1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Windows Security XP 2012 Virus

Discussion in 'Malware and Virus Removal Archive' started by ZanKhelledros, 2011/06/28.

Thread Status:
Not open for further replies.
  1. 2011/06/28
    ZanKhelledros

    ZanKhelledros Inactive Thread Starter

    Joined:
    2011/06/27
    Messages:
    17
    Likes Received:
    0
    [Inactive] Windows Security XP 2012 Virus

    Hello. I just recently got a virus on my computer, and I can't do anything to try to fix it because I can't open any programs. Every time I do a window for Windows Security XP 2012 pops up saying that the program that I'm trying to open is infected with a virus, and gives me two options to update the Windows Security, or continue without protection. I have never installed Windows Security XP 2012, so this might be the source of the problems. Since I can't open any programs in normal boot OR in safe mode, I could only run the DDS. Here's the logs:

    .
    DDS (Ver_2011-06-23.01) - NTFSx86 MINIMAL
    Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_23
    Run by Owner at 15:18:44 on 2011-06-28
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.332 [GMT -4:00]
    .
    AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    FW: Norton AntiVirus *Enabled*
    .
    ============== Running Processes ===============
    .
    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\system32\svchost.exe -k netsvcs
    C:\Program Files\Softex\OmniPass\OPXPApp.exe
    C:\WINDOWS\Explorer.EXE
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\ycj.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.google.com/
    uDefault_Page_URL =
    uSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
    mStart Page = hxxp://www.msn.com
    mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
    uInternet Connection Wizard,ShellNext = hxxp://us9.hpwis.com/
    uInternet Settings,ProxyOverride = 127.0.0.1;localhost;*.local
    uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
    uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\progra~1\yahoo!\common\yiesrvc.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    BHO: SidebarAutoLaunch Class: {f2aa9440-6328-4933-b7c9-a6ccdf9cbf6d} - c:\program files\yahoo!\browser\YSidebarIEBHO.dll
    TB: HP View: {b2847e28-5d7d-4deb-8b67-05d28bcf79f5} - c:\program files\hewlett-packard\digital imaging\bin\hpdtlk02.dll
    TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
    EB: hp view: {8f4902b6-6c04-4ade-8052-aa58578a21bd} - c:\windows\system32\Shdocvw.dll
    EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
    uRun: [BackupNotify] c:\program files\hewlett-packard\digital imaging\bin\backupnotify.exe
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [1664051546] c:\documents and settings\networkservice\local settings\application data\ycj.exe
    mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
    mRun: [RegSvr32]
    mRun: [AlcxMonitor] ALCXMNTR.EXE
    mRun: [IPInSightMonitor 02] "c:\program files\visual networks\visual ip insight\sbc\IPMon32.exe "
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll "
    mRun: [Monitor] "c:\program files\leapfrog\leapfrog connect\Monitor.exe "
    mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe
    mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe "
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe "
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRunServices: [Service] real.exe
    dRun: [ALUAlert] c:\program files\symantec\liveupdate\ALUNotify.exe
    dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    dRun: [1664051546] c:\documents and settings\networkservice\local settings\application data\ycj.exe
    StartupFolder: c:\docume~1\owner\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 2.0\program\quickstart.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\pgptray.lnk - c:\program files\pgp corporation\pgp for windows xp\PGPtray.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\sbcsel~1.lnk - c:\program files\sbc self support tool\bin\matcli.exe
    IE: &Yahoo! Search - file:///c:\program files\yahoo!\Common/ycsrch.htm
    IE: Yahoo! &Dictionary - file:///c:\program files\yahoo!\Common/ycdict.htm
    IE: Yahoo! &Maps - file:///c:\program files\yahoo!\Common/ycmap.htm
    IE: Yahoo! &SMS - file:///c:\program files\yahoo!\Common/ycsms.htm
    IE: {10F055B8-F443-4adf-948A-EC551E9DBCE4} - c:\documents and settings\owner\start menu\programs\ultimatebet\UltimateBet.lnk
    IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\progra~1\aim\aim.exe
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\progra~1\yahoo!\common\yiesrvc.dll
    IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
    DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
    DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
    DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
    DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
    DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photo.walgreens.com/WalgreensActivia.cab
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1135455836765
    DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
    DPF: {A30FBBDC-FA29-4606-8565-14AADCCA6708} - hxxps://photos.riteaid.com/control/RiteAidOneHourPhotoOnline.cab
    DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/installs/ydropper/ydropper1_4us.cab
    DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}
    DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    TCP: DhcpNameServer = 192.168.1.1
    TCP: Interfaces\{4000BCD1-33E5-42BC-8BF0-9F783C10E2CB} : DhcpNameServer = 192.168.1.1
    TCP: Interfaces\{BEC2E07B-95CB-427A-91FC-A75F3FD3E784} : DhcpNameServer = 172.16.0.1
    Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
    Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
    Notify: igfxcui - igfxsrvc.dll
    Notify: OPXPGina - c:\program files\softex\omnipass\opxpgina.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - c:\documents and settings\owner\application data\mozilla\firefox\profiles\vgens2qp.default\
    FF - prefs.js: browser.search.selectedEngine - Yahoo
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - prefs.js: network.proxy.type - 2
    FF - plugin: c:\documents and settings\owner\local settings\application data\unity\webplayer\loader\npUnity3D32.dll
    FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\real\realone player\netscape6\nppl3260.dll
    FF - plugin: c:\program files\real\realone player\netscape6\nprjplug.dll
    FF - plugin: c:\program files\real\realone player\netscape6\nprpjplug.dll
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
    FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
    FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
    FF - Ext: Freeze.com NetAssistant: {1266764D-FC4F-4FA7-B63B-884D53B1680F} - c:\documents and settings\owner\application data\NetAssistant
    .
    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
    ============= SERVICES / DRIVERS ===============
    .
    S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-6-25 441176]
    S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2009-4-22 307928]
    S1 Pernmdd;Pernmdd;\??\c:\windows\system32\drivers\dmitcpip.sys --> c:\windows\system32\drivers\dmitcpip.sys [?]
    S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-4-22 19544]
    S2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-6-14 42184]
    S2 mrtRate;mrtRate; [x]
    S2 PGPsdkServ;PGPsdkService;c:\windows\system32\PGPsdkServ.exe [2003-11-4 65536]
    S2 QGKDNWIH;QGKDNWIH;\??\c:\windows\system32\qgkdnwih.tyw --> c:\windows\system32\qgkdnwih.tyw [?]
    S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-1-10 24652]
    S3 kbeepm;kbeepm;c:\docume~1\owner\locals~1\temp\kbeepm.sys [2003-11-8 31744]
    S3 USBNET;Instant Wireless USB Network Adapter ver.2.6 Driver;c:\windows\system32\drivers\vnetusbl.sys [2007-10-7 107648]
    .
    =============== Created Last 30 ================
    .
    2011-06-28 18:49:26 -------- d-----w- C:\## aswSnx private storage
    2011-06-26 00:36:38 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2011-06-16 22:18:26 105472 -c----w- c:\windows\system32\dllcache\mup.sys
    2011-06-16 22:18:22 852480 -c----w- c:\windows\system32\dllcache\vgx.dll
    2011-06-09 12:22:53 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    .
    ==================== Find3M ====================
    .
    2011-05-10 12:10:59 40112 ----a-w- c:\windows\avastSS.scr
    2011-05-02 15:31:52 692736 ----a-w- c:\windows\system32\inetcomm.dll
    2011-04-29 16:19:43 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
    2011-04-25 14:47:19 81920 ------w- c:\windows\system32\ieencode.dll
    2011-04-25 14:47:19 667136 ----a-w- c:\windows\system32\wininet.dll
    2011-04-25 14:47:19 61952 ----a-w- c:\windows\system32\tdc.ocx
    2011-04-25 12:56:44 369664 ------w- c:\windows\system32\html.iec
    2011-04-21 13:37:43 105472 ----a-w- c:\windows\system32\drivers\mup.sys
    2011-03-02 19:26:19 8593992 ----a-w- c:\program files\Firefox Setup 3.6.14.exe
    2011-02-03 03:15:52 36069 ----a-w- c:\program files\uninstall.exe
    2011-01-19 08:27:48 76464 ----a-w- c:\program files\fraps64.dat
    2011-01-19 08:27:46 2350256 ----a-w- c:\program files\fraps.exe
    2011-01-19 08:26:10 159744 ----a-w- c:\program files\frapslcd.dll
    2010-12-02 08:08:12 253104 ----a-w- c:\program files\fraps32.dll
    2010-12-02 08:08:12 197808 ----a-w- c:\program files\fraps64.dll
    2010-11-23 00:32:37 5840851 ----a-w- c:\program files\3dfiction_v01.scr
    2010-11-23 00:32:37 206754 ----a-w- c:\program files\uninstall 3dfiction_v01.exe
    .
    ============= FINISH: 15:20:28.76 ===============

