This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Attacked by Packed Generic 233 after Fresh Installatio

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Guys!

After i had completed a fresh WINXP SP2 install i was attacked by this

Packed.Generic.233 Virus!

I was using my IE 6 which comes builtin and had no Antivirus installed.

Then i installed NAV Enteprise Edition 7 and it detects the virus in the Temp folder .


Here are the steps i have already done to contain the virus
——————————————————–
1> Installed Winpatrol & ERUNT. AND LATEST fIREFOX Updated .
1.1> Installed & Run Malwarebytes's Anti-Malware and Updated . (it dectected 10 files infected, i have the ORIGINAL Mlog)
2> Disabled system restore .
3> Onrestart it used to start giving Dr. watson error.. SO i uninstalled the NAV program. It stopped giving the error.
4> ReScanned with Malwarebyte's.. it showed 2 infected entries of the registry ( have the 2ndlog file).
5> Although i restart the Malware..rescan still gives me 1 file infected
i.e (one of the 2 registry files previously deleted by Malware…)
.Dunno how ,even though i delete it by selecting "Remove Selected" option in the end.(i have the other 3 logs also).
6> i have run CCleaner and removed the redundant Startup references to the detected virus exe (msword98.exe)
But still the infection shows in Malware-Anti… on restart and Re-scan using Maleware(Systen restore turned off still!).
(Even if System Restore is turned off before restart and then turned on, after ,Rescan and deletion by Maleware…it still shows after restart!)

So here is the summary and current status
———————————————————–
–No anti-virus installed (ofcourse i uninstalled it to remove the Dr.Watson error on restart)
– Still Malewarbyte's anti-Maleware shows 1 infection in the registry!
Here i have posted 3 Logs
HJT log
Malewarebyte's Anti-MalewareLog File.
HJT StartupListLog



Here is the HJT log (Current status.)
( previous logs not done):

————————————————–
—————————————————


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:09:15 AM, on 8/20/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.imdb.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - D:\RealPlayer11\rpbrowserrecordplugin.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\QuickTime7.62\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Unknown owner - C:\Program Files\NavNT\rtvscan.exe (file missing)
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

–
End of file - 3148 bytes





Here is the Malewarebyte's Anti-Maleware latest log:

(shows 1 infection and reappears after i restart eventhough I Rescan using Maleware… )

(((Just incase u need the ORIGINAL Malware….infection log file(shows 10 infections)
then tell me!)) Infact i have total 5logs)
——————————————————————————


Malwarebytes' Anti-Malware 1.40
Database version: 2656
Windows 5.1.2600 Service Pack 2

8/20/2009 12:49:30 AM
mbam-log-2009-08-20 (00-49-30).txt

Scan type: Quick Scan
Objects scanned: 79336
Time elapsed: 1 minute(s), 22 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



HJT StartupListLog
——————–

StartupList report, 8/20/2009, 2:11:02 AM
StartupList version: 1.52.2
Started from : C:\Program Files\Trend Micro\HijackThis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE

————————————————–

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\musical\Start Menu\Programs\Startup]
*No files*

Shell folders AltStartup:
*Folder not found*

User shell folders Startup:
*Folder not found*

User shell folders AltStartup:
*Folder not found*

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
BTTray.lnk = ?

Shell folders Common AltStartup:
*Folder not found*

User shell folders Common Startup:
*Folder not found*

User shell folders Alternate Common Startup:
*Folder not found*

————————————————–

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*

[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

IgfxTray = C:\WINDOWS\system32\igfxtray.exe
HotKeysCmds = C:\WINDOWS\system32\hkcmd.exe
AGRSMMSG = AGRSMMSG.exe
SoundMan = SOUNDMAN.EXE
Broadcom Wireless Manager UI = C:\WINDOWS\system32\WLTRAY
SynTPLpr = C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
SynTPEnh = C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
QuickTime Task = "D:\QuickTime7.62\qttask.exe" -atboottime
WinPatrol = C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*No values found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

*No values found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

————————————————–

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

————————————————–

File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command

(Default) = "%1" %*

————————————————–

File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command

(Default) = "%1" /S

————————————————–

File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command

(Default) = C:\WINDOWS\system32\mshta.exe "%1" %*

————————————————–

File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command

(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

————————————————–

Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)

[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP

[>{26923b43-4d38-484f-9b9e-de460746276c}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE

[>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

[{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

[{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

[{4b218e3e-bc98-4770-93d3-2731b9329278}] *
StubPath = %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf

[{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser

[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub

[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll

[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = %SystemRoot%\system32\ie4uinit.exe

————————————————–

Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps

*Registry key not found*

————————————————–

Load/Run keys from C:\WINDOWS\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

————————————————–

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\System32\logon.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

————————————————–

Checking for EXPLORER.EXE instances:

C:\WINDOWS\Explorer.exe: PRESENT!

C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present
C:\WINDOWS\Fonts\Explorer.exe: not present

————————————————–

Checking for superhidden extensions:

.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden

————————————————–

Verifying REGEDIT.EXE integrity:

- Regedit.exe found in C:\WINDOWS
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'

Registry check passed

————————————————–

Enumerating Browser Helper Objects:

(no name) - D:\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - D:\RealPlayer11\rpbrowserrecordplugin.dll - {3049C3E9-B461-4BC5-8870-4C09146192CA}

————————————————–

Enumerating Task Scheduler jobs:

*No jobs found*

————————————————–

Enumerating Download Program Files:

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\Adobe\Director\SwDir.dll
CODEBASE = http://download.macromedia.com/pub/shockwa…director/sw.cab

[DivXBrowserPlugin Object]
InProcServer32 = C:\Program Files\DivX\DivX Web Player\npdivx32.dll
CODEBASE = http://go.divx.com/plugin/DivXBrowserPlugin.cab

[{E2883E8F-472F-4FB0-9522-AC9BF37916A7}]
CODEBASE = http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

————————————————–

Enumerating Winsock LSP files:

NameSpace #1: C:\WINDOWS\System32\mswsock.dll
NameSpace #2: C:\WINDOWS\System32\winrnr.dll
NameSpace #3: C:\WINDOWS\System32\mswsock.dll
Protocol #1: C:\WINDOWS\system32\mswsock.dll
Protocol #2: C:\WINDOWS\system32\mswsock.dll
Protocol #3: C:\WINDOWS\system32\mswsock.dll
Protocol #4: C:\WINDOWS\system32\mswsock.dll
Protocol #5: C:\WINDOWS\system32\rsvpsp.dll
Protocol #6: C:\WINDOWS\system32\rsvpsp.dll
Protocol #7: C:\WINDOWS\system32\mswsock.dll
Protocol #8: C:\WINDOWS\system32\mswsock.dll
Protocol #9: C:\WINDOWS\system32\mswsock.dll
Protocol #10: C:\WINDOWS\system32\mswsock.dll
Protocol #11: C:\WINDOWS\system32\mswsock.dll
Protocol #12: C:\WINDOWS\system32\mswsock.dll
Protocol #13: C:\WINDOWS\system32\mswsock.dll
Protocol #14: C:\WINDOWS\system32\mswsock.dll
Protocol #15: C:\WINDOWS\system32\mswsock.dll
Protocol #16: C:\WINDOWS\system32\mswsock.dll

————————————————–

Enumerating Windows NT/2000/XP services

Microsoft ACPI Driver: system32\DRIVERS\ACPI.sys (system)
Microsoft Embedded Controller Driver: system32\DRIVERS\ACPIEC.sys (system)
Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
AEGIS Protocol (IEEE 802.1x) v3.2.0.3: system32\DRIVERS\AegisP.sys (autostart)
AFD: \SystemRoot\System32\drivers\afd.sys (system)
Agere Systems Soft Modem: system32\DRIVERS\AGRSM.sys (manual start)
Service for Realtek AC97 Audio (WDM): system32\drivers\ALCXWDM.SYS (manual start)
Alerter: %SystemRoot%\system32\svchost.exe -k LocalService (disabled)
Application Layer Gateway Service: %SystemRoot%\System32\alg.exe (manual start)
Application Management: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
1394 ARP Client Protocol: system32\DRIVERS\arp1394.sys (manual start)
RAS Asynchronous Media Driver: system32\DRIVERS\asyncmac.sys (manual start)
Standard IDE/ESDI Hard Disk Controller: system32\DRIVERS\atapi.sys (system)
ATM ARP Client Protocol: system32\DRIVERS\atmarpc.sys (manual start)
Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Audio Stub Driver: system32\DRIVERS\audstub.sys (manual start)
Broadcom 440x 10/100 Integrated Controller XP Driver: system32\DRIVERS\bcm4sbxp.sys (manual start)
Background Intelligent Transfer Service: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Computer Browser: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Bluetooth Protocol Stack: system32\drivers\btkrnl.sys (system)
Bluetooth Serial Driver: \??\C:\WINDOWS\system32\drivers\btserial.sys (autostart)
Bluetooth Port Client Driver: \??\C:\WINDOWS\system32\drivers\btslbcsp.sys (autostart)
Bluetooth Service: C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe (disabled)
CD-ROM Driver: system32\DRIVERS\cdrom.sys (system)
Indexing Service: %SystemRoot%\system32\cisvc.exe (manual start)
ClipBook: %SystemRoot%\system32\clipsrv.exe (disabled)
Microsoft ACPI Control Method Battery Driver: system32\DRIVERS\CmBatt.sys (manual start)
Microsoft Composite Battery Driver: system32\DRIVERS\compbatt.sys (system)
COM+ System Application: C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
Cryptographic Services: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
DCOM Server Process Launcher: %SystemRoot%\system32\svchost -k DcomLaunch (autostart)
DefWatch: "C:\Program Files\NavNT\defwatch.exe" (disabled)
DHCP Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Disk Driver: system32\DRIVERS\disk.sys (system)
Logical Disk Manager Administrative Service: %SystemRoot%\System32\dmadmin.exe /com (manual start)
dmboot: System32\drivers\dmboot.sys (disabled)
Logical Disk Manager Driver: System32\drivers\dmio.sys (system)
dmload: System32\drivers\dmload.sys (system)
Logical Disk Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
DNS Client: %SystemRoot%\system32\svchost.exe -k NetworkService (autostart)
Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
EMSCR: system32\DRIVERS\EMS7SK.sys (manual start)
Error Reporting Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
ESDCR: system32\DRIVERS\ESD7SK.sys (manual start)
ESMCR: system32\DRIVERS\ESM7SK.sys (manual start)
Event Log: %SystemRoot%\system32\services.exe (autostart)
COM+ Event System: C:\WINDOWS\system32\svchost.exe -k netsvcs (manual start)
Fast User Switching Compatibility: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
FltMgr: system32\DRIVERS\fltMgr.sys (system)
Volume Manager Driver: system32\DRIVERS\ftdisk.sys (system)
Generic Packet Classifier: system32\DRIVERS\msgpc.sys (manual start)
Help and Support: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Human Interface Device Access: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
HTTP: System32\Drivers\HTTP.sys (manual start)
HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start)
i8042 Keyboard and PS/2 Mouse Port Driver: system32\DRIVERS\i8042prt.sys (system)
ialm: system32\DRIVERS\ialmnt5.sys (manual start)
CD-Burning Filter Driver: system32\DRIVERS\imapi.sys (system)
IMAPI CD-Burning COM Service: C:\WINDOWS\system32\imapi.exe (manual start)
IntelIde: system32\DRIVERS\intelide.sys (system)
Intel Processor Driver: system32\DRIVERS\intelppm.sys (system)
IPv6 Windows Firewall Driver: system32\DRIVERS\Ip6Fw.sys (manual start)
IP Traffic Filter Driver: system32\DRIVERS\ipfltdrv.sys (manual start)
IP in IP Tunnel Driver: system32\DRIVERS\ipinip.sys (manual start)
IP Network Address Translator: system32\DRIVERS\ipnat.sys (manual start)
IPSEC driver: system32\DRIVERS\ipsec.sys (system)
IrDA Protocol: system32\DRIVERS\irda.sys (autostart)
IR Enumerator Service: system32\DRIVERS\irenum.sys (manual start)
Infrared Monitor: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
PnP ISA/EISA Bus Driver: system32\DRIVERS\isapnp.sys (system)
Keyboard Class Driver: system32\DRIVERS\kbdclass.sys (system)
Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
Server: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Workstation: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
TCP/IP NetBIOS Helper: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
Messenger: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
NetMeeting Remote Desktop Sharing: C:\WINDOWS\system32\mnmsrvc.exe (manual start)
Mouse Class Driver: system32\DRIVERS\mouclass.sys (system)
WebDav Client Redirector: system32\DRIVERS\mrxdav.sys (manual start)
MRXSMB: system32\DRIVERS\mrxsmb.sys (system)
Distributed Transaction Coordinator: C:\WINDOWS\system32\msdtc.exe (manual start)
Windows Installer: C:\WINDOWS\system32\msiexec.exe /V (manual start)
Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.sys (manual start)
Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
Microsoft System Management BIOS Driver: system32\DRIVERS\mssmbios.sys (manual start)
NAVAP: \??\C:\Program Files\NavNT\NAVAP.sys (manual start)
NAVAPEL: \??\C:\Program Files\NavNT\NAVAPEL.SYS (autostart)
NAVENG: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20090812.008\NAVENG.sys (manual start)
NAVEX15: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20090812.008\NAVEX15.sys (manual start)
Remote Access NDIS TAPI Driver: system32\DRIVERS\ndistapi.sys (manual start)
NDIS Usermode I/O Protocol: system32\DRIVERS\ndisuio.sys (manual start)
Remote Access NDIS WAN Driver: system32\DRIVERS\ndiswan.sys (manual start)
NetBIOS Interface: system32\DRIVERS\netbios.sys (system)
NetBios over Tcpip: system32\DRIVERS\netbt.sys (system)
Network DDE: %SystemRoot%\system32\netdde.exe (disabled)
Network DDE DSDM: %SystemRoot%\system32\netdde.exe (disabled)
Net Logon: %SystemRoot%\system32\lsass.exe (manual start)
Network Connections: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
1394 Net Driver: system32\DRIVERS\nic1394.sys (manual start)
Network Location Awareness (NLA): %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Norton AntiVirus Client: "C:\Program Files\NavNT\rtvscan.exe" (autostart)
Upper Class Filter Driver: system32\DRIVERS\NTIDrvr.sys (manual start)
NT LM Security Support Provider: %SystemRoot%\system32\lsass.exe (manual start)
Removable Storage: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
IPX Traffic Filter Driver: system32\DRIVERS\nwlnkflt.sys (manual start)
IPX Traffic Forwarder Driver: system32\DRIVERS\nwlnkfwd.sys (manual start)
Texas Instruments OHCI Compliant IEEE 1394 Host Controller: system32\DRIVERS\ohci1394.sys (system)
PCI Bus Driver: system32\DRIVERS\pci.sys (system)
PCIIde: system32\DRIVERS\pciide.sys (system)
Pcmcia: system32\DRIVERS\pcmcia.sys (system)
Plug and Play: %SystemRoot%\system32\services.exe (autostart)
IPSEC Services: %SystemRoot%\system32\lsass.exe (autostart)
WAN Miniport (PPTP): system32\DRIVERS\raspptp.sys (manual start)
Protected Storage: %SystemRoot%\system32\lsass.exe (autostart)
QoS Packet Scheduler: system32\DRIVERS\psched.sys (manual start)
Direct Parallel Link Driver: system32\DRIVERS\ptilink.sys (manual start)
Remote Access Auto Connection Driver: system32\DRIVERS\rasacd.sys (system)
Remote Access Auto Connection Manager: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
WAN Miniport (IrDA): system32\DRIVERS\rasirda.sys (manual start)
WAN Miniport (L2TP): system32\DRIVERS\rasl2tp.sys (manual start)
Remote Access Connection Manager: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Remote Access PPPOE Driver: system32\DRIVERS\raspppoe.sys (manual start)
Direct Parallel: system32\DRIVERS\raspti.sys (manual start)
Rdbss: system32\DRIVERS\rdbss.sys (system)
RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
Terminal Server Device Redirector Driver: system32\DRIVERS\rdpdr.sys (manual start)
Remote Desktop Help Session Manager: C:\WINDOWS\system32\sessmgr.exe (manual start)
Digital CD Audio Playback Filter Driver: system32\DRIVERS\redbook.sys (system)
Routing and Remote Access: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
Remote Registry: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
Remote Procedure Call (RPC) Locator: %SystemRoot%\system32\locator.exe (manual start)
Remote Procedure Call (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
QoS RSVP: %SystemRoot%\system32\rsvp.exe (manual start)
WLAN Transport: system32\DRIVERS\s24trans.sys (disabled)
Security Accounts Manager: %SystemRoot%\system32\lsass.exe (autostart)
Smart Card: %SystemRoot%\System32\SCardSvr.exe (manual start)
Task Scheduler: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
sdbus: system32\DRIVERS\sdbus.sys (manual start)
Secdrv: system32\DRIVERS\secdrv.sys (autostart)
Secondary Logon: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
System Event Notification: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Windows Firewall/Internet Connection Sharing (ICS): %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Shell Hardware Detection: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
SMC IrCC Miniport Device Driver: system32\DRIVERS\smcirda.sys (manual start)
Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start)
Print Spooler: %SystemRoot%\system32\spoolsv.exe (autostart)
System Restore Filter Driver: \SystemRoot\system32\DRIVERS\sr.sys (disabled)
System Restore Service: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Srv: system32\DRIVERS\srv.sys (manual start)
SSDP Discovery Service: %SystemRoot%\system32\svchost.exe -k LocalService (manual start)
Windows Image Acquisition (WIA): %SystemRoot%\system32\svchost.exe -k imgsvc (manual start)
Software Bus Driver: system32\DRIVERS\swenum.sys (manual start)
Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
MS Software Shadow Copy Provider: C:\WINDOWS\system32\dllhost.exe /Processid:{14A28F09-34E7-4109-AA78-983E7F87E168} (manual start)
SymEvent: \??\C:\Program Files\Symantec\SYMEVENT.SYS (manual start)
Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start)
Performance Logs and Alerts: %SystemRoot%\system32\smlogsvc.exe (manual start)
Telephony: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
TCP/IP Protocol Driver: system32\DRIVERS\tcpip.sys (system)
Terminal Device Driver: system32\DRIVERS\termdd.sys (system)
Terminal Services: %SystemRoot%\System32\svchost -k DComLaunch (manual start)
Themes: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
Telnet: C:\WINDOWS\system32\tlntsvr.exe (disabled)
Distributed Link Tracking Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Microcode Update Driver: system32\DRIVERS\update.sys (manual start)
Universal Plug and Play Device Host: %SystemRoot%\system32\svchost.exe -k LocalService (manual start)
Uninterruptible Power Supply: %SystemRoot%\System32\ups.exe (manual start)
Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: system32\DRIVERS\usbehci.sys (manual start)
USB2 Enabled Hub: system32\DRIVERS\usbhub.sys (manual start)
USB Mass Storage Driver: system32\DRIVERS\USBSTOR.SYS (manual start)
Microsoft USB Universal Host Controller Miniport Driver: system32\DRIVERS\usbuhci.sys (manual start)
VgaSave: \SystemRoot\System32\drivers\vga.sys (system)
Volume Shadow Copy: %SystemRoot%\System32\vssvc.exe (manual start)
Intel® PRO/Wireless 2200BG Network Connection Driver for Windows XP: system32\DRIVERS\w29n51.sys (manual start)
Windows Time: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Remote Access IP ARP Driver: system32\DRIVERS\wanarp.sys (manual start)
Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
WebClient: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
Windows Management Instrumentation: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Broadcom Wireless LAN Tray Service: %SystemRoot%\System32\wltrysvc.exe %SystemRoot%\System32\bcmwltry.exe (autostart)
Portable Media Serial Number Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Windows Management Instrumentation Driver Extensions: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
WMI Performance Adapter: C:\WINDOWS\system32\wbem\wmiapsrv.exe (manual start)
Security Center: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Automatic Updates: %systemroot%\system32\svchost.exe -k netsvcs (disabled)
Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Network Provisioning Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)


————————————————–

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:\DOCUME~1\musical\LOCALS~1\Temp\_iu14D2N.tmp


————————————————–

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll

————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*Registry key not found*

————————————————–

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*Registry key not found*

————————————————–

End of report, 31,148 bytes
Report generated in 0.125 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only





———————————————–
Basically i had been on Mr.Kenz's website www.swapfilecomputerservice.com which explains why i did, whatever i did! I hope you get what i mean to say! ,before coming outhere hence did the Installations and deletions!!

See ya Soon!
Please do the following:

NEXT

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Hi
Thanks for your time and effort!

I have to tell you 2 questions
—> the Avast Anti-virus Scan showed some infection in NTFS.sys file.
I chose option" Move " it saved it as" ntsf.sys.vir" by defaultsome where i can't remember.
(On restart after updating the antivirus-defs the AVAST engine did a FULL Scan OF ALL Drives before booting into Windows.)

// I installed Avast4.8 home anti-virus (as i cannot install the NAV EnT edition 7.6.It shows no activity when
i run the installation NAVexe! //
Q1 Did , me Deleting some of the missing entries of Nav Registries ,Mui missing links etc.. , shown by CCleaner has to do with this kind of behaviour of not installing The NAV?

—–> aFTER RUNNING Gmer.exe Scan and saving it as Gmer.txt as u directed ,
I pressed the "Ok" option on the GUI and the program terminated.
Q2 Was i to press "Cancel" after Saving the Gmer.txt file ? Your last step was not clear on how to exit Gmer .




Ok here are the 3 Txt files you requested:
1> Attach.txt

2> DDS.txt

3>Gmer.txt

1> Attach.txt

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-07-30.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 7/31/2009 2:00:54 PM
System Uptime: 8/26/2009 8:41:58 AM (75 hours ago)

Motherboard: Acer | | Dunlin
Processor: Intel® Pentium® M processor 1.60GHz | uFCPGA | 1596/133mhz

==== Disk Partitions =========================

C: is FIXED (FAT32) - 19 GiB total, 14.395 GiB free.
D: is FIXED (FAT32) - 19 GiB total, 4.67 GiB free.
E: is FIXED (FAT32) - 19 GiB total, 7.798 GiB free.
F: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

No restore point in system.

==== Installed Programs ======================

Adobe Download Manager
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 6.0
Adobe Shockwave Player 11.5
Agere Systems AC'97 Modem
Apple Software Update
avast! Antivirus
BitLord 1.1
Broadcom 440x 10/100 Integrated Controller
Broadcom 802.11 Network Adapter
CCleaner (remove only)
DivX Web Player
ERUNT 1.1j
HijackThis 2.0.2
Intel® Graphics Media Accelerator Driver for Mobile
LiveUpdate 1.6 (Symantec Corporation)
Malwarebytes' Anti-Malware
Mozilla Firefox (3.5.2)
Norton AntiVirus Corporate Edition
NTI DVD-Maker
NTI DVD-Maker Gold
NTI DVD Player
QuickTime
RealPlayer
SpywareBlaster 4.2
SpywareGuard v2.2
VC80CRTRedist - 8.0.50727.762
VideoLAN VLC media player 0.8.6f
WebFldrs XP
WIDCOMM Bluetooth Software
WinPatrol 2009

==== Event Viewer Messages From Past Week ========

8/28/2009 1:20:57 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the WZCSVC service.
8/24/2009 11:00:21 AM, error: Dhcp [1002] - The IP address lease 192.168.1.2 for the Network Card with network address 0012F0A6B935 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
8/23/2009 5:45:19 PM, error: ipnathlp [32003] - The Network Address Translator (NAT) was unable to request an operation of the kernel-mode translation module. This may indicate misconfiguration, insufficient resources, or an internal error. The data is the error code.
8/23/2009 11:22:22 PM, error: Tcpip [4199] - The system detected an address conflict for IP address 192.168.1.2 with the system having network hardware address 00:18:DE:17:E9:67. Network operations on this system may be disrupted as a result.
8/22/2009 2:30:36 PM, error: Service Control Manager [7000] - The NAVAPEL service failed to start due to the following error: The system cannot find the file specified.
8/22/2009 11:03:40 AM, error: Dhcp [1002] - The IP address lease 192.168.1.3 for the Network Card with network address 0012F0A6B935 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
8/22/2009 1:58:39 PM, warning: Windows File Protection [64008] - The protected system file c:\windows\system32\drivers\ntfs.sys could not be verified as valid because Windows File Protection is terminating. Use the SFC utility to verify the integrity of the file at a later time.

==== End Of File ===========================


2> DDS.txt




DDS (Ver_09-07-30.01) - FAT32x86
Run by [removed] at 11:02:27.01 on Sat 08/29/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1015.534 [GMT 5.5:30]

AV: avast! antivirus 4.8.1351 [VPS 090828-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
SVCHOST.EXE
C:\WINDOWS\system32\svchost.exe -k netsvcs
SVCHOST.EXE
SVCHOST.EXE
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\musical\Desktop\dds.pif

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.imdb.com/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
mWinlogon: Taskman=c:\recycler\s-1-5-21-4370436549-5252116245-213217422-2866\hd1.exe
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - d:\acrobat 6.0\reader\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - d:\realplayer11\rpbrowserrecordplugin.dll
BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\program files\spywareguard\dlprotect.dll
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [QuickTime Task] "d:\quicktime7.62\qttask.exe" -atboottime
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
StartupFolder: c:\docume~1\musical\startm~1\programs\startup\spywar~1.lnk - c:\program files\spywareguard\sgmain.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\bttray.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
IE: Send To &Bluetooth; - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {076169AA-8C3D-4CFC-AC23-3ACA88FC21B5} - hxxp://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://go.divx.com/plugin/DivXBrowserPlugin.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - c:\windows\system32\BTXPPanel.dll
Notify: igfxcui - igfxsrvc.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\program files\spywareguard\spywareguard.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\musical\applic~1\mozilla\firefox\profiles\drlglawz.default\
FF - component: d:\realplayer11\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\documents and settings\musical\application data\mozilla\firefox\profiles\drlglawz.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll
FF - plugin: d:\acrobat 6.0\reader\browser\nppdf32.dll
FF - plugin: d:\quicktime7.62\plugins\npqtplugin.dll
FF - plugin: d:\quicktime7.62\plugins\npqtplugin2.dll
FF - plugin: d:\quicktime7.62\plugins\npqtplugin3.dll
FF - plugin: d:\quicktime7.62\plugins\npqtplugin4.dll
FF - plugin: d:\quicktime7.62\plugins\npqtplugin5.dll
FF - plugin: d:\quicktime7.62\plugins\npqtplugin6.dll
FF - plugin: d:\quicktime7.62\plugins\npqtplugin7.dll
FF - plugin: d:\realplayer11\netscape6\nppl3260.dll
FF - plugin: d:\realplayer11\netscape6\nprjplug.dll
FF - plugin: d:\realplayer11\netscape6\nprpjplug.dll

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-8-22 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-8-22 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-8-22 138680]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-8-22 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-8-22 352920]
S2 NAVAPEL;NAVAPEL;\??\c:\program files\navnt\navapel.sys –> c:\program files\navnt\NAVAPEL.SYS [?]
S2 Norton AntiVirus Server;Norton AntiVirus Client;"c:\program files\navnt\rtvscan.exe" –> c:\program files\navnt\rtvscan.exe [?]
S3 getPlusHelper;getPlus® Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2004-8-3 14336]
S3 NAVAP;NAVAP;\??\c:\program files\navnt\navap.sys –> c:\program files\navnt\NAVAP.sys [?]
S3 NAVENG;NAVENG;\??\c:\progra~1\common~1\symant~1\virusd~1\20090812.008\naveng.sys –> c:\progra~1\common~1\symant~1\virusd~1\20090812.008\NAVENG.sys [?]
S3 NAVEX15;NAVEX15;\??\c:\progra~1\common~1\symant~1\virusd~1\20090812.008\navex15.sys –> c:\progra~1\common~1\symant~1\virusd~1\20090812.008\NAVEX15.sys [?]

=============== Created Last 30 ================

2009-08-29 10:58 –d-h— c:\windows\PIF
2009-08-22 13:50 1,060,864 a——- c:\windows\system32\MFC71.dll
2009-08-20 15:07 –d—– c:\program files\SpywareGuard
2009-08-20 14:44 1,071,088 a——- c:\windows\system32\MSCOMCTL.OCX
2009-08-20 14:44 118,784 a——- c:\windows\system32\MSSTDFMT.DLL
2009-08-20 14:44 –d—– c:\program files\SpywareBlaster
2009-08-20 12:24 306,688 a——- c:\windows\IsUninst.exe
2009-08-20 02:03 –d—– c:\program files\Trend Micro
2009-08-19 21:43 –d—– c:\program files\CCleaner
2009-08-19 20:30 –d—– c:\docume~1\musical\applic~1\Malwarebytes
2009-08-19 20:30 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-19 20:30 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-08-19 20:30 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-08-19 20:30 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-19 19:53 –d—– c:\docume~1\musical\applic~1\WinPatrol
2009-08-19 19:53 –d—– c:\program files\BillP Studios
2009-08-17 13:23 –d—– c:\program files\common files\DivX Shared
2009-08-17 13:23 –d—– c:\program files\DivX
2009-08-15 03:14 25 a——- c:\windows\cdplayer.ini
2009-08-15 03:13 –d—– c:\program files\common files\xing shared
2009-08-15 03:13 –d—– c:\program files\common files\Real
2009-08-11 23:49 –d—– c:\program files\VideoLAN
2009-08-08 16:36 1,846,632 a——- c:\windows\system32\D3DCompiler_41.dll
2009-08-08 16:36 453,456 a——- c:\windows\system32\d3dx10_41.dll
2009-08-08 16:36 4,178,264 a——- c:\windows\system32\D3DX9_41.dll
2009-08-08 16:06 116 a——- c:\windows\NeroDigital.ini
2009-08-08 00:49 –d—– C:\Sun
2009-08-07 21:55 –d—– c:\windows\system32\Adobe
2009-08-02 14:08 783 a——- c:\windows\NTIWVEDT.INI
2009-08-02 12:39 –d—– c:\docume~1\alluse~1\applic~1\Propellerhead Software
2009-08-02 12:39 233,472 a——- c:\windows\system32\REX Shared Library.dll
2009-08-02 12:39 225,280 a——- c:\windows\system32\ReWire.dll
2009-08-02 12:39 –d—– c:\docume~1\musical\applic~1\Propellerhead Software
2009-08-02 12:35 –d—– c:\docume~1\alluse~1\applic~1\DFX
2009-08-02 12:35 –d—– c:\program files\common files\DFX
2009-08-02 12:17 –d—– c:\program files\BitLord
2009-08-02 11:19 26,496 a——- c:\windows\system32\dllcache\usbstor.sys
2009-08-01 01:59 29 a——- c:\windows\CDMKR32.INI
2009-08-01 01:53 1,024 —-hr– c:\windows\system32\ntiembed.dll
2009-08-01 01:51 81,920 ——– c:\windows\system32\ezrgb24.ax
2009-08-01 01:51 226,816 ——– c:\windows\system32\htvcdsvcd.ax
2009-08-01 01:51 –d—– c:\windows\Vbox
2009-08-01 01:51 9,728 ——– c:\windows\system\regsvr32.exe
2009-08-01 01:50 –d—– c:\windows\system32\Iosubsys
2009-08-01 01:49 –d—– c:\program files\NewTech Infosystems
2009-08-01 01:49 1,024 —-hr– c:\windows\system32\NTIMPEG2.dll
2009-08-01 01:49 1,024 —-hr– c:\windows\system32\NTICDMK32.dll
2009-08-01 01:49 6,912 a——- c:\windows\system32\drivers\NTIDrvr.sys
2009-08-01 01:30 –dsh— C:\Recycled
2009-07-31 21:05 106,496 a——- c:\windows\system32\TwnLib20.dll
2009-07-31 21:04 471,040 ——– c:\windows\system32\ImagXRA7.dll
2009-07-31 21:04 262,144 ——– c:\windows\system32\ImagXR7.dll
2009-07-31 21:04 1,568,768 ——– c:\windows\system32\ImagX7.dll
2009-07-31 21:04 476,320 ——– c:\windows\system32\ImagXpr7.dll
2009-07-31 21:04 155,648 a——- c:\windows\system32\NeroCheck.exe
2009-07-31 20:50 –d—– c:\program files\WIDCOMM
2009-07-31 20:07 4,197,002 a——- c:\windows\pfirewall.log.old
2009-07-31 18:25 28 a——- c:\windows\ODBC.INI
2009-07-31 18:25 –d—– c:\windows\system32\CBA
2009-07-31 18:25 –d—– c:\program files\Symantec
2009-07-31 18:25 –d—– c:\docume~1\alluse~1\applic~1\Symantec
2009-07-31 18:24 –d—– c:\program files\NavNT
2009-07-31 18:17 499,712 a——- c:\windows\system32\msvcp71.dll
2009-07-31 18:17 348,160 a——- c:\windows\system32\msvcr71.dll
2009-07-31 17:08 –d—– c:\program files\Broadcom
2009-07-31 17:05 17,801 a——- c:\windows\system32\drivers\AegisP.sys
2009-07-31 17:05 81,920 ——– c:\windows\system32\wltrynt.dll
2009-07-31 17:05 192,512 ——– c:\windows\system32\AegisI5.exe
2009-07-31 17:05 172,032 ——– c:\windows\system32\BCMLogon.dll
2009-07-31 17:05 65,536 ——– c:\windows\system32\WLTRYSVC.EXE
2009-07-31 17:04 647,272 ——– c:\windows\system32\WLTRAY.EXE
2009-07-31 17:04 1,396,831 ——– c:\windows\system32\AegisE5.dll
2009-07-31 17:04 827,499 ——– c:\windows\system32\BCMWLTRY.EXE
2009-07-31 17:04 1,261,676 ——– c:\windows\system32\BCMWLCPL.CPL
2009-07-31 17:04 69,632 ——– c:\windows\system32\bcmwlD2K.EXE
2009-07-31 17:00 163,840 a—-r– c:\windows\system32\igfxres.dll
2009-07-31 16:55 3,222,784 a—-r– c:\windows\system32\drivers\w29n51.sys
2009-07-31 16:55 458,752 a—-r– c:\windows\system32\w29NCPA.dll
2009-07-31 16:55 156,672 a—-r– c:\windows\system32\RTLCPAPI.dll
2009-07-31 16:54 9,324,032 a—-r– c:\windows\system32\RTLCPL.EXE
2009-07-31 16:54 141,016 a—-r– c:\windows\system32\ALSNDMGR.WAV
2009-07-31 16:54 16,166,912 a—-r– c:\windows\system32\ALSNDMGR.CPL
2009-07-31 16:54 77,824 a—-r– c:\windows\SOUNDMAN.EXE
2009-07-31 16:54 2,300,928 a—-r– c:\windows\system32\drivers\ALCXWDM.SYS
2009-07-31 16:53 1,073,375 a—-r– c:\windows\system32\drivers\AGRSM.sys
2009-07-31 16:53 88,202 a—-r– c:\windows\AGRSMMSG.exe
2009-07-31 16:53 64,512 a—-r– c:\windows\agrsmdel.exe
2009-07-31 16:51 94,208 a—-r– c:\windows\system32\igfxcpl.cpl
2009-07-31 16:01 –ds—- c:\documents and settings\musical\UserData
2009-07-31 15:20 35,913 ——– c:\windows\system32\drivers\SMCIRDA.SY_
2009-07-31 14:57 –d—– c:\windows\pss
2009-07-31 14:55 –d—– c:\windows\system32\appmgmt
2009-07-31 14:51 –d—– c:\windows\Options
2009-07-31 14:51 356,352 a—-r– c:\windows\EMCRI.dll
2009-07-31 14:48 –d—– c:\windows\system32\ReinstallBackups
2009-07-31 14:40 –d—– c:\docume~1\musical\applic~1\Intel
2009-07-31 14:33 184,320 ——– c:\windows\system32\BCMWLU00.EXE
2009-07-31 14:33 369,024 ——– c:\windows\system32\drivers\BCMWL5.SYS
2009-07-31 14:28 6 a——- C:\ISACER.ID
2009-07-31 14:24 –d—– c:\windows\Cache
2009-07-31 14:22 173 a——- c:\windows\RtlRack.ini
2009-07-31 14:14 –d—– c:\windows\Downloaded Installations
2009-07-31 14:09 145,792 a——- c:\windows\system32\drivers\portcls.sys
2009-07-31 14:09 145,792 a——- c:\windows\system32\dllcache\portcls.sys
2009-07-31 14:09 130,048 a——- c:\windows\system32\ksproxy.ax
2009-07-31 14:09 130,048 a——- c:\windows\system32\dllcache\ksproxy.ax
2009-07-31 14:09 60,288 a——- c:\windows\system32\drivers\drmk.sys
2009-07-31 14:09 60,288 a——- c:\windows\system32\dllcache\drmk.sys
2009-07-31 14:09 4,096 a——- c:\windows\system32\ksuser.dll
2009-07-31 14:09 4,096 a——- c:\windows\system32\dllcache\ksuser.dll
2009-07-31 14:09 1,048 ——– c:\windows\system32\drivers\alcxinit.dat
2009-07-31 14:05 –d—– c:\documents and settings\musical
2009-07-31 14:02 –ds—- c:\windows\system32\Microsoft
2009-07-31 14:02 8,192 a——- c:\windows\REGLOCS.OLD
2009-07-31 13:59 26,112 a——- c:\windows\system32\dllcache\EXCH_seos.dll
2009-07-31 13:58 6,144 a——- c:\windows\system32\dllcache\kbdinpun.dll
2009-07-31 13:57 10,096,640 a——- c:\windows\system32\dllcache\hwxcht.dll
2009-07-31 13:56 66,082 a——- c:\windows\system32\dllcache\c_20285.nls
2009-07-31 13:55 2,626 a——- c:\windows\system32\CONFIG.NT
2009-07-31 13:55 0 a——- c:\windows\control.ini
2009-07-31 13:55 23,392 a——- c:\windows\system32\nscompat.tlb
2009-07-31 13:55 16,832 a——- c:\windows\system32\amcompat.tlb
2009-07-31 13:55 316,640 a——- c:\windows\WMSysPr9.prx
2009-07-31 13:54 –dsh— c:\documents and settings\all users\DRM
2009-07-31 13:54 488 a—hr– c:\windows\system32\WindowsLogon.manifest
2009-07-31 13:54 488 a—hr– c:\windows\system32\logonui.exe.manifest
2009-07-31 13:54 –ds—- c:\windows\Downloaded Program Files
2009-07-31 13:54 –d–r– c:\windows\Offline Web Pages
2009-07-31 13:54 749 a—hr– c:\windows\WindowsShell.Manifest
2009-07-31 13:54 749 a—hr– c:\windows\system32\wuaucpl.cpl.manifest
2009-07-31 13:54 749 a—hr– c:\windows\system32\sapi.cpl.manifest
2009-07-31 13:54 749 a—hr– c:\windows\system32\nwc.cpl.manifest
2009-07-31 13:54 749 a—hr– c:\windows\system32\ncpa.cpl.manifest
2009-07-31 13:54 749 a—hr– c:\windows\system32\cdplayer.exe.manifest
2009-07-31 13:54 –d-h— c:\program files\WindowsUpdate
2009-07-31 13:54 4,399,505 a——- c:\windows\system32\dllcache\nls302en.lex
2009-07-31 13:53 –d—– c:\windows\system32\DirectX
2009-07-31 13:53 28,160 a——- c:\windows\system32\dllcache\msoobe.exe
2009-07-31 13:53 35,328 a——- c:\windows\system32\dllcache\notiflag.exe
2009-07-31 13:53 11,264 a——- c:\windows\system32\dllcache\atrace.dll
2009-07-31 13:53 11,264 a——- c:\windows\system32\atrace.dll
2009-07-31 13:53 99,840 a——- c:\windows\system32\dllcache\helphost.exe
2009-07-31 13:53 21,504 a——- c:\windows\system32\dllcache\brpinfo.dll
2009-07-31 13:53 6,656 a——- c:\windows\system32\dllcache\hcappres.dll
2009-07-31 13:53 2 a——- c:\windows\system32\desktop.ini
2009-07-31 13:53 2 a——- c:\windows\desktop.ini
2009-07-31 13:53 48,680 —sh— c:\windows\winnt256.bmp
2009-07-31 13:53 48,680 —sh— c:\windows\winnt.bmp
2009-07-31 13:52 –d—– c:\program files\common files\MSSoap
2009-07-31 13:50 –d—– c:\program files\Online Services
2009-07-31 13:50 –d—– c:\program files\Messenger
2009-07-31 13:50 –d—– c:\program files\MSN Gaming Zone
2009-07-31 13:48 –d—– c:\program files\Windows NT
2009-07-31 13:37 –d—– c:\program files\common files\ODBC
2009-07-31 13:37 –d—– c:\program files\common files\SpeechEngines
2009-07-31 13:36 –d–r– c:\documents and settings\all users\Documents

==================== Find3M ====================

2009-08-15 21:44 619,200 a——- c:\windows\system32\dllcache\ntfs.sys
2009-08-10 20:16 12,464 a——- c:\windows\system32\drivers\secdrv.sys
2009-07-31 15:45 86,327 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-07-31 13:50 21,640 a——- c:\windows\system32\emptyregdb.dat

============= FINISH: 11:02:40.59 ===============


3>Gmer.txt


GMER 1.0.15.15077 [gmer.exe] - http://www.gmer.net
Rootkit scan 2009-08-29 11:17:16
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xAAD4E6B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xAAD4E574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xAAD4EA52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xAAD4E14C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xAAD4E64E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xAAD4E08C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xAAD4E0F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xAAD4E76E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xAAD4E72E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xAAD4E8AE]

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 sector 62: copy of MBR

—- EOF - GMER 1.0.15 —-


See you soon.
Thank you once more!
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
HI
Well I had 2 messages on restart
–1> one message on reboot abt regarding Windows explorer and i accepted "Keep new value"
–2> Winpatrol gave me a warning abt change in "HOSTS" file and I did Accept change .

Also i had 2 Questions
— Q1 > what sholud I do About the Ntfs.sys file that Avast Scan engine detected to have a virus .?
Technically I chose the "Move File " option while it was scanning
—Q2> Will this have any affect on my system?

Here is the Combofix log

COMBOFIX LOG




ComboFix 09-08-29.01 - musical 08/30/2009 10:00.1.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1015.673 [GMT 5.5:30]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1351 [VPS 090829-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-1-5-21-4370436549-5252116245-213217422-2866
c:\recycler\S-1-5-21-4370436549-5252116245-213217422-2866\Desktop.ini
c:\recycler\S-1-5-21-4370436549-5252116245-213217422-2866\hd1.exe
c:\recycler\S-1-5-21-6649707611-4345953983-140917801-2824
c:\recycler\S-1-5-21-8404539914-3956416585-573061920-4188

.
((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-30 )))))))))))))))))))))))))))))))
.

2009-08-29 05:28 . 2009-08-29 05:28 ——– d–h–w- c:\windows\PIF
2009-08-22 08:21 . 2009-08-17 16:04 51376 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-22 08:21 . 2009-08-17 16:04 23152 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-22 08:21 . 2009-08-17 16:03 26944 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-22 08:21 . 2009-08-17 16:02 97480 —-a-w- c:\windows\system32\AvastSS.scr
2009-08-22 08:21 . 2009-08-17 16:05 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-22 08:21 . 2009-08-17 16:05 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-22 08:21 . 2009-08-17 16:06 93392 —-a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-22 08:21 . 2009-08-17 16:06 94160 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-22 08:20 . 2009-08-17 16:10 1279456 —-a-w- c:\windows\system32\aswBoot.exe
2009-08-22 08:20 . 2003-03-18 21:20 1060864 —-a-w- c:\windows\system32\MFC71.dll
2009-08-22 08:20 . 2009-08-22 08:20 ——– d—–w- c:\program files\Alwil Software
2009-08-22 07:44 . 2009-08-22 07:44 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-08-22 07:44 . 2009-08-22 07:44 ——– d—–w- c:\program files\NOS
2009-08-22 07:44 . 2009-08-22 07:44 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-08-22 07:44 . 2009-08-07 07:14 30400 —-a-w- c:\documents and settings\musical\Application Data\Mozilla\Firefox\Profiles\drlglawz.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2009-08-22 07:44 . 2009-08-07 07:14 22848 —-a-w- c:\documents and settings\musical\Application Data\Mozilla\Firefox\Profiles\drlglawz.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg_bootstrap.exe
2009-08-22 07:44 . 2009-08-07 07:14 19792 —-a-w- c:\documents and settings\musical\Application Data\Mozilla\Firefox\Profiles\drlglawz.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2009-08-20 09:37 . 2009-08-20 09:37 ——– d—–w- c:\program files\SpywareGuard
2009-08-20 09:14 . 2009-08-20 09:14 ——– d—–w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-20 09:14 . 2009-08-20 09:14 ——– d—–w- c:\program files\SpywareBlaster
2009-08-20 09:14 . 2005-08-25 13:48 118784 —-a-w- c:\windows\system32\MSSTDFMT.DLL
2009-08-20 06:54 . 1998-10-29 11:15 306688 —-a-w- c:\windows\IsUninst.exe
2009-08-19 20:33 . 2009-08-19 20:33 ——– d—–w- c:\program files\Trend Micro
2009-08-19 16:13 . 2009-08-19 16:13 ——– d—–w- c:\program files\CCleaner
2009-08-19 15:00 . 2009-08-19 15:00 ——– d—–w- c:\documents and settings\musical\Application Data\Malwarebytes
2009-08-19 15:00 . 2009-08-03 08:06 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-19 15:00 . 2009-08-19 15:00 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-19 15:00 . 2009-08-19 15:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-19 15:00 . 2009-08-03 08:06 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-19 14:23 . 2009-08-19 14:23 ——– d—–w- c:\documents and settings\musical\Application Data\WinPatrol
2009-08-19 14:23 . 2009-07-31 08:25 0 —-a-w- c:\documents and settings\musical\Application Data\WinPatrol\Config.sys
2009-08-19 14:23 . 2009-07-31 08:25 0 —-a-w- c:\documents and settings\musical\Application Data\WinPatrol\Autoexec.bat
2009-08-19 14:23 . 2009-08-19 14:23 ——– d—–w- c:\program files\BillP Studios
2009-08-19 11:46 . 2009-08-19 11:46 ——– d—–w- c:\program files\ERUNT
2009-08-19 10:59 . 2009-08-19 10:59 0 —-a-w- c:\windows\nsreg.dat
2009-08-19 10:57 . 2009-08-19 10:57 ——– d—–w- c:\documents and settings\musical\Local Settings\Application Data\Mozilla
2009-08-17 07:53 . 2009-08-17 07:53 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-08-17 07:53 . 2009-08-17 07:53 ——– d—–w- c:\program files\DivX
2009-08-15 09:21 . 2009-08-15 09:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-08-15 09:20 . 2009-08-15 09:20 ——– d—–w- c:\documents and settings\musical\Local Settings\Application Data\Apple
2009-08-15 09:20 . 2009-08-15 09:20 ——– d—–w- c:\program files\Apple Software Update
2009-08-15 09:20 . 2009-08-15 09:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-08-15 09:18 . 2009-08-15 09:18 ——– d—–w- c:\documents and settings\musical\Local Settings\Application Data\Apple Computer
2009-08-14 21:43 . 2009-08-14 21:43 ——– d—–w- c:\program files\Common Files\xing shared
2009-08-14 21:43 . 2009-08-14 21:43 ——– d—–w- c:\program files\Common Files\Real
2009-08-11 19:14 . 2009-08-11 19:14 ——– d—–w- c:\documents and settings\musical\Application Data\vlc
2009-08-11 18:20 . 2009-08-11 18:20 ——– d—–w- c:\documents and settings\musical\Application Data\dvdcss
2009-08-11 18:19 . 2009-08-11 18:19 ——– d—–w- c:\program files\VideoLAN
2009-08-08 11:06 . 2009-03-09 09:57 453456 —-a-w- c:\windows\system32\d3dx10_41.dll
2009-08-08 11:06 . 2009-03-09 09:57 1846632 —-a-w- c:\windows\system32\D3DCompiler_41.dll
2009-08-08 11:06 . 2009-03-09 09:57 4178264 —-a-w- c:\windows\system32\D3DX9_41.dll
2009-08-07 19:31 . 2006-12-07 05:15 110592 —-a-w- c:\documents and settings\musical\Application Data\U3\temp\cleanup.exe
2009-08-07 19:19 . 2009-08-07 19:19 ——– d—–w- C:\Sun
2009-08-07 18:59 . 2006-12-07 05:15 3096576 —ha-w- c:\documents and settings\musical\Application Data\U3\temp\Launchpad Removal.exe
2009-08-07 18:58 . 2009-08-07 18:58 ——– d—–w- c:\documents and settings\musical\Application Data\U3
2009-08-07 16:40 . 2009-08-07 16:40 ——– d—–w- c:\documents and settings\musical\Local Settings\Application Data\Identities
2009-08-07 16:25 . 2009-08-07 16:25 ——– d—–w- c:\windows\system32\Adobe
2009-08-02 07:09 . 2009-08-02 07:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Propellerhead Software
2009-08-02 07:09 . 2009-08-02 07:09 233472 —-a-w- c:\windows\system32\REX Shared Library.dll
2009-08-02 07:09 . 2009-08-02 07:09 225280 —-a-w- c:\windows\system32\ReWire.dll
2009-08-02 07:09 . 2009-08-02 07:09 ——– d—–w- c:\documents and settings\musical\Application Data\Propellerhead Software
2009-08-02 07:05 . 2009-08-02 07:05 ——– d—–w- c:\documents and settings\musical\Local Settings\Application Data\DFX
2009-08-02 07:05 . 2009-08-02 07:05 ——– d—–w- c:\documents and settings\All Users\Application Data\DFX
2009-08-02 07:05 . 2009-08-02 07:05 ——– d—–w- c:\program files\Common Files\DFX
2009-08-02 06:47 . 2009-08-02 06:48 ——– d—–w- c:\program files\BitLord
2009-08-02 05:49 . 2004-08-03 17:38 26496 —-a-w- c:\windows\system32\dllcache\usbstor.sys
2009-07-31 20:28 . 2009-07-31 20:28 ——– d—–w- c:\documents and settings\musical\Local Settings\Application Data\Help
2009-07-31 20:23 . 2009-07-31 20:23 1024 —h–r- c:\windows\system32\ntiembed.dll
2009-07-31 20:21 . 2009-07-31 20:21 ——– d—–w- c:\windows\Vbox
2009-07-31 20:21 . 2001-08-23 07:30 9728 ——w- c:\windows\system\regsvr32.exe
2009-07-31 20:20 . 2009-07-31 20:20 ——– d—–w- c:\windows\system32\Iosubsys
2009-07-31 20:19 . 2009-07-31 20:20 ——– d—–w- c:\program files\NewTech Infosystems
2009-07-31 20:19 . 2009-07-31 20:19 1024 —h–r- c:\windows\system32\NTIMPEG2.dll
2009-07-31 20:19 . 2009-07-31 20:19 1024 —h–r- c:\windows\system32\NTICDMK32.dll
2009-07-31 20:19 . 2009-07-31 20:19 6912 —-a-w- c:\windows\system32\drivers\NTIDrvr.sys
2009-07-31 15:35 . 2000-06-26 06:15 106496 —-a-w- c:\windows\system32\TwnLib20.dll
2009-07-31 15:34 . 2004-07-26 11:46 471040 ——w- c:\windows\system32\ImagXRA7.dll
2009-07-31 15:34 . 2004-07-26 11:46 262144 ——w- c:\windows\system32\ImagXR7.dll
2009-07-31 15:34 . 2004-07-26 11:46 476320 ——w- c:\windows\system32\ImagXpr7.dll
2009-07-31 15:34 . 2004-07-26 11:46 1568768 ——w- c:\windows\system32\ImagX7.dll
2009-07-31 15:34 . 2009-07-31 15:34 ——– d—–w- c:\program files\Common Files\Ahead
2009-07-31 15:34 . 2001-07-09 06:20 155648 —-a-w- c:\windows\system32\NeroCheck.exe
2009-07-31 15:34 . 2009-07-31 15:34 ——– d—–w- c:\program files\Ahead
2009-07-31 15:20 . 2009-07-31 15:20 ——– d—–w- c:\program files\WIDCOMM
2009-07-31 12:55 . 2009-07-31 12:55 12328 —-a-w- c:\documents and settings\musical\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-31 12:55 . 2009-07-31 12:55 ——– d—–w- c:\windows\system32\CBA
2009-07-31 12:55 . 2009-07-31 12:55 ——– d—–w- c:\program files\Symantec
2009-07-31 12:55 . 2009-07-31 12:55 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-07-31 12:54 . 2009-07-31 12:54 ——– d—–w- c:\program files\NavNT
2009-07-31 12:47 . 2009-08-14 21:43 499712 —-a-w- c:\windows\system32\msvcp71.dll
2009-07-31 12:47 . 2009-08-14 21:43 348160 —-a-w- c:\windows\system32\msvcr71.dll
2009-07-31 11:38 . 2009-07-31 11:38 ——– d—–w- c:\program files\Broadcom
2009-07-31 11:35 . 2009-07-31 11:35 17801 —-a-w- c:\windows\system32\drivers\AegisP.sys
2009-07-31 11:35 . 2004-12-21 18:32 81920 ——w- c:\windows\system32\wltrynt.dll
2009-07-31 11:35 . 2004-12-21 18:32 192512 ——w- c:\windows\system32\AegisI5.exe
2009-07-31 11:35 . 2004-12-21 18:32 172032 ——w- c:\windows\system32\BCMLogon.dll
2009-07-31 11:35 . 2004-12-21 18:32 65536 ——w- c:\windows\system32\WLTRYSVC.EXE
2009-07-31 11:34 . 2004-12-21 18:32 647272 ——w- c:\windows\system32\WLTRAY.EXE
2009-07-31 11:34 . 2004-12-21 18:32 1396831 ——w- c:\windows\system32\AegisE5.dll
2009-07-31 11:34 . 2004-12-21 18:32 827499 ——w- c:\windows\system32\BCMWLTRY.EXE
2009-07-31 11:34 . 2004-12-21 18:32 69632 ——w- c:\windows\system32\bcmwlD2K.EXE
2009-07-31 11:30 . 2005-03-22 05:53 163840 —-a-r- c:\windows\system32\igfxres.dll
2009-07-31 11:25 . 2004-10-29 11:48 3222784 —-a-r- c:\windows\system32\drivers\w29n51.sys
2009-07-31 11:25 . 2004-10-15 03:20 458752 —-a-r- c:\windows\system32\w29NCPA.dll
2009-07-31 11:25 . 2004-09-07 06:23 156672 —-a-r- c:\windows\system32\RTLCPAPI.dll
2009-07-31 11:24 . 2004-12-01 07:57 9324032 —-a-r- c:\windows\system32\RTLCPL.EXE
2009-07-31 11:24 . 2004-12-01 07:54 77824 —-a-r- c:\windows\SOUNDMAN.EXE
2009-07-31 11:24 . 2004-12-01 12:40 2300928 —-a-r- c:\windows\system32\drivers\ALCXWDM.SYS
2009-07-31 11:23 . 2005-04-15 05:40 1073375 —-a-r- c:\windows\system32\drivers\AGRSM.sys
2009-07-31 11:23 . 2005-04-15 03:45 88202 —-a-r- c:\windows\AGRSMMSG.exe
2009-07-31 11:23 . 2004-04-05 02:49 64512 —-a-r- c:\windows\agrsmdel.exe
2009-07-31 10:31 . 2009-07-31 10:31 ——– d-s—w- c:\documents and settings\musical\UserData
2009-07-31 09:21 . 2009-07-31 09:21 ——– d—–w- c:\windows\Options
2009-07-31 09:21 . 2004-02-13 05:49 356352 —-a-r- c:\windows\EMCRI.dll
2009-07-31 09:10 . 2009-07-31 09:10 ——– d—–w- c:\documents and settings\musical\Application Data\Intel
2009-07-31 09:08 . 2009-07-31 09:08 ——– d—–w- c:\program files\Intel
2009-07-31 09:03 . 2004-12-21 18:32 184320 ——w- c:\windows\system32\BCMWLU00.EXE
2009-07-31 09:03 . 2004-12-21 18:32 369024 ——w- c:\windows\system32\drivers\BCMWL5.SYS

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-10 14:46 . 2004-07-17 05:06 12464 —-a-w- c:\windows\system32\drivers\secdrv.sys
2009-07-31 10:15 . 2009-07-31 08:24 86327 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-07-31 08:56 . 2009-07-31 08:56 ——– d—–w- c:\documents and settings\musical\Application Data\AdobeUM
2009-07-31 08:56 . 2009-07-31 08:56 ——– d—–w- c:\program files\Common Files\Adobe
2009-07-31 08:39 . 2009-07-31 08:39 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-31 08:39 . 2009-07-31 08:39 ——– d—–w- c:\program files\Common Files\InstallShield
2009-07-31 08:26 . 2009-07-31 08:26 ——– d—–w- c:\program files\microsoft frontpage
2009-07-31 08:20 . 2009-07-31 08:20 21640 —-a-w- c:\windows\system32\emptyregdb.dat
.

——- Sigcheck ——-

[-] 2009-08-15 16:14 619200 5D407322AA69AC6E7B17C81B48DEB327 c:\windows\system32\dllcache\ntfs.sys

c:\windows\system32\drivers\ntfs.sys … is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-03-22 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-03-22 126976]
"QuickTime Task"="d:\quicktime7.62\qttask.exe" [2009-05-26 413696]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-07-27 341312]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-08-14 198160]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2005-04-15 88202]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-12-01 77824]

c:\documents and settings\musical\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2004-5-25 565309]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"btwdins"=2 (0x2)
"wuauserv"=2 (0x2)
"Themes"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"d:\\pd\\bin\\pd.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [8/22/2009 1:51 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8/22/2009 1:51 PM 20560]
S3 getPlusHelper;getPlus® Helper;c:\windows\System32\svchost.exe -k getPlusHelper [8/3/2004 11:56 PM 14336]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-SynTPLpr - c:\program files\Synaptics\SynTP\SynTPLpr.exe
HKLM-Run-SynTPEnh - c:\program files\Synaptics\SynTP\SynTPEnh.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.imdb.com/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
FF - ProfilePath - c:\documents and settings\musical\Application Data\Mozilla\Firefox\Profiles\drlglawz.default\
FF - component: d:\realplayer11\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\documents and settings\musical\Application Data\Mozilla\Firefox\Profiles\drlglawz.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: d:\acrobat 6.0\Reader\browser\nppdf32.dll
FF - plugin: d:\quicktime7.62\Plugins\npqtplugin.dll
FF - plugin: d:\quicktime7.62\Plugins\npqtplugin2.dll
FF - plugin: d:\quicktime7.62\Plugins\npqtplugin3.dll
FF - plugin: d:\quicktime7.62\Plugins\npqtplugin4.dll
FF - plugin: d:\quicktime7.62\Plugins\npqtplugin5.dll
FF - plugin: d:\quicktime7.62\Plugins\npqtplugin6.dll
FF - plugin: d:\quicktime7.62\Plugins\npqtplugin7.dll
FF - plugin: d:\realplayer11\Netscape6\nppl3260.dll
FF - plugin: d:\realplayer11\Netscape6\nprjplug.dll
FF - plugin: d:\realplayer11\Netscape6\nprpjplug.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-30 10:04
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(608)
c:\windows\System32\BCMLogon.dll
c:\windows\system32\NavLogon.dll
.
———————— Other Running Processes ————————
.
c:\windows\SYSTEM32\WLTRYSVC.EXE
c:\windows\SYSTEM32\BCMWLTRY.EXE
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\WLTRAY.exe
c:\windows\SYSTEM32\WSCNTFY.EXE
.
**************************************************************************
.
Completion time: 2009-08-30 10:06 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-30 04:36

Pre-Run: 15,378,022,400 bytes free
Post-Run: 15,377,940,480 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
C:\ = "Microsoft Windows"

314


Thank you for your time .
Hi,

we need to find a replacement for the ntfs.sys file


Please do the following:

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :filefind
    *ntfs*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
HI
here is the Systemlook log


SystemLook v1.0 by jpshortstuff (29.08.09)
Log created at 01:00 on 31/08/2009 by musical (Administrator - Elevation successful)

========== filefind ==========

Searching for "*ntfs*"
C:\cmdcons\NTFS.SYS –a— 574592 bytes [17:45 03/08/2004] [17:45 03/08/2004] B78BE402C3F63DD55521F73876951CDD
C:\Program Files\Alwil Software\Avast4\DATA\moved\ntfs.sys.2.vir –a— 619200 bytes [08:31 22/08/2009] [08:31 22/08/2009] 5D407322AA69AC6E7B17C81B48DEB327
C:\Program Files\Alwil Software\Avast4\DATA\moved\ntfs.sys.vir –a— 619200 bytes [16:45 03/08/2004] [16:14 15/08/2009] 5D407322AA69AC6E7B17C81B48DEB327
C:\WINDOWS\system32\chkntfs.exe –a— 11264 bytes [06:30 23/08/2001] [06:30 23/08/2001] 8C0E9012EB04596B757FA4C547438908
C:\WINDOWS\system32\dfrgntfs.exe –a— 104960 bytes [18:26 03/08/2004] [18:26 03/08/2004] AD13E23A2CCDF46C0EB354E5867EAE72
C:\WINDOWS\system32\dllcache\chkntfs.exe –a— 11264 bytes [06:30 23/08/2001] [06:30 23/08/2001] 8C0E9012EB04596B757FA4C547438908
C:\WINDOWS\system32\dllcache\dfrgntfs.exe –a— 104960 bytes [18:26 03/08/2004] [18:26 03/08/2004] AD13E23A2CCDF46C0EB354E5867EAE72
C:\WINDOWS\system32\dllcache\EXCH_ntfsdrv.dll –a— 38912 bytes [08:29 31/07/2009] [17:06 17/08/2001] EEE6EFD0A1861B8322D0BF9B0060A8D5
C:\WINDOWS\system32\dllcache\ntfs.sys –a— 619200 bytes [16:45 03/08/2004] [16:14 15/08/2009] 5D407322AA69AC6E7B17C81B48DEB327
C:\WINDOWS\system32\dllcache\untfs.dll –a— 316416 bytes [18:26 03/08/2004] [18:26 03/08/2004] A5B34D9E90E7F9AF4C7630A38C6B1728
C:\WINDOWS\system32\untfs.dll –a— 316416 bytes [18:26 03/08/2004] [18:26 03/08/2004] A5B34D9E90E7F9AF4C7630A38C6B1728

-=End Of File=-

See ya soon !
Please do the following:

I would like you to upload a file to be scanned
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:


    c:\windows\system32\dllcache\ntfs.sys

  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.
Hi I am going to run VirScan Online Scan , but my free Anti-Virus Avast4.8 scanned it earlier and I chose an Option to "Move" it . However i am still gonna do as you have directed & I'll post the results. Thank you. See Ya!
Hi ,
Well i did not get the "ntfs.sys" file in the C:\Windows\… as you have directed , however there is "ntfs.sys.vir" file in
"C:\Program Files\Alwil Software\Avast4\DATA\moved " which i scanned online and here is the result.

Also IE gives me an error " Failed to find flengt file" and i cannot upload thru IE, hence i have used Firefox and manually copying and pasting the contents of the page here

Just incase you dont find this readable i have attached 2 GIF images of the Virscan online Report WEBPAGE

File information
File Name : ntfs.sys
File Size : 619200 byte
File Type : PE32 executable for MS Windows (native) Intel 80386 32-bit
MD5 : 5d407322aa69ac6e7b17c81b48deb327
SHA1 : a9d49e87ebcce46e62dd36dac22a59f80631a257

Scanner results
Scanner results : 38% Scanner(14/37) found malware!
Time : 2009/08/15 04:27:58 (IST)

Scanner || Engine Ver || Sig Ver || Sig Date || Scan result || Time
a-squared || [removed] || 20090815010138 || 2009-08-15 || Riskware.WinNT.Cutwail!IK || 0.378
AhnLab V3 2009.08.14.06 2009.08.14 2009-08-14 Win32/Ntfs 0.779
AntiVir 8.2.1.1 7.1.5.117 2009-08-14 RKIT/Kobcka.Patched.A 0.314
Antiy 20.18 20090814.2703881 2009-08-14 - 0.120
Arcavir 2009 200908131337 2009-08-13 - 0.058
Authentium 5.1.1 200908141913 2009-08-14 - 1.199
AVAST! 4.7.4 090814-0 2009-08-14 Win32:Cutwail-W [Trj] 0.024
AVG 8.5.288 270.13.57/2303 2009-08-15 Rootkit-Pakes.M 0.325
BitDefender 7.81008.3857542 7.27159 2009-08-15 Rootkit.Kobcka.Patched.A 3.315
CA (VET) [removed] 31.6.6677 2009-08-15 - 7.980
ClamAV 0.95.2 9696 2009-08-14 - 0.073
Comodo 3.10 1978 2009-08-14 - 0.740
CP Secure 1.1.0.715 2009.08.14 2009-08-14 - 12.301
Dr.Web 4.44.0.9170 2009.08.14 2009-08-14 BackDoor.Bulknet.404 8.201
F-Prot 4.4.4.56 20090814 2009-08-14 - 1.183
F-Secure 7.02.73807 2009.08.14.10 2009-08-14 Virus.Win32.Protector.c [AVP] 7.804
Fortinet 2.81-3.120 10.715 2009-08-14 - 0.285
GData 19.7134/19.439 20090814 2009-08-14 Virus.Win32.Protector.c [Engine:A] 4.649
Ikarus T3.1.01.64 2009.08.14.73240 2009-08-14 VirTool.WinNT.Cutwail 3.897
JiangMin 11.0.800 2009.08.14 2009-08-14 - 4.742
Kaspersky 5.5.10 2009.08.14 2009-08-14 Virus.Win32.Protector.c 0.057
KingSoft 2009.2.5.15 2009.8.14.18 2009-08-14 - 0.536
McAfee 5.3.00 5709 2009-08-14 - 3.093
Microsoft 1.4903 2009.08.14 2009-08-14 VirTool:WinNT/Cutwail.L 5.733
Norman 6.01.09 6.01.00 2009-08-13 - 2.006
nProtect 20090814.01 5009831 2009-08-14 - 6.145
Panda 9.05.01 2009.08.14 2009-08-14 Generic Rootkit 1.866
Quick Heal 10.00 2009.08.13 2009-08-13 - 1.288
Rising 20.0 21.42.44.00 2009-08-14 - 0.803
Sophos 2.89.1 4.44 2009-08-15 Troj/NTFSKit-B 3.004
Sunbelt 5330 5330 2009-08-13 - 1.307
Symantec 1.3.0.24 20090814.004 2009-08-14 - 0.154
The Hacker 6.3.4.3 v00383 2009-08-12 - 0.746
Trend Micro 8.700-1004 6.365.00 2009-08-14 - 0.030
VBA32 [removed] 20090813.1326 2009-08-13 - 1.844
ViRobot 20090814 2009.08.14 2009-08-14 - 0.411
VirusBuster 4.5.11.10 10.112.5/1799186 2009-08-14 - 3.509
NOTICE: It may be false positive by some scanners when they found a malware, so you should judge it by yourself.

Thank you.

See ya!

Attachments:

  • [attachment removed: rsz_virscanprt2.gif]
  • [attachment removed: rsz_1virscan1.gif]
Hi,

Yes I was aware the infected file has been moved.

We are trying to find a clean replacement.

There is a copy of ntfs in your dll cache here - c:\windows\system32\dllcache\ntfs.sys

this is the file I need scanned to see whether it too is infected.

If it is clean, we can copy it to where the original ntfs was located. If not we need your installation disk to copy a clean file.


You may need to show hidden files and folders to locate the file in dllcache:

  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Clear "Hide file extensions for known file types."
  • Under the "Hidden files" folder, select "Show hidden files and folders."
  • Clear "Hide protected operating system files."
  • Click Apply, and then click OK.


If you can now find the file c:\windows\system32\dllcache\ntfs.sys - please scan it

thank-you

~CB
Hi,

Please do the following:


1] Boot computer with the Windows XP CD-ROM in the CD-ROM drive.
2] To repair a Windows XP installation using Recovery Console, press R.
3] At the command prompt, type the following commands:-

cd \windows\system32\drivers [Press the ENTER Key]

ren ntfs.sys ntfs.old
[Press the ENTER Key]

If the ntfs.sys file is there and corrupt it will rename it. If it is not there then it was missing.

4]At the command prompt, type the following command, and then press ENTER:
copy X:\i386\ntfs.sys drive:\windows\system32\drivers [Where X=CD-ROM Drive letter]

5]Remove the Windows XP CD from CD-ROM drive, type quit, and then
press ENTER to quit the Recovery Console.

6. Restart the system.
Hi, Just before i do the aforesaid replacement of my ntfs.sys file I have 4 questions 1> will i lose the data stored in "My Documents " folder? 2> will i lose the new bookmarks stored in Firefox's bookmark? 3> what would change after this is replacement is done ? 4> will i be able to re- install NAV Enterprise edition 7.6 ? as it does not install when i run the CD! see you!
Hi All this is doing is replacing the infected ntfs.sys file. Nothing else on your computer should change. There are still some more scans to complete, to make sure all the malware is gone. I am not sure at this point what is preventing the installation of Nav Enterprise.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI