9DC0-D1AC9962B502}\MpKsl3944bb57.sys [x]
R1 MpKsl82826d39;MpKsl82826d39;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3ECE8236-4D98-42C8-B53D-B4EE536A3146}\MpKsl82826d39.sys [x]
R1 MpKsle0aa829f;MpKsle0aa829f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{32727CDB-5CB9-4D88-8678-DB1618F8A3F1}\MpKsle0aa829f.sys [x]
R1 MpKsle0bfaac9;MpKsle0bfaac9;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3ECE8236-4D98-42C8-B53D-B4EE536A3146}\MpKsle0bfaac9.sys [x]
R1 TKFWFV;nProtect Firewall Core Driver ;c:\windows\system32\TKFWFV.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 hshld;Hotspot Shield Service;c:\program files\Hotspot Shield\bin\openvpnas.exe [x]
R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe [x]
R3 BTWAMPFL;BTWAMPFL;c:\windows\system32\DRIVERS\btwampfl.sys [2010-12-24 301608]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-12-24 33320]
R3 CEDRIVER60;CEDRIVER60;c:\program files\Cheat Engine 6\dbk32.sys [2010-12-16 62336]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2011-05-08 79360]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [2011-08-18 15232]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2011-04-26 4213816]
R3 NTProcDrv;Process creation detector for NT.;c:\users\stevensan1983\Desktop\cabal\NtProcDrv.sys [x]
R3 TKFsAvM;TKFsAvM;c:\windows\system32\TKFsAv.sys [x]
R3 TkFsFtM;MiniFilter Driver;c:\windows\system32\TKFsFt.sys [x]
R3 TKFWVT;TKFWVT;c:\windows\system32\TKFWVT.sys [x]
R3 TkIdsVt;TkIdsVt;c:\windows\system32\TkIdsVt.sys [x]
R3 TKPcFt;TKPcFt;c:\windows\system32\TKPcFtCb.sys [x]
R3 WMZuneComm;Zune Windows Mobile Connectivity Service;c:\program files\Zune\WMZuneComm.exe [2011-08-05 268512]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
S0 amacpi;Microsoft Away Mode System;c:\windows\system32\DRIVERS\null.sys [2008-01-21 4608]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2011-08-18 64512]
S0 nvamacpi;NVIDIA Away Mode System;c:\windows\system32\DRIVERS\NVAMACPI.sys [2009-11-24 24680]
S2 AERTFilters;Andrea RT Filters Service;c:\program files\Realtek\Audio\HDA\AERTSrv.exe [2008-09-25 81920]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2011-10-28 2152152]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-12-24 652872]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-12-10 20464]
S3 WMP110v2;Linksys WMP110 RangePlus Wireless PCI Adapter Driver for Windows Vista;c:\windows\system32\DRIVERS\WMP110v2.sys [2008-06-05 338432]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
bthsvcs REG_MULTI_SZ BthServ
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-02 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2053659261-1753765920-3353709293-1000Core.job
- c:\users\stevensan1983\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-11-02 22:13]
.
2012-01-02 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2053659261-1753765920-3353709293-1000UA.job
- c:\users\stevensan1983\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-11-02 22:13]
.
2012-01-03 c:\windows\Tasks\ParetoLogic Registration3.job
- c:\program files\Common Files\ParetoLogic\UUS3\UUS3.dll [2011-03-29 23:17]
.
2011-12-24 c:\windows\Tasks\ParetoLogic Update Version3.job
- c:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2011-03-29 23:17]
.
2011-12-24 c:\windows\Tasks\PC Health Advisor Defrag.job
- c:\program files\ParetoLogic\PCHA\PCHA.exe [2011-10-25 21:30]
.
2012-01-02 c:\windows\Tasks\PC Health Advisor.job
- c:\program files\ParetoLogic\PCHA\PCHA.exe [2011-10-25 21:30]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.hotspotshield.com/g/?c=h
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.0.1 205.171.3.25
FF - ProfilePath - c:\users\stevensan1983\AppData\Roaming\Mozilla\Firefox\Profiles\0ngwn008.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2956065&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Hotspot Shield Private Search
FF - prefs.js: browser.startup.homepage - www.google.com
FF - prefs.js: keyword.URL - hxxp://search.hotspotshield.com/g/results.php?c=s&q=
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-WudfPf
SafeBoot-WudfRd
SafeBoot-MsMpSvc
.
.
.
**************************************************************************
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files:
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2053659261-1753765920-3353709293-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:3d,a7,37,08,33,99,2e,d5,6b,9f,83,62,2a,6d,09,56,74,47,b4,59,19,c6,e2,
ed,47,29,3b,8a,43,f0,af,f2,2a,b7,a6,47,09,13,54,f2,98,f3,8c,b5,91,99,ad,73,\
"??"=hex:cf,55,c7,95,2b,14,4d,f8,66,7b,0c,1b,19,52,fe,22
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(5424)
c:\program files\WIDCOMM\Bluetooth Software\btncopy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Creative\Shared Files\CTAudSvc.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\WIDCOMM\Bluetooth Software\btwdins.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\System32\rundll32.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2012-01-02 18:36:08 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-03 00:36
.
Pre-Run: 43,010,777,088 bytes free
Post-Run: 43,187,355,648 bytes free
.
- - End Of File - - EC31CA962185944688423250B9E4B7E3

Member Avatar
stevensan1983
Newbie Poster
5 posts since Jan 2012
Reputation Points: 0 [?]
Q&As Helped to Solve: 0 [?]
Skill Endorsements: 0 [?]
 
0
 

i had issues running MBA-M so i have a few logs i will condense and post in a sec

MBA-A

Malwarebytes Anti-Malware (Trial) 1.60.0.1800
www.malwarebytes.org

Database version: v2012.01.02.04

Windows Vista Service Pack 2 x86 NTFS (Safe Mode)
Internet Explorer 9.0.8112.16421
stevensan1983 :: STEVENSAN198-PC [administrator]

Protection: Disabled

1/2/2012 1:00:21 PM
mbam-log-2012-01-02 (13-00-21).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 349085
Time elapsed: 44 minute(s), 26 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 3
HKCR\AH (Rogue.MultipleAV) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\sp (TrojanProxy.Agent) -> Quarantined and deleted successfully.
HKLM\System\CurrentControlSet\Services\SPService (TrojanProxy.Agent) -> Quarantined and deleted successfully.

Registry Values Detected: 2
HKCR\ah|Content Type (Rogue.MultipleAV) -> Data: application/x-msdownload -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost|netsvc (TrojanProxy.Agent) -> Data: SPService^^ -> Quarantined and deleted successfully.

Registry Data Items Detected: 3
HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command| (Hijack.StartMenuInternet) -> Bad: ("C:\Users\stevensan1983\AppData\Local\xsq.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe") Good: (firefox.exe) -> Quarantined and repaired successfully.
HKLM\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command| (Hijack.StartMenuInternet) -> Bad: ("C:\Users\stevensan1983\AppData\Local\xsq.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode) Good: (firefox.exe -safe-mode) -> Quarantined and repaired successfully.
HKLM\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command| (Hijack.StartMenuInternet) -> Bad: ("C:\Users\stevensan1983\AppData\Local\xsq.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe") Good: (iexplore.exe) -> Quarantined and repaired successfully.

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Users\stevensan1983\Downloads\SoftonicDownloader_for_kaspersky-tdsskiller.exe (PUP.BundleOffer.Downloader.S) -> Quarantined and deleted successfully.

(end)

Malwarebytes Anti-Malware (Trial) 1.60.0.1800
www.malwarebytes.org

Database version: v2012.01.02.04

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
stevensan1983 :: STEVENSAN198-PC [administrator]

Protection: Disabled

1/2/2012 12:48:55 PM
mbam-log-2012-01-02 (12-48-55).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 47054
Time elapsed: 4 minute(s), 8 second(s) [aborted]

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{96AFBE69-C3B0-4b00-8578-D933D2896EE2} (TrojanProxy.Agent) -> Data: -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved|{96AFBE69-C3B0-4b00-8578-D933D2896EE2} (TrojanProxy.Agent) -> Data: sp -> Quarantined and deleted successfully.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

Member Avatar
stevensan1983
Newbie Poster
5 posts since Jan 2012
Reputation Points: 0 [?]
Q&As Helped to Solve: 0 [?]
Skill Endorsements: 0 [?]
 
0
 

since coming home from work and all scans finished i have not seen the ping.exe pop up not sure if its fixed or not i will advise further if it does pop up some more i know tat you commented that i have two av's i have microsoft sec installed but it is currently disabled and i normaly dont enable it as for the other one i use it regularly but it has many flaws obveusly lets stuff through if you could recomend a good freeware av and other security software would be much appriciated

Question Answered as of 2 Years Ago by jholland1964
You
This question has already been solved: Start a new discussion instead
Post:
Start New Discussion
Tags Related to this Article