    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_2011-06-23.01)
    .
    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume2
    Install Date: 10/29/2003 3:01:39 PM
    System Uptime: 6/28/2011 3:13:41 PM (0 hours ago)
    .
    Motherboard: ASUSTeK Computer INC. | | A7N8X-LA
    Processor: AMD Athlon(tm) XP 2600+ | Socket A | 2079/166mhz
    .
    ==== Disk Partitions =========================
    .
    A: is Removable
    C: is FIXED (NTFS) - 105 GiB total, 54.956 GiB free.
    D: is FIXED (FAT32) - 7 GiB total, 2.419 GiB free.
    E: is CDROM ()
    F: is CDROM ()
    G: is Removable
    H: is Removable
    I: is Removable
    J: is Removable
    K: is FIXED (NTFS) - 75 GiB total, 10.071 GiB free.
    L: is Removable
    .
    ==== Disabled Device Manager Items =============
    .
    ==== System Restore Points ===================
    .
    RP1053: 4/8/2011 5:40:19 PM - System Checkpoint
    RP1054: 4/10/2011 11:07:50 AM - System Checkpoint
    RP1055: 4/11/2011 1:38:42 PM - System Checkpoint
    RP1056: 4/12/2011 3:29:40 PM - System Checkpoint
    RP1057: 4/13/2011 7:15:29 PM - System Checkpoint
    RP1058: 4/13/2011 11:00:23 PM - Software Distribution Service 3.0
    RP1059: 4/15/2011 11:22:04 AM - System Checkpoint
    RP1060: 4/16/2011 1:47:48 PM - System Checkpoint
    RP1061: 4/17/2011 2:57:56 PM - System Checkpoint
    RP1062: 4/18/2011 4:48:46 PM - System Checkpoint
    RP1063: 4/19/2011 7:40:47 PM - System Checkpoint
    RP1064: 4/21/2011 8:06:10 AM - System Checkpoint
    RP1065: 4/22/2011 11:17:46 AM - System Checkpoint
    RP1066: 4/23/2011 11:36:25 AM - System Checkpoint
    RP1067: 4/24/2011 1:41:13 PM - System Checkpoint
    RP1068: 4/25/2011 3:08:21 PM - System Checkpoint
    RP1069: 4/26/2011 3:51:55 PM - System Checkpoint
    RP1070: 4/27/2011 7:31:03 PM - System Checkpoint
    RP1071: 4/27/2011 11:00:26 PM - Software Distribution Service 3.0
    RP1072: 4/28/2011 11:20:02 PM - System Checkpoint
    RP1073: 4/29/2011 11:29:46 PM - System Checkpoint
    RP1074: 5/1/2011 8:26:23 AM - System Checkpoint
    RP1075: 5/2/2011 12:39:49 PM - System Checkpoint
    RP1076: 5/3/2011 3:16:46 PM - System Checkpoint
    RP1077: 5/4/2011 3:25:15 PM - System Checkpoint
    RP1078: 5/5/2011 5:00:35 PM - System Checkpoint
    RP1079: 5/6/2011 5:01:46 PM - System Checkpoint
    RP1080: 5/7/2011 8:37:04 PM - System Checkpoint
    RP1081: 5/8/2011 9:49:47 PM - System Checkpoint
    RP1082: 5/9/2011 10:31:38 PM - System Checkpoint
    RP1083: 5/11/2011 12:01:45 AM - System Checkpoint
    RP1084: 5/11/2011 11:01:02 PM - Software Distribution Service 3.0
    RP1085: 5/12/2011 11:28:08 PM - System Checkpoint
    RP1086: 5/14/2011 8:20:08 AM - System Checkpoint
    RP1087: 5/15/2011 10:22:45 AM - System Checkpoint
    RP1088: 5/16/2011 12:39:06 PM - System Checkpoint
    RP1089: 5/17/2011 4:27:02 PM - System Checkpoint
    RP1090: 5/18/2011 10:51:00 PM - System Checkpoint
    RP1091: 5/19/2011 10:55:43 PM - System Checkpoint
    RP1092: 5/21/2011 12:09:35 AM - System Checkpoint
    RP1093: 5/22/2011 11:13:34 AM - System Checkpoint
    RP1094: 5/23/2011 11:44:07 AM - System Checkpoint
    RP1095: 5/24/2011 4:42:13 PM - System Checkpoint
    RP1096: 5/25/2011 5:29:03 PM - System Checkpoint
    RP1097: 5/26/2011 9:31:02 PM - System Checkpoint
    RP1098: 5/27/2011 11:46:15 PM - System Checkpoint
    RP1099: 5/29/2011 9:48:28 AM - System Checkpoint
    RP1100: 5/30/2011 10:43:45 AM - System Checkpoint
    RP1101: 5/31/2011 11:08:56 AM - System Checkpoint
    RP1102: 6/1/2011 12:09:00 PM - System Checkpoint
    RP1103: 6/2/2011 3:31:12 PM - System Checkpoint
    RP1104: 6/3/2011 5:33:01 PM - System Checkpoint
    RP1105: 6/4/2011 5:34:08 PM - System Checkpoint
    RP1106: 6/5/2011 5:56:32 PM - System Checkpoint
    RP1107: 6/6/2011 8:44:41 PM - System Checkpoint
    RP1108: 6/8/2011 11:43:52 AM - System Checkpoint
    RP1109: 6/9/2011 2:17:51 PM - System Checkpoint
    RP1110: 6/10/2011 5:28:14 PM - System Checkpoint
    RP1111: 6/11/2011 6:21:20 PM - System Checkpoint
    RP1112: 6/12/2011 9:23:15 PM - System Checkpoint
    RP1113: 6/13/2011 10:25:51 PM - System Checkpoint
    RP1114: 6/15/2011 12:34:40 AM - System Checkpoint
    RP1115: 6/16/2011 9:58:59 AM - System Checkpoint
    RP1116: 6/16/2011 11:00:23 PM - Software Distribution Service 3.0
    RP1117: 6/17/2011 11:43:43 PM - System Checkpoint
    RP1118: 6/19/2011 11:11:55 AM - System Checkpoint
    RP1119: 6/20/2011 2:45:11 PM - System Checkpoint
    RP1120: 6/21/2011 5:57:55 PM - System Checkpoint
    RP1121: 6/22/2011 10:25:31 PM - System Checkpoint
    RP1122: 6/24/2011 9:54:28 AM - System Checkpoint
    RP1123: 6/25/2011 6:47:11 PM - System Checkpoint
    .
    ==== Installed Programs ======================
    .
    .
    Adobe Acrobat 4.0
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Photoshop 5.0 Limited Edition
    Adobe Reader 7.1.0
    AOL Instant Messenger
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    ArcSoft ShowBiz 2
    AT&T Yahoo! Applications
    Audacity 1.2.6
    avast! Free Antivirus
    Blackhawk Striker from Hewlett-Packard Desktops (remove only)
    Blasterball 2 from Hewlett-Packard Desktops (remove only)
    Bonjour
    Bounce from Hewlett-Packard Desktops (remove only)
    BrettspielWelt
    BroadJump Client Foundation
    BufferChm
    CA eTrust PestPatrol Anti-Spyware
    Cannonballs from Hewlett-Packard Desktops (remove only)
    CDex extraction audio
    Color LaserJet 2600n
    Compatibility Pack for the 2007 Office system
    Coupon Printer for Windows
    CreativeProjects
    Critical Update for Windows Media Player 11 (KB959772)
    CustomerResearchQFolder
    D&D35E Screen Saver
    Destinations
    DeviceFunctionQFolder
    DeviceManagementQFolder
    Diablo
    Diablo II
    Easy Internet Sign-up
    ElectriCalm 3D Screensaver (remove only)
    Enhanced Multimedia Keyboard Solution
    eSupportQFolder
    Excavation from Hewlett-Packard Desktops (remove only)
    Five Card Frenzy from Hewlett-Packard Desktops (remove only)
    FLV Player 2.0, build 24
    Fraps
    GemMaster 3 from Hewlett-Packard Desktops (remove only)
    GIMP 2.4.4
    Google Video Player
    HeroScribe 1.0pre1
    HijackThis 1.99.0
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB2158563)
    Hotfix for Windows XP (KB2443685)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB970653-v3)
    Hotfix for Windows XP (KB976098-v2)
    Hotfix for Windows XP (KB979306)
    Hotfix for Windows XP (KB981793)
    Hoyle Board Games 3
    hp deskjet 3600
    HP Extended Capabilities 5.0
    HP Image Zone Express
    HP Imaging Device Functions 5.0
    HP Photo & Imaging 3.0
    HP Photo and Imaging 2.0 - Deskjet Series
    HP Photo and Imaging 2.0 - Photosmart Cameras
    HP Photo and Imaging 2.1 - Scanjet 2400 Series
    HP Software Update
    HP Solution Center & Imaging Support Tools 5.0
    HPImageZone
    HPIZ Fix2
    hpmdtab
    HpSdpAppCoreApp
    HPSystemDiagnostics
    IKEA HomePlanner Kitchen
    InstantShare
    Intel(R) Extreme Graphics Driver
    IntelliMover Data Transfer Demo
    InterVideo WinDVD Player
    iTunes
    Java 2 Runtime Environment, SE v1.4.1_02
    Java Auto Updater
    Java Web Start
    Java(TM) 6 Update 23
    LeapFrog Connect
    LeapFrog My Pals Plugin
    LiveUpdate Notice (Symantec Corporation)
    Logitech Gaming Software
    Macromedia Dreamweaver 4
    Macromedia Extension Manager
    Macromedia Shockwave Player
    Magic: The Gathering "” Duels of the Planeswalkers 2012 - Demo
    Mars Rover from Hewlett-Packard Desktops (remove only)
    Matrix-ks
    Memories Disc Creator 2.0
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB2416447)
    Microsoft .NET Framework 1.1 Security Update (KB979906)
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Digital Image Library 9 - Blocker
    Microsoft Digital Image Standard 2006
    Microsoft Digital Image Standard 2006 Editor
    Microsoft Digital Image Standard 2006 Library
    Microsoft Encarta Encyclopedia Standard 2006
    Microsoft Money 2006
    Microsoft Office Word Viewer 2003
    Microsoft Plus! Digital Media Edition
    Microsoft Streets & Trips 2006
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual Basic 6.0 Working Model Edition
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Visual J# .NET Redistributable Package 1.1
    Microsoft Web Publishing Wizard 1.53
    Microsoft Word 2002
    Microsoft Works
    Microsoft Works Suite 2006 Setup Launcher
    Microsoft Works Suite Add-in for Microsoft Word
    MobileMe Control Panel
    Mozilla Firefox (3.6.18)
    MSN Music Assistant
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    Multimedia Card Reader
    MUSICMATCH® Jukebox
    NetAssistant
    NetAssistant for Firefox
    Network Play System (Patching)
    NVIDIA Drivers
    OmniPass
    OpenOffice.org 2.0
    Orbital from Hewlett-Packard Desktops (remove only)
    OSS Video Decompiler 5.5.0.3
    Otto from Hewlett-Packard Desktops (remove only)
    PC-Doctor for Windows
    PDFCreator
    PGP 8.0.3
    PhotoGallery
    Photosmart 140,240,7200,7600,7700,7900 Series
    Polar Bowler from Hewlett-Packard Desktops (remove only)
    PrintScreen
    PS2
    PSShortcutsP
    Python 2.2 combined Win32 extensions
    Python 2.2.1
    QFolder
    Quake 4(TM)
    Quake II
    Quake III Arena
    Quicken 2003 New User Edition
    QuickProjects
    QuickTime
    RealPlayer
    RecordNow!
    Rhapsody Player Engine
    RolePlayingMaster
    S3Display
    S3Gamma2
    S3Info2
    S3Overlay
    SBC Self Support Tool
    SBC Yahoo! Applications
    Security Update for Step By Step Interactive Training (KB898458)
    Security Update for Step By Step Interactive Training (KB923723)
    Security Update for Windows Media Player (KB2378111)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB954155)
    Security Update for Windows Media Player (KB968816)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player (KB975558)
    Security Update for Windows Media Player (KB978695)
    Security Update for Windows Media Player 10 (KB911565)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows Media Player 10 (KB936782)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows XP (KB2079403)
    Security Update for Windows XP (KB2115168)
    Security Update for Windows XP (KB2121546)
    Security Update for Windows XP (KB2229593)
    Security Update for Windows XP (KB2259922)
    Security Update for Windows XP (KB2279986)
    Security Update for Windows XP (KB2286198)
    Security Update for Windows XP (KB2296011)
    Security Update for Windows XP (KB2296199)
    Security Update for Windows XP (KB2347290)
    Security Update for Windows XP (KB2360131)
    Security Update for Windows XP (KB2360937)
    Security Update for Windows XP (KB2387149)
    Security Update for Windows XP (KB2393802)
    Security Update for Windows XP (KB2412687)
    Security Update for Windows XP (KB2416400)
    Security Update for Windows XP (KB2419632)
    Security Update for Windows XP (KB2423089)
    Security Update for Windows XP (KB2436673)
    Security Update for Windows XP (KB2440591)
    Security Update for Windows XP (KB2443105)
    Security Update for Windows XP (KB2476490)
    Security Update for Windows XP (KB2476687)
    Security Update for Windows XP (KB2478960)
    Security Update for Windows XP (KB2478971)
    Security Update for Windows XP (KB2479628)
    Security Update for Windows XP (KB2479943)
    Security Update for Windows XP (KB2481109)
    Security Update for Windows XP (KB2482017)
    Security Update for Windows XP (KB2483185)
    Security Update for Windows XP (KB2485376)
    Security Update for Windows XP (KB2485663)
    Security Update for Windows XP (KB2491683)
    Security Update for Windows XP (KB2497640)
    Security Update for Windows XP (KB2503658)
    Security Update for Windows XP (KB2503665)
    Security Update for Windows XP (KB2506212)
    Security Update for Windows XP (KB2506223)
    Security Update for Windows XP (KB2507618)
    Security Update for Windows XP (KB2508272)
    Security Update for Windows XP (KB2508429)
    Security Update for Windows XP (KB2509553)
    Security Update for Windows XP (KB2510581)
    Security Update for Windows XP (KB2511455)
    Security Update for Windows XP (KB2524375)
    Security Update for Windows XP (KB2530548)
    Security Update for Windows XP (KB2535512)
    Security Update for Windows XP (KB2536276)
    Security Update for Windows XP (KB2544521)
    Security Update for Windows XP (KB2544893)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB938464-v2)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950759)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953838)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956390)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958215)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB958869)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960714)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB963027)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969059)
    Security Update for Windows XP (KB969897)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB969947)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB970430)
    Security Update for Windows XP (KB971468)
    Security Update for Windows XP (KB971486)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB971961)
    Security Update for Windows XP (KB972260)
    Security Update for Windows XP (KB972270)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973525)
    Security Update for Windows XP (KB973869)
    Security Update for Windows XP (KB973904)
    Security Update for Windows XP (KB974112)
    Security Update for Windows XP (KB974318)
    Security Update for Windows XP (KB974392)
    Security Update for Windows XP (KB974455)
    Security Update for Windows XP (KB974571)
    Security Update for Windows XP (KB975025)
    Security Update for Windows XP (KB975467)
    Security Update for Windows XP (KB975560)
    Security Update for Windows XP (KB975561)
    Security Update for Windows XP (KB975562)
    Security Update for Windows XP (KB975713)
    Security Update for Windows XP (KB976325)
    Security Update for Windows XP (KB977165)
    Security Update for Windows XP (KB977816)
    Security Update for Windows XP (KB977914)
    Security Update for Windows XP (KB978037)
    Security Update for Windows XP (KB978251)
    Security Update for Windows XP (KB978262)
    Security Update for Windows XP (KB978338)
    Security Update for Windows XP (KB978542)
    Security Update for Windows XP (KB978601)
    Security Update for Windows XP (KB978706)
    Security Update for Windows XP (KB979309)
    Security Update for Windows XP (KB979482)
    Security Update for Windows XP (KB979559)
    Security Update for Windows XP (KB979683)
    Security Update for Windows XP (KB979687)
    Security Update for Windows XP (KB980195)
    Security Update for Windows XP (KB980218)
    Security Update for Windows XP (KB980232)
    Security Update for Windows XP (KB980436)
    Security Update for Windows XP (KB981322)
    Security Update for Windows XP (KB981349)
    Security Update for Windows XP (KB981852)
    Security Update for Windows XP (KB981957)
    Security Update for Windows XP (KB981997)
    Security Update for Windows XP (KB982132)
    Security Update for Windows XP (KB982214)
    Security Update for Windows XP (KB982381)
    Security Update for Windows XP (KB982665)
    ShareIns
    SkinsHP1
    SkinsHP2
    Slyder from Hewlett-Packard Desktops (remove only)
    SolutionCenter
    SpamSubtract
    Spybot - Search & Destroy
    Spybot - Search & Destroy 1.4
    Status
    Steam(TM)
    STX from Hewlett-Packard Desktops (remove only)
    TextDraw v5.9 and Imagetrix v5.5
    toolkit
    TrayApp
    UltimateBet
    Unity Web Player
    Unload
    Unreal Editor
    Upaint
    Update for Windows XP (KB2141007)
    Update for Windows XP (KB2345886)
    Update for Windows XP (KB2467659)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955759)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB971029)
    Update for Windows XP (KB971737)
    Update for Windows XP (KB973687)
    Update for Windows XP (KB973815)
    Update for Windows XP (KB976749)
    Update for Windows XP (KB978207)
    Update for Windows XP (KB980182)
    Updates from HP
    Use the entry named LeapFrog Connect to uninstall (LeapFrog My Pals Plugin)
    VC Temptresses Screen Saver
    Viewpoint Manager (Remove Only)
    Virtual Warfare from Hewlett-Packard Desktops (remove only)
    Visual C++ 2008 x86 Runtime - (v9.0.30729)
    Visual C++ 2008 x86 Runtime - v9.0.30729.01
    Visual IP InSight(SBC)
    WebFldrs XP
    Weblink
    WebReg
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Service Pack 3
    WinRAR archiver
    Works Upgrade
    www.UselessCreations.com - The Amazing Spider-Man 3D Screensaver v1.7
    Yahoo! Photos Easy Upload Tool 1v4
    Zune Desktop Theme
    .
    ==== Event Viewer Messages From Past Week ========
    .
    6/28/2011 3:15:43 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD AmdK7 aswRdr aswSnx aswSP aswTdi Fips IPSec MRxSmb NetBIOS NetBT Pernmdd RasAcd Rdbss Tcpip WS2IFSL
    6/28/2011 3:15:43 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD Networking Support Environment service which failed to start because of the following error: A device attached to the system is not functioning.
    6/28/2011 3:15:43 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
    6/28/2011 3:15:43 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    6/28/2011 3:15:43 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBT service which failed to start because of the following error: A device attached to the system is not functioning.
    6/28/2011 3:15:43 PM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    6/28/2011 3:15:35 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments " " in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    6/28/2011 3:15:34 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments " " in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
    6/28/2011 3:11:09 PM, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).
    6/28/2011 3:10:51 PM, error: Service Control Manager [7034] - The PGPsdkService service terminated unexpectedly. It has done this 1 time(s).
    6/28/2011 3:10:48 PM, error: Service Control Manager [7034] - The Pml Driver HPZ12 service terminated unexpectedly. It has done this 1 time(s).
    6/28/2011 3:10:45 PM, error: Service Control Manager [7034] - The LeapFrog Connect Device Service service terminated unexpectedly. It has done this 1 time(s).
    6/28/2011 3:10:42 PM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
    6/28/2011 3:10:38 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
    6/25/2011 9:20:39 PM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer USER5-PC that believes that it is the master browser for the domain on transport NetBT_Tcpip_{4000BCD1-33E5-42BC-. The master browser is stopping or an election is being forced.
    6/25/2011 4:09:04 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the iPod Service service to connect.
    6/25/2011 4:09:04 PM, error: Service Control Manager [7000] - The iPod Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    6/25/2011 4:08:50 PM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service iPod Service with arguments " " in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}
    6/25/2011 10:41:50 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Pernmdd
    6/25/2011 10:41:50 AM, error: Service Control Manager [7000] - The mrtRate service failed to start due to the following error: The system cannot find the file specified.
    6/25/2011 1:39:00 PM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
    6/24/2011 10:38:34 AM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
    .
    ==== End Of File ===========================



    Thank you for your future help. :)
     
  2. 2011/06/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Welcome aboard [​IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running tools or applying updates other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    ======================================================

    Start with following these instructions: http://www.bleepingcomputer.com/virus-removal/remove-win-7-antispyware-2012

    Let me know, when done.
     

  3. to hide this advert.

  4. 2011/07/01
    ZanKhelledros

    ZanKhelledros Inactive Thread Starter

    Joined:
    2011/06/27
    Messages:
    17
    Likes Received:
    0
    okay, ill give this a shot
     
  5. 2011/07/01
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Ok....
     
  6. 2011/07/06
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    .....
     
  7. 2011/07/14
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Reopened.

    Please, complete all steps listed HERE
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.