Answers to your tech questions
Computer forums for help with removing malicious software (malware) and improving computer security

Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)

      
 
Closed TopicStart new topic
> [Resolved] Missing Drivers
mamopoth
post Jun 21 2008, 08:07 PM
Post #1


New Member
*

Group: New Member
Posts: 7
Joined: 21-June 08
Member No.: 79,778
Operating System: Windows XPSP2



pullhair.gif
I really am at a loss! I have Windows Microsoft XPSP2 and have a HP Compaq Presario.

I ran Fixware Out, ATF-Cleaner and Combo-Fix. I then ran the Hijack This. I still have several drivers listed as "stopped disabled".
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:57:08 PM, on 6/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\AOL\1212026350\ee\AOLSoftware.exe
C:\Program Files\ThreatFire\TFTray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ThreatFire\TFService.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\system32\wuauclt.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1212026350\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/sit...b?1212527457421
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1212074850656
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe

--
End of file - 7432 bytes

Name Description Version Type Status Start Path File Description

Abiosdsk Abiosdsk Kernel Driver Stopped Disabled
abp480n5 abp480n5 Kernel Driver Stopped Disabled
ACPIEC ACPIEC Kernel Driver Stopped Disabled
adpu160m adpu160m Kernel Driver Stopped Disabled
adpu160m adpu160m Kernel Driver Stopped Disabled
Aha154x Aha154x Kernel Driver Stopped Disabled
aic78u2 aic78u2 Kernel Driver Stopped Disabled
aic78xx aic78xx Kernel Driver Stopped Disabled
AliIde AliIde Kernel Driver Stopped Disabled
amsint amsint Kernel Driver Stopped Disabled
asc asc Kernel Driver Stopped Disabled
asc3350p asc3350p Kernel Driver Stopped Disabled
Asc3550 asc3550 Kernel Driver Stopped Disabled
Atdisk Atdisk Kernel Driver Stopped Disabled
cbidf2k cbidf2k Kernel Driver Stopped Disabled
cd20xrnt cd20xrnt Kernel Driver Stopped Disabled
CmdIde CmdIde Kernel Driver Stopped Disabled
Cpqarray Cpqarray Kernel Driver Stopped Disabled
dac960nt dac960nt Kernel Driver Stopped Disabled
dmboot dmboot Kernel Driver Stopped
dmio dmio Kernel Driver Stopped Disabled
dmload dmload Kernel Driver Stopped Disabled
dpti2o dpti2o Kernel Driver Stopped Disabled
Fastfat Fastfat File System Dvr Stopped Disabled
hpn hpn Kernel Driver Stopped Disabled
i2omp i2omp Kernel Driver Stopped Disabled
Ini910u ini910u Kernel Driver Stopped Disabled
intelppm Intel Processor Kernel Driver Stopped Disabled
mraid35x mraid35x Kernel Driver Stopped Disabled
ParVdm ParVdm Kernel Driver Stopped Disabled
Pcmcia Pcmcia Kernel Driver Stopped Disabled
perc2 perc2 Kernel Driver Stopped Disabled
Perc2hib perc2hib Kernel Driver Stopped Disabled
ql1080 ql1080 Kernel Driver Stopped Disabled
Ql10wnt Ql10wnt Kernel Drive Stopped Disabled
ql12160 ql12160 Kernel Driver Stopped Disabled
ql1240 ql1240 Kernel Driver Stopped Disabled
ql1280 ql1280 Kernel Driver Stopped Disabled
Simbad Simbad Kernel Driver Stopped Disabled
Sparrow Sparrow Kernel Driver Stopped Disabled
symc810 symc810 Kernel Driver Stopped Disabled
Symc8xx symc8xx Kernel Driver Stopped Disabled
sym_hi sym_hi Kernel Driver Stopped Disabled
sym_u3 sym_u3 Kernel Driver Stopped Disabled
TosIde TosIde Kernel Driver Stopped Disabled
Udfs Udfs File System Dvr Stopped Disabled
ultra ultra Kernel Driver Stopped Disabled

I have been trying for quite a while to fix this. The system did not come with recovery disks. I had to purchase them from HP. I have erased the hard drive and reinstalled the recovery disks at least three times. The drivers are always missing. I am just an ordinary person with no special computer capabilities. If you don't know what I can do, then I GIVE UP!.

Thank you,
mamopoth


Go to the top of the page
 
+Quote Post
Scotty
post Jun 22 2008, 09:10 AM
Post #2


Always Happy
Group Icon

Group: Malware Team
Posts: 3,782
Joined: 9-December 06
From: Haggistown, Kiltland
Member No.: 65,226
Operating System: XP Pro
Ubuntu 8.04



Hi

Windows comes with many drivers pre-installed. If they are not needed, they will not be running. What made you run Fixwareout and Combofix. You could have done damage using tools you know nothing about without instructions.
Go to the top of the page
 
+Quote Post
mamopoth
post Jun 22 2008, 12:34 PM
Post #3


New Member
*

Group: New Member
Posts: 7
Joined: 21-June 08
Member No.: 79,778
Operating System: Windows XPSP2



I found this site through Microsoft. I then looked up the advice given on this site to another person that was having problems. I followed the advice. Everywhere I look, I am always told to check for malware, spyware, etc. That is why I used those programs.

Thanks for your question.

mamopoth
Go to the top of the page
 
+Quote Post
Scotty
post Jun 22 2008, 01:17 PM
Post #4


Always Happy
Group Icon

Group: Malware Team
Posts: 3,782
Joined: 9-December 06
From: Haggistown, Kiltland
Member No.: 65,226
Operating System: XP Pro
Ubuntu 8.04



Hi

You shouldnt try to follow advice given to someone else, because situations can be unique. While you are here we can take a look for you.

Firstly, it would be good to see the logs that would have been created.

Navigate to this file:
C:\fixwareout\report.txt
Copy and paste the contents of report.txt in your next reply.

Then navigate to this file:
C:\Combofix\combofix.txt

And do the same.
Go to the top of the page
 
+Quote Post
mamopoth
post Jun 22 2008, 06:08 PM
Post #5


New Member
*

Group: New Member
Posts: 7
Joined: 21-June 08
Member No.: 79,778
Operating System: Windows XPSP2



FIXWARE OUT REPORT


Username "Compaq_Owner" - 06/20/2008 16:32:25 [Fixwareout edited 9/01/2007]

~~~~~ Prerun check

Successfully flushed the DNS Resolver Cache.


System was rebooted successfully.

~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "System"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....

~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPBootOp"="\"C:\\Program Files\\Hewlett-Packard\\HP Boot Optimizer\\HPBootOp.exe\" /run"
"HP Software Update"="C:\\Program Files\\Hp\\HP Software Update\\HPWuSchd2.exe"
"HostManager"="C:\\Program Files\\Common Files\\AOL\\1212026350\\ee\\AOLSoftware.exe"
"ThreatFire"="C:\\Program Files\\ThreatFire\\TFTray.exe"
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_06\\bin\\jusched.exe\""
"StartCCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\Core-Static\\CLIStart.exe\""

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FreeRAM XP"="\"C:\\Program Files\\YourWare Solutions\\FreeRAM XP Pro\\FreeRAM XP Pro.exe\" -win"
"ccleaner"="\"C:\\Program Files\\CCleaner\\CCleaner.exe\" /AUTO"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"updateMgr"="C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe AcRdB7_1_0"
"AOL Fast Start"="\"C:\\Program Files\\AOL 9.1\\AOL.EXE\" -b"
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~


COMBOFIX


ComboFix 08-06-19.4 - Compaq_Owner 2008-06-20 16:42:15.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.811 [GMT -5:00]
Running from: C:\Documents and Settings\Compaq_Owner\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-05-20 to 2008-06-20 )))))))))))))))))))))))))))))))
.

2008-06-20 16:31 . 2008-06-20 16:35 <DIR> d-------- C:\fixwareout
2008-06-20 13:07 . 2008-06-20 13:07 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-19 20:13 . 2007-01-18 07:00 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2008-06-14 22:10 . 2008-06-19 20:39 <DIR> d-------- C:\WINDOWS\tracing
2008-06-13 10:17 . 2008-06-13 10:17 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-06-12 21:25 . 2004-08-04 00:56 116,224 --a------ C:\WINDOWS\system32\dllcache\xrxwiadr.dll
2008-06-12 21:25 . 2001-08-17 22:37 27,648 --a------ C:\WINDOWS\system32\dllcache\xrxftplt.exe
2008-06-12 21:25 . 2001-08-17 22:36 23,040 --a------ C:\WINDOWS\system32\dllcache\xrxwbtmp.dll
2008-06-12 21:25 . 2001-08-17 22:36 17,408 --a------ C:\WINDOWS\system32\dllcache\xrxscnui.dll
2008-06-12 21:23 . 2001-08-17 13:28 701,386 --a------ C:\WINDOWS\system32\dllcache\wdhaalba.sys
2008-06-12 21:22 . 2001-08-17 13:28 794,399 --a------ C:\WINDOWS\system32\dllcache\usr1806v.sys
2008-06-12 21:21 . 2001-08-17 13:28 794,654 --a------ C:\WINDOWS\system32\dllcache\usr1801.sys
2008-06-12 21:20 . 2001-08-17 22:36 525,568 --a------ C:\WINDOWS\system32\dllcache\tridxp.dll
2008-06-12 21:19 . 2004-08-04 00:00 571,392 --a------ C:\WINDOWS\system32\dllcache\tintlgnt.ime
2008-06-12 21:18 . 2001-08-17 12:18 285,760 --a------ C:\WINDOWS\system32\dllcache\stlnata.sys
2008-06-12 21:17 . 2004-08-04 00:00 143,422 --a------ C:\WINDOWS\system32\dllcache\softkey.dll
2008-06-12 21:16 . 2004-08-03 22:41 404,990 --a------ C:\WINDOWS\system32\dllcache\slntamr.sys
2008-06-12 21:15 . 2004-08-04 00:56 286,792 --a------ C:\WINDOWS\system32\dllcache\slextspk.dll
2008-06-12 21:14 . 2001-08-17 22:36 495,616 --a------ C:\WINDOWS\system32\dllcache\sblfx.dll
2008-06-12 21:13 . 2004-08-04 00:56 397,056 --a------ C:\WINDOWS\system32\dllcache\s3gnb.dll
2008-06-12 21:12 . 2001-08-17 13:28 714,762 --a------ C:\WINDOWS\system32\dllcache\r2mdmkxx.sys
2008-06-12 20:41 . 2008-06-12 20:45 <DIR> d-------- C:\Program Files\Microsoft Bootvis
2008-06-12 12:21 . 2008-06-12 12:22 63 --a------ C:\WINDOWS\WINHELP.BMK
2008-06-11 21:24 . 2008-06-11 21:24 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-06-10 15:18 . 2008-06-13 08:10 272,128 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-10 15:18 . 2008-06-13 08:10 272,128 --a------ C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-03 18:55 . 2008-06-03 18:55 <DIR> d-------- C:\Program Files\IObit
2008-06-03 18:03 . 2008-06-03 18:03 1,160 --a------ C:\WINDOWS\mozver.dat
2008-06-03 17:43 . 2008-06-03 17:43 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-06-03 17:42 . 2008-06-03 17:42 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\InstallShield
2008-06-03 17:41 . 2008-06-03 17:43 <DIR> d-------- C:\Program Files\AMD
2008-06-03 15:22 . 2008-04-30 17:32 107,596 --a------ C:\toolkit_widget.gif
2008-06-03 11:55 . 2001-08-17 13:28 899,146 --a------ C:\WINDOWS\system32\dllcache\r2mdkxga.sys
2008-06-03 11:55 . 2004-08-04 00:00 77,824 --a------ C:\WINDOWS\system32\dllcache\quick.ime
2008-06-03 11:55 . 2001-08-17 13:52 49,024 --a------ C:\WINDOWS\system32\dllcache\ql1280.sys
2008-06-03 11:55 . 2001-08-17 22:36 41,472 --a------ C:\WINDOWS\system32\dllcache\qvusd.dll
2008-06-03 11:55 . 2001-08-17 13:53 3,328 --a------ C:\WINDOWS\system32\dllcache\qv2kux.sys
2008-06-03 11:53 . 2004-08-04 00:56 259,328 --a------ C:\WINDOWS\system32\dllcache\perm3dd.dll
2008-06-03 11:52 . 2004-08-04 00:56 4,274,816 --a------ C:\WINDOWS\system32\dllcache\nv4_disp.dll
2008-06-03 11:51 . 2001-08-17 12:50 198,144 --a------ C:\WINDOWS\system32\dllcache\nv3.sys
2008-06-03 11:50 . 2004-08-04 00:56 1,737,856 --a------ C:\WINDOWS\system32\dllcache\mtxparhd.dll
2008-06-03 11:49 . 2004-08-04 00:00 1,875,968 --a------ C:\WINDOWS\system32\dllcache\msir3jp.lex
2008-06-03 11:48 . 2001-08-17 13:28 802,683 --a------ C:\WINDOWS\system32\dllcache\ltsm.sys
2008-06-03 11:47 . 2004-08-04 00:00 1,158,818 --a------ C:\WINDOWS\system32\dllcache\korwbrkr.lex
2008-06-03 11:46 . 2004-08-04 00:00 471,102 --a------ C:\WINDOWS\system32\dllcache\imskdic.dll
2008-06-03 11:45 . 2004-08-04 00:00 811,064 --a------ C:\WINDOWS\system32\dllcache\imjp81k.dll
2008-06-03 11:44 . 2004-08-04 00:00 13,463,552 --a------ C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-06-03 11:43 . 2001-08-17 13:28 907,456 --a------ C:\WINDOWS\system32\dllcache\hcf_msft.sys
2008-06-03 11:42 . 2001-08-17 14:56 1,733,120 --a------ C:\WINDOWS\system32\dllcache\g400d.dll
2008-06-03 11:41 . 2001-08-17 12:17 629,952 --a------ C:\WINDOWS\system32\dllcache\eqn.sys
2008-06-03 11:40 . 2001-08-17 12:14 952,007 --a------ C:\WINDOWS\system32\dllcache\diwan.sys
2008-06-03 11:39 . 2001-08-17 22:36 614,429 --a------ C:\WINDOWS\system32\dllcache\digiview.exe
2008-06-03 11:38 . 2004-08-04 00:00 1,677,824 --a------ C:\WINDOWS\system32\dllcache\chsbrkr.dll
2008-06-03 11:37 . 2001-08-17 13:28 871,388 --a------ C:\WINDOWS\system32\dllcache\bcmdm.sys
2008-06-03 11:36 . 2004-08-04 00:56 870,784 --a------ C:\WINDOWS\system32\dllcache\ati3d1ag.dll
2008-06-03 11:35 . 2001-08-17 13:28 762,780 --a------ C:\WINDOWS\system32\dllcache\3cwmcru.sys
2008-06-03 10:24 . 2008-06-03 10:24 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\ATI
2008-06-03 10:24 . 2008-06-03 10:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ATI
2008-06-03 10:23 . 2008-06-03 10:23 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-06-03 09:57 . 2008-06-03 10:00 <DIR> d-------- C:\Program Files\ATI Technologies
2008-06-03 09:57 . 2008-05-12 10:49 593,920 --------- C:\WINDOWS\system32\ati2sgag.exe
2008-06-02 21:04 . 2008-06-02 21:04 <DIR> d-------- C:\Program Files\filehippo.com
2008-06-02 18:09 . 2008-06-02 18:09 <DIR> d-------- C:\ATI
2008-06-02 11:47 . 2008-06-02 12:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Tarma Installer
2008-06-02 11:47 . 1999-02-19 03:54 40,960 --------- C:\WINDOWS\SSubTmr6.dll
2008-06-02 10:46 . 2008-06-02 10:46 <DIR> d-------- C:\Program Files\SIW
2008-06-02 00:26 . 2008-06-02 00:26 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Auslogics
2008-06-01 00:45 . 2008-04-22 23:16 6,066,176 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-06-01 00:45 . 2007-04-17 04:32 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-06-01 00:45 . 2007-03-08 00:10 991,232 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-06-01 00:45 . 2008-04-22 23:16 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-06-01 00:45 . 2008-04-22 23:16 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-06-01 00:45 . 2008-04-22 23:16 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-06-01 00:45 . 2008-04-22 23:16 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll
2008-06-01 00:45 . 2008-04-22 23:16 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-06-01 00:45 . 2008-04-22 02:39 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-05-31 12:12 . 2008-05-31 12:12 262,144 --a------ C:\WINDOWS\system32\default_user_class.dat
2008-05-31 11:05 . 2008-05-31 11:05 <DIR> d-------- C:\WINDOWS\wt
2008-05-31 08:32 . 2008-05-31 08:32 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Template
2008-05-31 08:32 . 2008-06-12 12:02 330 --a------ C:\Documents and Settings\Compaq_Owner\Application Data\wklnhst.dat
2008-05-31 06:54 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-05-30 15:40 . 2008-05-30 15:40 <DIR> d-------- C:\eb77bced037debe83b0e0ca4
2008-05-30 13:34 . 2008-05-30 13:34 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-05-30 11:20 . 2008-05-30 11:20 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-05-29 20:12 . 2008-05-29 20:12 <DIR> d-------- C:\WINDOWS\Sun
2008-05-29 19:46 . 2008-05-29 19:46 <DIR> d-------- C:\Program Files\CCleaner
2008-05-29 18:54 . 2008-05-29 18:54 214 --a------ C:\WINDOWS\HP_48BitScanUpdatePatch.ini
2008-05-29 18:13 . 2008-05-29 18:13 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\WinBatch
2008-05-29 17:50 . 2008-05-29 17:50 234 --a------ C:\WINDOWS\PrnHlpLogConfig.ini
2008-05-29 17:34 . 2008-05-29 17:34 214 --a------ C:\WINDOWS\HP_InstantSHareJPG.ini
2008-05-29 17:31 . 2008-05-29 17:31 221 --a------ C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
2008-05-29 16:22 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-05-29 16:22 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-05-29 15:54 . 2008-05-29 15:54 <DIR> d-------- C:\WINDOWS\aolshare
2008-05-29 15:54 . 2008-05-29 17:17 <DIR> d-------- C:\Program Files\AOL 9.1
2008-05-29 15:54 . 2008-05-30 21:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-05-29 11:42 . 2008-05-30 17:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-05-29 11:27 . 2008-05-29 11:27 <DIR> d-------- C:\Program Files\UPHClean
2008-05-29 10:22 . 2008-05-29 10:22 <DIR> d--hs---- C:\Documents and Settings\Compaq_Owner\UserData
2008-05-29 01:15 . 2008-05-29 01:15 <DIR> d-------- C:\Program Files\Alwil Software
2008-05-29 00:23 . 2008-06-10 22:31 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-05-29 00:00 . 2008-05-29 00:00 <DIR> d-------- C:\Program Files\YourWare Solutions
2008-05-29 00:00 . 2008-05-29 00:00 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\IObit
2008-05-29 00:00 . 2008-04-17 16:19 90,668 --a------ C:\WINDOWS\system32\vobis32.dll
2008-05-28 22:05 . 2008-05-28 22:05 <DIR> d-------- C:\Program Files\ThreatFire
2008-05-28 22:05 . 2008-06-20 16:47 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-28 22:05 . 2008-05-28 22:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
2008-05-28 22:05 . 2008-04-24 16:52 51,520 --a------ C:\WINDOWS\system32\drivers\TfFsMon.sys
2008-05-28 22:05 . 2008-04-24 16:52 38,208 --a------ C:\WINDOWS\system32\drivers\TfSysMon.sys
2008-05-28 22:05 . 2008-04-24 16:52 33,088 --a------ C:\WINDOWS\system32\drivers\TfNetMon.sys
2008-05-28 22:05 . 2008-04-24 16:52 12,608 --a------ C:\WINDOWS\system32\drivers\TfKbMon.sys
2008-05-28 21:08 . 2008-05-28 21:30 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Netscape
2008-05-28 21:01 . 2008-05-28 21:01 <DIR> d-------- C:\Program Files\Common Files\Nullsoft
2008-05-28 21:01 . 2008-05-28 21:01 <DIR> d-------- C:\Program Files\Common Files\aolback
2008-05-28 21:01 . 2008-05-30 21:48 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\AOL
2008-05-28 21:01 . 2008-05-29 15:56 723 --a------ C:\WINDOWS\aolback.exe.lnk
2008-05-28 21:00 . 2008-05-28 21:00 <DIR> d-------- C:\Program Files\Viewpoint
2008-05-28 21:00 . 2008-05-28 21:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-05-28 20:59 . 2008-05-28 21:41 <DIR> d-------- C:\Program Files\AOL 9.0
2008-05-28 20:58 . 2008-05-28 20:58 335 --a------ C:\WINDOWS\nsreg.dat
2008-05-28 20:54 . 2003-01-10 16:13 33,588 -ra------ C:\WINDOWS\system32\drivers\wanatw4.sys
2008-05-28 20:53 . 2008-05-28 20:58 <DIR> d--h----- C:\TEMP
2008-05-28 20:53 . 2008-05-29 15:54 <DIR> d-------- C:\Program Files\Common Files\aolshare
2008-05-28 20:53 . 2008-05-30 21:43 <DIR> d-------- C:\Program Files\Common Files\AOL
2008-05-28 20:53 . 2008-05-29 15:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL

.mamopoth
Go to the top of the page
 
+Quote Post
Scotty
post Jun 23 2008, 02:47 AM
Post #6


Always Happy
Group Icon

Group: Malware Team
Posts: 3,782
Joined: 9-December 06
From: Haggistown, Kiltland
Member No.: 65,226
Operating System: XP Pro
Ubuntu 8.04



Im quite certain this is not a malware issue. Can you start a topic here
http://forums.whatthetech.com/Microsoft_Windows_f119.html

The tech guys have a better idea about this kind of thing.

And you had best do this.

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the x and the /u, it needs to be there.

Go to the top of the page
 
+Quote Post
mamopoth
post Jun 23 2008, 09:18 AM
Post #7


New Member
*

Group: New Member
Posts: 7
Joined: 21-June 08
Member No.: 79,778
Operating System: Windows XPSP2



Thank you, Scottie, for your time and trouble. I did as you suggested. Again, thank you.

mamopoth
Go to the top of the page
 
+Quote Post
Scotty
post Jun 23 2008, 12:00 PM
Post #8


Always Happy
Group Icon

Group: Malware Team
Posts: 3,782
Joined: 9-December 06
From: Haggistown, Kiltland
Member No.: 65,226
Operating System: XP Pro
Ubuntu 8.04



Since this issue appears to be resolved ... this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Go to the top of the page
 
+Quote Post

Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 


RSS Time is now: 10th October 2008 - 05:36 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy