This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Attacked by Packed Generic 233 after Fresh Installatio

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi well i did as you said but there was no file like ntfs.sys in the c:\….\drivers folder, when i used the "ren" command . however , then i used the "Copy " command as directed , to copy the ntfs.sys file . Now what is the next step? ( However there is "npfs.sys" file in the c:\windows\system32\drivers" already existing, do i have to do anything to it ?) See you!
Hi, Yes, that is probably the file you just copied over Please rerun Combofix - allow it to update if it asks to do so, we need to make sure we have overwritten that infected file.
Hi
here is the new Combofix Log now

ComboFix 09-08-31.04 - musical 09/01/2009 22:43.2.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1015.652 [GMT 5.5:30]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1351 [VPS 090831-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((( Files Created from 2009-08-01 to 2009-09-01 )))))))))))))))))))))))))))))))
.

2009-08-29 05:28 . 2009-08-29 05:28 ——– d–h–w- c:\windows\PIF
2009-08-22 08:21 . 2009-08-17 16:04 51376 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-22 08:21 . 2009-08-17 16:04 23152 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-22 08:21 . 2009-08-17 16:03 26944 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-22 08:21 . 2009-08-17 16:02 97480 —-a-w- c:\windows\system32\AvastSS.scr
2009-08-22 08:21 . 2009-08-17 16:05 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-22 08:21 . 2009-08-17 16:05 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-22 08:21 . 2009-08-17 16:06 93392 —-a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-22 08:21 . 2009-08-17 16:06 94160 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-22 08:20 . 2009-08-17 16:10 1279456 —-a-w- c:\windows\system32\aswBoot.exe
2009-08-22 08:20 . 2003-03-18 21:20 1060864 —-a-w- c:\windows\system32\MFC71.dll
2009-08-22 08:20 . 2009-08-22 08:20 ——– d—–w- c:\program files\Alwil Software
2009-08-22 07:44 . 2009-08-22 07:44 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-08-22 07:44 . 2009-08-22 07:44 ——– d—–w- c:\program files\NOS
2009-08-22 07:44 . 2009-08-22 07:44 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-08-22 07:44 . 2009-08-07 07:14 30400 —-a-w- c:\documents and settings\musical\Application Data\Mozilla\Firefox\Profiles\drlglawz.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2009-08-22 07:44 . 2009-08-07 07:14 22848 —-a-w- c:\documents and settings\musical\Application Data\Mozilla\Firefox\Profiles\drlglawz.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg_bootstrap.exe
2009-08-22 07:44 . 2009-08-07 07:14 19792 —-a-w- c:\documents and settings\musical\Application Data\Mozilla\Firefox\Profiles\drlglawz.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2009-08-20 09:37 . 2009-08-20 09:37 ——– d—–w- c:\program files\SpywareGuard
2009-08-20 09:14 . 2009-08-20 09:14 ——– d—–w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-20 09:14 . 2009-08-20 09:14 ——– d—–w- c:\program files\SpywareBlaster
2009-08-20 09:14 . 2005-08-25 13:48 118784 —-a-w- c:\windows\system32\MSSTDFMT.DLL
2009-08-20 06:54 . 1998-10-29 11:15 306688 —-a-w- c:\windows\IsUninst.exe
2009-08-19 20:33 . 2009-08-19 20:33 ——– d—–w- c:\program files\Trend Micro
2009-08-19 16:13 . 2009-08-19 16:13 ——– d—–w- c:\program files\CCleaner
2009-08-19 15:00 . 2009-08-19 15:00 ——– d—–w- c:\documents and settings\musical\Application Data\Malwarebytes
2009-08-19 15:00 . 2009-08-03 08:06 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-19 15:00 . 2009-08-19 15:00 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-19 15:00 . 2009-08-19 15:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-19 15:00 . 2009-08-03 08:06 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-19 14:23 . 2009-08-19 14:23 ——– d—–w- c:\documents and settings\musical\Application Data\WinPatrol
2009-08-19 14:23 . 2009-07-31 08:25 0 —-a-w- c:\documents and settings\musical\Application Data\WinPatrol\Config.sys
2009-08-19 14:23 . 2009-07-31 08:25 0 —-a-w- c:\documents and settings\musical\Application Data\WinPatrol\Autoexec.bat
2009-08-19 14:23 . 2009-08-19 14:23 ——– d—–w- c:\program files\BillP Studios
2009-08-19 11:46 . 2009-08-19 11:46 ——– d—–w- c:\program files\ERUNT
2009-08-19 10:59 . 2009-08-19 10:59 0 —-a-w- c:\windows\nsreg.dat
2009-08-19 10:57 . 2009-08-19 10:57 ——– d—–w- c:\documents and settings\musical\Local Settings\Application Data\Mozilla
2009-08-17 07:53 . 2009-08-17 07:53 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-08-17 07:53 . 2009-08-17 07:53 ——– d—–w- c:\program files\DivX
2009-08-15 09:21 . 2009-08-15 09:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-08-15 09:20 . 2009-08-15 09:20 ——– d—–w- c:\documents and settings\musical\Local Settings\Application Data\Apple
2009-08-15 09:20 . 2009-08-15 09:20 ——– d—–w- c:\program files\Apple Software Update
2009-08-15 09:20 . 2009-08-15 09:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-08-15 09:18 . 2009-08-15 09:18 ——– d—–w- c:\documents and settings\musical\Local Settings\Application Data\Apple Computer
2009-08-14 21:43 . 2009-08-14 21:43 ——– d—–w- c:\program files\Common Files\xing shared
2009-08-14 21:43 . 2009-08-14 21:43 ——– d—–w- c:\program files\Common Files\Real
2009-08-11 19:14 . 2009-08-11 19:14 ——– d—–w- c:\documents and settings\musical\Application Data\vlc
2009-08-11 18:20 . 2009-08-11 18:20 ——– d—–w- c:\documents and settings\musical\Application Data\dvdcss
2009-08-11 18:19 . 2009-08-11 18:19 ——– d—–w- c:\program files\VideoLAN
2009-08-08 11:06 . 2009-03-09 09:57 453456 —-a-w- c:\windows\system32\d3dx10_41.dll
2009-08-08 11:06 . 2009-03-09 09:57 1846632 —-a-w- c:\windows\system32\D3DCompiler_41.dll
2009-08-08 11:06 . 2009-03-09 09:57 4178264 —-a-w- c:\windows\system32\D3DX9_41.dll
2009-08-07 19:31 . 2006-12-07 05:15 110592 —-a-w- c:\documents and settings\musical\Application Data\U3\temp\cleanup.exe
2009-08-07 19:19 . 2009-08-07 19:19 ——– d—–w- C:\Sun
2009-08-07 18:59 . 2006-12-07 05:15 3096576 —ha-w- c:\documents and settings\musical\Application Data\U3\temp\Launchpad Removal.exe
2009-08-07 18:58 . 2009-08-07 18:58 ——– d—–w- c:\documents and settings\musical\Application Data\U3
2009-08-07 16:40 . 2009-08-07 16:40 ——– d—–w- c:\documents and settings\musical\Local Settings\Application Data\Identities
2009-08-07 16:25 . 2009-08-07 16:25 ——– d—–w- c:\windows\system32\Adobe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-14 21:43 . 2009-07-31 12:47 499712 —-a-w- c:\windows\system32\msvcp71.dll
2009-08-14 21:43 . 2009-07-31 12:47 348160 —-a-w- c:\windows\system32\msvcr71.dll
2009-08-10 14:46 . 2004-07-17 05:06 12464 —-a-w- c:\windows\system32\drivers\secdrv.sys
2009-08-02 07:09 . 2009-08-02 07:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Propellerhead Software
2009-08-02 07:09 . 2009-08-02 07:09 233472 —-a-w- c:\windows\system32\REX Shared Library.dll
2009-08-02 07:09 . 2009-08-02 07:09 225280 —-a-w- c:\windows\system32\ReWire.dll
2009-08-02 07:09 . 2009-08-02 07:09 ——– d—–w- c:\documents and settings\musical\Application Data\Propellerhead Software
2009-08-02 07:05 . 2009-08-02 07:05 ——– d—–w- c:\documents and settings\All Users\Application Data\DFX
2009-08-02 07:05 . 2009-08-02 07:05 ——– d—–w- c:\program files\Common Files\DFX
2009-08-02 06:48 . 2009-08-02 06:47 ——– d—–w- c:\program files\BitLord
2009-07-31 20:23 . 2009-07-31 20:23 1024 —h–r- c:\windows\system32\ntiembed.dll
2009-07-31 20:20 . 2009-07-31 20:19 ——– d—–w- c:\program files\NewTech Infosystems
2009-07-31 20:19 . 2009-07-31 20:19 1024 —h–r- c:\windows\system32\NTIMPEG2.dll
2009-07-31 20:19 . 2009-07-31 20:19 1024 —h–r- c:\windows\system32\NTICDMK32.dll
2009-07-31 20:19 . 2009-07-31 20:19 6912 —-a-w- c:\windows\system32\drivers\NTIDrvr.sys
2009-07-31 15:34 . 2009-07-31 15:34 ——– d—–w- c:\program files\Common Files\Ahead
2009-07-31 15:34 . 2009-07-31 15:34 ——– d—–w- c:\program files\Ahead
2009-07-31 15:20 . 2009-07-31 15:20 ——– d—–w- c:\program files\WIDCOMM
2009-07-31 12:55 . 2009-07-31 12:55 12328 —-a-w- c:\documents and settings\musical\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-31 12:55 . 2009-07-31 12:55 ——– d—–w- c:\program files\Symantec
2009-07-31 12:55 . 2009-07-31 12:55 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-07-31 12:54 . 2009-07-31 12:54 ——– d—–w- c:\program files\NavNT
2009-07-31 11:38 . 2009-07-31 11:38 ——– d—–w- c:\program files\Broadcom
2009-07-31 11:35 . 2009-07-31 11:35 17801 —-a-w- c:\windows\system32\drivers\AegisP.sys
2009-07-31 10:15 . 2009-07-31 08:24 86327 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-07-31 09:10 . 2009-07-31 09:10 ——– d—–w- c:\documents and settings\musical\Application Data\Intel
2009-07-31 09:08 . 2009-07-31 09:08 ——– d—–w- c:\program files\Intel
2009-07-31 08:56 . 2009-07-31 08:56 ——– d—–w- c:\documents and settings\musical\Application Data\AdobeUM
2009-07-31 08:56 . 2009-07-31 08:56 ——– d—–w- c:\program files\Common Files\Adobe
2009-07-31 08:39 . 2009-07-31 08:39 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-31 08:39 . 2009-07-31 08:39 ——– d—–w- c:\program files\Common Files\InstallShield
2009-07-31 08:26 . 2009-07-31 08:26 ——– d—–w- c:\program files\microsoft frontpage
2009-07-31 08:20 . 2009-07-31 08:20 21640 —-a-w- c:\windows\system32\emptyregdb.dat
.

((((((((((((((((((((((((((((( SnapShot@2009-08-30_04.34.52 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-01 16:14 . 2009-09-01 16:14 16384 c:\windows\Temp\Perflib_Perfdata_784.dat
+ 2004-08-03 16:45 . 2004-08-03 16:45 574592 c:\windows\system32\drivers\ntfs.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-03-22 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-03-22 126976]
"QuickTime Task"="d:\quicktime7.62\qttask.exe" [2009-05-26 413696]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-07-27 341312]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-08-14 198160]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2005-04-15 88202]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-12-01 77824]

c:\documents and settings\musical\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2004-5-25 565309]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"btwdins"=2 (0x2)
"wuauserv"=2 (0x2)
"Themes"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"d:\\pd\\bin\\pd.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [8/22/2009 1:51 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8/22/2009 1:51 PM 20560]
S3 getPlusHelper;getPlus® Helper;c:\windows\System32\svchost.exe -k getPlusHelper [8/3/2004 11:56 PM 14336]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.imdb.com/
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
FF - ProfilePath - c:\documents and settings\musical\Application Data\Mozilla\Firefox\Profiles\drlglawz.default\
FF - component: d:\realplayer11\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\documents and settings\musical\Application Data\Mozilla\Firefox\Profiles\drlglawz.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: d:\acrobat 6.0\Reader\browser\nppdf32.dll
FF - plugin: d:\quicktime7.62\Plugins\npqtplugin.dll
FF - plugin: d:\quicktime7.62\Plugins\npqtplugin2.dll
FF - plugin: d:\quicktime7.62\Plugins\npqtplugin3.dll
FF - plugin: d:\quicktime7.62\Plugins\npqtplugin4.dll
FF - plugin: d:\quicktime7.62\Plugins\npqtplugin5.dll
FF - plugin: d:\quicktime7.62\Plugins\npqtplugin6.dll
FF - plugin: d:\quicktime7.62\Plugins\npqtplugin7.dll
FF - plugin: d:\realplayer11\Netscape6\nppl3260.dll
FF - plugin: d:\realplayer11\Netscape6\nprjplug.dll
FF - plugin: d:\realplayer11\Netscape6\nprpjplug.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-01 22:46
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(608)
c:\windows\System32\BCMLogon.dll
c:\windows\system32\NavLogon.dll
.
Completion time: 2009-09-01 22:47
ComboFix-quarantined-files.txt 2009-09-01 17:17
ComboFix2.txt 2009-08-30 04:36

Pre-Run: 15,294,414,848 bytes free
Post-Run: 15,267,856,384 bytes free

203
Good job:

Now please do the following:


Open your MalwareBytes Antimalware program
  • Go to the update tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so.

NEXT
It's important to run this online scan to search for any remnants. It can take some time, so please be patient and allow it to run it's full course:

Using Internet Explorer or Firefox, visit Kaspersky Online Scanner:
1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.
    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
HI here is the malware bytes report , However the Kaspersky online scan is taking a lot of time to Download the update itself (about 1 hour for abt 45 Mb) hence, Could we run something else if there is an alternative . I am giving Kaspersky one more try though . Seeya! Malwarebytes' Anti-Malware 1.40 Database version: 2726 Windows 5.1.2600 Service Pack 2 9/1/2009 11:58:23 PM mbam-log-2009-09-01 (23-58-23).txt Scan type: Quick Scan Objects scanned: 81168 Time elapsed: 2 minute(s), 41 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi,

Yes Kaspersky does take a long time to run, it is very thorough

If you are having difficulty with it, try this scanner:

  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.


Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.
Hi Did the scan but stopped in the end coz it hanged hence did manually select the remaining folders on E drive to complete the scan Also the folder in E:\tools2\.. and E:\vijay mukhi ..\..are stored by my brother for his course he had enrolled hence i am bound to keepthem . here are the results ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Wednesday, September 2, 2009 Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Wednesday, September 02, 2009 09:33:00 Records in database: 2739681 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ Scan statistics: Objects scanned: 66157 Threats found: 29 Infected objects found: 64 Suspicious objects found: 0 Scan duration: 02:45:06 File name / Threat / Threats count C:\WINDOWS\system32\dllcache\ntfs.sys Infected: Virus.Win32.Protector.c 1 C:\Program Files\Alwil Software\Avast4\DATA\moved\ntfs.sys.vir Infected: Virus.Win32.Protector.c 1 C:\Program Files\Alwil Software\Avast4\DATA\moved\ntfs.sys.2.vir Infected: Virus.Win32.Protector.c 1 D:\achilles\horoscopes.exe Infected: not-a-virus:AdWare.Win32.Comet.az 1 D:\achilles\fgw13.zip Infected: not-a-virus:AdWare.Win32.WSearch.g 1 D:\DOWNLOADS\iso buster\New Divx Pro\DivXPro502GAINBundle.exe Infected: not-a-virus:AdWare.Win32.Gator.3202 1 D:\DOWNLOADS\LimeWire\june06\cardo - trombose MTV.mp3 Infected: Trojan-Downloader.WMA.GetCodec.f 1 D:\DOWNLOADS\LimeWire\june06\shaggy- wear di crown HD.avi Infected: Trojan-Downloader.WMA.GetCodec.f 1 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\cybercode\samdump.dll Infected: not-a-virus:PSWTool.Win32.PWDump.2 1 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\cybercode\pwdump2.exe Infected: not-a-virus:PSWTool.Win32.PWDump.2 1 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\netcat-nt-1.1.0.zip Infected: not-a-virus:RemoteAdmin.Win32.NetCat.jd 1 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\dsniff-1.8-win32-static.tgz Infected: HackTool.Win32.Sniffer.Dsniff 1 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\cryptcat-nt-22may01.zip Infected: not-a-virus:RemoteAdmin.Win32.NetCat.a 1 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\ca_setup.exe Infected: not-a-virus:PSWTool.Win32.Cain.28 1 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\ca_setup.exe Infected: not-a-virus:PSWTool.Win32.Cain.f 1 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\ca_setup.exe Infected: not-a-virus:PSWTool.Win32.Cain.e 1 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\john-16w.zip Infected: HackTool.Win32.John 3 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\attacker.zip Infected: DoS.Win32.Ataker.a 1 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\acespy331t.exe Infected: not-a-virus:Monitor.Win32.AceSpy.37 1 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\acespy331t.exe Infected: not-a-virus:Monitor.Win32.WinSpy.k 1 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\acespy331t.exe Infected: not-a-virus:Monitor.Win32.Dafunk 1 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\acespy331t.exe Infected: not-a-virus:Monitor.Win32.PCDetective.c 1 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\acespy331t.exe Infected: Backdoor.Win32.Hupigon.dipn 1 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\acespy331t.exe Infected: Trojan-Banker.Win32.Banker.jsb 1 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\acespy331t.exe Infected: Backdoor.Win32.Optix.Pro.13 1 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\pwdump2.zip Infected: not-a-virus:PSWTool.Win32.PWDump.2 2 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\nc111nt.zip Infected: not-a-virus:RemoteAdmin.Win32.NetCat.a 1 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\sara-6.0.7.tgz Infected: HackTool.Perl.TransRoot 2 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\sara-6.0.7.tgz Infected: HackTool.Perl.VulnTest.a 1 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\sara-6.0.7.tgz Infected: not-a-virus:PSWTool.Win32.PWDump.2 2 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\sara-6.0.7.tgz Infected: not-a-virus:RemoteAdmin.Win32.NetCat.jd 1 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\pwdump3v2.zip Infected: not-a-virus:PSWTool.Win32.PWDump.3 3 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\ariskkey.exe Infected: not-a-virus:PSWTool.Win32.Aster.55 2 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\vnc-4_1_1-x86_win32.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4110 1 E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\vnc-4_1_1-x86_win32.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1 E:\tools2\netcat-nt-1.1.0.zip Infected: not-a-virus:RemoteAdmin.Win32.NetCat.jd 1 E:\tools2\dsniff-1.8-win32-static.tgz Infected: HackTool.Win32.Sniffer.Dsniff 1 E:\tools2\cryptcat-nt-22may01.zip Infected: not-a-virus:RemoteAdmin.Win32.NetCat.a 1 E:\tools2\ca_setup.exe Infected: not-a-virus:PSWTool.Win32.Cain.269 1 E:\tools2\ca_setup.exe Infected: not-a-virus:PSWTool.Win32.Cain.e 2 E:\tools2\john-16w.zip Infected: HackTool.Win32.John 3 E:\tools2\attacker.zip Infected: DoS.Win32.Ataker.a 1 E:\tools2\acespy331t.exe Infected: not-a-virus:Monitor.Win32.AceSpy.37 1 E:\tools2\acespy331t.exe Infected: not-a-virus:Monitor.Win32.WinSpy.k 1 E:\tools2\acespy331t.exe Infected: not-a-virus:Monitor.Win32.Dafunk 1 E:\tools2\acespy331t.exe Infected: not-a-virus:Monitor.Win32.PCDetective.c 1 E:\tools2\acespy331t.exe Infected: Backdoor.Win32.Hupigon.dipn 1 E:\tools2\acespy331t.exe Infected: Trojan-Banker.Win32.Banker.jsb 1 E:\tools2\acespy331t.exe Infected: Backdoor.Win32.Optix.Pro.13 1 E:\tools2\pwdump2.zip Infected: not-a-virus:PSWTool.Win32.PWDump.2 2 E:\tools2\nc111nt.zip Infected: not-a-virus:RemoteAdmin.Win32.NetCat.a 1 E:\Downloads\BITLORD DOWNLOADS\Antares.Auto-Tune.VST.DX.RTAS.v4.39-AiR.zip Infected: Trojan-Downloader.Win32.Agent.antd 1 Scanning stopped by the user. see you!
Hi Also i Did the Critical Area scan. Here is the report for that. ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Wednesday, September 2, 2009 Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Wednesday, September 02, 2009 09:33:00 Records in database: 2739681 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - Critical areas: C:\Documents and Settings\All Users\Start Menu\Programs\Startup C:\Documents and Settings\musical\Start Menu\Programs\Startup C:\Program Files C:\WINDOWS Scan statistics: Objects scanned: 13068 Threats found: 1 Infected objects found: 3 Suspicious objects found: 0 Scan duration: 00:07:35 File name / Threat / Threats count C:\Program Files\Alwil Software\Avast4\DATA\moved\ntfs.sys.vir Infected: Virus.Win32.Protector.c 1 C:\Program Files\Alwil Software\Avast4\DATA\moved\ntfs.sys.2.vir Infected: Virus.Win32.Protector.c 1 C:\WINDOWS\system32\dllcache\ntfs.sys Infected: Virus.Win32.Protector.c 1 Selected area has been scanned. See you.
Hi,

Please do the following:

Note: a couple of those tools you say belong to your brother are infected with backdoor trojans. It is unwise to keep these files on your system.

A backdoor trojan can compromise the information contained in your computer.As a precaution, you should change all your passwords. If you have done any financial or personal business transactions with this computer, I would notify the banks/creditcard companies or other businesses that your personal information may have been compromised.

Please do the following:

  • Please download OTM by OldTimer and save it to your desktop.
  • Double click the [external image: Posted Image] icon on your desktop.
  • Paste the following code under the [external image: Posted Image] area.
    Do not include the word "Code".

    :Processes
    explorer.exe
    
    :Files
    C:\Program Files\Alwil Software\Avast4\DATA\moved\ntfs.sys.vir 
    C:\Program Files\Alwil Software\Avast4\DATA\moved\ntfs.sys.2.vir 
    C:\WINDOWS\system32\dllcache\ntfs.sys 
    E:\Downloads\BITLORD DOWNLOADS\Antares.Auto-Tune.VST.DX.RTAS.v4.39-AiR.zip
    E:\tools2\acespy331t.exe 
    E:\tools2\attacker.zip
    E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\acespy331t.exe 
    E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\attacker.zip
    D:\achilles\horoscopes.exe
    D:\achilles\fgw13.zip 
    D:\DOWNLOADS\iso buster\New Divx Pro\DivXPro502GAINBundle.exe
    D:\DOWNLOADS\LimeWire\june06\cardo - trombose MTV.mp3 
    D:\DOWNLOADS\LimeWire\june06\shaggy- wear di crown HD.avi
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [reboot]
  • Push the large [external image: Posted Image] button.
  • OTM may ask to reboot the machine. Please do so if asked.
  • Copy/Paste the contents under the [external image: Posted Image] line here in your next reply.
  • If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
Hi here is the log for OTM All processes killed ========== PROCESSES ========== No active process named explorer.exe was found! ========== FILES ========== C:\Program Files\Alwil Software\Avast4\DATA\moved\ntfs.sys.vir moved successfully. C:\Program Files\Alwil Software\Avast4\DATA\moved\ntfs.sys.2.vir moved successfully. C:\WINDOWS\system32\dllcache\ntfs.sys moved successfully. E:\tools2\acespy331t.exe moved successfully. E:\tools2\attacker.zip moved successfully. E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\acespy331t.exe moved successfully. E:\vijay mukhi tools AND PIRATES OF THE SILICON VALLEY\tools2\attacker.zip moved successfully. D:\achilles\horoscopes.exe moved successfully. D:\achilles\fgw13.zip moved successfully. D:\DOWNLOADS\iso buster\New Divx Pro\DivXPro502GAINBundle.exe moved successfully. D:\DOWNLOADS\LimeWire\june06\cardo - trombose MTV.mp3 moved successfully. D:\DOWNLOADS\LimeWire\june06\shaggy- wear di crown HD.avi moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: All Users User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: LocalService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 32902 bytes User: musical File delete failed. C:\Documents and Settings\musical\Local Settings\Temp\~DF2A77.tmp scheduled to be deleted on reboot. ->Temp folder emptied: 80667410 bytes ->Temporary Internet Files folder emptied: 2772418 bytes ->Java cache emptied: 13556966 bytes ->FireFox cache emptied: 90151106 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2142714 bytes %systemroot%\System32 .tmp files removed: 2577 bytes File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_790.dat scheduled to be deleted on reboot. Windows Temp folder emptied: 16384 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 180.57 mb OTM by OldTimer - Version 3.0.0.6 log created on 09022009_192245 Files moved on Reboot… C:\Documents and Settings\musical\Local Settings\Temp\~DF2A77.tmp moved successfully. File C:\WINDOWS\temp\_avast4_\Webshlock.txt not found! C:\WINDOWS\temp\Perflib_Perfdata_790.dat moved successfully. Registry entries deleted on Reboot…
Hi I have a question what are we supposed to do with these moved OTM files ? Here are the Attach.txt and DDsS logs Attach.txt UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-07-30.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 7/31/2009 2:00:54 PM System Uptime: 9/2/2009 8:46:58 PM (2 hours ago) Motherboard: Acer | | Dunlin Processor: Intel® Pentium® M processor 1.60GHz | uFCPGA | 1596/133mhz ==== Disk Partitions ========================= C: is FIXED (FAT32) - 19 GiB total, 14.006 GiB free. D: is FIXED (FAT32) - 19 GiB total, 4.688 GiB free. E: is FIXED (FAT32) - 19 GiB total, 7.798 GiB free. F: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP1: 8/30/2009 9:54:31 AM - System Checkpoint RP2: 8/31/2009 6:49:58 PM - System Checkpoint RP3: 9/1/2009 7:20:06 PM - System Checkpoint RP4: 9/2/2009 11:18:26 AM - Installed Java™ 6 Update 14 ==== Installed Programs ====================== Adobe Download Manager Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 6.0 Adobe Shockwave Player 11.5 Agere Systems AC'97 Modem Apple Software Update avast! Antivirus BitLord 1.1 Broadcom 440x 10/100 Integrated Controller Broadcom 802.11 Network Adapter CCleaner (remove only) DivX Web Player ERUNT 1.1j HijackThis 2.0.2 Intel® Graphics Media Accelerator Driver for Mobile Java™ 6 Update 14 LiveUpdate 1.6 (Symantec Corporation) Malwarebytes' Anti-Malware Mozilla Firefox (3.5.2) Norton AntiVirus Corporate Edition NTI DVD-Maker NTI DVD-Maker Gold NTI DVD Player QuickTime RealPlayer SpywareBlaster 4.2 SpywareGuard v2.2 VC80CRTRedist - 8.0.50727.762 VideoLAN VLC media player 0.8.6f WebFldrs XP WIDCOMM Bluetooth Software WinPatrol 2009 ==== Event Viewer Messages From Past Week ======== 9/2/2009 7:22:47 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). 9/2/2009 7:22:47 PM, error: Service Control Manager [7034] - The Broadcom Wireless LAN Tray Service service terminated unexpectedly. It has done this 1 time(s). 9/2/2009 11:03:21 AM, error: ipnathlp [32003] - The Network Address Translator (NAT) was unable to request an operation of the kernel-mode translation module. This may indicate misconfiguration, insufficient resources, or an internal error. The data is the error code. 8/30/2009 10:04:43 AM, error: Service Control Manager [7000] - The NAVAPEL service failed to start due to the following error: The system cannot find the file specified. 8/30/2009 10:00:01 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect. 8/29/2009 9:42:05 AM, error: Dhcp [1002] - The IP address lease 192.168.1.2 for the Network Card with network address 0012F0A6B935 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 8/28/2009 1:20:57 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the WZCSVC service. 8/27/2009 10:15:20 AM, error: Dhcp [1002] - The IP address lease 192.168.1.3 for the Network Card with network address 0012F0A6B935 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). ==== End Of File =========================== DDS LOG DDS (Ver_09-07-30.01) - FAT32x86 Run by [removed] at 22:48:30.25 on Wed 09/02/2009 Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_14 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1015.600 [GMT 5.5:30] AV: avast! antivirus 4.8.1351 [VPS 090901-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch SVCHOST.EXE C:\WINDOWS\system32\svchost.exe -k netsvcs SVCHOST.EXE SVCHOST.EXE C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\AGRSMMSG.exe C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\WLTRAY.exe C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\SpywareGuard\sgmain.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\SpywareGuard\sgbhp.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\musical\Desktop\dds.pif ============== Pseudo HJT Report =============== uStart Page = hxxp://www.imdb.com/ uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - d:\acrobat 6.0\reader\activex\AcroIEHelper.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - d:\realplayer11\rpbrowserrecordplugin.dll BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\program files\spywareguard\dlprotect.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [AGRSMMSG] AGRSMMSG.exe mRun: [SoundMan] SOUNDMAN.EXE mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY mRun: [QuickTime Task] "d:\quicktime7.62\qttask.exe" -atboottime mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" StartupFolder: c:\docume~1\musical\startm~1\programs\startup\spywar~1.lnk - c:\program files\spywareguard\sgmain.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\bttray.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe IE: Send To &Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {076169AA-8C3D-4CFC-AC23-3ACA88FC21B5} - hxxp://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://go.divx.com/plugin/DivXBrowserPlugin.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - c:\windows\system32\BTXPPanel.dll Notify: igfxcui - igfxsrvc.dll Notify: NavLogon - c:\windows\system32\NavLogon.dll SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\program files\spywareguard\spywareguard.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\musical\applic~1\mozilla\firefox\profiles\drlglawz.default\ FF - component: d:\realplayer11\browserrecord\components\nprpbrowserrecordplugin.dll FF - plugin: c:\documents and settings\musical\application data\mozilla\firefox\profiles\drlglawz.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll FF - plugin: d:\acrobat 6.0\reader\browser\nppdf32.dll FF - plugin: d:\quicktime7.62\plugins\npqtplugin.dll FF - plugin: d:\quicktime7.62\plugins\npqtplugin2.dll FF - plugin: d:\quicktime7.62\plugins\npqtplugin3.dll FF - plugin: d:\quicktime7.62\plugins\npqtplugin4.dll FF - plugin: d:\quicktime7.62\plugins\npqtplugin5.dll FF - plugin: d:\quicktime7.62\plugins\npqtplugin6.dll FF - plugin: d:\quicktime7.62\plugins\npqtplugin7.dll FF - plugin: d:\realplayer11\netscape6\nppl3260.dll FF - plugin: d:\realplayer11\netscape6\nprjplug.dll FF - plugin: d:\realplayer11\netscape6\nprpjplug.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-8-22 114768] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-8-22 20560] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-8-22 138680] R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-8-22 254040] R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-8-22 352920] S2 NAVAPEL;NAVAPEL;\??\c:\program files\navnt\navapel.sys –> c:\program files\navnt\NAVAPEL.SYS [?] S2 Norton AntiVirus Server;Norton AntiVirus Client;"c:\program files\navnt\rtvscan.exe" –> c:\program files\navnt\rtvscan.exe [?] S3 getPlusHelper;getPlus® Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2004-8-3 14336] S3 NAVAP;NAVAP;\??\c:\program files\navnt\navap.sys –> c:\program files\navnt\NAVAP.sys [?] S3 NAVENG;NAVENG;\??\c:\progra~1\common~1\symant~1\virusd~1\20090812.008\naveng.sys –> c:\progra~1\common~1\symant~1\virusd~1\20090812.008\NAVENG.sys [?] S3 NAVEX15;NAVEX15;\??\c:\progra~1\common~1\symant~1\virusd~1\20090812.008\navex15.sys –> c:\progra~1\common~1\symant~1\virusd~1\20090812.008\NAVEX15.sys [?] =============== Created Last 30 ================ 2009-09-02 19:25 –dsh— C:\Recycled 2009-09-02 19:22 –d—– C:\_OTM 2009-09-02 11:18 410,984 a——- c:\windows\system32\deploytk.dll 2009-09-02 11:18 73,728 a——- c:\windows\system32\javacpl.cpl 2009-08-30 10:05 –d—– c:\windows\system32\dllcache\cache 2009-08-30 09:59 a-dshr– C:\cmdcons 2009-08-30 09:54 229,376 a——- c:\windows\PEV.exe 2009-08-30 09:54 161,792 a——- c:\windows\SWREG.exe 2009-08-30 09:54 98,816 a——- c:\windows\sed.exe 2009-08-29 10:58 –d-h— c:\windows\PIF 2009-08-22 13:50 1,060,864 a——- c:\windows\system32\MFC71.dll 2009-08-20 15:07 –d—– c:\program files\SpywareGuard 2009-08-20 14:44 1,071,088 a——- c:\windows\system32\MSCOMCTL.OCX 2009-08-20 14:44 118,784 a——- c:\windows\system32\MSSTDFMT.DLL 2009-08-20 14:44 –d—– c:\program files\SpywareBlaster 2009-08-20 12:24 306,688 a——- c:\windows\IsUninst.exe 2009-08-20 02:03 –d—– c:\program files\Trend Micro 2009-08-19 21:43 –d—– c:\program files\CCleaner 2009-08-19 20:30 –d—– c:\docume~1\musical\applic~1\Malwarebytes 2009-08-19 20:30 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-19 20:30 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-08-19 20:30 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-08-19 20:30 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-08-19 19:53 –d—– c:\docume~1\musical\applic~1\WinPatrol 2009-08-19 19:53 –d—– c:\program files\BillP Studios 2009-08-17 13:23 –d—– c:\program files\common files\DivX Shared 2009-08-17 13:23 –d—– c:\program files\DivX 2009-08-15 03:14 25 a——- c:\windows\cdplayer.ini 2009-08-15 03:13 –d—– c:\program files\common files\xing shared 2009-08-15 03:13 –d—– c:\program files\common files\Real 2009-08-11 23:49 –d—– c:\program files\VideoLAN 2009-08-08 16:36 1,846,632 a——- c:\windows\system32\D3DCompiler_41.dll 2009-08-08 16:36 453,456 a——- c:\windows\system32\d3dx10_41.dll 2009-08-08 16:36 4,178,264 a——- c:\windows\system32\D3DX9_41.dll 2009-08-08 16:06 116 a——- c:\windows\NeroDigital.ini 2009-08-08 00:49 –d—– C:\Sun 2009-08-07 21:55 –d—– c:\windows\system32\Adobe ==================== Find3M ==================== 2009-08-15 03:13 499,712 a——- c:\windows\system32\msvcp71.dll 2009-08-15 03:13 348,160 a——- c:\windows\system32\msvcr71.dll 2009-08-10 20:16 12,464 a——- c:\windows\system32\drivers\secdrv.sys 2009-08-02 12:39 233,472 a——- c:\windows\system32\REX Shared Library.dll 2009-08-02 12:39 225,280 a——- c:\windows\system32\ReWire.dll 2009-08-01 01:49 6,912 a——- c:\windows\system32\drivers\NTIDrvr.sys 2009-07-31 17:05 17,801 a——- c:\windows\system32\drivers\AegisP.sys 2009-07-31 15:45 86,327 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2009-07-31 13:50 21,640 a——- c:\windows\system32\emptyregdb.dat ============= FINISH: 22:48:52.53 =============== SEE YOU!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI