Hello folks! I'm new to this community, though I've been lurking for a few days and it really seems that it'd be a nice place to become involved in. I'll be sure to post an introduction thread soon. 
In the mean time, I am facing a challenge removing this infection on a friend's system which I am repairing remotely. The system originally had a rogue infection and I ran Combofix as well as Malwarebytes Anti-malware and it appeared to take care of it. Unfortunately, there is still some freezing and the unit still runs slower than expected as per my friend.. plus MABM did pick up an infection in a quick scan.
Any assistance is greatly appreciated.
==
Logs
==
DDS (Ver_10-03-17.01) - NTFSx86 NETWORK
Run by Chris at 21:35:33.71 on Tue 08/24/2010
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2039.1382 [GMT -7:00]
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\TeamViewer\Version5\TeamViewer.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWWSC.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\msiexec.exe
C:\Program Files\UltraVNC\winvnc.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Chris\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BK5MN7WL\dds[1].scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uInternet Settings,ProxyOverride = *.local;<local>
uInternet Settings,ProxyServer = http=localhost:7171
BHO: MRI_DISABLED - No File
BHO: 1 (0x1) - No File
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
uRun: [Svhst] c:\users\chris\appdata\roaming\swhst\svhst.exe
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
dRun: [MySpaceIM] c:\program files\myspace\im\MySpaceIM.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\autoru~1\mri_di~1\exifla~1.lnk - c:\program files\finepixviewers\QuickDCF2.exe
uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
mPolicies-system: EnableLUA = 0 (0x0)
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_01\bin\npjpi160_01.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
Notify: igfxcui - igfxdev.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\chris\appdata\roaming\mozilla\firefox\profiles\l8k0id2p.default\
FF - component: c:\program files\mozilla firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
FF - component: c:\users\chris\appdata\roaming\mozilla\firefox\profiles\l8k0id2p.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
FF - plugin: c:\users\chris\appdata\roaming\mozilla\firefox\profiles\l8k0id2p.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-8-18 64288]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-8-12 1355416]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-8-17 165456]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-8-17 17744]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-8-17 50256]
S2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-8-17 40384]
S2 lxddCATSCustConnectService;lxddCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxddserv.exe [2007-4-25 99248]
S2 TeamViewer5;TeamViewer 5;c:\program files\teamviewer\version5\TeamViewer_Service.exe [2010-7-6 173352]
S2 uvnc_service;uvnc_service;c:\program files\ultravnc\winvnc.exe [2010-8-24 1590216]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-8-17 40384]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-8-17 40384]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2010-8-12 15008]
S3 mv2;mv2;c:\windows\system32\drivers\mv2.sys [2010-8-24 12096]
S3 NETw2v32;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\drivers\NETw2v32.sys [2006-11-2 2589184]
S4 B-Service;B-Service;c:\users\chris\downloads\B-Service.exe [2010-8-9 185640]
S4 lxdd_device;lxdd_device;c:\windows\system32\lxddcoms.exe -service --> c:\windows\system32\lxddcoms.exe -service [?]
=============== Created Last 30 ================
2010-08-25 04:27:59 23872 ----a-w- c:\windows\system32\mv2.dll
2010-08-25 04:27:59 12096 ----a-w- c:\windows\system32\drivers\mv2.sys
2010-08-25 04:27:51 0 d-----w- c:\program files\UltraVNC
2010-08-19 04:44:41 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-08-18 12:21:52 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-08-18 12:21:49 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-08-18 11:57:45 0 dc-h--w- c:\programdata\{ECC164E0-3133-4C70-A831-F08DB2940F70}
2010-08-18 11:57:06 0 d-----w- c:\programdata\Lavasoft
2010-08-18 11:57:06 0 d-----w- c:\program files\Lavasoft
2010-08-18 05:18:36 50256 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-08-18 05:18:11 38848 ----a-w- c:\windows\avastSS.scr
2010-08-18 05:18:08 0 d-----w- c:\programdata\Alwil Software
2010-08-17 02:51:46 0 d-----w- C:\SDFix
2010-08-17 02:41:06 53248 ----a-w- c:\windows\system32\process.exe
2010-08-17 02:41:06 126976 ----a-w- c:\windows\system32\zip.exe
2010-08-17 02:40:56 0 d-----w- c:\program files\roguescanfix
2010-08-17 02:32:07 0 d-----w- c:\windows\LMI7445.tmp
2010-08-17 02:27:38 0 d-----w- c:\program files\Trend Micro
2010-08-15 17:01:06 0 d-----w- c:\users\chris\appdata\roaming\TeamViewer
2010-08-15 15:49:02 0 d-----w- c:\users\chris\appdata\roaming\PCToolsFirewallPlus
2010-08-15 15:49:01 0 d-----w- c:\users\chris\appdata\roaming\Spam Monitor
2010-08-15 14:44:08 0 d-----w- c:\programdata\PC Tools
2010-08-15 14:44:08 0 d-----w- c:\program files\PC Tools Internet Security
2010-08-15 14:43:38 0 d-----w- c:\users\chris\appdata\roaming\Swhst
2010-08-15 14:09:02 798 ---ha-w- C:\IPH.PH
2010-08-15 14:09:02 0 d--h--w- C:\TEMP
2010-08-15 14:01:16 0 d-----w- c:\program files\common files\PC Tools
2010-08-15 14:01:14 0 d---a-w- c:\programdata\TEMP
2010-08-15 13:11:46 4213696 ----a-w- C:\ExterminateIt.exe
2010-08-15 07:16:34 0 d-----w- c:\program files\Exterminate It!
2010-08-15 06:51:29 226688 ----a-w- C:\BdUninstallTool2010.08.14-11.51.29.reg
2010-08-15 04:22:02 0 d-----w- c:\users\chris\appdata\roaming\QuickScan
2010-08-14 22:56:26 0 d-----w- c:\programdata\SUPERAntiSpyware.com
2010-08-14 14:19:07 0 d-sh--w- C:\$RECYCLE.BIN
2010-08-13 05:24:32 162616 ----a-w- c:\windows\RegDelNull.exe
2010-08-12 04:50:55 1152 ----a-w- c:\windows\system32\windrv.sys
2010-08-10 03:34:33 15892480 ----a-w- C:\Ad-AwareInstall.exe
2010-08-10 03:03:53 0 d-----w- c:\programdata\Spybot - Search & Destroy
2010-08-10 03:03:53 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-08-10 02:44:19 16409960 ----a-w- C:\spybotsd162.exe
2010-08-10 02:15:43 98816 ----a-w- c:\windows\sed.exe
2010-08-10 02:15:43 77312 ----a-w- c:\windows\MBR.exe
2010-08-10 02:15:43 256512 ----a-w- c:\windows\PEV.exe
2010-08-10 02:15:43 161792 ----a-w- c:\windows\SWREG.exe
2010-08-10 02:12:38 35 ----a-w- c:\users\chris\appdata\roaming\SetValue.bat
2010-08-10 02:12:37 691 ----a-w- c:\users\chris\appdata\roaming\GetValue.vbs
2010-08-09 23:56:45 0 d-----w- c:\users\chris\appdata\roaming\Malwarebytes
2010-08-09 23:56:27 0 d-----w- c:\programdata\Malwarebytes
2010-08-09 23:50:12 0 d-----w- c:\program files\TeamViewer
2010-08-03 22:46:16 221300608 ----a-w- c:\windows\MEMORY.DMP
==================== Find3M ====================
2010-08-25 04:28:06 86016 ----a-w- c:\windows\inf\infstrng.dat
2010-08-25 04:28:06 51200 ----a-w- c:\windows\inf\infpub.dat
2010-08-25 04:28:05 86016 ----a-w- c:\windows\inf\infstor.dat
2010-08-23 18:07:04 4022 ----a-w- c:\users\chris\appdata\roaming\wklnhst.dat
2008-08-03 09:44:02 174 --sha-w- c:\program files\desktop.ini
2008-08-03 09:31:48 665600 ----a-w- c:\windows\inf\drvindex.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-05-01 06:44:18 16384 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2009-05-01 06:44:18 32768 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2009-05-01 06:44:18 16384 --sha-w- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat
2008-01-15 06:45:41 16384 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2008-01-15 06:45:41 32768 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2008-01-15 06:45:41 16384 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\cookies\index.dat
2008-09-07 04:26:46 32768 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008090620080907\index.dat
============= FINISH: 21:36:32.46 ===============
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-08-23 21:03:44
Windows 6.0.6001 Service Pack 1
Running: nrl9qy0u.exe; Driver: C:\Users\Chris\AppData\Local\Temp\ufldapoc.sys
---- System - GMER 1.0.15 ----
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0x8E997B9C]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0x8E9979C0]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0x8E997AFA]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- EOF - GMER 1.0.15 ----
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4473
Windows 6.0.6001 Service Pack 1 (Safe Mode)
Internet Explorer 7.0.6001.18000
8/25/2010 04:06:29
mbam-log-2010-08-25 (04-06-29).txt
Scan type: Quick scan
Objects scanned: 135305
Time elapsed: 5 minute(s), 38 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svhst (Backdoor.PoisonIvy) -> No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
In the mean time, I am facing a challenge removing this infection on a friend's system which I am repairing remotely. The system originally had a rogue infection and I ran Combofix as well as Malwarebytes Anti-malware and it appeared to take care of it. Unfortunately, there is still some freezing and the unit still runs slower than expected as per my friend.. plus MABM did pick up an infection in a quick scan.
Any assistance is greatly appreciated.
==
Logs
==
DDS (Ver_10-03-17.01) - NTFSx86 NETWORK
Run by Chris at 21:35:33.71 on Tue 08/24/2010
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2039.1382 [GMT -7:00]
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\TeamViewer\Version5\TeamViewer.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWWSC.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\msiexec.exe
C:\Program Files\UltraVNC\winvnc.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Chris\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BK5MN7WL\dds[1].scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uInternet Settings,ProxyOverride = *.local;<local>
uInternet Settings,ProxyServer = http=localhost:7171
BHO: MRI_DISABLED - No File
BHO: 1 (0x1) - No File
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
uRun: [Svhst] c:\users\chris\appdata\roaming\swhst\svhst.exe
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
dRun: [MySpaceIM] c:\program files\myspace\im\MySpaceIM.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\autoru~1\mri_di~1\exifla~1.lnk - c:\program files\finepixviewers\QuickDCF2.exe
uPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
mPolicies-system: EnableLUA = 0 (0x0)
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_01\bin\npjpi160_01.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
Notify: igfxcui - igfxdev.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\chris\appdata\roaming\mozilla\firefox\profiles\l8k0id2p.default\
FF - component: c:\program files\mozilla firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
FF - component: c:\users\chris\appdata\roaming\mozilla\firefox\profiles\l8k0id2p.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
FF - plugin: c:\users\chris\appdata\roaming\mozilla\firefox\profiles\l8k0id2p.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-8-18 64288]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-8-12 1355416]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-8-17 165456]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-8-17 17744]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-8-17 50256]
S2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-8-17 40384]
S2 lxddCATSCustConnectService;lxddCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxddserv.exe [2007-4-25 99248]
S2 TeamViewer5;TeamViewer 5;c:\program files\teamviewer\version5\TeamViewer_Service.exe [2010-7-6 173352]
S2 uvnc_service;uvnc_service;c:\program files\ultravnc\winvnc.exe [2010-8-24 1590216]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-8-17 40384]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-8-17 40384]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\lavasoft\ad-aware\kernexplorer.sys [2010-8-12 15008]
S3 mv2;mv2;c:\windows\system32\drivers\mv2.sys [2010-8-24 12096]
S3 NETw2v32;Intel(R) PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\drivers\NETw2v32.sys [2006-11-2 2589184]
S4 B-Service;B-Service;c:\users\chris\downloads\B-Service.exe [2010-8-9 185640]
S4 lxdd_device;lxdd_device;c:\windows\system32\lxddcoms.exe -service --> c:\windows\system32\lxddcoms.exe -service [?]
=============== Created Last 30 ================
2010-08-25 04:27:59 23872 ----a-w- c:\windows\system32\mv2.dll
2010-08-25 04:27:59 12096 ----a-w- c:\windows\system32\drivers\mv2.sys
2010-08-25 04:27:51 0 d-----w- c:\program files\UltraVNC
2010-08-19 04:44:41 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-08-18 12:21:52 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-08-18 12:21:49 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-08-18 11:57:45 0 dc-h--w- c:\programdata\{ECC164E0-3133-4C70-A831-F08DB2940F70}
2010-08-18 11:57:06 0 d-----w- c:\programdata\Lavasoft
2010-08-18 11:57:06 0 d-----w- c:\program files\Lavasoft
2010-08-18 05:18:36 50256 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-08-18 05:18:11 38848 ----a-w- c:\windows\avastSS.scr
2010-08-18 05:18:08 0 d-----w- c:\programdata\Alwil Software
2010-08-17 02:51:46 0 d-----w- C:\SDFix
2010-08-17 02:41:06 53248 ----a-w- c:\windows\system32\process.exe
2010-08-17 02:41:06 126976 ----a-w- c:\windows\system32\zip.exe
2010-08-17 02:40:56 0 d-----w- c:\program files\roguescanfix
2010-08-17 02:32:07 0 d-----w- c:\windows\LMI7445.tmp
2010-08-17 02:27:38 0 d-----w- c:\program files\Trend Micro
2010-08-15 17:01:06 0 d-----w- c:\users\chris\appdata\roaming\TeamViewer
2010-08-15 15:49:02 0 d-----w- c:\users\chris\appdata\roaming\PCToolsFirewallPlus
2010-08-15 15:49:01 0 d-----w- c:\users\chris\appdata\roaming\Spam Monitor
2010-08-15 14:44:08 0 d-----w- c:\programdata\PC Tools
2010-08-15 14:44:08 0 d-----w- c:\program files\PC Tools Internet Security
2010-08-15 14:43:38 0 d-----w- c:\users\chris\appdata\roaming\Swhst
2010-08-15 14:09:02 798 ---ha-w- C:\IPH.PH
2010-08-15 14:09:02 0 d--h--w- C:\TEMP
2010-08-15 14:01:16 0 d-----w- c:\program files\common files\PC Tools
2010-08-15 14:01:14 0 d---a-w- c:\programdata\TEMP
2010-08-15 13:11:46 4213696 ----a-w- C:\ExterminateIt.exe
2010-08-15 07:16:34 0 d-----w- c:\program files\Exterminate It!
2010-08-15 06:51:29 226688 ----a-w- C:\BdUninstallTool2010.08.14-11.51.29.reg
2010-08-15 04:22:02 0 d-----w- c:\users\chris\appdata\roaming\QuickScan
2010-08-14 22:56:26 0 d-----w- c:\programdata\SUPERAntiSpyware.com
2010-08-14 14:19:07 0 d-sh--w- C:\$RECYCLE.BIN
2010-08-13 05:24:32 162616 ----a-w- c:\windows\RegDelNull.exe
2010-08-12 04:50:55 1152 ----a-w- c:\windows\system32\windrv.sys
2010-08-10 03:34:33 15892480 ----a-w- C:\Ad-AwareInstall.exe
2010-08-10 03:03:53 0 d-----w- c:\programdata\Spybot - Search & Destroy
2010-08-10 03:03:53 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-08-10 02:44:19 16409960 ----a-w- C:\spybotsd162.exe
2010-08-10 02:15:43 98816 ----a-w- c:\windows\sed.exe
2010-08-10 02:15:43 77312 ----a-w- c:\windows\MBR.exe
2010-08-10 02:15:43 256512 ----a-w- c:\windows\PEV.exe
2010-08-10 02:15:43 161792 ----a-w- c:\windows\SWREG.exe
2010-08-10 02:12:38 35 ----a-w- c:\users\chris\appdata\roaming\SetValue.bat
2010-08-10 02:12:37 691 ----a-w- c:\users\chris\appdata\roaming\GetValue.vbs
2010-08-09 23:56:45 0 d-----w- c:\users\chris\appdata\roaming\Malwarebytes
2010-08-09 23:56:27 0 d-----w- c:\programdata\Malwarebytes
2010-08-09 23:50:12 0 d-----w- c:\program files\TeamViewer
2010-08-03 22:46:16 221300608 ----a-w- c:\windows\MEMORY.DMP
==================== Find3M ====================
2010-08-25 04:28:06 86016 ----a-w- c:\windows\inf\infstrng.dat
2010-08-25 04:28:06 51200 ----a-w- c:\windows\inf\infpub.dat
2010-08-25 04:28:05 86016 ----a-w- c:\windows\inf\infstor.dat
2010-08-23 18:07:04 4022 ----a-w- c:\users\chris\appdata\roaming\wklnhst.dat
2008-08-03 09:44:02 174 --sha-w- c:\program files\desktop.ini
2008-08-03 09:31:48 665600 ----a-w- c:\windows\inf\drvindex.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-05-01 06:44:18 16384 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2009-05-01 06:44:18 32768 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2009-05-01 06:44:18 16384 --sha-w- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat
2008-01-15 06:45:41 16384 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2008-01-15 06:45:41 32768 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2008-01-15 06:45:41 16384 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\cookies\index.dat
2008-09-07 04:26:46 32768 --sha-w- c:\windows\system32\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\mshist012008090620080907\index.dat
============= FINISH: 21:36:32.46 ===============
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-08-23 21:03:44
Windows 6.0.6001 Service Pack 1
Running: nrl9qy0u.exe; Driver: C:\Users\Chris\AppData\Local\Temp\ufldapoc.sys
---- System - GMER 1.0.15 ----
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0x8E997B9C]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateSection [0x8E9979C0]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0x8E997AFA]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)
AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- EOF - GMER 1.0.15 ----
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4473
Windows 6.0.6001 Service Pack 1 (Safe Mode)
Internet Explorer 7.0.6001.18000
8/25/2010 04:06:29
mbam-log-2010-08-25 (04-06-29).txt
Scan type: Quick scan
Objects scanned: 135305
Time elapsed: 5 minute(s), 38 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svhst (Backdoor.PoisonIvy) -> No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)