Spyware / Malware / Virus Removal
[Resolved] webpage redirects and cannot install HJT
15 min read
iamquockie
Topic Starter
My webpages get redirected to random sites when I use IE and FireFox. I tried to download and install HJT but when I double click the HJT file I downloaded, it creates a shortcut on my desktop and that is it. Help? I am tired of clicking the back button two or three times before I can actually go to the website that I originally wanted.
Johnny
oldman960
Hi iamquockie, welcome to the forum.
To make cleaning this machine easier
Download OTListIt2 to your desktop.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
No need for a Hijackthis log this time.
To make cleaning this machine easier
- Please do not uninstall/install any programs unless asked to
It is more difficult when files/programs are appearing in/disappearing from the logs. - Please do not run any scans other than those requested
- Please follow all instructions in the order posted
- All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
- Do not attach any logs/reports, etc.. unless specifically requested to do so.
- If you have problems with or do not understand the instructions, Please ask before continuing.
- Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.
Download OTListIt2 to your desktop.
- Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
- When the window appears, underneath Output at the top change it to Minimal Output
- Check the boxes beside LOP Check and Purity Check.
- Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
No need for a Hijackthis log this time.
iamquockie
Thank you for your help, and to clarify or add in, I have scanned my machine with malwarebytes yesterday before I posted last night. here are my logs.
EXTRAS.TXT
OTL Extras logfile created on: 5/27/2009 3:42:05 PM - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\johnny\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.48 Mb Total Physical Memory | 742.19 Mb Available Physical Memory | 72.52% Memory free
2.41 Gb Paging File | 2.24 Gb Available in Paging File | 93.21% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14.29 Gb Total Space | 2.69 Gb Free Space | 18.81% Space Free | Partition Type: NTFS
Drive D: | 465.76 Gb Total Space | 443.68 Gb Free Space | 95.26% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: JOHNNY-5FA9E25A
Current User Name: johnny
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe (Nexon)
C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe (Nexon)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader (AOL LLC)
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes File not found
C:\Program Files\BitLord\BitLord.exe:*:Enabled:BitLord (www.BitLord.com)
C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe:*:Enabled:Nexon Game Manager (Nexon)
C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe (Nexon)
C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe (Nexon)
C:\Nexon\Combat Arms\NMService.exe:*:Enabled:Nexon Messenger Core (Nexon Corp.)
D:\LimeWire\LimeWire.exe:*:Enabled:LimeWire (Lime Wire, LLC)
D:\Nexon\Combat Arms\NMService.exe:*:Enabled:Nexon Messenger Core (Nexon Corp.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{15095BF3-A3D7-4DDF-B193-3A496881E003}" = Microsoft .NET Framework 3.0
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{3248F0A8-6813-11D6-A77B-00B0D0150120}" = J2SE Runtime Environment 5.0 Update 12
"{33CFCF98-F8D6-4549-B469-6F4295676D83}" = Symantec AntiVirus
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}" = iTunes
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{A3BC5D37-30F9-4CF7-BD5C-0DFF063E4B6D}" = 2Wire Wireless Client
"{A654A805-41D9-40C7-AA46-4AF04F044D61}" = Adobe® Photoshop® Album Starter Edition 3.2
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AFA20D47-69C3-4030-8DF8-D37466E70F13}" = Apple Mobile Device Support
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BC4AE628-81A4-4FC6-863A-7A9BA2E2531F}" = Nokia Connectivity Cable Driver
"{C93369CB-B4E9-E095-9289-E6B5AE941033}" = Nero 7 Demo
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe® Photoshop® Album Starter Edition 3.2" = Adobe® Photoshop® Album Starter Edition 3.2
"AIM_6" = AIM 6
"BitLord" = BitLord 1.1
"Combat Arms" = Combat Arms
"ERUNT_is1" = ERUNT 1.1j
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"LimeWire" = LimeWire 4.18.8
"LiveUpdate" = LiveUpdate 3.1 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaCoder" = MediaCoder 0.6.1
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"VIA Register Tool" = VIA Register Tool
"ViewpointMediaPlayer" = Viewpoint Media Player
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"WinRAR archiver" = WinRAR archiver
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Toolbar" = Yahoo! Toolbar
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 5/22/2009 10:09:13 PM | Computer Name = JOHNNY-5FA9E25A | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error This service is not authorized to start.
Error - 5/23/2009 8:53:28 PM | Computer Name = JOHNNY-5FA9E25A | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16827, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 5/23/2009 8:53:28 PM | Computer Name = JOHNNY-5FA9E25A | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16827, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 5/24/2009 12:54:30 AM | Computer Name = JOHNNY-5FA9E25A | Source = Application Hang | ID = 1002
Description = Hanging application AcroRd32.exe, version 8.1.0.137, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 5/24/2009 12:54:33 AM | Computer Name = JOHNNY-5FA9E25A | Source = Application Hang | ID = 1002
Description = Hanging application AcroRd32.exe, version 8.1.0.137, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 5/24/2009 4:34:59 PM | Computer Name = JOHNNY-5FA9E25A | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error This service is not authorized to start.
Error - 5/26/2009 8:05:27 PM | Computer Name = JOHNNY-5FA9E25A | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error This service is not authorized to start.
Error - 5/26/2009 10:04:38 PM | Computer Name = JOHNNY-5FA9E25A | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error This service is not authorized to start.
Error - 5/26/2009 10:38:27 PM | Computer Name = JOHNNY-5FA9E25A | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.0.3399, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 5/26/2009 10:49:23 PM | Computer Name = JOHNNY-5FA9E25A | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error This service is not authorized to start.
[ Application Events ]
Error - 5/22/2009 10:09:13 PM | Computer Name = JOHNNY-5FA9E25A | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error This service is not authorized to start.
Error - 5/23/2009 8:53:28 PM | Computer Name = JOHNNY-5FA9E25A | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16827, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 5/23/2009 8:53:28 PM | Computer Name = JOHNNY-5FA9E25A | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16827, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 5/24/2009 12:54:30 AM | Computer Name = JOHNNY-5FA9E25A | Source = Application Hang | ID = 1002
Description = Hanging application AcroRd32.exe, version 8.1.0.137, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 5/24/2009 12:54:33 AM | Computer Name = JOHNNY-5FA9E25A | Source = Application Hang | ID = 1002
Description = Hanging application AcroRd32.exe, version 8.1.0.137, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 5/24/2009 4:34:59 PM | Computer Name = JOHNNY-5FA9E25A | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error This service is not authorized to start.
Error - 5/26/2009 8:05:27 PM | Computer Name = JOHNNY-5FA9E25A | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error This service is not authorized to start.
Error - 5/26/2009 10:04:38 PM | Computer Name = JOHNNY-5FA9E25A | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error This service is not authorized to start.
Error - 5/26/2009 10:38:27 PM | Computer Name = JOHNNY-5FA9E25A | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.0.3399, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 5/26/2009 10:49:23 PM | Computer Name = JOHNNY-5FA9E25A | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error This service is not authorized to start.
[ System Events ]
Error - 5/26/2009 10:06:03 PM | Computer Name = JOHNNY-5FA9E25A | Source = Service Control Manager | ID = 7000
Description = The LiveUpdate service failed to start due to the following error:
%%2
Error - 5/26/2009 10:06:03 PM | Computer Name = JOHNNY-5FA9E25A | Source = Service Control Manager | ID = 7000
Description = The LiveUpdate service failed to start due to the following error:
%%2
Error - 5/26/2009 10:06:04 PM | Computer Name = JOHNNY-5FA9E25A | Source = DCOM | ID = 10005
Description = DCOM got error "%2" attempting to start the service LiveUpdate with
arguments "" in order to run the server: {03E0E6C2-363B-11D3-B536-00902771A435}
Error - 5/26/2009 10:06:04 PM | Computer Name = JOHNNY-5FA9E25A | Source = DCOM | ID = 10005
Description = DCOM got error "%2" attempting to start the service LiveUpdate with
arguments "" in order to run the server: {03E0E6C2-363B-11D3-B536-00902771A435}
Error - 5/26/2009 10:06:04 PM | Computer Name = JOHNNY-5FA9E25A | Source = Service Control Manager | ID = 7000
Description = The LiveUpdate service failed to start due to the following error:
%%2
Error - 5/26/2009 10:06:04 PM | Computer Name = JOHNNY-5FA9E25A | Source = Service Control Manager | ID = 7000
Description = The LiveUpdate service failed to start due to the following error:
%%2
Error - 5/26/2009 10:49:14 PM | Computer Name = JOHNNY-5FA9E25A | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000001'
while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring
the volume.
Error - 5/26/2009 10:49:25 PM | Computer Name = JOHNNY-5FA9E25A | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Automatic LiveUpdate
Scheduler service to connect.
Error - 5/26/2009 10:49:25 PM | Computer Name = JOHNNY-5FA9E25A | Source = Service Control Manager | ID = 7000
Description = The Automatic LiveUpdate Scheduler service failed to start due to
the following error: %%1053
Error - 5/26/2009 10:49:27 PM | Computer Name = JOHNNY-5FA9E25A | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
PCIIde SYMTDI
< End of report >
EXTRAS.TXT
OTL Extras logfile created on: 5/27/2009 3:42:05 PM - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\johnny\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.48 Mb Total Physical Memory | 742.19 Mb Available Physical Memory | 72.52% Memory free
2.41 Gb Paging File | 2.24 Gb Available in Paging File | 93.21% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14.29 Gb Total Space | 2.69 Gb Free Space | 18.81% Space Free | Partition Type: NTFS
Drive D: | 465.76 Gb Total Space | 443.68 Gb Free Space | 95.26% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: JOHNNY-5FA9E25A
Current User Name: johnny
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe (Nexon)
C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe (Nexon)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader (AOL LLC)
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes File not found
C:\Program Files\BitLord\BitLord.exe:*:Enabled:BitLord (www.BitLord.com)
C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe:*:Enabled:Nexon Game Manager (Nexon)
C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe (Nexon)
C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe (Nexon)
C:\Nexon\Combat Arms\NMService.exe:*:Enabled:Nexon Messenger Core (Nexon Corp.)
D:\LimeWire\LimeWire.exe:*:Enabled:LimeWire (Lime Wire, LLC)
D:\Nexon\Combat Arms\NMService.exe:*:Enabled:Nexon Messenger Core (Nexon Corp.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{15095BF3-A3D7-4DDF-B193-3A496881E003}" = Microsoft .NET Framework 3.0
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{3248F0A8-6813-11D6-A77B-00B0D0150120}" = J2SE Runtime Environment 5.0 Update 12
"{33CFCF98-F8D6-4549-B469-6F4295676D83}" = Symantec AntiVirus
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}" = iTunes
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{A3BC5D37-30F9-4CF7-BD5C-0DFF063E4B6D}" = 2Wire Wireless Client
"{A654A805-41D9-40C7-AA46-4AF04F044D61}" = Adobe® Photoshop® Album Starter Edition 3.2
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AFA20D47-69C3-4030-8DF8-D37466E70F13}" = Apple Mobile Device Support
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BC4AE628-81A4-4FC6-863A-7A9BA2E2531F}" = Nokia Connectivity Cable Driver
"{C93369CB-B4E9-E095-9289-E6B5AE941033}" = Nero 7 Demo
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe® Photoshop® Album Starter Edition 3.2" = Adobe® Photoshop® Album Starter Edition 3.2
"AIM_6" = AIM 6
"BitLord" = BitLord 1.1
"Combat Arms" = Combat Arms
"ERUNT_is1" = ERUNT 1.1j
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"LimeWire" = LimeWire 4.18.8
"LiveUpdate" = LiveUpdate 3.1 (Symantec Corporation)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaCoder" = MediaCoder 0.6.1
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"VIA Register Tool" = VIA Register Tool
"ViewpointMediaPlayer" = Viewpoint Media Player
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"WinRAR archiver" = WinRAR archiver
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Toolbar" = Yahoo! Toolbar
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 5/22/2009 10:09:13 PM | Computer Name = JOHNNY-5FA9E25A | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error This service is not authorized to start.
Error - 5/23/2009 8:53:28 PM | Computer Name = JOHNNY-5FA9E25A | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16827, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 5/23/2009 8:53:28 PM | Computer Name = JOHNNY-5FA9E25A | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16827, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 5/24/2009 12:54:30 AM | Computer Name = JOHNNY-5FA9E25A | Source = Application Hang | ID = 1002
Description = Hanging application AcroRd32.exe, version 8.1.0.137, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 5/24/2009 12:54:33 AM | Computer Name = JOHNNY-5FA9E25A | Source = Application Hang | ID = 1002
Description = Hanging application AcroRd32.exe, version 8.1.0.137, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 5/24/2009 4:34:59 PM | Computer Name = JOHNNY-5FA9E25A | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error This service is not authorized to start.
Error - 5/26/2009 8:05:27 PM | Computer Name = JOHNNY-5FA9E25A | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error This service is not authorized to start.
Error - 5/26/2009 10:04:38 PM | Computer Name = JOHNNY-5FA9E25A | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error This service is not authorized to start.
Error - 5/26/2009 10:38:27 PM | Computer Name = JOHNNY-5FA9E25A | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.0.3399, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 5/26/2009 10:49:23 PM | Computer Name = JOHNNY-5FA9E25A | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error This service is not authorized to start.
[ Application Events ]
Error - 5/22/2009 10:09:13 PM | Computer Name = JOHNNY-5FA9E25A | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error This service is not authorized to start.
Error - 5/23/2009 8:53:28 PM | Computer Name = JOHNNY-5FA9E25A | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16827, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 5/23/2009 8:53:28 PM | Computer Name = JOHNNY-5FA9E25A | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16827, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 5/24/2009 12:54:30 AM | Computer Name = JOHNNY-5FA9E25A | Source = Application Hang | ID = 1002
Description = Hanging application AcroRd32.exe, version 8.1.0.137, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 5/24/2009 12:54:33 AM | Computer Name = JOHNNY-5FA9E25A | Source = Application Hang | ID = 1002
Description = Hanging application AcroRd32.exe, version 8.1.0.137, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 5/24/2009 4:34:59 PM | Computer Name = JOHNNY-5FA9E25A | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error This service is not authorized to start.
Error - 5/26/2009 8:05:27 PM | Computer Name = JOHNNY-5FA9E25A | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error This service is not authorized to start.
Error - 5/26/2009 10:04:38 PM | Computer Name = JOHNNY-5FA9E25A | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error This service is not authorized to start.
Error - 5/26/2009 10:38:27 PM | Computer Name = JOHNNY-5FA9E25A | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.0.3399, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 5/26/2009 10:49:23 PM | Computer Name = JOHNNY-5FA9E25A | Source = Automatic LiveUpdate Scheduler | ID = 101
Description = Information Level: error This service is not authorized to start.
[ System Events ]
Error - 5/26/2009 10:06:03 PM | Computer Name = JOHNNY-5FA9E25A | Source = Service Control Manager | ID = 7000
Description = The LiveUpdate service failed to start due to the following error:
%%2
Error - 5/26/2009 10:06:03 PM | Computer Name = JOHNNY-5FA9E25A | Source = Service Control Manager | ID = 7000
Description = The LiveUpdate service failed to start due to the following error:
%%2
Error - 5/26/2009 10:06:04 PM | Computer Name = JOHNNY-5FA9E25A | Source = DCOM | ID = 10005
Description = DCOM got error "%2" attempting to start the service LiveUpdate with
arguments "" in order to run the server: {03E0E6C2-363B-11D3-B536-00902771A435}
Error - 5/26/2009 10:06:04 PM | Computer Name = JOHNNY-5FA9E25A | Source = DCOM | ID = 10005
Description = DCOM got error "%2" attempting to start the service LiveUpdate with
arguments "" in order to run the server: {03E0E6C2-363B-11D3-B536-00902771A435}
Error - 5/26/2009 10:06:04 PM | Computer Name = JOHNNY-5FA9E25A | Source = Service Control Manager | ID = 7000
Description = The LiveUpdate service failed to start due to the following error:
%%2
Error - 5/26/2009 10:06:04 PM | Computer Name = JOHNNY-5FA9E25A | Source = Service Control Manager | ID = 7000
Description = The LiveUpdate service failed to start due to the following error:
%%2
Error - 5/26/2009 10:49:14 PM | Computer Name = JOHNNY-5FA9E25A | Source = sr | ID = 1
Description = The System Restore filter encountered the unexpected error '0xC0000001'
while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring
the volume.
Error - 5/26/2009 10:49:25 PM | Computer Name = JOHNNY-5FA9E25A | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Automatic LiveUpdate
Scheduler service to connect.
Error - 5/26/2009 10:49:25 PM | Computer Name = JOHNNY-5FA9E25A | Source = Service Control Manager | ID = 7000
Description = The Automatic LiveUpdate Scheduler service failed to start due to
the following error: %%1053
Error - 5/26/2009 10:49:27 PM | Computer Name = JOHNNY-5FA9E25A | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
PCIIde SYMTDI
< End of report >
iamquockie
and OTL.txt log:
OTL logfile created on: 5/27/2009 3:42:05 PM - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\johnny\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.48 Mb Total Physical Memory | 742.19 Mb Available Physical Memory | 72.52% Memory free
2.41 Gb Paging File | 2.24 Gb Available in Paging File | 93.21% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14.29 Gb Total Space | 2.69 Gb Free Space | 18.81% Space Free | Partition Type: NTFS
Drive D: | 465.76 Gb Total Space | 443.68 Gb Free Space | 95.26% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: JOHNNY-5FA9E25A
Current User Name: johnny
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - D:\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe (Nero AG)
PRC - C:\WINDOWS\system32\devldr32.exe (Creative Technology Ltd.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Documents and Settings\johnny\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Automatic LiveUpdate Scheduler [Auto | Stopped]) – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LiveUpdate [On_Demand | Stopped]) – File not found
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NPFMntor [Auto | Stopped]) – File not found
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Viewpoint Manager Service [Auto | Running]) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
========== Driver Services (SafeList) ==========
DRV - (cercsr6 [Boot | Stopped]) – C:\WINDOWS\System32\drivers\cercsr6.sys (Adaptec, Inc.)
DRV - (ctljystk [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ctljystk.sys (Creative Technology Ltd.)
DRV - (emu10k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (emu10k1 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (ltmodem5 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ltmdmnt.sys (LT)
DRV - (MDC8021X [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (nmwcd [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ccdcmb.sys (Nokia)
DRV - (nmwcdc [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nmwcdc.sys (Nokia)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (rtl8139 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\RTL8139.SYS (Realtek Semiconductor Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sfman [On_Demand | Running]) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (SYMTDI [System | Stopped]) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (usbser [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbser.sys (Microsoft Corporation)
DRV - (UsbserFilt [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys (Windows ® Codename Longhorn DDK provider)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2016/01/25 20:09:25 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/05/25 23:57:49 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/05/25 23:57:29 | 00,000,000 | —D | M]
[2009/05/25 23:57:50 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\mozilla\Extensions
[2009/05/25 23:57:50 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/05/25 23:57:50 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\mozilla\Firefox\Profiles\yk7y7sbg.default\extensions
[2009/05/25 23:57:30 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/05/25 23:57:30 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/04/23 23:38:30 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/23 23:38:32 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/04/23 19:39:08 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/23 19:39:08 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/23 19:39:08 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/23 19:39:08 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/23 19:39:08 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/23 19:39:08 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/23 19:39:08 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O4 - HKLM..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" (Symantec Corporation)
O4 - HKLM..\Run: [iTunesHelper] "D:\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\nadanothing\mbam.exe" /runcleanupscript (Malwarebytes Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY File not found
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe (Symantec Corporation)
O4 - HKCU..\Run: [Aim6] File not found
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" (Nero AG)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {297DE2B6-509A-4B36-93C5-A65276606900} http://www.in.honda.com/rraaapps/rraasec/c…AX/RraainAX.CAB (RRAAINAX_02.RRAAINAX)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_12)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/12/12 18:57:32 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/05/21 09:41:06 | 00,000,368 | RHS- | M] () - D:\autorun.inf – [ NTFS ]
O33 - MountPoints2\{0b4e5db0-86b2-11dd-abc5-0010dc9d7860}\Shell - "" = Autorun
O33 - MountPoints2\{0b4e5db0-86b2-11dd-abc5-0010dc9d7860}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0b4e5db0-86b2-11dd-abc5-0010dc9d7860}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RECYCLER\S-0-5-82-100028843-100008884-100021789-8313.com d:\
O33 - MountPoints2\{0b4e5db0-86b2-11dd-abc5-0010dc9d7860}\Shell\Open\command - "" = D:\RECYCLER\S-0-5-82-100028843-100008884-100021789-8313.com – [2009/05/20 22:41:18 | 00,084,480 | RHS- | M] ()
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/05/27 15:40:46 | 00,000,000 | —D | M]
========== Files/Folders - Created Within 30 Days ==========
[5 C:\WINDOWS\*.tmp files]
[2016/01/25 19:50:23 | 00,001,950 | —- | C] () – C:\WINDOWS\System32\drivers\REGISTER.SYS
[2016/01/25 19:50:23 | 00,000,000 | —D | C] – C:\Program Files\Your Company Name
[2016/01/25 19:48:30 | 00,000,000 | —D | C] – C:\Program Files\nv4loopfix
[2009/05/27 15:40:46 | 00,501,760 | —- | C] (OldTimer Tools) – C:\Documents and Settings\johnny\Desktop\OTL.exe
[2009/05/26 22:08:12 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/05/26 22:05:41 | 00,000,000 | —D | C] – C:\Documents and Settings\johnny\Desktop\malware stuff
[2009/05/26 22:00:06 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/05/26 21:59:21 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/05/26 19:42:38 | 00,000,000 | —D | C] – C:\Documents and Settings\johnny\Application Data\Malwarebytes
[2009/05/26 19:05:16 | 10,732,70784 | -HS- | C] () – C:\hiberfil.sys
[2009/05/26 19:01:27 | 00,388,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\CF14767.exe
[2009/05/26 18:57:01 | 00,000,000 | —D | C] – C:\Qoobox
[2009/05/26 18:52:39 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/26 18:52:36 | 00,040,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/26 18:52:35 | 00,000,000 | —D | C] – C:\Program Files\nadanothing
[2009/05/26 18:52:35 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/05/26 18:21:58 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/05/25 23:57:51 | 00,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/05/25 23:57:47 | 00,000,000 | —D | C] – C:\Documents and Settings\johnny\Application Data\Mozilla
[2009/05/25 23:57:36 | 00,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/05/25 23:57:27 | 00,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2009/05/23 17:47:02 | 00,029,738 | —- | C] () – C:\Documents and Settings\johnny\Desktop\pdftown_com.htm
[2009/05/20 00:06:38 | 00,000,000 | R–D | C] – C:\Documents and Settings\johnny\My Documents\My Pictures
[2009/05/19 23:41:32 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Installations
[2009/05/19 23:38:42 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\usbser.sys
[2009/05/19 23:28:39 | 00,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
[2009/05/19 23:28:36 | 00,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2009/05/08 11:29:22 | 00,000,000 | —D | C] – C:\Nexon
[2009/05/05 21:51:56 | 00,114,402 | —- | C] () – C:\Documents and Settings\johnny\My Documents\KFC_Coupon_OprahWebsite.pdf
[2009/04/28 14:12:52 | 00,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2009/04/20 21:32:29 | 00,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2008/01/06 01:30:58 | 00,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/12/12 23:01:32 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/08/04 05:00:00 | 00,000,477 | —- | C] () – C:\WINDOWS\win.ini
[2004/08/04 05:00:00 | 00,000,231 | —- | C] () – C:\WINDOWS\system.ini
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/05/27 15:40:46 | 00,501,760 | —- | M] (OldTimer Tools) – C:\Documents and Settings\johnny\Desktop\OTL.exe
[2009/05/26 21:49:28 | 00,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/05/26 21:49:18 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\johnny\Local Settings\desktop.ini
[2009/05/26 21:49:14 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/05/26 21:49:13 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/05/26 21:49:12 | 10,732,70784 | -HS- | M] () – C:\hiberfil.sys
[2009/05/26 18:56:57 | 00,388,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\CF14767.exe
[2009/05/26 13:20:08 | 00,040,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/26 13:19:56 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/25 23:57:51 | 00,000,000 | —- | M] () – C:\WINDOWS\nsreg.dat
[2009/05/25 23:57:36 | 00,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/05/23 17:47:05 | 00,029,738 | —- | M] () – C:\Documents and Settings\johnny\Desktop\pdftown_com.htm
[2009/05/19 23:28:39 | 00,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
[2009/05/19 23:28:36 | 00,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2009/05/19 23:25:49 | 00,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/05/17 11:27:25 | 00,001,981 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/05/11 17:40:36 | 00,516,186 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/05/11 17:40:36 | 00,436,360 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/05/11 17:40:36 | 00,070,124 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/05/11 17:36:09 | 00,117,360 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/05/10 22:50:13 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/05/08 11:28:42 | 00,001,422 | —- | M] () – C:\Documents and Settings\johnny\Desktop\CoMbAt ViRuS.lnk
[2009/05/05 21:51:56 | 00,114,402 | —- | M] () – C:\Documents and Settings\johnny\My Documents\KFC_Coupon_OprahWebsite.pdf
========== LOP Check ==========
[2009/05/26 18:39:12 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/04/17 01:12:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/03/11 09:21:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/01/12 21:03:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2008/01/12 21:05:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL OCP
[2008/04/01 22:07:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2009/04/17 01:11:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/05/21 09:34:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2009/05/19 23:41:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2009/03/06 00:45:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
[2009/05/26 18:52:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2007/12/13 23:19:35 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/09/07 14:47:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NexonUS
[2009/03/06 00:50:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/04/20 14:49:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2008/01/12 21:03:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/11/06 20:39:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/09/23 21:58:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2009/05/26 19:42:38 | 00,000,000 | -H-D | M] – C:\Documents and Settings\johnny\Application Data
[2008/01/12 21:04:15 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\acccore
[2008/03/06 00:35:02 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Adobe
[2007/12/12 19:56:25 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Ahead
[2016/01/25 20:05:01 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Apple Computer
[2008/01/09 22:11:08 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Google
[2007/12/12 19:17:08 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Identities
[2008/05/06 22:05:38 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Leadertech
[2009/05/18 12:30:24 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\LimeWire
[2007/12/18 22:10:39 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Macromedia
[2009/05/26 19:42:38 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Malwarebytes
[2009/02/01 20:21:36 | 00,000,000 | –SD | M] – C:\Documents and Settings\johnny\Application Data\Microsoft
[2008/12/04 22:55:34 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Move Networks
[2009/05/25 23:57:50 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Mozilla
[2008/06/19 12:21:42 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Sun
[2007/12/12 19:45:46 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Symantec
[2004/08/04 05:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/05/26 21:49:14 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
< End of report >
OTL logfile created on: 5/27/2009 3:42:05 PM - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\johnny\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.48 Mb Total Physical Memory | 742.19 Mb Available Physical Memory | 72.52% Memory free
2.41 Gb Paging File | 2.24 Gb Available in Paging File | 93.21% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14.29 Gb Total Space | 2.69 Gb Free Space | 18.81% Space Free | Partition Type: NTFS
Drive D: | 465.76 Gb Total Space | 443.68 Gb Free Space | 95.26% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: JOHNNY-5FA9E25A
Current User Name: johnny
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - D:\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe (Nero AG)
PRC - C:\WINDOWS\system32\devldr32.exe (Creative Technology Ltd.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Documents and Settings\johnny\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Automatic LiveUpdate Scheduler [Auto | Stopped]) – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LiveUpdate [On_Demand | Stopped]) – File not found
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NPFMntor [Auto | Stopped]) – File not found
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Viewpoint Manager Service [Auto | Running]) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
========== Driver Services (SafeList) ==========
DRV - (cercsr6 [Boot | Stopped]) – C:\WINDOWS\System32\drivers\cercsr6.sys (Adaptec, Inc.)
DRV - (ctljystk [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ctljystk.sys (Creative Technology Ltd.)
DRV - (emu10k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (emu10k1 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (ltmodem5 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ltmdmnt.sys (LT)
DRV - (MDC8021X [Auto | Running]) – C:\WINDOWS\system32\DRIVERS\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (nmwcd [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ccdcmb.sys (Nokia)
DRV - (nmwcdc [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nmwcdc.sys (Nokia)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (rtl8139 [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\RTL8139.SYS (Realtek Semiconductor Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sfman [On_Demand | Running]) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (SYMTDI [System | Stopped]) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (usbser [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbser.sys (Microsoft Corporation)
DRV - (UsbserFilt [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys (Windows ® Codename Longhorn DDK provider)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2016/01/25 20:09:25 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/05/25 23:57:49 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/05/25 23:57:29 | 00,000,000 | —D | M]
[2009/05/25 23:57:50 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\mozilla\Extensions
[2009/05/25 23:57:50 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/05/25 23:57:50 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\mozilla\Firefox\Profiles\yk7y7sbg.default\extensions
[2009/05/25 23:57:30 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/05/25 23:57:30 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/04/23 23:38:30 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/23 23:38:32 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/04/23 19:39:08 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/23 19:39:08 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/23 19:39:08 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/23 19:39:08 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/23 19:39:08 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/23 19:39:08 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/23 19:39:08 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O4 - HKLM..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" (Symantec Corporation)
O4 - HKLM..\Run: [iTunesHelper] "D:\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\nadanothing\mbam.exe" /runcleanupscript (Malwarebytes Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY File not found
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe (Symantec Corporation)
O4 - HKCU..\Run: [Aim6] File not found
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" (Nero AG)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {297DE2B6-509A-4B36-93C5-A65276606900} http://www.in.honda.com/rraaapps/rraasec/c…AX/RraainAX.CAB (RRAAINAX_02.RRAAINAX)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_12)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/12/12 18:57:32 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/05/21 09:41:06 | 00,000,368 | RHS- | M] () - D:\autorun.inf – [ NTFS ]
O33 - MountPoints2\{0b4e5db0-86b2-11dd-abc5-0010dc9d7860}\Shell - "" = Autorun
O33 - MountPoints2\{0b4e5db0-86b2-11dd-abc5-0010dc9d7860}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{0b4e5db0-86b2-11dd-abc5-0010dc9d7860}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RECYCLER\S-0-5-82-100028843-100008884-100021789-8313.com d:\
O33 - MountPoints2\{0b4e5db0-86b2-11dd-abc5-0010dc9d7860}\Shell\Open\command - "" = D:\RECYCLER\S-0-5-82-100028843-100008884-100021789-8313.com – [2009/05/20 22:41:18 | 00,084,480 | RHS- | M] ()
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/05/27 15:40:46 | 00,000,000 | —D | M]
========== Files/Folders - Created Within 30 Days ==========
[5 C:\WINDOWS\*.tmp files]
[2016/01/25 19:50:23 | 00,001,950 | —- | C] () – C:\WINDOWS\System32\drivers\REGISTER.SYS
[2016/01/25 19:50:23 | 00,000,000 | —D | C] – C:\Program Files\Your Company Name
[2016/01/25 19:48:30 | 00,000,000 | —D | C] – C:\Program Files\nv4loopfix
[2009/05/27 15:40:46 | 00,501,760 | —- | C] (OldTimer Tools) – C:\Documents and Settings\johnny\Desktop\OTL.exe
[2009/05/26 22:08:12 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/05/26 22:05:41 | 00,000,000 | —D | C] – C:\Documents and Settings\johnny\Desktop\malware stuff
[2009/05/26 22:00:06 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/05/26 21:59:21 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/05/26 19:42:38 | 00,000,000 | —D | C] – C:\Documents and Settings\johnny\Application Data\Malwarebytes
[2009/05/26 19:05:16 | 10,732,70784 | -HS- | C] () – C:\hiberfil.sys
[2009/05/26 19:01:27 | 00,388,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\CF14767.exe
[2009/05/26 18:57:01 | 00,000,000 | —D | C] – C:\Qoobox
[2009/05/26 18:52:39 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/26 18:52:36 | 00,040,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/26 18:52:35 | 00,000,000 | —D | C] – C:\Program Files\nadanothing
[2009/05/26 18:52:35 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/05/26 18:21:58 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/05/25 23:57:51 | 00,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2009/05/25 23:57:47 | 00,000,000 | —D | C] – C:\Documents and Settings\johnny\Application Data\Mozilla
[2009/05/25 23:57:36 | 00,001,602 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/05/25 23:57:27 | 00,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2009/05/23 17:47:02 | 00,029,738 | —- | C] () – C:\Documents and Settings\johnny\Desktop\pdftown_com.htm
[2009/05/20 00:06:38 | 00,000,000 | R–D | C] – C:\Documents and Settings\johnny\My Documents\My Pictures
[2009/05/19 23:41:32 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Installations
[2009/05/19 23:38:42 | 00,025,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\usbser.sys
[2009/05/19 23:28:39 | 00,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
[2009/05/19 23:28:36 | 00,000,000 | -H– | C] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2009/05/08 11:29:22 | 00,000,000 | —D | C] – C:\Nexon
[2009/05/05 21:51:56 | 00,114,402 | —- | C] () – C:\Documents and Settings\johnny\My Documents\KFC_Coupon_OprahWebsite.pdf
[2009/04/28 14:12:52 | 00,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2009/04/20 21:32:29 | 00,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2008/01/06 01:30:58 | 00,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/12/12 23:01:32 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/08/04 05:00:00 | 00,000,477 | —- | C] () – C:\WINDOWS\win.ini
[2004/08/04 05:00:00 | 00,000,231 | —- | C] () – C:\WINDOWS\system.ini
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/05/27 15:40:46 | 00,501,760 | —- | M] (OldTimer Tools) – C:\Documents and Settings\johnny\Desktop\OTL.exe
[2009/05/26 21:49:28 | 00,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/05/26 21:49:18 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\johnny\Local Settings\desktop.ini
[2009/05/26 21:49:14 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/05/26 21:49:13 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/05/26 21:49:12 | 10,732,70784 | -HS- | M] () – C:\hiberfil.sys
[2009/05/26 18:56:57 | 00,388,608 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\CF14767.exe
[2009/05/26 13:20:08 | 00,040,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/26 13:19:56 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/25 23:57:51 | 00,000,000 | —- | M] () – C:\WINDOWS\nsreg.dat
[2009/05/25 23:57:36 | 00,001,602 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/05/23 17:47:05 | 00,029,738 | —- | M] () – C:\Documents and Settings\johnny\Desktop\pdftown_com.htm
[2009/05/19 23:28:39 | 00,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
[2009/05/19 23:28:36 | 00,000,000 | -H– | M] () – C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2009/05/19 23:25:49 | 00,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/05/17 11:27:25 | 00,001,981 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/05/11 17:40:36 | 00,516,186 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/05/11 17:40:36 | 00,436,360 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/05/11 17:40:36 | 00,070,124 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/05/11 17:36:09 | 00,117,360 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/05/10 22:50:13 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/05/08 11:28:42 | 00,001,422 | —- | M] () – C:\Documents and Settings\johnny\Desktop\CoMbAt ViRuS.lnk
[2009/05/05 21:51:56 | 00,114,402 | —- | M] () – C:\Documents and Settings\johnny\My Documents\KFC_Coupon_OprahWebsite.pdf
========== LOP Check ==========
[2009/05/26 18:39:12 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/04/17 01:12:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/03/11 09:21:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/01/12 21:03:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2008/01/12 21:05:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL OCP
[2008/04/01 22:07:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2009/04/17 01:11:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/05/21 09:34:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2009/05/19 23:41:32 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2009/03/06 00:45:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
[2009/05/26 18:52:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2007/12/13 23:19:35 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/09/07 14:47:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NexonUS
[2009/03/06 00:50:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/04/20 14:49:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2008/01/12 21:03:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/11/06 20:39:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/09/23 21:58:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2009/05/26 19:42:38 | 00,000,000 | -H-D | M] – C:\Documents and Settings\johnny\Application Data
[2008/01/12 21:04:15 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\acccore
[2008/03/06 00:35:02 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Adobe
[2007/12/12 19:56:25 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Ahead
[2016/01/25 20:05:01 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Apple Computer
[2008/01/09 22:11:08 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Google
[2007/12/12 19:17:08 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Identities
[2008/05/06 22:05:38 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Leadertech
[2009/05/18 12:30:24 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\LimeWire
[2007/12/18 22:10:39 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Macromedia
[2009/05/26 19:42:38 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Malwarebytes
[2009/02/01 20:21:36 | 00,000,000 | –SD | M] – C:\Documents and Settings\johnny\Application Data\Microsoft
[2008/12/04 22:55:34 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Move Networks
[2009/05/25 23:57:50 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Mozilla
[2008/06/19 12:21:42 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Sun
[2007/12/12 19:45:46 | 00,000,000 | —D | M] – C:\Documents and Settings\johnny\Application Data\Symantec
[2004/08/04 05:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/05/26 21:49:14 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
< End of report >
oldman960
Hi iamquockie,
I see you also ran combofix. Please see if there is a log at C:\Combofix or C:\qoobox It will be called combofix.txt.
Download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any "<— ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
Please post back with
Thanks
I see you also ran combofix. Please see if there is a log at C:\Combofix or C:\qoobox It will be called combofix.txt.
Download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any "<— ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
- Click NO
- In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
- Now click the Scan button.
Once the scan is complete, you may receive another notice about rootkit activity. - Click OK.
- GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
- Save it where you can easily find it, such as your desktop.
Please post back with
- combofix log, if found
- Gmer log
Thanks
iamquockie
Thanks OldMan-
I didn't run ComboFix, I downloaded but it would not let me install so I just left it there. Here is my gmer log
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-05-28 15:29:59
Windows 5.1.2600 Service Pack 2
—- System - GMER 1.0.15 —-
Code 86CD6DA0 ZwEnumerateKey
Code 86DC56B0 ZwFlushInstructionCache
Code 86D2800E IofCallDriver
Code 86D29226 IofCompleteRequest
—- Kernel code sections - GMER 1.0.15 —-
.text ntoskrnl.exe!IofCallDriver 804E13A7 5 Bytes JMP 86D28013
.text ntoskrnl.exe!IofCompleteRequest 804E17BD 5 Bytes JMP 86D2922B
PAGE ntoskrnl.exe!ZwEnumerateKey 80578EE4 5 Bytes JMP 86CD6DA4
PAGE ntoskrnl.exe!ZwFlushInstructionCache 805873DB 5 Bytes JMP 86DC56B4
? qtizcun.sys The system cannot find the file specified. !
—- Processes - GMER 1.0.15 —-
Library \\?\globalroot\systemroot\system32\gxvxcolwgvvqfwaiqvusudkgefyqxpftootpw.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [792] 0x10000000
Library \\?\globalroot\systemroot\system32\gxvxcolwgvvqfwaiqvusudkgefyqxpftootpw.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [840] 0x10000000
Library \\?\globalroot\systemroot\system32\gxvxcolwgvvqfwaiqvusudkgefyqxpftootpw.dll (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [908] 0x10000000
Library \\?\globalroot\systemroot\system32\gxvxcolwgvvqfwaiqvusudkgefyqxpftootpw.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [996] 0x10000000
Library \\?\globalroot\systemroot\system32\gxvxcolwgvvqfwaiqvusudkgefyqxpftootpw.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1056] 0x10000000
Library \\?\globalroot\systemroot\system32\gxvxcolwgvvqfwaiqvusudkgefyqxpftootpw.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1568] 0x10000000
Library \\?\globalroot\systemroot\system32\gxvxcolwgvvqfwaiqvusudkgefyqxpftootpw.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [2052] 0x10000000
—- Services - GMER 1.0.15 —-
Service C:\WINDOWS\system32\drivers\gxvxcwbodqqoqbivtmppkkwpioaqnmejwsftb.sys (*** hidden *** ) [SYSTEM] gxvxcserv.sys <– ROOTKIT !!!
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys@imagepath \systemroot\system32\drivers\gxvxcwbodqqoqbivtmppkkwpioaqnmejwsftb.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys\modules@gxvxcserv \\?\globalroot\systemroot\system32\drivers\gxvxcwbodqqoqbivtmppkkwpioaqnmejwsftb.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys\modules@gxvxcl \\?\globalroot\systemroot\system32\gxvxcolwgvvqfwaiqvusudkgefyqxpftootpw.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys\modules@gxvxcclk \\?\globalroot\systemroot\system32\gxvxckgovdbopxmysvxfqhylqbubeescurrtj.dll
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys@imagepath \systemroot\system32\drivers\gxvxcwbodqqoqbivtmppkkwpioaqnmejwsftb.sys
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys\modules
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys\modules@gxvxcserv \\?\globalroot\systemroot\system32\drivers\gxvxcwbodqqoqbivtmppkkwpioaqnmejwsftb.sys
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys\modules@gxvxcl \\?\globalroot\systemroot\system32\gxvxcolwgvvqfwaiqvusudkgefyqxpftootpw.dll
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys\modules@gxvxcclk \\?\globalroot\systemroot\system32\gxvxckgovdbopxmysvxfqhylqbubeescurrtj.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
—- Files - GMER 1.0.15 —-
File C:\WINDOWS\system32\drivers\gxvxcwbodqqoqbivtmppkkwpioaqnmejwsftb.sys 47616 bytes executable <– ROOTKIT !!!
File C:\WINDOWS\system32\gxvxckgovdbopxmysvxfqhylqbubeescurrtj.dll 27649 bytes executable
File C:\WINDOWS\system32\gxvxcolwgvvqfwaiqvusudkgefyqxpftootpw.dll 16385 bytes executable
—- EOF - GMER 1.0.15 —-
I didn't run ComboFix, I downloaded but it would not let me install so I just left it there. Here is my gmer log
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-05-28 15:29:59
Windows 5.1.2600 Service Pack 2
—- System - GMER 1.0.15 —-
Code 86CD6DA0 ZwEnumerateKey
Code 86DC56B0 ZwFlushInstructionCache
Code 86D2800E IofCallDriver
Code 86D29226 IofCompleteRequest
—- Kernel code sections - GMER 1.0.15 —-
.text ntoskrnl.exe!IofCallDriver 804E13A7 5 Bytes JMP 86D28013
.text ntoskrnl.exe!IofCompleteRequest 804E17BD 5 Bytes JMP 86D2922B
PAGE ntoskrnl.exe!ZwEnumerateKey 80578EE4 5 Bytes JMP 86CD6DA4
PAGE ntoskrnl.exe!ZwFlushInstructionCache 805873DB 5 Bytes JMP 86DC56B4
? qtizcun.sys The system cannot find the file specified. !
—- Processes - GMER 1.0.15 —-
Library \\?\globalroot\systemroot\system32\gxvxcolwgvvqfwaiqvusudkgefyqxpftootpw.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [792] 0x10000000
Library \\?\globalroot\systemroot\system32\gxvxcolwgvvqfwaiqvusudkgefyqxpftootpw.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [840] 0x10000000
Library \\?\globalroot\systemroot\system32\gxvxcolwgvvqfwaiqvusudkgefyqxpftootpw.dll (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [908] 0x10000000
Library \\?\globalroot\systemroot\system32\gxvxcolwgvvqfwaiqvusudkgefyqxpftootpw.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [996] 0x10000000
Library \\?\globalroot\systemroot\system32\gxvxcolwgvvqfwaiqvusudkgefyqxpftootpw.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1056] 0x10000000
Library \\?\globalroot\systemroot\system32\gxvxcolwgvvqfwaiqvusudkgefyqxpftootpw.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1568] 0x10000000
Library \\?\globalroot\systemroot\system32\gxvxcolwgvvqfwaiqvusudkgefyqxpftootpw.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [2052] 0x10000000
—- Services - GMER 1.0.15 —-
Service C:\WINDOWS\system32\drivers\gxvxcwbodqqoqbivtmppkkwpioaqnmejwsftb.sys (*** hidden *** ) [SYSTEM] gxvxcserv.sys <– ROOTKIT !!!
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys@imagepath \systemroot\system32\drivers\gxvxcwbodqqoqbivtmppkkwpioaqnmejwsftb.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys\modules@gxvxcserv \\?\globalroot\systemroot\system32\drivers\gxvxcwbodqqoqbivtmppkkwpioaqnmejwsftb.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys\modules@gxvxcl \\?\globalroot\systemroot\system32\gxvxcolwgvvqfwaiqvusudkgefyqxpftootpw.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\gxvxcserv.sys\modules@gxvxcclk \\?\globalroot\systemroot\system32\gxvxckgovdbopxmysvxfqhylqbubeescurrtj.dll
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys@imagepath \systemroot\system32\drivers\gxvxcwbodqqoqbivtmppkkwpioaqnmejwsftb.sys
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys\modules
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys\modules@gxvxcserv \\?\globalroot\systemroot\system32\drivers\gxvxcwbodqqoqbivtmppkkwpioaqnmejwsftb.sys
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys\modules@gxvxcl \\?\globalroot\systemroot\system32\gxvxcolwgvvqfwaiqvusudkgefyqxpftootpw.dll
Reg HKLM\SYSTEM\ControlSet003\Services\gxvxcserv.sys\modules@gxvxcclk \\?\globalroot\systemroot\system32\gxvxckgovdbopxmysvxfqhylqbubeescurrtj.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
—- Files - GMER 1.0.15 —-
File C:\WINDOWS\system32\drivers\gxvxcwbodqqoqbivtmppkkwpioaqnmejwsftb.sys 47616 bytes executable <– ROOTKIT !!!
File C:\WINDOWS\system32\gxvxckgovdbopxmysvxfqhylqbubeescurrtj.dll 27649 bytes executable
File C:\WINDOWS\system32\gxvxcolwgvvqfwaiqvusudkgefyqxpftootpw.dll 16385 bytes executable
—- EOF - GMER 1.0.15 —-
oldman960
Hi iamquockie,
We should be able to get this with combofix, but we will need to make a couple of adjustments first.
First, locate combofix.exe on your desktop, right click it and select delete.
Please follow all instructions.
It is vitally important that combofix is renamed before it is even started to download
Please download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
[external image: Posted Image]
[external image: Posted Image]
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
I see a Trend Micro folder has been created. What happens when you click the Hijackkthis shortcut?
Please post back with
Thanks
We should be able to get this with combofix, but we will need to make a couple of adjustments first.
First, locate combofix.exe on your desktop, right click it and select delete.
Please follow all instructions.
It is vitally important that combofix is renamed before it is even started to download
Please download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
- If you are using Firefox, make sure that your download settings are as follows:
-Tools->Options->Main tab
-Set to "Always ask me where to Save the files".
- During the download, rename Combofix to Combo-Fix as follows:
[external image: Posted Image]
[external image: Posted Image]
- It is important you rename Combofix during the download, but not after.
- Please do not rename Combofix to other names, but only to the one indicated.
- Close any open browsers.
- Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix
- If combofix will not run, Do Not rerun it, post back for further insrtuctions.
———————————————————–
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
- Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
———————————————————–
- Double click on ComboFix.exe & follow the prompts.
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
I see a Trend Micro folder has been created. What happens when you click the Hijackkthis shortcut?
Please post back with
- combofix log
- HJT log, if it will run
Thanks
iamquockie
Cheers once again,
I do not know what happen in between now and when I first began this thread but now HiJackThis runs. The HiJackThis icon used to just flash twice when I double-click it but I guess that is water under the brdige now. Here are the ComboFix and also the HiJackThis logs. Once again I appreciate you helping me.
COMBOFIX
ComboFix 09-05-28.07 - johnny 05/28/2009 22:30.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.806 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: Norton AntiVirus 2005 *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\gxvxcwbodqqoqbivtmppkkwpioaqnmejwsftb.sys
c:\windows\system32\GroupPolicy000.dat
c:\windows\system32\gxvxckgovdbopxmysvxfqhylqbubeescurrtj.dll
c:\windows\system32\gxvxcolwgvvqfwaiqvusudkgefyqxpftootpw.dll
C:\xcrashdump.dat
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_gxvxcserv.sys
((((((((((((((((((((((((( Files Created from 2009-04-28 to 2009-05-29 )))))))))))))))))))))))))))))))
.
2016-01-26 01:11 . 2016-01-26 01:11 57344 —-a-w c:\documents and settings\johnny\Application Data\Sun\Java\Deployment\cache\6.0\50\5b902232-51d78a66-n\Decora-SSE.dll
2016-01-26 01:11 . 2016-01-26 01:11 315392 —-a-w c:\documents and settings\johnny\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-6da45515-n\jogl.dll
2016-01-26 01:11 . 2016-01-26 01:11 24064 —-a-w c:\documents and settings\johnny\Application Data\Sun\Java\Deployment\cache\6.0\15\4e09eacf-5fabb0c4-n\Decora-D3D.dll
2016-01-26 01:11 . 2016-01-26 01:11 20480 —-a-w c:\documents and settings\johnny\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-6da45515-n\jogl_awt.dll
2016-01-26 01:11 . 2016-01-26 01:11 114688 —-a-w c:\documents and settings\johnny\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-6da45515-n\jogl_cg.dll
2016-01-26 01:11 . 2016-01-26 01:11 499712 —-a-w c:\documents and settings\johnny\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-652973b9-n\msvcp71.dll
2016-01-26 01:11 . 2016-01-26 01:11 499712 —-a-w c:\documents and settings\johnny\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-652973b9-n\jmc.dll
2016-01-26 01:11 . 2016-01-26 01:11 348160 —-a-w c:\documents and settings\johnny\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-652973b9-n\msvcr71.dll
2016-01-26 01:11 . 2016-01-26 01:11 20480 —-a-w c:\documents and settings\johnny\Application Data\Sun\Java\Deployment\cache\6.0\45\4f710eed-594c3c4a-n\gluegen-rt.dll
2016-01-26 01:10 . 2016-01-26 01:09 410984 —-a-w c:\windows\system32\deploytk.dll
2016-01-26 01:07 . 2016-01-26 01:07 152576 —-a-w c:\documents and settings\johnny\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2016-01-26 00:50 . 2016-01-26 00:50 ——– d—–w c:\program files\Your Company Name
2016-01-26 00:50 . 2001-11-28 09:58 1950 —-a-w c:\windows\system32\drivers\REGISTER.SYS
2016-01-26 00:50 . 2000-06-20 07:02 306688 —-a-w c:\windows\IsUninst.exe
2016-01-26 00:48 . 2016-01-26 00:48 ——– d—a-w c:\program files\nv4loopfix
2009-05-27 03:08 . 2009-05-27 03:08 ——– d—–w c:\program files\Trend Micro
2009-05-27 02:59 . 2009-05-27 02:59 ——– d—–w c:\program files\ERUNT
2009-05-27 02:17 . 2009-05-27 02:17 3371383 —-a-w c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-27 00:42 . 2009-05-27 00:42 ——– d—–w c:\documents and settings\johnny\Application Data\Malwarebytes
2009-05-26 23:52 . 2009-05-26 18:19 19096 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-26 23:52 . 2009-05-26 18:20 40160 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 23:52 . 2009-05-27 03:05 ——– d—–w c:\program files\nadanothing
2009-05-26 23:52 . 2009-05-26 23:52 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-26 23:41 . 2009-05-26 23:41 ——– d—–w c:\documents and settings\Administrator.JOHNNY-5FA9E25A\Local Settings\Application Data\Mozilla
2009-05-26 23:21 . 2009-05-26 23:40 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-26 04:57 . 2009-05-26 04:57 0 —-a-w c:\windows\nsreg.dat
2009-05-26 04:57 . 2009-05-26 04:57 ——– d—–w c:\documents and settings\johnny\Local Settings\Application Data\Mozilla
2009-05-21 14:38 . 2009-05-21 14:38 ——– d—–w c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2009-05-21 14:34 . 2009-05-21 14:34 ——– d—–w c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-05-20 04:41 . 2009-05-20 04:41 ——– d—–w c:\documents and settings\All Users\Application Data\Installations
2009-05-20 04:38 . 2004-08-04 04:08 25600 —-a-w c:\windows\system32\drivers\usbser.sys
2009-05-08 16:29 . 2009-05-08 16:29 ——– d—–w C:\Nexon
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-01-26 01:08 . 2008-06-19 17:13 ——– d—–w c:\program files\Java
2016-01-26 01:05 . 2008-04-02 03:11 ——– d—–w c:\documents and settings\johnny\Application Data\Apple Computer
2009-05-21 14:40 . 2008-01-10 01:38 ——– d—–w c:\program files\Google
2009-05-20 04:28 . 2009-05-20 04:28 0 —ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2009-05-20 04:28 . 2009-05-20 04:28 0 —ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-05-18 17:30 . 2008-10-04 05:06 ——– d—–w c:\documents and settings\johnny\Application Data\LimeWire
2009-04-28 21:12 . 2009-04-28 21:13 171046 —-a-w c:\windows\pchealth\helpctr\Config\Cache\Professional_32_1033.dat
2009-04-28 16:33 . 2009-04-20 19:49 ——– d—–w c:\program files\Symantec AntiVirus
2009-04-20 19:52 . 2009-04-20 19:49 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-04-20 19:50 . 2007-12-13 00:34 ——– d—–w c:\program files\Symantec
2009-04-20 19:49 . 2007-12-13 00:34 ——– d—–w c:\documents and settings\All Users\Application Data\Symantec
2009-04-17 06:12 . 2009-04-17 06:11 ——– d—–w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-17 06:12 . 2009-04-17 06:12 ——– d—–w c:\program files\iPod
2009-04-17 06:11 . 2008-04-02 03:07 ——– d—–w c:\program files\Common Files\Apple
2009-04-17 06:11 . 2008-04-02 03:09 ——– d—–w c:\documents and settings\All Users\Application Data\Apple Computer
2009-04-17 06:08 . 2009-04-17 06:08 ——– d—–w c:\program files\Bonjour
2009-04-17 06:08 . 2009-04-17 06:06 ——– d—–w c:\program files\QuickTime
2009-04-02 21:29 . 2009-04-02 21:29 75048 —-a-w c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-03-26 20:23 . 2009-04-17 06:05 1900544 —-a-w c:\windows\system32\usbaaplrc.dll
2009-03-19 21:32 . 2009-03-19 21:32 23400 —-a-w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-06 14:00 . 2004-08-04 10:00 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2006-03-04 03:33 826368 —-a-w c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-12-16 94208]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2016-01-26 148888]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="d:\itunes\iTunesHelper.exe" [2009-04-02 342312]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-20 52896]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-09-28 125168]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\nadanothing\mbam.exe" [2009-05-26 1283344]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"aux"= ctwdm32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\Nexon\\Combat Arms\\NMService.exe"=
"d:\\LimeWire\\LimeWire.exe"=
"d:\\Nexon\\Combat Arms\\NMService.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/12/2008 9:03 PM 24652]
— Other Services/Drivers In Memory —
*Deregistered* - project
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Aim6 - (no file)
HKLM-Run-PRISMSVR.EXE - c:\windows\system32\PRISMSVR.EXE
SafeBoot-procexp90.Sys
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: {297DE2B6-509A-4B36-93C5-A65276606900} - hxxp://www.in.honda.com/rraaapps/rraasec/codebase/RRAAINAX/RraainAX.CAB
FF - ProfilePath - c:\documents and settings\johnny\Application Data\Mozilla\Firefox\Profiles\yk7y7sbg.default\
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJPI150_12.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPOJI610.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: d:\itunes\Mozilla Plugins\npitunes.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-28 22:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-05-29 22:40
ComboFix-quarantined-files.txt 2009-05-29 03:39
Pre-Run: 2,829,553,664 bytes free
Post-Run: 3,525,476,352 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
161 — E O F — 2009-05-11 03:50
HIJACKTHIS
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:46:04 PM, on 5/28/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\63626362.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program
Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program
Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} -
C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program
Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program
Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program
Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter
Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader
8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\nadanothing\mbam.exe"
/runcleanupscript
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common
Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} -
C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://appldnld.apple.com.edgesuite.net/co…vex/qtplugin.ca
b
O16 - DPF: {297DE2B6-509A-4B36-93C5-A65276606900} (RRAAINAX_02.RRAAINAX) -
http://www.in.honda.com/rraaapps/rraasec/c…AX/RraainAX.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google
Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile
Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program
Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program
Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program
Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. -
C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE (file
missing)
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Unknown owner -
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program
Files\Viewpoint\Common\ViewpointService.exe
–
End of file - 6362 bytes
I do not know what happen in between now and when I first began this thread but now HiJackThis runs. The HiJackThis icon used to just flash twice when I double-click it but I guess that is water under the brdige now. Here are the ComboFix and also the HiJackThis logs. Once again I appreciate you helping me.
COMBOFIX
ComboFix 09-05-28.07 - johnny 05/28/2009 22:30.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.806 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: Norton AntiVirus 2005 *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\gxvxcwbodqqoqbivtmppkkwpioaqnmejwsftb.sys
c:\windows\system32\GroupPolicy000.dat
c:\windows\system32\gxvxckgovdbopxmysvxfqhylqbubeescurrtj.dll
c:\windows\system32\gxvxcolwgvvqfwaiqvusudkgefyqxpftootpw.dll
C:\xcrashdump.dat
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_gxvxcserv.sys
((((((((((((((((((((((((( Files Created from 2009-04-28 to 2009-05-29 )))))))))))))))))))))))))))))))
.
2016-01-26 01:11 . 2016-01-26 01:11 57344 —-a-w c:\documents and settings\johnny\Application Data\Sun\Java\Deployment\cache\6.0\50\5b902232-51d78a66-n\Decora-SSE.dll
2016-01-26 01:11 . 2016-01-26 01:11 315392 —-a-w c:\documents and settings\johnny\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-6da45515-n\jogl.dll
2016-01-26 01:11 . 2016-01-26 01:11 24064 —-a-w c:\documents and settings\johnny\Application Data\Sun\Java\Deployment\cache\6.0\15\4e09eacf-5fabb0c4-n\Decora-D3D.dll
2016-01-26 01:11 . 2016-01-26 01:11 20480 —-a-w c:\documents and settings\johnny\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-6da45515-n\jogl_awt.dll
2016-01-26 01:11 . 2016-01-26 01:11 114688 —-a-w c:\documents and settings\johnny\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-6da45515-n\jogl_cg.dll
2016-01-26 01:11 . 2016-01-26 01:11 499712 —-a-w c:\documents and settings\johnny\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-652973b9-n\msvcp71.dll
2016-01-26 01:11 . 2016-01-26 01:11 499712 —-a-w c:\documents and settings\johnny\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-652973b9-n\jmc.dll
2016-01-26 01:11 . 2016-01-26 01:11 348160 —-a-w c:\documents and settings\johnny\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-652973b9-n\msvcr71.dll
2016-01-26 01:11 . 2016-01-26 01:11 20480 —-a-w c:\documents and settings\johnny\Application Data\Sun\Java\Deployment\cache\6.0\45\4f710eed-594c3c4a-n\gluegen-rt.dll
2016-01-26 01:10 . 2016-01-26 01:09 410984 —-a-w c:\windows\system32\deploytk.dll
2016-01-26 01:07 . 2016-01-26 01:07 152576 —-a-w c:\documents and settings\johnny\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2016-01-26 00:50 . 2016-01-26 00:50 ——– d—–w c:\program files\Your Company Name
2016-01-26 00:50 . 2001-11-28 09:58 1950 —-a-w c:\windows\system32\drivers\REGISTER.SYS
2016-01-26 00:50 . 2000-06-20 07:02 306688 —-a-w c:\windows\IsUninst.exe
2016-01-26 00:48 . 2016-01-26 00:48 ——– d—a-w c:\program files\nv4loopfix
2009-05-27 03:08 . 2009-05-27 03:08 ——– d—–w c:\program files\Trend Micro
2009-05-27 02:59 . 2009-05-27 02:59 ——– d—–w c:\program files\ERUNT
2009-05-27 02:17 . 2009-05-27 02:17 3371383 —-a-w c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-27 00:42 . 2009-05-27 00:42 ——– d—–w c:\documents and settings\johnny\Application Data\Malwarebytes
2009-05-26 23:52 . 2009-05-26 18:19 19096 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-26 23:52 . 2009-05-26 18:20 40160 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 23:52 . 2009-05-27 03:05 ——– d—–w c:\program files\nadanothing
2009-05-26 23:52 . 2009-05-26 23:52 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-26 23:41 . 2009-05-26 23:41 ——– d—–w c:\documents and settings\Administrator.JOHNNY-5FA9E25A\Local Settings\Application Data\Mozilla
2009-05-26 23:21 . 2009-05-26 23:40 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-05-26 04:57 . 2009-05-26 04:57 0 —-a-w c:\windows\nsreg.dat
2009-05-26 04:57 . 2009-05-26 04:57 ——– d—–w c:\documents and settings\johnny\Local Settings\Application Data\Mozilla
2009-05-21 14:38 . 2009-05-21 14:38 ——– d—–w c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2009-05-21 14:34 . 2009-05-21 14:34 ——– d—–w c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-05-20 04:41 . 2009-05-20 04:41 ——– d—–w c:\documents and settings\All Users\Application Data\Installations
2009-05-20 04:38 . 2004-08-04 04:08 25600 —-a-w c:\windows\system32\drivers\usbser.sys
2009-05-08 16:29 . 2009-05-08 16:29 ——– d—–w C:\Nexon
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-01-26 01:08 . 2008-06-19 17:13 ——– d—–w c:\program files\Java
2016-01-26 01:05 . 2008-04-02 03:11 ——– d—–w c:\documents and settings\johnny\Application Data\Apple Computer
2009-05-21 14:40 . 2008-01-10 01:38 ——– d—–w c:\program files\Google
2009-05-20 04:28 . 2009-05-20 04:28 0 —ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2009-05-20 04:28 . 2009-05-20 04:28 0 —ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-05-18 17:30 . 2008-10-04 05:06 ——– d—–w c:\documents and settings\johnny\Application Data\LimeWire
2009-04-28 21:12 . 2009-04-28 21:13 171046 —-a-w c:\windows\pchealth\helpctr\Config\Cache\Professional_32_1033.dat
2009-04-28 16:33 . 2009-04-20 19:49 ——– d—–w c:\program files\Symantec AntiVirus
2009-04-20 19:52 . 2009-04-20 19:49 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-04-20 19:50 . 2007-12-13 00:34 ——– d—–w c:\program files\Symantec
2009-04-20 19:49 . 2007-12-13 00:34 ——– d—–w c:\documents and settings\All Users\Application Data\Symantec
2009-04-17 06:12 . 2009-04-17 06:11 ——– d—–w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-17 06:12 . 2009-04-17 06:12 ——– d—–w c:\program files\iPod
2009-04-17 06:11 . 2008-04-02 03:07 ——– d—–w c:\program files\Common Files\Apple
2009-04-17 06:11 . 2008-04-02 03:09 ——– d—–w c:\documents and settings\All Users\Application Data\Apple Computer
2009-04-17 06:08 . 2009-04-17 06:08 ——– d—–w c:\program files\Bonjour
2009-04-17 06:08 . 2009-04-17 06:06 ——– d—–w c:\program files\QuickTime
2009-04-02 21:29 . 2009-04-02 21:29 75048 —-a-w c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-03-26 20:23 . 2009-04-17 06:05 1900544 —-a-w c:\windows\system32\usbaaplrc.dll
2009-03-19 21:32 . 2009-03-19 21:32 23400 —-a-w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-06 14:00 . 2004-08-04 10:00 284160 —-a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2006-03-04 03:33 826368 —-a-w c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-12-16 94208]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2016-01-26 148888]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="d:\itunes\iTunesHelper.exe" [2009-04-02 342312]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-20 52896]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-09-28 125168]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\nadanothing\mbam.exe" [2009-05-26 1283344]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"aux"= ctwdm32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\Nexon\\Combat Arms\\NMService.exe"=
"d:\\LimeWire\\LimeWire.exe"=
"d:\\Nexon\\Combat Arms\\NMService.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/12/2008 9:03 PM 24652]
— Other Services/Drivers In Memory —
*Deregistered* - project
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Aim6 - (no file)
HKLM-Run-PRISMSVR.EXE - c:\windows\system32\PRISMSVR.EXE
SafeBoot-procexp90.Sys
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: {297DE2B6-509A-4B36-93C5-A65276606900} - hxxp://www.in.honda.com/rraaapps/rraasec/codebase/RRAAINAX/RraainAX.CAB
FF - ProfilePath - c:\documents and settings\johnny\Application Data\Mozilla\Firefox\Profiles\yk7y7sbg.default\
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPJPI150_12.dll
FF - plugin: c:\program files\Java\jre1.5.0_12\bin\NPOJI610.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: d:\itunes\Mozilla Plugins\npitunes.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-28 22:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-05-29 22:40
ComboFix-quarantined-files.txt 2009-05-29 03:39
Pre-Run: 2,829,553,664 bytes free
Post-Run: 3,525,476,352 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
161 — E O F — 2009-05-11 03:50
HIJACKTHIS
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:46:04 PM, on 5/28/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\63626362.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program
Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program
Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} -
C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program
Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program
Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program
Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter
Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader
8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\nadanothing\mbam.exe"
/runcleanupscript
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common
Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} -
C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://appldnld.apple.com.edgesuite.net/co…vex/qtplugin.ca
b
O16 - DPF: {297DE2B6-509A-4B36-93C5-A65276606900} (RRAAINAX_02.RRAAINAX) -
http://www.in.honda.com/rraaapps/rraasec/c…AX/RraainAX.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google
Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile
Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program
Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program
Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program
Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. -
C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE (file
missing)
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Unknown owner -
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program
Files\Viewpoint\Common\ViewpointService.exe
–
End of file - 6362 bytes
oldman960
Hi iamquockie,
A couple of things. Please make sure wordwrap in notepad is turned off, otherwise the logs are difficult to read.
In notepad, click format, uncheck wordwrap if checked.
Did you download something from NVidia? There are a couple of folders with strange creation dates.
And what do you know about this folder, where you renaming something?
c:\program files\nadanothing
It looks like you have 2 versions of Symantec (Norton) installed, one outdated, both running during the combofix run. We will need to address this.
You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.
Open MBAM
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
Please post back with
How is the computer now?
Thanks
A couple of things. Please make sure wordwrap in notepad is turned off, otherwise the logs are difficult to read.
In notepad, click format, uncheck wordwrap if checked.
Did you download something from NVidia? There are a couple of folders with strange creation dates.
2016-01-26 00:50 . 2016-01-26 00:50 ——– d—–w c:\program files\Your Company Name
2016-01-26 00:50 . 2001-11-28 09:58 1950 —-a-w c:\windows\system32\drivers\REGISTER.SYS
2016-01-26 00:50 . 2000-06-20 07:02 306688 —-a-w c:\windows\IsUninst.exe
2016-01-26 00:48 . 2016-01-26 00:48 ——– d—a-w c:\program files\nv4loopfix
And what do you know about this folder, where you renaming something?
c:\program files\nadanothing
It looks like you have 2 versions of Symantec (Norton) installed, one outdated, both running during the combofix run. We will need to address this.
You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.
Open MBAM
- Click the Update tab
- Click Check for Updates
- If an update is found, it will download and install the latest version.
- The program will close to update and reopen.
- Once the program has loaded, select "Perform Quick Scan", then click Scan.
- The scan may take some time to finish,so please be patient.
- When the scan is complete, click OK, then Show Results to view the results.
- Make sure that everything is checked, and click Remove Selected.
- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
- Copy&Paste the entire report in your next reply.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
Please post back with
- MBAM log
How is the computer now?
Thanks
iamquockie
The computer no longer redirects when I surf. I have two versions of Norton, one that was a trial version that ran out that no longer scans even when I ask it to and the current one, Symantec which I thought I disabled all protection prior to running ComboFix. The Nvdia patch was for my video card, it was an update to my driver that fixed a problem to where my computer would not load due to a loop error during startup. Nada nothing is a folder of which I renamed in one of my attempts to run the mbam program. I will run a scan of malwarebytes and post back with a new log.
oldman960
Hi iamquockie,
Thanks for the info.
Do you have disks for your current version of Symantec?
Thanks
iamquockie
I have the current Symantec corporate saved on my zip drive that I can access anytime. I apologize for not having word wrap on on my word pad, I thought I did that too. here is my mbam log that just finished.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:46:04 PM, on 5/28/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\63626362.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program
Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program
Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} -
C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program
Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program
Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program
Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter
Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader
8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\nadanothing\mbam.exe"
/runcleanupscript
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common
Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} -
C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://appldnld.apple.com.edgesuite.net/co…vex/qtplugin.ca
b
O16 - DPF: {297DE2B6-509A-4B36-93C5-A65276606900} (RRAAINAX_02.RRAAINAX) -
http://www.in.honda.com/rraaapps/rraasec/c…AX/RraainAX.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google
Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile
Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program
Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program
Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program
Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. -
C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE (file
missing)
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Unknown owner -
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program
Files\Viewpoint\Common\ViewpointService.exe
–
End of file - 6362 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:46:04 PM, on 5/28/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\63626362.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program
Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program
Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} -
C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program
Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program
Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program
Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter
Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader
8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\nadanothing\mbam.exe"
/runcleanupscript
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common
Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network
Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} -
C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://appldnld.apple.com.edgesuite.net/co…vex/qtplugin.ca
b
O16 - DPF: {297DE2B6-509A-4B36-93C5-A65276606900} (RRAAINAX_02.RRAAINAX) -
http://www.in.honda.com/rraaapps/rraasec/c…AX/RraainAX.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google
Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile
Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program
Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program
Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program
Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. -
C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Unknown owner - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE (file
missing)
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Unknown owner -
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program
Files\Viewpoint\Common\ViewpointService.exe
–
End of file - 6362 bytes
oldman960
Hi iamquockie,
You posted an old HJ log. I need the MBAM log.
Open MBAM, click the Logs tab. Click on the one with the most recent date, then click open. Please post the concents of chat log file.
Thanks
You posted an old HJ log. I need the MBAM log.
Open MBAM, click the Logs tab. Click on the one with the most recent date, then click open. Please post the concents of chat log file.
Thanks
iamquockie
go figure, both the logs were names the exact same file name
and I was eating lunch while typing that last reply. lol I guess this is the correct one, lets try it again.
Malwarebytes' Anti-Malware 1.37
Database version: 2183
Windows 5.1.2600 Service Pack 2
5/29/2009 12:51:17 PM
mbam-log-2009-05-29 (12-51-17).txt
Scan type: Full Scan (C:\|)
Objects scanned: 115813
Time elapsed: 46 minute(s), 0 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
oldman960
Hi iamquockie,
No problem.
BitLord and LimeWire
You have BitLord and LimeWire, P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.
References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.internetworldstats.com/articles…cles/art053.htm
I would recommend that you uninstall BitLord and LimeWire, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.
If you wish to keep them, please do not use them until your computer is cleaned.
Your java is out of date. Click your start button, open Control panel.
After the java is updated, reboot your computer if not prompted to.
One more scan just to be sure.
You will need to use Internet Explorer for this scan.
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.
Please go to Kaspersky website and perform an online antivirus scan.
Thanks
No problem.
BitLord and LimeWire
You have BitLord and LimeWire, P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.
References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.internetworldstats.com/articles…cles/art053.htm
I would recommend that you uninstall BitLord and LimeWire, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.
If you wish to keep them, please do not use them until your computer is cleaned.
Your java is out of date. Click your start button, open Control panel.
- Locate the Java icon (it looks like a coffee cup)
- double click it to open it
- click the Update tab
- Click update now
After the java is updated, reboot your computer if not prompted to.
One more scan just to be sure.
You will need to use Internet Explorer for this scan.
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.
Please go to Kaspersky website and perform an online antivirus scan.
- Read through the requirements and privacy statement and click on Accept button.
- It will start downloading and installing the scanner and virus definitions.
- You will be prompted to install an application from Kaspersky. Click Run.
- When the downloads have finished, click on Settings.
- Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
- Spyware, Adware, Dialers, and other potentially dangerous programs
- Archives
- Mail databases
- Click on My Computerr under Scan.
- Once the scan is complete, it will display the results. Click on View Scan Report.
- You will see a list of infected items there. Click on Save Report As….
- Change the Files of type to Text file (.txt)
- Set the Save In to Desktop
- click the Save button.
- Please post this log in your next reply along with a new HijackThis log.
Thanks
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI