This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Computer freezing up

36 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey!

I've been encountering random crashes while using a variation of programs recently. I recieve no error message, the current window locks up, I can move around for a bit but eventually me entire computer will crash– forcing me to reboot.



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:36:52 PM, on 7/23/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\EeePC\ACPI\AsTray.exe
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
C:\Program Files\EeePC\ACPI\AsEPCMon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\TASKBA~1\TaskBar.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: AOLSearchHook Class - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AIM Search\AOLSearch.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AOL Search Enhancement - {54EB34EA-E6BE-4CFD-9F4F-C4A0C2EAFA22} - C:\Program Files\AIM Search\AOLSearch.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe
O4 - HKLM\..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
O4 - HKLM\..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Taskbar Hide] C:\PROGRA~1\TASKBA~1\TaskBar.exe -Start
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: SuperHybridEngine.lnk = ?
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 5801 bytes
Hi and Welcome,

NOTE:
  • Malware removal is NOT instantaneous, most infections require several courses of action to completely eradicate.
  • Absence of symptoms does not always mean the computer is clean
  • Kindly follow my instructions in the order posted.
  • Please DO NOT run any scans or fix items without my direction.



Please do the following:

STEP #1

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


STEP #2


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Thank you for the welcome! The third scan cannot be completed though, due to my computer freezing up before it's finished. I've tried six times with little luck. DDS- DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 17:21:22.45 on Thu 07/23/2009 Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.615 [GMT -8:00] AV: AVG Anti-Virus *On-access scanning enabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Viewpoint\Common\ViewpointService.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\EeePC\ACPI\AsTray.exe C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe C:\Program Files\EeePC\ACPI\AsEPCMon.exe C:\WINDOWS\system32\igfxext.exe C:\Program Files\Messenger\msmsgs.exe C:\PROGRA~1\TASKBA~1\TaskBar.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Nigel Adamson\Desktop\dds.pif ============== Pseudo HJT Report =============== uStart Page = hxxp://google.com/ mDefault_Search_URL = hxxp://www.google.com/ie mSearchAssistant = hxxp://www.google.com/ie uURLSearchHooks: AOLSearchHook Class: {54eb34ea-e6be-4cfd-9f4f-c4a0c2eafa22} - c:\program files\aim search\AOLSearch.dll BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: AOLSearchHook Class: {54eb34ea-e6be-4cfd-9f4f-c4a0c2eafa22} - c:\program files\aim search\AOLSearch.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [Taskbar Hide] c:\progra~1\taskba~1\TaskBar.exe -Start mRun: [RTHDCPL] RTHDCPL.EXE mRun: [SoundMan] SOUNDMAN.EXE mRun: [AlcWzrd] ALCWZRD.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [AsusTray] c:\program files\eeepc\acpi\AsTray.exe mRun: [AsusACPIServer] c:\program files\eeepc\acpi\AsAcpiSvr.exe mRun: [AsusEPCMonitor] c:\program files\eeepc\acpi\AsEPCMon.exe mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\superh~1.lnk - c:\program files\asus\eeepc\super hybrid engine\SuperHybridEngine.exe IE: Send to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxdev.dll SEH: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No File ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-3-1 325128] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-3-1 27656] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-3-1 107272] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-3-1 298264] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-3-3 24652] R3 AsusACPI;ASUS ACPI Driver;c:\windows\system32\drivers\ASUSACPI.SYS [2008-5-22 11264] R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [2008-5-18 36864] R3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [2008-5-22 625024] S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-3-1 903960] =============== Created Last 30 ================ 2009-07-23 16:23 –d—– c:\program files\Trend Micro 2009-07-22 18:48 –d—– c:\docume~1\nigela~1\applic~1\SUPERAntiSpyware.com 2009-07-22 12:58 118 a——- c:\windows\system32\MRT.INI 2009-07-22 00:26 –ds—- c:\documents and settings\nigel adamson\UserData 2009-07-21 14:50 –d—– c:\docume~1\nigela~1\applic~1\Malwarebytes 2009-07-21 14:30 1,100 a——- c:\windows\system32\d3d8caps.dat 2009-07-21 14:22 272,128 -c—— c:\windows\system32\dllcache\bthport.sys 2009-07-21 14:22 272,128 ——– c:\windows\system32\drivers\bthport.sys 2009-07-21 11:37 203,136 -c—— c:\windows\system32\dllcache\rmcast.sys 2009-07-21 11:37 455,296 -c—— c:\windows\system32\dllcache\mrxsmb.sys 2009-07-21 11:36 333,952 -c—— c:\windows\system32\dllcache\srv.sys 2009-07-21 11:36 331,776 -c—— c:\windows\system32\dllcache\msadce.dll 2009-07-21 11:36 691,712 -c—— c:\windows\system32\dllcache\inetcomm.dll 2009-07-21 11:33 247,326 -c—— c:\windows\system32\dllcache\strmdll.dll 2009-07-21 11:33 337,408 -c—— c:\windows\system32\dllcache\netapi32.dll 2009-07-21 11:32 1,106,944 -c—— c:\windows\system32\dllcache\msxml3.dll 2009-07-21 11:29 2,560 ——– c:\windows\system32\xpsp4res.dll 2009-07-21 11:29 1,203,922 -c—— c:\windows\system32\dllcache\sysmain.sdb 2009-07-21 11:29 215,552 -c—— c:\windows\system32\dllcache\wordpad.exe 2009-07-21 11:27 –d—– c:\windows\system32\PreInstall 2009-07-21 11:27 22,752 a——- c:\windows\system32\spupdsvc.exe 2009-07-20 19:42 345,600 -c—— c:\windows\system32\dllcache\localspl.dll 2009-07-20 19:42 8,461,312 -c—— c:\windows\system32\dllcache\shell32.dll 2009-07-20 19:42 138,496 -c—— c:\windows\system32\dllcache\afd.sys 2009-07-20 19:16 –d—– c:\program files\Spybot - Search & Destroy 2009-07-20 19:16 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy 2009-07-20 18:58 268,648 a——- c:\windows\system32\mucltui.dll 2009-07-20 18:58 208,744 a——- c:\windows\system32\muweb.dll 2009-07-20 18:58 27,496 a——- c:\windows\system32\mucltui.dll.mui 2009-07-20 18:50 39,424 a——- c:\windows\zipinst.exe 2009-07-20 18:50 –d—– c:\program files\ShellExView 2009-07-20 18:10 –d—– c:\program files\Taskbar Hide 2009-07-20 14:39 –d—– c:\docume~1\nigela~1\applic~1\LimeWire 2009-07-20 12:43 –d—– c:\documents and settings\nigel adamson\Bluetooth Software 2009-07-20 12:43 –d—– c:\documents and settings\Nigel Adamson 2009-07-20 08:57 –d—– c:\windows\system32\LogFiles 2009-07-19 23:53 151,044 a——- c:\windows\msb.exe ==================== Find3M ==================== 2009-06-18 04:08 2,098 a–sh— c:\windows\system32\KGyGaAvL.sys 2009-06-16 06:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 06:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-03 11:09 1,291,264 a——- c:\windows\system32\quartz.dll 2009-05-07 07:32 345,600 a——- c:\windows\system32\localspl.dll 2009-05-03 21:10 410,984 a——- c:\windows\system32\deploytk.dll 2009-05-02 14:53 33,968 a—h— c:\windows\system32\mlfcache.dat 2009-04-28 20:46 666,624 a——- c:\windows\system32\wininet.dll 2009-04-28 20:46 81,920 a——- c:\windows\system32\ieencode.dll 2009-03-01 16:12 32 a——- c:\docume~1\alluse~1\applic~1\ezsid.dat 2005-04-16 12:43 244,224 a–shr– c:\windows\plugin.dat ============= FINISH: 17:21:59.34 =============== Attach- UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume1 Install Date: 3/1/2009 6:21:54 PM System Uptime: 7/23/2009 4:26:28 PM (1 hours ago) Motherboard: ASUSTeK Computer INC. | | 901 Processor: Intel® Atom™ CPU N270 @ 1.60GHz | Socket 478M | 1600/133mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 4 GiB total, 0.644 GiB free. ==== Disabled Device Manager Items ============= ==== System Restore Points =================== No restore point in system. ==== Installed Programs ====================== 7-Zip 4.65 Adabas D 13.01.00 Adobe Flash Player 10 ActiveX Adobe Shockwave Player 11.5 AIM 6 AIM Search Asus ACPI Driver ASUSUpdate for Eee PC Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver AVG Free 8.0 Azurewave Wireless LAN Build Your Own Net Dream (remove only) CCleaner (remove only) Choice Guard Download Updater (AOL LLC) Eee Instant Key Eusing Free Registry Cleaner HijackThis 2.0.2 Hotfix for Windows XP (KB952287) Intel® Graphics Media Accelerator Driver InterVideo Register Manager InterVideo WinDVD Java™ 6 Update 13 JGoodies JDiskReport 1.3.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 1.1 Hotfix (KB929729) Microsoft .NET Framework 2.0 Microsoft Application Error Reporting Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft VC9 runtime libraries Microsoft Visual C++ 2005 Redistributable mIRC MSVCRT Realtek High Definition Audio Driver RegCure 1.5.2.7 RPGXP Security Update for Windows Media Player (KB952069) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969897) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB973346) Segoe UI ShellExView Super Hybrid Engine Taskbar Hide Update for Windows XP (KB898461) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Viewpoint Media Player WebFldrs XP Where'd My Space Go version 1.0 WIDCOMM Bluetooth Software Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Mail Windows Live OneCare safety scanner Windows Live Sign-in Assistant Windows Live Upload Tool Yugioh Virtual Dueling ==== Event Viewer Messages From Past Week ======== 7/22/2009 6:48:02 PM, error: Service Control Manager [7023] - The Application Management service terminated with the following error: The specified module could not be found. 7/22/2009 1:04:48 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070003: Security Update for Windows XP (KB956572). 7/21/2009 11:41:55 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AvgLdx86 AvgMfx86 AvgTdiX Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SASDIFSV SASKUTIL Tcpip 7/21/2009 11:41:55 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. 7/21/2009 11:41:55 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 7/21/2009 11:41:55 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 7/21/2009 11:41:55 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 7/21/2009 11:41:19 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 7/20/2009 9:58:13 AM, error: Service Control Manager [7031] - The AVG Free8 WatchDog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 7/20/2009 8:52:42 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the WZCSVC service. 7/20/2009 5:43:49 PM, error: PlugPlayManager [12] - The device '802.11n Wireless LAN Card' (PCI\VEN_1814&DEV_0781&SUBSYS_27901814&REV_00\4&37028e5f&0&00E3) disappeared from the system without first being prepared for removal. 7/20/2009 10:31:42 AM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). ==== End Of File ===========================
Hi, I really would like to get a scan for rootkits before we proceed. Couple of things to try: Try running GMER in safe mode, if it wont run, try renaming it to REMG.exe
GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-07-24 14:51:13
Windows 5.1.2600 Service Pack 3


—- Devices - GMER 1.0.15 —-

Device \Driver\ACPI \Device\00000040 8615E1C0
Device \Driver\ACPI \Device\00000046 8615E1C0
Device \Driver\ACPI \Device\00000060 8615E1C0
Device \Driver\ACPI \Device\00000062 8615E1C0
Device \Driver\ACPI \Device\00000056 8615E1C0
Device \Driver\ACPI \Device\00000057 8615E1C0
Device \Driver\ACPI \Device\00000063 8615E1C0
Device \Driver\ACPI \Device\00000058 8615E1C0
Device \Driver\ACPI \Device\0000003a 8615E1C0
Device \Driver\ACPI \Device\0000003b 8615E1C0
Device \Driver\ACPI \Device\0000003c 8615E1C0
Device \Driver\ACPI \Device\0000003e 8615E1C0
Device \Driver\ACPI \Device\0000004b 8615E1C0
Device \Driver\ACPI \Device\0000003f 8615E1C0
Device \Driver\ACPI \Device\0000004c 8615E1C0
Device \Driver\ACPI \Device\0000004d 8615E1C0
Device \Driver\ACPI \Device\0000005b 8615E1C0
Device \Driver\ACPI \Device\0000004e 8615E1C0
Device \Driver\ACPI \Device\0000004f 8615E1C0
Device \Driver\ACPI \Device\0000005f 8615E1C0

—- Threads - GMER 1.0.15 —-

Thread System [4:180] 8613F7AB

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\@P_9}\2ó7}\x90\x203aó\0\4ï\xb8\0Nô7}\x90\x203aó\0\24ï\xb8\0v`,}X_9}L\t ?j??????????h?H??j????G???Wj?j?h I???U???}?P???C???Ph?a??h?;?

—- EOF - GMER 1.0.15 —-
Hi,

Please do the following:


Download Combofix from either of the links below. You must rename it before saving it.
Save it to your desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


Link 1
Link 2



During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.


———————————————————–

  • Double click on Combo-Fix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\Combo-Fix.txt" for further review.
    **Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**


    ———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

ComboFix 09-07-22.05 - Nigel Adamson 07/24/2009 15:14.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.633 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus *On-access scanning enabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-1-5-21-57989841-2000478354-1547161642-1003
c:\windows\Installer\1bb2df.msi
c:\windows\Installer\2cde4b.msi
c:\windows\Installer\2cde53.msi
c:\windows\Installer\2cde5f.msi
c:\windows\Installer\533c4d.msi
c:\windows\system32\wbem\proquota.exe

c:\windows\system32\proquota.exe . . . is missing!!

.
((((((((((((((((((((((((( Files Created from 2009-06-24 to 2009-07-24 )))))))))))))))))))))))))))))))
.

2009-07-24 00:23 . 2009-07-24 00:23 ——– d—–w- c:\program files\Trend Micro
2009-07-23 23:17 . 2009-07-23 23:17 1914000 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe
2009-07-23 23:16 . 2009-07-24 00:09 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-07-23 23:16 . 2009-07-24 00:09 ——– d—–w- c:\program files\NOS
2009-07-23 02:48 . 2009-07-23 02:48 ——– d—–w- c:\documents and settings\Nigel Adamson\Application Data\SUPERAntiSpyware.com
2009-07-22 08:26 . 2009-07-22 08:26 ——– d-s—w- c:\documents and settings\Nigel Adamson\UserData
2009-07-22 03:42 . 2009-07-22 03:42 ——– d—–w- c:\documents and settings\Guest\Application Data\Spyware Terminator
2009-07-21 22:50 . 2009-07-21 22:50 ——– d—–w- c:\documents and settings\Nigel Adamson\Application Data\Malwarebytes
2009-07-21 22:30 . 2009-07-21 22:34 1100 —-a-w- c:\windows\system32\d3d8caps.dat
2009-07-21 22:22 . 2008-06-13 11:05 272128 -c—-w- c:\windows\system32\dllcache\bthport.sys
2009-07-21 22:22 . 2008-06-13 11:05 272128 ——w- c:\windows\system32\drivers\bthport.sys
2009-07-21 19:37 . 2008-05-08 14:02 203136 -c—-w- c:\windows\system32\dllcache\rmcast.sys
2009-07-21 19:37 . 2008-10-24 11:21 455296 -c—-w- c:\windows\system32\dllcache\mrxsmb.sys
2009-07-21 19:36 . 2008-12-11 10:57 333952 -c—-w- c:\windows\system32\dllcache\srv.sys
2009-07-21 19:36 . 2008-05-01 14:33 331776 -c—-w- c:\windows\system32\dllcache\msadce.dll
2009-07-21 19:36 . 2008-04-11 19:04 691712 -c—-w- c:\windows\system32\dllcache\inetcomm.dll
2009-07-21 19:33 . 2008-10-03 10:02 247326 -c—-w- c:\windows\system32\dllcache\strmdll.dll
2009-07-21 19:33 . 2008-10-15 16:34 337408 -c—-w- c:\windows\system32\dllcache\netapi32.dll
2009-07-21 19:32 . 2008-09-04 17:15 1106944 -c—-w- c:\windows\system32\dllcache\msxml3.dll
2009-07-21 19:29 . 2008-05-03 11:55 2560 ——w- c:\windows\system32\xpsp4res.dll
2009-07-21 19:29 . 2008-04-21 12:08 215552 -c—-w- c:\windows\system32\dllcache\wordpad.exe
2009-07-21 19:27 . 2008-07-09 07:38 26488 —-a-w- c:\windows\system32\spupdsvc.exe
2009-07-21 19:26 . 2009-07-24 20:19 ——– d–h–w- c:\windows\$hf_mig$
2009-07-21 03:42 . 2009-05-07 15:32 345600 -c—-w- c:\windows\system32\dllcache\localspl.dll
2009-07-21 03:42 . 2008-06-17 19:02 8461312 -c—-w- c:\windows\system32\dllcache\shell32.dll
2009-07-21 03:42 . 2008-08-14 10:04 138496 -c—-w- c:\windows\system32\dllcache\afd.sys
2009-07-21 03:16 . 2009-07-22 21:09 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-07-21 03:16 . 2009-07-22 21:08 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-21 02:58 . 2008-10-16 22:06 268648 —-a-w- c:\windows\system32\mucltui.dll
2009-07-21 02:58 . 2008-10-16 22:06 208744 —-a-w- c:\windows\system32\muweb.dll
2009-07-21 02:57 . 2009-07-21 02:57 37712 —-a-w- c:\documents and settings\Nigel Adamson\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-21 02:50 . 2009-07-21 02:50 39424 —-a-w- c:\windows\zipinst.exe
2009-07-21 02:50 . 2009-07-21 02:52 ——– d—–w- c:\program files\ShellExView
2009-07-21 02:10 . 2009-07-21 02:10 ——– d—–w- c:\program files\Taskbar Hide
2009-07-20 22:39 . 2009-07-20 22:39 98304 —-a-w- c:\documents and settings\Nigel Adamson\Application Data\LimeWire\browser\xulrunner\nssdbm3.dll
2009-07-20 16:57 . 2009-07-20 16:57 ——– d—–w- c:\windows\system32\LogFiles
2009-07-20 07:53 . 2009-07-20 07:53 151044 —-a-w- c:\windows\msb.exe
2009-07-12 05:38 . 2009-07-12 05:38 ——– d-s—w- c:\documents and settings\Guest\UserData
2009-07-12 00:41 . 2009-07-12 00:41 37712 —-a-w- c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-12 00:41 . 2009-07-12 00:41 ——– d—–w- c:\documents and settings\Guest\Local Settings\Application Data\Google

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-24 20:22 . 2009-03-03 03:44 ——– d—–w- c:\program files\flupScript
2009-07-21 06:26 . 2009-07-20 22:39 ——– d—–w- c:\documents and settings\Nigel Adamson\Application Data\LimeWire
2009-07-21 02:12 . 2009-03-10 04:10 ——– d—–w- c:\program files\Eusing Free Registry Cleaner
2009-07-20 22:39 . 2009-07-20 22:39 9216 —-a-w- c:\documents and settings\Nigel Adamson\Application Data\LimeWire\browser\xulrunner\plds4.dll
2009-07-20 16:59 . 2009-06-02 01:39 ——– d—–w- c:\program files\Google
2009-07-20 16:59 . 2008-05-23 02:14 ——– d—–w- c:\program files\ASUS
2009-07-20 16:59 . 2008-05-23 02:07 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-04 09:44 . 2009-05-11 05:16 ——– d—–w- c:\program files\Windows Live Safety Center
2009-06-18 12:08 . 2009-06-16 12:26 2098 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-06-18 12:07 . 2009-06-16 12:26 56 –sh–r- c:\windows\system32\26B76D7757.sys
2009-06-16 14:36 . 2008-04-25 05:06 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2008-04-25 05:04 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-14 20:06 . 2008-05-23 03:11 ——– d—–w- c:\program files\Java
2009-06-03 19:09 . 2008-04-25 05:05 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-06-01 20:27 . 2009-06-01 20:17 ——– d—–w- c:\program files\AIM Toolbar
2009-06-01 20:19 . 2009-03-04 02:37 ——– d—–w- c:\program files\AIM6
2009-06-01 20:17 . 2009-03-04 02:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-05-29 15:21 . 2009-05-29 15:21 ——– d—–w- c:\program files\Enterbrain
2009-05-28 23:47 . 2009-05-28 23:47 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-05-28 23:47 . 2009-05-28 23:47 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-05-27 14:48 . 2009-05-27 14:48 0 —-a-w- c:\windows\nsreg.dat
2009-05-07 15:32 . 2008-04-25 05:04 345600 —-a-w- c:\windows\system32\localspl.dll
2009-05-04 05:10 . 2009-03-10 06:17 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-05-02 22:53 . 2009-05-02 22:53 33968 —ha-w- c:\windows\system32\mlfcache.dat
2009-04-29 04:46 . 2008-04-25 05:06 666624 —-a-w- c:\windows\system32\wininet.dll
2009-04-29 04:46 . 2008-04-25 05:04 81920 —-a-w- c:\windows\system32\ieencode.dll
2005-04-16 20:43 . 2005-04-16 20:43 244224 –sha-r- c:\windows\plugin.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"Taskbar Hide"="c:\progra~1\TASKBA~1\TaskBar.exe" [2008-10-17 402432]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2008-05-21 98304]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2008-05-21 479232]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2008-05-20 94208]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-01 1601304]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-04-28 16861696]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SoundMan.exe [2006-07-21 86016]
"AlcWzrd"="ALCWZRD.EXE" - c:\windows\alcwzrd.exe [2006-05-04 2808832]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-1-28 576104]
SuperHybridEngine.lnk - c:\program files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2008-5-22 294912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-01 22:53 10520 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BYOND\\bin\\byond.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\flupScript\\mirc.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\BYOND\\bin\\dreamseeker.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/1/2009 2:53 PM 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/1/2009 2:53 PM 107272]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/1/2009 2:52 PM 298264]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [3/3/2009 6:42 PM 24652]
R3 AsusACPI;ASUS ACPI Driver;c:\windows\system32\drivers\ASUSACPI.SYS [5/22/2008 6:11 PM 11264]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [5/18/2008 11:26 PM 36864]
R3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [5/22/2008 6:11 PM 625024]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [3/1/2009 2:52 PM 903960]
.
Contents of the 'Scheduled Tasks' folder

2009-07-24 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 17:58]

2009-07-09 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 17:58]
.
- - - - ORPHANS REMOVED - - - -

ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.com/
IE: Send to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-24 15:19
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•A~*]
"?????ó?¸???ó?¸?????"=multi:"\10j\03‹Îè×ûÿÿëµhÈH\00\10j\01‹ÎèGûÿÿWj\00j\00h I\00\10ÿUü…À}\15P‹ÎèC¢\01\00Ph¯a\00\00h¨;\00\00"
.
Completion time: 2009-07-24 15:23
ComboFix-quarantined-files.txt 2009-07-24 23:23

Pre-Run: 590,045,184 bytes free
Post-Run: 810,971,136 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

177 — E O F — 2009-07-24 20:20
Please do the following:

Go Start > Run and copy/paste the following single-line command into the Run box and click OK:
cmd /c PEV -l "%systemdrive%\proquota.exe" >Log.txt&Log.txt&del Log.txt
A Notepad file will open.
Post the contents of Log.txt in your next reply.
Entries: 0 (0) Directories: 0 Files: 0 Bytes: 0 Blocks: 0 I have came across another symptom, it seems if my computer doesn't crash for a while, the explorer.exe becomes huge. It starts at 15,000 or so upon boot, and it is currently 120,000.
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Computer_freezing_up_t105443.html&view=findpost&p=581031#entry581031

Collect::
c:\windows\msb.exe

SRPeek::
c:\windows\system32\proquota.exe

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
ComboFix 09-07-22.05 - Nigel Adamson 07/24/2009 16:41.2.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.555 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Nigel Adamson\Desktop\CFScript.txt
AV: AVG Anti-Virus *On-access scanning enabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

file zipped: c:\windows\msb.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\msb.exe

c:\windows\system32\proquota.exe . . . is missing!!

.
((((((((((((((((((((((((( Files Created from 2009-06-25 to 2009-07-25 )))))))))))))))))))))))))))))))
.

2009-07-24 00:23 . 2009-07-24 00:23 ——– d—–w- c:\program files\Trend Micro
2009-07-23 23:17 . 2009-07-23 23:17 1914000 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe
2009-07-23 23:16 . 2009-07-24 00:09 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-07-23 23:16 . 2009-07-24 00:09 ——– d—–w- c:\program files\NOS
2009-07-23 02:48 . 2009-07-23 02:48 ——– d—–w- c:\documents and settings\Nigel Adamson\Application Data\SUPERAntiSpyware.com
2009-07-22 08:26 . 2009-07-22 08:26 ——– d-s—w- c:\documents and settings\Nigel Adamson\UserData
2009-07-22 03:42 . 2009-07-22 03:42 ——– d—–w- c:\documents and settings\Guest\Application Data\Spyware Terminator
2009-07-21 22:50 . 2009-07-21 22:50 ——– d—–w- c:\documents and settings\Nigel Adamson\Application Data\Malwarebytes
2009-07-21 22:30 . 2009-07-21 22:34 1100 —-a-w- c:\windows\system32\d3d8caps.dat
2009-07-21 22:22 . 2008-06-13 11:05 272128 -c—-w- c:\windows\system32\dllcache\bthport.sys
2009-07-21 22:22 . 2008-06-13 11:05 272128 ——w- c:\windows\system32\drivers\bthport.sys
2009-07-21 19:37 . 2008-05-08 14:02 203136 -c—-w- c:\windows\system32\dllcache\rmcast.sys
2009-07-21 19:37 . 2008-10-24 11:21 455296 -c—-w- c:\windows\system32\dllcache\mrxsmb.sys
2009-07-21 19:36 . 2008-12-11 10:57 333952 -c—-w- c:\windows\system32\dllcache\srv.sys
2009-07-21 19:36 . 2008-05-01 14:33 331776 -c—-w- c:\windows\system32\dllcache\msadce.dll
2009-07-21 19:36 . 2008-04-11 19:04 691712 -c—-w- c:\windows\system32\dllcache\inetcomm.dll
2009-07-21 19:33 . 2008-10-03 10:02 247326 -c—-w- c:\windows\system32\dllcache\strmdll.dll
2009-07-21 19:33 . 2008-10-15 16:34 337408 -c—-w- c:\windows\system32\dllcache\netapi32.dll
2009-07-21 19:32 . 2008-09-04 17:15 1106944 -c—-w- c:\windows\system32\dllcache\msxml3.dll
2009-07-21 19:29 . 2008-05-03 11:55 2560 ——w- c:\windows\system32\xpsp4res.dll
2009-07-21 19:29 . 2008-04-21 12:08 215552 -c—-w- c:\windows\system32\dllcache\wordpad.exe
2009-07-21 19:27 . 2008-07-09 07:38 26488 —-a-w- c:\windows\system32\spupdsvc.exe
2009-07-21 19:26 . 2009-07-24 20:19 ——– d–h–w- c:\windows\$hf_mig$
2009-07-21 03:42 . 2009-05-07 15:32 345600 -c—-w- c:\windows\system32\dllcache\localspl.dll
2009-07-21 03:42 . 2008-06-17 19:02 8461312 -c—-w- c:\windows\system32\dllcache\shell32.dll
2009-07-21 03:42 . 2008-08-14 10:04 138496 -c—-w- c:\windows\system32\dllcache\afd.sys
2009-07-21 03:16 . 2009-07-22 21:09 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-07-21 03:16 . 2009-07-22 21:08 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-21 02:58 . 2008-10-16 22:06 268648 —-a-w- c:\windows\system32\mucltui.dll
2009-07-21 02:58 . 2008-10-16 22:06 208744 —-a-w- c:\windows\system32\muweb.dll
2009-07-21 02:57 . 2009-07-21 02:57 37712 —-a-w- c:\documents and settings\Nigel Adamson\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-21 02:50 . 2009-07-21 02:50 39424 —-a-w- c:\windows\zipinst.exe
2009-07-21 02:50 . 2009-07-21 02:52 ——– d—–w- c:\program files\ShellExView
2009-07-21 02:10 . 2009-07-21 02:10 ——– d—–w- c:\program files\Taskbar Hide
2009-07-20 22:39 . 2009-07-20 22:39 98304 —-a-w- c:\documents and settings\Nigel Adamson\Application Data\LimeWire\browser\xulrunner\nssdbm3.dll
2009-07-20 16:57 . 2009-07-20 16:57 ——– d—–w- c:\windows\system32\LogFiles
2009-07-12 05:38 . 2009-07-12 05:38 ——– d-s—w- c:\documents and settings\Guest\UserData
2009-07-12 00:41 . 2009-07-12 00:41 37712 —-a-w- c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-12 00:41 . 2009-07-12 00:41 ——– d—–w- c:\documents and settings\Guest\Local Settings\Application Data\Google

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-24 20:22 . 2009-03-03 03:44 ——– d—–w- c:\program files\flupScript
2009-07-21 06:26 . 2009-07-20 22:39 ——– d—–w- c:\documents and settings\Nigel Adamson\Application Data\LimeWire
2009-07-21 02:12 . 2009-03-10 04:10 ——– d—–w- c:\program files\Eusing Free Registry Cleaner
2009-07-20 22:39 . 2009-07-20 22:39 9216 —-a-w- c:\documents and settings\Nigel Adamson\Application Data\LimeWire\browser\xulrunner\plds4.dll
2009-07-20 16:59 . 2009-06-02 01:39 ——– d—–w- c:\program files\Google
2009-07-20 16:59 . 2008-05-23 02:14 ——– d—–w- c:\program files\ASUS
2009-07-20 16:59 . 2008-05-23 02:07 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-04 09:44 . 2009-05-11 05:16 ——– d—–w- c:\program files\Windows Live Safety Center
2009-06-18 12:08 . 2009-06-16 12:26 2098 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-06-18 12:07 . 2009-06-16 12:26 56 –sh–r- c:\windows\system32\26B76D7757.sys
2009-06-16 14:36 . 2008-04-25 05:06 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2008-04-25 05:04 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-14 20:06 . 2008-05-23 03:11 ——– d—–w- c:\program files\Java
2009-06-03 19:09 . 2008-04-25 05:05 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-06-01 20:27 . 2009-06-01 20:17 ——– d—–w- c:\program files\AIM Toolbar
2009-06-01 20:19 . 2009-03-04 02:37 ——– d—–w- c:\program files\AIM6
2009-06-01 20:17 . 2009-03-04 02:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-05-29 15:21 . 2009-05-29 15:21 ——– d—–w- c:\program files\Enterbrain
2009-05-28 23:47 . 2009-05-28 23:47 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-05-28 23:47 . 2009-05-28 23:47 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-05-27 14:48 . 2009-05-27 14:48 0 —-a-w- c:\windows\nsreg.dat
2009-05-07 15:32 . 2008-04-25 05:04 345600 —-a-w- c:\windows\system32\localspl.dll
2009-05-04 05:10 . 2009-03-10 06:17 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-05-02 22:53 . 2009-05-02 22:53 33968 —ha-w- c:\windows\system32\mlfcache.dat
2009-04-29 04:46 . 2008-04-25 05:06 666624 —-a-w- c:\windows\system32\wininet.dll
2009-04-29 04:46 . 2008-04-25 05:04 81920 —-a-w- c:\windows\system32\ieencode.dll
2005-04-16 20:43 . 2005-04-16 20:43 244224 –sha-r- c:\windows\plugin.dat
.

(((((((((((((((((((((((((((((((((((((((((( SR_Search ))))))))))))))))))))))))))))))))))))))))))))))))))))))))

c:\windows\system32\wbem\proquota.exe [x]
[-] 8D6465C1901F69C00952F1BBABECE604 40448 \RP1\A0000022.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-07-24_23.20.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-25 00:18 . 2009-07-25 00:18 16384 c:\windows\Temp\Perflib_Perfdata_504.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"Taskbar Hide"="c:\progra~1\TASKBA~1\TaskBar.exe" [2008-10-17 402432]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2008-05-21 98304]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2008-05-21 479232]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2008-05-20 94208]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-01 1601304]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-04-28 16861696]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SoundMan.exe [2006-07-21 86016]
"AlcWzrd"="ALCWZRD.EXE" - c:\windows\alcwzrd.exe [2006-05-04 2808832]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-1-28 576104]
SuperHybridEngine.lnk - c:\program files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2008-5-22 294912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-01 22:53 10520 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BYOND\\bin\\byond.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\flupScript\\mirc.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\BYOND\\bin\\dreamseeker.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/1/2009 2:53 PM 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/1/2009 2:53 PM 107272]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/1/2009 2:52 PM 298264]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [3/3/2009 6:42 PM 24652]
R3 AsusACPI;ASUS ACPI Driver;c:\windows\system32\drivers\ASUSACPI.SYS [5/22/2008 6:11 PM 11264]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [5/18/2008 11:26 PM 36864]
R3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [5/22/2008 6:11 PM 625024]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [3/1/2009 2:52 PM 903960]
.
Contents of the 'Scheduled Tasks' folder

2009-07-25 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 17:58]

2009-07-09 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-12-29 17:58]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://google.com/
IE: Send to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-24 16:45
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•A~*]
"?????ó?¸???ó?¸?????"=multi:"\10j\03‹Îè×ûÿÿëµhÈH\00\10j\01‹ÎèGûÿÿWj\00j\00h I\00\10ÿUü…À}\15P‹ÎèC¢\01\00Ph¯a\00\00h¨;\00\00"
.
Completion time: 2009-07-25 16:48
ComboFix-quarantined-files.txt 2009-07-25 00:48
ComboFix2.txt 2009-07-24 23:23

Pre-Run: 801,153,024 bytes free
Post-Run: 807,849,984 bytes free

172 — E O F — 2009-07-24 20:20
Upload was successful
Hi,

Please do the following:

  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


    8D6465C1901F69C00952F1BBABECE604 40448 \RP1\A0000022.exe

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.
It won't upload for some reason, I click and wait, but the screen remains the same and no information appears. Any other virus scanners we could use? Thanks. edit: after trying other file via 'browse'', they seem to scan, but when I paste the file link in it doesn't work. Where can I find the specific file?
Hi,

after doing a little more research, I don't believe that file is going to help us anyway.

One of your system files is missing and needs to be replaced.

You will need your XP installation disk for this (borrow one of the same OS if you don't have one)


then you will need to do the following:

Go to Start > Run.In the Run box, type in cmd and hit enter.

This opens the command prompt window.

Now type in the following red text exactly as seen. (if your cd drive is not D - change it to the appropriate letter)

expand D:\i386\proquota.ex_ c:\windows\system32\proquota.exe

There are two spaces in there, so I have pointed out below where they are.

ExpandSPACED:\i386\proquota.ex_SPACEc:\windows\system32\proquota.exe

If done correctly, it will say "one file(s) expanded successfully".

Let me know how it goes.
Alright, I'll order one then try that out. Thanks. edit: what do I order exactly? Windows XP recovery disk?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI