Internet lags, is it a virus?

Page 1 of 2 1, 2  Next

View previous topic View next topic Go down

Internet lags, is it a virus?

Post by Vladimir on Sun Apr 11, 2010 7:37 pm

My Internet lags, can you help me to see to it if it is a virus causing the problem?



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Belahzur on Sun Apr 11, 2010 10:42 pm

Download [You must be registered and logged in to see this link.] by OldTimer to your Desktop.

  • Close all windows and double click OTL.exe
  • Click Run Scan and let the program run uninterrupted
  • It will produce two logs for you, one will pop up - OTL.txt, the other will be saved on your Desktop - Extras.txt. Post both logs in this thread.
  • You may need to use two posts to get it all.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Tue Apr 13, 2010 1:18 am

I used a malware program and removed one trojan, I think that it is fixed, but to make sure I will be back shortly when I will have a lil bit more time.

Thanks



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Tue Apr 13, 2010 3:51 pm

OTL logfile created on: 13/4/2010 6:44:34 μμ - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\User\Επιφάνεια εργασίας
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000408 | Country: Ελλάδα | Language: ELL | Date Format: d/M/yyyy

3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 80,00% Memory free
4,00 Gb Paging File | 4,00 Gb Available in Paging File | 87,00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149,05 Gb Total Space | 48,65 Gb Free Space | 32,64% Space Free | Partition Type: NTFS
Drive D: | 149,05 Gb Total Space | 121,07 Gb Free Space | 81,23% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 642,26 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HP11546321382
Current User Name: User
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/04/13 18:43:44 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Επιφάνεια εργασίας\OTL.exe
PRC - [2010/04/04 23:37:17 | 000,908,248 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/03/30 11:16:12 | 001,107,336 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
PRC - [2009/10/30 14:57:08 | 000,369,200 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe
PRC - [2009/06/05 16:22:08 | 000,574,720 | ---- | M] (Panda Security, S.L.) -- C:\Program Files\Panda Security\Panda Global Protection 2010\ApVxdWin.exe
PRC - [2009/06/01 13:26:26 | 000,173,312 | ---- | M] (Panda Security, S.L.) -- C:\Program Files\Panda Security\Panda Global Protection 2010\PsCtrlS.exe
PRC - [2009/05/28 12:12:04 | 000,196,864 | ---- | M] (Panda Security, S.L.) -- C:\Program Files\Panda Security\Panda Global Protection 2010\AVENGINE.EXE
PRC - [2009/05/28 12:11:40 | 000,290,048 | ---- | M] (Panda Security, S.L.) -- C:\Program Files\Panda Security\Panda Global Protection 2010\PAVSRV51.EXE
PRC - [2009/05/19 12:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009/04/28 09:21:38 | 000,169,216 | ---- | M] (Panda Security, S.L.) -- C:\Program Files\Panda Security\Panda Global Protection 2010\PavFnSvr.exe
PRC - [2009/04/23 12:31:16 | 000,107,776 | ---- | M] (Panda Security, S.L.) -- C:\Program Files\Panda Security\Panda Global Protection 2010\WebProxy.exe
PRC - [2009/04/21 09:12:52 | 000,111,872 | ---- | M] (Panda Security, S.L.) -- C:\Program Files\Panda Security\Panda Global Protection 2010\PavBckPT.exe
PRC - [2009/04/17 10:17:24 | 000,157,440 | ---- | M] (Panda Security, S.L.) -- C:\Program Files\Panda Security\Panda Global Protection 2010\TPSrv.exe
PRC - [2009/04/08 10:56:24 | 000,226,560 | ---- | M] (Panda Security International) -- c:\Program Files\Panda Security\Panda Global Protection 2010\FIREWALL\PSHost.exe
PRC - [2009/02/23 20:43:12 | 000,576,000 | ---- | M] (MagicISO, Inc.) -- C:\Program Files\MagicDisc\MagicDisc.exe
PRC - [2008/07/02 16:16:16 | 000,397,312 | ---- | M] (Sony Ericsson Mobile Communications AB) -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
PRC - [2008/06/27 13:23:00 | 000,091,392 | ---- | M] (Panda Security, S.L.) -- C:\Program Files\Panda Security\Panda Global Protection 2010\SrvLoad.exe
PRC - [2008/06/25 15:43:08 | 000,028,928 | ---- | M] (Panda Security, S.L.) -- C:\Program Files\Panda Security\Panda Global Protection 2010\psksvc.exe
PRC - [2008/06/19 12:59:50 | 000,108,288 | ---- | M] (Panda Security S.L.) -- C:\Program Files\Panda Security\Panda Global Protection 2010\PsImSvc.exe
PRC - [2008/04/14 19:30:35 | 001,038,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/02/04 17:26:48 | 000,062,768 | ---- | M] (Panda Security, S.L.) -- C:\Program Files\Common Files\Panda Security\PavShld\PavPrSrv.exe
PRC - [2007/12/21 22:52:56 | 000,405,504 | ---- | M] ([You must be registered and logged in to see this link.] -- C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
PRC - [2007/08/07 11:59:50 | 000,540,184 | ---- | M] (PDF Complete Inc) -- C:\Program Files\PDF Complete\pdfsvc.exe
PRC - [2007/08/07 11:59:48 | 000,331,288 | ---- | M] (PDF Complete Inc) -- C:\Program Files\PDF Complete\pdfsty.exe
PRC - [2007/03/28 01:07:42 | 000,593,920 | R--- | M] () -- C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
PRC - [2007/02/28 10:55:18 | 000,880,640 | R--- | M] (Sony Ericsson Mobile Communications AB) -- C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
PRC - [2007/02/09 17:03:38 | 000,983,040 | R--- | M] (Teleca AB) -- C:\Program Files\Common Files\Teleca Shared\Generic.exe
PRC - [2006/10/06 20:35:21 | 000,049,152 | ---- | M] (infolearn) -- C:\WINDOWS\system32\infolearnasrv.exe
PRC - [2006/09/10 22:56:24 | 000,218,032 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
PRC - [2006/07/22 01:46:54 | 000,167,936 | ---- | M] (FarStone Technology Inc.) -- C:\Program Files\FarStone\GameDrive\GDP\gdtask.exe
PRC - [2005/11/16 11:00:00 | 000,122,880 | ---- | M] (WinZip Computing LP) -- C:\Program Files\WinZip\WZQKPICK.EXE
PRC - [2003/09/01 14:42:50 | 000,176,128 | ---- | M] (HP) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
PRC - [2003/08/29 02:22:30 | 000,131,072 | ---- | M] (InterVideo Inc.) -- C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
PRC - [2003/06/25 12:24:48 | 000,049,152 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd.exe
PRC - [2003/05/21 19:37:08 | 000,229,437 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe


========== Modules (SafeList) ==========

MOD - [2010/04/13 18:43:44 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Επιφάνεια εργασίας\OTL.exe
MOD - [2009/03/30 18:22:58 | 000,518,400 | ---- | M] (Panda Security, S.L.) -- C:\WINDOWS\system32\PavSHook.dll
MOD - [2009/03/18 19:18:48 | 000,095,488 | ---- | M] (Panda Security, S.L.) -- C:\Program Files\Panda Security\Panda Global Protection 2010\PavOEpl.dll
MOD - [2008/01/26 23:33:02 | 000,499,712 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcp71.dll
MOD - [2008/01/26 23:33:02 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvcr71.dll
MOD - [2007/02/08 10:53:40 | 000,107,568 | ---- | M] (Panda Software) -- C:\WINDOWS\system32\SYSTOOLS.DLL


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (NPFMntor)
SRV - File not found [Auto | Stopped] -- -- (Automatic LiveUpdate Scheduler)
SRV - [2010/03/30 11:16:12 | 001,107,336 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2009/08/05 23:48:42 | 000,704,864 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2009/06/01 13:26:26 | 000,173,312 | ---- | M] (Panda Security, S.L.) [Auto | Running] -- C:\Program Files\Panda Security\Panda Global Protection 2010\PsCtrls.exe -- (Panda Software Controller)
SRV - [2009/05/28 12:11:40 | 000,290,048 | ---- | M] (Panda Security, S.L.) [Auto | Running] -- C:\Program Files\Panda Security\Panda Global Protection 2010\pavsrv51.exe -- (PAVSRV)
SRV - [2009/05/19 12:36:18 | 000,240,512 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
SRV - [2009/04/28 09:21:38 | 000,169,216 | ---- | M] (Panda Security, S.L.) [Auto | Running] -- C:\Program Files\Panda Security\Panda Global Protection 2010\PavFnSvr.exe -- (PAVFNSVR)
SRV - [2009/04/17 10:17:24 | 000,157,440 | ---- | M] (Panda Security, S.L.) [Auto | Running] -- C:\Program Files\Panda Security\Panda Global Protection 2010\TPSrv.exe -- (TPSrv)
SRV - [2009/04/08 10:56:24 | 000,226,560 | ---- | M] (Panda Security International) [Auto | Running] -- c:\program files\panda security\panda global protection 2010\firewall\PSHOST.EXE -- (PSHost)
SRV - [2008/07/02 14:09:36 | 000,060,160 | ---- | M] (Panda Security, S.L.) [Auto | Running] -- C:\Program Files\Panda Security\Panda Global Protection 2010\GWMsrv.dll -- (Gwmsrv)
SRV - [2008/06/25 15:43:08 | 000,028,928 | ---- | M] (Panda Security, S.L.) [Auto | Running] -- C:\Program Files\Panda Security\Panda Global Protection 2010\PskSvc.exe -- (PskSvcRetail)
SRV - [2008/06/19 12:59:50 | 000,108,288 | ---- | M] (Panda Security S.L.) [Auto | Running] -- C:\Program Files\Panda Security\Panda Global Protection 2010\PsImSvc.exe -- (PSIMSVC)
SRV - [2008/02/04 17:26:48 | 000,062,768 | ---- | M] (Panda Security, S.L.) [Auto | Running] -- C:\Program Files\Common Files\Panda Security\PavShld\pavprsrv.exe -- (PavPrSrv)
SRV - [2007/08/07 11:59:50 | 000,540,184 | ---- | M] (PDF Complete Inc) [Auto | Running] -- C:\Program Files\PDF Complete\pdfsvc.exe -- (pdfcDispatcher)
SRV - [2006/10/06 20:35:21 | 000,049,152 | ---- | M] (infolearn) [Auto | Running] -- C:\WINDOWS\system32\infolearnasrv.exe -- (INFOlearn_admin_srv)
SRV - [2006/07/12 07:17:14 | 000,118,784 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\FarStone\GameDrive\LiveUpdate.exe -- (LiveUpdate)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Running] -- -- (PavTPK.sys)
DRV - File not found [Kernel | On_Demand | Running] -- -- (PavSRK.sys)
DRV - File not found [File_System | On_Demand | Running] -- -- (AvFlt)
DRV - [2010/04/13 17:06:56 | 000,013,880 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\COMFiltr.sys -- (ComFiltr)
DRV - [2009/12/01 15:30:14 | 000,078,848 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\SSHDRV85.sys -- (SSHDRV85)
DRV - [2009/10/28 14:23:55 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009/10/27 16:26:24 | 000,281,760 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\atksgt.sys -- (atksgt)
DRV - [2009/10/27 16:26:23 | 000,025,888 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2009/09/27 17:12:22 | 007,655,872 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2009/09/23 10:41:58 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hamachi.sys -- (hamachi)
DRV - [2009/08/05 23:48:42 | 000,054,752 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
DRV - [2009/06/02 13:12:02 | 000,177,416 | ---- | M] (Panda Security, S.L.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\PavProc.sys -- (PavProc)
DRV - [2009/02/24 19:42:14 | 000,116,736 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mcdbus.sys -- (mcdbus)
DRV - [2008/07/11 14:58:26 | 000,158,848 | ---- | M] (Panda Security, S.L.) [TDI Layer] [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\NETFLTDI.SYS -- (NETFLTDI)
DRV - [2008/07/07 10:40:49 | 000,056,108 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2008/06/26 11:25:28 | 000,197,888 | ---- | M] (Panda Security, S.L.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\neti1634.sys -- (NETIMFLT01060034)
DRV - [2008/06/25 15:42:18 | 000,073,728 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\APPFLT.SYS -- (APPFLT)
DRV - [2008/06/19 17:24:30 | 000,028,544 | ---- | M] (Panda Security, S.L.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\pavboot.sys -- (pavboot)
DRV - [2008/06/18 16:06:10 | 000,046,720 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\wnmflt.sys -- (WNMFLT)
DRV - [2008/06/18 16:06:04 | 000,193,792 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\idsflt.sys -- (IDSFLT)
DRV - [2008/06/18 16:06:02 | 000,052,992 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\dsaflt.sys -- (DSAFLT)
DRV - [2008/05/27 12:41:46 | 000,122,152 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017mdm.sys -- (s0017mdm)
DRV - [2008/05/27 12:41:46 | 000,117,672 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017unic.sys -- (s0017unic) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM)
DRV - [2008/05/27 12:41:46 | 000,111,912 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017obex.sys -- (s0017obex)
DRV - [2008/05/27 12:41:46 | 000,090,536 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017bus.sys -- (s0017bus) Sony Ericsson Device 0017 driver (WDM)
DRV - [2008/05/27 12:41:46 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017mdfl.sys -- (s0017mdfl)
DRV - [2008/05/27 12:41:44 | 000,115,496 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017mgmt.sys -- (s0017mgmt) Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM)
DRV - [2008/05/27 12:41:44 | 000,025,768 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0017nd5.sys -- (s0017nd5) Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS)
DRV - [2008/05/16 13:33:14 | 000,115,752 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0016unic.sys -- (s0016unic) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM)
DRV - [2008/05/16 13:33:14 | 000,025,512 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0016nd5.sys -- (s0016nd5) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS)
DRV - [2008/05/16 13:33:14 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0016mdfl.sys -- (s0016mdfl)
DRV - [2008/05/16 13:33:12 | 000,120,744 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0016mdm.sys -- (s0016mdm)
DRV - [2008/05/16 13:33:12 | 000,114,216 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0016mgmt.sys -- (s0016mgmt) Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM)
DRV - [2008/05/16 13:33:12 | 000,110,632 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0016obex.sys -- (s0016obex)
DRV - [2008/05/16 13:33:12 | 000,089,256 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s0016bus.sys -- (s0016bus) Sony Ericsson Device 0016 driver (WDM)
DRV - [2008/05/04 02:16:35 | 000,075,264 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\SSHDRV79.sys -- (SSHDRV79)
DRV - [2008/04/28 17:35:14 | 000,084,024 | ---- | M] (Panda Security, S.L.) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\pavdrv51.sys -- (PAVDRV)
DRV - [2008/04/13 19:36:05 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2008/03/28 11:25:06 | 000,022,072 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\fnetmon.sys -- (FNETMON)
DRV - [2008/03/04 15:59:42 | 000,041,144 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ShlDrv51.sys -- (ShldDrv)
DRV - [2008/01/14 23:12:59 | 000,082,380 | ---- | M] (Oak Technology Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AFS2K.SYS -- (AFS2K)
DRV - [2007/06/14 19:41:58 | 004,429,312 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2007/06/05 18:48:58 | 005,761,728 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\igxpmp32.sys -- (ialm)
DRV - [2007/04/12 11:19:42 | 000,160,256 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2006/09/18 14:59:08 | 000,090,800 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se27unic.sys -- (se27unic) Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (WDM)
DRV - [2006/09/18 14:59:02 | 000,086,560 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SE27obex.sys -- (SE27obex)
DRV - [2006/09/18 14:59:00 | 000,018,704 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se27nd5.sys -- (se27nd5) Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (NDIS)
DRV - [2006/09/18 14:58:58 | 000,088,688 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SE27mgmt.sys -- (SE27mgmt) Sony Ericsson Device 039 USB WMC Device Management Drivers (WDM)
DRV - [2006/09/18 14:58:54 | 000,097,184 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SE27mdm.sys -- (SE27mdm)
DRV - [2006/09/18 14:58:52 | 000,009,360 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SE27mdfl.sys -- (SE27mdfl)
DRV - [2006/09/18 14:58:48 | 000,061,600 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SE27bus.sys -- (SE27bus) Sony Ericsson Device 039 Driver driver (WDM)
DRV - [2006/09/05 20:58:26 | 000,061,536 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se58bus.sys -- (se58bus) Sony Ericsson Device 088 driver (WDM)
DRV - [2006/09/05 20:00:54 | 000,086,432 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se58obex.sys -- (se58obex)
DRV - [2006/09/05 20:00:06 | 000,088,624 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se58mgmt.sys -- (se58mgmt) Sony Ericsson Device 088 USB WMC Device Management Drivers (WDM)
DRV - [2006/09/05 19:59:18 | 000,097,088 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se58mdm.sys -- (se58mdm)
DRV - [2006/09/05 19:59:14 | 000,009,360 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se58mdfl.sys -- (se58mdfl)
DRV - [2006/09/05 19:57:54 | 000,018,704 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se58nd5.sys -- (se58nd5) Sony Ericsson Device 088 USB Ethernet Emulation SEMC58 (NDIS)
DRV - [2006/09/05 19:57:48 | 000,090,800 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\se58unic.sys -- (se58unic) Sony Ericsson Device 088 USB Ethernet Emulation SEMC58 (WDM)
DRV - [2006/08/05 07:20:36 | 000,071,680 | ---- | M] (FarStone Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\fgxscsi.sys -- (FGXSCSI)
DRV - [2006/07/12 07:17:06 | 000,011,520 | ---- | M] (FarStone Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\fgdxbus.sys -- (fgdxbus)
DRV - [2005/03/03 20:53:57 | 000,048,640 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2005/02/23 18:59:54 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
DRV - [2004/12/03 13:20:41 | 000,020,544 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfsync02.sys -- (sfsync02) StarForce Protection Synchronization Driver (version 2.x)
DRV - [2004/08/04 03:29:50 | 000,019,455 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wVchNTxx.sys -- (iAimFP4)
DRV - [2004/08/04 03:29:48 | 000,012,063 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wSiINTxx.sys -- (iAimFP3)
DRV - [2004/08/04 03:29:46 | 000,025,471 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wATV10nt.sys -- (iAimTV5)
DRV - [2004/08/04 03:29:46 | 000,023,615 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wCh7xxNT.sys -- (iAimTV4)
DRV - [2004/08/04 03:29:46 | 000,022,271 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wATV06nt.sys -- (iAimTV6)
DRV - [2004/08/04 03:29:44 | 000,033,599 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wATV04nt.sys -- (iAimTV3)
DRV - [2004/08/04 03:29:44 | 000,019,551 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wATV02NT.sys -- (iAimTV1)
DRV - [2004/08/04 03:29:42 | 000,029,311 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wATV01nt.sys -- (iAimTV0)
DRV - [2004/08/04 03:29:42 | 000,011,871 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV09NT.sys -- (iAimFP7)
DRV - [2004/08/04 03:29:40 | 000,011,807 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV07nt.sys -- (iAimFP5)
DRV - [2004/08/04 03:29:40 | 000,011,295 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV08NT.sys -- (iAimFP6)
DRV - [2004/08/04 03:29:38 | 000,161,020 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\i81xnt5.sys -- (i81x)
DRV - [2004/08/04 03:29:38 | 000,012,415 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV01nt.sys -- (iAimFP0)
DRV - [2004/08/04 03:29:38 | 000,012,127 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV02NT.sys -- (iAimFP1)
DRV - [2004/08/04 03:29:38 | 000,011,775 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wADV05NT.sys -- (iAimFP2)
DRV - [2003/05/08 04:00:00 | 000,090,357 | R--- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\P1130Vid.sys -- (P1130VID)
DRV - [2003/01/22 05:37:00 | 000,009,856 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
DRV - [2002/05/09 03:44:42 | 000,105,472 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\adpu320.sys -- (adpu320)
DRV - [2002/04/04 08:32:06 | 000,028,416 | R--- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symmpi.sys -- (Symmpi)
DRV - [2001/08/18 07:07:42 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2001/08/18 07:07:40 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2001/08/18 07:07:36 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2001/08/18 07:07:34 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)
DRV - [2001/08/18 00:20:04 | 000,096,256 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ac97intc.sys -- (ac97intc) Intel(r) 82801 υπηρεσία εγκατάστασης προγράμματος οδήγησης συσκευής ήχου (WDM)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Live Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = [You must be registered and logged in to see this link.]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultthis.engineName: "isoHunt Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1434207&SearchSource=3&q="
FF - prefs.js..browser.search.selectedEngine: "isoHunt Customized Web Search"
FF - prefs.js..browser.startup.homepage: "http://www.google.gr"
FF - prefs.js..extensions.enabledItems: [You must be registered and logged in to see this link.]:1.0
FF - prefs.js..extensions.enabledItems: [You must be registered and logged in to see this link.]:1.0
FF - prefs.js..network.proxy.share_proxy_settings: true

FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/07 14:42:39 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/04 23:37:23 | 000,000,000 | ---D | M]

[2009/03/06 00:53:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2009/03/06 00:53:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Mozilla\Extensions\mozswing@mozswing.org
[2010/04/13 02:01:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\cu6zhwsp.default\extensions
[2009/08/10 19:28:37 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\cu6zhwsp.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/01/15 10:24:26 | 000,000,876 | ---- | M] () -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\cu6zhwsp.default\searchplugins\conduit.xml
[2008/05/21 17:10:59 | 000,002,921 | ---- | M] () -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\cu6zhwsp.default\searchplugins\daemon-search.xml
[2010/04/13 02:01:05 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/04/07 14:14:24 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions\staff@hide-my-ip.com
[2007/08/30 00:47:44 | 000,054,600 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
[2008/04/17 02:09:28 | 000,249,856 | ---- | M] ( ) -- C:\Program Files\Mozilla Firefox\plugins\npff_gdm.dll
[2010/02/06 23:11:16 | 000,001,525 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/02/06 23:11:16 | 000,000,760 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/02/06 23:11:16 | 000,001,219 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-el.xml

O1 HOSTS File: ([2009/02/09 19:38:18 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APVXDWIN] C:\Program Files\Panda Security\Panda Global Protection 2010\APVXDWIN.EXE (Panda Security, S.L.)
O4 - HKLM..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O4 - HKLM..\Run: [GameDrive] C:\Program Files\FarStone\GameDrive\GDP\GDTask.exe (FarStone Technology Inc.)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe (HP)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (Macrovision Corporation)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe (PDF Complete Inc)
O4 - HKLM..\Run: [SCANINICIO] C:\Program Files\Panda Security\Panda Global Protection 2010\Inicio.exe (Panda Security, S.L.)
O4 - HKLM..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [Sony Ericsson PC Suite] C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe ()
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (Macrovision Corporation)
O4 - HKCU..\Run: [RGSC] C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe File not found
O4 - HKCU..\Run: [Sony Ericsson PC Suite] C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe (Sony Ericsson Mobile Communications AB)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Προγράμματα\Εκκίνηση\InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe (InterVideo Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Προγράμματα\Εκκίνηση\WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE (WinZip Computing LP)
O4 - Startup: C:\Documents and Settings\User\Start Menu\Προγράμματα\Εκκίνηση\AntiSpy Protector.lnk = C:\Program Files\AntiSpyware Protector\AntiSpyProt.exe File not found
O4 - Startup: C:\Documents and Settings\User\Start Menu\Προγράμματα\Εκκίνηση\MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Download the ¤t page with Offline Explorer - C:\Program Files\Offline Explorer\Add_AllO.htm ()
O8 - Extra context menu item: Download using Offline &Explorer - C:\Program Files\Offline Explorer\Add_UrlO.htm ()
O9 - Extra Button: Προσθήκη στο ιστολόγιο - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Προσθήκη στο ιστολόγιο στο Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (Intertrust Technologies, Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} [You must be registered and logged in to see this link.] (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} [You must be registered and logged in to see this link.] (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [You must be registered and logged in to see this link.] (Java Plug-in 1.6.0_19)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} [You must be registered and logged in to see this link.] (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avldr: DllName - avldr.dll - C:\WINDOWS\System32\avldr.dll (Panda Security, S.L.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (Τρέχουσα αρχική σελίδα) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/02/09 16:47:56 | 000,000,000 | ---- | M] () - C:\Autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2002/03/12 14:13:35 | 000,028,672 | R--- | M] (Dipl.-Ing. Stefan Krueger ) - F:\autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2002/03/12 14:13:36 | 000,000,044 | R--- | M] () - F:\autorun.inf -- [ CDFS ]
O32 - AutoRun File - [2002/03/12 14:13:36 | 000,000,991 | R--- | M] () - F:\autorun.ini -- [ CDFS ]
O33 - MountPoints2\{ec622361-bf6c-11dc-858c-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{ec622361-bf6c-11dc-858c-806d6172696f}\Shell\AutoRun\command - "" = F:\autorun.exe -- [2002/03/12 14:13:35 | 000,028,672 | R--- | M] (Dipl.-Ing. Stefan Krueger )
O33 - MountPoints2\{f9d52146-46b1-11de-863c-001d92227a93}\Shell - "" = AutoRun
O33 - MountPoints2\{f9d52146-46b1-11de-863c-001d92227a93}\Shell\AutoRun\command - "" = G:\start.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (MACHINE BootExecut) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

File not found -- C:\Documents and Settings\User\Επιφάνεια εργασίας\The lost book of Enki..
[2010/04/13 18:43:26 | 000,561,664 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\User\Επιφάνεια εργασίας\OTL.exe
[2010/04/13 17:04:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\LogMeIn Hamachi
[2010/04/11 00:20:45 | 000,000,000 | ---D | C] -- C:\Program Files\TombRaiderAOD
[2010/04/11 00:15:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Επιφάνεια εργασίας\tr aod
[2010/04/09 23:48:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2010/04/09 23:48:54 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2010/04/09 23:48:12 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe
[2010/04/09 23:48:12 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe
[2010/04/09 23:48:12 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe
[2010/04/07 14:14:24 | 000,266,552 | ---- | C] (My Privacy Tools, Inc.) -- C:\WINDOWS\System32\HMIPCore.dll
[2010/04/07 14:10:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\Hide IP NG
[2010/03/30 18:01:11 | 000,000,000 | ---D | C] -- C:\Program Files\LogMeIn Hamachi
[2010/03/29 18:44:57 | 000,026,176 | -H-- | C] (LogMeIn, Inc.) -- C:\WINDOWS\System32\hamachi.sys
[2010/03/25 17:30:51 | 000,000,000 | ---D | C] -- C:\Program Files\Rockstar Games
[2010/03/25 16:18:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\SmartFTP
[2010/03/25 16:18:39 | 000,000,000 | ---D | C] -- C:\Program Files\SmartFTP Client
[2010/03/25 16:18:23 | 000,000,000 | ---D | C] -- C:\Program Files\SmartFTP Client 4.0 Setup Files
[2009/07/22 17:56:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2008/09/16 01:00:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2008/02/02 11:22:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Symantec
[2008/01/26 19:27:09 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2008/01/12 12:37:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\ESET
[2008/01/10 23:41:28 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[20 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

File not found -- C:\Documents and Settings\User\Επιφάνεια εργασίας\The lost book of Enki..
[2010/04/13 18:43:44 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Επιφάνεια εργασίας\OTL.exe
[2010/04/13 18:35:00 | 000,000,238 | -H-- | M] () -- C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/04/13 18:25:00 | 000,000,278 | -H-- | M] () -- C:\WINDOWS\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
[2010/04/13 18:00:00 | 000,000,238 | -H-- | M] () -- C:\WINDOWS\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
[2010/04/13 17:22:48 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010/04/13 17:07:04 | 000,447,324 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\DsaFlt.rls.bck
[2010/04/13 17:07:04 | 000,447,324 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\DsaFlt.rls
[2010/04/13 17:07:04 | 000,001,132 | ---- | M] () -- C:\WINDOWS\System32\drivers\APPFLTR.CFG.bck
[2010/04/13 17:07:04 | 000,001,132 | ---- | M] () -- C:\WINDOWS\System32\drivers\APPFLTR.CFG
[2010/04/13 17:07:04 | 000,000,252 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\IdsFlt.cfg.bck
[2010/04/13 17:07:04 | 000,000,252 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\IdsFlt.cfg
[2010/04/13 17:07:04 | 000,000,092 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\NetLoc.wlt.bck
[2010/04/13 17:07:04 | 000,000,092 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\NetLoc.wlt
[2010/04/13 17:07:04 | 000,000,068 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\NetFlt.cfg.bck
[2010/04/13 17:07:04 | 000,000,068 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\NetFlt.cfg
[2010/04/13 17:07:04 | 000,000,056 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\WnmFlt.cfg.bck
[2010/04/13 17:07:04 | 000,000,056 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\WnmFlt.cfg
[2010/04/13 17:07:04 | 000,000,056 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\DsaFlt.cfg.bck
[2010/04/13 17:07:04 | 000,000,056 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\DsaFlt.cfg
[2010/04/13 17:06:56 | 000,013,880 | ---- | M] () -- C:\WINDOWS\System32\drivers\COMFiltr.sys
[2010/04/13 17:05:35 | 000,000,136 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\NetAdapt.cfg.bck
[2010/04/13 17:05:35 | 000,000,136 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\NetAdapt.cfg
[2010/04/13 17:05:35 | 000,000,064 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\NetAR.wlt.bck
[2010/04/13 17:05:35 | 000,000,064 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\NetAR.wlt
[2010/04/13 17:05:23 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/04/13 17:04:51 | 000,002,736 | ---- | M] () -- C:\Documents and Settings\User\UpdateLog.GDZ
[2010/04/13 17:04:49 | 000,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2010/04/13 17:04:21 | 000,253,748 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2010/04/13 17:04:13 | 000,000,236 | ---- | M] () -- C:\WINDOWS\tasks\OGALogon.job
[2010/04/13 17:03:56 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/04/13 17:03:50 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/04/13 17:03:48 | 3219,312,640 | -HS- | M] () -- C:\hiberfil.sys
[2010/04/13 17:02:20 | 010,485,760 | -H-- | M] () -- C:\Documents and Settings\User\NTUSER.DAT
[2010/04/13 04:29:07 | 003,710,062 | -H-- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\IconCache.db
[2010/04/12 21:26:08 | 000,008,627 | ---- | M] () -- C:\WINDOWS\System32\PAV_FOG.OPC
[2010/04/12 01:50:38 | 000,336,604 | ---- | M] () -- C:\WINDOWS\System32\drivers\APPFCONT.DAT.bck
[2010/04/12 01:50:38 | 000,336,604 | ---- | M] () -- C:\WINDOWS\System32\drivers\APPFCONT.DAT
[2010/04/06 14:11:23 | 001,175,872 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/04/06 14:11:23 | 000,554,772 | ---- | M] () -- C:\WINDOWS\System32\perfh008.dat
[2010/04/06 14:11:23 | 000,444,478 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/04/06 14:11:23 | 000,096,688 | ---- | M] () -- C:\WINDOWS\System32\perfc008.dat
[2010/04/06 14:11:23 | 000,072,354 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/03/31 19:31:44 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\User\ntuser.ini
[2010/03/25 17:30:56 | 000,001,715 | ---- | M] () -- C:\Documents and Settings\User\Επιφάνεια εργασίας\Play GTA Vice City.lnk
[20 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/03/25 17:41:38 | 000,001,715 | ---- | C] () -- C:\Documents and Settings\User\Επιφάνεια εργασίας\Play GTA Vice City.lnk
[2010/02/18 18:21:31 | 000,000,074 | ---- | C] () -- C:\WINDOWS\System32\config.ini
[2010/02/18 18:19:31 | 000,002,736 | ---- | C] () -- C:\Documents and Settings\User\UpdateLog.GDZ
[2010/02/12 15:51:55 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2010/01/09 20:49:04 | 000,000,104 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2010/01/08 16:51:14 | 001,191,936 | ---- | C] () -- C:\WINDOWS\System32\VCPUD.DLL
[2009/12/01 15:30:14 | 000,078,848 | ---- | C] () -- C:\WINDOWS\System32\drivers\SSHDRV85.sys
[2009/10/28 16:54:38 | 000,075,264 | ---- | C] () -- C:\WINDOWS\System32\drivers\SSHDRV79.sys
[2009/10/15 23:19:16 | 000,013,880 | ---- | C] () -- C:\WINDOWS\System32\drivers\COMFiltr.sys
[2009/10/15 22:50:57 | 000,000,361 | ---- | C] () -- C:\WINDOWS\AvDetected.ini
[2009/09/25 19:12:03 | 000,611,640 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/08/07 19:51:34 | 000,178,430 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/04/14 20:59:34 | 000,000,820 | ---- | C] () -- C:\WINDOWS\SPIDERMAN.INI
[2009/03/02 14:14:00 | 000,000,035 | ---- | C] () -- C:\WINDOWS\A5W.INI
[2009/03/02 14:11:05 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2009/03/02 14:04:47 | 000,000,037 | ---- | C] () -- C:\WINDOWS\Qtw.ini
[2009/02/09 19:32:49 | 000,000,327 | ---- | C] () -- C:\Documents and Settings\User\catchme.log
[2009/02/09 15:06:31 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\User\ebValidationResults.txt
[2009/02/03 15:22:51 | 000,009,752 | ---- | C] () -- C:\Documents and Settings\User\Application Data\VMCP.SPF
[2009/01/28 16:29:22 | 000,000,178 | ---- | C] () -- C:\Documents and Settings\User\Application Data\sub.txt
[2008/10/09 16:11:38 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2008/10/07 10:13:30 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 10:13:22 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 10:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/07/27 10:01:50 | 000,185,344 | ---- | C] () -- C:\WINDOWS\patchw32.dll
[2008/07/02 01:28:49 | 000,000,174 | ---- | C] () -- C:\WINDOWS\game.ini
[2008/06/22 16:58:15 | 000,056,320 | ---- | C] () -- C:\WINDOWS\System32\iyvu9_32.dll
[2008/06/12 20:36:38 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008/05/25 20:28:12 | 000,053,248 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2008/05/21 17:03:10 | 000,691,696 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008/04/12 07:41:20 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008/04/12 07:30:20 | 000,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008/03/20 13:24:42 | 000,000,040 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\.zreglib
[2008/03/07 13:39:12 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2008/03/07 13:39:12 | 000,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2008/03/07 13:39:12 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2008/03/07 13:39:12 | 000,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2008/03/07 13:39:12 | 000,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2008/03/07 13:39:12 | 000,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2008/02/08 18:17:21 | 000,000,012 | ---- | C] () -- C:\Documents and Settings\User\intlname.ols
[2008/02/05 15:25:36 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2008/02/01 20:38:47 | 000,000,036 | ---- | C] () -- C:\WINDOWS\Level.ini
[2008/01/26 23:41:12 | 000,000,075 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2008/01/20 19:26:20 | 000,069,632 | R--- | C] () -- C:\WINDOWS\System32\xmltok.dll
[2008/01/20 19:26:20 | 000,036,864 | R--- | C] () -- C:\WINDOWS\System32\xmlparse.dll
[2008/01/16 18:01:34 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/01/15 16:12:23 | 000,000,080 | RHS- | C] () -- C:\WINDOWS\System32\6689857412.dll
[2008/01/14 23:10:54 | 000,010,712 | ---- | C] () -- C:\WINDOWS\hpdj3600.ini
[2008/01/11 17:38:24 | 000,281,760 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2008/01/11 17:38:24 | 000,025,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2008/01/11 15:28:22 | 000,082,944 | ---- | C] () -- C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/01/10 23:41:58 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4837.dll
[2008/01/10 23:32:20 | 000,000,995 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2008/01/10 16:16:47 | 000,000,380 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/01/10 16:08:55 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\User\Local Settings\Application Data\fusioncache.dat
[2008/01/10 16:08:53 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\User\ntuser.dat.LOG
[2008/01/10 16:08:53 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\User\ntuser.ini
[2008/01/10 16:08:52 | 010,485,760 | -H-- | C] () -- C:\Documents and Settings\User\NTUSER.DAT
[2008/01/10 14:11:59 | 000,262,144 | ---- | C] () -- C:\Documents and Settings\All Users\ntuser.dat
[2008/01/10 14:11:59 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\All Users\ntuser.dat.LOG
[2008/01/10 13:57:08 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2007/02/05 20:05:26 | 000,000,038 | ---- | C] () -- C:\WINDOWS\AviSplitter.INI
[2006/07/12 07:17:28 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\VDExt800.dll
[2006/07/12 07:17:28 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\VDExt712.dll
[2006/07/12 07:17:24 | 000,006,398 | ---- | C] () -- C:\WINDOWS\System32\drivers\SmartCdx.sys
[2006/07/12 07:17:10 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\GDExt800.dll
[2006/07/12 07:17:10 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\GDExt712.dll
[2003/04/24 16:47:04 | 000,005,697 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI

========== Alternate Data Streams ==========

@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0CE7F3C9
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CE11B51
< End of report >



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Tue Apr 13, 2010 3:51 pm

OTL Extras logfile created on: 13/4/2010 6:44:34 μμ - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Documents and Settings\User\Επιφάνεια εργασίας
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000408 | Country: Ελλάδα | Language: ELL | Date Format: d/M/yyyy

3,00 Gb Total Physical Memory | 2,00 Gb Available Physical Memory | 80,00% Memory free
4,00 Gb Paging File | 4,00 Gb Available in Paging File | 87,00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149,05 Gb Total Space | 48,65 Gb Free Space | 32,64% Space Free | Partition Type: NTFS
Drive D: | 149,05 Gb Total Space | 121,07 Gb Free Space | 81,23% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 642,26 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: HP11546321382
Current User Name: User
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.js [@ = JSFile] -- C:\Program Files\Panda Security\Panda Global Protection 2010\PAVSCRIP.EXE (Panda Security, S.L.)
.jse [@ = JSEFile] -- C:\Program Files\Panda Security\Panda Global Protection 2010\PAVSCRIP.EXE (Panda Security, S.L.)
.vbe [@ = VBEFile] -- C:\Program Files\Panda Security\Panda Global Protection 2010\PAVSCRIP.EXE (Panda Security, S.L.)
.vbs [@ = VBSFile] -- C:\Program Files\Panda Security\Panda Global Protection 2010\PAVSCRIP.EXE (Panda Security, S.L.)
.wsf [@ = WSFFile] -- C:\Program Files\Panda Security\Panda Global Protection 2010\PAVSCRIP.EXE (Panda Security, S.L.)
.wsh [@ = WSHFile] -- C:\Program Files\Panda Security\Panda Global Protection 2010\PAVSCRIP.EXE (Panda Security, S.L.)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
jsfile [open] -- C:\PROGRA~1\PANDAS~1\PANDAG~1\PAVSCRIP.EXE "%1" %* (Panda Security, S.L.)
jsefile [open] -- C:\PROGRA~1\PANDAS~1\PANDAG~1\PAVSCRIP.EXE "%1" %* (Panda Security, S.L.)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
vbefile [open] -- C:\PROGRA~1\PANDAS~1\PANDAG~1\PAVSCRIP.EXE "%1" %* (Panda Security, S.L.)
vbsfile [open] -- C:\PROGRA~1\PANDAS~1\PANDAG~1\PAVSCRIP.EXE "%1" %* (Panda Security, S.L.)
wsffile [open] -- C:\PROGRA~1\PANDAS~1\PANDAG~1\PAVSCRIP.EXE "%1" %* (Panda Security, S.L.)
wshfile [open] -- C:\PROGRA~1\PANDAS~1\PANDAG~1\PAVSCRIP.EXE "%1" %* (Panda Security, S.L.)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
"DisableMonitoring" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
"DisableMonitoring" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:Torrent -- ()
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire -- File not found
"C:\TEST4U_EDU\TEST4U.exe" = C:\TEST4U_EDU\TEST4U.exe:LocalSubNet:Enabled:TEST4U -- (INFOlearn Corporation)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger -- (Yahoo! Inc.)
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server -- (Yahoo! Inc.)
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent -- ()
"C:\Program Files\DNA\btdna.exe" = C:\Program Files\DNA\btdna.exe:*:Enabled:DNA -- File not found
"C:\Documents and Settings\User\Επιφάνεια εργασίας\Guns 'N' Roses\uTorrent.exe" = C:\Documents and Settings\User\Επιφάνεια εργασίας\Guns 'N' Roses\uTorrent.exe:*:Enabled:Torrent -- (BitTorrent, Inc.)
"C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager\MediaManager.exe" = C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager\MediaManager.exe:*:Enabled:Sony Ericsson Media Manager 1.2 -- (Sony Creative Software Inc.)
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" = C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync -- (Microsoft Corporation)
"C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe" = C:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe:*:Enabled:Rockstar Games Social Club -- File not found
"C:\Program Files\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe" = C:\Program Files\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe:*:Enabled:Grand Theft Auto IV -- File not found
"C:\Program Files\SmartFTP Client\SmartFTP.exe" = C:\Program Files\SmartFTP Client\SmartFTP.exe:*:Enabled:SmartFTP Client 4.0 -- (SmartSoft Ltd.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"(Street-Boy) All Cards Unlocker" = (Street-Boy) All Cards Unlocker
"{006A0A2F-B99E-424E-85B1-165FFE70D183}" = Windows Live Writer
"{00BE2030-4991-43DF-80ED-358431E39B7C}" = Windows Live Essentials
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{02A10468-2F1C-447C-AD8E-4DEDDEA25AE2}" = Medieval II Total War : Kingdoms : Crusades
"{02DFB3FD-CF52-4183-8BCA-2A127D4888F4}" = iTunes
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{14001B93-0C6F-4353-8A10-BE96EE174E17}" = Windows Live Toolbar
"{1A655D51-1423-48A3-B748-8F5A0BE294C8}" = Microsoft Visual J# .NET Redistributable Package 1.1
"{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Εργαλείο αποστολής του Windows Live
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java(TM) 6 Update 19
"{2E660A2A-A55F-43CD-9F73-CAD7382EEB78}" = Microsoft Games for Windows - LIVE Redistributable
"{2FFE93F0-BB72-4E52-8761-354D1AAA9387}" = Sony Ericsson PC Suite 4.005.00
"{31923B7D-713A-4044-B6F8-15B36BE4B60F}" = SmartFTP Client
"{350C9408-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3571656A-575D-4CED-809D-5547587121FF}" = Yu-Gi-Oh! Power of Chaos YUGI THE DESTINY
"{3D9E9EB7-B14F-4AE4-8C1F-1AD4CF3093BE}" = Microsoft .NET Framework 1.1 Greek Language Pack
"{4089999C-6CB7-4F9D-A2F6-DB158DBF91FB}" = Rome - Total War(TM)
"{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}" = Bonjour
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4B35F00C-E63D-40DC-9839-DF15A33EAC46}" = Grand Theft Auto Vice City
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{51962132-EF73-4015-A69E-1538CDDFB835}" = Windows Live Mail
"{576E71DA-3000-48F6-9B21-B9A70D47DFCF}" = Star Wars JK II Jedi Outcast
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5A438E06-0BB3-4C5F-0085-B14F1F4077E6}" = FIFA 07
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype 3.6
"{60F6070C-B776-45ED-A5EC-5F629B14FEFD}" = Panda Global Protection 2010
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{685A56F8-75B6-44AD-B3DA-FB0A3266B47C}" = Adobe Flash Player 9 ActiveX
"{75983B66-804C-40D1-BA13-64DAF652A6F1}" = Medieval II Total War : Kingdoms : Americas
"{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}" = Avanquest update
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7AEE1963-7001-4C37-BC20-2FAEB74AA41C}" = Medieval II Total War : Kingdoms : Teutonic
"{7F34A21F-2DEB-4598-BB19-611D6BD24271}" = Managed DirectX (0901)
"{81A25967-DB85-4B48-A8A7-D25AC191DEE4}" = Panda Global Protection 2010
"{82DB1170-BB72-4A9C-B48B-07229C7BA8EA}" = Microsoft .NET Framework 2.0 Language Pack - ELL
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74DEFD-A224-49CC-AB80-4E88BC730125}" = LogMeIn Hamachi
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{90110408-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{91A5B6C0-EF4E-4830-AC7D-6761C0A9B292}" = hp deskjet 3600
"{93656878-FF8B-4935-99BB-F3F260037C57}" = Lara Croft Tomb Raider: The Angel Of Darkness
"{94F70511-C8A8-413C-AC8D-65313D8D3082}" = Windows Live Messenger
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD 4
"{9933F0EE-DFCD-4829-B979-3C56C367CB1A}" = InterVideo WinDVD Creator
"{9977BB98-D0E6-4850-A3BF-2BD8CFB9D794}" = Βοηθός εισόδου του Windows Live
"{9EB1504E-FD95-4BCD-8E93-B4039F59C469}" = Sony Ericsson Media Manager 1.2
"{9FEECBDA-8378-4874-AD65-D9E232BE2D11}" = Windows Live Sync
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}" = HP Help and Support
"{AC08BBA0-96B9-431A-A7D0-D8598E493775}" = RESIDENT EVIL 5
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.3
"{AEDDF5A3-29CE-11D5-A8C2-000102246AAE}" = ubi.com
"{B210130E-835C-4581-A695-CE10616B8B55}_is1" = Driver Sweeper 2.0.5
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B376402D-58EA-45EA-BD50-DD924EB67A70}" = Video CD HP
"{B5B0EE08-3950-40F1-AEC1-14A2D4EC18DE}" = TortoiseSVN 1.4.6.11647 (32 bit)
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}" = Apple Software Update
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BFD96B89-B769-4CD6-B11E-E79FFD46F067}" = QuickTime
"{C0698BDA-0D29-40EE-8570-A31106DF9AB1}" = Medieval II Total War
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C5C1C0F0-D62F-4DBF-81D4-D7EF397C228B}" = NVIDIA PhysX
"{CA2084E3-C37C-41BB-805A-6163BCC587F1}" = ShaderMark v2.1
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE7CB214-DB11-4B5D-A6AF-3B4ED47C68B7}" = Microsoft Game Studios Common Redistributables Pack 1
"{CEDDEE73-3D36-41C2-AA40-29355D9FBD63}" = Medieval II Total War : Kingdoms : Britannia
"{D01653EF-9F9F-41D6-B879-654A6BF5892C}" = Βοηθός του digital locker
"{D5BB0907-4BB2-46A3-AA68-0173D111058D}" = GameDrive
"{D87B8C91-4659-4C3B-A894-A4D670AE95E2}" = Συλλογή φωτογραφιών του Windows Live
"{D8AB8F0C-CEEB-4A29-8EF5-219B064813F4}" = Apple Mobile Device Support
"{E0828692-FD9D-459F-9312-C645C3CA6650}" = HP Photo and Imaging 2.0 - Deskjet Series
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{EDFBF404-E856-4C72-8ACB-202908147532}" = Οικογενειακή ασφάλεια του Windows Live
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F112F66E-25CA-42DD-983C-6118EB38F606}" = Microsoft Games for Windows - LIVE
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F5223680-993A-11D4-86F6-0001031E5712}" = InterVideo Installer
"{F9FD80CE-0448-4D4F-8BCD-77FC514C3F99}" = Vista Codec Package
"{FE6397C1-CECA-4EC3-B064-42AED7676898}" = Sony Ericsson PC Suite
"82A44D22-9452-49FB-00FB-CEC7DCAF7E23" = EA SPORTS online 2007
"ABC Amber ICL Converter" = ABC Amber ICL Converter
"ActiveScan 2.0" = Panda ActiveScan 2.0
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Creative PC-CAM Center" = Creative PC-CAM Center
"Creative PD1130" = Creative WebCam NX Pro Driver (1.00.06.0512)
"Creative WebCam Monitor" = Creative WebCam Monitor
"Creative WebCam NX Pro User's Guide English" = Creative WebCam NX Pro User's Guide (English)
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"EasyPHP_is1" = EasyPHP 2.0b1
"EAX Unified" = EAX Unified
"GameSpotDownloadManager" = GameSpot Download Manager
"Guitar Pro 5_is1" = Guitar Pro 5.2
"HDMI" = Intel(R) Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"hp print screen utility" = hp print screen utility
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Indeo software" = Indeo Software
"indeoxp" = %DeviceDesc%
"InstallShield_{93656878-FF8B-4935-99BB-F3F260037C57}" = Lara Croft Tomb Raider: The Angel Of Darkness
"InterActual Player" = InterActual Player
"LogMeIn Hamachi" = LogMeIn Hamachi
"Magic ISO Maker v5.5 (build 0276)" = Magic ISO Maker v5.5 (build 0276)
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Messenger Plus! Live" = Messenger Plus! Live
"MetaProducts Offline Explorer" = MetaProducts Offline Explorer
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0 Language Pack - ELL" = Microsoft .NET Framework 2.0 Language Pack - ELL
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.5.9)" = Mozilla Firefox (3.5.9)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"OpenAL" = OpenAL
"PDF Complete" = PDF Complete
"PowerISO" = PowerISO
"Product Key Explorer_is1" = Product Key Explorer 2.2.1
"RealPlayer 6.0" = RealPlayer
"Resident Evil 4_is1" = Resident Evil 4 1.10
"Shockwave" = Shockwave
"SmartFTP Client 4.0 Setup Files" = SmartFTP Client 4.0 Setup Files (remove only)
"ST6UNST #1" = TEST4U EDU setup
"ST6UNST #2" = TEST4U EDU setup (c:\TEST4U_EDU\)
"SubDownloader2" = SubDownloader2
"SystemRequirementsLab" = System Requirements Lab
"TeamViewer 3" = TeamViewer 3
"The Times - Exclusive Tomb Raider Level" = The Times - Exclusive Tomb Raider Level
"Tomb Raider - The Angel of Darkness" = Tomb Raider - The Angel of Darkness
"Tomb Raider - The Last Revelation" = Tomb Raider - The Last Revelation (remove only)
"Tomb Raider II" = Tomb Raider II
"Tomb Raider III - Adventures of Lara Croft" = Tomb Raider III - Adventures of Lara Croft (remove only)
"tomb3.exe" = Tomb Raider III (Demo)
"Vidmex" = Vidmex 1.39
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR 3.70 Εφαρμογή Διαχείρισης Συμπιεσμένων Αρχείων
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xfire" = Xfire (remove only)
"Yahoo! Mail" = Yahoo! Internet Mail
"Yahoo! Messenger" = Yahoo! Messenger
"YU2010_is1" = Your Uninstaller! 2010

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent" = BitTorrent
"Stainless_Steel_6.0_Part1of2" = Stainless_Steel_6.0_Part1of2
"Stainless_Steel_6.0_Part2of2" = Stainless_Steel_6.0_Part2of2
"uTorrent" = Torrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 5/4/2010 1:32:11 μμ | Computer Name = HP11546321382 | Source = Application Hang | ID = 1002
Description = Κρεμασμένη εφαρμογή jk2mp.exe, έκδοση 0.0.0.0, στοιχείο ελέγχου κρεμάσματος
hungapp, έκδοση 0.0.0.0, διεύθυνση κρεμάσματος 0x00000000.

Error - 5/4/2010 1:50:06 μμ | Computer Name = HP11546321382 | Source = Application Error | ID = 1000
Description = Ελαττωματική εφαρμογή jk2mp.exe, έκδοση 0.0.0.0, ελαττωματική λειτουργική
μονάδα jk2mp.exe, έκδοση 0.0.0.0, ελαττωματική διεύθυνση 0x00076368.

Error - 10/4/2010 8:01:46 πμ | Computer Name = HP11546321382 | Source = Application Error | ID = 1000
Description = Ελαττωματική εφαρμογή jk2mp.exe, έκδοση 0.0.0.0, ελαττωματική λειτουργική
μονάδα jk2mp.exe, έκδοση 0.0.0.0, ελαττωματική διεύθυνση 0x00076368.

Error - 10/4/2010 9:25:03 πμ | Computer Name = HP11546321382 | Source = Application Error | ID = 1000
Description = Ελαττωματική εφαρμογή jk2mp.exe, έκδοση 0.0.0.0, ελαττωματική λειτουργική
μονάδα jk2mp.exe, έκδοση 0.0.0.0, ελαττωματική διεύθυνση 0x00076368.

Error - 11/4/2010 1:55:03 μμ | Computer Name = HP11546321382 | Source = Application Error | ID = 1000
Description = Ελαττωματική εφαρμογή jk2mp.exe, έκδοση 0.0.0.0, ελαττωματική λειτουργική
μονάδα jk2mp.exe, έκδοση 0.0.0.0, ελαττωματική διεύθυνση 0x00076368.

Error - 11/4/2010 3:30:45 μμ | Computer Name = HP11546321382 | Source = EventSystem | ID = 4609
Description = Το σύστημα συμβάντων COM+ εντόπισε έναν εσφαλμένο κωδικό επιστροφής
κατά την εσωτερική του επεξεργασία. Το HRESULT ήταν 800706BA από τη γραμμή 44
του d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp. Επικοινωνήστε με
τις υπηρεσίες υποστήριξης προϊόντων της Microsoft για να αναφέρετε αυτό το σφάλμ

Error - 12/4/2010 10:44:07 πμ | Computer Name = HP11546321382 | Source = Application Hang | ID = 1002
Description = Κρεμασμένη εφαρμογή LUKernel.exe, έκδοση 15.0.0.498, στοιχείο ελέγχου
κρεμάσματος hungapp, έκδοση 0.0.0.0, διεύθυνση κρεμάσματος 0x00000000.

Error - 12/4/2010 12:42:55 μμ | Computer Name = HP11546321382 | Source = Application Error | ID = 1000
Description = Ελαττωματική εφαρμογή jk2mp.exe, έκδοση 0.0.0.0, ελαττωματική λειτουργική
μονάδα jk2mp.exe, έκδοση 0.0.0.0, ελαττωματική διεύθυνση 0x0006ca37.

Error - 12/4/2010 12:43:31 μμ | Computer Name = HP11546321382 | Source = Application Error | ID = 1000
Description = Ελαττωματική εφαρμογή jk2mp.exe, έκδοση 0.0.0.0, ελαττωματική λειτουργική
μονάδα jk2mp.exe, έκδοση 0.0.0.0, ελαττωματική διεύθυνση 0x0006ca37.

Error - 12/4/2010 6:51:05 μμ | Computer Name = HP11546321382 | Source = Application Hang | ID = 1002
Description = Κρεμασμένη εφαρμογή firefox.exe, έκδοση 1.9.1.3726, στοιχείο ελέγχου
κρεμάσματος hungapp, έκδοση 0.0.0.0, διεύθυνση κρεμάσματος 0x00000000.

[ System Events ]
Error - 12/4/2010 10:43:01 πμ | Computer Name = HP11546321382 | Source = Service Control Manager | ID = 7023
Description = Η υπηρεσία SSHNAS τερματίστηκε με το ακόλουθο σφάλμα: %%126

Error - 12/4/2010 10:44:13 πμ | Computer Name = HP11546321382 | Source = Service Control Manager | ID = 7034
Description = Η λειτουργία της υπηρεσίας INFOlearn Admin Service τερματίστηκε αναπάντεχα.
Αυτό συνέβη 1 φορά(ές).

Error - 13/4/2010 7:28:21 πμ | Computer Name = HP11546321382 | Source = Service Control Manager | ID = 7000
Description = Δεν ήταν δυνατή η εκκίνηση της υπηρεσίας Automatic LiveUpdate Scheduler
εξαιτίας του ακόλουθου σφάλματος: %%3

Error - 13/4/2010 7:28:21 πμ | Computer Name = HP11546321382 | Source = Service Control Manager | ID = 7023
Description = Η υπηρεσία SSHNAS τερματίστηκε με το ακόλουθο σφάλμα: %%126

Error - 13/4/2010 9:58:08 πμ | Computer Name = HP11546321382 | Source = W32Time | ID = 39452689
Description = Υπηρεσία Παροχής Χρόνου NtpClient: Παρουσιάστηκε ένα σφάλμα κατά την
αναζήτηση DNS του σταθμού 'time.windows.com,0x1' με μη αυτόματες ρυθμίσεις παραμέτρων.
Το NtpClient θα επιχειρήσει αναζήτηση DNS ξανά σε 15 λεπτά. Το σφάλμα ήταν: Επιχειρήθηκε
η εκτέλεση μιας λειτουργίας υποδοχής σε ένα κεντρικό υπολογιστή, ο οποίος δεν είναι
προσπελάσιμος. (0x80072751)

Error - 13/4/2010 9:58:08 πμ | Computer Name = HP11546321382 | Source = W32Time | ID = 39452701
Description = Η υπηρεσία παροχής χρόνου NtpClient έχει ρυθμιστεί να λαμβάνει ώρα
από μία ή περισσότερες προελεύσεις χρόνου, ωστόσο αυτή τη στιγμή δεν είναι προσπελάσιμη
καμία
από αυτές. Δεν θα γίνει καμία προσπάθεια επικοινωνίας με κάποια προέλευση χρόνου
για 14 λεπτά. Ο NtpClient δεν έχει προέλευση ακριβούς ώρας.

Error - 13/4/2010 9:58:17 πμ | Computer Name = HP11546321382 | Source = W32Time | ID = 39452689
Description = Υπηρεσία Παροχής Χρόνου NtpClient: Παρουσιάστηκε ένα σφάλμα κατά την
αναζήτηση DNS του σταθμού 'time.windows.com,0x1' με μη αυτόματες ρυθμίσεις παραμέτρων.
Το NtpClient θα επιχειρήσει αναζήτηση DNS ξανά σε 15 λεπτά. Το σφάλμα ήταν: Επιχειρήθηκε
η εκτέλεση μιας λειτουργίας υποδοχής σε ένα κεντρικό υπολογιστή, ο οποίος δεν είναι
προσπελάσιμος. (0x80072751)

Error - 13/4/2010 9:58:17 πμ | Computer Name = HP11546321382 | Source = W32Time | ID = 39452701
Description = Η υπηρεσία παροχής χρόνου NtpClient έχει ρυθμιστεί να λαμβάνει ώρα
από μία ή περισσότερες προελεύσεις χρόνου, ωστόσο αυτή τη στιγμή δεν είναι προσπελάσιμη
καμία
από αυτές. Δεν θα γίνει καμία προσπάθεια επικοινωνίας με κάποια προέλευση χρόνου
για 15 λεπτά. Ο NtpClient δεν έχει προέλευση ακριβούς ώρας.

Error - 13/4/2010 10:04:40 πμ | Computer Name = HP11546321382 | Source = Service Control Manager | ID = 7000
Description = Δεν ήταν δυνατή η εκκίνηση της υπηρεσίας Automatic LiveUpdate Scheduler
εξαιτίας του ακόλουθου σφάλματος: %%3

Error - 13/4/2010 10:04:40 πμ | Computer Name = HP11546321382 | Source = Service Control Manager | ID = 7023
Description = Η υπηρεσία SSHNAS τερματίστηκε με το ακόλουθο σφάλμα: %%126


< End of report >



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Belahzur on Tue Apr 13, 2010 6:52 pm

Please run OTL.exe.

  • Copy the commands with file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose CopyCrying


    :OTL
    O4 - HKLM..\Run: [] File not found
    [2010/04/13 18:35:00 | 000,000,238 | -H-- | M] () -- C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
    [2010/04/13 18:25:00 | 000,000,278 | -H-- | M] () -- C:\WINDOWS\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
    [2010/04/13 18:00:00 | 000,000,238 | -H-- | M] () -- C:\WINDOWS\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job


  • Return to OTL, right click in the "Custom Scans/Fixes" window (under the light green bar) and choose Paste.

  • Click the red Run Fix button.
  • A fix log in Notepad will appear. Copy the contents of the fix log to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTL.exe
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Wed Apr 14, 2010 11:43 am

========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job moved successfully.
C:\WINDOWS\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job moved successfully.
C:\WINDOWS\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job moved successfully.

OTL by OldTimer - Version 3.2.1.1 log created on 04142010_144322



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Belahzur on Wed Apr 14, 2010 9:11 pm

Please download and run this tool.

Download Malwarebytes' Anti-Malware from [You must be registered and logged in to see this link.]

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Thu Apr 15, 2010 1:16 pm

So pc is infected from what you saw? I run the malware scan now



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Thu Apr 15, 2010 1:26 pm

Here are the results :

Malwarebytes' Anti-Malware 1.45
[You must be registered and logged in to see this link.]

Έκδοση βάσης δεδομένων: 3990

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

15/4/2010 4:25:37 μμ
mbam-log-2010-04-15 (16-25-37).txt

Τύπος σάρωσης: Γρήγορη σάρωση
Αντικείμενα που σαρώθηκαν: 123052
Χρόνος που έχει διανυθεί: 8 λεπτό(ά), 58 δευτερόλεπτο(α)

Μολυσμένες διεργασίες στη μνήμη: 0
Μολυσμένα στοιχεία στη μνήμη: 0
Μολυσμένα κλειδιά στο μητρώο: 5
Μολυσμένες τιμές στο μητρώο: 0
Μολυσμένα αντικείμενα δεδομένων στο μητρώο: 0
Μολυσμένοι φάκελοι: 1
Μολυσμένα αρχεία: 6

Μολυσμένες διεργασίες στη μνήμη:
(Δεν εντοπίστηκαν επιβλαβή αντικείμενα)

Μολυσμένα στοιχεία στη μνήμη:
(Δεν εντοπίστηκαν επιβλαβή αντικείμενα)

Μολυσμένα κλειδιά στο μητρώο:
HKEY_CURRENT_USER\SOFTWARE\BMIMZMHMFM (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\WS9E3IQBKY (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SSHNAS (Trojan.Renos) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\NordBull (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.

Μολυσμένες τιμές στο μητρώο:
(Δεν εντοπίστηκαν επιβλαβή αντικείμενα)

Μολυσμένα αντικείμενα δεδομένων στο μητρώο:
(Δεν εντοπίστηκαν επιβλαβή αντικείμενα)

Μολυσμένοι φάκελοι:
C:\Documents and Settings\User\Start Menu\Προγράμματα\AntiSpyware Protector (Rogue.AntiSpywareProtector) -> Quarantined and deleted successfully.

Μολυσμένα αρχεία:
C:\Documents and Settings\User\Start Menu\Προγράμματα\AntiSpyware Protector\AntiSpy Monitor.lnk (Rogue.AntiSpywareProtector) -> Quarantined and deleted successfully.
C:\Documents and Settings\User\Start Menu\Προγράμματα\AntiSpyware Protector\AntiSpy Protector Home.lnk (Rogue.AntiSpywareProtector) -> Quarantined and deleted successfully.
C:\Documents and Settings\User\Start Menu\Προγράμματα\AntiSpyware Protector\AntiSpy Protector.lnk (Rogue.AntiSpywareProtector) -> Quarantined and deleted successfully.
C:\Documents and Settings\User\Start Menu\Προγράμματα\AntiSpyware Protector\Documentation.lnk (Rogue.AntiSpywareProtector) -> Quarantined and deleted successfully.
C:\Documents and Settings\User\Start Menu\Προγράμματα\AntiSpyware Protector\ReadMe.lnk (Rogue.AntiSpywareProtector) -> Quarantined and deleted successfully.
C:\Documents and Settings\User\Start Menu\Προγράμματα\Εκκίνηση\AntiSpy Protector.lnk (Rogue.AntiSpywareProtector) -> Quarantined and deleted successfully.


I go for restart



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Belahzur on Thu Apr 15, 2010 7:46 pm

Hello.

  • Download combofix from here
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]

    1. If you are using Firefox, make sure that your download settings are as follows:

    * Tools->Options->Main tab
    * Set to "Always ask me where to Save the files".

    2. During the download, rename Combofix to Combo-Fix as follows:





    3. It is important you rename Combofix during the download, but not after.
    4. Please do not rename Combofix to other names, but only to the one indicated.
    5. Close any open browsers.
    6. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • We need to disable your local AV (Anti-virus) before running Combofix.
  • See [You must be registered and logged in to see this link.] for how to disable your AV.
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.



  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will then get this next prompt that asks if you want to continue the malware scan, select yes



  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Fri Apr 16, 2010 10:16 am

ComboFix 10-04-15.02 - User 16/04/2010 12:54:58.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1253.30.1032.18.3070.2551 [GMT 3:00]
Running from: c:\documents and settings\User\Επιφάνεια εργασίας\Combo-Fix.exe
AV: Panda Global Protection 2010 *On-access scanning disabled* (Updated) {8BF935E7-731F-4115-B7A5-789FF5087595}
FW: Panda Personal Firewall 2010 *disabled* {7B090DC0-8905-4BAF-8040-FD98A41C8FB8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Ινδιάνος .bmp
c:\windows\system32\6689857412.dll
c:\windows\system32\Config.ini
c:\windows\system32\SHELLLNK.TLB
c:\windows\system32\Thumbs.db

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_SSHNAS


((((((((((((((((((((((((( Files Created from 2010-03-16 to 2010-04-16 )))))))))))))))))))))))))))))))
.

2010-04-15 13:10 . 2010-03-29 21:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-15 13:10 . 2010-04-15 13:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-15 13:10 . 2010-03-29 21:45 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-15 12:12 . 2010-04-15 12:12 -------- d-----w- c:\program files\Advanced Attitude Software
2010-04-14 13:42 . 2010-04-14 13:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Deskshare
2010-04-14 13:38 . 2010-04-14 13:39 -------- d-----w- c:\windows\XSxS
2010-04-14 13:38 . 2010-04-14 13:38 -------- d-----w- c:\program files\Xenocode
2010-04-14 13:38 . 2010-04-14 13:38 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Xenocode
2010-04-14 13:31 . 2010-04-14 13:31 -------- d-----w- c:\program files\Common Files\Deskshare Shared
2010-04-14 13:31 . 2010-04-14 13:31 -------- d-----w- c:\program files\Deskshare
2010-04-14 11:43 . 2010-04-14 11:43 -------- d-----w- C:\_OTL
2010-04-10 21:20 . 2010-04-11 13:30 -------- d-----w- c:\program files\TombRaiderAOD
2010-04-09 20:48 . 2010-04-09 20:48 -------- d-----w- c:\program files\Common Files\Java
2010-04-07 11:14 . 2010-01-30 07:48 266552 ----a-w- c:\windows\system32\HMIPCore.dll
2010-04-07 11:10 . 2010-04-07 11:13 -------- d-----w- c:\documents and settings\User\Application Data\Hide IP NG
2010-03-30 15:01 . 2010-03-30 15:01 -------- d-----w- c:\program files\LogMeIn Hamachi
2010-03-29 15:44 . 2010-02-03 12:56 26176 ---ha-w- c:\windows\system32\hamachi.sys
2010-03-25 14:30 . 2010-03-25 14:30 -------- d-----w- c:\program files\Rockstar Games
2010-03-25 13:18 . 2010-03-25 13:18 -------- d-----w- c:\documents and settings\User\Application Data\SmartFTP
2010-03-25 13:18 . 2010-03-25 13:18 -------- d-----w- c:\program files\SmartFTP Client
2010-03-25 13:18 . 2010-03-25 13:18 -------- d-----w- c:\program files\SmartFTP Client 4.0 Setup Files

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-16 10:06 . 2009-10-28 13:54 1132 ----a-w- c:\windows\system32\drivers\APPFLTR.CFG.bck
2010-04-16 10:06 . 2009-10-28 13:54 1132 ----a-w- c:\windows\system32\drivers\APPFLTR.CFG
2010-04-16 10:06 . 2009-10-15 20:19 13880 ----a-w- c:\windows\system32\drivers\COMFiltr.sys
2010-04-16 10:05 . 2009-10-28 13:54 343120 ----a-w- c:\windows\system32\drivers\APPFCONT.DAT.bck
2010-04-16 10:05 . 2009-10-28 13:54 343120 ----a-w- c:\windows\system32\drivers\APPFCONT.DAT
2010-04-13 13:55 . 2008-01-14 15:58 -------- d-----w- c:\documents and settings\User\Application Data\uTorrent
2010-04-11 19:37 . 2008-01-10 21:17 -------- d-----w- c:\program files\LimeWire
2010-04-09 20:50 . 2010-04-09 20:49 503808 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-748fd146-n\msvcp71.dll
2010-04-09 20:49 . 2010-04-09 20:49 499712 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-748fd146-n\jmc.dll
2010-04-09 20:49 . 2010-04-09 20:49 348160 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-748fd146-n\msvcr71.dll
2010-04-09 20:49 . 2010-04-09 20:49 61440 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-28638271-n\decora-sse.dll
2010-04-09 20:49 . 2010-04-09 20:49 12800 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-28638271-n\decora-d3d.dll
2010-04-09 20:47 . 2008-01-10 10:51 -------- d-----w- c:\program files\Java
2010-04-06 11:11 . 2006-05-15 16:27 96688 ----a-w- c:\windows\system32\perfc008.dat
2010-04-06 11:11 . 2006-05-15 16:27 554772 ----a-w- c:\windows\system32\perfh008.dat
2010-03-12 14:08 . 2009-02-06 13:29 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-03-11 16:50 . 2009-02-09 12:01 -------- d-----w- c:\documents and settings\User\Application Data\Recruitment Viewer
2010-03-11 12:33 . 2004-09-04 13:45 832512 ----a-w- c:\windows\system32\wininet.dll
2010-03-11 12:33 . 2004-09-04 13:45 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:33 . 2004-09-04 13:45 17408 ------w- c:\windows\system32\corpol.dll
2010-03-09 11:10 . 2004-09-04 13:45 430080 ----a-w- c:\windows\system32\vbscript.dll
2010-03-09 01:28 . 2009-02-09 18:12 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-02 12:17 . 2008-01-10 10:52 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-01 11:47 . 2010-02-27 10:42 -------- d-----w- c:\program files\Capcom
2010-02-27 10:39 . 2010-02-27 10:38 -------- d-----w- c:\program files\MagicDisc
2010-02-24 13:11 . 2004-08-04 06:15 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-19 15:03 . 2008-01-14 20:26 66512 ----a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-18 15:23 . 2008-01-10 21:58 -------- d-----w- c:\program files\Microsoft Games
2010-02-18 15:19 . 2010-02-18 15:19 -------- d-----w- c:\documents and settings\User\Application Data\FarStone
2010-02-18 15:15 . 2010-02-18 15:15 65536 ----a-w- c:\windows\system32\GDPersns.dat
2010-02-18 15:14 . 2010-02-18 15:14 -------- d-----w- c:\program files\FarStone
2010-02-18 15:14 . 2010-02-18 15:14 90112 ----a-w- c:\windows\system32\Dversion.dll
2010-02-18 15:14 . 2010-02-18 15:14 126976 ----a-w- c:\windows\system32\DVC.dll
2010-02-18 14:07 . 2010-02-18 14:07 152576 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-02-18 14:07 . 2009-11-08 20:35 79488 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-17 11:06 . 2004-09-04 13:41 2196992 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:06 . 2006-03-02 09:00 2073856 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 12:53 . 2010-02-12 12:51 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2010-02-12 04:34 . 2004-09-04 13:44 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2004-08-04 06:07 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
2010-01-27 14:10 . 2009-09-25 16:12 611640 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2008-03-20 10:24 . 2008-03-20 10:22 24 --sha-w- c:\windows\S3201ED5C.tmp
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-10 218032]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-07-02 397312]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-13 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-13 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-13 138008]
"PDF Complete"="c:\program files\PDF Complete\pdfsty.exe" [2007-08-07 331288]
"SetRefresh"="c:\program files\Compaq\SetRefresh\SetRefresh.exe" [2003-11-20 525824]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2006-09-10 218032]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-10 86960]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-10-23 233472]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-09-01 176128]
"DeviceDiscovery"="c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2003-05-21 229437]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-01-31 385024]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-02-04 267048]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-03-27 593920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"APVXDWIN"="c:\program files\Panda Security\Panda Global Protection 2010\APVXDWIN.EXE" [2009-06-05 574720]
"SCANINICIO"="c:\program files\Panda Security\Panda Global Protection 2010\Inicio.exe" [2009-04-21 56064]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-09-23 1657448]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"GameDrive"="c:\program files\FarStone\GameDrive\GDP\GDTask.exe" [2006-07-21 167936]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 1820040]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\User\Start Menu\šα˜˜\΅΅εžž\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2010-2-27 576000]

c:\documents and settings\All Users\Start Menu\šα˜˜\΅΅εžž\
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2008-3-7 131072]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-5-23 122880]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
2008-03-18 13:58 58672 ----a-w- c:\windows\system32\avldr.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PskSvcRetail]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Documents and Settings\\User\\Επιφάνεια εργασίας\\Guns 'N' Roses\\uTorrent.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

R0 FGXSCSI;FGXSCSI;c:\windows\system32\drivers\fgxscsi.sys [18/2/2010 6:15 μμ 71680]
R0 pavboot;Panda boot driver;c:\windows\system32\drivers\pavboot.sys [5/4/2009 4:23 μμ 28544]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [21/5/2008 5:03 μμ 691696]
R1 APPFLT;App Filter Plugin;c:\windows\system32\drivers\APPFLT.SYS [15/10/2009 11:13 μμ 73728]
R1 DSAFLT;DSA Filter Plugin;c:\windows\system32\drivers\dsaflt.sys [15/10/2009 11:14 μμ 52992]
R1 FNETMON;NetMon Filter Plugin;c:\windows\system32\drivers\fnetmon.sys [15/10/2009 11:13 μμ 22072]
R1 IDSFLT;Ids Filter Plugin;c:\windows\system32\drivers\idsflt.sys [15/10/2009 11:14 μμ 193792]
R1 NETFLTDI;Panda Net Driver [TDI Layer];c:\windows\system32\drivers\NETFLTDI.SYS [15/10/2009 11:13 μμ 158848]
R1 ShldDrv;Panda File Shield Driver;c:\windows\system32\drivers\ShlDrv51.sys [15/10/2009 11:02 μμ 41144]
R1 SSHDRV79;SSHDRV79;c:\windows\system32\drivers\SSHDRV79.sys [28/10/2009 4:54 μμ 75264]
R1 SSHDRV85;SSHDRV85;c:\windows\system32\drivers\SSHDRV85.sys [1/12/2009 3:30 μμ 78848]
R1 WNMFLT;Wifi Monitor Filter Plugin;c:\windows\system32\drivers\wnmflt.sys [15/10/2009 11:14 μμ 46720]
R2 Gwmsrv;Panda Goodware Cache Manager;c:\windows\system32\svchost -k Panda --> c:\windows\system32\svchost -k Panda [?]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [30/3/2010 11:16 πμ 1107336]
R2 INFOlearn_admin_srv;INFOlearn Admin Service;c:\windows\system32\infolearnasrv.exe [6/10/2006 8:35 μμ 49152]
R2 PavProc;Panda Process Protection Driver;c:\windows\system32\drivers\PavProc.sys [15/10/2009 11:02 μμ 177416]
R2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [10/1/2008 1:54 μμ 540184]
R2 PskSvcRetail;Panda PSK service;c:\program files\Panda Security\Panda Global Protection 2010\psksvc.exe [15/10/2009 11:13 μμ 28928]
R3 AvFlt;Antivirus Filter Driver;c:\windows\system32\drivers\av5flt.sys --> c:\windows\system32\drivers\av5flt.sys [?]
R3 ComFiltr;Panda Anti-Dialer;c:\windows\system32\drivers\COMFiltr.sys [15/10/2009 11:19 μμ 13880]
R3 NETIMFLT01060034;PANDA NDIS IM Filter Miniport v1.6.0.34;c:\windows\system32\drivers\neti1634.sys [15/10/2009 11:13 μμ 197888]
R3 PavSRK.sys;PavSRK.sys;\??\c:\windows\system32\PavSRK.sys --> c:\windows\system32\PavSRK.sys [?]
R3 PavTPK.sys;PavTPK.sys;\??\c:\windows\system32\PavTPK.sys --> c:\windows\system32\PavTPK.sys [?]
S1 SSHDRV65;SSHDRV65;\??\c:\windows\system32\drivers\SSHDRV65.sys --> c:\windows\system32\drivers\SSHDRV65.sys [?]
S3 P1130VID;Creative WebCam NX Pro;c:\windows\system32\drivers\P1130Vid.sys [4/2/2008 5:25 μμ 90357]
S3 PCD65X2;PCD65X2;\??\c:\docume~1\User\LOCALS~1\Temp\PCD65X2.sys --> c:\docume~1\User\LOCALS~1\Temp\PCD65X2.sys [?]
S3 PCD65X3;PCD65X3;\??\c:\docume~1\User\LOCALS~1\Temp\PCD65X3.sys --> c:\docume~1\User\LOCALS~1\Temp\PCD65X3.sys [?]
S3 PCD65X4;PCD65X4;\??\c:\docume~1\User\LOCALS~1\Temp\PCD65X4.sys --> c:\docume~1\User\LOCALS~1\Temp\PCD65X4.sys [?]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [30/6/2009 9:32 μμ 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [30/6/2009 9:32 μμ 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [30/6/2009 9:32 μμ 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [30/6/2009 9:32 μμ 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [30/6/2009 9:32 μμ 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [30/6/2009 9:32 μμ 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [30/6/2009 9:32 μμ 115752]
S3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\drivers\s0017bus.sys [30/6/2009 9:32 μμ 90536]
S3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\drivers\s0017mdfl.sys [30/6/2009 9:32 μμ 15016]
S3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\drivers\s0017mdm.sys [30/6/2009 9:32 μμ 122152]
S3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0017mgmt.sys [30/6/2009 9:32 μμ 115496]
S3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\drivers\s0017nd5.sys [30/6/2009 9:32 μμ 25768]
S3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\drivers\s0017obex.sys [30/6/2009 9:32 μμ 111912]
S3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\drivers\s0017unic.sys [30/6/2009 9:32 μμ 117672]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
panda REG_MULTI_SZ Gwmsrv
.
Contents of the 'Scheduled Tasks' folder

2010-04-16 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 12:07]
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
uSearchMigratedDefaultURL = [You must be registered and logged in to see this link.]
uInternet Connection Wizard,ShellNext = iexplore
IE: Download the ¤t page with Offline Explorer - [You must be registered and logged in to see this link.] files\Offline Explorer\Add_AllO.htm
IE: Download using Offline &Explorer - [You must be registered and logged in to see this link.] files\Offline Explorer\Add_UrlO.htm
IE: Ε&ξαγωγή στο Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\cu6zhwsp.default\
FF - prefs.js: browser.search.defaulturl - [You must be registered and logged in to see this link.]
FF - prefs.js: browser.search.selectedEngine - isoHunt Customized Web Search
FF - prefs.js: browser.startup.homepage - [You must be registered and logged in to see this link.]
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npff_gdm.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-RGSC - c:\program files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe
AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe
AddRemove-HijackThis - c:\documents and settings\User\Επιφάνεια εργασίας\HijackThis.exe
AddRemove-{D5BB0907-4BB2-46A3-AA68-0173D111058D} - c:\program files\FarStone\GameDrive\Setup.exe
AddRemove-{F5223680-993A-11D4-86F6-0001031E5712} - c:\program files\InterVideo\Installer\IVIUninstaller.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2010-04-16 13:03
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwEnumerateKey, ZwClose, ZwEnumerateValueKey, ZwQueryValueKey, ZwOpenFile

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, [You must be registered and logged in to see this link.]

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll sfsync02.sys atapi.sys spyp.sys >>UNKNOWN [0x8ADEC938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xb80ecf28
\Driver\ACPI -> ACPI.sys @ 0xb7e73cb8
\Driver\atapi -> sfsync02.sys @ 0xb8340d60
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->NDIS: Broadcom NetLink (TM) Gigabit Ethernet -> SendCompleteHandler -> NDIS.sys @ 0xb7cecbb0
PacketIndicateHandler -> NDIS.sys @ 0xb7cf9a21
SendHandler -> NDIS.sys @ 0xb7cd787b
user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-4160596134-3961019470-752118726-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-4160596134-3961019470-752118726-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:16,10,41,ed,64,3d,77,f2,44,9e,32,86,e1,f1,8f,c6,19,aa,b3,67,76,a2,d2,
73,61,f4,91,60,e8,8e,09,5d,f5,db,35,bd,f1,b2,26,dc,8a,86,20,0e,c9,1e,4f,98,\
"??"=hex:c2,59,d1,1c,d4,d2,90,9f,4a,b4,64,fe,e2,10,24,81

[HKEY_USERS\S-1-5-21-4160596134-3961019470-752118726-1005\Software\SecuROM\License information*]
"datasecu"=hex:4e,10,57,e3,ee,b9,10,cd,ed,b0,f4,0a,39,5b,5d,c4,f4,5c,f9,8d,eb,
25,1d,10,c6,8f,ff,9b,72,ca,0a,32,3c,29,20,a5,3a,7e,00,95,4e,90,cb,5d,c2,27,\
"rkeysecu"=hex:8b,a4,d9,a9,1b,8f,88,92,bf,ca,aa,f3,89,e8,18,92
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1020)
c:\windows\system32\avldr.dll

- - - - - - - > 'explorer.exe'(3816)
c:\program files\TortoiseSVN\bin\tortoisesvn.dll
c:\program files\TortoiseSVN\bin\intl3_svn.dll
c:\program files\SmartFTP Client\en-US\sfShellTools.dll.mui
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Panda Security\Panda Global Protection 2010\TPSrv.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Panda Security\Panda Global Protection 2010\PsCtrls.exe
c:\program files\Panda Security\Panda Global Protection 2010\PavFnSvr.exe
c:\program files\Common Files\Panda Security\PavShld\pavprsrv.exe
c:\program files\panda security\panda global protection 2010\firewall\PSHOST.EXE
c:\program files\Panda Security\Panda Global Protection 2010\PsImSvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Panda Security\Panda Global Protection 2010\pavsrv51.exe
c:\program files\Panda Security\Panda Global Protection 2010\AVENGINE.EXE
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\TortoiseSVN\bin\TSVNCache.exe
c:\program files\Common Files\Teleca Shared\CapabilityManager.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Teleca Shared\Generic.exe
c:\program files\Panda Security\Panda Global Protection 2010\PavBckPT.exe
c:\program files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
c:\program files\Panda Security\Panda Global Protection 2010\WebProxy.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-04-16 13:10:11 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-16 10:10

Pre-Run: 25 Κατάλογοι 52.391.751.680 διαθέσιμα byte
Post-Run: 28 Κατάλογοι 59.941.031.936 διαθέσιμα byte

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
C:\wubildr.mbr = "Ubuntu"

- - End Of File - - 32E71DB8886B3305FA96458A65A8C62A


My internet still lags...



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Fri Apr 16, 2010 11:16 am

I run malwarebytes again but this time on full scan to see why my internet continues to lag and got this:

Malwarebytes' Anti-Malware 1.45
[You must be registered and logged in to see this link.]

Έκδοση βάσης δεδομένων: 3990

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

16/4/2010 2:15:43 μμ
mbam-log-2010-04-16 (14-15-43).txt

Τύπος σάρωσης: Πλήρης σάρωση (C:\|D:\|)
Αντικείμενα που σαρώθηκαν: 228253
Χρόνος που έχει διανυθεί: 50 λεπτό(ά), 48 δευτερόλεπτο(α)

Μολυσμένες διεργασίες στη μνήμη: 0
Μολυσμένα στοιχεία στη μνήμη: 0
Μολυσμένα κλειδιά στο μητρώο: 0
Μολυσμένες τιμές στο μητρώο: 0
Μολυσμένα αντικείμενα δεδομένων στο μητρώο: 0
Μολυσμένοι φάκελοι: 0
Μολυσμένα αρχεία: 2

Μολυσμένες διεργασίες στη μνήμη:
(Δεν εντοπίστηκαν επιβλαβή αντικείμενα)

Μολυσμένα στοιχεία στη μνήμη:
(Δεν εντοπίστηκαν επιβλαβή αντικείμενα)

Μολυσμένα κλειδιά στο μητρώο:
(Δεν εντοπίστηκαν επιβλαβή αντικείμενα)

Μολυσμένες τιμές στο μητρώο:
(Δεν εντοπίστηκαν επιβλαβή αντικείμενα)

Μολυσμένα αντικείμενα δεδομένων στο μητρώο:
(Δεν εντοπίστηκαν επιβλαβή αντικείμενα)

Μολυσμένοι φάκελοι:
(Δεν εντοπίστηκαν επιβλαβή αντικείμενα)

Μολυσμένα αρχεία:
C:\System Volume Information\_restore{9D141A0A-D8A0-4AAD-A9B0-8D979F5057F9}\RP775\A0167407.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{9D141A0A-D8A0-4AAD-A9B0-8D979F5057F9}\RP775\A0167408.exe (Trojan.Downloader) -> Quarantined and deleted successfully.


What the heck? Will those damn viruses stop infecting my pc? Where did they come from?



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Fri Apr 16, 2010 2:18 pm

Maybe I'm beeing hacked? Internet sometimes is ok and other lags like hell. In the past it didn't do so and others with the same connection as mine don't have any of these lag problems..



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Belahzur on Fri Apr 16, 2010 8:28 pm

Hello.
I see the problem, but this malware has 2 versions right now, either you have the old version and this will die easily. Or, you have the newer version, and it's gonna put up a fight and wont die easily. =/

Download the GMER rootkit scan from here: [You must be registered and logged in to see this link.]

  1. Unzip it and start GMER.
  2. Click the >>> tab and then click the Scan button.
  3. Once done, click the Copy button.
  4. This will copy the results to your clipboard.
  5. Paste the results in your next reply.
Note:
If you're having problems with running GMER.exe, try it in safe mode. This tools works in safe mode.
You can also try renaming it since some malware blocks GMER.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Sun Apr 18, 2010 11:19 am

Somehow I didn't save it the first time, but I did it again and saved it, is it bad? Internet seems ok now, can you inform me of that malware and if it's been deleted?

Here is the log from gmer:

GMER 1.0.15.15281 - [You must be registered and logged in to see this link.]
Rootkit scan 2010-04-18 01:02:16
Windows 5.1.2600 Service Pack 3
Running: b9j1djej.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fgloapod.sys


---- Kernel code sections - GMER 1.0.15 ----

.text C:\WINDOWS\system32\drivers\SSHDRV79.sys section is writeable [0xB85BD000, 0x2247E, 0xE8000020]
.pklstb C:\WINDOWS\system32\drivers\SSHDRV79.sys entry point in ".pklstb" section [0xB85EE000]
.relo2 C:\WINDOWS\system32\drivers\SSHDRV79.sys unknown last section [0xB8603000, 0x8A, 0x42000040]
.text C:\WINDOWS\system32\drivers\SSHDRV85.sys section is writeable [0xB8572000, 0x24A24, 0xE8000020]
.pklstb C:\WINDOWS\system32\drivers\SSHDRV85.sys entry point in ".pklstb" section [0xB85A5000]
.relo2 C:\WINDOWS\system32\drivers\SSHDRV85.sys unknown last section [0xB85BB000, 0x8E, 0x42000040]

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\x2018\3Γ\3Ν\3\xb3\3Η\3Α\3Ώ\3\xbd\3Ώ\3Β\3 \0ΐ\3Α\3Ώ\3Γ\3\xb1\3Α\3Ό\3Ώ\3\xb3\3\xad\3\xb1\3Β\3 \0R\0A\0S 1?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\xa0\3\xb1\3Ί\3\xad\3Δ\3Ώ\3 \0Η\3Α\3Ώ\3\xbd\3Ώ\3\x384\3Ή\3\xb1\3\xb3\3Α\3\xac\3Ό\3Ό\3\xb1\3Δ\3Ώ\3Β\3 \0M\0i\0n\0i\0p\0o\0r\0t 1?2?3?4?5?6?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\x2018\3ΐ\3\3Ε\3Έ\3\3\x2015\3\xb1\3Β\3 \0ΐ\3\xb1\3Α\3\xac\3\xbb\3\xbb\3\xb7\3\xbb\3\xb7\3 1?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\xa3\3Ν\3\xbd\3\x384\3\3Γ\3\xb7\3 \0Δ\3\xb7\3\xbb\3\3Μ\3Α\3\xb1\3Γ\3\xb7\3Β\3/\0\xb2\3\x2015\3\xbd\3Δ\3\3Ώ\3 \0Δ\3\xb7\3Β\3 \0M\0i\0c\0r\0o\0s\0o\0f\0t 1?
Reg HKLM\SYSTEM\CurrentControlSet\Services\FGXSCSI\Parameters\PnpInterface@0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x38 0x0F 0x98 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xA4 0xE9 0x52 0xD3 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xFA 0xCE 0x0B 0x75 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xCB 0xA7 0xF1 0xC2 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xD2 0xD7 0x2F 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x25 0x41 0xC1 0x5A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xA0 0x54 0x09 0x3C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x09 0xB6 0x21 0xB4 ...
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\x2018\3Γ\3Ν\3\xb3\3Η\3Α\3Ώ\3\xbd\3Ώ\3Β\3 \0ΐ\3Α\3Ώ\3Γ\3\xb1\3Α\3Ό\3Ώ\3\xb3\3\xad\3\xb1\3Β\3 \0R\0A\0S 1?
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\xa0\3\xb1\3Ί\3\xad\3Δ\3Ώ\3 \0Η\3Α\3Ώ\3\xbd\3Ώ\3\x384\3Ή\3\xb1\3\xb3\3Α\3\xac\3Ό\3Ό\3\xb1\3Δ\3Ώ\3Β\3 \0M\0i\0n\0i\0p\0o\0r\0t 1?2?3?4?5?6?
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\x2018\3ΐ\3\3Ε\3Έ\3\3\x2015\3\xb1\3Β\3 \0ΐ\3\xb1\3Α\3\xac\3\xbb\3\xbb\3\xb7\3\xbb\3\xb7\3 1?
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\xa3\3Ν\3\xbd\3\x384\3\3Γ\3\xb7\3 \0Δ\3\xb7\3\xbb\3\3Μ\3Α\3\xb1\3Γ\3\xb7\3Β\3/\0\xb2\3\x2015\3\xbd\3Δ\3\3Ώ\3 \0Δ\3\xb7\3Β\3 \0M\0i\0c\0r\0o\0s\0o\0f\0t 1?
Reg HKLM\SYSTEM\ControlSet002\Services\FGXSCSI\Parameters\PnpInterface@0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x38 0x0F 0x98 0x02 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xA4 0xE9 0x52 0xD3 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xFA 0xCE 0x0B 0x75 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xCB 0xA7 0xF1 0xC2 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xD2 0xD7 0x2F 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x25 0x41 0xC1 0x5A ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xA0 0x54 0x09 0x3C ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x09 0xB6 0x21 0xB4 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x28 0xE7 0xC2 0x70 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x25 0x41 0xC1 0x5A ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xDC 0x0C 0xB0 0xC5 ...

---- EOF - GMER 1.0.15 ----



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Belahzur on Sun Apr 18, 2010 5:03 pm

Please download SystemLook from one of the links below and save it to your Desktop.
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    Code:

    :filefind
    sfsync02.sys
    atapi.sys
    SSHDRV79.sys
    SSHDRV85.sys

  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Sun Apr 18, 2010 5:44 pm

SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 20:42 on 18/04/2010 by User (Administrator - Elevation successful)

========== filefind ==========

Searching for "sfsync02.sys"
C:\Documents and Settings\User\Επιφάνεια εργασίας\Guns 'N' Roses\drivers\sfsync02.sys --a--- 20544 bytes [10:20 03/12/2004] [10:20 03/12/2004] 798D918D8F20380008277CE3CE5319D1
C:\WINDOWS\system32\drivers\sfsync02.sys --a--- 20544 bytes [13:54 28/10/2009] [10:20 03/12/2004] 798D918D8F20380008277CE3CE5319D1

Searching for "atapi.sys"
C:\WINDOWS\$NtServicePackUninstall$\atapi.sys -----c 95360 bytes [21:45 15/09/2008] [20:59 03/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51
C:\WINDOWS\ERDNT\cache\atapi.sys --a--- 96512 bytes [10:09 16/04/2010] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\ServicePackFiles\i386\atapi.sys ------ 96512 bytes [18:40 13/04/2008] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\system32\drivers\atapi.sys --a--- 96512 bytes [05:59 04/08/2004] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\i386\atapi.sys --a--- 95360 bytes [10:45 10/01/2008] [05:59 04/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51
C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\i386\atapi.sys --a--- 95360 bytes [10:45 10/01/2008] [20:59 03/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51

Searching for "SSHDRV79.sys"
C:\Documents and Settings\User\Επιφάνεια εργασίας\Guns 'N' Roses\drivers\SSHDRV79.sys --a--- 75264 bytes [23:16 03/05/2008] [23:16 03/05/2008] B4710B65D78849DD7743B8998162C2FC
C:\WINDOWS\system32\drivers\SSHDRV79.sys --a--- 75264 bytes [13:54 28/10/2009] [23:16 03/05/2008] B4710B65D78849DD7743B8998162C2FC

Searching for "SSHDRV85.sys"
C:\WINDOWS\system32\drivers\SSHDRV85.sys --a--- 78848 bytes [12:30 01/12/2009] [12:30 01/12/2009] F0BE373861A3F34CFAB55C1B7CE1FEB5

-=End Of File=-



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Belahzur on Sun Apr 18, 2010 6:16 pm

Hello.
I am consulting with an expert, stay with me here, something confusing I wasn't expecting to see here.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Belahzur on Sun Apr 18, 2010 6:24 pm

Hello, please re-run GMER, this time, tick all the boxes on the right, except for "show all", I need to see as much as I can.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Sun Apr 18, 2010 6:35 pm

Alright, gmer takes 2 hours though...



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Belahzur on Sun Apr 18, 2010 6:36 pm

Cause it has a lot to scan? I need as much detail as possible, even if it shows no difference, I'm not leaving it to chance.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Sun Apr 18, 2010 6:37 pm

By the way the previous time everything was checked, so shall I do the same?



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Belahzur on Sun Apr 18, 2010 6:42 pm

Yes please, while doing that I am talking to another expert about this, something weird is going on.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Sun Apr 18, 2010 6:44 pm

Alright, I'll be off for a while to run gmer on safe mode. I will be back as soon as possible



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Belahzur on Sun Apr 18, 2010 7:18 pm

Hello.
Do you have the XP disc? we need a copy of some infected files.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Mon Apr 19, 2010 9:33 am

The xp which I have installed my windows? I think not but I shall search. By the way I shall post the results of gmer as soon as possible



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Mon Apr 19, 2010 10:00 am

I don't think that it has to do with my XP, because I would have this problem from the start. Check out this as someone has given this to me. This might be the problem.
-
Note: It contains viruses and other things which we found with the scan of malwerbytes (keylogers, viruses, etc)



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Belahzur on Mon Apr 19, 2010 10:26 am

I removed the link, please don't post links to something that contains malware, sites or archived files.

I will be back later when I am at home and have access to my toolkit.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Mon Apr 19, 2010 11:29 am

You saved the link or I will have to pm you?

Inform me when you can



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Belahzur on Mon Apr 19, 2010 2:59 pm

Don't need the link if the file contains malware, what MBAM found is nothing compared to this infection.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Mon Apr 19, 2010 3:08 pm

So what can do now? I will run gmer in 10 mins again, because yesterday I left and didn't save it..



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Belahzur on Mon Apr 19, 2010 3:18 pm

Hello.
I want to test something.


  • Download [You must be registered and logged in to see this link.] and save it to your Desktop.
  • Extract its contents to your desktop and make sure TDSSKiller.exe (the contents of the zipped file) is on the Desktop itself, not within a folder on the desktop.
  • Go to Start > Run (Or you can hold down your Windows key and press R) and copy and paste the following into the text field. (make sure you include the quote marks) Then press OK.

    "%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v

  • If it says "Hidden service detected" DO NOT type anything in. Just press Enter on your keyboard to not do anything to the file.
  • When it is done, a log file should be created on your C: drive called "TDSSKiller.txt" please copy and paste the contents of that file here.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Mon Apr 19, 2010 6:22 pm

When I do it, it says that it couldn't file the file, even though thee tdss is on the desktop. I tried to rename it on tdss.exe and still nothing.. But I looked on C: and here is the file:

21:18:26:671 5368 TDSS rootkit removing tool 2.2.8.1 Mar 22 2010 10:43:04
21:18:26:671 5368 ================================================================================
21:18:26:671 5368 SystemInfo:

21:18:26:671 5368 OS Version: 5.1.2600 ServicePack: 3.0
21:18:26:671 5368 Product type: Workstation
21:18:26:671 5368 ComputerName: HP11546321382
21:18:26:671 5368 UserName: User
21:18:26:671 5368 Windows directory: C:\WINDOWS
21:18:26:671 5368 Processor architecture: Intel x86
21:18:26:671 5368 Number of processors: 1
21:18:26:671 5368 Page size: 0x1000
21:18:26:671 5368 Boot type: Normal boot
21:18:26:671 5368 ================================================================================
21:18:26:671 5368 UnloadDriverW: NtUnloadDriver error 2
21:18:26:671 5368 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
21:18:26:781 5368 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
21:18:26:781 5368 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
21:18:26:781 5368 wfopen_ex: Trying to KLMD file open
21:18:26:781 5368 wfopen_ex: File opened ok (Flags 2)
21:18:26:781 5368 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
21:18:26:781 5368 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
21:18:26:781 5368 wfopen_ex: Trying to KLMD file open
21:18:26:781 5368 wfopen_ex: File opened ok (Flags 2)
21:18:26:781 5368 Initialize success
21:18:26:781 5368
21:18:26:781 5368 Scanning Services ...
21:18:27:484 5368 Raw services enum returned 427 services
21:18:27:500 5368
21:18:27:500 5368 Scanning Kernel memory ...
21:18:27:500 5368 Devices to scan: 4
21:18:27:500 5368
21:18:27:500 5368 Driver Name: Disk
21:18:27:500 5368 IRP_MJ_CREATE : B80EEBB0
21:18:27:500 5368 IRP_MJ_CREATE_NAMED_PIPE : 804F355A
21:18:27:500 5368 IRP_MJ_CLOSE : B80EEBB0
21:18:27:500 5368 IRP_MJ_READ : B80E8D1F
21:18:27:500 5368 IRP_MJ_WRITE : B80E8D1F
21:18:27:500 5368 IRP_MJ_QUERY_INFORMATION : 804F355A
21:18:27:500 5368 IRP_MJ_SET_INFORMATION : 804F355A
21:18:27:500 5368 IRP_MJ_QUERY_EA : 804F355A
21:18:27:500 5368 IRP_MJ_SET_EA : 804F355A
21:18:27:500 5368 IRP_MJ_FLUSH_BUFFERS : B80E92E2
21:18:27:500 5368 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F355A
21:18:27:500 5368 IRP_MJ_SET_VOLUME_INFORMATION : 804F355A
21:18:27:500 5368 IRP_MJ_DIRECTORY_CONTROL : 804F355A
21:18:27:500 5368 IRP_MJ_FILE_SYSTEM_CONTROL : 804F355A
21:18:27:500 5368 IRP_MJ_DEVICE_CONTROL : B80E93BB
21:18:27:500 5368 IRP_MJ_INTERNAL_DEVICE_CONTROL : B80ECF28
21:18:27:500 5368 IRP_MJ_SHUTDOWN : B80E92E2
21:18:27:500 5368 IRP_MJ_LOCK_CONTROL : 804F355A
21:18:27:500 5368 IRP_MJ_CLEANUP : 804F355A
21:18:27:500 5368 IRP_MJ_CREATE_MAILSLOT : 804F355A
21:18:27:500 5368 IRP_MJ_QUERY_SECURITY : 804F355A
21:18:27:500 5368 IRP_MJ_SET_SECURITY : 804F355A
21:18:27:500 5368 IRP_MJ_POWER : B80EAC82
21:18:27:500 5368 IRP_MJ_SYSTEM_CONTROL : B80EF99E
21:18:27:500 5368 IRP_MJ_DEVICE_CHANGE : 804F355A
21:18:27:500 5368 IRP_MJ_QUERY_QUOTA : 804F355A
21:18:27:500 5368 IRP_MJ_SET_QUOTA : 804F355A
21:18:27:593 5368 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
21:18:27:593 5368
21:18:27:593 5368 Driver Name: Disk
21:18:27:593 5368 IRP_MJ_CREATE : B80EEBB0
21:18:27:593 5368 IRP_MJ_CREATE_NAMED_PIPE : 804F355A
21:18:27:593 5368 IRP_MJ_CLOSE : B80EEBB0
21:18:27:593 5368 IRP_MJ_READ : B80E8D1F
21:18:27:593 5368 IRP_MJ_WRITE : B80E8D1F
21:18:27:593 5368 IRP_MJ_QUERY_INFORMATION : 804F355A
21:18:27:593 5368 IRP_MJ_SET_INFORMATION : 804F355A
21:18:27:593 5368 IRP_MJ_QUERY_EA : 804F355A
21:18:27:593 5368 IRP_MJ_SET_EA : 804F355A
21:18:27:593 5368 IRP_MJ_FLUSH_BUFFERS : B80E92E2
21:18:27:593 5368 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F355A
21:18:27:593 5368 IRP_MJ_SET_VOLUME_INFORMATION : 804F355A
21:18:27:593 5368 IRP_MJ_DIRECTORY_CONTROL : 804F355A
21:18:27:593 5368 IRP_MJ_FILE_SYSTEM_CONTROL : 804F355A
21:18:27:593 5368 IRP_MJ_DEVICE_CONTROL : B80E93BB
21:18:27:593 5368 IRP_MJ_INTERNAL_DEVICE_CONTROL : B80ECF28
21:18:27:593 5368 IRP_MJ_SHUTDOWN : B80E92E2
21:18:27:593 5368 IRP_MJ_LOCK_CONTROL : 804F355A
21:18:27:593 5368 IRP_MJ_CLEANUP : 804F355A
21:18:27:593 5368 IRP_MJ_CREATE_MAILSLOT : 804F355A
21:18:27:593 5368 IRP_MJ_QUERY_SECURITY : 804F355A
21:18:27:593 5368 IRP_MJ_SET_SECURITY : 804F355A
21:18:27:593 5368 IRP_MJ_POWER : B80EAC82
21:18:27:593 5368 IRP_MJ_SYSTEM_CONTROL : B80EF99E
21:18:27:593 5368 IRP_MJ_DEVICE_CHANGE : 804F355A
21:18:27:593 5368 IRP_MJ_QUERY_QUOTA : 804F355A
21:18:27:593 5368 IRP_MJ_SET_QUOTA : 804F355A
21:18:27:593 5368 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
21:18:27:593 5368
21:18:27:593 5368 Driver Name: atapi
21:18:27:593 5368 IRP_MJ_CREATE : B7E08B40
21:18:27:593 5368 IRP_MJ_CREATE_NAMED_PIPE : 804F355A
21:18:27:593 5368 IRP_MJ_CLOSE : B7E08B40
21:18:27:593 5368 IRP_MJ_READ : 804F355A
21:18:27:593 5368 IRP_MJ_WRITE : 804F355A
21:18:27:593 5368 IRP_MJ_QUERY_INFORMATION : 804F355A
21:18:27:593 5368 IRP_MJ_SET_INFORMATION : 804F355A
21:18:27:593 5368 IRP_MJ_QUERY_EA : 804F355A
21:18:27:593 5368 IRP_MJ_SET_EA : 804F355A
21:18:27:593 5368 IRP_MJ_FLUSH_BUFFERS : 804F355A
21:18:27:593 5368 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F355A
21:18:27:593 5368 IRP_MJ_SET_VOLUME_INFORMATION : 804F355A
21:18:27:593 5368 IRP_MJ_DIRECTORY_CONTROL : 804F355A
21:18:27:593 5368 IRP_MJ_FILE_SYSTEM_CONTROL : 804F355A
21:18:27:593 5368 IRP_MJ_DEVICE_CONTROL : B7E08B40
21:18:27:593 5368 IRP_MJ_INTERNAL_DEVICE_CONTROL : B8340D60
21:18:27:593 5368 IRP_MJ_SHUTDOWN : 804F355A
21:18:27:593 5368 IRP_MJ_LOCK_CONTROL : 804F355A
21:18:27:593 5368 IRP_MJ_CLEANUP : 804F355A
21:18:27:593 5368 IRP_MJ_CREATE_MAILSLOT : 804F355A
21:18:27:593 5368 IRP_MJ_QUERY_SECURITY : 804F355A
21:18:27:593 5368 IRP_MJ_SET_SECURITY : 804F355A
21:18:27:593 5368 IRP_MJ_POWER : B7E08B40
21:18:27:593 5368 IRP_MJ_SYSTEM_CONTROL : B7E08B40
21:18:27:593 5368 IRP_MJ_DEVICE_CHANGE : 804F355A
21:18:27:593 5368 IRP_MJ_QUERY_QUOTA : 804F355A
21:18:27:593 5368 IRP_MJ_SET_QUOTA : 804F355A
21:18:27:593 5368 C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: 1
21:18:27:593 5368
21:18:27:593 5368 Driver Name: atapi
21:18:27:593 5368 IRP_MJ_CREATE : B7E08B40
21:18:27:593 5368 IRP_MJ_CREATE_NAMED_PIPE : 804F355A
21:18:27:593 5368 IRP_MJ_CLOSE : B7E08B40
21:18:27:593 5368 IRP_MJ_READ : 804F355A
21:18:27:593 5368 IRP_MJ_WRITE : 804F355A
21:18:27:593 5368 IRP_MJ_QUERY_INFORMATION : 804F355A
21:18:27:593 5368 IRP_MJ_SET_INFORMATION : 804F355A
21:18:27:593 5368 IRP_MJ_QUERY_EA : 804F355A
21:18:27:593 5368 IRP_MJ_SET_EA : 804F355A
21:18:27:593 5368 IRP_MJ_FLUSH_BUFFERS : 804F355A
21:18:27:593 5368 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F355A
21:18:27:593 5368 IRP_MJ_SET_VOLUME_INFORMATION : 804F355A
21:18:27:593 5368 IRP_MJ_DIRECTORY_CONTROL : 804F355A
21:18:27:593 5368 IRP_MJ_FILE_SYSTEM_CONTROL : 804F355A
21:18:27:593 5368 IRP_MJ_DEVICE_CONTROL : B7E08B40
21:18:27:593 5368 IRP_MJ_INTERNAL_DEVICE_CONTROL : B8340D60
21:18:27:593 5368 IRP_MJ_SHUTDOWN : 804F355A
21:18:27:593 5368 IRP_MJ_LOCK_CONTROL : 804F355A
21:18:27:593 5368 IRP_MJ_CLEANUP : 804F355A
21:18:27:593 5368 IRP_MJ_CREATE_MAILSLOT : 804F355A
21:18:27:593 5368 IRP_MJ_QUERY_SECURITY : 804F355A
21:18:27:593 5368 IRP_MJ_SET_SECURITY : 804F355A
21:18:27:593 5368 IRP_MJ_POWER : B7E08B40
21:18:27:593 5368 IRP_MJ_SYSTEM_CONTROL : B7E08B40
21:18:27:593 5368 IRP_MJ_DEVICE_CHANGE : 804F355A
21:18:27:593 5368 IRP_MJ_QUERY_QUOTA : 804F355A
21:18:27:593 5368 IRP_MJ_SET_QUOTA : 804F355A
21:18:27:593 5368 C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: 1
21:18:27:593 5368
21:18:27:593 5368 Completed
21:18:27:593 5368
21:18:27:593 5368 Results:
21:18:27:609 5368 Memory objects infected / cured / cured on reboot: 0 / 0 / 0
21:18:27:609 5368 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
21:18:27:609 5368 File objects infected / cured / cured on reboot: 0 / 0 / 0
21:18:27:609 5368
21:18:27:609 5368 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
21:18:27:609 5368 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
21:18:27:609 5368 KLMD(ARK) unloaded successfully


And here are the results of Gmer you asked me (only this time, I clicked on D: too because it enables me to store files there as if it was C: and you said to me to click all the fields available on the right):

GMER 1.0.15.15281 - [You must be registered and logged in to see this link.]
Rootkit scan 2010-04-19 21:12:19
Windows 5.1.2600 Service Pack 3
Running: b9j1djej.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\fgloapod.sys


---- Kernel code sections - GMER 1.0.15 ----

.text C:\WINDOWS\system32\drivers\SSHDRV79.sys section is writeable [0xB85BD000, 0x2247E, 0xE8000020]
.pklstb C:\WINDOWS\system32\drivers\SSHDRV79.sys entry point in ".pklstb" section [0xB85EE000]
.relo2 C:\WINDOWS\system32\drivers\SSHDRV79.sys unknown last section [0xB8603000, 0x8A, 0x42000040]
.text C:\WINDOWS\system32\drivers\SSHDRV85.sys section is writeable [0xB8572000, 0x24A24, 0xE8000020]
.pklstb C:\WINDOWS\system32\drivers\SSHDRV85.sys entry point in ".pklstb" section [0xB85A5000]
.relo2 C:\WINDOWS\system32\drivers\SSHDRV85.sys unknown last section [0xB85BB000, 0x8E, 0x42000040]

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\x2018\3Γ\3Ν\3\xb3\3Η\3Α\3Ώ\3\xbd\3Ώ\3Β\3 \0ΐ\3Α\3Ώ\3Γ\3\xb1\3Α\3Ό\3Ώ\3\xb3\3\xad\3\xb1\3Β\3 \0R\0A\0S 1?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\xa0\3\xb1\3Ί\3\xad\3Δ\3Ώ\3 \0Η\3Α\3Ώ\3\xbd\3Ώ\3\x384\3Ή\3\xb1\3\xb3\3Α\3\xac\3Ό\3Ό\3\xb1\3Δ\3Ώ\3Β\3 \0M\0i\0n\0i\0p\0o\0r\0t 1?2?3?4?5?6?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\x2018\3ΐ\3\3Ε\3Έ\3\3\x2015\3\xb1\3Β\3 \0ΐ\3\xb1\3Α\3\xac\3\xbb\3\xbb\3\xb7\3\xbb\3\xb7\3 1?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\xa3\3Ν\3\xbd\3\x384\3\3Γ\3\xb7\3 \0Δ\3\xb7\3\xbb\3\3Μ\3Α\3\xb1\3Γ\3\xb7\3Β\3/\0\xb2\3\x2015\3\xbd\3Δ\3\3Ώ\3 \0Δ\3\xb7\3Β\3 \0M\0i\0c\0r\0o\0s\0o\0f\0t 1?
Reg HKLM\SYSTEM\CurrentControlSet\Services\FGXSCSI\Parameters\PnpInterface@0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x38 0x0F 0x98 0x02 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x47 0x95 0xFC 0x5F ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xFA 0xCE 0x0B 0x75 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xCB 0xA7 0xF1 0xC2 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xD2 0xD7 0x2F 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x25 0x41 0xC1 0x5A ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xA0 0x54 0x09 0x3C ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x09 0xB6 0x21 0xB4 ...
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\x2018\3Γ\3Ν\3\xb3\3Η\3Α\3Ώ\3\xbd\3Ώ\3Β\3 \0ΐ\3Α\3Ώ\3Γ\3\xb1\3Α\3Ό\3Ώ\3\xb3\3\xad\3\xb1\3Β\3 \0R\0A\0S 1?
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\xa0\3\xb1\3Ί\3\xad\3Δ\3Ώ\3 \0Η\3Α\3Ώ\3\xbd\3Ώ\3\x384\3Ή\3\xb1\3\xb3\3Α\3\xac\3Ό\3Ό\3\xb1\3Δ\3Ώ\3Β\3 \0M\0i\0n\0i\0p\0o\0r\0t 1?2?3?4?5?6?
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\x2018\3ΐ\3\3Ε\3Έ\3\3\x2015\3\xb1\3Β\3 \0ΐ\3\xb1\3Α\3\xac\3\xbb\3\xbb\3\xb7\3\xbb\3\xb7\3 1?
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\Descriptions@\xa3\3Ν\3\xbd\3\x384\3\3Γ\3\xb7\3 \0Δ\3\xb7\3\xbb\3\3Μ\3Α\3\xb1\3Γ\3\xb7\3Β\3/\0\xb2\3\x2015\3\xbd\3Δ\3\3Ώ\3 \0Δ\3\xb7\3Β\3 \0M\0i\0c\0r\0o\0s\0o\0f\0t 1?
Reg HKLM\SYSTEM\ControlSet002\Services\FGXSCSI\Parameters\PnpInterface@0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x38 0x0F 0x98 0x02 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 1
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x47 0x95 0xFC 0x5F ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xFA 0xCE 0x0B 0x75 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0xCB 0xA7 0xF1 0xC2 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xD2 0xD7 0x2F 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x25 0x41 0xC1 0x5A ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xA0 0x54 0x09 0x3C ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41@khjeh 0x09 0xB6 0x21 0xB4 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x28 0xE7 0xC2 0x70 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x25 0x41 0xC1 0x5A ...
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xDC 0x0C 0xB0 0xC5 ...

---- EOF - GMER 1.0.15 ----


Last edited by Vladimir on Mon Apr 19, 2010 6:26 pm; edited 1 time in total



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Belahzur on Mon Apr 19, 2010 6:24 pm

Hello.
Sorry, I should of realized before. Your OS is in a different language, so "Desktop" isn't "Desktop"

Is it "Επιφάνεια εργασίας" in your language? if so, replace "Desktop" with "Επιφάνεια εργασίας", and make sure TDSSKiller ISN'T renamed, otherwise this wont work.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Mon Apr 19, 2010 6:28 pm

Yes, that did it

21:28:19:015 5864 TDSS rootkit removing tool 2.2.8.1 Mar 22 2010 10:43:04
21:28:19:015 5864 ================================================================================
21:28:19:015 5864 SystemInfo:

21:28:19:015 5864 OS Version: 5.1.2600 ServicePack: 3.0
21:28:19:015 5864 Product type: Workstation
21:28:19:015 5864 ComputerName: HP11546321382
21:28:19:015 5864 UserName: User
21:28:19:015 5864 Windows directory: C:\WINDOWS
21:28:19:015 5864 Processor architecture: Intel x86
21:28:19:015 5864 Number of processors: 1
21:28:19:015 5864 Page size: 0x1000
21:28:19:015 5864 Boot type: Normal boot
21:28:19:015 5864 ================================================================================
21:28:19:015 5864 UnloadDriverW: NtUnloadDriver error 2
21:28:19:015 5864 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
21:28:19:031 5864 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
21:28:19:031 5864 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
21:28:19:031 5864 wfopen_ex: Trying to KLMD file open
21:28:19:031 5864 wfopen_ex: File opened ok (Flags 2)
21:28:19:031 5864 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
21:28:19:031 5864 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
21:28:19:031 5864 wfopen_ex: Trying to KLMD file open
21:28:19:031 5864 wfopen_ex: File opened ok (Flags 2)
21:28:19:031 5864 Initialize success
21:28:19:031 5864
21:28:19:031 5864 Scanning Services ...
21:28:19:328 5864 Raw services enum returned 427 services
21:28:19:343 5864
21:28:19:343 5864 Scanning Kernel memory ...
21:28:19:343 5864 Devices to scan: 4
21:28:19:343 5864
21:28:19:343 5864 Driver Name: Disk
21:28:19:343 5864 IRP_MJ_CREATE : B80EEBB0
21:28:19:343 5864 IRP_MJ_CREATE_NAMED_PIPE : 804F355A
21:28:19:343 5864 IRP_MJ_CLOSE : B80EEBB0
21:28:19:343 5864 IRP_MJ_READ : B80E8D1F
21:28:19:343 5864 IRP_MJ_WRITE : B80E8D1F
21:28:19:343 5864 IRP_MJ_QUERY_INFORMATION : 804F355A
21:28:19:343 5864 IRP_MJ_SET_INFORMATION : 804F355A
21:28:19:343 5864 IRP_MJ_QUERY_EA : 804F355A
21:28:19:343 5864 IRP_MJ_SET_EA : 804F355A
21:28:19:343 5864 IRP_MJ_FLUSH_BUFFERS : B80E92E2
21:28:19:343 5864 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F355A
21:28:19:343 5864 IRP_MJ_SET_VOLUME_INFORMATION : 804F355A
21:28:19:343 5864 IRP_MJ_DIRECTORY_CONTROL : 804F355A
21:28:19:343 5864 IRP_MJ_FILE_SYSTEM_CONTROL : 804F355A
21:28:19:343 5864 IRP_MJ_DEVICE_CONTROL : B80E93BB
21:28:19:343 5864 IRP_MJ_INTERNAL_DEVICE_CONTROL : B80ECF28
21:28:19:343 5864 IRP_MJ_SHUTDOWN : B80E92E2
21:28:19:343 5864 IRP_MJ_LOCK_CONTROL : 804F355A
21:28:19:343 5864 IRP_MJ_CLEANUP : 804F355A
21:28:19:343 5864 IRP_MJ_CREATE_MAILSLOT : 804F355A
21:28:19:343 5864 IRP_MJ_QUERY_SECURITY : 804F355A
21:28:19:343 5864 IRP_MJ_SET_SECURITY : 804F355A
21:28:19:343 5864 IRP_MJ_POWER : B80EAC82
21:28:19:343 5864 IRP_MJ_SYSTEM_CONTROL : B80EF99E
21:28:19:343 5864 IRP_MJ_DEVICE_CHANGE : 804F355A
21:28:19:343 5864 IRP_MJ_QUERY_QUOTA : 804F355A
21:28:19:343 5864 IRP_MJ_SET_QUOTA : 804F355A
21:28:19:375 5864 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
21:28:19:375 5864
21:28:19:375 5864 Driver Name: Disk
21:28:19:375 5864 IRP_MJ_CREATE : B80EEBB0
21:28:19:375 5864 IRP_MJ_CREATE_NAMED_PIPE : 804F355A
21:28:19:375 5864 IRP_MJ_CLOSE : B80EEBB0
21:28:19:375 5864 IRP_MJ_READ : B80E8D1F
21:28:19:375 5864 IRP_MJ_WRITE : B80E8D1F
21:28:19:375 5864 IRP_MJ_QUERY_INFORMATION : 804F355A
21:28:19:375 5864 IRP_MJ_SET_INFORMATION : 804F355A
21:28:19:375 5864 IRP_MJ_QUERY_EA : 804F355A
21:28:19:375 5864 IRP_MJ_SET_EA : 804F355A
21:28:19:375 5864 IRP_MJ_FLUSH_BUFFERS : B80E92E2
21:28:19:375 5864 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F355A
21:28:19:375 5864 IRP_MJ_SET_VOLUME_INFORMATION : 804F355A
21:28:19:375 5864 IRP_MJ_DIRECTORY_CONTROL : 804F355A
21:28:19:375 5864 IRP_MJ_FILE_SYSTEM_CONTROL : 804F355A
21:28:19:375 5864 IRP_MJ_DEVICE_CONTROL : B80E93BB
21:28:19:375 5864 IRP_MJ_INTERNAL_DEVICE_CONTROL : B80ECF28
21:28:19:375 5864 IRP_MJ_SHUTDOWN : B80E92E2
21:28:19:375 5864 IRP_MJ_LOCK_CONTROL : 804F355A
21:28:19:375 5864 IRP_MJ_CLEANUP : 804F355A
21:28:19:375 5864 IRP_MJ_CREATE_MAILSLOT : 804F355A
21:28:19:375 5864 IRP_MJ_QUERY_SECURITY : 804F355A
21:28:19:375 5864 IRP_MJ_SET_SECURITY : 804F355A
21:28:19:375 5864 IRP_MJ_POWER : B80EAC82
21:28:19:375 5864 IRP_MJ_SYSTEM_CONTROL : B80EF99E
21:28:19:375 5864 IRP_MJ_DEVICE_CHANGE : 804F355A
21:28:19:375 5864 IRP_MJ_QUERY_QUOTA : 804F355A
21:28:19:375 5864 IRP_MJ_SET_QUOTA : 804F355A
21:28:19:375 5864 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
21:28:19:375 5864
21:28:19:375 5864 Driver Name: atapi
21:28:19:375 5864 IRP_MJ_CREATE : B7E08B40
21:28:19:375 5864 IRP_MJ_CREATE_NAMED_PIPE : 804F355A
21:28:19:375 5864 IRP_MJ_CLOSE : B7E08B40
21:28:19:375 5864 IRP_MJ_READ : 804F355A
21:28:19:375 5864 IRP_MJ_WRITE : 804F355A
21:28:19:375 5864 IRP_MJ_QUERY_INFORMATION : 804F355A
21:28:19:375 5864 IRP_MJ_SET_INFORMATION : 804F355A
21:28:19:375 5864 IRP_MJ_QUERY_EA : 804F355A
21:28:19:375 5864 IRP_MJ_SET_EA : 804F355A
21:28:19:375 5864 IRP_MJ_FLUSH_BUFFERS : 804F355A
21:28:19:375 5864 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F355A
21:28:19:375 5864 IRP_MJ_SET_VOLUME_INFORMATION : 804F355A
21:28:19:375 5864 IRP_MJ_DIRECTORY_CONTROL : 804F355A
21:28:19:375 5864 IRP_MJ_FILE_SYSTEM_CONTROL : 804F355A
21:28:19:375 5864 IRP_MJ_DEVICE_CONTROL : B7E08B40
21:28:19:375 5864 IRP_MJ_INTERNAL_DEVICE_CONTROL : B8340D60
21:28:19:375 5864 IRP_MJ_SHUTDOWN : 804F355A
21:28:19:375 5864 IRP_MJ_LOCK_CONTROL : 804F355A
21:28:19:375 5864 IRP_MJ_CLEANUP : 804F355A
21:28:19:375 5864 IRP_MJ_CREATE_MAILSLOT : 804F355A
21:28:19:375 5864 IRP_MJ_QUERY_SECURITY : 804F355A
21:28:19:375 5864 IRP_MJ_SET_SECURITY : 804F355A
21:28:19:375 5864 IRP_MJ_POWER : B7E08B40
21:28:19:375 5864 IRP_MJ_SYSTEM_CONTROL : B7E08B40
21:28:19:375 5864 IRP_MJ_DEVICE_CHANGE : 804F355A
21:28:19:375 5864 IRP_MJ_QUERY_QUOTA : 804F355A
21:28:19:375 5864 IRP_MJ_SET_QUOTA : 804F355A
21:28:19:375 5864 C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: 1
21:28:19:375 5864
21:28:19:375 5864 Driver Name: atapi
21:28:19:375 5864 IRP_MJ_CREATE : B7E08B40
21:28:19:375 5864 IRP_MJ_CREATE_NAMED_PIPE : 804F355A
21:28:19:375 5864 IRP_MJ_CLOSE : B7E08B40
21:28:19:375 5864 IRP_MJ_READ : 804F355A
21:28:19:375 5864 IRP_MJ_WRITE : 804F355A
21:28:19:375 5864 IRP_MJ_QUERY_INFORMATION : 804F355A
21:28:19:375 5864 IRP_MJ_SET_INFORMATION : 804F355A
21:28:19:375 5864 IRP_MJ_QUERY_EA : 804F355A
21:28:19:375 5864 IRP_MJ_SET_EA : 804F355A
21:28:19:375 5864 IRP_MJ_FLUSH_BUFFERS : 804F355A
21:28:19:375 5864 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F355A
21:28:19:375 5864 IRP_MJ_SET_VOLUME_INFORMATION : 804F355A
21:28:19:375 5864 IRP_MJ_DIRECTORY_CONTROL : 804F355A
21:28:19:375 5864 IRP_MJ_FILE_SYSTEM_CONTROL : 804F355A
21:28:19:375 5864 IRP_MJ_DEVICE_CONTROL : B7E08B40
21:28:19:375 5864 IRP_MJ_INTERNAL_DEVICE_CONTROL : B8340D60
21:28:19:375 5864 IRP_MJ_SHUTDOWN : 804F355A
21:28:19:375 5864 IRP_MJ_LOCK_CONTROL : 804F355A
21:28:19:375 5864 IRP_MJ_CLEANUP : 804F355A
21:28:19:375 5864 IRP_MJ_CREATE_MAILSLOT : 804F355A
21:28:19:375 5864 IRP_MJ_QUERY_SECURITY : 804F355A
21:28:19:375 5864 IRP_MJ_SET_SECURITY : 804F355A
21:28:19:375 5864 IRP_MJ_POWER : B7E08B40
21:28:19:375 5864 IRP_MJ_SYSTEM_CONTROL : B7E08B40
21:28:19:375 5864 IRP_MJ_DEVICE_CHANGE : 804F355A
21:28:19:375 5864 IRP_MJ_QUERY_QUOTA : 804F355A
21:28:19:375 5864 IRP_MJ_SET_QUOTA : 804F355A
21:28:19:375 5864 C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: 1
21:28:19:375 5864
21:28:19:375 5864 Completed
21:28:19:375 5864
21:28:19:375 5864 Results:
21:28:19:375 5864 Memory objects infected / cured / cured on reboot: 0 / 0 / 0
21:28:19:375 5864 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
21:28:19:375 5864 File objects infected / cured / cured on reboot: 0 / 0 / 0
21:28:19:375 5864
21:28:19:375 5864 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
21:28:19:375 5864 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
21:28:19:390 5864 KLMD(ARK) unloaded successfully



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Belahzur on Mon Apr 19, 2010 6:32 pm

Hmmm.

Please re-run Combofix.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Mon Apr 19, 2010 6:49 pm

ComboFix 10-04-15.02 - User 19/04/2010 21:38:53.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1253.30.1032.18.3070.2551 [GMT 3:00]
Running from: c:\documents and settings\User\Επιφάνεια εργασίας\Guns 'N' Roses\Combo-Fix.exe
AV: Panda Global Protection 2010 *On-access scanning disabled* (Updated) {8BF935E7-731F-4115-B7A5-789FF5087595}
FW: Panda Personal Firewall 2010 *disabled* {7B090DC0-8905-4BAF-8040-FD98A41C8FB8}
.

((((((((((((((((((((((((( Files Created from 2010-03-19 to 2010-04-19 )))))))))))))))))))))))))))))))
.

2010-04-18 11:13 . 2010-04-18 11:13 -------- d-----w- c:\documents and settings\Administrator\Application Data\Subversion
2010-04-18 08:49 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-04-17 12:11 . 2010-04-17 12:11 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2010-04-17 12:10 . 2010-04-19 15:19 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\TSVNCache
2010-04-15 13:10 . 2010-03-29 21:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-15 13:10 . 2010-04-15 13:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-15 13:10 . 2010-03-29 21:45 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-15 12:12 . 2010-04-15 12:12 -------- d-----w- c:\program files\Advanced Attitude Software
2010-04-14 13:42 . 2010-04-14 13:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Deskshare
2010-04-14 13:38 . 2010-04-14 13:39 -------- d-----w- c:\windows\XSxS
2010-04-14 13:38 . 2010-04-14 13:38 -------- d-----w- c:\program files\Xenocode
2010-04-14 13:38 . 2010-04-14 13:38 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Xenocode
2010-04-14 13:31 . 2010-04-14 13:31 -------- d-----w- c:\program files\Common Files\Deskshare Shared
2010-04-14 13:31 . 2010-04-14 13:31 -------- d-----w- c:\program files\Deskshare
2010-04-14 11:43 . 2010-04-14 11:43 -------- d-----w- C:\_OTL
2010-04-12 14:43 . 2005-02-14 07:57 32768 ----a-w- c:\documents and settings\All Users\Application Data\Sony Ericsson\Sony Ericsson PC Suite\LiveUpdate\Temp\CleanBuild.exe
2010-04-10 21:20 . 2010-04-11 13:30 -------- d-----w- c:\program files\TombRaiderAOD
2010-04-09 20:49 . 2010-04-09 20:50 503808 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-748fd146-n\msvcp71.dll
2010-04-09 20:49 . 2010-04-09 20:49 499712 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-748fd146-n\jmc.dll
2010-04-09 20:49 . 2010-04-09 20:49 348160 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-748fd146-n\msvcr71.dll
2010-04-09 20:49 . 2010-04-09 20:49 61440 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-28638271-n\decora-sse.dll
2010-04-09 20:49 . 2010-04-09 20:49 12800 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-28638271-n\decora-d3d.dll
2010-04-09 20:48 . 2010-04-09 20:48 -------- d-----w- c:\program files\Common Files\Java
2010-04-07 11:14 . 2010-01-30 07:48 266552 ----a-w- c:\windows\system32\HMIPCore.dll
2010-04-07 11:10 . 2010-04-07 11:13 -------- d-----w- c:\documents and settings\User\Application Data\Hide IP NG
2010-03-30 15:01 . 2010-03-30 15:01 -------- d-----w- c:\program files\LogMeIn Hamachi
2010-03-29 15:44 . 2010-02-03 12:56 26176 ---ha-w- c:\windows\system32\hamachi.sys
2010-03-25 14:30 . 2010-03-25 14:30 -------- d-----w- c:\program files\Rockstar Games
2010-03-25 13:18 . 2010-03-25 13:18 -------- d-----w- c:\documents and settings\User\Application Data\SmartFTP
2010-03-25 13:18 . 2010-03-25 13:18 -------- d-----w- c:\program files\SmartFTP Client
2010-03-25 13:18 . 2010-03-25 13:18 -------- d-----w- c:\program files\SmartFTP Client 4.0 Setup Files

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-19 18:40 . 2009-10-28 13:54 1132 ----a-w- c:\windows\system32\drivers\APPFLTR.CFG.bck
2010-04-19 18:40 . 2009-10-28 13:54 1132 ----a-w- c:\windows\system32\drivers\APPFLTR.CFG
2010-04-19 18:40 . 2009-10-15 20:19 13880 ----a-w- c:\windows\system32\drivers\COMFiltr.sys
2010-04-19 18:38 . 2009-10-28 13:54 348056 ----a-w- c:\windows\system32\drivers\APPFCONT.DAT.bck
2010-04-19 18:38 . 2009-10-28 13:54 348056 ----a-w- c:\windows\system32\drivers\APPFCONT.DAT
2010-04-13 13:55 . 2008-01-14 15:58 -------- d-----w- c:\documents and settings\User\Application Data\uTorrent
2010-04-11 19:37 . 2008-01-10 21:17 -------- d-----w- c:\program files\LimeWire
2010-04-09 20:47 . 2008-01-10 10:51 -------- d-----w- c:\program files\Java
2010-04-06 11:11 . 2006-05-15 16:27 96688 ----a-w- c:\windows\system32\perfc008.dat
2010-04-06 11:11 . 2006-05-15 16:27 554772 ----a-w- c:\windows\system32\perfh008.dat
2010-03-12 14:08 . 2009-02-06 13:29 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-03-11 16:50 . 2009-02-09 12:01 -------- d-----w- c:\documents and settings\User\Application Data\Recruitment Viewer
2010-03-11 12:33 . 2004-09-04 13:45 832512 ----a-w- c:\windows\system32\wininet.dll
2010-03-11 12:33 . 2004-09-04 13:45 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:33 . 2004-09-04 13:45 17408 ------w- c:\windows\system32\corpol.dll
2010-03-09 11:10 . 2004-09-04 13:45 430080 ----a-w- c:\windows\system32\vbscript.dll
2010-03-09 01:28 . 2009-02-09 18:12 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-02 12:17 . 2008-01-10 10:52 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-01 11:47 . 2010-02-27 10:42 -------- d-----w- c:\program files\Capcom
2010-02-27 10:39 . 2010-02-27 10:38 -------- d-----w- c:\program files\MagicDisc
2010-02-24 13:11 . 2004-08-04 06:15 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-19 15:03 . 2008-01-14 20:26 66512 ----a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-18 15:15 . 2010-02-18 15:15 65536 ----a-w- c:\windows\system32\GDPersns.dat
2010-02-18 15:14 . 2010-02-18 15:14 90112 ----a-w- c:\windows\system32\Dversion.dll
2010-02-18 15:14 . 2010-02-18 15:14 126976 ----a-w- c:\windows\system32\DVC.dll
2010-02-18 14:07 . 2010-02-18 14:07 152576 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-02-18 14:07 . 2009-11-08 20:35 79488 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-17 11:06 . 2004-09-04 13:41 2196992 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:06 . 2006-03-02 09:00 2073856 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 12:53 . 2010-02-12 12:51 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2010-02-12 04:34 . 2004-09-04 13:44 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2004-08-04 06:07 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
2010-01-27 14:10 . 2009-09-25 16:12 611640 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2008-03-20 10:24 . 2008-03-20 10:22 24 --sha-w- c:\windows\S3201ED5C.tmp
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-10 218032]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-07-02 397312]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-13 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-13 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-13 138008]
"PDF Complete"="c:\program files\PDF Complete\pdfsty.exe" [2007-08-07 331288]
"SetRefresh"="c:\program files\Compaq\SetRefresh\SetRefresh.exe" [2003-11-20 525824]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2006-09-10 218032]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-10 86960]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-10-23 233472]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-09-01 176128]
"DeviceDiscovery"="c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2003-05-21 229437]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-01-31 385024]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-02-04 267048]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-03-27 593920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"APVXDWIN"="c:\program files\Panda Security\Panda Global Protection 2010\APVXDWIN.EXE" [2009-06-05 574720]
"SCANINICIO"="c:\program files\Panda Security\Panda Global Protection 2010\Inicio.exe" [2009-04-21 56064]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-09-23 1657448]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"GameDrive"="c:\program files\FarStone\GameDrive\GDP\GDTask.exe" [2006-07-21 167936]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 1820040]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\User\Start Menu\šα˜˜\΅΅εžž\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2010-2-27 576000]

c:\documents and settings\All Users\Start Menu\šα˜˜\΅΅εžž\
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2008-3-7 131072]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-5-23 122880]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
2008-03-18 13:58 58672 ----a-w- c:\windows\system32\avldr.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PskSvcRetail]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Documents and Settings\\User\\Επιφάνεια εργασίας\\Guns 'N' Roses\\uTorrent.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

R0 FGXSCSI;FGXSCSI;c:\windows\system32\drivers\fgxscsi.sys [18/2/2010 6:15 μμ 71680]
R0 pavboot;Panda boot driver;c:\windows\system32\drivers\pavboot.sys [5/4/2009 4:23 μμ 28544]
R1 APPFLT;App Filter Plugin;c:\windows\system32\drivers\APPFLT.SYS [15/10/2009 11:13 μμ 73728]
R1 DSAFLT;DSA Filter Plugin;c:\windows\system32\drivers\dsaflt.sys [15/10/2009 11:14 μμ 52992]
R1 FNETMON;NetMon Filter Plugin;c:\windows\system32\drivers\fnetmon.sys [15/10/2009 11:13 μμ 22072]
R1 IDSFLT;Ids Filter Plugin;c:\windows\system32\drivers\idsflt.sys [15/10/2009 11:14 μμ 193792]
R1 NETFLTDI;Panda Net Driver [TDI Layer];c:\windows\system32\drivers\NETFLTDI.SYS [15/10/2009 11:13 μμ 158848]
R1 ShldDrv;Panda File Shield Driver;c:\windows\system32\drivers\ShlDrv51.sys [15/10/2009 11:02 μμ 41144]
R1 SSHDRV79;SSHDRV79;c:\windows\system32\drivers\SSHDRV79.sys [28/10/2009 4:54 μμ 75264]
R1 SSHDRV85;SSHDRV85;c:\windows\system32\drivers\SSHDRV85.sys [1/12/2009 3:30 μμ 78848]
R1 WNMFLT;Wifi Monitor Filter Plugin;c:\windows\system32\drivers\wnmflt.sys [15/10/2009 11:14 μμ 46720]
R2 Gwmsrv;Panda Goodware Cache Manager;c:\windows\system32\svchost -k Panda --> c:\windows\system32\svchost -k Panda [?]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [30/3/2010 11:16 πμ 1107336]
R2 INFOlearn_admin_srv;INFOlearn Admin Service;c:\windows\system32\infolearnasrv.exe [6/10/2006 8:35 μμ 49152]
R2 PavProc;Panda Process Protection Driver;c:\windows\system32\drivers\PavProc.sys [15/10/2009 11:02 μμ 177416]
R2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [10/1/2008 1:54 μμ 540184]
R2 PskSvcRetail;Panda PSK service;c:\program files\Panda Security\Panda Global Protection 2010\psksvc.exe [15/10/2009 11:13 μμ 28928]
R3 AvFlt;Antivirus Filter Driver;c:\windows\system32\drivers\av5flt.sys --> c:\windows\system32\drivers\av5flt.sys [?]
R3 ComFiltr;Panda Anti-Dialer;c:\windows\system32\drivers\COMFiltr.sys [15/10/2009 11:19 μμ 13880]
R3 NETIMFLT01060034;PANDA NDIS IM Filter Miniport v1.6.0.34;c:\windows\system32\drivers\neti1634.sys [15/10/2009 11:13 μμ 197888]
R3 PavSRK.sys;PavSRK.sys;\??\c:\windows\system32\PavSRK.sys --> c:\windows\system32\PavSRK.sys [?]
R3 PavTPK.sys;PavTPK.sys;\??\c:\windows\system32\PavTPK.sys --> c:\windows\system32\PavTPK.sys [?]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [21/5/2008 5:03 μμ 691696]
S1 SSHDRV65;SSHDRV65;\??\c:\windows\system32\drivers\SSHDRV65.sys --> c:\windows\system32\drivers\SSHDRV65.sys [?]
S3 P1130VID;Creative WebCam NX Pro;c:\windows\system32\drivers\P1130Vid.sys [4/2/2008 5:25 μμ 90357]
S3 PCD65X2;PCD65X2;\??\c:\docume~1\User\LOCALS~1\Temp\PCD65X2.sys --> c:\docume~1\User\LOCALS~1\Temp\PCD65X2.sys [?]
S3 PCD65X3;PCD65X3;\??\c:\docume~1\User\LOCALS~1\Temp\PCD65X3.sys --> c:\docume~1\User\LOCALS~1\Temp\PCD65X3.sys [?]
S3 PCD65X4;PCD65X4;\??\c:\docume~1\User\LOCALS~1\Temp\PCD65X4.sys --> c:\docume~1\User\LOCALS~1\Temp\PCD65X4.sys [?]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [30/6/2009 9:32 μμ 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [30/6/2009 9:32 μμ 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [30/6/2009 9:32 μμ 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [30/6/2009 9:32 μμ 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [30/6/2009 9:32 μμ 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [30/6/2009 9:32 μμ 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [30/6/2009 9:32 μμ 115752]
S3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\drivers\s0017bus.sys [30/6/2009 9:32 μμ 90536]
S3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\drivers\s0017mdfl.sys [30/6/2009 9:32 μμ 15016]
S3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\drivers\s0017mdm.sys [30/6/2009 9:32 μμ 122152]
S3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0017mgmt.sys [30/6/2009 9:32 μμ 115496]
S3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\drivers\s0017nd5.sys [30/6/2009 9:32 μμ 25768]
S3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\drivers\s0017obex.sys [30/6/2009 9:32 μμ 111912]
S3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\drivers\s0017unic.sys [30/6/2009 9:32 μμ 117672]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
panda REG_MULTI_SZ Gwmsrv
.
Contents of the 'Scheduled Tasks' folder

2010-04-19 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 12:07]
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
uSearchMigratedDefaultURL = [You must be registered and logged in to see this link.]
uInternet Connection Wizard,ShellNext = iexplore
IE: Download the &current page with Offline Explorer - [You must be registered and logged in to see this link.] files\Offline Explorer\Add_AllO.htm
IE: Download using Offline &Explorer - [You must be registered and logged in to see this link.] files\Offline Explorer\Add_UrlO.htm
IE: Ε&ξαγωγή στο Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\cu6zhwsp.default\
FF - prefs.js: browser.search.defaulturl - [You must be registered and logged in to see this link.]
FF - prefs.js: browser.search.selectedEngine - isoHunt Customized Web Search
FF - prefs.js: browser.startup.homepage - [You must be registered and logged in to see this link.]
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npff_gdm.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
.
------- File Associations -------
.
JSEFile=c:\progra~1\PANDAS~1\PANDAG~1\PAVSCRIP.EXE "%1" %*
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2010-04-19 21:45
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwEnumerateKey, ZwClose, ZwEnumerateValueKey, ZwQueryValueKey, ZwOpenFile

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-4160596134-3961019470-752118726-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-4160596134-3961019470-752118726-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:16,10,41,ed,64,3d,77,f2,44,9e,32,86,e1,f1,8f,c6,19,aa,b3,67,76,a2,d2,
73,61,f4,91,60,e8,8e,09,5d,f5,db,35,bd,f1,b2,26,dc,8a,86,20,0e,c9,1e,4f,98,\
"??"=hex:c2,59,d1,1c,d4,d2,90,9f,4a,b4,64,fe,e2,10,24,81

[HKEY_USERS\S-1-5-21-4160596134-3961019470-752118726-1005\Software\SecuROM\License information*]
"datasecu"=hex:4e,10,57,e3,ee,b9,10,cd,ed,b0,f4,0a,39,5b,5d,c4,f4,5c,f9,8d,eb,
25,1d,10,c6,8f,ff,9b,72,ca,0a,32,3c,29,20,a5,3a,7e,00,95,4e,90,cb,5d,c2,27,\
"rkeysecu"=hex:8b,a4,d9,a9,1b,8f,88,92,bf,ca,aa,f3,89,e8,18,92
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1320)
c:\windows\system32\avldr.dll
.
Completion time: 2010-04-19 21:47:58
ComboFix-quarantined-files.txt 2010-04-19 18:47
ComboFix2.txt 2010-04-16 10:10

Pre-Run: 27 Κατάλογοι 59.889.401.856 διαθέσιμα byte
Post-Run: 28 Κατάλογοι 59.861.573.632 διαθέσιμα byte

- - End Of File - - 1DA6D771BC885ABAC3BC4767DD5035A8



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Belahzur on Mon Apr 19, 2010 6:53 pm

Weird, the rootkit is gone. Oh well, lets tidy this up now.

I see that you are running BitTorrent.
P2P(Peer to peer) applications are designed to help you easily share and distribute files between you and a group of people. But they can also be used to distribute malware, and thus are not considered safe.
The removal of these programs is optional, but highly recommended.

Go to Start > Control Panel > Add/Remove Programs and remove the following programs.

    Torrent
    Adobe Reader 9.1.3
    BitTorrent
    Java(TM) 6 Update 19

Next,

  1. Close any open browsers.
  2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  3. Open notepad and copy/paste the text in the quotebox below into it:
    Code:

    KILLALL::

    Driver::
    PCD65X2
    PCD65X3
    PCD65X4
    PavSRK.sys
    PavTPK.sys

    Firefox::
    FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\cu6zhwsp.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1434207&SearchSource=3&q=
    FF - prefs.js: browser.search.selectedEngine - isoHunt Customized Web Search
  4. Save this as CFScript.txt, in the same location as ComboFix.exe



  5. Referring to the picture above, drag CFScript into ComboFix.exe
  6. When finished, it shall produce a log for you at C:\ComboFix.txt
  7. Please post the contents of the log in your next reply.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Mon Apr 19, 2010 6:55 pm

I cannot keep μTorrent? Indifferent or Blank



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Mon Apr 19, 2010 7:12 pm

ComboFix 10-04-15.02 - User 19/04/2010 22:01:41.4.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1253.30.1032.18.3070.2473 [GMT 3:00]
Running from: c:\documents and settings\User\Επιφάνεια εργασίας\Combo-Fix.exe
Command switches used :: c:\documents and settings\User\Επιφάνεια εργασίας\CFscript.txt.txt
AV: Panda Global Protection 2010 *On-access scanning disabled* (Updated) {8BF935E7-731F-4115-B7A5-789FF5087595}
FW: Panda Personal Firewall 2010 *disabled* {7B090DC0-8905-4BAF-8040-FD98A41C8FB8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_PAVSRK.SYS
-------\Legacy_PAVTPK.SYS
-------\Legacy_PCD65X2
-------\Legacy_PCD65X3
-------\Legacy_PCD65X4
-------\Service_PavSRK.sys
-------\Service_PavTPK.sys
-------\Service_PCD65X2
-------\Service_PCD65X3
-------\Service_PCD65X4


((((((((((((((((((((((((( Files Created from 2010-03-19 to 2010-04-19 )))))))))))))))))))))))))))))))
.

2010-04-19 18:35 . 2010-04-19 18:48 -------- d-----w- C:\Combo-Fix17504C
2010-04-18 11:13 . 2010-04-18 11:13 -------- d-----w- c:\documents and settings\Administrator\Application Data\Subversion
2010-04-18 08:49 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-04-17 12:11 . 2010-04-17 12:11 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2010-04-17 12:10 . 2010-04-19 15:19 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\TSVNCache
2010-04-15 13:10 . 2010-03-29 21:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-15 13:10 . 2010-04-15 13:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-15 13:10 . 2010-03-29 21:45 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-15 12:12 . 2010-04-15 12:12 -------- d-----w- c:\program files\Advanced Attitude Software
2010-04-14 13:42 . 2010-04-14 13:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Deskshare
2010-04-14 13:38 . 2010-04-14 13:39 -------- d-----w- c:\windows\XSxS
2010-04-14 13:38 . 2010-04-14 13:38 -------- d-----w- c:\program files\Xenocode
2010-04-14 13:38 . 2010-04-14 13:38 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Xenocode
2010-04-14 13:31 . 2010-04-14 13:31 -------- d-----w- c:\program files\Common Files\Deskshare Shared
2010-04-14 13:31 . 2010-04-14 13:31 -------- d-----w- c:\program files\Deskshare
2010-04-14 11:43 . 2010-04-14 11:43 -------- d-----w- C:\_OTL
2010-04-10 21:20 . 2010-04-11 13:30 -------- d-----w- c:\program files\TombRaiderAOD
2010-04-09 20:48 . 2010-04-09 20:48 -------- d-----w- c:\program files\Common Files\Java
2010-04-07 11:14 . 2010-01-30 07:48 266552 ----a-w- c:\windows\system32\HMIPCore.dll
2010-04-07 11:10 . 2010-04-07 11:13 -------- d-----w- c:\documents and settings\User\Application Data\Hide IP NG
2010-03-30 15:01 . 2010-03-30 15:01 -------- d-----w- c:\program files\LogMeIn Hamachi
2010-03-29 15:44 . 2010-02-03 12:56 26176 ---ha-w- c:\windows\system32\hamachi.sys
2010-03-25 14:30 . 2010-03-25 14:30 -------- d-----w- c:\program files\Rockstar Games
2010-03-25 13:18 . 2010-03-25 13:18 -------- d-----w- c:\documents and settings\User\Application Data\SmartFTP
2010-03-25 13:18 . 2010-03-25 13:18 -------- d-----w- c:\program files\SmartFTP Client
2010-03-25 13:18 . 2010-03-25 13:18 -------- d-----w- c:\program files\SmartFTP Client 4.0 Setup Files

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-19 19:10 . 2009-10-28 13:54 1132 ----a-w- c:\windows\system32\drivers\APPFLTR.CFG.bck
2010-04-19 19:10 . 2009-10-28 13:54 1132 ----a-w- c:\windows\system32\drivers\APPFLTR.CFG
2010-04-19 19:08 . 2009-10-15 20:19 13880 ----a-w- c:\windows\system32\drivers\COMFiltr.sys
2010-04-19 19:07 . 2009-10-28 13:54 334432 ----a-w- c:\windows\system32\drivers\APPFCONT.DAT.bck
2010-04-19 19:07 . 2009-10-28 13:54 334432 ----a-w- c:\windows\system32\drivers\APPFCONT.DAT
2010-04-19 18:59 . 2008-01-10 13:44 -------- d-----w- c:\program files\Common Files\Adobe
2010-04-13 13:55 . 2008-01-14 15:58 -------- d-----w- c:\documents and settings\User\Application Data\uTorrent
2010-04-11 19:37 . 2008-01-10 21:17 -------- d-----w- c:\program files\LimeWire
2010-04-09 20:50 . 2010-04-09 20:49 503808 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-748fd146-n\msvcp71.dll
2010-04-09 20:49 . 2010-04-09 20:49 499712 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-748fd146-n\jmc.dll
2010-04-09 20:49 . 2010-04-09 20:49 348160 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-748fd146-n\msvcr71.dll
2010-04-09 20:49 . 2010-04-09 20:49 61440 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-28638271-n\decora-sse.dll
2010-04-09 20:49 . 2010-04-09 20:49 12800 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-28638271-n\decora-d3d.dll
2010-04-09 20:47 . 2008-01-10 10:51 -------- d-----w- c:\program files\Java
2010-04-06 11:11 . 2006-05-15 16:27 96688 ----a-w- c:\windows\system32\perfc008.dat
2010-04-06 11:11 . 2006-05-15 16:27 554772 ----a-w- c:\windows\system32\perfh008.dat
2010-03-12 14:08 . 2009-02-06 13:29 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-03-11 16:50 . 2009-02-09 12:01 -------- d-----w- c:\documents and settings\User\Application Data\Recruitment Viewer
2010-03-11 12:33 . 2004-09-04 13:45 832512 ----a-w- c:\windows\system32\wininet.dll
2010-03-11 12:33 . 2004-09-04 13:45 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:33 . 2004-09-04 13:45 17408 ------w- c:\windows\system32\corpol.dll
2010-03-09 11:10 . 2004-09-04 13:45 430080 ----a-w- c:\windows\system32\vbscript.dll
2010-03-09 01:28 . 2009-02-09 18:12 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-02 12:17 . 2008-01-10 10:52 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-01 11:47 . 2010-02-27 10:42 -------- d-----w- c:\program files\Capcom
2010-02-27 10:39 . 2010-02-27 10:38 -------- d-----w- c:\program files\MagicDisc
2010-02-24 13:11 . 2004-08-04 06:15 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-19 15:03 . 2008-01-14 20:26 66512 ----a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-18 15:15 . 2010-02-18 15:15 65536 ----a-w- c:\windows\system32\GDPersns.dat
2010-02-18 15:14 . 2010-02-18 15:14 90112 ----a-w- c:\windows\system32\Dversion.dll
2010-02-18 15:14 . 2010-02-18 15:14 126976 ----a-w- c:\windows\system32\DVC.dll
2010-02-18 14:07 . 2010-02-18 14:07 152576 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-02-18 14:07 . 2009-11-08 20:35 79488 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-17 11:06 . 2004-09-04 13:41 2196992 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:06 . 2006-03-02 09:00 2073856 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 12:53 . 2010-02-12 12:51 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2010-02-12 04:34 . 2004-09-04 13:44 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2004-08-04 06:07 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
2010-01-27 14:10 . 2009-09-25 16:12 611640 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2008-03-20 10:24 . 2008-03-20 10:22 24 --sha-w- c:\windows\S3201ED5C.tmp
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-10 218032]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-07-02 397312]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-13 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-13 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-13 138008]
"PDF Complete"="c:\program files\PDF Complete\pdfsty.exe" [2007-08-07 331288]
"SetRefresh"="c:\program files\Compaq\SetRefresh\SetRefresh.exe" [2003-11-20 525824]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2006-09-10 218032]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-10 86960]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-10-23 233472]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-09-01 176128]
"DeviceDiscovery"="c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2003-05-21 229437]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-01-31 385024]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-02-04 267048]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-03-27 593920]
"APVXDWIN"="c:\program files\Panda Security\Panda Global Protection 2010\APVXDWIN.EXE" [2009-06-05 574720]
"SCANINICIO"="c:\program files\Panda Security\Panda Global Protection 2010\Inicio.exe" [2009-04-21 56064]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-09-23 1657448]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016]
"GameDrive"="c:\program files\FarStone\GameDrive\GDP\GDTask.exe" [2006-07-21 167936]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 1820040]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\User\Start Menu\šα˜˜\΅΅εžž\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2010-2-27 576000]

c:\documents and settings\All Users\Start Menu\šα˜˜\΅΅εžž\
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2008-3-7 131072]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-5-23 122880]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
2008-03-18 13:58 58672 ----a-w- c:\windows\system32\avldr.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PskSvcRetail]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Documents and Settings\\User\\Επιφάνεια εργασίας\\Guns 'N' Roses\\uTorrent.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

R0 FGXSCSI;FGXSCSI;c:\windows\system32\drivers\fgxscsi.sys [18/2/2010 6:15 μμ 71680]
R0 pavboot;Panda boot driver;c:\windows\system32\drivers\pavboot.sys [5/4/2009 4:23 μμ 28544]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [21/5/2008 5:03 μμ 691696]
R1 APPFLT;App Filter Plugin;c:\windows\system32\drivers\APPFLT.SYS [15/10/2009 11:13 μμ 73728]
R1 DSAFLT;DSA Filter Plugin;c:\windows\system32\drivers\dsaflt.sys [15/10/2009 11:14 μμ 52992]
R1 FNETMON;NetMon Filter Plugin;c:\windows\system32\drivers\fnetmon.sys [15/10/2009 11:13 μμ 22072]
R1 IDSFLT;Ids Filter Plugin;c:\windows\system32\drivers\idsflt.sys [15/10/2009 11:14 μμ 193792]
R1 NETFLTDI;Panda Net Driver [TDI Layer];c:\windows\system32\drivers\NETFLTDI.SYS [15/10/2009 11:13 μμ 158848]
R1 ShldDrv;Panda File Shield Driver;c:\windows\system32\drivers\ShlDrv51.sys [15/10/2009 11:02 μμ 41144]
R1 SSHDRV79;SSHDRV79;c:\windows\system32\drivers\SSHDRV79.sys [28/10/2009 4:54 μμ 75264]
R1 SSHDRV85;SSHDRV85;c:\windows\system32\drivers\SSHDRV85.sys [1/12/2009 3:30 μμ 78848]
R1 WNMFLT;Wifi Monitor Filter Plugin;c:\windows\system32\drivers\wnmflt.sys [15/10/2009 11:14 μμ 46720]
R2 Gwmsrv;Panda Goodware Cache Manager;c:\windows\system32\svchost -k Panda --> c:\windows\system32\svchost -k Panda [?]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [30/3/2010 11:16 πμ 1107336]
R2 INFOlearn_admin_srv;INFOlearn Admin Service;c:\windows\system32\infolearnasrv.exe [6/10/2006 8:35 μμ 49152]
R2 PavProc;Panda Process Protection Driver;c:\windows\system32\drivers\PavProc.sys [15/10/2009 11:02 μμ 177416]
R2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [10/1/2008 1:54 μμ 540184]
R2 PskSvcRetail;Panda PSK service;c:\program files\Panda Security\Panda Global Protection 2010\psksvc.exe [15/10/2009 11:13 μμ 28928]
R3 AvFlt;Antivirus Filter Driver;c:\windows\system32\drivers\av5flt.sys --> c:\windows\system32\drivers\av5flt.sys [?]
R3 ComFiltr;Panda Anti-Dialer;c:\windows\system32\drivers\COMFiltr.sys [15/10/2009 11:19 μμ 13880]
R3 NETIMFLT01060034;PANDA NDIS IM Filter Miniport v1.6.0.34;c:\windows\system32\drivers\neti1634.sys [15/10/2009 11:13 μμ 197888]
R3 PavTPK.sys;PavTPK.sys;\??\c:\windows\system32\PavTPK.sys --> c:\windows\system32\PavTPK.sys [?]
S1 SSHDRV65;SSHDRV65;\??\c:\windows\system32\drivers\SSHDRV65.sys --> c:\windows\system32\drivers\SSHDRV65.sys [?]
S3 P1130VID;Creative WebCam NX Pro;c:\windows\system32\drivers\P1130Vid.sys [4/2/2008 5:25 μμ 90357]
S3 PavSRK.sys;PavSRK.sys;\??\c:\windows\system32\PavSRK.sys --> c:\windows\system32\PavSRK.sys [?]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [30/6/2009 9:32 μμ 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [30/6/2009 9:32 μμ 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [30/6/2009 9:32 μμ 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [30/6/2009 9:32 μμ 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [30/6/2009 9:32 μμ 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [30/6/2009 9:32 μμ 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [30/6/2009 9:32 μμ 115752]
S3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\drivers\s0017bus.sys [30/6/2009 9:32 μμ 90536]
S3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\drivers\s0017mdfl.sys [30/6/2009 9:32 μμ 15016]
S3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\drivers\s0017mdm.sys [30/6/2009 9:32 μμ 122152]
S3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0017mgmt.sys [30/6/2009 9:32 μμ 115496]
S3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\drivers\s0017nd5.sys [30/6/2009 9:32 μμ 25768]
S3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\drivers\s0017obex.sys [30/6/2009 9:32 μμ 111912]
S3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\drivers\s0017unic.sys [30/6/2009 9:32 μμ 117672]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - PAVTPK.SYS

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
panda REG_MULTI_SZ Gwmsrv
.
Contents of the 'Scheduled Tasks' folder

2010-04-19 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 12:07]
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
uSearchMigratedDefaultURL = [You must be registered and logged in to see this link.]
uInternet Connection Wizard,ShellNext = iexplore
IE: Download the ¤t page with Offline Explorer - [You must be registered and logged in to see this link.] files\Offline Explorer\Add_AllO.htm
IE: Download using Offline &Explorer - [You must be registered and logged in to see this link.] files\Offline Explorer\Add_UrlO.htm
IE: Ε&ξαγωγή στο Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\cu6zhwsp.default\
FF - prefs.js: browser.startup.homepage - [You must be registered and logged in to see this link.]
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npff_gdm.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2010-04-19 22:06
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, [You must be registered and logged in to see this link.]

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll sfsync02.sys atapi.sys spjk.sys >>UNKNOWN [0x8ADEC938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xb80ecf28
\Driver\ACPI -> ACPI.sys @ 0xb7e73cb8
\Driver\atapi -> sfsync02.sys @ 0xb8340d60
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->NDIS: Broadcom NetLink (TM) Gigabit Ethernet -> SendCompleteHandler -> NDIS.sys @ 0xb7cecbb0
PacketIndicateHandler -> NDIS.sys @ 0xb7cf9a21
SendHandler -> NDIS.sys @ 0xb7cd787b
user & kernel MBR OK

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-4160596134-3961019470-752118726-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-4160596134-3961019470-752118726-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:16,10,41,ed,64,3d,77,f2,44,9e,32,86,e1,f1,8f,c6,19,aa,b3,67,76,a2,d2,
73,61,f4,91,60,e8,8e,09,5d,f5,db,35,bd,f1,b2,26,dc,8a,86,20,0e,c9,1e,4f,98,\
"??"=hex:c2,59,d1,1c,d4,d2,90,9f,4a,b4,64,fe,e2,10,24,81

[HKEY_USERS\S-1-5-21-4160596134-3961019470-752118726-1005\Software\SecuROM\License information*]
"datasecu"=hex:4e,10,57,e3,ee,b9,10,cd,ed,b0,f4,0a,39,5b,5d,c4,f4,5c,f9,8d,eb,
25,1d,10,c6,8f,ff,9b,72,ca,0a,32,3c,29,20,a5,3a,7e,00,95,4e,90,cb,5d,c2,27,\
"rkeysecu"=hex:8b,a4,d9,a9,1b,8f,88,92,bf,ca,aa,f3,89,e8,18,92
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1340)
c:\windows\system32\avldr.dll

- - - - - - - > 'explorer.exe'(4992)
c:\program files\Panda Security\Panda Global Protection 2010\pavoepl.dll
c:\program files\TortoiseSVN\bin\tortoisesvn.dll
c:\program files\TortoiseSVN\bin\intl3_svn.dll
c:\program files\SmartFTP Client\en-US\sfShellTools.dll.mui
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Panda Security\Panda Global Protection 2010\TPSrv.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Panda Security\Panda Global Protection 2010\PsCtrls.exe
c:\program files\Panda Security\Panda Global Protection 2010\PavFnSvr.exe
c:\program files\Common Files\Panda Security\PavShld\pavprsrv.exe
c:\program files\panda security\panda global protection 2010\firewall\PSHOST.EXE
c:\program files\Panda Security\Panda Global Protection 2010\PsImSvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Panda Security\Panda Global Protection 2010\pavsrv51.exe
c:\program files\Panda Security\Panda Global Protection 2010\AVENGINE.EXE
c:\program files\TortoiseSVN\bin\TSVNCache.exe
c:\program files\PANDA SECURITY\PANDA GLOBAL PROTECTION 2010\WebProxy.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Teleca Shared\Generic.exe
c:\program files\Panda Security\Panda Global Protection 2010\SRVLOAD.EXE
c:\program files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
c:\program files\Panda Security\Panda Global Protection 2010\PavBckPT.exe
.
**************************************************************************
.
Completion time: 2010-04-19 22:12:11 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-19 19:12
ComboFix2.txt 2010-04-19 18:48
ComboFix3.txt 2010-04-16 10:10

Pre-Run: 28 Κατάλογοι 60.089.749.504 διαθέσιμα byte
Post-Run: 29 Κατάλογοι 60.038.750.208 διαθέσιμα byte

- - End Of File - - CF41ACA0B36125F51F5F9B96CA21C94C



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Belahzur on Mon Apr 19, 2010 7:23 pm

Hello.

Submit a file for analysis.

  1. Please visit this website: [You must be registered and logged in to see this link.]
  2. Press the "Browse" button and locate the following file in bold:
    C:\WINDOWS\system32\drivers\sfsync02.sys
  3. Press the "Submit File button to submit the file for analysis.
  4. Allow it to be scanned, it could take a few minutes depending on server load.
  5. Copy and paste the result back here.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Tue Apr 20, 2010 8:43 am

[ArcaVir]
2010-04-19 Found nothing
[F-Secure Anti-Virus]
2010-04-20 Found nothing
[A-Squared]
2010-04-20 Found nothing
[G DATA]
2010-04-20 Found nothing
[Avast! antivirus]



And



Filename: sfsync02.sys
Status:
Scan finished. 0 out of 20 scanners reported malware.
Scan taken on: Tue 20 Apr 2010 10:41:13 (CET) Permalink
2010-04-19 Found nothing
[Ikarus]
2010-04-20 Found nothing
[Grisoft AVG Anti-Virus]
2010-04-20 Found nothing
[Kaspersky Anti-Virus]
2010-04-20 Found nothing
[Avira AntiVir]
2010-04-20 Found nothing
[ESET NOD32]
2010-04-19 Found nothing
[Softwin BitDefender]
2010-04-20 Found nothing
[Panda Antivirus]
2010-04-19 Found nothing
[ClamAV]
2010-04-20 Found nothing
[Quick Heal]
2010-04-20 Found nothing
[CPsecure]
2010-04-20 Found nothing
[Sophos]
2010-04-20 Found nothing
[Dr.Web]
2010-04-20 Found nothing
[VirusBlokAda VBA32]
2010-04-18 Found nothing
[Frisk F-Prot Antivirus]
2010-04-19 Found nothing
[VirusBuster]
2010-04-19 Found nothing



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Belahzur on Tue Apr 20, 2010 12:12 pm

Hello.
Please download RootkitUnhooker from [You must be registered and logged in to see this link.]

Unzip it and run the program.
Go to the File menu, select, Quick Report, and save info from current page.

Please post the log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Tue Apr 20, 2010 12:36 pm

RkUnhooker report generator v0.7
==============================================
Rootkit Unhooker kernel version: 3.7.300.509
==============================================
Windows Major Version: 5
Windows Minor Version: 1
Windows Build Number: 2600
==============================================
NtCreateKey
Actual Address 0xB7EB50E0
Hooked by: spgl.sys

NtEnumerateKey
Actual Address 0xB7ECDDA4
Hooked by: spgl.sys

NtEnumerateValueKey
Actual Address 0xB7ECE132
Hooked by: spgl.sys

NtOpenKey
Actual Address 0xB7EB50C0
Hooked by: spgl.sys

NtQueryKey
Actual Address 0xB7ECE20A
Hooked by: spgl.sys

NtQueryValueKey
Actual Address 0xB7ECE08A
Hooked by: spgl.sys

NtSetValueKey
Actual Address 0xB7ECE29C
Hooked by: spgl.sys

NtTerminateProcess
Actual Address 0xB350D654
Hooked by: C:\WINDOWS\system32\DRIVERS\PavProc.sys

NtTerminateThread
Actual Address 0xB350CC2E
Hooked by: C:\WINDOWS\system32\DRIVERS\PavProc.sys



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Tue Apr 20, 2010 8:24 pm

-

Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Belahzur on Tue Apr 20, 2010 10:00 pm

Hello.
Please delete the copy of Combofix you have now, then re-download it and run this new script.

  1. Close any open browsers.
  2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  3. Open notepad and copy/paste the text in the quotebox below into it:
    Code:

    FCopy::
    C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\i386\atapi.sys | C:\WINDOWS\system32\drivers\atapi.sys
  4. Save this as CFScript.txt, in the same location as ComboFix.exe



  5. Referring to the picture above, drag CFScript into ComboFix.exe
  6. When finished, it shall produce a log for you at C:\ComboFix.txt
  7. Please post the contents of the log in your next reply.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Wed Apr 21, 2010 9:26 am

ComboFix 10-04-20.01 - User 21/04/2010 12:15:31.5.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1253.30.1032.18.3070.2573 [GMT 3:00]
Running from: c:\documents and settings\User\Επιφάνεια εργασίας\Combo-Fix.exe
Command switches used :: c:\documents and settings\User\Επιφάνεια εργασίας\CFScript.txt.txt
AV: Panda Global Protection 2010 *On-access scanning disabled* (Updated) {8BF935E7-731F-4115-B7A5-789FF5087595}
FW: Panda Personal Firewall 2010 *disabled* {7B090DC0-8905-4BAF-8040-FD98A41C8FB8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
--------------- FCopy ---------------

c:\windows\system32\ReinstallBackups\0000\DriverFiles\i386\atapi.sys --> c:\windows\system32\drivers\atapi.sys
.
((((((((((((((((((((((((( Files Created from 2010-03-21 to 2010-04-21 )))))))))))))))))))))))))))))))
.

2010-04-19 18:35 . 2010-04-19 18:48 -------- d-----w- C:\Combo-Fix17504C
2010-04-18 11:13 . 2010-04-18 11:13 -------- d-----w- c:\documents and settings\Administrator\Application Data\Subversion
2010-04-18 08:49 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2010-04-17 12:11 . 2010-04-17 12:11 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2010-04-17 12:10 . 2010-04-19 15:19 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\TSVNCache
2010-04-15 13:10 . 2010-03-29 21:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-15 13:10 . 2010-04-15 13:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-15 13:10 . 2010-03-29 21:45 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-15 12:12 . 2010-04-15 12:12 -------- d-----w- c:\program files\Advanced Attitude Software
2010-04-14 13:42 . 2010-04-14 13:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Deskshare
2010-04-14 13:38 . 2010-04-14 13:39 -------- d-----w- c:\windows\XSxS
2010-04-14 13:38 . 2010-04-14 13:38 -------- d-----w- c:\program files\Xenocode
2010-04-14 13:38 . 2010-04-14 13:38 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Xenocode
2010-04-14 13:31 . 2010-04-14 13:31 -------- d-----w- c:\program files\Common Files\Deskshare Shared
2010-04-14 13:31 . 2010-04-14 13:31 -------- d-----w- c:\program files\Deskshare
2010-04-14 11:43 . 2010-04-14 11:43 -------- d-----w- C:\_OTL
2010-04-12 14:43 . 2005-02-14 07:57 32768 ----a-w- c:\documents and settings\All Users\Application Data\Sony Ericsson\Sony Ericsson PC Suite\LiveUpdate\Temp\CleanBuild.exe
2010-04-10 21:20 . 2010-04-11 13:30 -------- d-----w- c:\program files\TombRaiderAOD
2010-04-09 20:49 . 2010-04-09 20:50 503808 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-748fd146-n\msvcp71.dll
2010-04-09 20:49 . 2010-04-09 20:49 499712 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-748fd146-n\jmc.dll
2010-04-09 20:49 . 2010-04-09 20:49 348160 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-748fd146-n\msvcr71.dll
2010-04-09 20:49 . 2010-04-09 20:49 61440 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-28638271-n\decora-sse.dll
2010-04-09 20:49 . 2010-04-09 20:49 12800 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-28638271-n\decora-d3d.dll
2010-04-09 20:48 . 2010-04-09 20:48 -------- d-----w- c:\program files\Common Files\Java
2010-04-07 11:14 . 2010-01-30 07:48 266552 ----a-w- c:\windows\system32\HMIPCore.dll
2010-04-07 11:10 . 2010-04-07 11:13 -------- d-----w- c:\documents and settings\User\Application Data\Hide IP NG
2010-03-30 15:01 . 2010-03-30 15:01 -------- d-----w- c:\program files\LogMeIn Hamachi
2010-03-29 15:44 . 2010-02-03 12:56 26176 ---ha-w- c:\windows\system32\hamachi.sys
2010-03-25 14:30 . 2010-03-25 14:30 -------- d-----w- c:\program files\Rockstar Games
2010-03-25 13:18 . 2010-03-25 13:18 -------- d-----w- c:\documents and settings\User\Application Data\SmartFTP
2010-03-25 13:18 . 2010-03-25 13:18 -------- d-----w- c:\program files\SmartFTP Client
2010-03-25 13:18 . 2010-03-25 13:18 -------- d-----w- c:\program files\SmartFTP Client 4.0 Setup Files
2010-03-24 08:04 . 2010-03-24 18:17 952768 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\8028\AdobeARM.exe
2010-03-24 08:04 . 2010-03-24 18:17 70584 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\8028\AdobeExtractFiles.dll
2010-03-24 08:04 . 2010-03-24 18:17 326056 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\8028\ReaderUpdater.exe
2010-03-24 08:04 . 2010-03-24 18:17 326056 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\8028\AcrobatUpdater.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-21 09:16 . 2009-10-28 13:54 1132 ----a-w- c:\windows\system32\drivers\APPFLTR.CFG.bck
2010-04-21 09:16 . 2009-10-28 13:54 1132 ----a-w- c:\windows\system32\drivers\APPFLTR.CFG
2010-04-21 09:16 . 2009-10-15 20:19 13880 ----a-w- c:\windows\system32\drivers\COMFiltr.sys
2010-04-21 09:14 . 2009-10-28 13:54 343712 ----a-w- c:\windows\system32\drivers\APPFCONT.DAT.bck
2010-04-21 09:14 . 2009-10-28 13:54 343712 ----a-w- c:\windows\system32\drivers\APPFCONT.DAT
2010-04-20 21:02 . 2008-01-10 13:44 -------- d-----w- c:\program files\Common Files\Adobe
2010-04-13 13:55 . 2008-01-14 15:58 -------- d-----w- c:\documents and settings\User\Application Data\uTorrent
2010-04-11 19:37 . 2008-01-10 21:17 -------- d-----w- c:\program files\LimeWire
2010-04-09 20:47 . 2008-01-10 10:51 -------- d-----w- c:\program files\Java
2010-04-06 11:11 . 2006-05-15 16:27 96688 ----a-w- c:\windows\system32\perfc008.dat
2010-04-06 11:11 . 2006-05-15 16:27 554772 ----a-w- c:\windows\system32\perfh008.dat
2010-03-12 14:08 . 2009-02-06 13:29 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-03-11 16:50 . 2009-02-09 12:01 -------- d-----w- c:\documents and settings\User\Application Data\Recruitment Viewer
2010-03-11 12:33 . 2004-09-04 13:45 832512 ----a-w- c:\windows\system32\wininet.dll
2010-03-11 12:33 . 2004-09-04 13:45 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:33 . 2004-09-04 13:45 17408 ------w- c:\windows\system32\corpol.dll
2010-03-09 11:10 . 2004-09-04 13:45 430080 ----a-w- c:\windows\system32\vbscript.dll
2010-03-09 01:28 . 2009-02-09 18:12 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-02 12:17 . 2008-01-10 10:52 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-03-01 11:47 . 2010-02-27 10:42 -------- d-----w- c:\program files\Capcom
2010-02-27 10:39 . 2010-02-27 10:38 -------- d-----w- c:\program files\MagicDisc
2010-02-24 13:11 . 2004-08-04 06:15 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-19 15:03 . 2008-01-14 20:26 66512 ----a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-18 15:15 . 2010-02-18 15:15 65536 ----a-w- c:\windows\system32\GDPersns.dat
2010-02-18 15:14 . 2010-02-18 15:14 90112 ----a-w- c:\windows\system32\Dversion.dll
2010-02-18 15:14 . 2010-02-18 15:14 126976 ----a-w- c:\windows\system32\DVC.dll
2010-02-18 14:07 . 2010-02-18 14:07 152576 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-02-18 14:07 . 2009-11-08 20:35 79488 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-17 11:06 . 2004-09-04 13:41 2196992 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:06 . 2006-03-02 09:00 2073856 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 12:53 . 2010-02-12 12:51 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll
2010-02-12 04:34 . 2004-09-04 13:44 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2004-08-04 06:07 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
2010-01-27 14:10 . 2009-09-25 16:12 611640 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2008-03-20 10:24 . 2008-03-20 10:22 24 --sha-w- c:\windows\S3201ED5C.tmp
.

((((((((((((((((((((((((((((( [You must be registered and logged in to see this link.] )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-08-04 05:59 . 2004-08-04 05:59 95360 c:\windows\system32\dllcache\atapi.sys
+ 2009-12-21 17:09 . 2009-12-21 17:09 16832 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\ViewerPS.dll
+ 2009-12-21 22:57 . 2009-12-21 22:57 35760 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\reader_sl.exe
+ 2009-12-21 17:02 . 2009-12-21 17:02 79280 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\PDFPrevHndlr.dll
+ 2009-12-21 20:21 . 2009-12-21 20:21 99776 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\eula.exe
+ 2009-12-21 20:37 . 2009-12-21 20:37 27048 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\acrotextextractor.exe
+ 2009-12-21 15:39 . 2009-12-21 15:39 15288 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AcroRd32Info.exe
+ 2009-12-21 15:27 . 2009-12-21 15:27 75200 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\acroiehelpershim.dll
+ 2009-12-21 15:27 . 2009-12-21 15:27 61888 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AcroIEHelper.dll
+ 2009-12-21 15:35 . 2009-12-21 15:35 378264 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\pdfshell.dll
+ 2009-12-21 17:05 . 2009-12-21 17:05 116168 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\PDFPrevHndlrShim.exe
+ 2009-12-21 15:34 . 2009-12-21 15:34 103864 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\nppdf32.dll
+ 2009-11-09 16:18 . 2009-11-09 16:18 684032 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\JP2KLib.dll
+ 2009-12-21 17:02 . 2009-12-21 17:02 542168 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AdobeCollabSync.exe
+ 2009-12-21 15:43 . 2009-12-21 15:43 120240 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AcroRdIF.dll
+ 2009-12-21 22:57 . 2009-12-21 22:57 349616 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AcroRd32.exe
+ 2009-12-21 15:15 . 2009-12-21 15:15 660912 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AcroPDF.dll
+ 2009-12-21 16:32 . 2009-12-21 16:32 280024 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\acrobroker.exe
+ 2009-12-21 16:15 . 2009-12-21 16:15 251296 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\a3dutility.exe
+ 2010-04-20 21:03 . 2010-04-20 21:03 3940352 c:\windows\Installer\cefdc2.msi
+ 2009-12-21 15:29 . 2009-12-21 15:29 2409880 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\rt3d.dll
+ 2009-10-27 17:34 . 2009-10-27 17:34 5009408 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\authplay.dll
+ 2009-12-21 20:31 . 2009-12-21 20:31 5713920 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AGM.dll
+ 2010-04-04 06:54 . 2010-04-04 06:54 11850240 c:\windows\Installer\cefe66.msp
+ 2009-12-21 20:21 . 2009-12-21 20:21 20436408 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AcroRd32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-10 218032]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-07-02 397312]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-13 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-13 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-13 138008]
"PDF Complete"="c:\program files\PDF Complete\pdfsty.exe" [2007-08-07 331288]
"SetRefresh"="c:\program files\Compaq\SetRefresh\SetRefresh.exe" [2003-11-20 525824]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2006-09-10 218032]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-10 86960]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-10-23 233472]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-09-01 176128]
"DeviceDiscovery"="c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2003-05-21 229437]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-01-31 385024]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-02-04 267048]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-03-27 593920]
"APVXDWIN"="c:\program files\Panda Security\Panda Global Protection 2010\APVXDWIN.EXE" [2009-06-05 574720]
"SCANINICIO"="c:\program files\Panda Security\Panda Global Protection 2010\Inicio.exe" [2009-04-21 56064]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-09-23 1657448]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-09-27 13918208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-09-27 86016]
"GameDrive"="c:\program files\FarStone\GameDrive\GDP\GDTask.exe" [2006-07-21 167936]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 1820040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\User\Start Menu\šα˜˜\΅΅εžž\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2010-2-27 576000]

c:\documents and settings\All Users\Start Menu\šα˜˜\΅΅εžž\
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2008-3-7 131072]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-5-23 122880]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
2008-03-18 13:58 58672 ----a-w- c:\windows\system32\avldr.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PskSvcRetail]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Documents and Settings\\User\\Επιφάνεια εργασίας\\Guns 'N' Roses\\uTorrent.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

R0 FGXSCSI;FGXSCSI;c:\windows\system32\drivers\fgxscsi.sys [18/2/2010 6:15 μμ 71680]
R0 pavboot;Panda boot driver;c:\windows\system32\drivers\pavboot.sys [5/4/2009 4:23 μμ 28544]
R1 APPFLT;App Filter Plugin;c:\windows\system32\drivers\APPFLT.SYS [15/10/2009 11:13 μμ 73728]
R1 DSAFLT;DSA Filter Plugin;c:\windows\system32\drivers\dsaflt.sys [15/10/2009 11:14 μμ 52992]
R1 FNETMON;NetMon Filter Plugin;c:\windows\system32\drivers\fnetmon.sys [15/10/2009 11:13 μμ 22072]
R1 IDSFLT;Ids Filter Plugin;c:\windows\system32\drivers\idsflt.sys [15/10/2009 11:14 μμ 193792]
R1 NETFLTDI;Panda Net Driver [TDI Layer];c:\windows\system32\drivers\NETFLTDI.SYS [15/10/2009 11:13 μμ 158848]
R1 ShldDrv;Panda File Shield Driver;c:\windows\system32\drivers\ShlDrv51.sys [15/10/2009 11:02 μμ 41144]
R1 SSHDRV79;SSHDRV79;c:\windows\system32\drivers\SSHDRV79.sys [28/10/2009 4:54 μμ 75264]
R1 SSHDRV85;SSHDRV85;c:\windows\system32\drivers\SSHDRV85.sys [1/12/2009 3:30 μμ 78848]
R1 WNMFLT;Wifi Monitor Filter Plugin;c:\windows\system32\drivers\wnmflt.sys [15/10/2009 11:14 μμ 46720]
R2 Gwmsrv;Panda Goodware Cache Manager;c:\windows\system32\svchost -k Panda --> c:\windows\system32\svchost -k Panda [?]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [30/3/2010 11:16 πμ 1107336]
R2 INFOlearn_admin_srv;INFOlearn Admin Service;c:\windows\system32\infolearnasrv.exe [6/10/2006 8:35 μμ 49152]
R2 PavProc;Panda Process Protection Driver;c:\windows\system32\drivers\PavProc.sys [15/10/2009 11:02 μμ 177416]
R2 pdfcDispatcher;PDF Document Manager;c:\program files\PDF Complete\pdfsvc.exe [10/1/2008 1:54 μμ 540184]
R2 PskSvcRetail;Panda PSK service;c:\program files\Panda Security\Panda Global Protection 2010\psksvc.exe [15/10/2009 11:13 μμ 28928]
R3 AvFlt;Antivirus Filter Driver;c:\windows\system32\drivers\av5flt.sys --> c:\windows\system32\drivers\av5flt.sys [?]
R3 ComFiltr;Panda Anti-Dialer;c:\windows\system32\drivers\COMFiltr.sys [15/10/2009 11:19 μμ 13880]
R3 NETIMFLT01060034;PANDA NDIS IM Filter Miniport v1.6.0.34;c:\windows\system32\drivers\neti1634.sys [15/10/2009 11:13 μμ 197888]
R3 PavSRK.sys;PavSRK.sys;\??\c:\windows\system32\PavSRK.sys --> c:\windows\system32\PavSRK.sys [?]
R3 PavTPK.sys;PavTPK.sys;\??\c:\windows\system32\PavTPK.sys --> c:\windows\system32\PavTPK.sys [?]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [21/5/2008 5:03 μμ 691696]
S1 SSHDRV65;SSHDRV65;\??\c:\windows\system32\drivers\SSHDRV65.sys --> c:\windows\system32\drivers\SSHDRV65.sys [?]
S3 P1130VID;Creative WebCam NX Pro;c:\windows\system32\drivers\P1130Vid.sys [4/2/2008 5:25 μμ 90357]
S3 rkhdrv40;Rootkit Unhooker Driver; [x]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [30/6/2009 9:32 μμ 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [30/6/2009 9:32 μμ 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [30/6/2009 9:32 μμ 120744]
S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [30/6/2009 9:32 μμ 114216]
S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [30/6/2009 9:32 μμ 25512]
S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [30/6/2009 9:32 μμ 110632]
S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [30/6/2009 9:32 μμ 115752]
S3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\drivers\s0017bus.sys [30/6/2009 9:32 μμ 90536]
S3 s0017mdfl;Sony Ericsson Device 0017 USB WMC Modem Filter;c:\windows\system32\drivers\s0017mdfl.sys [30/6/2009 9:32 μμ 15016]
S3 s0017mdm;Sony Ericsson Device 0017 USB WMC Modem Driver;c:\windows\system32\drivers\s0017mdm.sys [30/6/2009 9:32 μμ 122152]
S3 s0017mgmt;Sony Ericsson Device 0017 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0017mgmt.sys [30/6/2009 9:32 μμ 115496]
S3 s0017nd5;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (NDIS);c:\windows\system32\drivers\s0017nd5.sys [30/6/2009 9:32 μμ 25768]
S3 s0017obex;Sony Ericsson Device 0017 USB WMC OBEX Interface;c:\windows\system32\drivers\s0017obex.sys [30/6/2009 9:32 μμ 111912]
S3 s0017unic;Sony Ericsson Device 0017 USB Ethernet Emulation SEMC0017 (WDM);c:\windows\system32\drivers\s0017unic.sys [30/6/2009 9:32 μμ 117672]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
panda REG_MULTI_SZ Gwmsrv
.
Contents of the 'Scheduled Tasks' folder

2010-04-21 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 12:07]
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
uSearchMigratedDefaultURL = [You must be registered and logged in to see this link.]
uInternet Connection Wizard,ShellNext = iexplore
IE: Download the &current page with Offline Explorer - [You must be registered and logged in to see this link.] files\Offline Explorer\Add_AllO.htm
IE: Download using Offline &Explorer - [You must be registered and logged in to see this link.] files\Offline Explorer\Add_UrlO.htm
IE: Ε&ξαγωγή στο Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\cu6zhwsp.default\
FF - prefs.js: browser.startup.homepage - [You must be registered and logged in to see this link.]
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npff_gdm.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2010-04-21 12:22
Windows 5.1.2600 Service Pack 3 NTFS

detected NTDLL code modification:
ZwEnumerateKey, ZwClose, ZwEnumerateValueKey, ZwQueryValueKey, ZwOpenFile

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\pdfcDispatcher]
"ImagePath"="c:\program files\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-4160596134-3961019470-752118726-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-4160596134-3961019470-752118726-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:16,10,41,ed,64,3d,77,f2,44,9e,32,86,e1,f1,8f,c6,19,aa,b3,67,76,a2,d2,
73,61,f4,91,60,e8,8e,09,5d,f5,db,35,bd,f1,b2,26,dc,8a,86,20,0e,c9,1e,4f,98,\
"??"=hex:c2,59,d1,1c,d4,d2,90,9f,4a,b4,64,fe,e2,10,24,81

[HKEY_USERS\S-1-5-21-4160596134-3961019470-752118726-1005\Software\SecuROM\License information*]
"datasecu"=hex:4e,10,57,e3,ee,b9,10,cd,ed,b0,f4,0a,39,5b,5d,c4,f4,5c,f9,8d,eb,
25,1d,10,c6,8f,ff,9b,72,ca,0a,32,3c,29,20,a5,3a,7e,00,95,4e,90,cb,5d,c2,27,\
"rkeysecu"=hex:8b,a4,d9,a9,1b,8f,88,92,bf,ca,aa,f3,89,e8,18,92
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1320)
c:\windows\system32\avldr.dll
.
Completion time: 2010-04-21 12:24:31
ComboFix-quarantined-files.txt 2010-04-21 09:24
ComboFix2.txt 2010-04-19 19:12
ComboFix3.txt 2010-04-19 18:48
ComboFix4.txt 2010-04-16 10:10

Pre-Run: 28 Κατάλογοι 59.637.858.304 διαθέσιμα byte
Post-Run: 29 Κατάλογοι 59.609.624.576 διαθέσιμα byte

- - End Of File - - FAAD2D2BCAAE24D4CD9B05513F1BE38C



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Belahzur on Wed Apr 21, 2010 4:04 pm

Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /uninstall

This will also reset your restore points.

How is the machine running now?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34916
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : XP SP3 Media Centre
Points Points : 245059
# Likes # Likes : 1

View user profile

Back to top Go down

Re: Internet lags, is it a virus?

Post by Vladimir on Wed Apr 21, 2010 7:31 pm

Yes, it seems ok for now, I'll test it for a couple of days and answer you back.

Thanks very much though Honored



Vladimir
Senior
Senior

Posts Posts : 219
Joined Joined : 2009-02-09
Gender Gender : Male
OS OS : Windows XP SP3
Points Points : 30498
# Likes # Likes : 0

View user profile

Back to top Go down

Page 1 of 2 1, 2  Next

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum