Buy Malwarebytes antimalware











This site is hosted at Hostgator.com




Sponsored Adverts

Sponsored Ads

These adverts come direct from Google adsense



Welcome to The Spykiller

You need to register to  get help with malware cleaning on your computer or take part in the general discussion forums and to upload files that have been requested from other forums. Unfortunately we are getting massive spam attacks from allowing guest postings to uploads
It takes a very long time and a lot of hard work on our part to read all the logs posted here and research and prepare the fixes for you. In many cases each part of the fix takes about 30 minutes to prepare so a large part of our time is spent helping you

 INSTRUCTIONS - Read This Before Posting For Malware Removal Help

Author Topic: I can't open control panel on vista HiJackThis log attached  (Read 4323 times)

amanda520

  • Guest
I can't open control panel on vista HiJackThis log attached
« on: December 07, 2009, 12:38:27 »
I tried SFC but could find no errors, can someone check my HiJackThis log please? Thanks.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:30:26 PM, on 12/7/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18319)
Boot mode: Normal

Running processes:
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Windows\Pixart\Pac7302\Monitor.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Windows\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Tencent\QQ\TXPlatform.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\Dwm.exe
D:\Games\Steam.exe
C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Tencent\QQ\QQ.exe
C:\Windows\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe

F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,C:\Windows\system32\config\systemprofile\AppData\Roaming\sdra64.exe,
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [PAC7302_Monitor] C:\Windows\PixArt\PAC7302\Monitor.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Steam] "d:\games\steam.exe" -silent
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: ??QQ.lnk = C:\Program Files\Tencent\QQ\QQ.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: ???QQ?? - C:\Program Files\Tencent\QQ\AddEmotion.htm
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - ESC Trusted Zone: http://*.update.microsoft.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - BioWare - d:\games\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

--
End of file - 9890 bytes


Offline Derek

  • Administrator
  • *****
  • Posts: 11927
Re: I can't open control panel on vista HiJackThis log attached
« Reply #1 on: December 07, 2009, 20:53:39 »
Delete any existing version of ComboFix you have sitting on your desktop
Please read and follow all these instructions very carefully

Download ComboFix from Here to your Desktop.

**Note:  It is important that it is saved directly to your desktop  and run from the desktop and not any other folder on your computer**
--------------------------------------------------------------------
1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • Very Important! Temporarily disable your anti-virus and  anti-malware real-time protection and any script blocking components of them or your firewall before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results" or stop combofix running at all
  • Click on THIS LINK to see instructions on how to temporarily disable many security programs while running combofix. The list does not cover every program. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again after combofix has finished
--------------------------------------------------------------------
2. Close any open browsers and any other programs you might have running
Double click on combofix.exe & follow the prompts.
If you are using windows XP It might display a pop up saying that "Recovery console is not installed, do you want to install?"
Please select yes & let it download the files it needs to do this
When finished, it will produce a report for you. 
Please post the "C:\ComboFix.txt" for further review


****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell us when you reply. Read HERE why we disable autoruns

Please do not install any new programs or update anything (always allow your antivirus/antispyware to update) unless told to do so while we are fixing your problem. If combofix alerts to a new version and offers to update, please let it. It is essential we always use the latest version. 
Derek
Microsoft MVP  Windows - Security
Modern Malware is so involved and difficult to fix that it takes a very long time and a lot of hard work and research to prepare the fixes for you. A large part of my time is spent helping you
Would you do all this for nothing?
 I run this site to raise funds for Hedgehog Rescue
Please donate if I have helped you or you have found this site useful.

amanda520

  • Guest
Re: I can't open control panel on vista HiJackThis log attached
« Reply #2 on: December 08, 2009, 00:31:51 »
I am running Vista btw.

I tried that combofix program but everytime I ran it, I got the blue screen of death during the scanning or whatever after my computer restarted. Also I can't find combofix.txt file, probably due to incomplete scanning. I have however found a ComboFix icon that brings me back to My Computer everytime I click it, and a Qoobox folder that I was aware of until just now, so I suspect that was from the ComboFix program?

Please advice.

Offline Derek

  • Administrator
  • *****
  • Posts: 11927
Re: I can't open control panel on vista HiJackThis log attached
« Reply #3 on: December 09, 2009, 14:39:32 »
lets see if these will show why Combofix is crashing out

follow advice here and post the logs those programs make
Derek
Microsoft MVP  Windows - Security
Modern Malware is so involved and difficult to fix that it takes a very long time and a lot of hard work and research to prepare the fixes for you. A large part of my time is spent helping you
Would you do all this for nothing?
 I run this site to raise funds for Hedgehog Rescue
Please donate if I have helped you or you have found this site useful.

amanda520

  • Guest
Re: I can't open control panel on vista HiJackThis log attached
« Reply #4 on: December 10, 2009, 13:37:42 »
I also got a message that says: You will no longer receive notifications, including those about your license or activation. Use the link below to find out how to fix your system.

Here is the log from the guide above:


DDS (Ver_09-12-01.01) - NTFSx86 
Run by A CHIANG at 12:11:28.27 on 12/10/2009 Thu
Internet Explorer: 7.0.6001.18000 BrowserJavaVersion: 1.6.0_12
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\rundll32.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\config\systemprofile\AppData\Roaming\sdra64.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Windows\Pixart\Pac7302\Monitor.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
D:\Games\Steam.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\wuauclt.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Windows\System32\svchost.exe -k NetworkService
C:\Windows\explorer.exe
C:\Program Files\Tencent\QQ\TXPlatform.exe
C:\Program Files\Tencent\QQ\QQ.exe
C:\Windows\system32\conime.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Users\A CHIANG\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://ffo.qq.com/index.shtml?ADTAG=GameClient.Link.LK.lk02
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\config\systemprofile\appdata\roaming\sdra64.exe,c:\windows\system32\sdra64.exe,
mWinlogon: SFCDisable=4 (0x4)
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: NCO 2.0 IE BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\common files\symantec shared\coshared\browser\2.6\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Show Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\common files\symantec shared\coshared\browser\2.6\CoIEPlg.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [Steam] "d:\games\steam.exe" -silent
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [VolPanel] "c:\program files\creative\sound blaster x-fi\volume panel\VolPanlu.exe" /r
mRun: [P17RunE] RunDll32 P17RunE.dll,RunDLLEntry
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RemoteControl8] "c:\program files\cyberlink\powerdvd8\PDVD8Serv.exe"
mRun: [PDVD8LanguageShortcut] "c:\program files\cyberlink\powerdvd8\language\Language.exe"
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe"  -osboot
mRun: [PAC7302_Monitor] c:\windows\pixart\pac7302\Monitor.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [osCheck] "c:\program files\norton 360\osCheck.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
StartupFolder: c:\users\achian~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\??qq.lnk - c:\program files\tencent\qq\QQ.exe
uPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: ???QQ?? - c:\program files\tencent\qq\AddEmotion.htm
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: {4032B3B8-C4C8-43F5-8EEB-B903685213A9} = 155.198.142.7 155.198.142.8

================= FIREFOX ===================

FF - ProfilePath - c:\users\achian~1\appdata\roaming\mozilla\firefox\profiles\bnaoykgm.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - prefs.js: browser.startup.homepage - www.facebook.com
FF - component: c:\program files\mozilla firefox\components\coFFPlgn.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R0 QKeyService;QKeyServiceDisplay;c:\windows\system32\KeyCrypt.sys [2009-10-11 11648]
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\symantec\defini~1\symcdata\ipsdefs\20091120.002\IDSvix86.sys [2009-12-1 286768]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\common files\symantec shared\CCSVCHST.EXE [2008-2-18 149352]
R2 StarWindService;StarWind iSCSI Service;c:\program files\alcohol soft\alcohol 120\starwind\StarWindService.exe [2005-4-2 217600]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-10-13 102448]
R3 Symantec Core LC;Symantec Core LC;c:\progra~1\common~1\symant~1\ccpd-lc\symlcsvc.exe [2009-1-25 1245064]
R3 SYMNDISV;SYMNDISV;c:\windows\system32\drivers\symndisv.sys [2009-2-19 41008]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-1-13 23888]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;d:\games\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe [2009-11-10 25832]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\lavalys\everest home edition\kerneld.wnt [2005-8-18 7168]
S3 TesDrvPt;TesDrvPt;c:\windows\system32\TesDrvPt.sys [2009-10-11 15952]
S3 TesSafe;TesSafe;c:\windows\system32\TesSafe.sys [2009-10-11 158256]

============== File Associations ===============

txtfile=c:\windows\notepad.exe %1

=============== Created Last 30 ================

2009-12-09 04:36:41   0   d-----w-   c:\users\achian~1\appdata\roaming\SafeBase
2009-12-08 10:42:54   0   d-----w-   c:\programdata\Windows Genuine Advantage
2009-12-08 01:15:04   0   d-----w-   c:\programdata\WindowsSearch
2009-12-08 00:18:14   0   d-s---w-   C:\ComboFix
2009-12-08 00:09:11   98816   ----a-w-   c:\windows\sed.exe
2009-12-08 00:09:11   77312   ----a-w-   c:\windows\MBR.exe
2009-12-08 00:09:11   260608   ----a-w-   c:\windows\PEV.exe
2009-12-08 00:09:11   161792   ----a-w-   c:\windows\SWREG.exe
2009-12-07 22:23:01   26600   ----a-w-   c:\windows\system32\drivers\GEARAspiWDM.sys
2009-12-07 22:23:01   107368   ----a-w-   c:\windows\system32\GEARAspi.dll
2009-12-07 22:22:27   0   d-----w-   c:\program files\iPod
2009-12-07 22:22:26   0   d-----w-   c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-07 22:22:26   0   d-----w-   c:\program files\iTunes
2009-12-07 17:31:57   532   ----a-w-   c:\windows\eReg.dat
2009-12-07 12:41:22   2048   ----a-w-   c:\windows\system32\tzres.dll
2009-12-07 12:41:06   453456   ----a-w-   c:\windows\system32\d3dx10_42.dll
2009-12-07 12:41:06   1892184   ----a-w-   c:\windows\system32\D3DX9_42.dll
2009-12-07 12:30:02   0   d-----w-   c:\program files\Trend Micro
2009-12-07 11:41:45   0   d-sh--w-   c:\windows\system32\lowsec
2009-11-25 08:10:57   1399296   ----a-w-   c:\windows\system32\msxml6.dll
2009-11-25 08:10:57   1257472   ----a-w-   c:\windows\system32\msxml3.dll
2009-11-25 08:10:54   714240   ----a-w-   c:\windows\system32\timedate.cpl
2009-11-25 00:57:04   0   d-----w-   c:\users\achian~1\appdata\roaming\QQMusicUpdate
2009-11-19 18:51:07   0   d-----w-   c:\programdata\Real
2009-11-16 03:24:52   0   d-----w-   c:\windows\SQLTools9_KB970892_ENU
2009-11-16 03:23:47   0   d-----w-   c:\windows\SQL9_KB970892_ENU
2009-11-16 03:20:04   97800   ----a-w-   c:\windows\system32\infocardapi.dll
2009-11-16 03:20:04   622080   ----a-w-   c:\windows\system32\icardagt.exe
2009-11-16 03:20:04   43544   ----a-w-   c:\windows\system32\PresentationHostProxy.dll
2009-11-16 03:20:04   37384   ----a-w-   c:\windows\system32\infocardcpl.cpl
2009-11-16 03:20:04   11264   ----a-w-   c:\windows\system32\icardres.dll
2009-11-16 03:20:04   105016   ----a-w-   c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-11-16 03:20:03   781344   ----a-w-   c:\windows\system32\PresentationNative_v0300.dll
2009-11-16 03:20:01   326160   ----a-w-   c:\windows\system32\PresentationHost.exe
2009-11-16 03:15:45   96760   ----a-w-   c:\windows\system32\dfshim.dll
2009-11-16 03:15:43   282112   ----a-w-   c:\windows\system32\mscoree.dll
2009-11-16 03:15:42   41984   ----a-w-   c:\windows\system32\netfxperf.dll
2009-11-16 03:15:36   158720   ----a-w-   c:\windows\system32\mscorier.dll
2009-11-16 03:15:33   83968   ----a-w-   c:\windows\system32\mscories.dll
2009-11-14 13:43:35   0   d-----w-   c:\programdata\BioWare
2009-11-14 13:24:35   0   d-----w-   c:\program files\Microsoft Office Outlook Connector
2009-11-12 18:58:47   0   d-----w-   c:\program files\Refworks
2009-11-11 17:04:15   2035712   ----a-w-   c:\windows\system32\win32k.sys
2009-11-11 17:04:02   351232   ----a-w-   c:\windows\system32\WSDApi.dll
2009-11-10 23:08:24   94208   ----a-w-   c:\windows\system32\QuickTimeVR.qtx
2009-11-10 23:08:24   69632   ----a-w-   c:\windows\system32\QuickTime.qts

==================== Find3M  ====================

2009-12-07 22:19:48   86016   ----a-w-   c:\windows\inf\infstor.dat
2009-12-07 22:19:48   51200   ----a-w-   c:\windows\inf\infpub.dat
2009-12-07 22:19:47   86016   ----a-w-   c:\windows\inf\infstrng.dat
2009-12-01 14:59:54   158256   ----a-w-   c:\windows\system32\TesSafe.sys
2009-11-06 10:59:54   15406728   ----a-w-   c:\windows\system32\xlive.dll
2009-11-06 10:59:54   13642888   ----a-w-   c:\windows\system32\xlivefnt.dll
2009-11-02 18:05:36   167064   ----a-w-   c:\windows\system32\xliveinstall.dll
2009-11-02 18:05:34   71832   ----a-w-   c:\windows\system32\xliveinstallhost.exe
2009-10-15 16:29:41   0   ---ha-w-   c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-10-11 15:37:57   15952   ----a-w-   c:\windows\system32\TesDrvPt.sys
2008-07-31 10:59:49   665600   ----a-w-   c:\windows\inf\drvindex.dat
2008-01-21 02:43:21   174   --sha-w-   c:\program files\desktop.ini
2006-11-02 12:42:02   30674   ----a-w-   c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02   30674   ----a-w-   c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02   287440   ----a-w-   c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02   287440   ----a-w-   c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21   287440   ----a-w-   c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21   287440   ----a-w-   c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19   30674   ----a-w-   c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19   30674   ----a-w-   c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 12:12:20.16 ===============


[attachment deleted by admin]

Offline Derek

  • Administrator
  • *****
  • Posts: 11927
Re: I can't open control panel on vista HiJackThis log attached
« Reply #5 on: December 10, 2009, 16:54:27 »
see what this can clean first


Please download Malwarebytes' Anti-Malware to your desktop
from HERE or HERE

Double-click mbam-setup.exe and follow the prompts to install the program. At the end, be sure a checkmark is placed next to the following:

Update Malwarebytes' Anti-Malware. Launch Malwarebytes' Anti-Malware. Then click Finish.

If an update is found, it will download and install the latest version. Press Update to make sure the latest database is loaded.
Once the program has loaded, select Perform quick scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad.
Please include this log in your next reply.

It might ask you to reboot to finish cleaning. Please do so. ( Press YES on the alert) 
If you receive an (Error Loading xxxxxxxxxx .dll) error on reboot please reboot a second time . It is normal for this error to occur once and does not need to be reported unless it continues on every boot 
Derek
Microsoft MVP  Windows - Security
Modern Malware is so involved and difficult to fix that it takes a very long time and a lot of hard work and research to prepare the fixes for you. A large part of my time is spent helping you
Would you do all this for nothing?
 I run this site to raise funds for Hedgehog Rescue
Please donate if I have helped you or you have found this site useful.

amanda520

  • Guest
Re: I can't open control panel on vista HiJackThis log attached
« Reply #6 on: December 10, 2009, 17:16:33 »
Here is the log. Thanks:

Malwarebytes' Anti-Malware 1.42
Database version: 3339
Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000

12/10/2009 5:16:01 PM
mbam-log-2009-12-10 (17-16-01).txt

Scan type: Quick Scan
Objects scanned: 100728
Time elapsed: 6 minute(s), 12 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 1
Registry Data Items Infected: 3
Folders Infected: 1
Files Infected: 4

Memory Processes Infected:
C:\Windows\System32\sdra64.exe (Spyware.Zbot) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6} (Trojan.Zbot) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\uid (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Spyware.Zbot) -> Data: c:\windows\system32\sdra64.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Spyware.Zbot) -> Data: system32\sdra64.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\Windows\system32\userinit.exe,C:\Windows\system32\config\systemprofile\AppData\Roaming\sdra64.exe,C:\Windows\system32\sdra64.exe,) Good: (Userinit.exe) -> Quarantined and deleted successfully.

Folders Infected:
C:\Windows\System32\lowsec (Stolen.data) -> Delete on reboot.

Files Infected:
C:\Windows\System32\lowsec\local.ds (Stolen.data) -> Delete on reboot.
C:\Windows\System32\lowsec\user.ds (Stolen.data) -> Delete on reboot.
C:\Windows\System32\lowsec\user.ds.lll (Stolen.data) -> Quarantined and deleted successfully.
C:\Windows\System32\sdra64.exe (Spyware.Zbot) -> Delete on reboot.

amanda520

  • Guest
Re: I can't open control panel on vista HiJackThis log attached
« Reply #7 on: December 10, 2009, 20:10:06 »
Ok a little update, my computer seems to fine now without showing the error message, and I can once again acess my control panel (the error usually happens a while after I turn on my computer everytime). But I am still getting random popups from sites that don't normally have them....

Offline Derek

  • Administrator
  • *****
  • Posts: 11927
Re: I can't open control panel on vista HiJackThis log attached
« Reply #8 on: December 11, 2009, 08:21:40 »
reboot first then

see if combofix will run now

first delete existing combofix from desktop & then download an updated version from same link
Derek
Microsoft MVP  Windows - Security
Modern Malware is so involved and difficult to fix that it takes a very long time and a lot of hard work and research to prepare the fixes for you. A large part of my time is spent helping you
Would you do all this for nothing?
 I run this site to raise funds for Hedgehog Rescue
Please donate if I have helped you or you have found this site useful.

amanda520

  • Guest
Re: I can't open control panel on vista HiJackThis log attached
« Reply #9 on: December 11, 2009, 13:26:30 »
Combo Fix log. Oh and sorry for the chinese, it seems to be using the default language on the computer. I'll try to find someone to translate them if necessary.

ComboFix 09-12-10.01 - A CHIANG 1/2009 Fri  11:23:45.3.8 - x86
????: c:\users\A CHIANG\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

(((((((((((((((((((((((((((((((((((((((   ??????   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\AutoRun.inf
c:\windows\system32\Data
c:\windows\system32\images
c:\windows\system32\images\toolbar\calendar.gif
c:\windows\system32\images\toolbar\crlogo.gif
c:\windows\system32\images\toolbar\export.gif
c:\windows\system32\images\toolbar\export_over.gif
c:\windows\system32\images\toolbar\exportd.gif
c:\windows\system32\images\toolbar\First.gif
c:\windows\system32\images\toolbar\first_over.gif
c:\windows\system32\images\toolbar\Firstd.gif
c:\windows\system32\images\toolbar\gotopage.gif
c:\windows\system32\images\toolbar\gotopage_over.gif
c:\windows\system32\images\toolbar\gotopaged.gif
c:\windows\system32\images\toolbar\grouptree.gif
c:\windows\system32\images\toolbar\grouptree_over.gif
c:\windows\system32\images\toolbar\grouptreed.gif
c:\windows\system32\images\toolbar\grouptreepressed.gif
c:\windows\system32\images\toolbar\Last.gif
c:\windows\system32\images\toolbar\last_over.gif
c:\windows\system32\images\toolbar\Lastd.gif
c:\windows\system32\images\toolbar\Next.gif
c:\windows\system32\images\toolbar\next_over.gif
c:\windows\system32\images\toolbar\Nextd.gif
c:\windows\system32\images\toolbar\Prev.gif
c:\windows\system32\images\toolbar\prev_over.gif
c:\windows\system32\images\toolbar\Prevd.gif
c:\windows\system32\images\toolbar\print.gif
c:\windows\system32\images\toolbar\print_over.gif
c:\windows\system32\images\toolbar\printd.gif
c:\windows\system32\images\toolbar\Refresh.gif
c:\windows\system32\images\toolbar\refresh_over.gif
c:\windows\system32\images\toolbar\refreshd.gif
c:\windows\system32\images\toolbar\Search.gif
c:\windows\system32\images\toolbar\search_over.gif
c:\windows\system32\images\toolbar\searchd.gif
c:\windows\system32\images\toolbar\up.gif
c:\windows\system32\images\toolbar\up_over.gif
c:\windows\system32\images\toolbar\upd.gif
c:\windows\system32\images\tree\begindots.gif
c:\windows\system32\images\tree\beginminus.gif
c:\windows\system32\images\tree\beginplus.gif
c:\windows\system32\images\tree\blank.gif
c:\windows\system32\images\tree\blankdots.gif
c:\windows\system32\images\tree\dots.gif
c:\windows\system32\images\tree\lastdots.gif
c:\windows\system32\images\tree\lastminus.gif
c:\windows\system32\images\tree\lastplus.gif
c:\windows\system32\images\tree\Magnify.gif
c:\windows\system32\images\tree\minus.gif
c:\windows\system32\images\tree\minusbox.gif
c:\windows\system32\images\tree\plus.gif
c:\windows\system32\images\tree\plusbox.gif
c:\windows\system32\images\tree\singleminus.gif
c:\windows\system32\images\tree\singleplus.gif
F:\autorun.inf

.
(((((((((((((((((((((((((((((((((((((((   ??/??   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_TesSafe


(((((((((((((((((((((((((  2009-11-11 ? 2009-12-11 ?????  )))))))))))))))))))))))))))))))
.

2009-12-11 11:31 . 2009-12-11 11:34   --------   d-----w-   c:\users\A CHIANG\AppData\Local\temp
2009-12-11 11:31 . 2009-12-11 11:31   --------   d-----w-   c:\users\Default\AppData\Local\temp
2009-12-11 11:17 . 2009-12-11 11:18   --------   d-----w-   C:\32788R22FWJFW
2009-12-10 17:07 . 2009-12-10 17:07   --------   d-----w-   c:\users\A CHIANG\AppData\Roaming\Malwarebytes
2009-12-10 17:06 . 2009-12-03 16:13   19160   ----a-w-   c:\windows\system32\drivers\mbam.sys
2009-12-10 17:06 . 2009-12-03 16:14   38224   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-10 17:06 . 2009-12-10 17:08   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2009-12-10 17:06 . 2009-12-10 17:06   --------   d-----w-   c:\programdata\Malwarebytes
2009-12-09 04:36 . 2009-12-09 04:36   --------   d-----w-   c:\users\A CHIANG\AppData\Roaming\SafeBase
2009-12-08 01:15 . 2009-12-08 01:15   --------   d-----w-   c:\programdata\WindowsSearch
2009-12-07 22:23 . 2009-05-18 14:17   26600   ----a-w-   c:\windows\system32\drivers\GEARAspiWDM.sys
2009-12-07 22:23 . 2008-04-17 13:12   107368   ----a-w-   c:\windows\system32\GEARAspi.dll
2009-12-07 22:22 . 2009-12-07 22:22   --------   d-----w-   c:\program files\iPod
2009-12-07 22:22 . 2009-12-07 22:23   --------   d-----w-   c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-07 22:22 . 2009-12-07 22:23   --------   d-----w-   c:\program files\iTunes
2009-12-07 22:21 . 2009-12-07 22:21   --------   d-----w-   c:\program files\QuickTime
2009-12-07 17:31 . 2009-12-07 17:40   532   ----a-w-   c:\windows\eReg.dat
2009-12-07 12:41 . 2009-10-29 09:41   2048   ----a-w-   c:\windows\system32\tzres.dll
2009-12-07 12:41 . 2009-09-04 17:29   453456   ----a-w-   c:\windows\system32\d3dx10_42.dll
2009-12-07 12:41 . 2009-09-04 17:29   1892184   ----a-w-   c:\windows\system32\D3DX9_42.dll
2009-12-07 12:30 . 2009-12-07 12:30   --------   d-----w-   c:\program files\Trend Micro
2009-11-25 08:10 . 2009-08-10 11:01   1399296   ----a-w-   c:\windows\system32\msxml6.dll
2009-11-25 08:10 . 2009-08-10 11:00   1257472   ----a-w-   c:\windows\system32\msxml3.dll
2009-11-25 00:57 . 2009-11-25 00:57   --------   d-----w-   c:\users\A CHIANG\AppData\Roaming\QQMusicUpdate
2009-11-16 03:24 . 2009-11-16 03:24   --------   d-----w-   c:\windows\SQLTools9_KB970892_ENU
2009-11-16 03:23 . 2009-11-16 03:23   --------   d-----w-   c:\windows\SQL9_KB970892_ENU
2009-11-16 03:20 . 2008-06-20 01:14   43544   ----a-w-   c:\windows\system32\PresentationHostProxy.dll
2009-11-16 03:20 . 2008-06-20 01:14   105016   ----a-w-   c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-11-16 03:20 . 2008-06-20 01:14   97800   ----a-w-   c:\windows\system32\infocardapi.dll
2009-11-16 03:20 . 2008-06-20 01:14   11264   ----a-w-   c:\windows\system32\icardres.dll
2009-11-16 03:20 . 2008-06-20 01:14   622080   ----a-w-   c:\windows\system32\icardagt.exe
2009-11-16 03:20 . 2008-06-20 01:14   781344   ----a-w-   c:\windows\system32\PresentationNative_v0300.dll
2009-11-16 03:20 . 2008-06-20 01:14   326160   ----a-w-   c:\windows\system32\PresentationHost.exe
2009-11-16 03:15 . 2008-07-27 18:03   96760   ----a-w-   c:\windows\system32\dfshim.dll
2009-11-16 03:15 . 2008-07-27 18:03   282112   ----a-w-   c:\windows\system32\mscoree.dll
2009-11-16 03:15 . 2008-07-27 18:03   41984   ----a-w-   c:\windows\system32\netfxperf.dll
2009-11-16 03:15 . 2008-07-27 18:03   158720   ----a-w-   c:\windows\system32\mscorier.dll
2009-11-16 03:15 . 2008-07-27 18:03   83968   ----a-w-   c:\windows\system32\mscories.dll
2009-11-14 13:43 . 2009-11-14 13:43   --------   d-----w-   c:\programdata\BioWare
2009-11-14 13:24 . 2009-11-14 13:24   --------   d-----w-   c:\program files\Microsoft Office Outlook Connector
2009-11-12 18:58 . 2009-11-12 18:58   --------   d-----w-   c:\program files\Refworks
2009-11-11 17:04 . 2009-08-14 13:53   2035712   ----a-w-   c:\windows\system32\win32k.sys
2009-11-11 17:04 . 2009-08-10 13:05   351232   ----a-w-   c:\windows\system32\WSDApi.dll

.
((((((((((((((((((((((((((((((((((((((((   ???????????   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-11 11:31 . 2009-02-02 08:40   12   ----a-w-   c:\windows\bthservsdp.dat
2009-12-11 11:16 . 2009-01-25 01:16   --------   d-----w-   c:\users\A CHIANG\AppData\Roaming\uTorrent
2009-12-11 09:08 . 2009-01-26 12:04   --------   d-----w-   c:\users\A CHIANG\AppData\Roaming\dvdcss
2009-12-10 17:24 . 2009-12-09 04:38   31048   ----a-w-   c:\users\A CHIANG\AppData\Roaming\QQ\59B848686BA6270269CE15953350482D\SafeBase\selfupdate.exe
2009-12-10 17:07 . 2009-12-10 17:07   4844295   ----a-w-   c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-09 09:00 . 2009-12-11 09:46   2747440   ----a-w-   c:\programdata\Symantec\Definitions\VirusDefs\20091210.041\CCERASER.DLL
2009-12-09 09:00 . 2009-12-11 01:40   2747440   ----a-w-   c:\programdata\Symantec\Definitions\VirusDefs\20091210.023\CCERASER.DLL
2009-12-09 04:37 . 2009-12-09 04:37   31048   ----a-w-   c:\users\A CHIANG\AppData\Roaming\SafeBase\_temp\SelfUpdate.exe
2009-12-09 04:10 . 2009-01-21 11:37   --------   d-----w-   c:\users\A CHIANG\AppData\Roaming\Apple Computer
2009-12-07 23:14 . 2009-01-21 11:31   --------   d-----w-   c:\programdata\Apple
2009-12-07 22:22 . 2009-01-25 13:03   --------   d-----w-   c:\program files\Common Files\Apple
2009-12-07 22:22 . 2009-01-25 13:04   --------   d-----w-   c:\programdata\Apple Computer
2009-12-07 21:47 . 2009-12-07 21:47   79144   ----a-w-   c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-12-07 18:51 . 2009-12-07 18:51   439816   ----a-w-   c:\users\A CHIANG\AppData\Roaming\Real\Update\setup3.09\setup.exe
2009-12-07 15:39 . 2009-01-17 13:34   1356   ----a-w-   c:\users\A CHIANG\AppData\Local\d3d9caps.dat
2009-12-01 14:59 . 2009-10-11 15:37   158256   ----a-w-   c:\windows\system32\TesSafe.sys
2009-11-25 00:57 . 2009-01-24 21:31   --------   d-----w-   c:\users\A CHIANG\AppData\Roaming\Tencent
2009-11-25 00:56 . 2009-02-14 03:18   --------   d-----w-   c:\programdata\Tencent
2009-11-20 03:02 . 2009-12-01 05:19   268664   ----a-w-   c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20091120.002\SymIDSco.sys
2009-11-20 03:02 . 2009-11-20 03:02   268664   ----a-w-   c:\programdata\Symantec\Definitions\SymcData\ipsdefs\BinHub\symidsco.sys
2009-11-20 03:02 . 2009-12-01 05:19   732536   ----a-w-   c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20091120.002\Scxpx86.dll
2009-11-20 03:02 . 2009-12-01 05:19   286768   ----a-w-   c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20091120.002\IDSvix86.sys
2009-11-20 03:02 . 2009-12-01 05:19   173432   ----a-w-   c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20091120.002\SymIDSI.dll
2009-11-20 03:02 . 2009-11-20 03:02   732536   ----a-w-   c:\programdata\Symantec\Definitions\SymcData\ipsdefs\BinHub\scxpx86.dll
2009-11-20 03:02 . 2009-11-20 03:02   286768   ----a-w-   c:\programdata\Symantec\Definitions\SymcData\ipsdefs\BinHub\IDSvix86.sys
2009-11-20 03:02 . 2009-11-20 03:02   173432   ----a-w-   c:\programdata\Symantec\Definitions\SymcData\ipsdefs\BinHub\SymIDSI.dll
2009-11-20 03:02 . 2009-12-01 05:19   685432   ----a-w-   c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20091120.002\IDSxpx86.dll
2009-11-20 03:02 . 2009-12-01 05:19   396336   ----a-w-   c:\programdata\Symantec\Definitions\SymcData\ipsdefs\20091120.002\IDSviA64.sys
2009-11-20 03:02 . 2009-11-20 03:02   685432   ----a-w-   c:\programdata\Symantec\Definitions\SymcData\ipsdefs\BinHub\idsxpx86.dll
2009-11-20 03:02 . 2009-11-20 03:02   396336   ----a-w-   c:\programdata\Symantec\Definitions\SymcData\ipsdefs\BinHub\IDSvia64.sys
2009-11-18 01:41 . 2008-07-31 10:46   --------   d--h--w-   c:\program files\InstallShield Installation Information
2009-11-16 03:38 . 2006-11-02 11:18   --------   d-----w-   c:\program files\Windows Mail
2009-11-16 03:28 . 2009-02-22 20:05   --------   d-----w-   c:\programdata\Microsoft Help
2009-11-16 03:28 . 2009-02-22 20:17   1680064   ----a-w-   c:\programdata\Microsoft\VisualStudio\9.0\1033\ResourceCache.dll
2009-11-16 03:25 . 2009-02-22 20:21   --------   d-----w-   c:\program files\Microsoft SQL Server
2009-11-16 03:12 . 2009-02-22 20:17   18368   ----a-w-   c:\programdata\Microsoft\VSA\9.0\1033\ResourceCache.dll
2009-11-14 13:42 . 2009-01-17 13:43   --------   d-----w-   c:\program files\Common Files\Wise Installation Wizard
2009-11-14 13:42 . 2009-01-17 13:43   --------   d-----w-   c:\program files\AGEIA Technologies
2009-11-14 13:23 . 2009-01-25 11:36   --------   d-----w-   c:\program files\Windows Live
2009-11-14 13:22 . 2009-02-22 20:20   --------   d-----w-   c:\program files\Microsoft SQL Server Compact Edition
2009-11-14 13:20 . 2009-01-25 11:37   --------   d-----w-   c:\program files\Microsoft
2009-11-06 10:59 . 2009-11-06 10:59   15406728   ----a-w-   c:\windows\system32\xlive.dll
2009-11-06 10:59 . 2009-11-06 10:59   13642888   ----a-w-   c:\windows\system32\xlivefnt.dll
2009-11-02 22:48 . 2009-01-25 01:51   --------   d-----w-   c:\program files\Common Files\Steam
2009-11-02 18:05 . 2009-11-02 18:05   167064   ----a-w-   c:\windows\system32\xliveinstall.dll
2009-11-02 18:05 . 2009-11-02 18:05   71832   ----a-w-   c:\windows\system32\xliveinstallhost.exe
2009-10-29 22:29 . 2009-01-20 15:33   --------   d-----w-   c:\programdata\Nero
2009-10-29 22:29 . 2009-01-20 15:33   --------   d-----w-   c:\program files\Common Files\Nero
2009-10-16 23:23 . 2009-01-24 21:31   31048   ------r-   c:\users\A CHIANG\AppData\Roaming\Tencent\QQ\SafeBase\selfupdate.exe
2009-10-15 16:29 . 2009-10-15 16:29   0   ---ha-w-   c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-10-13 00:21 . 2009-10-13 00:21   10134   ----a-r-   c:\users\A CHIANG\AppData\Roaming\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-10-13 00:21 . 2009-10-13 00:21   --------   d-----w-   c:\program files\Microsoft WSE
2009-10-11 15:37 . 2009-10-11 15:37   15952   ----a-w-   c:\windows\system32\TesDrvPt.sys
2009-10-11 08:00 . 2009-12-11 09:46   259440   ----a-w-   c:\programdata\Symantec\Definitions\VirusDefs\20091210.041\ECMSVR32.DLL
2009-10-11 08:00 . 2009-12-11 01:40   259440   ----a-w-   c:\programdata\Symantec\Definitions\VirusDefs\20091210.023\ECMSVR32.DLL
2009-09-30 13:58 . 2008-02-18 19:38   9576   ----a-w-   c:\programdata\Symantec\LiveUpdate\LuRegManifests\Static\CCMSLLUM.DLL
2009-09-14 09:44 . 2009-10-14 04:51   144896   ----a-w-   c:\windows\system32\drivers\srv2.sys
2009-03-31 21:47 . 2009-01-25 11:07   324976   ----a-w-   c:\program files\mozilla firefox\components\coFFPlgn.dll
.

(((((((((((((((((((((((((((((((((((((   ?????   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*??* ???????????????
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="d:\games\steam.exe" [2009-10-25 1217808]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"RtHDVCpl"="RtHDVCpl.exe" [2007-09-19 4702208]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2007-02-28 180224]
"P17RunE"="P17RunE.dll" [2007-04-09 14848]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-26 13683232]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-26 92704]
"RemoteControl8"="c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-03-20 83240]
"PDVD8LanguageShortcut"="c:\program files\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 50472]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-01-21 185896]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]

c:\users\A CHIANG\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
??QQ.lnk - c:\program files\Tencent\QQ\QQ.exe [2009-7-1 1988008]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

R0 QKeyService;QKeyServiceDisplay;c:\windows\System32\KeyCrypt.sys [10/11/2009 3:38 PM 11648]
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20091120.002\IDSvix86.sys [12/1/2009 5:19 AM 286768]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2/18/2008 7:37 PM 149352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [10/13/2009 11:04 AM 102448]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [2/19/2009 11:31 AM 41008]
S3 COH_Mon;COH_Mon;c:\windows\System32\drivers\COH_Mon.sys [1/13/2008 2:32 AM 23888]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;d:\games\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe [11/10/2009 3:16 AM 25832]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt [8/18/2005 7168]
S3 TesDrvPt;TesDrvPt;c:\windows\System32\TesDrvPt.sys [10/11/2009 3:37 PM 15952]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - COMHOST

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs   REG_MULTI_SZ      BthServ
WindowsMobile   REG_MULTI_SZ      wcescomm rapimgr
LocalServiceRestricted   REG_MULTI_SZ      WcesComm RapiMgr
.
------- ????? -------
.
uStart Page = hxxp://ffo.qq.com/index.shtml?ADTAG=GameClient.Link.LK.lk02
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: ???QQ?? - c:\program files\Tencent\QQ\AddEmotion.htm
TCP: {4032B3B8-C4C8-43F5-8EEB-B903685213A9} = 155.198.142.7 155.198.142.8
FF - ProfilePath - c:\users\A CHIANG\AppData\Roaming\Mozilla\Firefox\Profiles\bnaoykgm.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - prefs.js: browser.startup.homepage - www.facebook.com
FF - component: c:\program files\Mozilla Firefox\components\coFFPlgn.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- ?????? ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
.
------- ???? -------
.
txtfile=c:\windows\notepad.exe %1
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
HKCU-Run-LightScribe Control Panel - c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
HKLM-Run-NBKeyScan - c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
AddRemove-QQó??· - d:\mygames\Tencent\QQGAME\Uninstall.EXE



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-11 11:34
Windows 6.0.6001 Service Pack 1 NTFS

???????? ???  

????????? ???

???????? ???  

????
??????: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x85884618]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0x8a5ad322
\Driver\ACPI -> acpi.sys @ 0x807c2d4c
\Driver\atapi -> 0x857971f8
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->Warning: possible MBR rootkit infection !
user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-691425603-4024494106-2681200341-1000\Software\Microsoft\Internet Explorer\MenuExt\??0RQ*Q*h?`]
@Allowed: (Read) (RestrictedCode)
@="c:\\Program Files\\Tencent\\QQ\\AddEmotion.htm"
"contexts"=dword:00000002

[HKEY_USERS\S-1-5-21-691425603-4024494106-2681200341-1000\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Q*Q*?1u{^?]
@Allowed: (Read) (RestrictedCode)
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,00,00,00,00,00,00,00,01,fc,83,
   e9,92,4a,ca,01,0e,00,00,00,44,00,3a,00,5c,00,4d,00,79,00,20,00,47,00,61,00,\
"Changed"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Q*Q*2*0*0*8*ck_Hr\Components\SectionQQ]
"Installed"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Q*Q*?1u{^?]
"DisplayName"="QQ????"
"UninstallString"="d:\\MYGAME~1\\QQFFO\\UNWISE.EXE d:\\MYGAME~1\\QQFFO\\INSTALL.LOG"

[HKEY_LOCAL_MACHINE\SOFTWARE\Tencent\Q*Q*?1u{^?\SYS]
"path"="d:\\MYGAME~1\\QQFFO"
"PathRoot"="d:\\MYGAME~1\\QQFFO"
"install"="d:\\MYGAME~1\\QQFFO\\qqffo.exe"
.
--------------------- ??????????? ---------------------

- - - - - - - > 'Explorer.exe'(5172)
c:\windows\System32\NLSData0009.dll
c:\windows\system32\OneX.DLL
c:\windows\System32\SyncCenter.dll
.
------------------------ ?????? ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\conime.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\rundll32.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
????: 2009-12-11  11:41:12 - ???????
ComboFix-quarantined-files.txt  2009-12-11 11:41

Pre-Run: 9,874,690,048 bytes free
Post-Run: 9,388,535,808 bytes free

- - End Of File - - B714ACDE21D756C253CE1E05AFF5E88A

 

Donations

You have come to The Spykiller for help because your Antivirus or Antispyware hasn't been able to fix your problem.

Modern Malware has become so involved and difficult to fix that it takes a very long time and a lot of hard work to read all the logs posted here and research and prepare the fixes for you. In many cases each part of the fix takes about 30 minutes to prepare, so a large part of my time is spent helping you

Would you do all this for nothing?

The reason I run this site is to raise funds for Hedgehog Rescue

Please donate if I have helped you or you have found this site useful.

You can donate safely and securely by using the paypal service, just click on one of the buttons below.

To donate in UK £

To donate in US$

To donate in Euro €

Any amount no matter how small is gratefully accepted and needed to ensure we keep the Rescue Centre running

To donate via paypal when the button doesn't appear or the link doesn't work: just go to www.paypal.com or your country's paypal log in page and chose send money and use help@thehedgehog.co.uk as recipient email address and select other service as the option. then follow prompts


Useful Advice and Programs

Stop killing hedgehogs with strimmers
Welcome, Guest. Please login or register.
Did you miss your activation email?
May 23, 2013, 04:28:13

Login with username, password and session length

secunia Software inspector


RoboForm: Learn more...

You have come to The Spykiller for help because your Antivirus or Antispyware hasn't been able to fix your problem.

Modern Malware is so involved and difficult to fix that it takes a very long time and a lot of hard work to read all the logs posted here and research and prepare the fixes for you.
In many cases each part of the fix takes about 30 minutes to prepare, so a large part of my time is spent helping you

Would you do all this for nothing?

I run this site to help raise funds for Hedgehog Rescue

Please donate if I have helped you or you have found this site useful.

You can donate safely and securely by using the PayPal service, just click on one of the buttons below.

To donate in UK £

To donate in US$

To donate in Euro €

Any amount no matter how small is gratefully accepted and needed to ensure we keep the Rescue Centre running