This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Need help asap please.

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ive reformatted my comp twice still ahve this weird problem

First it said Windows Explorer has encountered a problem and needs to close then after I reofrmatted it said Win32 Generic problem

My internet is slow and it wont let me go to microsoft.com or even TrendSecure

anyays heres my hijackthis log and ill get my combo fix log up soon

Combofix:
ComboFix 09-02-28.01 - Owner 2009-03-01 0:06:12.1 - NTFSx86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Owner\Local Settings\Temporary Internet Files\PLauncher.exe

.
((((((((((((((((((((((((( Files Created from 2009-02-01 to 2009-03-01 )))))))))))))))))))))))))))))))
.

2009-02-28 23:59 . 2009-02-28 23:59 d——– c:\windows\Sun
2009-02-28 23:55 . 2009-02-28 23:55 d——– c:\program files\Trend Micro
2009-02-28 23:16 . 2009-02-28 23:16 d——– c:\documents and settings\Owner\Application Data\Logitech
2009-02-28 23:15 . 2009-02-28 23:15 0 –ah—– c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-02-28 23:15 . 2009-02-28 23:15 0 –ah—– c:\windows\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2009-02-28 23:15 . 2009-02-28 23:15 0 –ah—– c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2009-02-28 23:14 . 2009-02-28 23:14 d—-c— c:\windows\system32\DRVSTORE
2009-02-28 23:14 . 2009-02-28 23:14 d——– C:\ijji
2009-02-28 23:14 . 2009-02-28 23:15 d–h—– c:\documents and settings\Owner\Application Data\ijjigame
2009-02-28 23:14 . 2009-02-28 23:14 d——– c:\documents and settings\All Users\Application Data\IJJIGame
2009-02-28 23:14 . 2007-04-11 15:33 1,419,024 –a—— c:\windows\system32\WdfCoInstaller01005.dll
2009-02-28 23:14 . 2007-04-11 15:33 79,376 –a—— c:\windows\system32\drivers\LMouKE.Sys
2009-02-28 23:14 . 2007-04-11 15:32 63,248 –a—— c:\windows\system32\drivers\L8042mou.Sys
2009-02-28 23:14 . 2007-04-11 15:32 56,080 –a—— c:\windows\KHALMNPR.Exe
2009-02-28 23:14 . 2007-04-11 15:32 36,112 –a—— c:\windows\system32\drivers\LMouFilt.Sys
2009-02-28 23:14 . 2007-04-11 15:32 34,832 –a—— c:\windows\system32\drivers\LHidFilt.Sys
2009-02-28 23:14 . 2007-04-11 15:33 28,688 –a—— c:\windows\system32\drivers\LUsbFilt.sys
2009-02-28 23:14 . 2007-04-11 15:32 20,496 –a—— c:\windows\system32\drivers\L8042Kbd.sys
2009-02-28 23:13 . 2009-02-28 23:13 d——– c:\program files\Logitech
2009-02-28 23:13 . 2009-02-28 23:13 d——– c:\program files\Common Files\Logitech
2009-02-28 23:13 . 2009-02-28 23:13 d——– c:\documents and settings\Owner\Application Data\InstallShield
2009-02-28 23:13 . 2009-02-28 23:13 d——– c:\documents and settings\All Users\Application Data\Logitech
2009-02-28 23:13 . 2009-02-28 23:13 d——– c:\documents and settings\All Users\Application Data\LogiShrd
2009-02-28 23:13 . 2007-04-23 04:00 163,840 –a—— c:\windows\system32\kemutb.dll
2009-02-28 23:13 . 2007-04-23 04:00 135,168 –a—— c:\windows\system32\KemUtil.dll
2009-02-28 23:13 . 2007-04-23 04:00 110,592 –a—— c:\windows\system32\KemWnd.dll
2009-02-28 23:13 . 2007-04-23 04:00 69,632 –a—— c:\windows\system32\KemXML.dll
2009-02-28 23:12 . 2009-02-28 23:12 d——– c:\documents and settings\Owner\Application Data\McAfee.com Personal Firewall
2009-02-28 23:10 . 2009-02-28 23:10 d——– c:\program files\CCleaner
2009-02-28 23:06 . 2009-02-28 23:06 d——– c:\program files\Ventrilo
2009-02-28 23:06 . 2009-02-28 23:06 d——– c:\program files\Common Files\Wise Installation Wizard
2009-02-28 23:06 . 2009-02-28 23:06 262 –a—— c:\windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
2009-02-28 23:05 . 2009-02-28 23:05 d——– c:\program files\Xfire
2009-02-28 23:05 . 2009-02-28 23:05 d——– c:\documents and settings\Owner\Application Data\Xfire
2009-02-28 22:28 . 2009-02-28 22:28 2 –a—— c:\windows\msoffice.ini
2009-02-28 22:00 . 2009-02-28 21:05 d——– c:\windows\system32\config\systemprofile\WINDOWS
2009-02-28 22:00 . 2009-02-28 21:05 d——– c:\documents and settings\Default User\WINDOWS
2009-02-28 21:58 . 2009-02-28 21:58 8,192 –a—— c:\windows\REGLOCS.OLD
2009-02-28 21:56 . 2009-02-28 21:56 333 –a—— c:\windows\system32\$ncsp$.inf
2009-02-28 21:56 . 2009-02-28 21:56 0 –a—— c:\windows\system32\GATEWAY_T3504__GRC6520004224.MRK
2009-02-28 21:55 . 2009-02-28 21:55 d——– c:\windows\system32\Lang
2009-02-28 21:55 . 2009-02-28 21:55 940,794 –a—— c:\windows\system32\LoopyMusic.wav
2009-02-28 21:55 . 2009-02-28 21:55 146,650 –a—— c:\windows\system32\BuzzingBee.wav
2009-02-28 21:53 . 2009-02-28 23:12 2,752 –a—— c:\windows\system32\Status.MPF
2009-02-28 21:52 . 2009-02-28 22:28 d——– c:\documents and settings\Owner\Application Data\AOL
2009-02-28 21:42 . 2009-02-28 22:07 d–h—– c:\windows\$hf_mig$
2009-02-28 21:41 . 2009-02-28 21:41 d——– c:\documents and settings\All Users\Application Data\McAfee.com
2009-02-28 21:40 . 2009-02-28 23:29 d——– c:\program files\McAfee.com
2009-02-28 21:40 . 2009-02-28 21:40 d——– c:\documents and settings\All Users\Application Data\McAfee.com Personal Firewall
2009-02-28 21:40 . 2005-08-29 20:01 349,760 –a—— c:\windows\system32\mcinsctl.dll
2009-02-28 21:40 . 2005-05-24 20:23 288,320 –a—— c:\windows\system32\mcgdmgr.dll
2009-02-28 21:40 . 2004-08-04 12:00 221,184 –a—— c:\windows\system32\wmpns.dll
2009-02-28 21:39 . 2006-01-18 04:41 80,512 –a—— c:\windows\system32\drivers\Rtnicxp.sys
2009-02-28 21:39 . 2003-03-25 06:00 67,072 –a—— c:\windows\POWERCFG.EXE
2009-02-28 21:38 . 2009-02-28 21:38 d——– c:\program files\Common Files\Nullsoft
2009-02-28 21:38 . 2009-02-28 21:38 d——– c:\documents and settings\Owner\Application Data\You've Got Pictures Screensaver
2009-02-28 21:38 . 1999-11-10 12:05 86,016 –a—— c:\windows\unvise32qt.exe
2009-02-28 21:37 . 2009-02-28 21:37 d——– c:\program files\Common Files\Real
2009-02-28 21:37 . 2009-02-28 21:37 d——– c:\documents and settings\Owner\Application Data\SampleView
2009-02-28 21:37 . 2009-02-28 21:37 d——– c:\documents and settings\All Users\Application Data\Viewpoint
2009-02-28 21:37 . 2009-02-28 21:37 d——– c:\documents and settings\All Users\Application Data\QuickTime
2009-02-28 21:37 . 2009-02-28 21:37 d——– c:\documents and settings\All Users\Application Data\Pure Networks
2009-02-28 21:36 . 2009-02-28 22:28 d——– c:\documents and settings\All Users\Application Data\AOL
2009-02-28 21:36 . 2009-02-28 21:38 1,112 –ah—– C:\IPH.PH
2009-02-28 21:36 . 2009-02-28 21:36 335 –a—— c:\windows\nsreg.dat
2009-02-28 21:35 . 2009-02-28 22:37 d——– c:\program files\Napster
2009-02-28 21:35 . 2009-02-28 21:35 d——– c:\program files\MSN Encarta Plus
2009-02-28 21:35 . 2009-02-28 21:35 d——– c:\program files\Common Files\Adobe
2009-02-28 21:35 . 2009-02-28 22:37 d——– c:\documents and settings\All Users\Application Data\Napster
2009-02-28 21:35 . 2003-03-18 13:05 89,088 –a—— c:\windows\system32\atl71.dll
2009-02-28 21:34 . 2009-02-28 21:34 4 –a—— c:\windows\Pix11.dat
2009-02-28 21:32 . 2009-02-28 21:39 d——– c:\program files\Realtek
2009-02-28 21:31 . 2005-03-04 04:36 49,265 –a—— c:\windows\system32\jpicpl32.cpl
2009-02-28 21:31 . 2004-09-03 17:07 20,480 –a—— c:\windows\system32\Marker32.exe
2009-02-28 21:30 . 2009-02-28 21:31 d——– c:\program files\Java
2009-02-28 21:30 . 2009-02-28 21:30 d——– c:\program files\Common Files\Java
2009-02-28 21:30 . 2004-07-15 15:08 471,300 –a—— c:\windows\wallpe.exe
2009-02-28 21:30 . 2006-01-31 12:54 94,208 –a—— c:\windows\system32\bae.dll
2009-02-28 21:30 . 2004-04-22 18:48 30,056 –a—— c:\windows\system32\oemlogo.bmp
2009-02-28 21:29 . 2009-02-28 21:29 2 –a—— C:\AUDIT_INSTALL_IN_PROGRESS
2009-02-28 21:28 . 2004-03-22 15:17 24,816 –a—— c:\windows\system32\mdimon.dll
2009-02-28 21:28 . 2009-02-28 21:28 376 –a—— c:\windows\ODBC.INI
2009-02-28 21:26 . 2009-02-28 23:13 d–h—– c:\program files\InstallShield Installation Information
2009-02-28 21:26 . 2009-02-28 21:35 d——– c:\program files\Common Files\InstallShield
2009-02-28 21:21 . 2009-02-28 21:21 d——– c:\program files\Common Files\New Boundary
2009-02-28 21:21 . 2009-02-28 21:21 d——– c:\documents and settings\All Users\Application Data\Prism Deploy
2009-02-28 21:19 . 2009-02-28 21:19 2 -r-hs—- C:\USER
2009-02-28 21:19 . 2009-02-28 21:52 0 –a—— C:\REQUEST_OEMRESET_ENDUSER
2009-02-28 21:17 . 2001-08-17 13:48 12,160 –a—— c:\windows\system32\drivers\mouhid.sys
2009-02-28 21:17 . 2001-08-17 13:48 12,160 –a–c— c:\windows\system32\dllcache\mouhid.sys
2009-02-28 21:17 . 2001-08-17 14:02 9,600 –a—— c:\windows\system32\drivers\hidusb.sys
2009-02-28 21:17 . 2001-08-17 14:02 9,600 –a–c— c:\windows\system32\dllcache\hidusb.sys
2009-02-28 21:16 . 2004-08-04 00:08 26,624 –a—— c:\windows\system32\drivers\usbehci.sys
2009-02-28 21:16 . 2004-08-03 23:31 20,992 –a—— c:\windows\system32\drivers\RTL8139.sys
2009-02-28 21:16 . 2004-08-04 00:08 17,024 –a—— c:\windows\system32\drivers\usbohci.sys
2009-02-28 21:16 . 2004-08-04 01:56 7,168 –a—— c:\windows\system32\hccoin.dll
2009-02-28 21:11 . 2009-02-28 21:42 d——– c:\windows\creator
2009-02-28 21:11 . 2009-02-28 21:11 60 –a—— c:\windows\system32\SYSDRV.DAT
2009-02-28 21:10 . 2009-02-28 21:36 d——– c:\windows\SMINST
2009-02-28 21:10 . 2009-02-28 21:55 d——– c:\windows\I386
2009-02-28 21:10 . 2005-09-22 22:26 1,094,751 –a—— c:\windows\system32\drivers\AGRSM.sys
2009-02-28 21:10 . 2005-05-01 21:10 68,096 –a—— c:\windows\agrsmdel.exe
2009-02-28 21:08 . 2004-08-03 17:56 4,274,816 –a—— c:\windows\system32\nv4_disp.dll
2009-02-28 21:07 . 2004-08-03 15:29 1,897,408 –a—— c:\windows\system32\drivers\nv4_mini.sys
2009-02-28 21:06 . 2004-08-03 17:56 47,104 –a—— c:\windows\system32\cnbjmon.dll
2009-02-10 17:14 . 2009-02-10 17:14 42,320 –a—— c:\windows\system32\xfcodec.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-01 04:37 8,552 —-a-w c:\windows\system32\drivers\asctrm.sys
2009-03-01 04:05 ——— d—–w c:\program files\microsoft frontpage
2004-08-04 19:00 168,509 –sha-r c:\windows\system32\pruvtt.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OASClnt]
–a—— 2005-08-11 23:02 53248 c:\program files\McAfee.com\VSO\oasclnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
–a—— 2002-09-13 23:42 212992 c:\windows\SMINST\Recguard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
–a—— 2005-02-25 18:24 966656 c:\windows\creator\Remind_XP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
–a—— 2005-08-10 13:49 163840 c:\program files\McAfee.com\VSO\mcvsshld.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask]
–a—— 2005-07-08 19:18 151552 c:\progra~1\McAfee.com\VSO\mcmnhdlr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
–a—— 2005-05-03 04:43 69632 c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
–a—— 2006-04-04 03:44 16120832 c:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\IJJIGame\\PLauncher.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9562:TCP"= 9562:TCP:rrqfgytk

R2 kqhxqnbyf;jpwfmbm;c:\windows\system32\svchost.exe [2004-08-04 14336]


— Other Services/Drivers In Memory —

*Deregistered* - abp480n5
*Deregistered* - adpu160m
*Deregistered* - AFD
*Deregistered* - agp440
*Deregistered* - agpCPQ
*Deregistered* - Aha154x
*Deregistered* - aic78u2
*Deregistered* - aic78xx
*Deregistered* - AliIde
*Deregistered* - alim1541
*Deregistered* - amdagp
*Deregistered* - amsint
*Deregistered* - asc
*Deregistered* - asc3350p
*Deregistered* - asc3550
*Deregistered* - ATI Smart
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - Beep
*Deregistered* - Browser
*Deregistered* - cbidf
*Deregistered* - cd20xrnt
*Deregistered* - Cdfs
*Deregistered* - CmdIde
*Deregistered* - Cpqarray
*Deregistered* - CryptSvc
*Deregistered* - dac2w2k
*Deregistered* - dac960nt
*Deregistered* - Dhcp
*Deregistered* - Dnscache
*Deregistered* - dpti2o
*Deregistered* - EventSystem
*Deregistered* - Fastfat
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - helpsvc
*Deregistered* - hpn
*Deregistered* - i2omgmt
*Deregistered* - i2omp
*Deregistered* - ini910u
*Deregistered* - IntelIde
*Deregistered* - IPSec
*Deregistered* - kqhxqnbyf
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - mnmdd
*Deregistered* - MountMgr
*Deregistered* - mraid35x
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - PartMgr
*Deregistered* - perc2
*Deregistered* - perc2hib
*Deregistered* - PptpMiniport
*Deregistered* - PSched
*Deregistered* - ql1080
*Deregistered* - Ql10wnt
*Deregistered* - ql12160
*Deregistered* - ql1240
*Deregistered* - ql1280
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - RpcSs
*Deregistered* - SENS
*Deregistered* - ShellHWDetection
*Deregistered* - sisagp
*Deregistered* - Sparrow
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - swenum
*Deregistered* - sym_hi
*Deregistered* - sym_u3
*Deregistered* - symc810
*Deregistered* - symc8xx
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - TermDD
*Deregistered* - TosIde
*Deregistered* - TrkWks
*Deregistered* - ultra
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - viaagp
*Deregistered* - ViaIde
*Deregistered* - VolSnap
*Deregistered* - Wanarp
*Deregistered* - Wdf01000
*Deregistered* - winmgmt

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
kqhxqnbyf
.
Contents of the 'Scheduled Tasks' folder

2009-03-01 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-04 12:00]

2009-03-01 c:\windows\Tasks\ISP signup reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-04 12:00]

2009-03-01 c:\windows\Tasks\ISP signup reminder 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-04 12:00]
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-McafWelcome - c:\program files\McAfee.com\Agent\mcwelcom.exe
MSConfigStartUp-MCAgentExe - c:\progra~1\mcafee.com\agent\mcagent.exe
MSConfigStartUp-MCUpdateExe - c:\progra~1\mcafee.com\agent\McUpdate.exe
MSConfigStartUp-MSKAGENTEXE - c:\progra~1\McAfee\SPAMKI~1\MskAgent.exe
MSConfigStartUp-MSKDetectorExe - c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe


.
——- Supplementary Scan ——-
.
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\g1t8tieb.default\
FF - prefs.js: browser.startup.homepage - sfront.ijji.com
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJPI150_02.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiCHPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-01 00:07:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\kqhxqnbyf]
"ServiceDll"="c:\windows\system32\pruvtt.dll"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(512)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-03-01 0:07:59
ComboFix-quarantined-files.txt 2009-03-01 07:07:43

Pre-Run: 90,544,508,928 bytes free
Post-Run: 90,544,926,720 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

321
Hi deNieD88 and welcome to the forums here at WTT! :welcome: First, that's the combofix log. Need the HijackThis log. I would also not advise running combofix without guidance from an expert. I can definitely see at least one what looks to be nasty rootkit running here. How long ago did you reformat? And when you say reformat, did you completely wipe the drive clean and re-install? Not just repair install? Another question…..after reformatting did you restore any data that was backed up, and possibly infected. There are other variables too that we'll need to go over. For now, just post the HijackThis log and we'll go from there.
heres my hijack this log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:41:23 PM, on 3/1/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\WINDOWS\explorer.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

–
End of file - 968 bytes


and to answer your questions I reformatted yersterday and I didnt backup any files I just reformatted back to Factory style

I cant get on microsoft.com of windows.com or trendsecure.com its really weird and now that I reformatted Now I cant download service pack 3 or any updates because of this.
The HijackThis log is cut off. Need to make sure and post the whole log. Let's try this.

The below scan can take up to an hour or longer, please be patient.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so no conflicts and to speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once scan is finished remember to re-enable resident antivirus protection along with whatever antispyware app you use.


Please do a scan with Kaspersky Online Scanner or from here
http://www.kaspersky.com/virusscanner

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition
    files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
    * Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    * Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    * Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
Click on: Save Report As
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:
Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in
your reply.

Animated tutorial
http://i275.photobucket.com/albums/jj285/B…ng/KAS/KAS9.gif

(Note.. for Internet Explorer 7 users:
If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%
.)
Or use Firefox with IE-Tab plugin
https://addons.mozilla.org/en-US/firefox/addon/1419

In your next reply post:
Kaspersky log
New HJT log taken after the above scan has run
my internet wont let be go to that website i seriously think whatever I have is preventing me from certain websites such as microsoft.com windows.com
I'm suspecting Virut. Try this…download on another PC if you cannot on this one. Transfer over on a flash drive.

Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, in the menu, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
K done i saved the file what now hey guess what! i can go on microsoft.com!!!!!!!!!
my files attached cause Idk what to open it with D: hsrkqtx[1].gif;C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\GBM547GV;Win32.HLLW.Shadow.based;Deleted.; A0000015.bat;C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1;Probably BATCH.Virus;Incurable.Deleted.; A0001184.dll;C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP4;Win32.HLLW.Shadow.based;Deleted.; nvm thats it!
Well that's good news, as it doesn't appear to be Virut. If you cannot download combofix on this PC you will need another PC to download it on, then copy it over with a USB drive, ect….

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply. Please also post an updated HijackThis log and let me know how it's running.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix 09-03-02.03 - Owner 2009-03-03 19:10:19.2 - NTFSx86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2009-02-04 to 2009-03-04 )))))))))))))))))))))))))))))))
.

2009-03-03 14:44 . 2005-10-11 12:48 10,280 –a—— c:\windows\BigFixClientOverride.dll
2009-03-01 22:04 . 2009-03-01 22:04 d——– c:\program files\Apple Software Update
2009-03-01 22:04 . 2009-03-01 22:04 d——– c:\documents and settings\All Users\Application Data\Apple
2009-03-01 20:24 . 2009-03-01 21:37 d——– c:\documents and settings\Owner\DoctorWeb
2009-03-01 18:16 . 2009-03-01 18:16 d——– C:\ATI
2009-03-01 15:59 . 2009-03-01 15:59 d——– c:\program files\IObit
2009-03-01 15:59 . 2009-03-03 14:36 d——– c:\documents and settings\Owner\Application Data\IObit
2009-03-01 15:41 . 2009-03-01 15:41 d——– c:\program files\Trend Micro
2009-03-01 03:36 . 2009-03-01 03:36 d——– c:\program files\Microsoft LifeCam
2009-03-01 03:33 . 2009-03-01 03:33 d——– c:\windows\system32\drivers\umdf
2009-03-01 02:20 . 2004-08-03 23:07 59,264 –a—— c:\windows\system32\drivers\USBAUDIO.sys
2009-03-01 02:20 . 2004-08-03 23:07 59,264 –a–c— c:\windows\system32\dllcache\usbaudio.sys
2009-03-01 02:19 . 2004-08-03 23:08 31,616 –a—— c:\windows\system32\drivers\usbccgp.sys
2009-03-01 02:19 . 2004-08-03 23:08 31,616 –a–c— c:\windows\system32\dllcache\usbccgp.sys
2009-03-01 02:13 . 2009-03-01 16:09 d——– c:\documents and settings\Owner\Application Data\Ventrilo
2009-03-01 00:49 . 2003-07-18 23:17 5,174 –a—— c:\windows\system32\nppt9x.vxd
2009-03-01 00:49 . 2005-01-02 14:43 4,682 –a—— c:\windows\system32\npptNT2.sys
2009-03-01 00:48 . 2009-03-01 00:48 d——– c:\program files\Common Files\INCA Shared
2009-03-01 00:23 . 2009-03-01 00:23 d——– c:\documents and settings\NetworkService\Application Data\Xfire
2009-02-28 23:59 . 2009-02-28 23:59 d——– c:\windows\Sun
2009-02-28 23:16 . 2009-02-28 23:16 d——– c:\documents and settings\Owner\Application Data\Logitech
2009-02-28 23:15 . 2009-02-28 23:15 0 –ah—– c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-02-28 23:15 . 2009-02-28 23:15 0 –ah—– c:\windows\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2009-02-28 23:15 . 2009-02-28 23:15 0 –ah—– c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2009-02-28 23:14 . 2009-03-01 22:04 d—-c— c:\windows\system32\DRVSTORE
2009-02-28 23:14 . 2009-02-28 23:14 d——– C:\ijji
2009-02-28 23:14 . 2009-03-01 00:35 d–h—– c:\documents and settings\Owner\Application Data\ijjigame
2009-02-28 23:14 . 2009-02-28 23:14 d——– c:\documents and settings\All Users\Application Data\IJJIGame
2009-02-28 23:14 . 2007-04-11 15:33 1,419,024 –a—— c:\windows\system32\WdfCoInstaller01005.dll
2009-02-28 23:14 . 2007-04-11 15:33 79,376 –a—— c:\windows\system32\drivers\LMouKE.Sys
2009-02-28 23:14 . 2007-04-11 15:32 63,248 –a—— c:\windows\system32\drivers\L8042mou.Sys
2009-02-28 23:14 . 2007-04-11 15:32 56,080 –a—— c:\windows\KHALMNPR.Exe
2009-02-28 23:14 . 2007-04-11 15:32 36,112 –a—— c:\windows\system32\drivers\LMouFilt.Sys
2009-02-28 23:14 . 2007-04-11 15:32 34,832 –a—— c:\windows\system32\drivers\LHidFilt.Sys
2009-02-28 23:14 . 2007-04-11 15:33 28,688 –a—— c:\windows\system32\drivers\LUsbFilt.sys
2009-02-28 23:14 . 2007-04-11 15:32 20,496 –a—— c:\windows\system32\drivers\L8042Kbd.sys
2009-02-28 23:13 . 2009-02-28 23:13 d——– c:\program files\Logitech
2009-02-28 23:13 . 2009-02-28 23:13 d——– c:\program files\Common Files\Logitech
2009-02-28 23:13 . 2009-02-28 23:13 d——– c:\documents and settings\Owner\Application Data\InstallShield
2009-02-28 23:13 . 2009-02-28 23:13 d——– c:\documents and settings\All Users\Application Data\Logitech
2009-02-28 23:13 . 2009-02-28 23:13 d——– c:\documents and settings\All Users\Application Data\LogiShrd
2009-02-28 23:13 . 2007-04-23 04:00 163,840 –a—— c:\windows\system32\kemutb.dll
2009-02-28 23:13 . 2007-04-23 04:00 135,168 –a—— c:\windows\system32\KemUtil.dll
2009-02-28 23:13 . 2007-04-23 04:00 110,592 –a—— c:\windows\system32\KemWnd.dll
2009-02-28 23:13 . 2007-04-23 04:00 69,632 –a—— c:\windows\system32\KemXML.dll
2009-02-28 23:12 . 2009-02-28 23:12 d——– c:\documents and settings\Owner\Application Data\McAfee.com Personal Firewall
2009-02-28 23:10 . 2009-02-28 23:10 d——– c:\program files\CCleaner
2009-02-28 23:06 . 2009-02-28 23:06 d——– c:\program files\Ventrilo
2009-02-28 23:06 . 2009-02-28 23:06 d——– c:\program files\Common Files\Wise Installation Wizard
2009-02-28 23:06 . 2009-02-28 23:06 262 –a—— c:\windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
2009-02-28 23:05 . 2009-03-02 16:05 d——– c:\program files\Xfire
2009-02-28 23:05 . 2009-03-03 19:09 d——– c:\documents and settings\Owner\Application Data\Xfire
2009-02-28 22:28 . 2009-02-28 22:28 2 –a—— c:\windows\msoffice.ini
2009-02-28 22:00 . 2009-02-28 21:05 d——– c:\windows\system32\config\systemprofile\WINDOWS
2009-02-28 22:00 . 2009-02-28 21:05 d——– c:\documents and settings\Default User\WINDOWS
2009-02-28 21:58 . 2009-02-28 21:58 8,192 –a—— c:\windows\REGLOCS.OLD
2009-02-28 21:56 . 2009-02-28 21:56 333 –a—— c:\windows\system32\$ncsp$.inf
2009-02-28 21:56 . 2009-02-28 21:56 0 –a—— c:\windows\system32\GATEWAY_T3504__GRC6520004224.MRK
2009-02-28 21:55 . 2009-02-28 21:55 d——– c:\windows\system32\Lang
2009-02-28 21:55 . 2009-02-28 21:55 940,794 –a—— c:\windows\system32\LoopyMusic.wav
2009-02-28 21:55 . 2009-02-28 21:55 146,650 –a—— c:\windows\system32\BuzzingBee.wav
2009-02-28 21:53 . 2009-02-28 23:12 2,752 –a—— c:\windows\system32\Status.MPF
2009-02-28 21:52 . 2009-02-28 22:28 d——– c:\documents and settings\Owner\Application Data\AOL
2009-02-28 21:42 . 2009-02-28 22:07 d–h—– c:\windows\$hf_mig$
2009-02-28 21:41 . 2009-02-28 21:41 d——– c:\documents and settings\All Users\Application Data\McAfee.com
2009-02-28 21:40 . 2009-02-28 23:29 d——– c:\program files\McAfee.com
2009-02-28 21:40 . 2009-02-28 21:40 d——– c:\documents and settings\All Users\Application Data\McAfee.com Personal Firewall
2009-02-28 21:40 . 2005-08-29 20:01 349,760 –a—— c:\windows\system32\mcinsctl.dll
2009-02-28 21:40 . 2005-05-24 20:23 288,320 –a—— c:\windows\system32\mcgdmgr.dll
2009-02-28 21:40 . 2004-08-04 12:00 221,184 –a—— c:\windows\system32\wmpns.dll
2009-02-28 21:39 . 2006-01-18 04:41 80,512 –a—— c:\windows\system32\drivers\Rtnicxp.sys
2009-02-28 21:39 . 2003-03-25 06:00 67,072 –a—— c:\windows\POWERCFG.EXE
2009-02-28 21:38 . 2009-02-28 21:38 d——– c:\program files\Common Files\Nullsoft
2009-02-28 21:38 . 2009-02-28 21:38 d——– c:\documents and settings\Owner\Application Data\You've Got Pictures Screensaver
2009-02-28 21:38 . 1999-11-10 12:05 86,016 –a—— c:\windows\unvise32qt.exe
2009-02-28 21:37 . 2009-03-01 15:36 d——– c:\program files\Common Files\Real
2009-02-28 21:37 . 2009-02-28 21:37 d——– c:\documents and settings\Owner\Application Data\SampleView
2009-02-28 21:37 . 2009-02-28 21:37 d——– c:\documents and settings\All Users\Application Data\Viewpoint
2009-02-28 21:37 . 2009-02-28 21:37 d——– c:\documents and settings\All Users\Application Data\QuickTime
2009-02-28 21:37 . 2009-02-28 21:37 d——– c:\documents and settings\All Users\Application Data\Pure Networks
2009-02-28 21:37 . 2000-05-22 17:58 647,872 –a—— c:\windows\system32\MSComCt2.ocx
2009-02-28 21:37 . 2000-05-22 01:00 203,976 –a—— c:\windows\system32\RichTx32.ocx
2009-02-28 21:37 . 2001-03-13 15:49 140,288 –a—— c:\windows\system32\COMDLG32.OCX
2009-02-28 21:37 . 2000-05-22 01:00 115,920 –a—— c:\windows\system32\MSInet.ocx
2009-02-28 21:37 . 2001-11-21 11:15 102,400 –a—— c:\windows\system32\SimpleRegistry.dll
2009-02-28 21:37 . 1999-04-17 03:06 10,752 –a—— c:\windows\system32\aamd532.dll
2009-02-28 21:36 . 2009-02-28 22:28 d——– c:\documents and settings\All Users\Application Data\AOL
2009-02-28 21:36 . 2009-02-28 21:38 1,112 –ah—– C:\IPH.PH
2009-02-28 21:36 . 2009-02-28 21:36 335 –a—— c:\windows\nsreg.dat
2009-02-28 21:35 . 2009-02-28 21:35 d——– c:\program files\MSN Encarta Plus
2009-02-28 21:35 . 2009-02-28 21:35 d——– c:\program files\Common Files\Adobe
2009-02-28 21:35 . 2009-02-28 22:37 d——– c:\documents and settings\All Users\Application Data\Napster
2009-02-28 21:35 . 2003-03-18 13:05 89,088 –a—— c:\windows\system32\atl71.dll
2009-02-28 21:34 . 2009-02-28 21:34 4 –a—— c:\windows\Pix11.dat
2009-02-28 21:32 . 2009-02-28 21:39 d——– c:\program files\Realtek
2009-02-28 21:31 . 2005-03-04 04:36 49,265 –a—— c:\windows\system32\jpicpl32.cpl
2009-02-28 21:31 . 2004-09-03 17:07 20,480 –a—— c:\windows\system32\Marker32.exe
2009-02-28 21:30 . 2009-02-28 21:31 d——– c:\program files\Java
2009-02-28 21:30 . 2009-02-28 21:30 d——– c:\program files\Common Files\Java
2009-02-28 21:30 . 2004-07-15 15:08 471,300 –a—— c:\windows\wallpe.exe
2009-02-28 21:30 . 2006-01-31 12:54 94,208 –a—— c:\windows\system32\bae.dll
2009-02-28 21:30 . 2004-04-22 18:48 30,056 –a—— c:\windows\system32\oemlogo.bmp
2009-02-28 21:29 . 2009-02-28 21:29 2 –a—— C:\AUDIT_INSTALL_IN_PROGRESS
2009-02-28 21:28 . 2004-03-22 15:17 24,816 –a—— c:\windows\system32\mdimon.dll
2009-02-28 21:28 . 2009-02-28 21:28 376 –a—— c:\windows\ODBC.INI
2009-02-28 21:26 . 2009-03-01 00:33 d–h—– c:\program files\InstallShield Installation Information
2009-02-28 21:26 . 2009-02-28 21:35 d——– c:\program files\Common Files\InstallShield
2009-02-28 21:21 . 2009-02-28 21:21 d——– c:\program files\Common Files\New Boundary
2009-02-28 21:21 . 2009-02-28 21:21 d——– c:\documents and settings\All Users\Application Data\Prism Deploy
2009-02-28 21:19 . 2009-02-28 21:19 2 -r-hs—- C:\USER
2009-02-28 21:19 . 2009-02-28 21:52 0 –a—— C:\REQUEST_OEMRESET_ENDUSER
2009-02-28 21:17 . 2001-08-17 13:48 12,160 –a—— c:\windows\system32\drivers\mouhid.sys
2009-02-28 21:17 . 2001-08-17 13:48 12,160 –a–c— c:\windows\system32\dllcache\mouhid.sys
2009-02-28 21:17 . 2001-08-17 14:02 9,600 –a—— c:\windows\system32\drivers\hidusb.sys
2009-02-28 21:17 . 2001-08-17 14:02 9,600 –a–c— c:\windows\system32\dllcache\hidusb.sys
2009-02-28 21:16 . 2004-08-04 00:08 26,624 –a—— c:\windows\system32\drivers\usbehci.sys
2009-02-28 21:16 . 2004-08-03 23:31 20,992 –a—— c:\windows\system32\drivers\RTL8139.sys
2009-02-28 21:16 . 2004-08-04 00:08 17,024 –a—— c:\windows\system32\drivers\usbohci.sys
2009-02-28 21:16 . 2004-08-04 01:56 7,168 –a—— c:\windows\system32\hccoin.dll
2009-02-28 21:11 . 2009-02-28 21:42 d——– c:\windows\creator
2009-02-28 21:11 . 2009-02-28 21:11 60 –a—— c:\windows\system32\SYSDRV.DAT
2009-02-28 21:10 . 2009-02-28 21:36 d——– c:\windows\SMINST
2009-02-28 21:10 . 2009-02-28 21:55 d——– c:\windows\I386
2009-02-28 21:10 . 2005-09-22 22:26 1,094,751 –a—— c:\windows\system32\drivers\AGRSM.sys
2009-02-28 21:10 . 2005-05-01 21:10 68,096 –a—— c:\windows\agrsmdel.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-01 04:05 ——— d—–w c:\program files\microsoft frontpage
.

((((((((((((((((((((((((((((( SnapShot@2009-03-01_ 0.07.16.54 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-01 07:45:59 787,904 —-a-w c:\windows\Downloaded Program Files\PurpleBean.exe
+ 2009-03-01 10:37:59 49,334 —-a-r c:\windows\Installer\{06C32EA0-4A22-4919-979A-8700715865B8}\_16A9981913383BD480C5C1.exe
+ 2009-03-01 10:37:59 287,934 —-a-r c:\windows\Installer\{06C32EA0-4A22-4919-979A-8700715865B8}\_21E30B652578A3CA82B737.exe
+ 2009-03-01 10:37:59 49,334 —-a-r c:\windows\Installer\{06C32EA0-4A22-4919-979A-8700715865B8}\_3CD681031019B09D231079.exe
+ 2009-03-01 10:37:59 287,934 —-a-r c:\windows\Installer\{06C32EA0-4A22-4919-979A-8700715865B8}\_7C9BE5D3E5F0C3BB96A0FC.exe
+ 2009-03-01 10:37:59 29,926 —-a-r c:\windows\Installer\{06C32EA0-4A22-4919-979A-8700715865B8}\_84C60C2FC68B0EEBE7A589.exe
+ 2009-03-02 05:04:45 27,136 —-a-r c:\windows\Installer\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}\AppleSoftwareUpdateIco.exe
- 1998-10-30 00:45:06 306,688 —-a-w c:\windows\IsUninst.exe
+ 1998-10-29 23:45:06 306,688 —-a-w c:\windows\IsUninst.exe
- 2004-08-11 09:45:04 480,768 —-a-w c:\windows\system32\Audiodev.dll
+ 2006-08-25 05:30:12 276,480 —-a-w c:\windows\system32\audiodev.dll
- 2004-08-11 09:45:04 233,472 —-a-w c:\windows\system32\blackbox.dll
+ 2006-08-25 05:30:12 537,600 —-a-w c:\windows\system32\blackbox.dll
- 2004-08-11 09:45:04 161,792 —-a-w c:\windows\system32\cewmdm.dll
+ 2006-08-25 05:30:12 228,352 —-a-w c:\windows\system32\cewmdm.dll
+ 2006-12-05 22:37:56 183,072 —-a-w c:\windows\system32\cVX3000.dll
+ 2005-02-06 02:45:26 2,222,800 —-a-w c:\windows\system32\d3dx9_24.dll
+ 2005-03-19 00:19:58 2,337,488 —-a-w c:\windows\system32\d3dx9_25.dll
+ 2005-05-26 22:34:52 2,297,552 —-a-w c:\windows\system32\d3dx9_26.dll
+ 2005-07-23 02:59:04 2,319,568 —-a-w c:\windows\system32\d3dx9_27.dll
+ 2005-12-06 01:09:18 2,323,664 —-a-w c:\windows\system32\d3dx9_28.dll
+ 2006-02-03 15:43:16 2,332,368 —-a-w c:\windows\system32\d3dx9_29.dll
+ 2006-03-31 19:40:58 2,388,176 —-a-w c:\windows\system32\d3dx9_30.dll
+ 2006-09-28 23:05:20 2,414,360 —-a-w c:\windows\system32\d3dx9_31.dll
- 2004-08-11 09:45:04 233,472 -c–a-w c:\windows\system32\dllcache\blackbox.dll
+ 2006-08-25 05:30:12 537,600 -c–a-w c:\windows\system32\dllcache\blackbox.dll
+ 2004-08-04 06:10:18 17,024 -c–a-w c:\windows\system32\dllcache\ccdecode.sys
- 2004-08-11 09:45:04 161,792 -c–a-w c:\windows\system32\dllcache\cewmdm.dll
+ 2006-08-25 05:30:12 228,352 -c–a-w c:\windows\system32\dllcache\cewmdm.dll
- 2004-08-04 07:08:00 60,288 -c–a-w c:\windows\system32\dllcache\drmk.sys
+ 2004-08-04 06:08:00 60,288 -c–a-w c:\windows\system32\dllcache\drmk.sys
- 2004-08-11 09:45:04 527,360 -c–a-w c:\windows\system32\dllcache\drmv2clt.dll
+ 2006-08-25 05:30:14 990,208 -c–a-w c:\windows\system32\dllcache\drmv2clt.dll
+ 2004-08-04 07:56:44 47,616 -c–a-w c:\windows\system32\dllcache\iyuv_32.dll
- 2004-08-04 07:15:22 140,928 -c–a-w c:\windows\system32\dllcache\ks.sys
+ 2004-08-04 06:15:22 140,928 -c–a-w c:\windows\system32\dllcache\ks.sys
- 2004-08-04 08:56:44 4,096 -c–a-w c:\windows\system32\dllcache\ksuser.dll
+ 2004-08-04 07:56:44 4,096 -c–a-w c:\windows\system32\dllcache\ksuser.dll
- 2004-08-11 09:45:04 6,656 -c–a-w c:\windows\system32\dllcache\laprxy.dll
+ 2006-08-25 05:30:16 11,264 -c–a-w c:\windows\system32\dllcache\LAPRXY.dll
- 2004-08-11 09:45:04 96,768 -c–a-w c:\windows\system32\dllcache\logagent.exe
+ 2006-08-25 03:31:04 100,864 -c–a-w c:\windows\system32\dllcache\logagent.exe
- 2004-08-04 19:00:00 310,272 -c–a-w c:\windows\system32\dllcache\mp43dmod.dll
+ 2006-08-25 05:30:18 4,096 -c–a-w c:\windows\system32\dllcache\MP43DMOD.dll
- 2004-08-04 19:00:00 384,512 -c–a-w c:\windows\system32\dllcache\mp4sdmod.dll
+ 2006-08-25 05:30:18 4,096 -c–a-w c:\windows\system32\dllcache\MP4SDMOD.dll
- 2004-08-04 19:00:00 240,640 -c–a-w c:\windows\system32\dllcache\mpg4dmod.dll
+ 2006-08-25 05:30:18 4,096 -c–a-w c:\windows\system32\dllcache\MPG4DMOD.dll
- 2004-08-11 09:45:04 141,312 -c–a-w c:\windows\system32\dllcache\msnetobj.dll
+ 2006-08-25 05:30:18 179,712 -c–a-w c:\windows\system32\dllcache\msnetobj.dll
- 2004-08-11 09:45:04 25,088 -c–a-w c:\windows\system32\dllcache\mspmsnsv.dll
+ 2006-08-25 05:30:20 27,648 -c–a-w c:\windows\system32\dllcache\mspmsnsv.dll
- 2004-08-11 09:45:04 169,472 -c–a-w c:\windows\system32\dllcache\mspmsp.dll
+ 2006-08-25 05:30:20 175,104 -c–a-w c:\windows\system32\dllcache\mspmsp.dll
- 2004-08-11 09:45:04 360,176 -c–a-w c:\windows\system32\dllcache\msscp.dll
+ 2006-08-25 05:30:20 414,208 -c–a-w c:\windows\system32\dllcache\msscp.dll
+ 2004-08-04 05:58:40 5,504 -c–a-w c:\windows\system32\dllcache\mstee.sys
- 2004-08-11 09:45:04 311,296 -c–a-w c:\windows\system32\dllcache\mswmdm.dll
+ 2006-08-25 05:30:20 320,512 -c–a-w c:\windows\system32\dllcache\mswmdm.dll
+ 2004-08-04 07:56:46 17,408 -c–a-w c:\windows\system32\dllcache\msyuv.dll
+ 2004-08-04 06:10:30 85,376 -c–a-w c:\windows\system32\dllcache\nabtsfec.sys
+ 2004-08-04 06:10:14 10,880 -c–a-w c:\windows\system32\dllcache\ndisip.sys
+ 2004-03-16 18:58:20 136,960 -c–a-w c:\windows\system32\dllcache\portcls.sys
- 2004-08-11 09:45:04 221,184 -c–a-w c:\windows\system32\dllcache\qasf.dll
+ 2006-08-25 05:30:22 210,432 -c–a-w c:\windows\system32\dllcache\qasf.dll
+ 2004-08-04 06:10:18 11,136 -c–a-w c:\windows\system32\dllcache\slip.sys
- 2004-08-04 07:08:04 48,640 -c–a-w c:\windows\system32\dllcache\stream.sys
+ 2004-08-04 06:08:04 48,640 -c–a-w c:\windows\system32\dllcache\stream.sys
+ 2004-08-04 06:10:14 15,360 -c–a-w c:\windows\system32\dllcache\streamip.sys
+ 2001-08-18 05:36:34 8,192 -c–a-w c:\windows\system32\dllcache\tsbyuv.dll
+ 2004-08-04 07:56:48 53,760 -c–a-w c:\windows\system32\dllcache\vfwwdm32.dll
- 2004-08-11 09:45:04 380,144 -c–a-w c:\windows\system32\dllcache\wmadmod.dll
+ 2006-08-25 05:30:22 757,248 -c–a-w c:\windows\system32\dllcache\WMADMOD.dll
- 2004-08-11 09:45:04 712,704 -c–a-w c:\windows\system32\dllcache\wmadmoe.dll
+ 2006-08-25 05:30:22 1,118,208 -c–a-w c:\windows\system32\dllcache\WMADMOE.dll
- 2004-08-11 09:45:04 229,376 -c–a-w c:\windows\system32\dllcache\wmasf.dll
+ 2006-08-25 05:30:22 222,208 -c–a-w c:\windows\system32\dllcache\WMASF.dll
- 2004-08-11 09:45:04 30,208 -c–a-w c:\windows\system32\dllcache\wmdmlog.dll
+ 2006-08-25 05:30:22 33,792 -c–a-w c:\windows\system32\dllcache\wmdmlog.dll
- 2004-08-11 09:45:04 34,304 -c–a-w c:\windows\system32\dllcache\wmdmps.dll
+ 2006-08-25 05:30:22 37,376 -c–a-w c:\windows\system32\dllcache\wmdmps.dll
- 2004-08-11 09:45:04 150,016 -c–a-w c:\windows\system32\dllcache\wmidx.dll
+ 2006-08-25 05:30:24 157,184 -c–a-w c:\windows\system32\dllcache\wmidx.dll
- 2004-08-11 09:45:04 1,027,072 -c–a-w c:\windows\system32\dllcache\wmnetmgr.dll
+ 2006-08-25 05:30:24 937,984 -c–a-w c:\windows\system32\dllcache\WMNetMgr.dll
- 2004-08-11 09:45:04 773,368 -c–a-w c:\windows\system32\dllcache\wmsdmod.dll
+ 2006-08-25 05:30:26 4,096 -c–a-w c:\windows\system32\dllcache\wmsdmod.dll
- 2004-08-11 09:45:04 1,116,160 -c–a-w c:\windows\system32\dllcache\wmsdmoe2.dll
+ 2006-08-25 05:30:26 4,096 -c–a-w c:\windows\system32\dllcache\wmsdmoe2.dll
- 2004-08-11 09:45:06 531,192 -c–a-w c:\windows\system32\dllcache\wmspdmod.dll
+ 2006-08-25 05:30:26 603,648 -c–a-w c:\windows\system32\dllcache\WMSPDMOD.dll
- 2004-08-11 09:45:06 936,960 -c–a-w c:\windows\system32\dllcache\wmspdmoe.dll
+ 2006-08-25 05:30:26 1,327,616 -c–a-w c:\windows\system32\dllcache\WMSPDMOE.dll
- 2004-08-11 09:45:06 2,362,104 -c–a-w c:\windows\system32\dllcache\wmvcore.dll
+ 2006-08-25 05:30:26 2,450,944 -c–a-w c:\windows\system32\dllcache\wmvcore.dll
- 2004-08-11 09:45:06 871,160 -c–a-w c:\windows\system32\dllcache\wmvdmod.dll
+ 2006-08-25 05:30:26 4,096 -c–a-w c:\windows\system32\dllcache\wmvdmod.dll
- 2004-08-11 09:45:06 999,424 -c–a-w c:\windows\system32\dllcache\wmvdmoe2.dll
+ 2006-08-25 05:30:26 4,096 -c–a-w c:\windows\system32\dllcache\wmvdmoe2.dll
+ 2004-08-04 06:10:22 19,328 -c–a-w c:\windows\system32\dllcache\wstcodec.sys
+ 2007-10-12 01:40:00 9,096 —-a-w c:\windows\system32\drivers\amdide.sys
+ 2004-08-04 06:10:18 17,024 —-a-w c:\windows\system32\drivers\CCDECODE.sys
- 2004-08-04 07:08:00 60,288 —-a-w c:\windows\system32\drivers\drmk.sys
+ 2004-08-04 06:08:00 60,288 —-a-w c:\windows\system32\drivers\drmk.sys
- 2004-08-04 07:15:22 140,928 —-a-w c:\windows\system32\drivers\ks.sys
+ 2004-08-04 06:15:22 140,928 —-a-w c:\windows\system32\drivers\ks.sys
+ 2004-08-04 05:58:40 5,504 —-a-w c:\windows\system32\drivers\MSTEE.sys
+ 2004-08-04 06:10:30 85,376 —-a-w c:\windows\system32\drivers\NABTSFEC.sys
+ 2004-08-04 06:10:14 10,880 —-a-w c:\windows\system32\drivers\NdisIP.sys
+ 2004-08-04 06:10:18 11,136 —-a-w c:\windows\system32\drivers\SLIP.sys
- 2004-08-04 07:08:04 48,640 —-a-w c:\windows\system32\drivers\stream.sys
+ 2004-08-04 06:08:04 48,640 —-a-w c:\windows\system32\drivers\stream.sys
+ 2004-08-04 06:10:14 15,360 —-a-w c:\windows\system32\drivers\StreamIP.sys
+ 2006-08-25 05:30:26 667,648 ——w c:\windows\system32\drivers\umdf\wpdmtpdr.dll
+ 2006-12-05 22:39:14 1,964,064 —-a-w c:\windows\system32\drivers\VX3000.sys
- 2004-08-11 09:45:06 18,944 —-a-w c:\windows\system32\drivers\wpdusb.sys
+ 2006-08-25 03:26:02 38,656 —-a-w c:\windows\system32\drivers\wpdusb.sys
+ 2004-08-04 06:10:22 19,328 —-a-w c:\windows\system32\drivers\WSTCODEC.SYS
+ 2006-08-25 03:27:06 249,344 ——w c:\windows\system32\drmupgds.exe
- 2004-08-11 09:45:04 527,360 —-a-w c:\windows\system32\drmv2clt.dll
+ 2006-08-25 05:30:14 990,208 —-a-w c:\windows\system32\drmv2clt.dll
+ 2006-12-19 18:28:44 199,448 -c–a-w c:\windows\system32\DRVSTORE\NX6000_2E35915C239DFE541CDDDD6085121FF3936DECC8\LCCoin13.dll
+ 2006-12-19 18:27:58 31,512 -c–a-w c:\windows\system32\DRVSTORE\NX6000_2E35915C239DFE541CDDDD6085121FF3936DECC8\nx6000.sys
+ 2006-12-05 22:37:14 109,344 -c–a-w c:\windows\system32\DRVSTORE\VX1000_F0D00687F2C6654412F544D2A9CB1DB0F291EC6A\1033\VX1000.dll
+ 2006-12-05 22:37:56 183,072 -c–a-w c:\windows\system32\DRVSTORE\VX1000_F0D00687F2C6654412F544D2A9CB1DB0F291EC6A\cVX1000.dll
+ 2006-12-05 22:38:04 199,456 -c–a-w c:\windows\system32\DRVSTORE\VX1000_F0D00687F2C6654412F544D2A9CB1DB0F291EC6A\LCCoin13.dll
+ 2006-12-05 22:38:42 502,560 -c–a-w c:\windows\system32\DRVSTORE\VX1000_F0D00687F2C6654412F544D2A9CB1DB0F291EC6A\TwainUI.dll
+ 2006-12-05 22:38:32 473,888 -c–a-w c:\windows\system32\DRVSTORE\VX1000_F0D00687F2C6654412F544D2A9CB1DB0F291EC6A\vVX1000.dll
+ 2006-12-05 22:38:58 707,360 -c–a-w c:\windows\system32\DRVSTORE\VX1000_F0D00687F2C6654412F544D2A9CB1DB0F291EC6A\vVX1000.exe
+ 2006-12-05 22:39:12 1,963,680 -c–a-w c:\windows\system32\DRVSTORE\VX1000_F0D00687F2C6654412F544D2A9CB1DB0F291EC6A\VX1000.sys
+ 2006-12-05 22:37:22 109,344 -c–a-w c:\windows\system32\DRVSTORE\VX3000_0433D7FB800BA3CD73AE2E16AC2F9C4C9B45C2DE\1033\VX3000.dll
+ 2006-12-05 22:37:56 183,072 -c–a-w c:\windows\system32\DRVSTORE\VX3000_0433D7FB800BA3CD73AE2E16AC2F9C4C9B45C2DE\cVX3000.dll
+ 2006-12-05 22:38:04 199,456 -c–a-w c:\windows\system32\DRVSTORE\VX3000_0433D7FB800BA3CD73AE2E16AC2F9C4C9B45C2DE\LCCoin13.dll
+ 2006-12-05 22:38:42 502,560 -c–a-w c:\windows\system32\DRVSTORE\VX3000_0433D7FB800BA3CD73AE2E16AC2F9C4C9B45C2DE\TwainUI.dll
+ 2006-12-05 22:38:30 473,888 -c–a-w c:\windows\system32\DRVSTORE\VX3000_0433D7FB800BA3CD73AE2E16AC2F9C4C9B45C2DE\vVX3000.dll
+ 2006-12-05 22:39:00 707,360 -c–a-w c:\windows\system32\DRVSTORE\VX3000_0433D7FB800BA3CD73AE2E16AC2F9C4C9B45C2DE\vVX3000.exe
+ 2006-12-05 22:39:14 1,964,064 -c–a-w c:\windows\system32\DRVSTORE\VX3000_0433D7FB800BA3CD73AE2E16AC2F9C4C9B45C2DE\VX3000.sys
+ 2006-12-19 18:28:14 113,432 -c–a-w c:\windows\system32\DRVSTORE\VX6000_2DD332AD17334A76BABFAE3D3F1C0795D0B900F6\1033\VX6000.dll
+ 2006-12-19 18:28:42 183,064 -c–a-w c:\windows\system32\DRVSTORE\VX6000_2DD332AD17334A76BABFAE3D3F1C0795D0B900F6\cVX6000.dll
+ 2006-12-19 18:28:44 199,448 -c–a-w c:\windows\system32\DRVSTORE\VX6000_2DD332AD17334A76BABFAE3D3F1C0795D0B900F6\LCCoin13.dll
+ 2006-12-19 18:28:52 482,072 -c–a-w c:\windows\system32\DRVSTORE\VX6000_2DD332AD17334A76BABFAE3D3F1C0795D0B900F6\vVX6000.dll
+ 2006-12-19 18:29:00 994,072 -c–a-w c:\windows\system32\DRVSTORE\VX6000_2DD332AD17334A76BABFAE3D3F1C0795D0B900F6\vVX6000.exe
+ 2006-12-19 18:29:04 2,383,256 -c–a-w c:\windows\system32\DRVSTORE\VX6000_2DD332AD17334A76BABFAE3D3F1C0795D0B900F6\VX6000Xp.sys
+ 2006-12-19 18:27:58 33,688 -c–a-w c:\windows\system32\DRVSTORE\VX6000_2DD332AD17334A76BABFAE3D3F1C0795D0B900F6\VX6KCamd.sys
+ 2006-12-19 18:28:54 506,648 -c–a-w c:\windows\system32\DRVSTORE\VX6000_2DD332AD17334A76BABFAE3D3F1C0795D0B900F6\VX6KTUI.dll
- 2004-08-04 00:56:44 47,616 —-a-w c:\windows\system32\iyuv_32.dll
+ 2004-08-04 07:56:44 47,616 —-a-w c:\windows\system32\iyuv_32.dll
- 2004-08-04 08:56:44 4,096 —-a-w c:\windows\system32\ksuser.dll
+ 2004-08-04 07:56:44 4,096 —-a-w c:\windows\system32\ksuser.dll
- 2004-08-11 09:45:04 6,656 —-a-w c:\windows\system32\laprxy.dll
+ 2006-08-25 05:30:16 11,264 —-a-w c:\windows\system32\LAPRXY.dll
+ 2006-12-05 22:38:04 199,456 —-a-w c:\windows\system32\LCCoin13.dll
- 2004-08-11 09:45:04 96,768 —-a-w c:\windows\system32\logagent.exe
+ 2006-08-25 03:31:04 100,864 —-a-w c:\windows\system32\logagent.exe
+ 2006-08-25 05:30:18 211,968 ——w c:\windows\system32\MFPLAT.dll
+ 2006-08-25 05:30:18 258,560 ——w c:\windows\system32\MP43DECD.dll
- 2004-08-04 19:00:00 310,272 —-a-w c:\windows\system32\mp43dmod.dll
+ 2006-08-25 05:30:18 4,096 —-a-w c:\windows\system32\MP43DMOD.dll
+ 2006-08-25 05:30:18 316,928 ——w c:\windows\system32\MP4SDECD.dll
- 2004-08-04 19:00:00 384,512 —-a-w c:\windows\system32\mp4sdmod.dll
+ 2006-08-25 05:30:18 4,096 —-a-w c:\windows\system32\MP4SDMOD.dll
+ 2006-08-25 05:30:18 259,072 ——w c:\windows\system32\MPG4DECD.dll
- 2004-08-04 19:00:00 240,640 —-a-w c:\windows\system32\mpg4dmod.dll
+ 2006-08-25 05:30:18 4,096 —-a-w c:\windows\system32\MPG4DMOD.dll
- 2004-08-04 00:56:58 294,912 —-a-w c:\windows\system32\msh263.drv
+ 2004-08-04 07:56:58 294,912 —-a-w c:\windows\system32\msh263.drv
- 2004-08-11 09:45:04 141,312 —-a-w c:\windows\system32\msnetobj.dll
+ 2006-08-25 05:30:18 179,712 —-a-w c:\windows\system32\msnetobj.dll
- 2004-08-11 09:45:04 25,088 —-a-w c:\windows\system32\MsPMSNSv.dll
+ 2006-08-25 05:30:20 27,648 —-a-w c:\windows\system32\mspmsnsv.dll
- 2004-08-11 09:45:04 169,472 —-a-w c:\windows\system32\MsPMSP.dll
+ 2006-08-25 05:30:20 175,104 —-a-w c:\windows\system32\mspmsp.dll
- 2004-08-11 09:45:04 360,176 —-a-w c:\windows\system32\MSSCP.dll
+ 2006-08-25 05:30:20 414,208 —-a-w c:\windows\system32\msscp.dll
- 2004-08-11 09:45:04 311,296 —-a-w c:\windows\system32\MSWMDM.dll
+ 2006-08-25 05:30:20 320,512 —-a-w c:\windows\system32\mswmdm.dll
- 2004-08-04 00:56:46 17,408 —-a-w c:\windows\system32\msyuv.dll
+ 2004-08-04 07:56:46 17,408 —-a-w c:\windows\system32\msyuv.dll
+ 2006-08-25 05:30:22 284,160 ——w c:\windows\system32\PortableDeviceApi.dll
+ 2006-08-25 05:30:22 101,888 ——w c:\windows\system32\PortableDeviceClassExtension.dll
+ 2006-08-25 05:30:22 166,912 ——w c:\windows\system32\PortableDeviceTypes.dll
+ 2006-08-25 05:30:22 132,096 ——w c:\windows\system32\PortableDeviceWiaCompat.dll
+ 2006-08-25 05:30:22 198,144 ——w c:\windows\system32\PortableDeviceWMDRM.dll
- 2004-08-11 09:45:04 221,184 —-a-w c:\windows\system32\qasf.dll
+ 2006-08-25 05:30:22 210,432 —-a-w c:\windows\system32\qasf.dll
+ 2004-08-04 07:08:00 60,288 —-a-w c:\windows\system32\ReinstallBackups\0005\DriverFiles\i386\drmk.sys
+ 2004-08-04 06:15:22 140,928 —-a-w c:\windows\system32\ReinstallBackups\0005\DriverFiles\i386\ks.sys
+ 2004-08-04 07:56:44 4,096 —-a-w c:\windows\system32\ReinstallBackups\0005\DriverFiles\i386\ksuser.dll
+ 2004-03-16 18:58:20 136,960 —-a-w c:\windows\system32\ReinstallBackups\0005\DriverFiles\i386\portcls.sys
+ 2004-08-04 07:08:04 48,640 —-a-w c:\windows\system32\ReinstallBackups\0005\DriverFiles\i386\stream.sys
+ 2004-08-04 06:07:56 59,264 —-a-w c:\windows\system32\ReinstallBackups\0005\DriverFiles\i386\USBAUDIO.sys
+ 2004-08-04 08:56:58 23,552 —-a-w c:\windows\system32\ReinstallBackups\0005\DriverFiles\i386\wdmaud.drv
+ 2004-08-04 19:00:00 95,360 —-a-w c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
+ 2004-08-04 19:00:00 3,328 —-a-w c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\pciide.sys
+ 2004-08-04 19:00:00 25,088 —-a-w c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\pciidex.sys
- 2001-08-17 22:36:34 8,192 —-a-w c:\windows\system32\tsbyuv.dll
+ 2001-08-18 05:36:34 8,192 —-a-w c:\windows\system32\tsbyuv.dll
- 2004-08-11 09:45:04 47,104 —-a-w c:\windows\system32\uwdf.exe
+ 2006-08-25 05:42:14 8,704 —-a-w c:\windows\system32\uwdf.exe
+ 2004-08-04 07:56:48 53,760 —-a-w c:\windows\system32\vfwwdm32.dll
- 2004-08-11 09:45:04 15,872 —-a-w c:\windows\system32\wdfapi.dll
+ 2006-08-25 05:30:22 4,096 —-a-w c:\windows\system32\wdfapi.dll
- 2004-08-11 09:45:04 38,912 —-a-w c:\windows\system32\wdfmgr.exe
+ 2006-08-25 05:42:14 8,704 —-a-w c:\windows\system32\wdfmgr.exe
- 2004-08-11 09:45:04 380,144 —-a-w c:\windows\system32\wmadmod.dll
+ 2006-08-25 05:30:22 757,248 —-a-w c:\windows\system32\WMADMOD.dll
- 2004-08-11 09:45:04 712,704 —-a-w c:\windows\system32\wmadmoe.dll
+ 2006-08-25 05:30:22 1,118,208 —-a-w c:\windows\system32\WMADMOE.dll
- 2004-08-11 09:45:04 229,376 —-a-w c:\windows\system32\wmasf.dll
+ 2006-08-25 05:30:22 222,208 —-a-w c:\windows\system32\WMASF.dll
- 2004-08-11 09:45:04 30,208 —-a-w c:\windows\system32\WMDMLOG.dll
+ 2006-08-25 05:30:22 33,792 —-a-w c:\windows\system32\wmdmlog.dll
- 2004-08-11 09:45:04 34,304 —-a-w c:\windows\system32\WMDMPS.dll
+ 2006-08-25 05:30:22 37,376 —-a-w c:\windows\system32\wmdmps.dll
- 2004-08-11 09:45:04 344,064 —-a-w c:\windows\system32\WMDRMdev.dll
+ 2006-08-25 05:30:22 428,032 —-a-w c:\windows\system32\wmdrmdev.dll
- 2004-08-11 09:45:04 290,816 —-a-w c:\windows\system32\WMDRMNet.dll
+ 2006-08-25 05:30:24 347,648 —-a-w c:\windows\system32\wmdrmnet.dll
+ 2006-08-25 05:30:24 532,992 ——w c:\windows\system32\wmdrmsdk.dll
- 2004-08-11 09:45:04 150,016 —-a-w c:\windows\system32\wmidx.dll
+ 2006-08-25 05:30:24 157,184 —-a-w c:\windows\system32\wmidx.dll
- 2004-08-11 09:45:04 1,027,072 —-a-w c:\windows\system32\wmnetmgr.dll
+ 2006-08-25 05:30:24 937,984 —-a-w c:\windows\system32\WMNetMgr.dll
- 2004-08-11 09:45:04 773,368 —-a-w c:\windows\system32\wmsdmod.dll
+ 2006-08-25 05:30:26 4,096 —-a-w c:\windows\system32\wmsdmod.dll
- 2004-08-11 09:45:04 1,116,160 —-a-w c:\windows\system32\wmsdmoe2.dll
+ 2006-08-25 05:30:26 4,096 —-a-w c:\windows\system32\wmsdmoe2.dll
- 2004-08-11 09:45:06 531,192 —-a-w c:\windows\system32\wmspdmod.dll
+ 2006-08-25 05:30:26 603,648 —-a-w c:\windows\system32\WMSPDMOD.dll
- 2004-08-11 09:45:06 936,960 —-a-w c:\windows\system32\wmspdmoe.dll
+ 2006-08-25 05:30:26 1,327,616 —-a-w c:\windows\system32\WMSPDMOE.dll
- 2004-08-11 09:45:06 1,181,944 —-a-w c:\windows\system32\wmvadvd.dll
+ 2006-08-25 05:30:26 4,096 —-a-w c:\windows\system32\WMVADVD.dll
- 2004-08-11 09:45:06 1,509,376 —-a-w c:\windows\system32\WMVADVE.DLL
+ 2006-08-25 05:30:26 4,096 —-a-w c:\windows\system32\WMVADVE.DLL
- 2004-08-11 09:45:06 2,362,104 —-a-w c:\windows\system32\wmvcore.dll
+ 2006-08-25 05:30:26 2,450,944 —-a-w c:\windows\system32\wmvcore.dll
+ 2006-08-25 05:30:26 1,539,584 ——w c:\windows\system32\WMVDECOD.dll
- 2004-08-11 09:45:06 871,160 —-a-w c:\windows\system32\wmvdmod.dll
+ 2006-08-25 05:30:26 4,096 —-a-w c:\windows\system32\wmvdmod.dll
- 2004-08-11 09:45:06 999,424 —-a-w c:\windows\system32\wmvdmoe2.dll
+ 2006-08-25 05:30:26 4,096 —-a-w c:\windows\system32\wmvdmoe2.dll
+ 2006-08-25 05:30:26 1,532,416 ——w c:\windows\system32\WMVENCOD.dll
+ 2006-08-25 05:30:26 1,392,128 ——w c:\windows\system32\WMVSDECD.dll
+ 2006-08-25 05:30:26 790,016 ——w c:\windows\system32\WMVSENCD.dll
+ 2006-08-25 05:30:26 656,896 ——w c:\windows\system32\WMVXENCD.dll
- 2004-08-11 09:45:06 38,912 —-a-w c:\windows\system32\wpd_ci.dll
+ 2006-08-25 05:30:28 629,760 —-a-w c:\windows\system32\wpd_ci.dll
- 2004-08-11 09:45:06 61,952 —-a-w c:\windows\system32\wpdconns.dll
+ 2006-08-25 05:30:26 35,840 —-a-w c:\windows\system32\wpdconns.dll
- 2004-08-11 09:45:06 114,176 —-a-w c:\windows\system32\wpdmtp.dll
+ 2006-08-25 05:30:26 154,624 —-a-w c:\windows\system32\wpdmtp.dll
- 2004-08-11 09:45:06 66,560 —-a-w c:\windows\system32\wpdmtpus.dll
+ 2006-08-25 05:30:28 63,488 —-a-w c:\windows\system32\wpdmtpus.dll
+ 2006-08-25 05:30:28 2,589,184 ——w c:\windows\system32\WpdShext.dll
+ 2006-08-25 03:26:22 17,408 ——w c:\windows\system32\wpdshextautoplay.exe
+ 2006-08-25 05:30:28 133,120 ——w c:\windows\system32\WPDShServiceObj.dll
- 2004-08-11 09:45:06 327,680 —-a-w c:\windows\system32\wpdsp.dll
+ 2006-08-25 05:30:28 349,184 —-a-w c:\windows\system32\wpdsp.dll
+ 2006-02-03 15:41:26 14,032 —-a-w c:\windows\system32\x3daudio1_0.dll
+ 2006-09-28 23:03:28 15,128 —-a-w c:\windows\system32\x3daudio1_1.dll
+ 2006-02-03 15:42:06 230,096 —-a-w c:\windows\system32\xactengine2_0.dll
+ 2006-03-31 19:39:48 229,584 —-a-w c:\windows\system32\xactengine2_1.dll
+ 2006-05-31 14:24:16 230,168 —-a-w c:\windows\system32\xactengine2_2.dll
+ 2006-07-28 16:30:32 236,824 —-a-w c:\windows\system32\xactengine2_3.dll
+ 2006-09-28 23:05:56 237,848 —-a-w c:\windows\system32\xactengine2_4.dll
- 2009-02-11 00:14:12 42,320 —-a-w c:\windows\system32\xfcodec.dll
+ 2009-02-26 18:46:50 42,320 —-a-w c:\windows\system32\xfcodec.dll
+ 2006-03-31 19:39:24 62,672 —-a-w c:\windows\system32\xinput1_1.dll
+ 2006-07-28 16:30:14 62,744 —-a-w c:\windows\system32\xinput1_2.dll
+ 2006-09-28 23:04:02 68,888 —-a-w c:\windows\system32\xinput1_3.dll
+ 2005-12-06 01:07:30 61,136 —-a-w c:\windows\system32\xinput9_1_0.dll
+ 2006-12-05 22:38:42 502,560 —-a-w c:\windows\twain_32\VX3000\TwainUI.dll
+ 2006-12-05 22:38:30 473,888 —-a-w c:\windows\vVX3000.dll
+ 2006-12-05 22:39:00 707,360 —-a-w c:\windows\vVX3000.exe
+ 2006-12-05 22:37:22 109,344 —-a-w c:\windows\VX3000.dll
+ 2006-12-02 05:54:32 479,232 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2006-12-02 05:54:34 548,864 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
+ 2006-12-02 05:54:32 626,688 —-a-w c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2009-02-22 2272592]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 3]
–a—— 2009-02-22 14:45 2272592 c:\program files\IObit\Advanced SystemCare 3\AWC.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
–a—— 2007-01-12 17:48 275800 c:\program files\Microsoft LifeCam\LifeExp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OASClnt]
–a—— 2005-08-11 23:02 53248 c:\program files\McAfee.com\VSO\oasclnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
–a—— 2002-09-13 23:42 212992 c:\windows\SMINST\Recguard.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
–a—— 2005-02-25 18:24 966656 c:\windows\creator\Remind_XP.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
–a—— 2005-08-10 13:49 163840 c:\program files\McAfee.com\VSO\mcvsshld.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask]
–a—— 2005-07-08 19:18 151552 c:\progra~1\McAfee.com\VSO\mcmnhdlr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX3000]
–a—— 2006-12-05 15:39 707360 c:\windows\vVX3000.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
–a—— 2005-05-03 04:43 69632 c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
–a—— 2006-04-04 03:44 16120832 c:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\IJJIGame\\PLauncher.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\WINDOWS\\Downloaded Program Files\\PurpleBean.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9562:TCP"= 9562:TCP:rrqfgytk

