1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Active I deleted malware - now got no exe file association

Discussion in 'Malware and Virus Removal Archive' started by Random person, 2010/03/16.

  1. 2010/03/16
    Random person

    Random person Inactive Thread Starter

    Joined:
    2010/03/16
    Messages:
    3
    Likes Received:
    0
    [Active] I deleted malware - now got no exe file association

    Hello guys,

    I deleted some malware with SUPERantispyware

    ie. Trojan.dropper/win-nv
    Trojan.Agent/Gen-Fraudload
    and about 12 others

    this is my DDS print out, if this helps


    DDS (Ver_09-12-01.01) - NTFSx86
    Run by Shaun at 15:16:34.33 on Wed 17/03/2010
    Internet Explorer: 8.0.6001.18882 BrowserJavaVersion: 1.6.0_18
    Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6001.1.1252.64.1033.18.3069.1831 [GMT 13:00]

    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
    SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}

    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\STacSV.exe
    C:\Windows\system32\svchost.exe -k GPSvcGroup
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\Hpservice.exe
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\aestsrv.exe
    C:\Windows\system32\agrsmsvc.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\ProgramData\Philips\Common Database\ProntoDataService.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\Program Files\SMINST\BLService.exe
    C:\Program Files\CyberLink\Shared files\RichVideo.exe
    C:\Windows\system32\taskeng.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\PROGRA~1\SQUEEZ~2\server\Bin\MSWIN3~1\mysqld.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe
    C:\Program Files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Windows\system32\SearchIndexer.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\MPK\MPK.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\wuauclt.exe
    \\?\C:\Windows\system32\wbem\WMIADAP.EXE
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Users\Shaun\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.google.co.nz/
    uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_nz&c=91&bd=Pavilion&pf=cnnb
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_nz&c=91&bd=Pavilion&pf=cnnb
    mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_nz&c=91&bd=Pavilion&pf=cnnb
    mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\mpk\MPK.exe
    mWinlogon: Taskman=c:\recycler\s-1-5-21-4937515367-5873750382-966093979-4138\vhg32.exe
    uWinlogon: Shell=c:\recycler\s-1-5-21-0210833299-9696177177-461157718-2954\vhg32.exe,c:\recycler\s-1-5-21-2384956000-6072731983-060223337-6395\vhg32.exe,c:\recycler\s-1-5-21-1727168447-7092571670-332286740-7560\vhg32.exe,explorer.exe,c:\recycler\s-1-5-21-4937515367-5873750382-966093979-4138\vhg32.exe
    BHO: ContributeBHO Class: {074c1dc5-9320-4a9a-947d-c042949c6216} - c:\program files\adobe\/Adobe Contribute CS4/contributeieplugin.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
    BHO: AOL Toolbar BHO: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol\aol toolbar 5.0\aoltb.dll
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Catcher Class: {adecbed6-0366-4377-a739-e69dfba04663} - c:\program files\moyea\youtube converter\MoyeaCth.dll
    BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
    TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol\aol toolbar 5.0\aoltb.dll
    TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
    TB: Contribute Toolbar: {517bdde4-e3a7-4570-b21e-2b52b6139fc7} - c:\program files\adobe\/Adobe Contribute CS4/contributeieplugin.dll
    uRun: [Regedit32] c:\windows\system32\regedit.exe
    uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
    uRun: [12CFG214-K641-12SF-N85P] c:\recycler\s-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe
    mRun: [Regedit32] c:\windows\system32\regedit.exe
    mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
    StartupFolder: c:\users\shaun\appdata\roaming\micros~1\windows\startm~1\programs\startup\9635938.lnk - c:\users\shaun\appdata\local\temp\mvNat.exe
    StartupFolder: c:\users\shaun\appdata\roaming\microsoft\windows\start menu\programs\startup\ihaupd32.exe
    StartupFolder: c:\users\shaun\appdata\roaming\micros~1\windows\startm~1\programs\startup\limewi~1.lnk - c:\program files\limewire\LimeWire.exe
    StartupFolder: c:\users\shaun\appdata\roaming\microsoft\windows\start menu\programs\startup\zipdkg32.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\squeez~1.lnk - c:\program files\squeezebox\SqueezeTray.exe
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: &AOL Toolbar Search - c:\programdata\aol\ietoolbar\resources\en-nz\local\search.html
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
    DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
    DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} - hxxp://service.futuremark.com/virtualmark/tc/FMSI.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    TCP: {6B336BF1-2CA6-4AD9-8C0B-65BE0DA26BF2} = 202.27.158.40,202.27.156.72
    Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
    Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
    Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
    AppInit_DLLs: avgrsstx.dll
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
    SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
    mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe "

    ================= FIREFOX ===================

    FF - ProfilePath - c:\users\shaun\appdata\roaming\mozilla\firefox\profiles\804ejo61.default\
    FF - prefs.js: browser.search.selectedEngine - Ask
    FF - prefs.js: browser.startup.homepage - hxxp://www.ask.com/?o=13166&l=dis
    FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13165&gct=&gc=1&q=
    FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
    FF - plugin: c:\users\shaun\appdata\roaming\facebook\npfbplugin_1_0_1.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

    ============= SERVICES / DRIVERS ===============

    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-3-17 162640]
    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-2-24 335240]
    R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-2-24 27784]
    R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-2-24 108552]
    R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
    R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-2-17 66632]
    R2 {55662437-DA8C-40c0-AADA-2C816A897A49};{55662437-DA8C-40c0-AADA-2C816A897A49};c:\program files\hewlett-packard\media\dvd\000.fcl [2008-9-26 59376]
    R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_805f33de\AEstSrv.exe [2009-2-12 77824]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-3-17 19024]
    R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-3-17 51792]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-17 40384]
    R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-2-24 297752]
    R2 hpsrv;HP Service;c:\windows\system32\hpservice.exe [2008-3-19 19456]
    R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-7 34064]
    R2 ProntoDataService;Pronto Data Server;c:\programdata\philips\common database\ProntoDataService.exe [2009-7-24 20480]
    R2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\sminst\BLService.exe [2008-11-5 365952]
    R2 SqueezeMySQL;SqueezeMySQL;c:\progra~1\squeez~2\server\bin\mswin3~1\mysqld.exe --defaults-file=c:\progra~2\squeez~2\cache\my.cnf squeezemysql --> c:\progra~1\squeez~2\server\bin\mswin3~1\mysqld.exe --defaults-file=c:\progra~2\squeez~2\cache\my.cnf SqueezeMySQL [?]
    R2 TVCapSvc;TV Background Capture Service (TVBCS);c:\program files\hewlett-packard\media\tv\kernel\tv\TVCapSvc.exe [2009-4-22 296320]
    R2 TVSched;TV Task Scheduler (TVTS);c:\program files\hewlett-packard\media\tv\kernel\tv\TVSched.exe [2009-4-22 116104]
    R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-17 40384]
    R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-17 40384]
    R3 enecir;ENE CIR Receiver;c:\windows\system32\drivers\enecir.sys [2008-4-29 54784]
    R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\NETw5v32.sys [2009-2-12 3664384]
    R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2009-4-30 64032]
    S2 Norton Internet Security;Norton Internet Security; "c:\program files\norton internet security\engine\16.0.0.125\ccsvchst.exe" /s "norton internet security" /m "c:\program files\norton internet security\engine\16.0.0.125\dimaster.dll" /prefetch:1 --> c:\program files\norton internet security\engine\16.0.0.125\ccSvcHst.exe [?]
    S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\common files\adobe\adobe version cue cs4\server\bin\VersionCueCS4.exe [2008-8-15 284016]
    S3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2008-11-4 193840]
    S3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\solidworks corp\solidworks\swscheduler\DTSCoordinatorService.exe [2009-10-15 87336]
    S3 FTD2XX;FTD2XX.SYS FT8U2XX device driver;c:\windows\system32\drivers\FTD2XX.sys [2008-9-2 24197]
    S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2008-7-21 100184]
    S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2010-2-17 12872]
    S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\microsoft visual studio 8\common7\ide\remote debugger\x86\msvsmon.exe [2005-9-23 2799808]

    =============== Created Last 30 ================

    2010-03-17 00:23:31 16 ----a-w- c:\users\shaun\appdata\roaming\zcbmvn.dat
    2010-03-17 00:23:25 4 ----a-w- c:\users\shaun\appdata\roaming\avdrn.dat
    2010-03-17 00:22:30 0 d-----w- c:\programdata\SUPERAntiSpyware.com
    2010-03-17 00:20:54 0 d-----w- c:\users\shaun\appdata\roaming\SUPERAntiSpyware.com
    2010-03-17 00:20:54 0 d-----w- c:\program files\SUPERAntiSpyware
    2010-03-17 00:20:09 51792 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
    2010-03-17 00:18:44 0 d-----w- c:\programdata\Alwil Software
    2010-03-16 05:01:42 1 ----a-w- c:\users\shaun\oashdihasidhasuidhiasdhiashdiuasdhasd
    2010-03-16 04:07:15 159744 ----a-w- c:\users\shaun\appdata\roaming\rwrnw.exe
    2010-03-16 02:48:45 14405 ----a-w- c:\users\shaun\MasterCAM.X4.-.with.Working.Crack!.torrent
    2010-03-14 00:01:54 135168 ----a-w- c:\users\shaun\loft.sldprt
    2010-03-13 23:44:56 105984 ----a-w- c:\users\shaun\rack.SLDPRT
    2010-03-13 23:27:05 175104 ----a-w- c:\users\shaun\Tutor.SLDASM
    2010-03-13 23:19:20 201216 ----a-w- c:\users\shaun\Tutor2.SLDPRT
    2010-03-13 23:12:33 0 d-----w- C:\temp
    2010-03-13 04:15:41 256512 ----a-w- c:\users\shaun\Tutor1.SLDPRT
    2010-03-12 14:00:26 0 d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
    2010-03-11 22:07:20 0 d-----w- c:\programdata\Sun
    2010-03-11 03:55:41 0 d-----w- c:\users\shaun\appdata\roaming\SolidWorks 2010
    2010-03-11 03:48:16 0 d-----w- c:\programdata\DassaultSystemes
    2010-03-11 03:48:15 0 d-----w- c:\users\shaun\appdata\roaming\DassaultSystemes
    2010-03-11 03:47:23 0 d-----w- c:\users\shaun\appdata\roaming\Luxology
    2010-03-11 03:23:40 0 ----a-w- c:\windows\eDrawingOfficeAutomator.INI
    2010-03-11 03:21:33 23 ---ha-w- c:\windows\yacht.xws
    2010-03-11 02:58:24 0 d-----w- c:\program files\common files\SolidWorks Shared
    2010-03-11 02:58:15 0 d-----w- c:\programdata\SolidWorks
    2010-03-11 02:58:15 0 d-----w- c:\program files\SolidWorks Corp
    2010-03-11 02:54:27 0 d-----w- C:\SolidWorks Data
    2010-03-11 02:54:00 0 d-----w- c:\program files\common files\SolidWorks Installation Manager
    2010-03-11 02:52:38 0 d-----w- c:\windows\SolidWorks
    2010-03-11 02:52:31 0 d-----w- c:\users\shaun\appdata\roaming\SolidWorks
    2010-03-10 14:02:24 24064 ----a-w- c:\windows\system32\nshhttp.dll
    2010-03-10 14:02:20 411136 ----a-w- c:\windows\system32\drivers\http.sys
    2010-03-10 14:02:20 31232 ----a-w- c:\windows\system32\httpapi.dll
    2010-03-09 09:57:00 0 d-----w- c:\program files\MSECache
    2010-02-24 20:48:26 2048 ----a-w- c:\windows\system32\tzres.dll
    2010-02-24 20:47:38 523776 ----a-w- c:\windows\system32\RMActivate_isv.exe
    2010-02-24 20:47:37 511488 ----a-w- c:\windows\system32\RMActivate.exe
    2010-02-24 20:47:35 472576 ----a-w- c:\windows\system32\secproc_isv.dll
    2010-02-24 20:47:35 472064 ----a-w- c:\windows\system32\secproc.dll
    2010-02-24 20:47:35 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
    2010-02-24 20:47:35 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
    2010-02-24 20:47:35 329216 ----a-w- c:\windows\system32\msdrm.dll
    2010-02-24 20:47:35 151040 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
    2010-02-24 20:47:35 151040 ----a-w- c:\windows\system32\secproc_ssp.dll
    2010-02-20 23:50:13 9745 ----a-w- c:\users\shaun\config.bin

    ==================== Find3M ====================

    2010-03-17 02:11:33 557272 ----a-w- c:\programdata\nvModes.dat
    2010-03-11 03:07:38 51200 ----a-w- c:\windows\inf\infpub.dat
    2010-03-11 03:07:38 143360 ----a-w- c:\windows\inf\infstrng.dat
    2010-03-11 03:07:03 86016 ----a-w- c:\windows\inf\infstor.dat
    2010-02-23 20:16:06 181632 ------w- c:\windows\system32\MpSigStub.exe
    2010-01-21 23:32:42 149884 ----a-w- c:\windows\AVR300 Programmer Uninstaller.exe
    2010-01-02 06:38:20 916480 ----a-w- c:\windows\system32\wininet.dll
    2010-01-02 06:32:33 71680 ----a-w- c:\windows\system32\iesetup.dll
    2010-01-02 06:32:33 109056 ----a-w- c:\windows\system32\iesysprep.dll
    2010-01-02 04:57:00 133632 ----a-w- c:\windows\system32\ieUnatt.exe
    2009-12-28 12:35:50 11776 ----a-w- c:\windows\system32\tsbyuv.dll
    2009-12-28 12:35:00 1314816 ----a-w- c:\windows\system32\quartz.dll
    2009-12-28 12:32:34 22528 ----a-w- c:\windows\system32\msyuv.dll
    2009-12-28 12:32:32 31744 ----a-w- c:\windows\system32\msvidc32.dll
    2009-12-28 12:32:32 123904 ----a-w- c:\windows\system32\msvfw32.dll
    2009-12-28 12:32:25 13312 ----a-w- c:\windows\system32\msrle32.dll
    2009-12-28 12:31:22 82944 ----a-w- c:\windows\system32\mciavi32.dll
    2009-12-28 12:31:01 50176 ----a-w- c:\windows\system32\iyuv_32.dll
    2009-12-28 12:28:43 91136 ----a-w- c:\windows\system32\avifil32.dll
    2009-12-28 12:28:43 65024 ----a-w- c:\windows\system32\avicap32.dll
    2009-12-17 04:14:00 411368 ----a-w- c:\windows\system32\deploytk.dll
    2008-11-04 10:01:48 665600 ----a-w- c:\windows\inf\drvindex.dat
    2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
    2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
    2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
    2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
    2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
    2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
    2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
    2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
    2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
    2009-10-16 03:04:27 245760 --sha-w- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
    2008-11-04 10:01:47 8192 --sha-w- c:\windows\users\default\NTUSER.DAT

    ============= FINISH: 15:17:50.42 ===============
     
  2. 2010/03/16
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    2nd part of DDS log is missing.
     

  3. to hide this advert.

  4. 2010/03/17
    Random person

    Random person Inactive Thread Starter

    Joined:
    2010/03/16
    Messages:
    3
    Likes Received:
    0
    Did you want this piece 2??

    Sorry very new to forums

    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-12-01.01)

    Microsoft® Windows Vista™ Home Premium
    Boot Device: \Device\HarddiskVolume1
    Install Date: 12/02/2009 3:52:55 p.m.
    System Uptime: 17/03/2010 3:10:19 p.m. (0 hours ago)

    Motherboard: Compal | | 30F4
    Processor: Intel(R) Core(TM)2 Duo CPU P8700 @ 2.53GHz | CPU | 1600/1066mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 454 GiB total, 64.023 GiB free.
    D: is FIXED (NTFS) - 12 GiB total, 1.904 GiB free.
    E: is CDROM ()
    F: is Removable

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================


    ==== Installed Programs ======================

    2007 Microsoft Office system
    3DMark Vantage
    7-Zip 4.65
    Acrobat.com
    Activation Assistant for the 2007 Microsoft Office suites
    Adobe Acrobat 9 Pro - English, Français, Deutsch
    Adobe After Effects CS4
    Adobe After Effects CS4 Presets
    Adobe After Effects CS4 Third Party Content
    Adobe AIR
    Adobe Anchor Service CS4
    Adobe Asset Services CS4
    Adobe Bridge CS4
    Adobe CMaps CS4
    Adobe Color - Photoshop Specific CS4
    Adobe Color EU Extra Settings CS4
    Adobe Color JA Extra Settings CS4
    Adobe Color NA Recommended Settings CS4
    Adobe Color Video Profiles AE CS4
    Adobe Color Video Profiles CS CS4
    Adobe Contribute CS4
    Adobe Creative Suite 4 Master Collection
    Adobe CS4 American English Speech Analysis Models
    Adobe CSI CS4
    Adobe Default Language CS4
    Adobe Device Central CS4
    Adobe Dreamweaver CS4
    Adobe Drive CS4
    Adobe Dynamiclink Support
    Adobe Encore CS4
    Adobe Encore CS4 Codecs
    Adobe ExtendScript Toolkit CS4
    Adobe Extension Manager CS4
    Adobe Fireworks CS4
    Adobe Flash CS4
    Adobe Flash CS4 Extension - Flash Lite STI en
    Adobe Flash CS4 STI-en
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Fonts All
    Adobe Illustrator CS4
    Adobe InDesign CS4
    Adobe InDesign CS4 Application Feature Set Files (Roman)
    Adobe InDesign CS4 Common Base Files
    Adobe InDesign CS4 Icon Handler
    Adobe Linguistics CS4
    Adobe Media Encoder CS4
    Adobe Media Encoder CS4 Additional Exporter
    Adobe Media Encoder CS4 Dolby
    Adobe Media Encoder CS4 Exporter
    Adobe Media Encoder CS4 Importer
    Adobe Media Player
    Adobe MotionPicture Color Files CS4
    Adobe OnLocation CS4
    Adobe Output Module
    Adobe PDF Library Files CS4
    Adobe Photoshop CS4
    Adobe Photoshop CS4 Support
    Adobe Premiere Pro CS4
    Adobe Premiere Pro CS4 Functional Content
    Adobe Premiere Pro CS4 Third Party Content
    Adobe Reader 9
    Adobe Search for Help
    Adobe Service Manager Extension
    Adobe Setup
    Adobe SGM CS4
    Adobe Shockwave Player
    Adobe SING CS4
    Adobe Soundbooth CS4
    Adobe Soundbooth CS4 Codecs
    Adobe Type Support CS4
    Adobe Update Manager CS4
    Adobe Version Cue CS4 Server
    Adobe WinSoft Linguistics Plugin
    Adobe XMP Panels CS4
    AdobeColorCommonSetCMYK
    AdobeColorCommonSetRGB
    Agere Systems HDA Modem
    AOL Toolbar 5.0
    Apple Application Support
    Apple Software Update
    µTorrent
    avast! Free Antivirus
    AVG 8.5
    AVR300 Programmer
    Axium Software Suite
    Belarc Advisor 7.2
    Business Contact Manager for Outlook 2007 SP2
    Canon Inkjet Printer Driver Add-On Module
    CDG Autoname
    CDRWIN
    CloneDVD 4.5.0.0
    Combined Community Codec Pack 2009-09-09
    Compel Adaptec WinASPI
    Connect
    CyberLink DVD Suite
    Driver Genius Professional Edition
    DVD Decrypter (Remove Only)
    DVD Shrink 3.2
    DVDFab 6.0.7.0 (18/09/2009)
    DWGeditor
    ESU for Microsoft Vista
    Facebook Plug-In
    Free M4a to MP3 Converter 6.0
    Free YouTube to Mp3 Converter version 3.1
    gBurner
    GDR 4053 for SQL Server Database Services 2005 ENU (KB970892)
    Hewlett-Packard Active Check for Health Check
    Hewlett-Packard Asset Agent for Health Check
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    HP Active Support Library
    HP Customer Experience Enhancements
    HP Doc Viewer
    HP Help and Support
    HP MediaSmart DVD
    HP MediaSmart Music/Photo/Video
    HP MediaSmart SmartMenu
    HP MediaSmart TV
    HP MediaSmart Webcam
    HP MULTIPLE MODEM INSTALLER for VISTA
    HP Quick Launch Buttons 6.40 H2
    HP Total Care Advisor
    HP Update
    HP User Guides 0129
    HP Wireless Assistant
    HPNetworkAssistant
    HPTCSSetup
    IDT Audio
    InFusion Design Center
    InFusion Driver Tools
    Java Auto Updater
    Java(TM) 6 Update 18
    Java(TM) 6 Update 7
    JMicron JMB38X Flash Media Controller
    Karaoke Song List Creator Professional KJ Edition 2004
    KJ Pro
    kuler
    LabelPrint
    LightScribe System Software 1.14.17.1
    LimeWire PRO 5.3.6
    Magic ISO Maker v5.5 (build 0276)
    MCE Controller 1.1
    MediaMonkey 3.0
    Microsoft .NET Framework 3.5 SP1
    Microsoft Application Error Reporting
    Microsoft Choice Guard
    Microsoft Office 2003 Web Components
    Microsoft Office 2007 Primary Interop Assemblies
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Access MUI (English) 2007
    Microsoft Office Access Setup Metadata MUI (English) 2007
    Microsoft Office Enterprise 2007
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Groove MUI (English) 2007
    Microsoft Office Groove Setup Metadata MUI (English) 2007
    Microsoft Office InfoPath MUI (English) 2007
    Microsoft Office OneNote MUI (English) 2007
    Microsoft Office Outlook MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office Professional Hybrid 2007
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Publisher MUI (English) 2007
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Small Business Connectivity Components
    Microsoft Office Word MUI (English) 2007
    Microsoft Silverlight
    Microsoft SQL Server 2005
    Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
    Microsoft SQL Server Native Client
    Microsoft SQL Server Setup Support Files (English)
    Microsoft SQL Server VSS Writer
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual Studio 2005 Tools for Applications - ENU
    mIRC
    Moyea YouTube Converter Version: 1.4.1.149
    Mozilla Firefox (3.0.14)
    MP3+G Toolz
    MSVCRT
    MSXML 4.0
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    muvee Reveal
    My HP Games
    Nokia Connectivity Cable Driver
    Nokia Lifeblog 2.1
    Nokia MTP driver
    Nokia PC Connectivity Solution
    Nokia PC Suite
    Nokia Software Launcher
    Norton Internet Security
    NVIDIA Drivers
    NVIDIA PhysX
    PCDJ VJ
    PDF Settings CS4
    Photoshop Camera Raw
    PhotoView 360
    Picasa 3
    Pixel Bender Toolkit
    Power CD+G Burner
    Power2Go
    PowerDirector
    PowerISO
    ProntoEdit Professional
    ProntoEdit Professional 2
    ProtectSmart Hard Drive Protection
    QuickTime
    Realtek 8169 8168 8101E 8102E Ethernet Driver
    RightClick
    Sax & Dottys Karaoke Utilities
    Sax & Dottys Show Hoster
    Security Update for 2007 Microsoft Office System (KB969559)
    Security Update for 2007 Microsoft Office System (KB978380)
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft Office Excel 2007 (KB978382)
    Security Update for Microsoft Office Outlook 2007 (KB972363)
    Security Update for Microsoft Office PowerPoint 2007 (KB957789)
    Security Update for Microsoft Office Publisher 2007 (KB969693)
    Security Update for Microsoft Office system 2007 (972581)
    Security Update for Microsoft Office system 2007 (KB969613)
    Security Update for Microsoft Office system 2007 (KB974234)
    Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
    SoftSqueeze 3.7
    SoftStylus
    SolidWorks 2010 SP0
    SolidWorks eDrawings 2010
    SolidWorks Explorer 2010 SP0
    Spelling Dictionaries Support For Adobe Reader 9
    SPORE Creature Creator Trial Edition
    Squeezebox Server 7.4.1
    Suite Shared Configuration CS4
    SUPERAntiSpyware Free Edition
    Synaptics Pointing Device Driver
    Tag&Rename 3.5.3
    Uninstall 1.0.0.1
    Update for 2007 Microsoft Office System (KB967642)
    Update for 2007 Microsoft Office System (KB977724)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft Office 2007 Help for Common Features (KB963673)
    Update for Microsoft Office Access 2007 Help (KB963663)
    Update for Microsoft Office Excel 2007 Help (KB963678)
    Update for Microsoft Office InfoPath 2007 (KB976416)
    Update for Microsoft Office Infopath 2007 Help (KB963662)
    Update for Microsoft Office OneNote 2007 Help (KB963670)
    Update for Microsoft Office Outlook 2007 Help (KB963677)
    Update for Microsoft Office Powerpoint 2007 Help (KB963669)
    Update for Microsoft Office Publisher 2007 Help (KB963667)
    Update for Microsoft Office Script Editor Help (KB963671)
    Update for Microsoft Office Word 2007 (KB974561)
    Update for Microsoft Office Word 2007 Help (KB963665)
    Update for Outlook 2007 Junk Email Filter (kb979895)
    Vantage / Axium Software Suite
    Vantage LCD320C5 USB Drivers
    VC User CRT71 RTL X86 ---
    VC User MFC71 RTL X86 ---
    VC User STL71 RTL X86 ---
    VLC media player 0.9.8a
    Winamp (remove only)
    Windows Driver Package - ENE (enecir) HIDClass (04/29/2008 2.5.0.0)
    Windows Live Call
    Windows Live Communications Platform
    Windows Live Essentials
    Windows Live Messenger
    Windows Live Sign-in Assistant
    Windows Live Upload Tool
    WinPcap 4.0.2
    WinRAR archiver
    Wireshark 1.0.7

    ==== End Of File ===========================
     
  5. 2010/03/17
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Yes, thank you :)

    Download and run exeHelper.

    * Please download exeHelper from Raktor to your desktop.
    * Double-click on exeHelper.com to run the fix.
    * A black window should pop up, press any key to close once the fix is completed.
    * A log file named log.txt will be created in the directory where you ran exeHelper.com
    * Attach the log.txt file to your next message.[/LIST]

    Note: If the window shows a message that says "Error deleting file ", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.