This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Plzz help me with Root kit agent ODG , AGAIN

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Oh, I finished my scanning. Lost all the afternoon times.

I think there aren't infected files in my lap, right? I used some Keygens, cracks for softwares, and test some keylogger… etc… :D


MBAM LOG

Malwarebytes' Anti-Malware 1.40
Database version: 2665
Windows 6.0.6002 Service Pack 2

8/27/2009 11:34:10 AM
mbam-log-2009-08-27 (11-34-10).txt

Scan type: Quick Scan
Objects scanned: 86536
Time elapsed: 2 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
================================================================================
=======================

Kaspersky Log
——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Thursday, August 27, 2009
Operating system: Microsoft Windows Vista Ultimate Edition, 32-bit Service Pack 2 (build 6002)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Thursday, August 27, 2009 07:38:01
Records in database: 2691050
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\

Scan statistics:
Objects scanned: 228350
Threats found: 24
Infected objects found: 30
Suspicious objects found: 0
Scan duration: 03:27:47


File name / Threat / Threats count
E:\Setup\Internet - Network\Yahoo Messenger\Boot tool\D-O-Y_Error_v_1_.1 can 1 bot login.rar Infected: not-a-virus:RiskTool.Win32.VB.h 2
E:\Setup\Internet - Network\Yahoo Messenger\Boot tool\R.I.A.D_5.0.rar Infected: not-a-virus:RiskTool.Win32.VB.h 1
E:\Setup\Internet - Network\Yahoo Messenger\Boot tool\www.tina.vn_boom_nick_yahoo.zip Infected: not-a-virus:RiskTool.Win32.VB.h 1
E:\Setup\Mobile devices\N-70 ME\Games\MobileHeart.com-Mosquitos-1228-1124.zip Infected: Trojan.SymbOS.Mosquit.c 1
E:\Setup\Multimedia\Tools\Portable.Mp3Doctor.5.11.049 sua chua file nhac\Portable.Mp3Doctor.5.11.049.EXE Infected: Backdoor.Win32.IRCBot.lwc 1
E:\Setup\Security\Crack - Hack\Cracker toolkit.rar Infected: not-a-virus:Monitor.Win32.GoldenEye.401 1
E:\Setup\Security\Crack - Hack\Cracker toolkit.rar Infected: Trojan.Win32.Hooker.j 1
E:\Setup\Security\Crack - Hack\Cracker toolkit.rar Infected: Trojan-Spy.Win32.SpyAnyTime.a 1
E:\Setup\Security\Crack - Hack\ophcrack-livecd-1.2.1.iso Infected: not-a-virus:PSWTool.Win32.PWDump.2 1
E:\Setup\Security\Crack - Hack\ophcrack-livecd-1.2.1.iso Infected: not-a-virus:PSWTool.Win32.PWDump.s 1
E:\Setup\Security\Crack - Hack\ophcrack-livecd-1.2.1.iso Infected: not-a-virus:PSWTool.Win32.PWDump.d 2
E:\Setup\Security\Crack - Hack\Perfect keylogger\2003.rar Infected: Trojan-Spy.Win32.Perfloger.ag 1
E:\Setup\Security\Crack - Hack\Perfect keylogger\2003.rar Infected: not-a-virus:Monitor.Win32.Perflogger.az 2
E:\Setup\Security\Crack - Hack\Perfect keylogger\2003.rar Infected: Trojan-Spy.Win32.Perfloger.ab 1
E:\Setup\Security\Crack - Hack\Perfect keylogger\2003.rar Infected: not-a-virus:Monitor.Win32.Perflogger.by 1
E:\Setup\Security\Crack - Hack\Perfect keylogger\BPK 2007.rar Infected: not-a-virus:Monitor.Win32.Perflogger.ad 1
E:\Setup\Security\Crack - Hack\Perfect keylogger\BPK 2007.rar Infected: not-a-virus:Monitor.Win32.Perflogger.cl 1
E:\Setup\Security\Crack - Hack\Perfect keylogger\BPK 2007.rar Infected: not-a-virus:Monitor.Win32.Perflogger.ca 2
E:\Setup\Security\Crack - Hack\Perfect keylogger\BPK 2007.rar Infected: not-a-virus:Monitor.Win32.Perflogger.ct 1
E:\Setup\Security\Crack - Hack\Perfect keylogger\BPK 2007.rar Infected: not-a-virus:Monitor.Win32.Perflogger.cr 1
E:\Setup\Security\Crack - Hack\Perfect keylogger\BPK 2007.rar Infected: not-a-virus:Monitor.Win32.Perflogger.cb 1
E:\Setup\Security\Crack - Hack\tim-kiem-keygen.rar Infected: HackTool.Win32.CrackSearch.a 1
E:\Setup\Security\Crack - Hack\tim-kiem-keygen.rar Infected: not-a-virus:AdWare.Win32.Craagle.18 1
E:\Setup\Security\Crack - Hack\Toxic-Ps2.2 (trojan).zip Infected: Trojan-PSW.Win32.VB.fu 1
E:\Setup\Utilities\Recovery - Hirent Boot\picture doctor.zip Infected: Trojan-Downloader.Win32.Adload.gev 1
E:\Setup\Window's\Offices\Fonts va Bo go\Bo go tieng viet\(Unikey).zip Infected: Trojan.Win32.Genome.wod 1

Selected area has been scanned.

I used some Keygens, cracks for softwares, and test some keylogger… etc..


Cracks and keygens are always infected and are the surest way to turn your computer into a doorstop, which is what nearly happened this time.

It is also illegal and we do not condone such actions at WTT - please think about the consequences of such activity and change your practice. :(


NEXT


  • Please download OTM by OldTimer and save it to your desktop.
  • Double click the [external image: Posted Image] icon on your desktop.
  • Paste the following code under the [external image: Posted Image] area. Do not include the word "Code".
    :Processes
    explorer.exe
    
    :Files
    E:\Setup\Internet - Network\Yahoo Messenger\Boot tool\D-O-Y_Error_v_1_.1 can 1 bot login.rar 
    E:\Setup\Internet - Network\Yahoo Messenger\Boot tool\R.I.A.D_5.0.rar 
    E:\Setup\Internet - Network\Yahoo Messenger\Boot tool\www.tina.vn_boom_nick_yahoo.zip 
    E:\Setup\Mobile devices\N-70 ME\Games\MobileHeart.com-Mosquitos-1228-1124.zip
    E:\Setup\Multimedia\Tools\Portable.Mp3Doctor.5.11.049 sua chua file nhac\Portable.Mp3Doctor.5.11.049.EXE 
    E:\Setup\Security\Crack - Hack\Cracker toolkit.rar
    E:\Setup\Security\Crack - Hack\ophcrack-livecd-1.2.1.iso 
    E:\Setup\Security\Crack - Hack\Perfect keylogger\2003.rar 
    E:\Setup\Security\Crack - Hack\Perfect keylogger\BPK 2007.rar 
    E:\Setup\Security\Crack - Hack\tim-kiem-keygen.rar 
    E:\Setup\Security\Crack - Hack\Toxic-Ps2.2 (trojan).zip 
    E:\Setup\Utilities\Recovery - Hirent Boot\picture doctor.zip 
    E:\Setup\Window's\Offices\Fonts va Bo go\Bo go tieng viet\(Unikey).zip 
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Push the large [external image: Posted Image] button.
  • OTM may ask to reboot the machine. Please do so if asked.
  • Copy/Paste the contents under the [external image: Posted Image] line here in your next reply.
  • If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.


NEXT

Post a fresh DDS and Attach.txt and advise how your computer is running now and if you have any outstanding issues.
OTM LOG

All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== FILES ==========
E:\Setup\Internet - Network\Yahoo Messenger\Boot tool\D-O-Y_Error_v_1_.1 can 1 bot login.rar moved successfully.
E:\Setup\Internet - Network\Yahoo Messenger\Boot tool\R.I.A.D_5.0.rar moved successfully.
E:\Setup\Internet - Network\Yahoo Messenger\Boot tool\www.tina.vn_boom_nick_yahoo.zip moved successfully.
E:\Setup\Mobile devices\N-70 ME\Games\MobileHeart.com-Mosquitos-1228-1124.zip moved successfully.
E:\Setup\Multimedia\Tools\Portable.Mp3Doctor.5.11.049 sua chua file nhac\Portable.Mp3Doctor.5.11.049.EXE moved successfully.
E:\Setup\Security\Crack - Hack\Cracker toolkit.rar moved successfully.
E:\Setup\Security\Crack - Hack\Perfect keylogger\2003.rar moved successfully.
E:\Setup\Security\Crack - Hack\Perfect keylogger\BPK 2007.rar moved successfully.
E:\Setup\Security\Crack - Hack\tim-kiem-keygen.rar moved successfully.
E:\Setup\Security\Crack - Hack\Toxic-Ps2.2 (trojan).zip moved successfully.
E:\Setup\Utilities\Recovery - Hirent Boot\picture doctor.zip moved successfully.
E:\Setup\Window's\Offices\Fonts va Bo go\Bo go tieng viet\(Unikey).zip moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: o0 Virgo 0o
->Temp folder emptied: 78309946 bytes
->Temporary Internet Files folder emptied: 14125732 bytes
->Java cache emptied: 135751 bytes
->FireFox cache emptied: 73777699 bytes

User: Public
->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
Windows Temp folder emptied: 328106 bytes
RecycleBin emptied: 3563800 bytes

Total Files Cleaned = 162.35 mb


OTM by OldTimer - Version 3.0.0.6 log created on 08282009_030416

Files moved on Reboot…

Registry entries deleted on Reboot…

================================================================================
==============================

DDS LOG


DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 3:11:31.86 on Fri 08/28/2009
Internet Explorer: 8.0.6001.18813
Microsoft® Windows Vista™ Ultimate 6.0.6002.2.1252.1.1033.18.3068.1993 [GMT 7:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\STacSV.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\vfsFPService.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\SWSetup\DigitalPersona\Bin\DpHostW.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\SWSetup\DigitalPersona\Bin\DpAgent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_030ac640\aestsrv.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
D:\Install\ESET Smart Security 4\ekrn.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
D:\Install\Razer\Copperhead\razerhid.exe
C:\Program Files\Windows Sidebar\sidebar.exe
D:\Install\UniKey 4.0.8 Final\UniKey.exe
C:\Program Files\Windows Sidebar\sidebar.exe
D:\Install\Razer\Copperhead\razerofa.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
D:\Install\Malwarebytes' Anti-Malware\mbamservice.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Install\Internet Download Manager 5.17\IDMan.exe
D:\Install\Internet Download Manager 5.17\IEMonitor.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Users\o0 Virgo 0o\Desktop\dds.EXE

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com.vn/
BHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - d:\install\internet download manager 5.17\IDMIECC.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [UniKey] d:\install\unikey 4.0.8 final\UniKey.exe
mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [DpAgent] c:\swsetup\digitalpersona\bin\dpagent.exe
mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"
mRun: [OnScreenDisplay] c:\program files\hewlett-packard\hp quicktouch\HPKBDAPP.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_05\bin\jusched.exe"
mRun: [hpWirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [Copperhead] d:\install\razer\copperhead\razerhid.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download all links with IDM - d:\install\internet download manager 5.17\IEGetAll.htm
IE: Download FLV video content with IDM - d:\install\internet download manager 5.17\IEGetVL.htm
IE: Download with IDM - d:\install\internet download manager 5.17\IEExt.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device… - c:\swsetup\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\swsetup\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\swsetup\widcomm\bluetooth software\btsendto_ie.htm
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
TCP: {A0D5BE24-2A69-4825-B6B4-232AB7C22CE6} = 203.113.131.1,203.113.131.2
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
LSA: Notification Packages = scecli DPPWDFLT

================= FIREFOX ===================

FF - ProfilePath - c:\users\o0virg~1\appdata\roaming\mozilla\firefox\profiles\hbza7uts.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.vn/
FF - component: c:\users\o0 virgo 0o\appdata\roaming\idm\idmmzcc3\components\idmmzcc.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: d:\install\k-lite mega codec pack 5.05\real\browser\plugins\nppl3260.dll
FF - plugin: d:\install\k-lite mega codec pack 5.05\real\browser\plugins\nprpjplug.dll
FF - plugin: d:\install\picasa3\npPicasa3.dll

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-8-21 130936]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-2-6 106208]
R2 {22D78859-9CE9-4B77-BF18-AC83E81A9263};{22D78859-9CE9-4B77-BF18-AC83E81A9263};c:\program files\hp\quickplay\000.fcl [2009-8-20 39408]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_030ac640\AEstSrv.exe [2009-8-20 73728]
R2 ekrn;ESET Service;d:\install\eset smart security 4\ekrn.exe [2009-2-6 727720]
R2 epfwwfp;epfwwfp;c:\windows\system32\drivers\epfwwfp.sys [2009-2-6 38240]
R2 hpsrv;HP Service;c:\windows\system32\hpservice.exe [2008-3-19 19456]
R2 MBAMService;MBAMService;d:\install\malwarebytes' anti-malware\mbamservice.exe [2009-8-21 232720]
R2 vfsFPService;Validity Fingerprint Service;c:\windows\system32\vfsFPService.exe [2008-3-27 595248]
R3 AVerBDA6x;AVerBDA6x service;c:\windows\system32\drivers\AVerBDA716x.sys [2009-8-20 934912]
R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2009-8-20 193840]
R3 enecir;ENE CIR Receiver;c:\windows\system32\drivers\enecir.sys [2008-10-28 52736]
R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [2008-10-28 81296]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-8-21 19096]
R3 NETw5v32;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\system32\drivers\NETw5v32.sys [2008-10-28 3658752]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-10-28 43552]
R3 vfs101x;vfs101x;c:\windows\system32\drivers\vfs101x.sys [2008-3-27 40752]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [2006-11-2 9216]
S3 sdAuxService;PC Tools Auxiliary Service;d:\install\spyware doctor\pctsAuxs.exe [2009-8-21 348752]
S3 UsbFltr;Razer Copperhead Driver;c:\windows\system32\drivers\copperhd.sys [2009-8-21 11596]

=============== Created Last 30 ================

2009-08-28 03:04 –d—– C:\_OTM
2009-08-27 06:41 –dsh— C:\$RECYCLE.BIN
2009-08-25 18:07 229,376 a——- c:\windows\PEV.exe
2009-08-25 18:07 161,792 a——- c:\windows\SWREG.exe
2009-08-25 18:07 98,816 a——- c:\windows\sed.exe
2009-08-24 01:02 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-08-21 03:20 5,702 a—h— c:\windows\nod32restoretemdono.reg
2009-08-21 03:20 568 a—h— c:\windows\nod32fixtemdono.reg
2009-08-21 03:15 –d—– c:\users\o0virg~1\appdata\roaming\ESET
2009-08-21 03:14 –d—– c:\programdata\ESET
2009-08-21 01:09 –d—– c:\users\o0virg~1\appdata\roaming\Desktopicon
2009-08-21 00:52 –d—– c:\users\o0virg~1\appdata\roaming\Malwarebytes
2009-08-21 00:52 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-21 00:52 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-08-21 00:52 –d—– c:\programdata\Malwarebytes
2009-08-21 00:52 –d—– c:\progra~2\Malwarebytes
2009-08-21 00:34 51,355 a——- c:\windows\system32\muzika.xm
2009-08-21 00:29 159,600 a——- c:\windows\system32\drivers\pctgntdi.sys
2009-08-21 00:29 130,936 a——- c:\windows\system32\drivers\PCTCore.sys
2009-08-21 00:29 73,840 a——- c:\windows\system32\drivers\PCTAppEvent.sys
2009-08-21 00:28 64,392 a——- c:\windows\system32\drivers\pctplsg.sys
2009-08-21 00:28 –d—– c:\program files\common files\PC Tools
2009-08-21 00:28 –d—– c:\users\o0virg~1\appdata\roaming\PC Tools
2009-08-21 00:28 –d—– c:\programdata\PC Tools
2009-08-21 00:28 –d—– c:\progra~2\PC Tools
2009-08-21 00:09 14,592 a——- c:\windows\system32\drivers\USBICP.sys
2009-08-21 00:09 69,632 a——- c:\windows\system32\copperhd.cpl
2009-08-21 00:09 11,596 a——- c:\windows\system32\drivers\copperhd.sys
2009-08-20 23:58 –d—– c:\programdata\FLEXnet
2009-08-20 19:17 –d—– c:\users\o0 virgo 0o\Bluetooth Software
2009-08-20 19:17 80,936 a——- c:\windows\system32\drivers\btwavdt.sys
2009-08-20 19:17 80,424 a——- c:\windows\system32\drivers\btwaudio.sys
2009-08-20 19:17 16,168 a——- c:\windows\system32\drivers\btwrchid.sys
2009-08-20 19:17 233,472 a——- c:\windows\system32\BtwRSupport.dll
2009-08-20 19:17 –d—– c:\windows\system32\es-MX
2009-08-20 19:17 –d—– c:\windows\system32\es-AR
2009-08-20 19:15 12 a——- c:\windows\bthservsdp.dat
2009-08-20 19:12 –d—– c:\users\o0virg~1\appdata\roaming\DigitalPersona
2009-08-20 18:59 –d—– c:\programdata\CyberLink
2009-08-20 18:58 1,233,920 a——- c:\windows\system32\msxml4.dll
2009-08-20 18:58 82,432 a——- c:\windows\system32\msxml4r.dll
2009-08-20 18:58 44,544 a——- c:\windows\system32\msxml4a.dll
2009-08-20 18:58 1,060,864 ——– c:\windows\system32\MFC71.dll
2009-08-20 18:58 1,047,552 ——– c:\windows\system32\MFC71u.dll
2009-08-20 18:58 499,712 ——– c:\windows\system32\msvcp71.dll
2009-08-20 18:58 348,160 ——– c:\windows\system32\msvcr71.dll
2009-08-20 18:58 89,088 ——– c:\windows\system32\atl71.dll
2009-08-20 18:57 1,560,576 a——- c:\windows\system32\BttnCmns_64.dll
2009-08-20 18:57 1,560,576 a——- c:\windows\system32\BttnCmns.dll
2009-08-20 18:57 1,419,232 a——- c:\windows\system32\drivers\wdfcoinstaller01005.dll
2009-08-20 18:57 987,136 a——- c:\windows\system32\BttnCmn.dll
2009-08-20 18:57 16,768 a——- c:\windows\system32\drivers\HpqKbFiltr.sys
2009-08-20 18:57 –d—– c:\program files\common files\muvee Technologies
2009-08-20 18:56 –d—– c:\programdata\muvee Technologies
2009-08-20 18:53 –d—– c:\program files\HP
2009-08-20 18:52 –d—– c:\users\o0virg~1\appdata\roaming\Macrovision
2009-08-20 18:51 –d—– c:\windows\system32\tr
2009-08-20 18:51 –d—– c:\windows\system32\ru
2009-08-20 18:51 –d—– c:\windows\system32\ko
2009-08-20 18:51 –d—– c:\windows\system32\ja
2009-08-20 18:51 –d—– c:\windows\system32\it
2009-08-20 18:51 –d—– c:\windows\system32\fr
2009-08-20 18:51 –d—– c:\windows\system32\es
2009-08-20 18:51 –d—– c:\windows\system32\de
2009-08-20 18:51 –d—– c:\windows\DPDrv
2009-08-20 18:51 –d—– c:\programdata\Macrovision
2009-08-20 18:49 –d—– c:\programdata\NVIDIA
2009-08-20 18:49 28,409 a——- c:\programdata\nvModes.dat
2009-08-20 18:49 28,409 a——- c:\progra~2\nvModes.dat
2009-08-20 18:45 1,079,840 a——- c:\windows\system32\nvcpluir.dll
2009-08-20 18:45 768,544 a——- c:\windows\system32\nvcplui.exe
2009-08-20 18:45 420,384 a——- c:\windows\system32\nvcpl.cpl
2009-08-20 18:45 313,888 a——- c:\windows\system32\nvexpbar.dll
2009-08-20 18:45 446,464 a——- c:\windows\system32\NVUNINST.EXE
2009-08-20 18:45 934,912 a——- c:\windows\system32\drivers\AVerBDA716x.sys
2009-08-20 18:45 147,877 a——- c:\windows\system32\MV716x.ax
2009-08-20 18:45 3,072 a——- c:\windows\system32\716xCoInstaller.dll
2009-08-20 18:45 –d—– c:\windows\Driver Cache
2009-08-20 18:45 –d—– c:\program files\AVerMedia
2009-08-20 18:44 0 a—h— c:\windows\system32\drivers\Msft_Kernel_SynTP_01000.Wdf
2009-08-20 18:44 –d—– c:\program files\Synaptics
2009-08-20 18:44 –d—– c:\windows\system32\ENU
2009-08-20 18:44 1,034,776 a——- c:\windows\system32\imsmudlg.exe
2009-08-20 18:44 319,456 a——- c:\windows\system32\difxapi.dll
2009-08-20 18:44 –d—– c:\windows\system32\Lang
2009-08-20 18:44 312,344 a——- c:\windows\system32\drivers\iaStor.sys
2009-08-20 18:43 –d—– c:\windows\system32\HPMDP
2009-08-20 18:43 118,784 a——- c:\windows\system32\drivers\Rtlh86.sys
2009-08-20 18:43 –d—– c:\program files\Realtek
2009-08-20 18:43 54,824 ——– c:\windows\system32\agrsmdel.exe
2009-08-20 18:42 –d—– c:\windows\Options
2009-08-20 18:42 –d—– C:\SWSetup
2009-08-20 18:42 –d—– c:\users\o0virg~1\appdata\roaming\Hewlett Packard
2009-08-20 18:42 –d—– c:\program files\Validity Sensors, Inc
2009-08-20 18:42 –dsh— c:\windows\Installer
2009-08-20 18:41 251 a——- c:\windows\xUninstall.bat
2009-08-20 18:41 15,086 a——- c:\windows\system32\jmcr_xd.ico
2009-08-20 18:41 15,086 a——- c:\windows\system32\jmcr_ms.ico
2009-08-20 18:41 15,086 a——- c:\windows\system32\jmcr_mmc.ico
2009-08-20 18:41 –d—– c:\windows\JMCR_DIR
2009-08-20 18:40 53,248 a——- c:\windows\system32\CSVer.dll
2009-08-20 18:39 –d—– c:\program files\IDT
2009-08-20 07:58 –d—– c:\programdata\Adobe
2009-08-20 07:57 –d—– c:\program files\common files\Macrovision Shared
2009-08-20 07:06 –d—– c:\programdata\Yahoo!
2009-08-20 07:06 –d—– c:\program files\Yahoo!
2009-08-20 06:57 32,592 a——- c:\windows\system32\msonpmon.dll
2009-08-20 06:55 –d—– c:\windows\PCHEALTH
2009-08-20 06:50 –d—– c:\program files\Microsoft Visual Studio 8
2009-08-20 06:50 –d—– c:\programdata\Microsoft Help
2009-08-20 06:41 –d—– c:\users\o0virg~1\appdata\roaming\IDM
2009-08-20 06:41 –d—– c:\users\o0virg~1\appdata\roaming\DMCache
2009-08-20 06:38 –d—– c:\program files\common files\PX Storage Engine
2009-08-20 06:38 –d—– c:\windows\system32\IOSUBSYS
2009-08-20 06:26 –d—– c:\windows\Lhsp
2009-08-20 06:26 –d—– c:\programdata\InstallShield
2009-08-20 06:26 58,368 a——- c:\windows\system32\TCaptureX.dll
2009-08-20 06:26 385,100 a——- c:\windows\system32\Msvcrtd.dll
2009-08-20 06:26 98,304 a——- c:\windows\system32\TCapture.dll
2009-08-20 06:26 27,648 a——- c:\windows\system32\RL.dll
2009-08-20 06:26 7,168 a——- c:\windows\system32\TCCustom.dll
2009-08-20 06:15 –d—– c:\users\o0virg~1\appdata\roaming\MTD
2009-08-20 06:11 –d—– c:\program files\common files\MSSoap
2009-08-20 06:11 –d—– c:\program files\common files\L&H
2009-08-20 06:04 –d—– c:\users\o0virg~1\appdata\roaming\Foxit
2009-08-20 05:57 –d—– c:\program files\common files\EZB Systems
2009-08-20 05:47 1,638,912 a——- c:\windows\system32\mshtml.tlb
2009-08-20 05:37 a-d—– c:\programdata\TEMP
2009-08-20 05:37 –d—– c:\users\o0virg~1\appdata\roaming\URSoft
2009-08-16 10:55 –d—– c:\windows\system32\vi-VN
2009-08-16 10:55 –d—– c:\windows\system32\eu-ES
2009-08-16 10:55 –d—– c:\windows\system32\ca-ES
2009-08-16 10:52 –d—– c:\windows\system32\SPReview
2009-08-16 10:47 928,768 a——- c:\windows\system32\scavenge.dll
2009-08-16 10:46 57,856 a——- c:\windows\system32\compcln.exe
2009-08-16 10:43 3,408,896 a——- c:\windows\system32\SLsvc.exe
2009-08-16 10:41 –d—– c:\windows\system32\EventProviders
2009-08-16 10:25 –d—– c:\windows\Panther
2009-08-16 10:06 193,024 a——- c:\windows\system32\recdisc.exe
2009-08-16 10:06 6,656 a——- c:\windows\system32\sdspres.dll
2009-08-16 10:06 28,160 a——- c:\windows\system32\sxproxy.dll
2009-08-16 10:04 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-16 10:03 6,656 a——- c:\windows\system32\kbd106n.dll
2009-08-16 10:02 196,608 a——- c:\windows\SPInstall.etl
2009-08-16 09:41 –d—– c:\users\o0 Virgo 0o

==================== Find3M ====================

2009-08-21 03:14 143,360 a——- c:\windows\inf\infstrng.dat
2009-08-21 03:14 86,016 a——- c:\windows\inf\infstor.dat
2009-08-21 03:14 51,200 a——- c:\windows\inf\infpub.dat
2009-08-16 10:54 665,600 a——- c:\windows\inf\drvindex.dat
2009-08-16 10:31 174 a–sh— c:\program files\desktop.ini
2009-08-16 10:18 101,888 a——- c:\windows\system32\ifxcardm.dll
2009-08-16 10:18 82,432 a——- c:\windows\system32\axaltocm.dll
2009-07-22 04:52 915,456 a——- c:\windows\system32\wininet.dll
2009-07-22 04:47 109,056 a——- c:\windows\system32\iesysprep.dll
2009-07-22 04:47 71,680 a——- c:\windows\system32\iesetup.dll
2009-07-22 03:13 133,632 a——- c:\windows\system32\ieUnatt.exe
2009-06-02 23:11 85,504 a——- c:\windows\system32\ff_vfw.dll
2009-05-30 04:37 205,824 a——- c:\windows\system32\xvidvfw.dll
2009-05-30 04:31 881,664 a——- c:\windows\system32\xvidcore.dll
2006-11-02 19:40 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 19:40 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 19:40 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 19:40 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 16:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 16:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 16:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 16:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 3:11:52.71 ===============

================================================================================
==============================


Attack Log


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-07-30.01)

Microsoft® Windows Vista™ Ultimate
Boot Device: \Device\HarddiskVolume1
Install Date: 8/16/2009 9:35:35 AM
System Uptime: 8/28/2009 3:05:21 AM (0 hours ago)

Motherboard: Quanta | | 3603
Processor: Intel® Core™2 Duo CPU T9400 @ 2.53GHz | CPU | 2534/1066mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 80 GiB total, 60.171 GiB free.
D: is FIXED (NTFS) - 80 GiB total, 34.204 GiB free.
E: is FIXED (NTFS) - 128 GiB total, 34.885 GiB free.
F: is FIXED (NTFS) - 10 GiB total, 1.666 GiB free.
G: is CDROM ()
H: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

No restore point in system.

==== Installed Programs ======================

Adobe AIR
Adobe Anchor Service CS4
Adobe Bridge CS4
Adobe CMaps CS4
Adobe Color - Photoshop Specific CS4
Adobe Color EU Extra Settings CS4
Adobe Color JA Extra Settings CS4
Adobe Color NA Recommended Settings CS4
Adobe Color Video Profiles CS CS4
Adobe CSI CS4
Adobe Default Language CS4
Adobe Device Central CS4
Adobe Drive CS4
Adobe ExtendScript Toolkit CS4
Adobe Extension Manager CS4
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Fonts All
Adobe Linguistics CS4
Adobe Media Player
Adobe Output Module
Adobe PDF Library Files CS4
Adobe Photoshop CS4
Adobe Photoshop CS4 Support
Adobe Search for Help
Adobe Service Manager Extension
Adobe Setup
Adobe Shockwave Player
Adobe Type Support CS4
Adobe Update Manager CS4
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS4
AdobeColorCommonSetCMYK
AdobeColorCommonSetRGB
Agere Systems HDA Modem
AVerMedia MCE Encoder x86 [removed]
CCleaner (remove only)
Connect
CyberLink YouCam
DigitalPersona Personal 3.0.1
ESET Smart Security
Foxit Reader
Hewlett-Packard Active Check for Health Check
Hewlett-Packard Asset Agent for Health Check
HP Active Support Library
HP Help and Support
HP Integrated Module with Bluetooth wireless technology 6.0.1.6200
HP MiniCard Hybrid TV [removed]
HP MULTIPLE MODEM INSTALLER for VISTA
HP Quick Launch Buttons 6.40 H2
HP QuickPlay 3.7
HP QuickTouch 1.00 D2
HP Update
HP User Guides 0102
HP Wireless Assistant
HPNetworkAssistant
IDT Audio
Intel® Matrix Storage Manager
Internet Download Manager
Java™ 6 Update 5
Javidic 2008 Final
JMicron JMB38X Flash Media Controller
K-Lite Mega Codec Pack 5.0.5
kuler
L&H TTS3000 British English
L&H TTS3000 Japanese
Lac Viet mtd9 EVA
LacViet mtdCVH 2005
Malwarebytes' Anti-Malware
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (3.5.2)
muvee autoProducer 6.1
NOD32 v3.0.642 FiX1.2 by TemDono (31 days remaining forever up
NVIDIA Drivers
PDF Settings CS4
Photoshop Camera Raw
Picasa 3
ProDic 2007
ProtectSmart Hard Drive Protection
QuickPlay SlingPlayer 0.4.6
Razer Copperhead
Realtek 8169 8168 8101E 8102E Ethernet Driver
Spyware Doctor 6.1
Suite Shared Configuration CS4
Synaptics Pointing Device Driver
UltraISO Premium V9.33
Unlocker 1.8.7
Validity Sensors software
WinRAR archiver
Yahoo! Messenger
Your Uninstaller! 2008 Version 6.2

==== Event Viewer Messages From Past Week ========

8/28/2009 3:11:22 AM, Error: netbt [4321] - The name "WORKGROUP :1d" could not be registered on the interface with IP address 192.168.1.192. The computer with the IP address 192.168.1.100 did not allow the name to be claimed by this computer.
8/28/2009 3:07:27 AM, Error: Service Control Manager [7022] - The QuickPlay Task Scheduler (QTS) service hung on starting.
8/28/2009 3:07:20 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Eset Nod32 Boot service to connect.
8/28/2009 3:07:20 AM, Error: Service Control Manager [7000] - The Eset Nod32 Boot service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
8/28/2009 3:04:19 AM, Error: Service Control Manager [7034] - The MBAMService service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:19 AM, Error: Service Control Manager [7031] - The HP Health Check Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
8/28/2009 3:04:18 AM, Error: Service Control Manager [7034] - The QuickPlay Task Scheduler (QTS) service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:18 AM, Error: Service Control Manager [7034] - The hpqwmiex service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:18 AM, Error: Service Control Manager [7034] - The Com4QLBEx service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:17 AM, Error: Service Control Manager [7034] - The Validity Fingerprint Service service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:17 AM, Error: Service Control Manager [7034] - The QuickPlay Background Capture Service (QBCS) service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:17 AM, Error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:17 AM, Error: Service Control Manager [7034] - The Intel® Matrix Storage Event Monitor service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:17 AM, Error: Service Control Manager [7034] - The HP Service service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:17 AM, Error: Service Control Manager [7034] - The Biometric Authentication Service service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:17 AM, Error: Service Control Manager [7034] - The Audio Service service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:17 AM, Error: Service Control Manager [7034] - The Andrea ST Filters Service service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:17 AM, Error: Service Control Manager [7034] - The Agere Modem Call Progress Audio service terminated unexpectedly. It has done this 1 time(s).
8/28/2009 3:04:17 AM, Error: Service Control Manager [7031] - The ESET Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.
8/27/2009 7:40:34 AM, Error: Service Control Manager [7022] - The QuickPlay Background Capture Service (QBCS) service hung on starting.
8/27/2009 6:37:24 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the PEVSystemStart service to connect.
8/27/2009 6:37:22 AM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
8/27/2009 2:40:33 PM, Error: BROWSER [8020] - The browser was unable to promote itself to master browser. The computer that currently believes it is the master browser is unknown.
8/27/2009 11:39:35 AM, Error: BROWSER [8009] - The browser was unable to promote itself to master browser. The computer that currently believes it is the master browser is PC375266281045.
8/27/2009 1:22:57 PM, Error: BROWSER [8019] - The browser was unable to promote itself to master browser. The browser will continue to attempt to promote itself to the master browser, but will no longer log any events in the event log in Event Viewer.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD CSC DfsC ehdrv NetBIOS netbt nsiproxy PSched RasAcd rdbss Smb spldr tdx Wanarpv6
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The WebDav Client Redirector Driver service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The WebClient service depends on the WebDav Client Redirector Driver service which failed to start because of the following error: The dependency service or group failed to start.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service service which failed to start because of the following error: A device attached to the system is not functioning.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
8/26/2009 6:57:47 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
8/26/2009 6:57:26 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
8/26/2009 6:56:52 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
8/26/2009 6:56:52 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
8/26/2009 6:56:52 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF}
8/26/2009 6:56:50 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
8/26/2009 6:56:43 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
8/26/2009 3:50:03 AM, Error: EventLog [6008] - The previous system shutdown at 3:48:59 AM on 8/26/2009 was unexpected.
8/25/2009 10:32:07 AM, Error: EventLog [6008] - The previous system shutdown at 10:30:44 AM on 8/25/2009 was unexpected.
8/25/2009 10:26:44 AM, Error: EventLog [6008] - The previous system shutdown at 10:24:48 AM on 8/25/2009 was unexpected.
8/25/2009 10:11:20 AM, Error: Service Control Manager [7034] - The PC Tools Security Service service terminated unexpectedly. It has done this 1 time(s).
8/21/2009 3:14:06 AM, Error: Service Control Manager [7030] - The ESET Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
8/21/2009 2:23:13 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service sdrsvc with arguments "" in order to run the server: {47135EEA-06B6-4452-8787-4A187C64A47E}
8/21/2009 1:06:03 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: spldr Wanarpv6

==== End Of File ===========================
Hi,

You are clean,

just some housekeeping to do now

Please do the following:

Please download JavaRa to your desktop and unzip it to its own folder.
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
  • Scroll down to the Java SE Runtime Environment (JRE) option.
  • Download and install the latest Java Runtime Environment (JRE) version for your computer.(version 6, update 16)

NEXT


Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.


  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • For Firefox, I highly recommend this add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Oh, thanks for your hints and agree with those. Uhm, I tell you something about this. My ocpation relates computers, sometimes it is IT. So, I need to know a little about hack, crack, types of virus, trojan, malware… and things like that to prevent Computers of friends, colleagues, offices… and to know how to remove them. In reality, I download some above to test ( or practice, as you said :blush: ), and maybe try when I have free time. But, I almost haven't had time and conditions to practice or deep research. So, I just put them in Setup Folder :smack: Maybe, the infections at this time from WEB of Friend USBs. After this, I think I need 2 computers, one is clean for work, and one is for test. I can't concentrate on my work if my Lap isn't clean, therefor you don't know how I'm pleased and thankful for your help. :blush: :thumbup:
At last, these are what I want to say.

When I have a problems with harm softwares, I always find the way to Delete them with my own hands, sometimes with the help from the 4rum and Profesionnal or person who has experience about this. Up to this time, I believe that this is the best forum to help about Infections, and you are the best helper ( with me :woot: ) .

Once more, I want to say thank to you for what you help me. I also thank malware teams (person who assist in this 4rum), and special thank you, Catbyte. When I detected this Trojan, tried all the methods to kill and was disappointed, I knew you yourself is the person can help me at time I found out this 4rum, and saw your help the same problems of others, with the name catbytes.

I have learn some more about preventions and detections, and deletions from you. From now on, If I have a problem like this I can't solve, I come back here again to ask your help. Because I remember that name, :wub: Expert (######) Catbytes in What the Tech 4rum . :lol: :rofl: . You will help me, won't you ? :wub:

I Wish you well and every success, and continue your work in the 4rum. Thank you very much
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI