This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] System Clock resets to 12th April 2016 when turned on

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, Tonight my computer changed its date to 12th April 2016 when it was turned on. Reset it to the coorrect time and date but done it again when restarted. Have run Spybot and Antivir Removal Tool but both have failed to find anything. Any help will be appreciated. Have attached the required files. DDS Text DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 0:06:12.07 on Fri 04/12/2009 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_17 Microsoft Windows XP Professional 5.1.2600.3.1252.61.1033.18.2046.996 [GMT 11:00] AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe svchost.exe C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe C:\WINDOWS\system32\svchost.exe -k hpdevmgmt C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\system32\PSIService.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\PROGRA~1\Allume\StuffIt\MXTask.exe C:\WINDOWS\system32\Tablet.exe C:\PROGRA~1\Allume\StuffIt\mxtask.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe C:\WINDOWS\stsystra.exe C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe C:\PROGRA~1\EPSONS~1\EVENTM~1\EEventManager.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe C:\WINDOWS\system32\WTablet\TabUserW.exe C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Documents and Settings\Sharon\Desktop\removaltool-win32-en.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Sharon\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uSearch Bar = hxxp://www.google.com.au/hws/sb/dell-row/en/side.html?channel=au uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\program files\common files\svchost.exe, BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: ContributeBHO Class: {074c1dc5-9320-4a9a-947d-c042949c6216} - c:\program files\adobe\/Adobe Contribute CS3/contributeieplugin.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll {29d2c90d-87d8-4580-b12c-d174076d2934} BHO: FGCatchUrl: {2f364306-aa45-47b5-9f9d-39a8b94e7ef7} - c:\program files\flashget\jccatch.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: EWPBrowseObject Class: {68f9551e-0411-48e4-9aaf-4bc42a6a46be} - c:\program files\canon\easy-webprint\EWPBrowseLoader.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll BHO: FlashGet GetFlash Class: {f156768e-81ef-470c-9057-481ba8380dba} - c:\program files\flashget\getflash.dll TB: {9FB3908C-6565-4CB0-95F8-E9F85258723C} - No File TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: Contribute Toolbar: {517bdde4-e3a7-4570-b21e-2b52b6139fc7} - c:\program files\adobe\/Adobe Contribute CS3/contributeieplugin.dll TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll TB: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background mRun: [TrueImageMonitor.exe] c:\program files\acronis\trueimagehome\TrueImageMonitor.exe mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [LVCOMSX] "c:\program files\common files\logishrd\lcommgr\LVComSX.exe" mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe" mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\Iaanotif.exe mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay mRun: [AcronisTimounterMonitor] c:\program files\acronis\trueimagehome\TimounterMonitor.exe mRun: [Acronis Scheduler2 Service] "c:\program files\common files\acronis\schedule2\schedhlp.exe" mRun: [Adobe_ID0EYTHM] c:\progra~1\common~1\adobe\adobev~1\server\bin\VERSIO~2.EXE mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [FUFAXSTM] "c:\program files\epson software\fax utility\FUFAXSTM.exe" mRun: [EEventManager] c:\progra~1\epsons~1\eventm~1\EEventManager.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [nvcpl] c:\program files\common files\svchost.exe dRun: [PcSync] c:\program files\nokia\nokia pc suite 6\PcSync2.exe /NoDialog mExplorerRun: [none2] c:\windows\lsass.exe StartupFolder: c:\documents and settings\sharon\start menu\programs\startup\PowerReg Scheduler.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\tabuse~1.lnk - c:\windows\system32\wtablet\TabUserW.exe mPolicies-system: EnableLUA = 0 (0x0) IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\belkin\bluetooth software\btsendto_ie.htm IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - c:\program files\flashget\FlashGet.exe IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {7F9DB11C-E358-4ca6-A83D-ACC663939424} - {9999A076-A9E2-4C99-8A2B-632FC9429223} - c:\program files\bonjour\ExplorerPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll Trusted Zone: imb.com.au\extranet DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} - hxxp://aac001.imb.com.au/CitrixSessionInit/ICAWEB/en/ica32/wficat.cab DPF: {7E0FDFBB-87D4-43A1-9AD4-41F0EA8AFF7B} - hxxps://extranet.imb.com.au/net6helper.cab DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {BA2CB6B1-03EE-4068-87CC-F5E4DD772A9B} - hxxps://extranet.imb.com.au/CitrixLogonPoint/access_ext/EPAClient/CitrixCAO.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Handler: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - c:\windows\system32\BTXPPanel.dll Notify: LBTWlgn - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R0 snapman380;Acronis Snapshots Manager (Build 380);c:\windows\system32\drivers\snman380.sys [2009-6-11 134272] R0 tdrpman174;Acronis Try&Decide and Restore Points filter (build 174);c:\windows\system32\drivers\tdrpm174.sys [2009-6-11 971552] R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-3-13 33800] R2 ekrn;Eset Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2007-12-21 468224] R3 Net6IM;Net6;c:\windows\system32\drivers\net6im51.sys [2008-6-27 44664] S2 D0777A50F98F8688;D0777A50F98F8688;\??\c:\windows\system32\d0777a50f98f8688\d0777a50f98f8688 –> c:\windows\system32\d0777a50f98f8688\D0777A50F98F8688 [?] S2 FlexService;Remote Connections Service;"c:\program files\rapidbit\cisvc.exe" –> c:\program files\rapidbit\cisvc.exe [?] S3 bepldr;BCL easyPDF SDK 5 Loader;c:\program files\common files\bcl technologies\easypdf 5\bepldr.exe [2007-2-21 151552] =============== Created Last 30 ================ 2009-11-26 21:05 –d—– c:\windows\Delicious Emilys Holiday Season 2009-11-26 12:22 –d—– c:\documents and settings\sharon\.csi 2009-11-25 23:10 –d—– c:\windows\Gardenscapes 2009-11-25 21:57 –d—– c:\docume~1\sharon\applic~1\TitanicMystery 2009-11-25 21:47 –d—– c:\windows\1912 Titanic Mystery 2009-11-25 20:07 –d—– c:\windows\Hotel Dash Suite Success 2009-11-25 20:02 –d—– c:\program files\MSXML 4.0 2009-11-24 13:46 –d—– c:\docume~1\sharon\applic~1\My Reflections 2009-11-22 21:35 –d—– c:\windows\Cake Shop 2009-11-22 21:18 –d—– c:\docume~1\alluse~1\applic~1\Brainiversity2 2009-11-20 20:19 0 a——- c:\windows\system32\NULL 2009-11-15 14:36 137,716 a—h— c:\windows\system32\mlfcache.dat 2009-11-14 01:56 96,659,731 a——- c:\docume~1\sharon\applic~1\Gardenscapes.exe 2009-11-11 10:18 –d—– c:\program files\Alawar Games 2009-11-09 13:34 0 a——- c:\windows\EEventManager.INI 2009-11-09 13:30 –d—– c:\docume~1\alluse~1\applic~1\Riverdeep Interactive Learning Limited 2009-11-09 13:25 –d—– c:\program files\Riverdeep 2009-11-09 13:25 –d—– c:\program files\Web Publish 2009-11-09 13:25 970,752 a——- c:\windows\system32\cdintf210.dll 2009-11-09 13:24 –d—– c:\docume~1\alluse~1\applic~1\Broderbund Software 2009-11-09 13:24 –d—– c:\program files\common files\Broderbund 2009-11-09 13:24 –d—– c:\program files\The Print Shop 20 2009-11-08 23:09 0 a——- c:\windows\Game.INI 2009-11-08 23:01 –d—– c:\program files\RapidBIT 2009-11-08 22:49 78,595 —sh— c:\docume~1\sharon\applic~1\10090_8147e655532c352899efc4f88b0b655f.exe 2009-11-08 22:44 –d—– c:\windows\Lost City of Z - Special Edition 2009-11-08 22:02 –d—– c:\docume~1\sharon\applic~1\MBT 2009-11-08 21:54 –d—– c:\windows\World of Zellians 2009-11-08 21:54 –d—– c:\windows\Wizards Hat 2009-11-08 21:33 –d—– c:\docume~1\sharon\applic~1\Magic Academy 2 2009-11-08 20:43 –d—– c:\docume~1\sharon\applic~1\VampireSaga 2009-11-08 20:39 –d—– c:\docume~1\sharon\applic~1\TikisLab 2009-11-08 20:38 –d—– c:\windows\Travel League - The Missing Jewels 2009-11-08 19:55 8,192 a——- c:\windows\system32\E_DCINST.DLL 2009-11-08 19:55 93,696 a——- c:\windows\system32\E_FLBFHP.DLL 2009-11-08 19:55 79,360 a——- c:\windows\system32\E_FD4BFHP.DLL 2009-11-08 19:52 –d—– c:\docume~1\alluse~1\applic~1\UDL 2009-11-08 19:49 –d—– c:\program files\Epson Software 2009-11-08 19:49 474,892 a——- c:\windows\system32\ensppmon.dll 2009-11-08 19:49 474,892 a——- c:\windows\system32\enppmon.dll 2009-11-08 19:49 457,611 a——- c:\windows\system32\ensppui.dll 2009-11-08 19:49 457,611 a——- c:\windows\system32\enppui.dll 2009-11-08 19:49 249,344 a——- c:\windows\system32\enspres.dll 2009-11-08 19:49 249,344 a——- c:\windows\system32\enpres.dll 2009-11-08 19:48 –d—– c:\program files\common files\EPSON 2009-11-08 19:48 –d—– c:\program files\EpsonNet 2009-11-08 19:45 –d—– c:\docume~1\alluse~1\applic~1\EPSON 2009-11-08 19:45 342,016 a——- c:\windows\system32\eswiaud.dll 2009-11-08 19:45 9,216 a——- c:\windows\system32\escdev.dll 2009-11-08 19:29 –d—– c:\docume~1\sharon\applic~1\Freezetag 2009-11-08 15:12 –d—– c:\windows\Romance of Rome 2009-11-08 15:07 –d—– c:\docume~1\alluse~1\applic~1\SOS 2009-11-08 14:34 –d—– c:\docume~1\sharon\applic~1\Enki Games 2009-11-08 14:34 –d—– c:\windows\Reincarnations - Awakening 2009-11-08 13:01 –d—– c:\docume~1\sharon\applic~1\casanova 2009-11-07 22:52 –d—– c:\docume~1\sharon\applic~1\HdO Adventure 2009-11-07 22:51 –d—– c:\windows\HdO Adventure Secrets of the Vatican 2009-11-07 22:31 –d—– c:\windows\Hidden World of Art 2 Undercover Art Agent 2009-11-07 22:07 –d—– c:\windows\Hostile Makeover - A Fashion Murder Mystery Game 2009-11-07 20:00 –d—– c:\windows\Ghost Town Mysteries Bodie 2009-11-07 17:50 –d—– c:\docume~1\sharon\applic~1\ERS G-Studio 2009-11-07 17:36 –d—– c:\program files\Destination Treasure Island 2009-11-07 16:57 –d—– c:\windows\Fishdom Spooky Splash ==================== Find3M ==================== 2009-11-09 20:35 411,368 a——- c:\windows\system32\deploytk.dll 2009-10-21 15:08 3,598,336 a——- c:\windows\system32\dllcache\mshtml.dll 2009-10-05 00:28 3,702 a——- c:\windows\08c33573f2968a15218042c99ab8.exe 2009-09-30 19:18 91,000,343 a——- c:\docume~1\sharon\applic~1\Affair Bureau.exe 2009-09-16 17:47 1,966,080 a——- c:\windows\system32\cdintf251.dll 2009-09-12 01:18 136,192 a——- c:\windows\system32\msv1_0.dll 2009-09-12 01:18 136,192 ——– c:\windows\system32\dllcache\msv1_0.dll 2009-09-08 07:04 16,384 a——- c:\docume~1\sharon\applic~1\onload.exe 2009-09-05 08:03 58,880 a——- c:\windows\system32\msasn1.dll 2009-09-05 08:03 58,880 ——– c:\windows\system32\dllcache\msasn1.dll 2009-08-30 03:46 100,015,912 a——- c:\program files\B.A.4.exe 2009-03-22 01:06 94,720 —sh— c:\program files\common files\svchost.exe 2008-06-27 23:08 1,183,768 a——- c:\docume~1\sharon\applic~1\CitrixSAClient.exe 2008-07-28 18:25 88 —shr– c:\windows\system32\7DD5BF6A16.sys 2009-04-12 23:17 2,254 a–sh— c:\windows\system32\KGyGaAvL.sys 2009-01-07 17:53 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009010720090108\index.dat ============= FINISH: 0:07:12.98 =============== ROOT REPEAL ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/12/04 00:22 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ——————- Name: dump_iaStor.sys Image Path: C:\WINDOWS\System32\Drivers\dump_iaStor.sys Address: 0x993EC000 Size: 749568 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0x97130000 Size: 49152 File Visible: No Signed: - Status: - Processes ——————- Path: C:\WINDOWS\explorer.exe PID: 3228 Status: Hidden from the Windows API! Hidden Services ——————- Service Name: D0777A50F98F8688 Image Path: C:\WINDOWS\system32\D0777A50F98F8688\D0777A50F98F8688 ==EOF==

Attachments:

Hi sharmick, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

Reset your clock to the correct time
  • Right click on the clock
  • Click Adjust Time/Date
  • Set the Date and Time to the coorect settings
  • Click apply

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with the combofix log.

How's the computer?

Thanks
Thanks for getting back to me Oldman960. Hopefully this won't be too painful. I have a problem in that I cannot disable the Avira AntiVir Removal tool. It was a stand alone thing I thought I would run - didn't install. But now Security Centre and the Combo Fix say it is running. Unable to find it anywere on the computer to disable it. Will running Combo fix with it running affec the results or do you have any suggestions? Michael
Hi sharmick,

If it is running there should be a icon on the taskbar. Open it and click Stop Scan then click Exit. If it isn't showing as an icon, then double click the program to start it, make sure it is indeed stopped. You can tell if it's running or not by which option is greyed out. If the option to Stop Scan is greyed out then the tool is indeed all ready stopped. Then click exit.

Once you have confirmed that the Avira AntiVir Removal tool is stopped, go ahead an run combofix. Ok any warnings but make sure your antivirus program is also disabled.

Thanks
Hi Oldman960, Avira was supposed to be a stand alone removal tool. I deleted the exe and had nothing in prog. files. The normal avira progs were not running in startup. I ran the Avira removal tool to remove it from the registry, but Security Centre and Combo Fix still reported it as running. I took a punt and asssumed it wasn't and have ran Combo Fix. Combo Fix installed Recovery Console and the log is attached. Upon restarting the PC the time has stayed at the correct time. Is there anything else we need to do or do you think we have it beaten.

Attachments:

Hi sharmick,

We still have some more to do.

AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Resident AV is active

This shows 2 antivirus programs installed. Can you clarify your antivirus situation?

Combofix was ran while your date was still set incorrectly. We'll make a new restore point before we continue.

  • Go to Start - All Programs - Accessories - System Tools - System Restore.
  • Click Create a restore point, and then click Next.
  • In the text box labeled Restore Point Description, type a name for this restore point
  • click create
After it has completed, please continue.

We will be using Combofix again but will run it differently.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the all of the text in the code box below into the Notepad, (including the URL). Do Not copy the word CODE

http://forums.whatthetech.com/System_Clock_resets_12th_April_2016_when_turned_t108661.html

Killall::

Collect::
C:\cpx.exe
C:\prx.exe
C:\install.48469.exe
C:\your_exe.exe
C:\ic.exe

Folder::
c:\windows\system32\D0777A50F98F8688

Driver::
D0777A50F98F8688

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit" = "c:\\windows\\system32\\userinit.exe,"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"nvcpl"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{W0YMS373-5163-DX3Q-VP05-4G3PIC12Q4GR}]
[-HKEY_CLASSES_ROOT\CLSID\{A45F39DC-3608-4237-8F0E-139F1BC49464}]

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.

Please post back with the combofix log.

Thanks
Hi Oldman950, Re Antivirus - We only have NOD32 installed. Avira Antivir Removal Tool was run but for some strange reason the PC thinks it is installed. There is no folder or programme for it, I have removed it from Application Data, run Avira's Registry Cleaner for it so I am pretty sure it is not running. Re System Date. Combofix restarted the PC which reset the date forward to 2016 so then it completed its tasks in the wrong date. Will post the log when Combofix finishes doing what it is doing. Edit: Combofix Log file attached.

Attachments:

Hi sharmick,

The date seems to be fine now. We'll see if we can clear that Security Center entry.

Please open this link HERE in a new window.

In the box marked Link to topic where this file was requested: please paste in the following text
http://forums.whatthetech.com/System_Clock_resets_12th_April_2016_when_turned_t108661.html

Click the Browse button and navigate to C:\Qoobox\Quarantine

There should be a zip file there called [4]-Submit_****-**-**_**.**.**.zip ( the * denotes Date and Time stamp - yours will be similar to : 2009-12-05 xxxx )
Select this file and click Open


Click SendFile


We will be using Combofix again but will run it differently.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the all of the text in the code box below into the Notepad, (including the URL). Do Not copy the word CODE

DirLook::
c:\documents and settings\Sharon\Local Settings\Application Data\.#

SecCenter:: 
{AD166499-45F9-482A-A743-FDD3350758C7}

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

**Note**



You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Please post back with the combofix log and the MBAM log.

Thanks
Hi sharmick,

Just about done.

You have some old vulnerable java installed.

Click the Start button, Open Control Panel > Add/Remove Programs and uninstall

J2SE Runtime Environment 5.0 Update 6
Java™ SE Runtime Environment 6 Update 1
Java™ 6 Update 2
Java™ 6 Update 3
Java™ 6 Update 5


Do Not uninstall Java™ 6 Update 17

Next, clear the java cache

To clear the Java Plug-in cache:
  • Click Start > Control Panel.
  • Double-click the Java icon in the control panel.
  • On the General tab, Click Settings under Temporary Internet Files.
  • On the Temporary Files Settings screen, Click Delete Files.
  • check all boxes
  • Click OK

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computerr under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply.

Please post back with
  • Kaspersky log
How's the computer?

Thanks
Hi sharmick,

Most of the detections are in games. At least one detection is from a cracked game.

C:\Documents and Settings\Sharon\Desktop\For Mum\Big Fish Games Steve the Sheriff 2 The Case of the Missing Thing Precracked.exe

This may explain some of the infections.

Next, Rooter.exe to your desktop
  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt (Where %systemdrive% is usually C: or the drive that you have installed Windows). Post that in your next reply.

We'll deal with everything at he same time.

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI