This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Tons of Viruses/Trojans Found -still infected? HELP

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My dad's computer has been infected with a virus/rootkit or trojan. Probably all 3. He immediatelly shut down the computer but it was too late. On subsequent boot, after loading into windows i noticed the following. A crapload of popups for a program called PC_Antispyware 2010 that tried to scan the computer, also braviax.exe was in my task manager. It wouldn't let me do anything so i ended the both processes. Then avast antivirus scan asked me to delete braviax.exe but couldn't so it said that i needed to do a Avast BootTime Scan so i went ahead and did that. Its currently running and so far its found the following. some of which i deleted and others which i moved to the chest. I need further assistance in making sure the computer is completely virus/malware free and rootkit free. First scan is complete but its running another one. so i'll update this with whatever else it finds. thanks for the help.

ALSO I'm using another computer to type this.

It found the following which i deleted!
2bti.exe - win32:rootkit-gen
DLLNC.dll - win32:Trojan-gen
KoPb.exe - Win32:trojan-gen
mshtml2.exe [UPX] - Win32-Agent-YTZ (TRJ)
msiexec.exe - Win32: Agent-VDE [TRJ]
c3w3clab/in[1].html - JS:Obfuscated-cv [trj]
C:/programfiles/pc_antispyware2010/wscui.cpl - win32

Found a couple files in my system restore folder which i moved to the chest or deleted

Found the following which i moved to chest(quarantine)
C:/windows/sytem32/000020.exe - win32:Trojan-gen
C:/Windows/system32/000090.exe - win32:crypt-CIL (TRJ)
C:Windows/system32/dllcache/beep.sys is infelected by Win32:FakeAV-No[Rtk]
C:Windows/system32/dllcache/figaro.sys is infelected by Win32:FakeAV-No[Rtk]
C:/windows/sytem32/imeshere.dIl is infected by win32:Trojan-gen

UPDATE: scan was complete, got back onto windows only for it to find another virus. Again Avast is making me run a bootTime Scan.There are two user privalages on the computer ( 1 being my account which is given full rights, and my fathers which is limited(thats where he got he virus using his account). Seems like both are infected though. Can someone please help. thank you.
————————————–

DDS RESULTS::: - had to run this under my account because it wouldn't let me do it under my fathers.



DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 15:27:31.10 on Wed 08/26/2009
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.446.75 [GMT -4:00]

AV: avast! antivirus 4.8.1351 [VPS 090826-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\PROGRA~1\FREEDO~1\fdm.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner.YOUR-642EF43EAF\My Documents\Computer Fix\dds.scr

============== Pseudo HJT Report ===============

uSearch Bar = hxxp://www.gateway.com/g/sidepanel.html?Ch=Retail&Br;=GTW&Loc;=ENG_US&Sys;=PTB&M;=MX6433
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&Br;=GTW&Loc;=ENG_US&Sys;=PTB&M;=MX6433
BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll
TB: {4E7BD74F-2B8D-469E-9FA5-A33DE8DBE931} - No File
TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [updateMgr] c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe AcRdB7_0_9
uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockw~1\SWHELP~1.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0; .NET CLR 2.0.50727; Media Center PC 2.8; FDM)" -"http://games2.gamesxl.com/03a3616a71e4ef8deed49732d104fce9/game.php?file=687474703a2f2f67616d6573322e67616d6573786c2e636f6d2f30336133363136613731653
465663864656564343937333264313034666365392f3332392e646372&width;=100%&height;=100%&gamesxl;=1&cr;=1&ovrprldr;=1&nobtn;=1"
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Reminder] %WINDIR%\Creator\Remind_XP.exe
mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY
mRun: [AdaptecDirectCD] c:\program files\adaptec\easy cd creator 5\directcd\DirectCD.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [ActiveSMART] c:\program files\active smart\\ActiveSMART.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
StartupFolder: c:\docume~1\savan\startm~1\programs\startup\hddlife.lnk - c:\program files\binarysense\hddlife 3\HDDlifeNB.exe
IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1176519432375
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: AtiExtEvent - Ati2evxx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\savan\applic~1\mozilla\firefox\profiles\5dlbpgce.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr;=megaup&p;=
FF - component: c:\documents and settings\savan\application data\mozilla\firefox\profiles\5dlbpgce.default\extensions\{0b457caa-602d-484a-8fe7-c1d894a011ba}\platform\winnt_x86-msvc\components\SSSLauncher.dll
FF - component: c:\program files\free download manager\firefox\extension\components\vmsfdmff.dll

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-4-5 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-4-5 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2007-9-29 138680]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2006-11-7 200576]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2007-9-29 254040]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2007-9-29 352920]

=============== Created Last 30 ================

2009-08-26 14:08 34,816 a——- c:\windows\system32\drivers\.sys
2009-08-26 10:29 17,130 a——- c:\windows\sygumetap.vbs
2009-08-26 10:29 16,666 a——- c:\docume~1\alluse~1\applic~1\yxokem.reg
2009-08-26 10:29 15,653 a——- c:\windows\foxifumes.inf
2009-08-26 10:29 14,566 a——- c:\windows\system32\uxyjagiwu.inf
2009-08-26 10:29 10,791 a——- c:\windows\system32\yjojymygy.dll
2009-08-26 10:29 10,631 a——- c:\windows\uxewi.dat
2009-08-26 10:29 10,015 a——- c:\windows\system32\ykegij.exe
2009-08-26 10:29 16,897 a——- c:\docume~1\alluse~1\applic~1\wuburowaf.com
2009-08-26 07:20 19,462 a——- c:\windows\ejuxyb.reg
2009-08-26 07:20 16,277 a——- c:\windows\system32\uhaketizub.sys
2009-08-26 07:20 13,258 a——- c:\docume~1\alluse~1\applic~1\vobacyl.vbs
2009-08-26 07:20 11,504 a——- c:\program files\common files\ukiku.vbs
2009-08-26 07:20 10,088 a——- c:\windows\yvalytuz.ban
2009-08-26 07:20 18,962 a——- c:\windows\system32\oraked.dl
2009-08-26 07:20 18,677 a——- c:\program files\common files\kecyg.vbs
2009-08-26 07:20 18,438 a——- c:\windows\ogahygosyr.sys
2009-08-26 07:20 18,171 a——- c:\windows\system32\uxohejisy.pif
2009-08-26 07:20 18,031 a——- c:\docume~1\alluse~1\applic~1\hujat.sys
2009-08-26 07:20 14,289 a——- c:\docume~1\alluse~1\applic~1\tyryxiheqa.bat
2009-08-26 07:20 10,845 a——- c:\program files\common files\dilomu.bat
2009-08-26 07:20 –d—– c:\program files\PC_Antispyware2010
2009-08-26 07:13 190,697 a——- c:\windows\system32\wisdstr.exe

==================== Find3M ====================

2009-08-26 10:29 12,993 a——- c:\program files\common files\noxytafo.ban
2009-08-26 07:20 14,530 a——- c:\program files\common files\ewicizo.lib
2009-06-17 12:43 34,688 a——- c:\docume~1\savan\applic~1\GDIPFONTCACHEV1.DAT
2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll
2009-06-03 15:09 1,291,264 a——- c:\windows\system32\quartz.dll
2008-06-13 16:12 187,904 —sh— c:\program files\common files\Yazzle1552OinAdmin.exe

============= FINISH: 15:28:22.75 ===============

Attachments:

Avast BOOT SCAN RESULTS
08/26/2009 10:32
Scan of all local drives

File C:\Documents and Settings\Owner.YOUR-642EF43EAF\Local Settings\Temp\2bti.exe is infected by Win32:Rootkit-gen [Rtk], Deleted
File C:\Documents and Settings\Owner.YOUR-642EF43EAF\Local Settings\Temp\DLLNC.dll is infected by Win32:Trojan-gen {Other}, Deleted
File C:\Documents and Settings\Owner.YOUR-642EF43EAF\Local Settings\Temp\KoPb.exe is infected by Win32:Trojan-gen {Other}, Deleted
File C:\Documents and Settings\Owner.YOUR-642EF43EAF\Local Settings\Temp\mshtml2.exe\[UPX] is infected by Win32:Agent-YTZ [Trj], Deleted
File C:\Documents and Settings\Owner.YOUR-642EF43EAF\Local Settings\Temp\msiexec.exe is infected by Win32:Agent-VDE [Trj], Deleted
File C:\Documents and Settings\Owner.YOUR-642EF43EAF\Local Settings\Temporary Internet Files\Content.IE5\C3W3CLAB\in[1].htm is infected by JS:Obfuscated-CV [Trj], Deleted
File C:\Program Files\PC_Antispyware2010\wscui.cpl is infected by Win32:Rootkit-gen [Rtk], Deleted
File C:\Program Files\Trend Micro\HijackThis\backups\backup-20080623-192845-562.dll is infected by Win32:Trojan-gen {Other}, Moved to chest
File C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP231\A0057118.cpl is infected by Win32:Rootkit-gen [Rtk], Moved to chest
File C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP231\A0057125.cpl is infected by Win32:Rootkit-gen [Rtk], Moved to chest
File C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP231\A0057126.dll is infected by Win32:Trojan-gen {Other}, Moved to chest
File C:\WINDOWS\system32\000070.exe is infected by Win32:Trojan-gen {Other}, Move to chest: Error 0xC0000034 {Object Name not found.}, Deleted
File C:\WINDOWS\system32\000090.exe is infected by Win32:Crypt-CIL [Trj], Moved to chest
File C:\WINDOWS\system32\dllcache\beep.sys is infected by Win32:FakeAV-NO [Rtk], Moved to chest
File C:\WINDOWS\system32\dllcache\figaro.sys is infected by Win32:FakeAV-NO [Rtk], Moved to chest
File C:\WINDOWS\system32\imeshere.dIl is infected by Win32:Trojan-gen {Other}, Moved to chest
Number of searched folders: 9551
Number of tested files: 118948
Number of infected files: 16

—————————————-
08/26/2009 12:27
Scan of all local drives

File C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP231\A0057127.exe is infected by Win32:Trojan-gen {Other}, Moved to chest
File C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP231\A0057128.exe is infected by Win32:Crypt-CIL [Trj], Moved to chest
File C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP231\A0057129.sys is infected by Win32:FakeAV-NO [Rtk], Moved to chest
File C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP231\A0057130.sys is infected by Win32:FakeAV-NO [Rtk], Moved to chest
Number of searched folders: 9551
Number of tested files: 118975
Number of infected files: 4
ROOT REPEAL RESULTS - I had to run this under my account as my fathers doesn't have adminstrator privalages? should i change this and allow him adminstrator pivalages? I can re-run if nesscary.

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/26 14:17
Program Version: Version 1.3.5.0
Windows Version: Windows XP Media Center Edition SP3
==================================================

Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF1C6E000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7BDA000 Size: 8192 File Visible: No Signed: -
Status: -

Name: PCI_NTPNP3188
Image Path: \Driver\PCI_NTPNP3188
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xEE8BA000 Size: 49152 File Visible: No Signed: -
Status: -

SSDT
——————-
#: 025 Function Name: NtClose
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf1cda6b8

#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf1cda574

#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf1cdaa52

#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf1cda14c

#: 071 Function Name: NtEnumerateKey
Status: Hooked by "sptd.sys" at address 0xf747be2c

#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "sptd.sys" at address 0xf747c1ba

#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf1cda64e

#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf1cda08c

#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf1cda0f0

#: 160 Function Name: NtQueryKey
Status: Hooked by "sptd.sys" at address 0xf747c292

#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf1cda76e

#: 204 Function Name: NtRestoreKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf1cda72e

#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\System32\Drivers\aswSP.SYS" at address 0xf1cda8ae

Stealth Objects
——————-
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x84d521e8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x84d521e8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x84d521e8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x84d521e8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x84d521e8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x84d521e8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x84d521e8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x84d521e8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x84d521e8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x84d521e8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x84d521e8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x84d521e8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x84d521e8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84d521e8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x84d521e8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x84d521e8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x84d521e8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x84d521e8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x84d521e8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x84d521e8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x84d521e8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x84d521e8 Size: 121

Object: Hidden Code [Driver: Fastfat, IRP_MJ_CREATE]
Process: System Address: 0x847063f8 Size: 121

Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLOSE]
Process: System Address: 0x847063f8 Size: 121

Object: Hidden Code [Driver: Fastfat, IRP_MJ_READ]
Process: System Address: 0x847063f8 Size: 121

Object: Hidden Code [Driver: Fastfat, IRP_MJ_WRITE]
Process: System Address: 0x847063f8 Size: 121

Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x847063f8 Size: 121

Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x847063f8 Size: 121

Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_EA]
Process: System Address: 0x847063f8 Size: 121

Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_EA]
Process: System Address: 0x847063f8 Size: 121

Object: Hidden Code [Driver: Fastfat, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x847063f8 Size: 121

Object: Hidden Code [Driver: Fastfat, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x847063f8 Size: 121

Object: Hidden Code [Driver: Fastfat, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x847063f8 Size: 121

Object: Hidden Code [Driver: Fastfat, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x847063f8 Size: 121

Object: Hidden Code [Driver: Fastfat, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x847063f8 Size: 121

Object: Hidden Code [Driver: Fastfat, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x847063f8 Size: 121

Object: Hidden Code [Driver: Fastfat, IRP_MJ_SHUTDOWN]
Process: System Address: 0x847063f8 Size: 121

Object: Hidden Code [Driver: Fastfat, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x847063f8 Size: 121

Object: Hidden Code [Driver: Fastfat, IRP_MJ_CLEANUP]
Process: System Address: 0x847063f8 Size: 121

Object: Hidden Code [Driver: Fastfat, IRP_MJ_PNP]
Process: System Address: 0x847063f8 Size: 121

Object: Hidden Code [Driver: Ql10wnt, IRP_MJ_CREATE]
Process: System Address: 0x84dd31e8 Size: 121

Object: Hidden Code [Driver: Ql10wnt, IRP_MJ_CLOSE]
Process: System Address: 0x84dd31e8 Size: 121

Object: Hidden Code [Driver: Ql10wnt, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84dd31e8 Size: 121

Object: Hidden Code [Driver: Ql10wnt, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84dd31e8 Size: 121

Object: Hidden Code [Driver: Ql10wnt, IRP_MJ_POWER]
Process: System Address: 0x84dd31e8 Size: 121

Object: Hidden Code [Driver: Ql10wnt, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84dd31e8 Size: 121

Object: Hidden Code [Driver: Ql10wnt, IRP_MJ_PNP]
Process: System Address: 0x84dd31e8 Size: 121

Object: Hidden Code [Driver: perc2, IRP_MJ_CREATE]
Process: System Address: 0x84d581e8 Size: 121

Object: Hidden Code [Driver: perc2, IRP_MJ_CLOSE]
Process: System Address: 0x84d581e8 Size: 121

Object: Hidden Code [Driver: perc2, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84d581e8 Size: 121

Object: Hidden Code [Driver: perc2, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84d581e8 Size: 121

Object: Hidden Code [Driver: perc2, IRP_MJ_POWER]
Process: System Address: 0x84d581e8 Size: 121

Object: Hidden Code [Driver: perc2, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84d581e8 Size: 121

Object: Hidden Code [Driver: perc2, IRP_MJ_PNP]
Process: System Address: 0x84d581e8 Size: 121

Object: Hidden Code [Driver: cbidf, IRP_MJ_CREATE]
Process: System Address: 0x84d551e8 Size: 121

Object: Hidden Code [Driver: cbidf, IRP_MJ_CLOSE]
Process: System Address: 0x84d551e8 Size: 121

Object: Hidden Code [Driver: cbidf, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84d551e8 Size: 121

Object: Hidden Code [Driver: cbidf, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84d551e8 Size: 121

Object: Hidden Code [Driver: cbidf, IRP_MJ_POWER]
Process: System Address: 0x84d551e8 Size: 121

Object: Hidden Code [Driver: cbidf, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84d551e8 Size: 121

Object: Hidden Code [Driver: cbidf, IRP_MJ_PNP]
Process: System Address: 0x84d551e8 Size: 121

Object: Hidden Code [Driver: ini910u, IRP_MJ_CREATE]
Process: System Address: 0x84dd01e8 Size: 121

Object: Hidden Code [Driver: ini910u, IRP_MJ_CLOSE]
Process: System Address: 0x84dd01e8 Size: 121

Object: Hidden Code [Driver: ini910u, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84dd01e8 Size: 121

Object: Hidden Code [Driver: ini910u, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84dd01e8 Size: 121

Object: Hidden Code [Driver: ini910u, IRP_MJ_POWER]
Process: System Address: 0x84dd01e8 Size: 121

Object: Hidden Code [Driver: ini910u, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84dd01e8 Size: 121

Object: Hidden Code [Driver: ini910u, IRP_MJ_PNP]
Process: System Address: 0x84dd01e8 Size: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x84b1c1e8 Size: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x84b1c1e8 Size: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x84b1c1e8 Size: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x84b1c1e8 Size: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x84b1c1e8 Size: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84b1c1e8 Size: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84b1c1e8 Size: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x84b1c1e8 Size: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x84b1c1e8 Size: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84b1c1e8 Size: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x84b1c1e8 Size: 121

Object: Hidden Code [Driver: asc, IRP_MJ_CREATE]
Process: System Address: 0x84dd21e8 Size: 121

Object: Hidden Code [Driver: asc, IRP_MJ_CLOSE]
Process: System Address: 0x84dd21e8 Size: 121

Object: Hidden Code [Driver: asc, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84dd21e8 Size: 121

Object: Hidden Code [Driver: asc, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84dd21e8 Size: 121

Object: Hidden Code [Driver: asc, IRP_MJ_POWER]
Process: System Address: 0x84dd21e8 Size: 121

Object: Hidden Code [Driver: asc, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84dd21e8 Size: 121

Object: Hidden Code [Driver: asc, IRP_MJ_PNP]
Process: System Address: 0x84dd21e8 Size: 121

Object: Hidden Code [Driver: ql1280, IRP_MJ_CREATE]
Process: System Address: 0x84d5a1e8 Size: 121

Object: Hidden Code [Driver: ql1280, IRP_MJ_CLOSE]
Process: System Address: 0x84d5a1e8 Size: 121

Object: Hidden Code [Driver: ql1280, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84d5a1e8 Size: 121

Object: Hidden Code [Driver: ql1280, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84d5a1e8 Size: 121

Object: Hidden Code [Driver: ql1280, IRP_MJ_POWER]
Process: System Address: 0x84d5a1e8 Size: 121

Object: Hidden Code [Driver: ql1280, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84d5a1e8 Size: 121

Object: Hidden Code [Driver: ql1280, IRP_MJ_PNP]
Process: System Address: 0x84d5a1e8 Size: 121

Object: Hidden Code [Driver: asc3350p, IRP_MJ_CREATE]
Process: System Address: 0x84dcc1e8 Size: 121

Object: Hidden Code [Driver: asc3350p, IRP_MJ_CLOSE]
Process: System Address: 0x84dcc1e8 Size: 121

Object: Hidden Code [Driver: asc3350p, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84dcc1e8 Size: 121

Object: Hidden Code [Driver: asc3350p, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84dcc1e8 Size: 121

Object: Hidden Code [Driver: asc3350p, IRP_MJ_POWER]
Process: System Address: 0x84dcc1e8 Size: 121

Object: Hidden Code [Driver: asc3350p, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84dcc1e8 Size: 121

Object: Hidden Code [Driver: asc3350p, IRP_MJ_PNP]
Process: System Address: 0x84dcc1e8 Size: 121

Object: Hidden Code [Driver: mraid35x, IRP_MJ_CREATE]
Process: System Address: 0x84dd11e8 Size: 121

Object: Hidden Code [Driver: mraid35x, IRP_MJ_CLOSE]
Process: System Address: 0x84dd11e8 Size: 121

Object: Hidden Code [Driver: mraid35x, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84dd11e8 Size: 121

Object: Hidden Code [Driver: mraid35x, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84dd11e8 Size: 121

Object: Hidden Code [Driver: mraid35x, IRP_MJ_POWER]
Process: System Address: 0x84dd11e8 Size: 121

Object: Hidden Code [Driver: mraid35x, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84dd11e8 Size: 121

Object: Hidden Code [Driver: mraid35x, IRP_MJ_PNP]
Process: System Address: 0x84dd11e8 Size: 121

Object: Hidden Code [Driver: cd20xrnt, IRP_MJ_CREATE]
Process: System Address: 0x84dcb1e8 Size: 121

Object: Hidden Code [Driver: cd20xrnt, IRP_MJ_CLOSE]
Process: System Address: 0x84dcb1e8 Size: 121

Object: Hidden Code [Driver: cd20xrnt, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84dcb1e8 Size: 121

Object: Hidden Code [Driver: cd20xrnt, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84dcb1e8 Size: 121

Object: Hidden Code [Driver: cd20xrnt, IRP_MJ_POWER]
Process: System Address: 0x84dcb1e8 Size: 121

Object: Hidden Code [Driver: cd20xrnt, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84dcb1e8 Size: 121

Object: Hidden Code [Driver: cd20xrnt, IRP_MJ_PNP]
Process: System Address: 0x84dcb1e8 Size: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]
Process: System Address: 0x84dd71e8 Size: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]
Process: System Address: 0x84dd71e8 Size: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_READ]
Process: System Address: 0x84dd71e8 Size: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]
Process: System Address: 0x84dd71e8 Size: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x84dd71e8 Size: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84dd71e8 Size: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84dd71e8 Size: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]
Process: System Address: 0x84dd71e8 Size: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]
Process: System Address: 0x84dd71e8 Size: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84dd71e8 Size: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]
Process: System Address: 0x84dd71e8 Size: 121

Object: Hidden Code [Driver: symc8xx, IRP_MJ_CREATE]
Process: System Address: 0x84d5f1e8 Size: 121

Object: Hidden Code [Driver: symc8xx, IRP_MJ_CLOSE]
Process: System Address: 0x84d5f1e8 Size: 121

Object: Hidden Code [Driver: symc8xx, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84d5f1e8 Size: 121

Object: Hidden Code [Driver: symc8xx, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84d5f1e8 Size: 121

Object: Hidden Code [Driver: symc8xx, IRP_MJ_POWER]
Process: System Address: 0x84d5f1e8 Size: 121

Object: Hidden Code [Driver: symc8xx, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84d5f1e8 Size: 121

Object: Hidden Code [Driver: symc8xx, IRP_MJ_PNP]
Process: System Address: 0x84d5f1e8 Size: 121

Object: Hidden Code [Driver: usbohci, IRP_MJ_CREATE]
Process: System Address: 0x84c141e8 Size: 121

Object: Hidden Code [Driver: usbohci, IRP_MJ_CLOSE]
Process: System Address: 0x84c141e8 Size: 121

Object: Hidden Code [Driver: usbohci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84c141e8 Size: 121

Object: Hidden Code [Driver: usbohci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84c141e8 Size: 121

Object: Hidden Code [Driver: usbohci, IRP_MJ_POWER]
Process: System Address: 0x84c141e8 Size: 121

Object: Hidden Code [Driver: usbohci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84c141e8 Size: 121

Object: Hidden Code [Driver: usbohci, IRP_MJ_PNP]
Process: System Address: 0x84c141e8 Size: 121

Object: Hidden Code [Driver: Sys, IRP_MJ_CREATE]
Process: System Address: 0xe1d16140 Size: 2858

Object: Hidden Code [Driver: Sys, IRP_MJ_CLOSE]
Process: System Address: 0xe1d16140 Size: 2858

Object: Hidden Code [Driver: Sys, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0xe1d16140 Size: 2858

Object: Hidden Code [Driver: ultra, IRP_MJ_CREATE]
Process: System Address: 0x84dca1e8 Size: 121

Object: Hidden Code [Driver: ultra, IRP_MJ_CLOSE]
Process: System Address: 0x84dca1e8 Size: 121

Object: Hidden Code [Driver: ultra, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84dca1e8 Size: 121

Object: Hidden Code [Driver: ultra, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84dca1e8 Size: 121

Object: Hidden Code [Driver: ultra, IRP_MJ_POWER]
Process: System Address: 0x84dca1e8 Size: 121

Object: Hidden Code [Driver: ultra, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84dca1e8 Size: 121

Object: Hidden Code [Driver: ultra, IRP_MJ_PNP]
Process: System Address: 0x84dca1e8 Size: 121

Object: Hidden Code [Driver: dac960nt, IRP_MJ_CREATE]
Process: System Address: 0x84d641e8 Size: 121

Object: Hidden Code [Driver: dac960nt, IRP_MJ_CLOSE]
Process: System Address: 0x84d641e8 Size: 121

Object: Hidden Code [Driver: dac960nt, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84d641e8 Size: 121

Object: Hidden Code [Driver: dac960nt, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84d641e8 Size: 121

Object: Hidden Code [Driver: dac960nt, IRP_MJ_POWER]
Process: System Address: 0x84d641e8 Size: 121

Object: Hidden Code [Driver: dac960nt, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84d641e8 Size: 121

Object: Hidden Code [Driver: dac960nt, IRP_MJ_PNP]
Process: System Address: 0x84d641e8 Size: 121

Object: Hidden Code [Driver: aic78u2, IRP_MJ_CREATE]
Process: System Address: 0x84dcf1e8 Size: 121

Object: Hidden Code [Driver: aic78u2, IRP_MJ_CLOSE]
Process: System Address: 0x84dcf1e8 Size: 121

Object: Hidden Code [Driver: aic78u2, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84dcf1e8 Size: 121

Object: Hidden Code [Driver: aic78u2, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84dcf1e8 Size: 121

Object: Hidden Code [Driver: aic78u2, IRP_MJ_POWER]
Process: System Address: 0x84dcf1e8 Size: 121

Object: Hidden Code [Driver: aic78u2, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84dcf1e8 Size: 121

Object: Hidden Code [Driver: aic78u2, IRP_MJ_PNP]
Process: System Address: 0x84dcf1e8 Size: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x84d681e8 Size: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x84d681e8 Size: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x84d681e8 Size: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x84d681e8 Size: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84d681e8 Size: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84d681e8 Size: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x84d681e8 Size: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x84d681e8 Size: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x84d681e8 Size: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84d681e8 Size: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x84d681e8 Size: 121

Object: Hidden Code [Driver: adpu160m, IRP_MJ_CREATE]
Process: System Address: 0x84d5d1e8 Size: 121

Object: Hidden Code [Driver: adpu160m, IRP_MJ_CLOSE]
Process: System Address: 0x84d5d1e8 Size: 121

Object: Hidden Code [Driver: adpu160m, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84d5d1e8 Size: 121

Object: Hidden Code [Driver: adpu160m, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84d5d1e8 Size: 121

Object: Hidden Code [Driver: adpu160m, IRP_MJ_POWER]
Process: System Address: 0x84d5d1e8 Size: 121

Object: Hidden Code [Driver: adpu160m, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84d5d1e8 Size: 121

Object: Hidden Code [Driver: adpu160m, IRP_MJ_PNP]
Process: System Address: 0x84d5d1e8 Size: 121

Object: Hidden Code [Driver: sym_u3, IRP_MJ_CREATE]
Process: System Address: 0x84d5e1e8 Size: 121

Object: Hidden Code [Driver: sym_u3, IRP_MJ_CLOSE]
Process: System Address: 0x84d5e1e8 Size: 121

Object: Hidden Code [Driver: sym_u3, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84d5e1e8 Size: 121

Object: Hidden Code [Driver: sym_u3, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84d5e1e8 Size: 121

Object: Hidden Code [Driver: sym_u3, IRP_MJ_POWER]
Process: System Address: 0x84d5e1e8 Size: 121

Object: Hidden Code [Driver: sym_u3, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84d5e1e8 Size: 121

Object: Hidden Code [Driver: sym_u3, IRP_MJ_PNP]
Process: System Address: 0x84d5e1e8 Size: 121

Object: Hidden Code [Driver: abp480n5, IRP_MJ_CREATE]
Process: System Address: 0x84dcd1e8 Size: 121

Object: Hidden Code [Driver: abp480n5, IRP_MJ_CLOSE]
Process: System Address: 0x84dcd1e8 Size: 121

Object: Hidden Code [Driver: abp480n5, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84dcd1e8 Size: 121

Object: Hidden Code [Driver: abp480n5, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84dcd1e8 Size: 121

Object: Hidden Code [Driver: abp480n5, IRP_MJ_POWER]
Process: System Address: 0x84dcd1e8 Size: 121

Object: Hidden Code [Driver: abp480n5, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84dcd1e8 Size: 121

Object: Hidden Code [Driver: abp480n5, IRP_MJ_PNP]
Process: System Address: 0x84dcd1e8 Size: 121

Object: Hidden Code [Driver: ql1080, IRP_MJ_CREATE]
Process: System Address: 0x84d5b1e8 Size: 121

Object: Hidden Code [Driver: ql1080, IRP_MJ_CLOSE]
Process: System Address: 0x84d5b1e8 Size: 121

Object: Hidden Code [Driver: ql1080, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84d5b1e8 Size: 121

Object: Hidden Code [Driver: ql1080, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84d5b1e8 Size: 121

Object: Hidden Code [Driver: ql1080, IRP_MJ_POWER]
Process: System Address: 0x84d5b1e8 Size: 121

Object: Hidden Code [Driver: ql1080, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84d5b1e8 Size: 121

Object: Hidden Code [Driver: ql1080, IRP_MJ_PNP]
Process: System Address: 0x84d5b1e8 Size: 121

Object: Hidden Code [Driver: prohlp02, IRP_MJ_CREATE]
Process: System Address: 0xe188a4f8 Size: 2169

Object: Hidden Code [Driver: prohlp02, IRP_MJ_CLOSE]
Process: System Address: 0xe188a4f8 Size: 2169

Object: Hidden Code [Driver: prohlp02, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0xe188a4f8 Size: 2169

Object: Hidden Code [Driver: symc810, IRP_MJ_CREATE]
Process: System Address: 0x84d651e8 Size: 121

Object: Hidden Code [Driver: symc810, IRP_MJ_CLOSE]
Process: System Address: 0x84d651e8 Size: 121

Object: Hidden Code [Driver: symc810, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84d651e8 Size: 121

Object: Hidden Code [Driver: symc810, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84d651e8 Size: 121

Object: Hidden Code [Driver: symc810, IRP_MJ_POWER]
Process: System Address: 0x84d651e8 Size: 121

Object: Hidden Code [Driver: symc810, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84d651e8 Size: 121

Object: Hidden Code [Driver: symc810, IRP_MJ_PNP]
Process: System Address: 0x84d651e8 Size: 121

Object: Hidden Code [Driver: hpn, IRP_MJ_CREATE]
Process: System Address: 0x84d561e8 Size: 121

Object: Hidden Code [Driver: hpn, IRP_MJ_CLOSE]
Process: System Address: 0x84d561e8 Size: 121

Object: Hidden Code [Driver: hpn, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84d561e8 Size: 121

Object: Hidden Code [Driver: hpn, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84d561e8 Size: 121

Object: Hidden Code [Driver: hpn, IRP_MJ_POWER]
Process: System Address: 0x84d561e8 Size: 121

Object: Hidden Code [Driver: hpn, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84d561e8 Size: 121

Object: Hidden Code [Driver: hpn, IRP_MJ_PNP]
Process: System Address: 0x84d561e8 Size: 121

Object: Hidden Code [Driver: ql12160, IRP_MJ_CREATE]
Process: System Address: 0x84d591e8 Size: 121

Object: Hidden Code [Driver: ql12160, IRP_MJ_CLOSE]
Process: System Address: 0x84d591e8 Size: 121

Object: Hidden Code [Driver: ql12160, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84d591e8 Size: 121

Object: Hidden Code [Driver: ql12160, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84d591e8 Size: 121

Object: Hidden Code [Driver: ql12160, IRP_MJ_POWER]
Process: System Address: 0x84d591e8 Size: 121

Object: Hidden Code [Driver: ql12160, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84d591e8 Size: 121

Object: Hidden Code [Driver: ql12160, IRP_MJ_PNP]
Process: System Address: 0x84d591e8 Size: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x8494f1e8 Size: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x8494f1e8 Size: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8494f1e8 Size: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8494f1e8 Size: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x8494f1e8 Size: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x8494f1e8 Size: 121

Object: Hidden Code [Driver: aic78xx, IRP_MJ_CREATE]
Process: System Address: 0x84dd41e8 Size: 121

Object: Hidden Code [Driver: aic78xx, IRP_MJ_CLOSE]
Process: System Address: 0x84dd41e8 Size: 121

Object: Hidden Code [Driver: aic78xx, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84dd41e8 Size: 121

Object: Hidden Code [Driver: aic78xx, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84dd41e8 Size: 121

Object: Hidden Code [Driver: aic78xx, IRP_MJ_POWER]
Process: System Address: 0x84dd41e8 Size: 121

Object: Hidden Code [Driver: aic78xx, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84dd41e8 Size: 121

Object: Hidden Code [Driver: aic78xx, IRP_MJ_PNP]
Process: System Address: 0x84dd41e8 Size: 121

Object: Hidden Code [Driver: amsint, IRP_MJ_CREATE]
Process: System Address: 0x84d631e8 Size: 121

Object: Hidden Code [Driver: amsint, IRP_MJ_CLOSE]
Process: System Address: 0x84d631e8 Size: 121

Object: Hidden Code [Driver: amsint, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84d631e8 Size: 121

Object: Hidden Code [Driver: amsint, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84d631e8 Size: 121

Object: Hidden Code [Driver: amsint, IRP_MJ_POWER]
Process: System Address: 0x84d631e8 Size: 121

Object: Hidden Code [Driver: amsint, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84d631e8 Size: 121

Object: Hidden Code [Driver: amsint, IRP_MJ_PNP]
Process: System Address: 0x84d631e8 Size: 121

Object: Hidden Code [Driver: dac2w2k, IRP_MJ_CREATE]
Process: System Address: 0x84d541e8 Size: 121

Object: Hidden Code [Driver: dac2w2k, IRP_MJ_CLOSE]
Process: System Address: 0x84d541e8 Size: 121

Object: Hidden Code [Driver: dac2w2k, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84d541e8 Size: 121

Object: Hidden Code [Driver: dac2w2k, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84d541e8 Size: 121

Object: Hidden Code [Driver: dac2w2k, IRP_MJ_POWER]
Process: System Address: 0x84d541e8 Size: 121

Object: Hidden Code [Driver: dac2w2k, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84d541e8 Size: 121

Object: Hidden Code [Driver: dac2w2k, IRP_MJ_PNP]
Process: System Address: 0x84d541e8 Size: 121

Object: Hidden Code [Driver: Sparrow, IRP_MJ_CREATE]
Process: System Address: 0x84dd51e8 Size: 121

Object: Hidden Code [Driver: Sparrow, IRP_MJ_CLOSE]
Process: System Address: 0x84dd51e8 Size: 121

Object: Hidden Code [Driver: Sparrow, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x84dd51e8 Size: 121

Object: Hidden Code [Driver: Sparrow, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x84dd51e8 Size: 121

Object: Hidden Code [Driver: Sparrow, IRP_MJ_POWER]
Process: System Address: 0x84dd51e8 Size: 121

Object: Hidden Code [Driver: Sparrow, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x84dd51e8 Size: 121

Object: Hidden Code [Driver: Sparrow, IRP_MJ_PNP]
Process: System Address: 0x84dd51e8 ==EOF==
HIJACK THIS LOG:

MY FATHERS ACCOUNT HAS THE BRAVIAX.EXE in Start=UP

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:55:18 PM, on 8/26/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…TB&M=MX6433
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/first_usage&s=bT…n-38BKeOSDMfvy0
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ActiveSMART] C:\Program Files\Active SMART\\ActiveSMART.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [braviax] C:\WINDOWS\system32\braviax.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] "C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE" -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0; .NET CLR 2.0.50727; Media Center PC 2.8; FDM)" -"http://www.chitralekha.com/"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1176519432375
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

–
End of file - 4414 bytes
————————————————————-

my ACCOUNT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:24:14 PM, on 8/26/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.gateway.com/g/sidepanel.html?Ch…TB&M=MX6433
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…TB&M=MX6433
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ActiveSMART] C:\Program Files\Active SMART\\ActiveSMART.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0; .NET CLR 2.0.50727; Media Center PC 2.8; FDM)" -"http://games2.gamesxl.com/03a3616a71e4ef8deed49732d104fce9/game.php?file=687474703a2f2f67616d6573322e67616d6573786c2e636f6d2f30336133363136613731653
465663864656564343937333264313034666365392f3332392e646372&width=100%&height=100%&gamesxl=1&cr=1&ovrprldr=1&nobtn=1"
O4 - Startup: HDDlife.lnk = C:\Program Files\BinarySense\HDDlife 3\HDDlifeNB.exe
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1176519432375
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

–
End of file - 5980 bytes
Hi,

Please do the following (run in your account - it wont make a difference )

Please save this file to your desktop.

Now click on Start->Run, and copy/paste the following command (the text inside the quotebox) into the "Open" runbox, and click OK.


"%userprofile%\desktop\win32kdiag.exe" -f -r


When it's finished, there will be a log called Win32kDiag.txt on your desktop.

Please open it with notepad and post the contents here.


NEXT

Download Combofix from either of the links below. You must rename it before saving it. Save it to your desktop.

Link 2
Link 3

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–

Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt back into this thread.
The following is the Win32kDiag.txt Log file is located at: C:\Documents and Settings\Savan\Desktop\Win32kDiag.txt Removing all found mount points. Attempting to reset file permissions. WARNING: Could not get backup privileges! Searching 'C:\WINDOWS'… Finished!
Combo-Fix Log, seems like it got rid of a lot of stuff… Thanks for the help. Can you let me know what i should do next?
—————————–
ComboFix 09-08-27.01 - Savan 08/27/2009 12:35.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.446.78 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: avast! antivirus 4.8.1351 [VPS 090826-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\hujat.sys
c:\documents and settings\All Users\Application Data\ikukocetih._sy
c:\documents and settings\All Users\Application Data\tyryxiheqa.bat
c:\documents and settings\All Users\Application Data\vobacyl.vbs
c:\documents and settings\All Users\Application Data\wuburowaf.com
c:\documents and settings\All Users\Application Data\yxokem.reg
c:\documents and settings\All Users\Documents\alijetoxo.sys
c:\documents and settings\All Users\Documents\bujehu.bin
c:\documents and settings\All Users\Documents\ewob.dl
c:\documents and settings\Owner.YOUR-642EF43EAF\Application Data\eber.sys
c:\documents and settings\Owner.YOUR-642EF43EAF\Application Data\gowun.dll
c:\documents and settings\Owner.YOUR-642EF43EAF\Application Data\ripex._sy
c:\documents and settings\Owner.YOUR-642EF43EAF\Local Settings\Application Data\ohanuvyne.reg
c:\documents and settings\Owner.YOUR-642EF43EAF\Local Settings\Application Data\ykukofed.ban
c:\documents and settings\Owner.YOUR-642EF43EAF\Local Settings\Temporary Internet Files\davoq._sy
c:\documents and settings\Owner.YOUR-642EF43EAF\Local Settings\Temporary Internet Files\gowygac._sy
c:\documents and settings\Owner.YOUR-642EF43EAF\Local Settings\Temporary Internet Files\orytysojeb.exe
c:\documents and settings\Owner.YOUR-642EF43EAF\Start Menu\Programs\AVI Codec Pack +
c:\documents and settings\Owner.YOUR-642EF43EAF\Start Menu\Programs\AVI Codec Pack +\Check For Updates.lnk
c:\documents and settings\Owner.YOUR-642EF43EAF\Start Menu\Programs\AVI Codec Pack +\Uninstall.lnk
c:\program files\AVI Codec Pack
c:\program files\AVI Codec Pack\AC3\ac3filter.ax
c:\program files\AVI Codec Pack\AC3\dialog_patch.exe
c:\program files\AVI Codec Pack\LAYER-3\L3CODECP.ACM
c:\program files\AVI Codec Pack\LAYER-3\RaMp3Cfg.exe
c:\program files\AVI Codec Pack\uninstall.exe
c:\program files\Common Files\dilomu.bat
c:\program files\Common Files\kecyg.vbs
c:\program files\Common Files\noxytafo.ban
c:\program files\Common Files\ukiku.vbs
c:\program files\PC_Antispyware2010
c:\program files\PC_Antispyware2010\AVEngn.dll
c:\program files\PC_Antispyware2010\data\daily.cvd
c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcm80.dll
c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcp80.dll
c:\program files\PC_Antispyware2010\Microsoft.VC80.CRT\msvcr80.dll
c:\program files\PC_Antispyware2010\PC_Antispyware2010.cfg
c:\program files\PC_Antispyware2010\pthreadVC2.dll
c:\recycler\S-1-5-21-2246483566-3919505835-4098456700-500
c:\windows\ejuxyb.reg
c:\windows\foxifumes.inf
c:\windows\Installer\271fd.msp
c:\windows\Installer\27212.msp
c:\windows\Installer\27228.msp
c:\windows\Installer\2723e.msp
c:\windows\Installer\dedeb.msi
c:\windows\Installer\dedec.msp
c:\windows\Installer\deded.msp
c:\windows\Installer\dedee.msp
c:\windows\Installer\dedef.msp
c:\windows\Installer\dedf0.msp
c:\windows\Installer\dedf1.msp
c:\windows\Installer\dedf2.msp
c:\windows\Installer\dedf3.msp
c:\windows\Installer\dedf4.msp
c:\windows\kb913800.exe
c:\windows\ogahygosyr.sys
c:\windows\sygumetap.vbs
c:\windows\system32\oraked.dl
c:\windows\system32\uhaketizub.sys
c:\windows\system32\uxohejisy.pif
c:\windows\system32\uxyjagiwu.inf
c:\windows\system32\yjojymygy.dll
c:\windows\system32\ykegij.exe
c:\windows\yvalytuz.ban
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2009-07-27 to 2009-08-27 )))))))))))))))))))))))))))))))
.

2009-08-27 03:55 . 2009-08-27 03:55 ——– d—–w- c:\documents and settings\Owner.YOUR-642EF43EAF\Local Settings\Application Data\Help
2009-08-26 20:38 . 2009-08-26 20:38 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-08-26 20:11 . 2009-08-26 20:11 ——– d—–w- c:\documents and settings\Owner.YOUR-642EF43EAF\Application Data\Malwarebytes
2009-08-26 19:42 . 2009-08-26 19:42 ——– d—–w- c:\documents and settings\Savan\Application Data\Malwarebytes
2009-08-26 19:42 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-26 19:42 . 2009-08-26 19:42 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-26 19:42 . 2009-08-26 19:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-26 19:42 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-26 19:25 . 2009-08-26 19:25 ——– d—–w- c:\program files\ERUNT
2009-08-26 18:08 . 2009-08-26 18:17 34816 —-a-w- c:\windows\system32\drivers\.sys
2009-08-26 14:29 . 2009-08-26 14:29 13607 —-a-w- c:\documents and settings\Owner.YOUR-642EF43EAF\Local Settings\Application Data\upyc.dat
2009-08-26 14:29 . 2009-08-26 14:29 10631 —-a-w- c:\windows\uxewi.dat
2009-08-20 03:48 . 2009-08-20 03:48 ——– d—–w- c:\documents and settings\Savan\Application Data\dvdcss

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-27 16:43 . 2008-06-03 01:36 ——– d—–w- c:\documents and settings\Savan\Application Data\Free Download Manager
2009-08-27 05:14 . 2007-05-29 23:53 ——– d—–w- c:\program files\Soulseek
2009-08-27 04:47 . 2007-01-01 22:11 ——– d—–w- c:\documents and settings\Savan\Application Data\uTorrent
2009-08-27 03:55 . 2006-12-31 18:44 ——– d—–w- c:\program files\AIM
2009-08-27 03:36 . 2007-05-12 20:40 ——– d—–w- c:\program files\mIRC
2009-08-26 11:20 . 2009-08-26 11:20 14530 —-a-w- c:\program files\Common Files\ewicizo.lib
2009-08-25 21:48 . 2007-12-26 23:33 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-25 21:48 . 2007-01-13 23:59 ——– d—–w- c:\program files\SpywareBlaster
2009-08-25 21:40 . 2009-06-08 23:01 ——– d—–w- c:\program files\WebSite Downloader for Windows
2009-08-17 16:10 . 2007-09-29 17:02 1279456 —-a-w- c:\windows\system32\aswBoot.exe
2009-08-17 16:06 . 2007-09-29 17:02 93392 —-a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-17 16:06 . 2007-09-29 17:02 94160 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-17 16:05 . 2008-04-05 20:09 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-17 16:05 . 2008-04-05 20:09 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 16:04 . 2007-09-29 17:02 51376 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-17 16:04 . 2007-09-29 17:02 23152 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-17 16:03 . 2007-09-29 17:02 26944 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-17 16:02 . 2007-09-29 17:02 97480 —-a-w- c:\windows\system32\AvastSS.scr
2009-07-17 02:50 . 2009-07-17 02:50 ——– d—–w- c:\documents and settings\Savan\Application Data\MozillaControl
2009-07-17 02:44 . 2009-07-17 02:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Fenrir & Co
2009-07-11 03:19 . 2009-07-11 03:08 ——– d—–w- c:\program files\Netscape
2009-07-11 03:09 . 2009-07-11 03:09 ——– d—–w- c:\documents and settings\Savan\Application Data\Netscape
2009-07-11 02:18 . 2009-07-11 02:13 ——– d—–w- c:\documents and settings\Savan\Application Data\MxBoost
2009-06-27 00:09 . 2009-05-18 03:37 127872 —-a-w- c:\documents and settings\Savan\Application Data\Move Networks\uninstall.exe
2009-06-27 00:09 . 2009-06-16 06:35 4183416 —-a-w- c:\documents and settings\Savan\Application Data\Move Networks\plugins\npqmp071503000010.dll
2009-06-27 00:06 . 2009-06-27 00:05 670130 —-a-w- c:\documents and settings\Savan\Application Data\Move Networks\MoveMediaPlayerWinSilent_071503000010.exe
2009-06-24 23:47 . 2006-06-19 04:25 34688 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-16 14:36 . 2006-06-17 09:23 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2006-06-17 09:23 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 06:35 . 2009-06-16 06:35 97144 —-a-w- c:\documents and settings\Savan\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe
2009-06-03 19:09 . 2006-06-17 09:23 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-01-07 21:39 . 2006-12-31 18:58 67688 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2009-01-07 21:39 . 2006-12-31 18:58 54368 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2009-01-07 21:39 . 2006-12-31 18:58 34944 —-a-w- c:\program files\mozilla firefox\components\myspell.dll
2009-01-07 21:39 . 2006-12-31 18:58 46712 —-a-w- c:\program files\mozilla firefox\components\spellchk.dll
2009-01-07 21:39 . 2006-12-31 18:58 172136 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2009-02-24 19:34 . 2009-02-24 19:34 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 688218]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2005-02-26 966656]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-29 344064]
"AdaptecDirectCD"="c:\program files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" [2006-12-31 684032]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-12-11 286720]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\F:\0autocheck autochk *

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=c:\windows\pss\BigFix.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Documents and Settings\\Savan\\Desktop\\temp\\utorrent.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Soulseek\\slsk.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Savan\\My Documents\\LDC++ 1.00 v2a-bin\\LDCPlusPlus.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [4/5/2008 4:09 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/5/2008 4:09 PM 20560]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [11/7/2006 4:36 PM 200576]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [8/26/2009 3:42 PM 38160]

— Other Services/Drivers In Memory —

*NewlyCreated* - MBAMSWISSARMY
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKLM-Run-ActiveSMART - c:\program files\Active SMART\\ActiveSMART.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&Br;=GTW&Loc;=ENG_US&Sys;=PTB&M;=MX6433
IE: Download all with Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Savan\Application Data\Mozilla\Firefox\Profiles\5dlbpgce.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr;=megaup&p;=
FF - component: c:\documents and settings\Savan\Application Data\Mozilla\Firefox\Profiles\5dlbpgce.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\platform\WINNT_x86-msvc\components\SSSLauncher.dll
FF - component: c:\program files\Free Download Manager\Firefox\Extension\components\vmsfdmff.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-27 12:42
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3441063250-2323267336-695642373-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*V%Àx*]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-3441063250-2323267336-695642373-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*V%Àx*\OpenWithList]
@Class="Shell"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(776)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
.
Completion time: 2009-08-27 12:46
ComboFix-quarantined-files.txt 2009-08-27 16:46

Pre-Run: 31,172,579,328 bytes free
Post-Run: 31,204,892,672 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /fastdetect /NoExecute=OptIn

255 — E O F — 2009-07-26 23:40
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Tons_Viruses_Trojans_Found_still_infected_HELP_t106477.html&view=findpost&p=591106#entry591106

Collect::
c:\windows\system32\drivers\.sys
c:\documents and settings\Owner.YOUR-642EF43EAF\Local Settings\Application Data\upyc.dat
c:\windows\uxewi.dat
c:\program files\Common Files\ewicizo.lib

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]

  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Once ComboFix has finished it will advise it is uploading files for analysis - please allow it to do so.

NEXT



  • Open your Malwarebytes' Anti-Malware program and select the update tab,
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so.

NEXT
It's important to run this online scan to search for any remnants. It can take some time, so please be patient and allow it to run it's full course:

Using Internet Explorer or Firefox, visit Kaspersky Online Scanner:
1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.
    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
OK i re-ran ComboFix with the code. Here is the log. I'll try running MalwareBytes which i ran before but it wouldn't actually work, 5 seconds in and it would close. I'll re-run it and see what happens. I'll post the message here. Thanks. UPDATE: Ok MalwareBytes seems to be running better than before. I think whatever was blocking it has been deleted. Hopefully the scan completes, and i'll post the log as soon as its done.
———————–
ComboFix 09-08-27.01 - Savan 08/27/2009 13:36.2.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.446.126 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Savan\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1351 [VPS 090826-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

file zipped: c:\documents and settings\Owner.YOUR-642EF43EAF\Local Settings\Application Data\upyc.dat
file zipped: c:\program files\Common Files\ewicizo.lib
file zipped: c:\windows\system32\drivers\.sys
file zipped: c:\windows\uxewi.dat
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Owner.YOUR-642EF43EAF\Local Settings\Application Data\upyc.dat
c:\program files\Common Files\ewicizo.lib
c:\windows\system32\drivers\.sys
c:\windows\uxewi.dat

.
((((((((((((((((((((((((( Files Created from 2009-07-27 to 2009-08-27 )))))))))))))))))))))))))))))))
.

2009-08-27 03:55 . 2009-08-27 03:55 ——– d—–w- c:\documents and settings\Owner.YOUR-642EF43EAF\Local Settings\Application Data\Help
2009-08-26 20:38 . 2009-08-26 20:38 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-08-26 20:11 . 2009-08-26 20:11 ——– d—–w- c:\documents and settings\Owner.YOUR-642EF43EAF\Application Data\Malwarebytes
2009-08-26 19:42 . 2009-08-26 19:42 ——– d—–w- c:\documents and settings\Savan\Application Data\Malwarebytes
2009-08-26 19:42 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-26 19:42 . 2009-08-26 19:42 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-26 19:42 . 2009-08-26 19:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-26 19:42 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-26 19:25 . 2009-08-26 19:25 ——– d—–w- c:\program files\ERUNT
2009-08-20 03:48 . 2009-08-20 03:48 ——– d—–w- c:\documents and settings\Savan\Application Data\dvdcss

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-27 17:43 . 2008-06-03 01:36 ——– d—–w- c:\documents and settings\Savan\Application Data\Free Download Manager
2009-08-27 05:14 . 2007-05-29 23:53 ——– d—–w- c:\program files\Soulseek
2009-08-27 04:47 . 2007-01-01 22:11 ——– d—–w- c:\documents and settings\Savan\Application Data\uTorrent
2009-08-27 03:55 . 2006-12-31 18:44 ——– d—–w- c:\program files\AIM
2009-08-27 03:36 . 2007-05-12 20:40 ——– d—–w- c:\program files\mIRC
2009-08-25 21:48 . 2007-12-26 23:33 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-25 21:48 . 2007-01-13 23:59 ——– d—–w- c:\program files\SpywareBlaster
2009-08-25 21:40 . 2009-06-08 23:01 ——– d—–w- c:\program files\WebSite Downloader for Windows
2009-08-17 16:10 . 2007-09-29 17:02 1279456 —-a-w- c:\windows\system32\aswBoot.exe
2009-08-17 16:06 . 2007-09-29 17:02 93392 —-a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-17 16:06 . 2007-09-29 17:02 94160 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-17 16:05 . 2008-04-05 20:09 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-17 16:05 . 2008-04-05 20:09 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 16:04 . 2007-09-29 17:02 51376 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-17 16:04 . 2007-09-29 17:02 23152 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-17 16:03 . 2007-09-29 17:02 26944 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-17 16:02 . 2007-09-29 17:02 97480 —-a-w- c:\windows\system32\AvastSS.scr
2009-07-17 02:50 . 2009-07-17 02:50 ——– d—–w- c:\documents and settings\Savan\Application Data\MozillaControl
2009-07-17 02:44 . 2009-07-17 02:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Fenrir & Co
2009-07-11 03:19 . 2009-07-11 03:08 ——– d—–w- c:\program files\Netscape
2009-07-11 03:09 . 2009-07-11 03:09 ——– d—–w- c:\documents and settings\Savan\Application Data\Netscape
2009-07-11 02:18 . 2009-07-11 02:13 ——– d—–w- c:\documents and settings\Savan\Application Data\MxBoost
2009-06-27 00:09 . 2009-05-18 03:37 127872 —-a-w- c:\documents and settings\Savan\Application Data\Move Networks\uninstall.exe
2009-06-27 00:09 . 2009-06-16 06:35 4183416 —-a-w- c:\documents and settings\Savan\Application Data\Move Networks\plugins\npqmp071503000010.dll
2009-06-27 00:06 . 2009-06-27 00:05 670130 —-a-w- c:\documents and settings\Savan\Application Data\Move Networks\MoveMediaPlayerWinSilent_071503000010.exe
2009-06-24 23:47 . 2006-06-19 04:25 34688 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-16 14:36 . 2006-06-17 09:23 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2006-06-17 09:23 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 06:35 . 2009-06-16 06:35 97144 —-a-w- c:\documents and settings\Savan\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe
2009-06-03 19:09 . 2006-06-17 09:23 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-01-07 21:39 . 2006-12-31 18:58 67688 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2009-01-07 21:39 . 2006-12-31 18:58 54368 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2009-01-07 21:39 . 2006-12-31 18:58 34944 —-a-w- c:\program files\mozilla firefox\components\myspell.dll
2009-01-07 21:39 . 2006-12-31 18:58 46712 —-a-w- c:\program files\mozilla firefox\components\spellchk.dll
2009-01-07 21:39 . 2006-12-31 18:58 172136 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2009-02-24 19:34 . 2009-02-24 19:34 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 688218]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2005-02-26 966656]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-29 344064]
"AdaptecDirectCD"="c:\program files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" [2006-12-31 684032]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-12-11 286720]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\F:\0autocheck autochk *

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=c:\windows\pss\BigFix.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Documents and Settings\\Savan\\Desktop\\temp\\utorrent.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Soulseek\\slsk.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Savan\\My Documents\\LDC++ 1.00 v2a-bin\\LDCPlusPlus.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [4/5/2008 4:09 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/5/2008 4:09 PM 20560]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [11/7/2006 4:36 PM 200576]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [8/26/2009 3:42 PM 38160]

— Other Services/Drivers In Memory —

*NewlyCreated* - MBAMSWISSARMY
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&Br;=GTW&Loc;=ENG_US&Sys;=PTB&M;=MX6433
IE: Download all with Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Savan\Application Data\Mozilla\Firefox\Profiles\5dlbpgce.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr;=megaup&p;=
FF - component: c:\documents and settings\Savan\Application Data\Mozilla\Firefox\Profiles\5dlbpgce.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\platform\WINNT_x86-msvc\components\SSSLauncher.dll
FF - component: c:\program files\Free Download Manager\Firefox\Extension\components\vmsfdmff.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-27 13:43
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3441063250-2323267336-695642373-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*V%Àx*]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-3441063250-2323267336-695642373-1007\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*V%Àx*\OpenWithList]
@Class="Shell"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(776)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
.
Completion time: 2009-08-27 13:46
ComboFix-quarantined-files.txt 2009-08-27 17:45
ComboFix2.txt 2009-08-27 16:46

Pre-Run: 31,222,001,664 bytes free
Post-Run: 31,206,449,152 bytes free

183 — E O F — 2009-07-26 23:40
Upload was successful
Ok MBAB quick scan actually worked this time without any errors. Here is the log: Thanks for your help. Moving onto the next step. I was wondering if you think i should use the recovery partrition and just do a factory reinstall? Now if things seem okay i can wait and do it at a later time (Like in a couple weeks giving me enough time to back up all my data) but i just feel like this virus could have messed up some windows files. What are your thoughts? thanks. Malwarebytes' Anti-Malware 1.40 Database version: 2700 Windows 5.1.2600 Service Pack 3 8/27/2009 2:02:16 PM mbam-log-2009-08-27 (14-02-13).txt Scan type: Quick Scan Objects scanned: 104993 Time elapsed: 7 minute(s), 19 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)

I was wondering if you think i should use the recovery partrition and just do a factory reinstall? Now if things seem okay i can wait and do it at a later time (Like in a couple weeks giving me enough time to back up all my data) but i just feel like this virus could have messed up some windows files. What are your thoughts? thanks


Let's see what Kaspersky comes back with - you probably wont need to reformat, but that decision is up to you.

We need to get you totally cleaned up first, then give it a test drive to see how your computer is running.

Kaspersky can take several hours to run, it's very thorough, so let it complete.

Thanks

~CB
Alright, while the computer seems to be running better, I'm having some issues running Kapersky. The browser keeps crashing while it trys to scan. Happens in both IE and Firefox. Is With IE it crashes almost right away, but with firefox i was able to run it for 17%, it was hanging like that for almost an hour, and then the browser just closed. is there anything else i can try? It found two viruses, but i wasn't able to save a log.
Hi,

Try this scanner instead

Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
Results from ESET scan: C:\Documents and Settings\All Users\Documents\Computer Fix\SDFix.exe Win32/PrcView application deleted - quarantined C:\IPOD Data\Data\Back Up Savan\Temp Folder\Computer FIX programs\Programs\ListMakerFull.zip probably a variant of Win32/Agent trojan deleted - quarantined C:\IPOD Data\Data\Back Up Savan\Temp Folder\Computer FIX programs\Programs\SRS Audio\patch.exe a variant of Win32/HackTool.Patcher.A application cleaned by deleting - quarantined C:\SDFix\apps\Process.exe Win32/PrcView application cleaned by deleting - quarantined C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP231\A0057262.exe a variant of Win32/Adware.ISM application deleted - quarantined C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP232\A0057478.exe probably a variant of Win32/Packed.Themida application cleaned by deleting - quarantined C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP232\A0057479.exe probably a variant of Win32/Packed.Themida application cleaned by deleting - quarantined C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP233\A0057719.exe a variant of Win32/HackTool.Patcher.A application cleaned by deleting - quarantined C:\System Volume Information\_restore{4E015214-6BB0-4181-B365-456CF1DEC069}\RP233\A0057726.exe Win32/PrcView application cleaned by deleting - quarantined Question: ESET is asking me about the following. Should i uninstall application on close and delete quarantined files? Thanks.
No,

The only files that needs deleting are

C:\IPOD Data\Data\Back Up Savan\Temp Folder\Computer FIX programs\Programs\ListMakerFull.zip
C:\IPOD Data\Data\Back Up Savan\Temp Folder\Computer FIX programs\Programs\SRS Audio\patch.exe

the rest is already in quarantine.

Please do the following

Go Start > Run and copy/paste the following single-line command (it's one long command - there is no break) into the Run box and click OK:

cmd /c del /f/a/q "C:\IPOD Data\Data\Back Up Savan\Temp Folder\Computer FIX programs\Programs\ListMakerFull.zip" "C:\IPOD Data\Data\Back Up Savan\Temp Folder\Computer FIX programs\Programs\SRS Audio\patch.exe"


NEXT:

Post a fresh DDS Log and Attach.txt and describe how your computer is running now and if there are any out standing issues

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI