1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Wanna help me fix my PC before i start school?

Discussion in 'Malware and Virus Removal Archive' started by Kome, 2010/09/06.

Thread Status:
Not open for further replies.
  1. 2010/09/06
    Kome

    Kome Inactive Thread Starter

    Joined:
    2010/09/06
    Messages:
    8
    Likes Received:
    0
    [Inactive] Wanna help me fix my PC before i start school?

    Hello, new here, but I've been lurking these forums to fix problems now and then. :)

    So to the point, for the past 3 or so months my computer has been messed up. I'm not sure if it's virus/malware or just something i didn't update(I've been told this was it but it made no difference). The story behind this is that my little cousin visited me one weekend from Mexico, i let him use my computer while i went to bed, last thing i knew he was doing he was just chatting it up on MSN. He wakes me up at about 2 AM to tell me that there's something wrong with my PC(Apparently someone send my cousin a link on MSN anonymously and he was dumb enough to click on it). So i go and check it out. Just some annoying re-link going on with my Firefox asking me to purchase Anti-virus software, i didn't make a big deal out of it and shut the PC off and went to bed. In the morning i tried using my computer but couldn't get passed the login sequence, i put in my password and i would just be able to login for about a second, long enough to see my desktop background before my PC restarted itself. And that was it, i could do nothing else, safe mode made no difference, type in pass word, press enter, see desktop for a second, self restart, repeat. I was out of ideas, and really had no other way to get online to try and diagnose the problem.

    I eventually got fed up and ended up calling Dell. Who were kind of enough to charge me $130 just to partially fix my computer. All they did was fix it enough so i could login and use my PC. That was it. Needless to say my computer was never the same after that. I could use the PC sure, but ever since then I've been stuck with these annoying symptoms.

    -Way longer start up time then before. (Which ***** cause i had just upgraded to 3GB of RAM prior to this :()
    -Google, Bing and any other search engines results get relinked to the same 2 or so pages. Ad pages. (Very annoying)
    -Firefox will just spontaneously open up a new tab. Sometimes it goes to a page with a large GIF file showing what's suppose to be my PC being scanned. Other times the tab will just stay blank but with a link in the adress bar.
    -Adobe flash crash. When using Youtube, music streaming etc.
    -I lose sound, ALOT! Probably the most annoying thing that happens. Even when i just start up the computer. It'll start up with no sound. Sometimes it'll just lose it while I'm using my PC and it wont come back until i restart at least 3 times. Sometimes i'll just lose sound on my Windows Media Player and Zune player but i can still hear it on Youtube, other times vice versa. But most of the times it's all together.
    -Error message "Generic Host Process for Win32 Services has encountered a problem and needs to close. We are sorry for the inconvenience." Comes up whenever i use my computer, regardless of what I'm doing.
    -PC overall is slower then it use to be. Even with simple thing as trying to open up My Pictures folder or anything along those lines.

    Now this is what i have tried to do though. But i haven't had any luck.

    -Tried to scan with multiple Anti-virus softwares. Bitdefender, AVG, Spybot etc. Even tried house call.
    -Clean out folders and files i didn't use.
    -Combofix
    -System Restore. (But i could only go back so far, and it made no difference.).

    I really don't know what else to do. All the Anti virus programs that I've used never pick up on any sort of virus or malware. I've been ignoring all this simply cause i gave up :(. But I'm moving cities to start school in about a month and i don't wanna deal with this when i do. I won't have enough time either with school and work.

    If you guys could please help me out in whatever way you can, it would be appreciated. Really ANYTHING would help. Lol. Thanks in advance :)
     
    Kome,
    #1
  2. 2010/09/06
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please, read HERE and post requested logs.
     

  3. to hide this advert.

  4. 2010/09/06
    Kome

    Kome Inactive Thread Starter

    Joined:
    2010/09/06
    Messages:
    8
    Likes Received:
    0
    DDS (Ver_10-03-17.01) - NTFSx86
    Run by EMOK!!! at 21:45:09.56 on Mon 09/06/2010
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2315 [GMT -7:00]


    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    svchost.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    c:\WINDOWS\system32\ZuneBusEnum.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\DivX\DivX Update\DivXUpdate.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MagicDisc\MagicDisc.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Mozilla Firefox\plugin-container.exe
    C:\Program Files\uTorrent\uTorrent.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\Documents and Settings\EMOK!!!\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    uInternet Settings,ProxyOverride = <local>
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
    BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
    TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
    dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
    StartupFolder: c:\docume~1\emok!!!\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL
    DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    TCP: {3848FFF9-CF73-45CF-8C8E-6E070BB0B4C3} = 205.171.3.65,205.171.2.65
    Notify: AtiExtEvent - Ati2evxx.dll
    Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\emok!!!\applic~1\mozilla\firefox\profiles\v9gkpdej.default\
    FF - prefs.js: network.proxy.type - 2
    FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
    FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
    FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    c:\program files\mozilla firefox\greprefs\all.js - pref( "ui.use_native_colors ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "ui.use_native_popup_windows ", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.enable_click_image_resizing ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "accessibility.browsewithcaret_shortcut.enabled ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "javascript.options.mem.high_water_mark ", 32);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "javascript.options.mem.gc_frequency ", 1600);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.lu ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.nu ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.nz ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgbaam7a8h ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgberp4a5d4ar ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--p1ai ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.xn--mgbayh7gpa ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.IDN.whitelist.tel ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.auth.force-generic-ntlm ", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.proxy.type ", 5);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.buffer.cache.count ", 24);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "network.buffer.cache.size ", 4096);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "dom.ipc.plugins.timeoutSecs ", 45);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "svg.smil.enabled ", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "ui.trackpoint_hack.enabled ", -1);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.debug ", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.agedWeight ", 2);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.bucketSize ", 1);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.maxTimeGroupings ", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.timeGroupingSize ", 604800);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.boundaryWeight ", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "browser.formfill.prefixWeight ", 5);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "accelerometer.enabled ", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref( "html5.enable ", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref ", true);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl.renego_unrestricted_hosts ", " ");
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl.treat_unsafe_negotiation_as_broken ", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl.require_safe_negotiation ", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref( "security.ssl3.rsa_seed_sha ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref( "app.update.download.backgroundInterval ", 600);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref( "app.update.url.manual ", "http://www.firefox.com ");
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref( "browser.search.param.yahoo-fr-ja ", "mozff ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name ", "chrome://browser/locale/browser.properties ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description ", "chrome://browser/locale/browser.properties ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "xpinstall.whitelist.add ", "addons.mozilla.org ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "xpinstall.whitelist.add.36 ", "getpersonas.com ");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "lightweightThemes.update.enabled ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.allTabs.previews ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "plugins.hide_infobar_for_outdated_plugin ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "plugins.update.notifyUser ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "toolbar.customization.usesheet ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.nptest.dll ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npswf32.dll ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npctrl.dll ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled.npqtplugin.dll ", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "dom.ipc.plugins.enabled ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.enable ", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.max ", 20);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref( "browser.taskbar.previews.cachetime ", 20);

    ============= SERVICES / DRIVERS ===============

    R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2010-9-6 28552]
    R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
    S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [2009-9-30 33792]
    S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\manycam.sys --> c:\windows\system32\drivers\ManyCam.sys [?]
    S4 sprtlisten;SupportSoft Listener Service;c:\program files\common files\supportsoft\bin\sprtlisten.exe [2008-1-8 1213728]
    S4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-5-8 24652]

    =============== Created Last 30 ================

    2010-09-06 07:56:59 28552 ----a-w- c:\windows\system32\drivers\pavboot.sys
    2010-09-06 07:56:34 0 d-----w- c:\program files\Panda Security
    2010-09-04 05:04:00 0 d-----w- c:\program files\Steam
    2010-08-09 00:21:04 0 d-----w- c:\windows\system32\wbem\Repository

    ==================== Find3M ====================

    2010-06-09 23:01:10 133616 ------w- c:\windows\system32\pxafs.dll
    2010-06-09 23:01:10 126448 ------w- c:\windows\system32\pxinsi64.exe
    2010-06-09 23:01:10 123888 ------w- c:\windows\system32\pxcpyi64.exe
    2009-12-17 11:27:09 245760 --sha-w- c:\windows\system32\config\systemprofile\ietldcache\index.dat
    2009-12-17 11:27:09 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009121720091218\index.dat

    ============= FINISH: 21:46:36.17 ===============
     
    Kome,
    #3
  5. 2010/09/06
    Kome

    Kome Inactive Thread Starter

    Joined:
    2010/09/06
    Messages:
    8
    Likes Received:
    0
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_10-03-17.01)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 5/7/2009 5:53:20 PM
    System Uptime: 9/6/2010 12:59:26 PM (9 hours ago)

    Motherboard: Dell Inc. | | 0WG860
    Processor: Intel(R) Core(TM)2 CPU 6300 @ 1.86GHz | Microprocessor | 1862/1066mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 466 GiB total, 139.134 GiB free.
    D: is CDROM ()
    E: is CDROM (CDFS)

    ==== Disabled Device Manager Items =============

    Class GUID:
    Description:
    Device ID: ROOT\SYSTEM\0003
    Manufacturer:
    Name:
    PNP Device ID: ROOT\SYSTEM\0003
    Service:

    ==== System Restore Points ===================

    RP509: 6/10/2010 4:48:08 PM - System Checkpoint
    RP510: 6/11/2010 6:58:23 PM - System Checkpoint
    RP511: 6/12/2010 10:52:30 PM - System Checkpoint
    RP512: 6/13/2010 11:11:15 PM - System Checkpoint
    RP513: 6/15/2010 5:15:49 PM - System Checkpoint
    RP514: 6/16/2010 5:18:16 PM - System Checkpoint
    RP515: 6/17/2010 6:25:42 PM - System Checkpoint
    RP516: 6/18/2010 7:00:14 PM - System Checkpoint
    RP517: 6/19/2010 7:13:16 PM - System Checkpoint
    RP518: 6/21/2010 5:05:00 PM - System Checkpoint
    RP519: 6/25/2010 10:47:20 PM - Installed QuickTime
    RP520: 6/25/2010 10:50:11 PM - Removed QuickTime
    RP521: 6/28/2010 1:56:55 PM - System Checkpoint
    RP522: 6/29/2010 6:03:23 PM - System Checkpoint
    RP523: 6/30/2010 9:09:20 PM - System Checkpoint
    RP524: 7/6/2010 6:32:57 PM - System Checkpoint
    RP525: 7/9/2010 9:21:54 PM - System Checkpoint
    RP526: 7/10/2010 10:18:59 PM - System Checkpoint
    RP527: 7/12/2010 3:31:31 PM - System Checkpoint
    RP528: 7/14/2010 1:38:24 PM - System Checkpoint
    RP529: 7/17/2010 4:04:21 PM - System Checkpoint
    RP530: 7/18/2010 5:12:21 PM - System Checkpoint
    RP531: 7/19/2010 6:16:05 PM - System Checkpoint
    RP532: 7/21/2010 11:53:04 AM - System Checkpoint
    RP533: 7/22/2010 1:02:49 AM - Removed Condemned - Criminal Origins
    RP534: 7/25/2010 12:47:26 PM - Removed Battlefield 2142 Server
    RP535: 7/25/2010 12:47:50 PM - Removed Battlefield 2142
    RP536: 7/25/2010 1:00:17 PM - Installed BitDefender Antivirus 2010
    RP537: 7/25/2010 1:04:33 PM - Removed Ask Toolbar.
    RP538: 7/25/2010 1:04:53 PM - avast! Free Antivirus Setup
    RP539: 7/27/2010 3:20:12 AM - System Checkpoint
    RP540: 7/28/2010 6:24:33 PM - System Checkpoint
    RP541: 8/2/2010 2:51:50 PM - System Checkpoint
    RP542: 8/3/2010 8:49:42 PM - System Checkpoint
    RP543: 8/4/2010 1:07:28 PM - Removed BitDefender Antivirus 2010
    RP544: 8/4/2010 1:09:42 PM - Installed BitDefender Antivirus 2010
    RP545: 8/8/2010 5:19:52 PM - Restore Operation
    RP546: 8/10/2010 4:54:40 PM - System Checkpoint
    RP547: 8/11/2010 7:12:59 PM - System Checkpoint
    RP548: 8/13/2010 2:32:31 PM - System Checkpoint
    RP549: 8/14/2010 7:46:39 PM - System Checkpoint
    RP550: 8/16/2010 7:31:03 PM - System Checkpoint
    RP551: 8/18/2010 1:32:18 AM - System Checkpoint
    RP552: 8/19/2010 1:42:44 AM - System Checkpoint
    RP553: 8/20/2010 3:10:54 AM - System Checkpoint
    RP554: 8/21/2010 3:56:19 AM - System Checkpoint
    RP555: 8/22/2010 4:24:55 PM - System Checkpoint
    RP556: 8/23/2010 4:42:21 PM - System Checkpoint
    RP557: 8/25/2010 2:28:58 PM - System Checkpoint
    RP558: 8/25/2010 11:07:00 PM - Removed Steam
    RP559: 8/28/2010 5:32:23 PM - System Checkpoint
    RP560: 8/29/2010 11:20:24 PM - System Checkpoint
    RP561: 8/31/2010 4:09:59 PM - System Checkpoint
    RP562: 9/2/2010 2:07:57 PM - System Checkpoint
    RP563: 9/3/2010 5:28:46 PM - System Checkpoint
    RP564: 9/3/2010 10:03:59 PM - Installed Steam
    RP565: 9/5/2010 3:46:56 PM - System Checkpoint
    RP566: 9/6/2010 12:53:10 PM - Removed BitDefender Antivirus 2010

    ==== Installed Programs ======================

    µTorrent
    7-Zip 4.65
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 9.3.1
    Advanced_Random_Permutation (C:\Program Files\Project1\)
    AIM 7
    Antares Autotune VST RTAS TDM v5.08
    Any Video Converter 2.7.3
    Apple Application Support
    Apple Software Update
    ATI - Software Uninstall Utility
    ATI Catalyst Control Center
    ATI Display Driver
    AVS DVDMenu Editor 1.2.1.20
    AVS Update Manager 1.0
    AVS Video ReMaker 2.4
    AVS4YOU Software Navigator 1.3
    Catalyst Control Center - Branding
    Catalyst Control Center Core Implementation
    Catalyst Control Center Graphics Full Existing
    Catalyst Control Center Graphics Full New
    Catalyst Control Center Graphics Light
    Catalyst Control Center Graphics Previews Common
    Catalyst Control Center HydraVision Full
    ccc-core-preinstall
    ccc-core-static
    ccc-utility
    CCC Help English
    Collab
    Conexant HDA D110 MDC V.92 Modem
    Critical Update for Windows Media Player 11 (KB959772)
    D-Link VGA Webcam
    Digital Photo Navigator 1.5
    DivX Plus DirectShow Filters
    DivX Setup
    Download Updater (AOL LLC)
    EAX Unified
    FinalBurner Free v2.15.0.171
    FL Studio 8
    GemMaster Mystic
    GoToAssist 8.0.0.514
    High Definition Audio Driver Package - KB835221
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 10 (KB903157)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB932716-v2)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB954708)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB970653-v3)
    Hotfix for Windows XP (KB976098-v2)
    Hotfix for Windows XP (KB979306)
    IL Download Manager
    Intel(R) PRO Network Connections Drivers
    Java Auto Updater
    Java(TM) 6 Update 20
    Junk Mail filter update
    K-Lite Codec Pack 4.8.0 (Full)
    Left 4 Dead
    Mafia
    MagicDisc 2.7.106
    Messenger Plus! Live
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB953297)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Application Error Reporting
    Microsoft Choice Guard
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Games for Windows - LIVE
    Microsoft Games for Windows - LIVE Redistributable
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Word 2007
    Microsoft Office Word MUI (English) 2007
    Microsoft Search Enhancement Pack
    Microsoft Silverlight
    Microsoft Software Update for Web Folders (English) 12
    Microsoft SQL Server 2005 Compact Edition [ENU]
    Microsoft Sync Framework Runtime Native v1.0 (x86)
    Microsoft Sync Framework Services Native v1.0 (x86)
    Microsoft User-Mode Driver Framework Feature Pack 1.9
    Microsoft VC9 runtime libraries
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft WinUsb 1.0
    Mozilla Firefox (3.6.8)
    Mp3tag v2.43
    MSM32Installer
    MSVCRT
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 6 Service Pack 2 (KB973686)
    Music Creator 4
    NVIDIA PhysX v8.10.17
    Otto
    Panda ActiveScan 2.0
    PoiZone
    PowerCinema NE for Everio
    PowerDirector Express
    PowerISO
    PowerProducer
    QuickConnect
    Qwest Installer
    Qwest Personal Digital Vault™
    Qwest QuickAssist Desktop Tools
    Roxio DLA
    Roxio MyDVD LE
    Roxio RecordNow Audio
    Roxio RecordNow Copy
    Roxio RecordNow Data
    Security Update for 2007 Microsoft Office System (KB969559)
    Security Update for 2007 Microsoft Office System (KB976321)
    Security Update for 2007 Microsoft Office System (KB978380)
    Security Update for Microsoft Office system 2007 (972581)
    Security Update for Microsoft Office system 2007 (KB974234)
    Security Update for Microsoft Office Word 2007 (KB969604)
    Security Update for Windows Internet Explorer 8 (KB971961)
    Security Update for Windows Internet Explorer 8 (KB972260)
    Security Update for Windows Internet Explorer 8 (KB974455)
    Security Update for Windows Internet Explorer 8 (KB976325)
    Security Update for Windows Internet Explorer 8 (KB978207)
    Security Update for Windows Internet Explorer 8 (KB981332)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB954155)
    Security Update for Windows Media Player (KB968816)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB938464-v2)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958869)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969059)
    Security Update for Windows XP (KB969897)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB969947)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB970430)
    Security Update for Windows XP (KB971468)
    Security Update for Windows XP (KB971486)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB972260)
    Security Update for Windows XP (KB972270)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973525)
    Security Update for Windows XP (KB973869)
    Security Update for Windows XP (KB973904)
    Security Update for Windows XP (KB974112)
    Security Update for Windows XP (KB974318)
    Security Update for Windows XP (KB974392)
    Security Update for Windows XP (KB974571)
    Security Update for Windows XP (KB975025)
    Security Update for Windows XP (KB975467)
    Security Update for Windows XP (KB975560)
    Security Update for Windows XP (KB975561)
    Security Update for Windows XP (KB975713)
    Security Update for Windows XP (KB977816)
    Security Update for Windows XP (KB977914)
    Security Update for Windows XP (KB978037)
    Security Update for Windows XP (KB978262)
    Security Update for Windows XP (KB978338)
    Security Update for Windows XP (KB978542)
    Security Update for Windows XP (KB978601)
    Security Update for Windows XP (KB978706)
    Security Update for Windows XP (KB979309)
    Security Update for Windows XP (KB979683)
    Security Update for Windows XP (KB980232)
    Segoe UI
    SigmaTel Audio
    Skins
    Sonic Encoders
    Sonic Update Manager
    SoulSeek 157 NS 13d
    Spectro
    Spelling Dictionaries Support For Adobe Reader 9
    Spybot - Search & Destroy
    Steam
    Switch Sound File Converter
    Toxic Biohazard
    Update for 2007 Microsoft Office System (KB967642)
    Update for 2007 Microsoft Office System (KB981715)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft Office InfoPath 2007 (KB976416)
    Update for Windows Internet Explorer 8 (KB976662)
    Update for Windows Internet Explorer 8 (KB976749)
    Update for Windows Internet Explorer 8 (KB980182)
    Update for Windows Media Player 10 (KB913800)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955759)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB961503)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB971737)
    Update for Windows XP (KB973687)
    Update for Windows XP (KB973815)
    Update Rollup 2 for Windows XP Media Center Edition 2005
    VC80CRTRedist - 8.0.50727.4053
    Viewpoint Media Player
    Visual C++ 8.0 Runtime Setup Package
    WebFldrs XP
    Windows Imaging Component
    Windows Internet Explorer 8
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Mail
    Windows Live Messenger
    Windows Live Photo Gallery
    Windows Live Sign-in Assistant
    Windows Live Sync
    Windows Live Toolbar
    Windows Live Upload Tool
    Windows Live Writer
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows PowerShell(TM) 1.0
    Windows XP Media Center Edition 2005 KB925766
    Windows XP Media Center Edition 2005 KB973768
    Windows XP Service Pack 3
    XML Paper Specification Shared Components Pack 1.0
    Zune
    Zune Language Pack (ES)
    Zune Language Pack (FR)

    ==== Event Viewer Messages From Past Week ========

    9/5/2010 9:12:25 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service BITS with arguments " " in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}
    9/4/2010 9:01:46 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Fast User Switching Compatibility service to connect.
    9/4/2010 9:01:46 PM, error: Service Control Manager [7000] - The Fast User Switching Compatibility service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    9/4/2010 8:19:37 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service netman with arguments " " in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
    9/4/2010 6:53:33 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service SeaPort with arguments "-Service" in order to run the server: {D6381B4A-D254-46EB-9018-A62E0F4BA6BA}
    9/3/2010 9:29:41 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service EventSystem with arguments " " in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    9/3/2010 7:11:57 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service wuauserv with arguments " " in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
    9/3/2010 6:27:29 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service winmgmt with arguments " " in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820}
    9/2/2010 8:49:40 PM, error: Service Control Manager [7022] - The Windows Image Acquisition (WIA) service hung on starting.
    9/2/2010 8:48:17 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Wireless Zero Configuration service to connect.
    9/2/2010 8:48:17 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Themes service to connect.
    9/2/2010 8:48:17 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Shell Hardware Detection service to connect.
    9/2/2010 8:48:17 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the DHCP Client service to connect.
    9/2/2010 8:48:17 PM, error: Service Control Manager [7000] - The Wireless Zero Configuration service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    9/2/2010 8:48:17 PM, error: Service Control Manager [7000] - The Themes service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    9/2/2010 8:48:17 PM, error: Service Control Manager [7000] - The DHCP Client service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    9/1/2010 1:40:10 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Task Scheduler service to connect.
    9/1/2010 1:40:10 PM, error: Service Control Manager [7000] - The Task Scheduler service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    9/1/2010 1:36:05 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Workstation service to connect.
    9/1/2010 1:36:05 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Windows Audio service to connect.
    9/1/2010 1:36:05 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Logical Disk Manager service to connect.
    9/1/2010 1:36:05 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Error Reporting Service service to connect.
    9/1/2010 1:36:05 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the CryptSvc service to connect.
    9/1/2010 1:36:05 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the COM+ Event System service to connect.
    9/1/2010 1:36:05 PM, error: Service Control Manager [7001] - The System Event Notification service depends on the COM+ Event System service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
    9/1/2010 1:36:05 PM, error: Service Control Manager [7001] - The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
    9/1/2010 1:36:05 PM, error: Service Control Manager [7000] - The Workstation service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    9/1/2010 1:36:05 PM, error: Service Control Manager [7000] - The Windows Audio service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    9/1/2010 1:36:05 PM, error: Service Control Manager [7000] - The Logical Disk Manager service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    9/1/2010 1:36:05 PM, error: Service Control Manager [7000] - The CryptSvc service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    9/1/2010 1:36:05 PM, error: Service Control Manager [7000] - The COM+ Event System service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    8/31/2010 3:04:19 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Windows Time service to connect.
    8/31/2010 3:04:19 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Windows Management Instrumentation service to connect.
    8/31/2010 3:04:19 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the System Restore Service service to connect.
    8/31/2010 3:04:19 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Server service to connect.
    8/31/2010 3:04:19 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Secondary Logon service to connect.
    8/31/2010 3:04:19 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Network Connections service to connect.
    8/31/2010 3:04:19 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Help and Support service to connect.
    8/31/2010 3:04:19 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Distributed Link Tracking Client service to connect.
    8/31/2010 3:04:19 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Automatic Updates service to connect.
    8/31/2010 3:04:19 PM, error: Service Control Manager [7001] - The Windows Firewall/Internet Connection Sharing (ICS) service depends on the Network Connections service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
    8/31/2010 3:04:19 PM, error: Service Control Manager [7001] - The Security Center service depends on the Windows Management Instrumentation service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion.
    8/31/2010 3:04:19 PM, error: Service Control Manager [7000] - The Windows Time service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    8/31/2010 3:04:19 PM, error: Service Control Manager [7000] - The System Restore Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    8/31/2010 3:04:19 PM, error: Service Control Manager [7000] - The Server service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    8/31/2010 3:04:19 PM, error: Service Control Manager [7000] - The Network Connections service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    8/31/2010 3:04:19 PM, error: Service Control Manager [7000] - The Help and Support service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    8/31/2010 3:04:19 PM, error: Service Control Manager [7000] - The Distributed Link Tracking Client service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    8/31/2010 3:04:19 PM, error: Service Control Manager [7000] - The Automatic Updates service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

    ==== End Of File ===========================
     
    Kome,
    #4
  6. 2010/09/06
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Print these instructions out.

    NOTE. If any of the programs listed below refuse to run, try renaming executive file to something else; for instance, rename hijackthis.exe to scanner.exe

    ***VERY IMPORTANT! Make sure, you update Malwarebytes before running the scan.***

    STEP 1. Download Malwarebytes' Anti-Malware: http://www.malwarebytes.org/mbam.php to your desktop.
    (Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt


    STEP 2. Download GMER: http://www.gmer.net/files.php, by clicking on Download EXE button.
    Alternative downloads:
    - http://majorgeeks.com/GMER_d5198.html
    - http://www.softpedia.com/get/Interne...ers/GMER.shtml
    Double click on downloaded .exe file, select Rootkit tab and click the Scan button.
    When scan is completed, click Save button, and save the results as gmer.log
    Warning ! Please, do not select the "Show all" checkbox during the scan.
    Post the log to your next reply.


    STEP 3. Download MBRCheck to your desktop

    Double click MBRCheck.exe to run (Vista and Windows 7 users, right click and select Run as Administrator).
    It will show a black screen with some data on it.
    A report called MBRcheckxxxx.txt will be on your desktop
    Open this report and post its content in your next reply.


    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
  7. 2010/09/07
    Kome

    Kome Inactive Thread Starter

    Joined:
    2010/09/06
    Messages:
    8
    Likes Received:
    0
    Ok it's scanning, i''l post the Malwarebytes log when it is finished.
     
    Kome,
    #6
  8. 2010/09/07
    Kome

    Kome Inactive Thread Starter

    Joined:
    2010/09/06
    Messages:
    8
    Likes Received:
    0
    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4558

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    9/6/2010 11:09:04 PM
    mbam-log-2010-09-06 (23-09-04).txt

    Scan type: Full scan (C:\|)
    Objects scanned: 291252
    Time elapsed: 1 hour(s), 9 minute(s), 56 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
     
    Kome,
    #7
  9. 2010/09/07
    Kome

    Kome Inactive Thread Starter

    Joined:
    2010/09/06
    Messages:
    8
    Likes Received:
    0
    I'm having trouble with GMER. I've tried scanning with 4 times and it will crash every single time. It will just freeze and i have to shut down my PC cause my computer freezes/lags. The 2nd time i actually got the Blue Screen of Death, that freaked me out of a bit.

    So i'm just gonna skip to step 3 and post the MBRcheck log.
     
    Kome,
    #8
  10. 2010/09/07
    Kome

    Kome Inactive Thread Starter

    Joined:
    2010/09/06
    Messages:
    8
    Likes Received:
    0
    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows XP Professional
    Windows Information: Service Pack 3 (build 2600)
    Logical Drives Mask: 0x0000001c

    Kernel Drivers (total 144):
    0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
    0x806E4000 \WINDOWS\system32\hal.dll
    0xBA5A8000 \WINDOWS\system32\KDCOM.DLL
    0xBA4B8000 \WINDOWS\system32\BOOTVID.dll
    0xB9F79000 ACPI.sys
    0xBA5AA000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
    0xB9F68000 pci.sys
    0xBA0A8000 ohci1394.sys
    0xBA0B8000 \WINDOWS\system32\DRIVERS\1394BUS.SYS
    0xBA0C8000 isapnp.sys
    0xBA0D8000 MountMgr.sys
    0xB9F49000 ftdisk.sys
    0xBA5AC000 dmload.sys
    0xB9F23000 dmio.sys
    0xBA328000 PartMgr.sys
    0xBA330000 pavboot.sys
    0xBA0E8000 VolSnap.sys
    0xB9E6C000 iaStor.sys
    0xBA338000 cercsr6.sys
    0xB9E54000 \WINDOWS\System32\Drivers\SCSIPORT.SYS
    0xBA0F8000 disk.sys
    0xBA108000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
    0xB9E34000 fltmgr.sys
    0xB9E22000 sr.sys
    0xB9E0C000 DRVMCDB.SYS
    0xBA118000 PxHelp20.sys
    0xB9DF5000 KSecDD.sys
    0xB9DDE000 WudfPf.sys
    0xB9D51000 Ntfs.sys
    0xB9D24000 NDIS.sys
    0xB9D0A000 Mup.sys
    0xBA158000 \SystemRoot\system32\DRIVERS\nic1394.sys
    0xBA238000 \SystemRoot\system32\DRIVERS\intelppm.sys
    0xB854A000 \SystemRoot\system32\DRIVERS\ati2mtag.sys
    0xB8536000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
    0xB84FD000 \SystemRoot\system32\DRIVERS\e1e5132.sys
    0xBA438000 \SystemRoot\system32\DRIVERS\usbuhci.sys
    0xB84D9000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
    0xBA440000 \SystemRoot\system32\DRIVERS\usbehci.sys
    0xB84B1000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
    0xB83BD000 \SystemRoot\system32\DRIVERS\atinavrr.sys
    0xB839A000 \SystemRoot\system32\DRIVERS\ks.sys
    0xB9800000 \SystemRoot\system32\DRIVERS\NCREMOTEPCI.SYS
    0xBA604000 \SystemRoot\system32\DRIVERS\USBD.SYS
    0xBA55C000 \SystemRoot\system32\DRIVERS\BdaSup.SYS
    0xBA248000 \SystemRoot\system32\DRIVERS\imapi.sys
    0xBA258000 \SystemRoot\system32\DRIVERS\cdrom.sys
    0xBA268000 \SystemRoot\system32\DRIVERS\redbook.sys
    0xBA730000 \SystemRoot\system32\DRIVERS\audstub.sys
    0xBA278000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
    0xBA564000 \SystemRoot\system32\DRIVERS\ndistapi.sys
    0xB8383000 \SystemRoot\system32\DRIVERS\ndiswan.sys
    0xBA288000 \SystemRoot\system32\DRIVERS\raspppoe.sys
    0xBA298000 \SystemRoot\system32\DRIVERS\raspptp.sys
    0xBA448000 \SystemRoot\system32\DRIVERS\TDI.SYS
    0xB8372000 \SystemRoot\system32\DRIVERS\psched.sys
    0xBA2A8000 \SystemRoot\system32\DRIVERS\msgpc.sys
    0xBA450000 \SystemRoot\system32\DRIVERS\ptilink.sys
    0xBA458000 \SystemRoot\system32\DRIVERS\raspti.sys
    0xB8342000 \SystemRoot\system32\DRIVERS\rdpdr.sys
    0xBA2B8000 \SystemRoot\system32\DRIVERS\termdd.sys
    0xBA460000 \SystemRoot\system32\DRIVERS\kbdclass.sys
    0xBA468000 \SystemRoot\system32\DRIVERS\mouclass.sys
    0xB8325000 \SystemRoot\system32\DRIVERS\mcdbus.sys
    0xBA606000 \SystemRoot\system32\DRIVERS\swenum.sys
    0xB82C7000 \SystemRoot\system32\DRIVERS\update.sys
    0xBA584000 \SystemRoot\system32\DRIVERS\mssmbios.sys
    0xB969E000 \SystemRoot\system32\DRIVERS\zumbus.sys
    0xB968E000 \SystemRoot\system32\DRIVERS\WDFLDR.SYS
    0xB8256000 \SystemRoot\System32\Drivers\wdf01000.sys
    0xB967E000 \SystemRoot\system32\DRIVERS\usbhub.sys
    0xB966E000 \SystemRoot\System32\Drivers\NDProxy.SYS
    0xA622B000 \SystemRoot\system32\DRIVERS\HSFHWAZL.sys
    0xA6139000 \SystemRoot\system32\DRIVERS\HSF_DPV.sys
    0xA6086000 \SystemRoot\system32\DRIVERS\HSF_CNXT.sys
    0xA85B8000 \SystemRoot\System32\Drivers\Modem.SYS
    0xA5F76000 \SystemRoot\system32\drivers\sthda.sys
    0xA5F52000 \SystemRoot\system32\drivers\portcls.sys
    0xA8380000 \SystemRoot\system32\drivers\drmk.sys
    0xBA5DA000 \SystemRoot\System32\Drivers\DLACDBHM.SYS
    0xBA5DC000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
    0xA76BF000 \SystemRoot\System32\Drivers\Null.SYS
    0xBA5DE000 \SystemRoot\System32\Drivers\Beep.SYS
    0xA8598000 \SystemRoot\System32\Drivers\DLARTL_N.SYS
    0xA8590000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
    0xA8588000 \SystemRoot\System32\drivers\vga.sys
    0xBA5E0000 \SystemRoot\System32\Drivers\mnmdd.SYS
    0xBA5E2000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
    0xA8580000 \SystemRoot\System32\Drivers\Msfs.SYS
    0xA8252000 \SystemRoot\System32\Drivers\Npfs.SYS
    0xAB0A2000 \SystemRoot\system32\DRIVERS\rasacd.sys
    0xA3E1F000 \SystemRoot\system32\DRIVERS\ipsec.sys
    0xA3DC6000 \SystemRoot\system32\DRIVERS\tcpip.sys
    0xA3D9E000 \SystemRoot\system32\DRIVERS\netbt.sys
    0xA3D78000 \SystemRoot\system32\DRIVERS\ipnat.sys
    0xA3D56000 \SystemRoot\System32\drivers\afd.sys
    0xA8360000 \SystemRoot\system32\DRIVERS\netbios.sys
    0xA8350000 \SystemRoot\System32\Drivers\SCDEmu.SYS
    0xA8340000 \SystemRoot\system32\DRIVERS\wanarp.sys
    0xA3CB3000 \SystemRoot\system32\DRIVERS\rdbss.sys
    0xA8330000 \SystemRoot\system32\DRIVERS\arp1394.sys
    0xA3C43000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
    0xA7EAE000 \SystemRoot\System32\Drivers\Fips.SYS
    0xBA5A4000 \SystemRoot\system32\DRIVERS\hidusb.sys
    0xA7E9E000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
    0xA824A000 \SystemRoot\system32\DRIVERS\usbccgp.sys
    0xA0FCC000 \SystemRoot\system32\DRIVERS\kbdhid.sys
    0xA0FC0000 \SystemRoot\system32\DRIVERS\mouhid.sys
    0x9FECA000 \SystemRoot\System32\Drivers\Cdfs.SYS
    0x9E59D000 \SystemRoot\System32\Drivers\ov519vid.sys
    0x9FEBA000 \SystemRoot\System32\Drivers\STREAM.SYS
    0xA894D000 \SystemRoot\System32\Drivers\ov519cmd.sys
    0x9FEAA000 \SystemRoot\system32\drivers\usbaudio.sys
    0x9E4E6000 \SystemRoot\System32\Drivers\dump_iastor.sys
    0xBF800000 \SystemRoot\System32\win32k.sys
    0xA0B0D000 \SystemRoot\System32\drivers\Dxapi.sys
    0xA85C0000 \SystemRoot\System32\watchdog.sys
    0xBF000000 \SystemRoot\System32\drivers\dxg.sys
    0xBA6A2000 \SystemRoot\System32\drivers\dxgthk.sys
    0xBF012000 \SystemRoot\System32\ati2dvag.dll
    0xBF065000 \SystemRoot\System32\ati2cqag.dll
    0xBF0FE000 \SystemRoot\System32\atikvmag.dll
    0xBF182000 \SystemRoot\System32\atiok3x2.dll
    0xBF1CD000 \SystemRoot\System32\ati3duag.dll
    0xBF572000 \SystemRoot\System32\ativvaxx.dll
    0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
    0xBA2F8000 \SystemRoot\System32\Drivers\DRVNDDM.SYS
    0xBA7E5000 \SystemRoot\System32\DLA\DLADResN.SYS
    0x9C2D0000 \SystemRoot\System32\DLA\DLAIFS_M.SYS
    0xBA554000 \SystemRoot\System32\DLA\DLAOPIOM.SYS
    0xBA658000 \SystemRoot\System32\DLA\DLAPoolM.SYS
    0xA8212000 \SystemRoot\System32\DLA\DLABOIOM.SYS
    0x9C2B8000 \SystemRoot\System32\DLA\DLAUDFAM.SYS
    0x9C2A2000 \SystemRoot\System32\DLA\DLAUDF_M.SYS
    0xA1898000 \SystemRoot\system32\DRIVERS\ndisuio.sys
    0x9C215000 \SystemRoot\system32\drivers\wdmaud.sys
    0xAB47B000 \SystemRoot\system32\drivers\sysaudio.sys
    0x9C051000 \SystemRoot\system32\DRIVERS\mrxdav.sys
    0x9BFE8000 \SystemRoot\System32\Drivers\HTTP.sys
    0x9C28E000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
    0x9BF41000 \SystemRoot\system32\DRIVERS\srv.sys
    0xA7A92000 \SystemRoot\system32\drivers\MSPQM.sys
    0x9B7F9000 \??\C:\DOCUME~1\EMOK!!!\LOCALS~1\Temp\kgnyypod.sys
    0x7C900000 \WINDOWS\system32\ntdll.dll

    Processes (total 31):
    0 System Idle Process
    4 System
    760 C:\WINDOWS\system32\smss.exe
    836 csrss.exe
    872 C:\WINDOWS\system32\winlogon.exe
    920 C:\WINDOWS\system32\services.exe
    932 C:\WINDOWS\system32\lsass.exe
    1136 C:\WINDOWS\system32\svchost.exe
    1208 svchost.exe
    1332 C:\WINDOWS\system32\svchost.exe
    1420 svchost.exe
    1508 svchost.exe
    1564 C:\WINDOWS\system32\svchost.exe
    1712 C:\WINDOWS\system32\spoolsv.exe
    552 C:\WINDOWS\explorer.exe
    780 svchost.exe
    136 C:\WINDOWS\ehome\ehrecvr.exe
    1008 C:\WINDOWS\ehome\ehSched.exe
    1572 svchost.exe
    1960 C:\Program Files\DivX\DivX Update\DivXUpdate.exe
    1968 C:\WINDOWS\system32\ctfmon.exe
    1984 C:\Program Files\MagicDisc\MagicDisc.exe
    2032 C:\Program Files\Mozilla Firefox\firefox.exe
    992 C:\WINDOWS\system32\svchost.exe
    636 C:\WINDOWS\system32\ZuneBusEnum.exe
    1464 mcrdsvc.exe
    1276 C:\WINDOWS\system32\wuauclt.exe
    2352 C:\WINDOWS\system32\dllhost.exe
    2460 C:\WINDOWS\system32\wscntfy.exe
    2728 alg.exe
    1312 C:\Documents and Settings\EMOK!!!\Desktop\MBRCheck.exe

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)

    PhysicalDrive0 Model Number: WDCWD5000AAJS-00A8B2, Rev: 01.03B01

    Size Device Name MBR Status
    --------------------------------------------
    465 GB \\.\PhysicalDrive0 Windows XP MBR code detected
    SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A


    Done!
     
    Kome,
    #9
  11. 2010/09/07
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Please download ComboFix from [color= "Red"]Here[/color] or [color= "#FF0000"]Here[/color] to your Desktop.

    [color= "Blue"]**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**[/color]
    1. Please, never rename Combofix unless instructed.
    2. Close any open browsers.
    3. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results ".
      • Click on [color= "Red"]this link[/color] to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.
      • Close any open browsers.
      • [color= "Red"]WARNING:[/color] Combofix will disconnect your machine from the Internet as soon as it starts
      • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
      • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    4. Double click on combofix.exe & follow the prompts.
    5. When finished, it will produce a report for you.
    6. Please post the "C:\ComboFix.txt"
    **Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

    Make sure, you re-enable your security programs, when you're done with Combofix.

    DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.