— Other Services/Drivers In Memory —

*Deregistered* - abp480n5
*Deregistered* - adpu160m
*Deregistered* - AFD
*Deregistered* - agp440
*Deregistered* - agpCPQ
*Deregistered* - Aha154x
*Deregistered* - aic78u2
*Deregistered* - aic78xx
*Deregistered* - AliIde
*Deregistered* - alim1541
*Deregistered* - amdagp
*Deregistered* - amsint
*Deregistered* - asc
*Deregistered* - asc3350p
*Deregistered* - asc3550
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - Beep
*Deregistered* - cbidf
*Deregistered* - cd20xrnt
*Deregistered* - Cdfs
*Deregistered* - CmdIde
*Deregistered* - Cpqarray
*Deregistered* - CryptSvc
*Deregistered* - dac2w2k
*Deregistered* - dac960nt
*Deregistered* - Dhcp
*Deregistered* - Dnscache
*Deregistered* - dpti2o
*Deregistered* - dump_wmimmc
*Deregistered* - Fastfat
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - hpn
*Deregistered* - i2omgmt
*Deregistered* - i2omp
*Deregistered* - ini910u
*Deregistered* - IntelIde
*Deregistered* - IPSec
*Deregistered* - KSecDD
*Deregistered* - mnmdd
*Deregistered* - MountMgr
*Deregistered* - mraid35x
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - PartMgr
*Deregistered* - perc2
*Deregistered* - perc2hib
*Deregistered* - PptpMiniport
*Deregistered* - PSched
*Deregistered* - ql1080
*Deregistered* - Ql10wnt
*Deregistered* - ql12160
*Deregistered* - ql1240
*Deregistered* - ql1280
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - RpcSs
*Deregistered* - sisagp
*Deregistered* - Sparrow
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - swenum
*Deregistered* - sym_hi
*Deregistered* - sym_u3
*Deregistered* - symc810
*Deregistered* - symc8xx
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - TermDD
*Deregistered* - TosIde
*Deregistered* - ultra
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - viaagp
*Deregistered* - ViaIde
*Deregistered* - VolSnap
*Deregistered* - Wanarp
*Deregistered* - Wdf01000
*Deregistered* - winmgmt

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
kqhxqnbyf
.
Contents of the 'Scheduled Tasks' folder

2009-03-01 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-04 12:00]

2009-03-01 c:\windows\Tasks\ISP signup reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-04 12:00]

2009-03-01 c:\windows\Tasks\ISP signup reminder 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-04 12:00]

2009-03-01 c:\windows\Tasks\Microsoft_Hardware_Launch_LifeExp_exe.job
- c:\program files\Microsoft LifeCam\LifeExp.exe [2007-01-12 17:48]

2009-03-01 c:\windows\Tasks\Microsoft_Hardware_Launch_vVX3000_exe.job
- c:\windows\vVX3000.exe [2006-12-05 15:39]
.
.
——- Supplementary Scan ——-
.
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\g1t8tieb.default\
FF - prefs.js: browser.startup.homepage - sfront.ijji.com
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPJPI150_02.dll
FF - plugin: c:\program files\Java\jre1.5.0_02\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiCHPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-03 19:11:26
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(532)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-03-03 19:12:24
ComboFix-quarantined-files.txt 2009-03-04 02:12:12
ComboFix2.txt 2009-03-01 07:08:00

Pre-Run: 87,584,055,296 bytes free
Post-Run: 87,585,632,256 bytes free

613
First, use Use ATF Cleaner to remove temp files,
cookies, cache, ect…

Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and Paste the entire report in your next reply along with a Hijackthis log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI